Podezření na virus
Napsal: 30 čer 2025 07:32
Dobrý den,
včera jsem se koukal na video na iPrima a klikl jsem dole na liště videa na ikonku s otazníkem. krátce se objevilo cosi o měření a od té chvíle se notebook dramaticky zpomalil, několikrát jsem se snažil ho restartovat, hlásilo to i problém s Windows, pak se umoudřil natolik, že funguje na pohled normálně, ale v Tsak manageru vidím téměř pořád odesílání přes Wi-fi.
Popravdě nevím, jestli notebook něco neodesílá pořád, dokud nebyl ten včerejší problém, tak jsem to nezkoumal.
Raději posílám FRSR. RSIT jsem nedělal, mám Win 10.
Prosím o kontrolu logu a předem děkuji.
Pavel
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28-06-2025
Ran by trew1 (administrator) on DESKTOP-UM04K9K (HP HP Pavilion Gaming Laptop 15-ec2xxx) (30-06-2025 08:14:41)
Running from C:\Users\trew1\Desktop\FRST64.exe
Loaded Profiles: trew1
Platform: Microsoft Windows 10 Home Version 22H2 19045.5965 (X64) Language: Čeština (Česko)
Default browser: Edge
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\egui.exe
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eOppFrame.exe
(C:\Program Files\WindowsApps\AppleInc.AppleDevices_1.1284.24577.0_x64__nzyj5cx40ttqa\AppleMobileDeviceLauncher.exe ->) (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.) C:\Program Files\WindowsApps\AppleInc.AppleDevices_1.1284.24577.0_x64__nzyj5cx40ttqa\AppleMobileDeviceProcess.exe
(DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f2bc3e822f15dc0b\x64\SysInfoCap.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f2bc3e822f15dc0b\x64\BridgeCommunication.exe
(DriverStore\FileRepository\u0367686.inf_amd64_8619bf9fd6ff97a0\B366682\atiesrxx.exe ->) (Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0367686.inf_amd64_8619bf9fd6ff97a0\B366682\atieclxx.exe
(Elaborate Bytes AG -> Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(ETDService.exe ->) (ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronics Corp.) C:\Windows\System32\ETDCtrl.exe
(explorer.exe ->) (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.) C:\Program Files\WindowsApps\AppleInc.AppleDevices_1.1284.24577.0_x64__nzyj5cx40ttqa\AppleMobileDeviceLauncher.exe
(explorer.exe ->) (Hewlett Packard -> HP Inc.) C:\Program Files\HP\HP DeskJet 5000 series\Bin\ScanToPCActivationApp.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <25>
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\OneDrive.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotifyIcon.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0367686.inf_amd64_8619bf9fd6ff97a0\B366682\atiesrxx.exe
(services.exe ->) (ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronics Corp.) C:\Windows\System32\ETDService.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\efwd.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_bdc4c744cf4529f4\x64\TouchpointAnalyticsClientService.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f2bc3e822f15dc0b\x64\AppHelperCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f2bc3e822f15dc0b\x64\DiagsCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f2bc3e822f15dc0b\x64\NetworkCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f2bc3e822f15dc0b\x64\SysInfoCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpomencustomcapcomp.inf_amd64_f1b47696babae655\x64\OmenCap\OmenCap.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvhm.inf_amd64_5c197d2d97068bef\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.) C:\Windows\RtkBtManServ.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_b022f456c858acec\RtkAudUService64.exe <2>
(SlySoft, Inc.) [File not signed] C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\25.105.0601.0002\FileCoAuth.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_b022f456c858acec\RtkAudUService64.exe [1269656 2021-07-28] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [292064 2025-05-12] (ESET, spol. s r.o. -> ESET)
HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG -> Elaborate Bytes AG)
HKLM-x32\...\Run: [CloneCDTray] => C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe [57344 2009-01-29] (SlySoft, Inc.) [File not signed]
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-2704875781-386717825-2673586809-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4966720 2025-06-27] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2704875781-386717825-2673586809-1001\...\Run: [HP DeskJet 5000 (NET)] => C:\Program Files\HP\HP DeskJet 5000 series\Bin\ScanToPCActivationApp.exe [4065416 2018-04-19] (Hewlett Packard -> HP Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\137.0.7151.122\Installer\chrmstp.exe [2025-06-27] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Akcelerátor spuštění AutoCADu.lnk [2022-03-13]
ShortcutTarget: Akcelerátor spuštění AutoCADu.lnk -> C:\Program Files (x86)\Common Files\Autodesk Shared\acstart17.exe (Autodesk, Inc -> Autodesk, Inc)
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {7EFC8197-6FF8-4F86-9CD1-3F65DB1028C5} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1580992 2025-03-21] (Adobe Inc. -> Adobe Inc.)
Task: {E44C2F62-D825-4172-9ED5-7C3013F0FCDC} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem138.0.7194.0{CBA40BFB-96B9-40EB-A18E-66710EF3BC34} => C:\Program Files (x86)\Google\GoogleUpdater\138.0.7194.0\updater.exe [7080032 2025-05-22] (Google LLC -> Google LLC)
Task: {F61615A7-072F-40F1-9FE1-63E4B3664DF3} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [79312 2025-05-08] (HP Inc. -> HP Inc.)
Task: {35580093-43AE-4D0D-BAB6-A239C9166564} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor Logon => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [79312 2025-05-08] (HP Inc. -> HP Inc.)
Task: {6608CA28-E150-4366-9726-24188D3A4ADA} - System32\Tasks\HPCustParticipation HP DeskJet 5000 series => C:\Program Files\HP\HP DeskJet 5000 series\Bin\HPCustPartic.exe [6660744 2018-04-19] (Hewlett Packard -> HP Inc.)
Task: {B6F52653-6996-4759-812F-2715A8AADB2E} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28952664 2025-06-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {CBCC028D-DD8F-4AB5-9277-040244552F62} - System32\Tasks\Microsoft\Office\Office Background Push Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE16\opushutil.exe [60392 2025-06-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {B5B00D6B-7F62-4174-91D6-28FC341B1ECE} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28952664 2025-06-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {55989CE6-72F4-4A45-B18E-76ED07DBED41} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [222688 2025-06-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {6D9B70BB-53F0-4977-9793-9CBAA779019C} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [222688 2025-06-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {BC7D044F-3515-48B2-BBF9-91CD19C6AB81} - System32\Tasks\Microsoft\Office\Office Startup Boost => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [222688 2025-06-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {2A4F4192-8BDA-44D7-A278-8E62246939AD} - System32\Tasks\Microsoft\Office\Office Startup Boost Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [222688 2025-06-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {1AEDFD6C-ADC0-42DF-8873-74E51B89BC2F} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4223784 2025-06-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {B7A9F0D6-F6E9-47A0-A338-F40E5369ABD1} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2704875781-386717825-2673586809-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4223784 2025-06-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {6A4F5C90-ABB2-44EB-B7B3-C8FA31FF1A9C} - System32\Tasks\OneDrive Startup Task-S-1-5-21-2704875781-386717825-2673586809-1001 => C:\Program Files\Microsoft OneDrive\25.105.0601.0002\OneDriveLauncher.exe [684352 2025-06-27] (Microsoft Corporation -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.43.1
Tcpip\..\Interfaces\{35379157-0ba1-4a3f-aa4c-68d7027ab254}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{35379157-0ba1-4a3f-aa4c-68d7027ab254}: [DhcpDomain] home
Tcpip\..\Interfaces\{c48cec14-6f9e-453e-8bb3-b4d27ff20075}: [DhcpNameServer] 192.168.43.1
Tcpip\..\Interfaces\{c48cec14-6f9e-453e-8bb3-b4d27ff20075}\255646D69602E4F647560283020527F6: [DhcpNameServer] 192.168.43.1
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\trew1\AppData\Local\Microsoft\Edge\User Data\Default [2025-06-30]
Edge Extension: (Dokumenty Google offline) - C:\Users\trew1\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-04-28]
Edge Extension: (Edge relevant text changes) - C:\Users\trew1\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-02-12]
Edge HKLM-x32\...\Edge\Extension: [nkapkmklnmidbbgjaipbgpcnbomnaakc]
FireFox:
========
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2025-06-06] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2025-06-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=3.0.16 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
Chrome:
=======
CHR Profile: C:\Users\trew1\AppData\Local\Google\Chrome\User Data\Default [2025-06-29]
CHR Session Restore: Default -> is enabled.
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\trew1\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2025-06-29]
CHR Extension: (Dokumenty Google offline) - C:\Users\trew1\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-06-14]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\trew1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-03-06]
CHR HKU\S-1-5-21-2704875781-386717825-2673586809-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [oombnmpbbhbakfpfgdflaajkhicgfaam]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [174520 2025-03-21] (Adobe Inc. -> Adobe Inc.)
S3 Autodesk Licensing Service; C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe [77944 2022-03-13] (Autodesk, Inc -> Autodesk)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13725240 2025-06-27] (Microsoft Corporation -> Microsoft Corporation)
R2 efwd; C:\Program Files\ESET\ESET Security\efwd.exe [5559152 2025-05-12] (ESET, spol. s r.o. -> ESET)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [4582480 2025-05-12] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [4582480 2025-05-12] (ESET, spol. s r.o. -> ESET)
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\25.105.0601.0002\FileSyncHelper.exe [3620168 2025-06-27] (Microsoft Corporation -> Microsoft Corporation)
R2 HPAppHelperCap; C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f2bc3e822f15dc0b\x64\AppHelperCap.exe [928888 2025-05-06] (HP Inc. -> HP Inc.)
R2 HPDiagsCap; C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f2bc3e822f15dc0b\x64\DiagsCap.exe [927328 2025-05-06] (HP Inc. -> HP Inc.)
R2 HPNetworkCap; C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f2bc3e822f15dc0b\x64\NetworkCap.exe [923256 2025-05-06] (HP Inc. -> HP Inc.)
R2 HPOmenCap; C:\Windows\System32\DriverStore\FileRepository\hpomencustomcapcomp.inf_amd64_f1b47696babae655\x64\OmenCap\OmenCap.exe [755152 2023-10-19] (HP Inc. -> HP Inc.)
R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [243664 2025-05-08] (HP Inc. -> HP Inc.)
R2 HPSysInfoCap; C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f2bc3e822f15dc0b\x64\SysInfoCap.exe [928352 2025-05-06] (HP Inc. -> HP Inc.)
R2 HpTouchpointAnalyticsService; C:\Windows\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_bdc4c744cf4529f4\x64\TouchpointAnalyticsClientService.exe [631448 2025-03-26] (HP Inc. -> HP Inc.)
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nvhm.inf_amd64_5c197d2d97068bef\Display.NvContainer\NVDisplay.Container.exe [1275016 2024-12-12] (NVIDIA Corporation -> NVIDIA Corporation)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\25.105.0601.0002\OneDriveUpdaterService.exe [3873096 2025-06-27] (Microsoft Corporation -> Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3004048 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103384 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AmUStor; C:\Windows\system32\drivers\AmUStorU.sys [143904 2020-05-11] (Alcorlink Corp. -> )
S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\Windows\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BTHMODEM; C:\Windows\System32\drivers\bthmodem.sys [76800 2019-12-07] (Microsoft Corporation) [File not signed]
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [227224 2025-05-12] (ESET, spol. s r.o. -> ESET)
R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [121816 2025-05-12] (Microsoft Windows Hardware Compatibility Publisher -> ESET)
S0 eelam; C:\Windows\System32\DRIVERS\eelam.sys [16336 2022-09-05] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [266944 2025-05-12] (ESET, spol. s r.o. -> ESET)
R2 ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [57304 2025-05-12] (ESET, spol. s r.o. -> ESET)
R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft Inc. -> SlySoft, Inc.)
R3 ElbyCDFL; C:\Windows\SysWOW64\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft Inc. -> SlySoft, Inc.)
R1 epfw; C:\Windows\system32\DRIVERS\epfw.sys [86200 2025-05-12] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [128512 2025-05-12] (ESET, spol. s r.o. -> ESET)
R3 HPCustomCapDriver; C:\Windows\System32\DriverStore\FileRepository\hpcustomcapdriver.inf_amd64_1421dec2010cc057\x64\hpcustomcapdriver.sys [18984 2024-05-07] (Microsoft Windows Hardware Compatibility Publisher -> HP Inc.)
R3 HPOmenCustomCapDriver; C:\Windows\System32\DriverStore\FileRepository\hpomencustomcapdriver.inf_amd64_326f2e1d16385daf\x64\hpomencustomcapdriver.sys [33464 2018-12-19] (HP Inc. -> HP Inc.)
S3 Ser2pl; C:\Windows\system32\DRIVERS\ser2pl64.sys [328784 2023-03-06] (Microsoft Windows Hardware Compatibility Publisher -> Prolific Technology Inc.)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R1 VBoxNetAdp; C:\Windows\system32\DRIVERS\VBoxNetAdp6.sys [131144 2017-04-18] (Oracle Corporation -> Oracle Corporation)
R1 VBoxNetLwf; C:\Windows\system32\DRIVERS\VBoxNetLwf.sys [205952 2017-04-18] (Oracle Corporation -> Oracle Corporation)
R3 ViGEmBus; C:\Windows\System32\DriverStore\FileRepository\vigembus.inf_amd64_8a927fc43d8a7838\x64\ViGEmBus.sys [91432 2020-04-21] (HP Inc. -> Benjamin Hoeglinger-Stelzer)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [54200 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessButtonDriver64; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [40200 2023-11-17] (HP Inc. -> HP)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-06-30 08:14 - 2025-06-30 08:15 - 000020668 _____ C:\Users\trew1\Desktop\FRST.txt
2025-06-30 08:14 - 2025-06-30 08:15 - 000000000 ____D C:\FRST
2025-06-30 08:11 - 2025-06-30 08:12 - 002407936 _____ (Farbar) C:\Users\trew1\Desktop\FRST64.exe
2025-06-29 23:14 - 2025-06-29 23:14 - 996698027 _____ C:\Windows\MEMORY.DMP
2025-06-29 23:14 - 2025-06-29 23:14 - 001430884 _____ C:\Windows\Minidump\062925-9062-01.dmp
2025-06-27 21:30 - 2025-06-27 21:30 - 000000090 _____ C:\logUploaderSettings_temp.ini
2025-06-27 21:30 - 2025-06-27 21:30 - 000000090 _____ C:\logUploaderSettings.ini
2025-06-23 14:31 - 2025-06-23 14:31 - 000000000 ____D C:\Users\trew1\AppData\Local\FreeCAD
2025-06-23 14:23 - 2025-06-23 14:23 - 000001930 _____ C:\Users\Public\Desktop\FreeCAD 1.0.lnk
2025-06-23 14:23 - 2025-06-23 14:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeCAD 1.0
2025-06-23 14:21 - 2025-06-23 14:23 - 000000000 ____D C:\Program Files\FreeCAD 1.0
2025-06-23 13:33 - 2025-06-23 13:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2025-06-23 13:33 - 2025-06-23 13:33 - 000000000 ____D C:\Program Files\7-Zip
2025-06-23 13:32 - 2025-06-23 13:33 - 000000000 ____D C:\Users\trew1\Documents\ZIP
2025-06-23 13:27 - 2025-06-23 14:19 - 000000000 ____D C:\Users\trew1\Documents\FreeCAD
2025-06-23 13:27 - 2025-06-23 13:27 - 000000000 ____D C:\Users\trew1\Documents\Nová složka
2025-06-13 21:35 - 2025-06-13 21:35 - 000000000 ___HD C:\$WinREAgent
2025-06-11 17:39 - 2025-06-11 17:41 - 000000000 ____D C:\Users\trew1\Documents\Máma
2025-06-11 17:28 - 2025-06-11 17:28 - 000000000 ____D C:\Users\trew1\Documents\Fax
2025-06-08 13:04 - 2025-06-08 13:04 - 007754473 _____ C:\Users\trew1\Downloads\navod-na-pouziti.pdf
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-06-30 08:12 - 2022-05-11 13:38 - 000714500 _____ C:\Windows\system32\perfh005.dat
2025-06-30 08:12 - 2022-05-11 13:38 - 000144182 _____ C:\Windows\system32\perfc005.dat
2025-06-30 08:12 - 2022-03-06 13:55 - 000005620 _____ C:\Windows\system32\PerfStringBackup.INI
2025-06-30 08:09 - 2022-03-06 14:03 - 000000000 ___RD C:\Users\trew1\OneDrive
2025-06-30 08:09 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-06-30 08:07 - 2022-03-06 13:57 - 000000000 ____D C:\ProgramData\NVIDIA
2025-06-30 08:07 - 2022-03-06 13:49 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2025-06-30 08:07 - 2022-03-06 13:49 - 000000000 ____D C:\Windows\system32\SleepStudy
2025-06-30 08:07 - 2021-06-25 20:10 - 000008192 ___SH C:\DumpStack.log.tmp
2025-06-29 23:14 - 2022-07-22 16:08 - 000000000 ____D C:\Windows\Minidump
2025-06-29 23:14 - 2019-12-07 11:13 - 000000000 ____D C:\Windows\INF
2025-06-29 23:12 - 2022-03-06 13:57 - 000000000 ____D C:\Users\trew1
2025-06-29 23:08 - 2022-04-01 13:42 - 000000000 ____D C:\Windows\SystemTemp
2025-06-29 23:08 - 2019-12-07 11:03 - 000786432 _____ C:\Windows\system32\config\BBI
2025-06-29 23:03 - 2022-03-06 15:18 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2025-06-29 23:03 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2025-06-29 23:03 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\AppReadiness
2025-06-29 23:02 - 2022-03-26 11:12 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2025-06-29 23:02 - 2022-03-06 14:01 - 000000000 ____D C:\Users\trew1\AppData\Local\Packages
2025-06-29 20:02 - 2022-03-06 13:49 - 000002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-06-29 20:02 - 2022-03-06 13:49 - 000002281 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2025-06-28 00:24 - 2022-03-06 15:00 - 000002254 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2025-06-28 00:24 - 2022-03-06 15:00 - 000002213 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2025-06-27 21:30 - 2025-02-07 21:06 - 000003546 _____ C:\Windows\system32\Tasks\OneDrive Startup Task-S-1-5-21-2704875781-386717825-2673586809-1001
2025-06-27 21:30 - 2022-03-22 12:32 - 000003194 _____ C:\Windows\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2025-06-27 21:30 - 2022-03-22 12:32 - 000002137 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-06-27 21:30 - 2022-03-06 14:03 - 000003592 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2704875781-386717825-2673586809-1001
2025-06-27 20:03 - 2022-03-29 15:37 - 000000000 ____D C:\Users\trew1\AppData\Roaming\Microsoft\Excel
2025-06-27 19:55 - 2022-03-13 12:29 - 000000000 ____D C:\Users\trew1\Documents\Byt_SVJ_Údržba v domě
2025-06-23 22:31 - 2025-02-04 21:07 - 000000000 ____D C:\Users\trew1\AppData\Local\LightBurn
2025-06-23 16:07 - 2024-03-07 15:51 - 000000000 ____D C:\Users\trew1\AppData\Local\CrashDumps
2025-06-23 15:06 - 2022-09-21 14:41 - 000000000 ____D C:\Users\trew1\AppData\Roaming\FreeCAD
2025-06-23 14:10 - 2022-09-18 18:24 - 000000000 ____D C:\Users\trew1\AppData\Local\cache
2025-06-22 15:12 - 2022-03-06 15:05 - 000000000 ____D C:\Users\trew1\AppData\Roaming\vlc
2025-06-15 23:08 - 2022-03-06 14:01 - 000000000 ____D C:\Users\trew1\AppData\Local\D3DSCache
2025-06-14 06:42 - 2023-06-17 01:08 - 000000000 ____D C:\Users\trew1\AppData\Local\Notepad
2025-06-14 00:16 - 2022-11-08 22:47 - 000002080 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2025-06-14 00:16 - 2022-11-08 22:47 - 000002068 _____ C:\Users\Public\Desktop\Adobe Acrobat.lnk
2025-06-14 00:16 - 2022-08-03 21:08 - 000004562 _____ C:\Windows\system32\Tasks\Adobe Acrobat Update Task
2025-06-14 00:02 - 2022-05-29 19:57 - 000428304 _____ C:\Windows\system32\FNTCACHE.DAT
2025-06-14 00:01 - 2024-07-11 02:18 - 000000000 ____D C:\Windows\system32\compatrel
2025-06-14 00:01 - 2019-12-07 11:14 - 000000000 ___RD C:\Windows\PrintDialog
2025-06-14 00:01 - 2019-12-07 11:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2025-06-14 00:01 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SysWOW64\Dism
2025-06-14 00:01 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SystemResources
2025-06-14 00:01 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\ShellExperiences
2025-06-14 00:01 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\SecureBootUpdates
2025-06-14 00:01 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\PerceptionSimulation
2025-06-14 00:01 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\oobe
2025-06-14 00:01 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\Dism
2025-06-14 00:01 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\ShellExperiences
2025-06-14 00:01 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\ShellComponents
2025-06-14 00:01 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\bcastdvr
2025-06-14 00:01 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\Common Files\System
2025-06-13 21:47 - 2019-12-07 11:03 - 000000000 ____D C:\Windows\CbsTemp
2025-06-13 21:44 - 2022-03-06 13:52 - 003016192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2025-06-13 21:35 - 2022-03-15 13:06 - 000000000 ____D C:\Windows\system32\MRT
2025-06-13 21:28 - 2022-03-15 13:06 - 216824056 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2025-06-13 14:39 - 2022-09-14 17:09 - 000000000 ____D C:\Users\trew1\AppData\Roaming\PrusaSlicer
2025-06-11 18:22 - 2022-03-21 13:56 - 000000000 ____D C:\Users\trew1\AppData\Roaming\Microsoft\Word
2025-06-11 17:35 - 2023-12-18 16:22 - 000000000 ___RD C:\Users\trew1\Documents\Scanned Documents
2025-06-11 17:25 - 2025-03-26 23:19 - 000001717 _____ C:\Users\Public\Desktop\HP Print and Scan Doctor.lnk
2025-06-07 20:30 - 2025-02-01 22:18 - 000000000 ____D C:\Users\trew1\Documents\Výlety
==================== Files in the root of some directories ========
2024-12-27 19:25 - 2024-12-27 19:25 - 000006102 _____ () C:\Program Files (x86)\unins000.dat
2024-12-27 19:25 - 2024-12-27 19:25 - 000905381 _____ () C:\Program Files (x86)\unins000.exe
2022-06-15 08:37 - 2022-08-02 21:07 - 000000745 _____ () C:\Users\trew1\AppData\Local\CastleLinkProps.dat
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
včera jsem se koukal na video na iPrima a klikl jsem dole na liště videa na ikonku s otazníkem. krátce se objevilo cosi o měření a od té chvíle se notebook dramaticky zpomalil, několikrát jsem se snažil ho restartovat, hlásilo to i problém s Windows, pak se umoudřil natolik, že funguje na pohled normálně, ale v Tsak manageru vidím téměř pořád odesílání přes Wi-fi.
Popravdě nevím, jestli notebook něco neodesílá pořád, dokud nebyl ten včerejší problém, tak jsem to nezkoumal.
Raději posílám FRSR. RSIT jsem nedělal, mám Win 10.
Prosím o kontrolu logu a předem děkuji.
Pavel
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28-06-2025
Ran by trew1 (administrator) on DESKTOP-UM04K9K (HP HP Pavilion Gaming Laptop 15-ec2xxx) (30-06-2025 08:14:41)
Running from C:\Users\trew1\Desktop\FRST64.exe
Loaded Profiles: trew1
Platform: Microsoft Windows 10 Home Version 22H2 19045.5965 (X64) Language: Čeština (Česko)
Default browser: Edge
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\egui.exe
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eOppFrame.exe
(C:\Program Files\WindowsApps\AppleInc.AppleDevices_1.1284.24577.0_x64__nzyj5cx40ttqa\AppleMobileDeviceLauncher.exe ->) (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.) C:\Program Files\WindowsApps\AppleInc.AppleDevices_1.1284.24577.0_x64__nzyj5cx40ttqa\AppleMobileDeviceProcess.exe
(DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f2bc3e822f15dc0b\x64\SysInfoCap.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f2bc3e822f15dc0b\x64\BridgeCommunication.exe
(DriverStore\FileRepository\u0367686.inf_amd64_8619bf9fd6ff97a0\B366682\atiesrxx.exe ->) (Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0367686.inf_amd64_8619bf9fd6ff97a0\B366682\atieclxx.exe
(Elaborate Bytes AG -> Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(ETDService.exe ->) (ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronics Corp.) C:\Windows\System32\ETDCtrl.exe
(explorer.exe ->) (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.) C:\Program Files\WindowsApps\AppleInc.AppleDevices_1.1284.24577.0_x64__nzyj5cx40ttqa\AppleMobileDeviceLauncher.exe
(explorer.exe ->) (Hewlett Packard -> HP Inc.) C:\Program Files\HP\HP DeskJet 5000 series\Bin\ScanToPCActivationApp.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <25>
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\OneDrive.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotifyIcon.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0367686.inf_amd64_8619bf9fd6ff97a0\B366682\atiesrxx.exe
(services.exe ->) (ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronics Corp.) C:\Windows\System32\ETDService.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\efwd.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_bdc4c744cf4529f4\x64\TouchpointAnalyticsClientService.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f2bc3e822f15dc0b\x64\AppHelperCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f2bc3e822f15dc0b\x64\DiagsCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f2bc3e822f15dc0b\x64\NetworkCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f2bc3e822f15dc0b\x64\SysInfoCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Windows\System32\DriverStore\FileRepository\hpomencustomcapcomp.inf_amd64_f1b47696babae655\x64\OmenCap\OmenCap.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvhm.inf_amd64_5c197d2d97068bef\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.) C:\Windows\RtkBtManServ.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_b022f456c858acec\RtkAudUService64.exe <2>
(SlySoft, Inc.) [File not signed] C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\25.105.0601.0002\FileCoAuth.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_b022f456c858acec\RtkAudUService64.exe [1269656 2021-07-28] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [292064 2025-05-12] (ESET, spol. s r.o. -> ESET)
HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG -> Elaborate Bytes AG)
HKLM-x32\...\Run: [CloneCDTray] => C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe [57344 2009-01-29] (SlySoft, Inc.) [File not signed]
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-2704875781-386717825-2673586809-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4966720 2025-06-27] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2704875781-386717825-2673586809-1001\...\Run: [HP DeskJet 5000 (NET)] => C:\Program Files\HP\HP DeskJet 5000 series\Bin\ScanToPCActivationApp.exe [4065416 2018-04-19] (Hewlett Packard -> HP Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\137.0.7151.122\Installer\chrmstp.exe [2025-06-27] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Akcelerátor spuštění AutoCADu.lnk [2022-03-13]
ShortcutTarget: Akcelerátor spuštění AutoCADu.lnk -> C:\Program Files (x86)\Common Files\Autodesk Shared\acstart17.exe (Autodesk, Inc -> Autodesk, Inc)
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {7EFC8197-6FF8-4F86-9CD1-3F65DB1028C5} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1580992 2025-03-21] (Adobe Inc. -> Adobe Inc.)
Task: {E44C2F62-D825-4172-9ED5-7C3013F0FCDC} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem138.0.7194.0{CBA40BFB-96B9-40EB-A18E-66710EF3BC34} => C:\Program Files (x86)\Google\GoogleUpdater\138.0.7194.0\updater.exe [7080032 2025-05-22] (Google LLC -> Google LLC)
Task: {F61615A7-072F-40F1-9FE1-63E4B3664DF3} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [79312 2025-05-08] (HP Inc. -> HP Inc.)
Task: {35580093-43AE-4D0D-BAB6-A239C9166564} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor Logon => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [79312 2025-05-08] (HP Inc. -> HP Inc.)
Task: {6608CA28-E150-4366-9726-24188D3A4ADA} - System32\Tasks\HPCustParticipation HP DeskJet 5000 series => C:\Program Files\HP\HP DeskJet 5000 series\Bin\HPCustPartic.exe [6660744 2018-04-19] (Hewlett Packard -> HP Inc.)
Task: {B6F52653-6996-4759-812F-2715A8AADB2E} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28952664 2025-06-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {CBCC028D-DD8F-4AB5-9277-040244552F62} - System32\Tasks\Microsoft\Office\Office Background Push Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE16\opushutil.exe [60392 2025-06-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {B5B00D6B-7F62-4174-91D6-28FC341B1ECE} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28952664 2025-06-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {55989CE6-72F4-4A45-B18E-76ED07DBED41} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [222688 2025-06-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {6D9B70BB-53F0-4977-9793-9CBAA779019C} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [222688 2025-06-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {BC7D044F-3515-48B2-BBF9-91CD19C6AB81} - System32\Tasks\Microsoft\Office\Office Startup Boost => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [222688 2025-06-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {2A4F4192-8BDA-44D7-A278-8E62246939AD} - System32\Tasks\Microsoft\Office\Office Startup Boost Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [222688 2025-06-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {1AEDFD6C-ADC0-42DF-8873-74E51B89BC2F} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4223784 2025-06-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {B7A9F0D6-F6E9-47A0-A338-F40E5369ABD1} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2704875781-386717825-2673586809-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4223784 2025-06-27] (Microsoft Corporation -> Microsoft Corporation)
Task: {6A4F5C90-ABB2-44EB-B7B3-C8FA31FF1A9C} - System32\Tasks\OneDrive Startup Task-S-1-5-21-2704875781-386717825-2673586809-1001 => C:\Program Files\Microsoft OneDrive\25.105.0601.0002\OneDriveLauncher.exe [684352 2025-06-27] (Microsoft Corporation -> Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.43.1
Tcpip\..\Interfaces\{35379157-0ba1-4a3f-aa4c-68d7027ab254}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{35379157-0ba1-4a3f-aa4c-68d7027ab254}: [DhcpDomain] home
Tcpip\..\Interfaces\{c48cec14-6f9e-453e-8bb3-b4d27ff20075}: [DhcpNameServer] 192.168.43.1
Tcpip\..\Interfaces\{c48cec14-6f9e-453e-8bb3-b4d27ff20075}\255646D69602E4F647560283020527F6: [DhcpNameServer] 192.168.43.1
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\trew1\AppData\Local\Microsoft\Edge\User Data\Default [2025-06-30]
Edge Extension: (Dokumenty Google offline) - C:\Users\trew1\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-04-28]
Edge Extension: (Edge relevant text changes) - C:\Users\trew1\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-02-12]
Edge HKLM-x32\...\Edge\Extension: [nkapkmklnmidbbgjaipbgpcnbomnaakc]
FireFox:
========
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2025-06-06] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2025-06-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=3.0.16 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2021-06-18] (VideoLAN -> VideoLAN)
Chrome:
=======
CHR Profile: C:\Users\trew1\AppData\Local\Google\Chrome\User Data\Default [2025-06-29]
CHR Session Restore: Default -> is enabled.
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\trew1\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2025-06-29]
CHR Extension: (Dokumenty Google offline) - C:\Users\trew1\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-06-14]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\trew1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-03-06]
CHR HKU\S-1-5-21-2704875781-386717825-2673586809-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [oombnmpbbhbakfpfgdflaajkhicgfaam]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [174520 2025-03-21] (Adobe Inc. -> Adobe Inc.)
S3 Autodesk Licensing Service; C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe [77944 2022-03-13] (Autodesk, Inc -> Autodesk)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13725240 2025-06-27] (Microsoft Corporation -> Microsoft Corporation)
R2 efwd; C:\Program Files\ESET\ESET Security\efwd.exe [5559152 2025-05-12] (ESET, spol. s r.o. -> ESET)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [4582480 2025-05-12] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [4582480 2025-05-12] (ESET, spol. s r.o. -> ESET)
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\25.105.0601.0002\FileSyncHelper.exe [3620168 2025-06-27] (Microsoft Corporation -> Microsoft Corporation)
R2 HPAppHelperCap; C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f2bc3e822f15dc0b\x64\AppHelperCap.exe [928888 2025-05-06] (HP Inc. -> HP Inc.)
R2 HPDiagsCap; C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f2bc3e822f15dc0b\x64\DiagsCap.exe [927328 2025-05-06] (HP Inc. -> HP Inc.)
R2 HPNetworkCap; C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f2bc3e822f15dc0b\x64\NetworkCap.exe [923256 2025-05-06] (HP Inc. -> HP Inc.)
R2 HPOmenCap; C:\Windows\System32\DriverStore\FileRepository\hpomencustomcapcomp.inf_amd64_f1b47696babae655\x64\OmenCap\OmenCap.exe [755152 2023-10-19] (HP Inc. -> HP Inc.)
R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [243664 2025-05-08] (HP Inc. -> HP Inc.)
R2 HPSysInfoCap; C:\Windows\System32\DriverStore\FileRepository\hpcustomcapcomp.inf_amd64_f2bc3e822f15dc0b\x64\SysInfoCap.exe [928352 2025-05-06] (HP Inc. -> HP Inc.)
R2 HpTouchpointAnalyticsService; C:\Windows\System32\DriverStore\FileRepository\hpanalyticscomp.inf_amd64_bdc4c744cf4529f4\x64\TouchpointAnalyticsClientService.exe [631448 2025-03-26] (HP Inc. -> HP Inc.)
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nvhm.inf_amd64_5c197d2d97068bef\Display.NvContainer\NVDisplay.Container.exe [1275016 2024-12-12] (NVIDIA Corporation -> NVIDIA Corporation)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\25.105.0601.0002\OneDriveUpdaterService.exe [3873096 2025-06-27] (Microsoft Corporation -> Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3004048 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103384 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AmUStor; C:\Windows\system32\drivers\AmUStorU.sys [143904 2020-05-11] (Alcorlink Corp. -> )
S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\Windows\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [File not signed]
S3 BTHMODEM; C:\Windows\System32\drivers\bthmodem.sys [76800 2019-12-07] (Microsoft Corporation) [File not signed]
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [227224 2025-05-12] (ESET, spol. s r.o. -> ESET)
R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [121816 2025-05-12] (Microsoft Windows Hardware Compatibility Publisher -> ESET)
S0 eelam; C:\Windows\System32\DRIVERS\eelam.sys [16336 2022-09-05] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [266944 2025-05-12] (ESET, spol. s r.o. -> ESET)
R2 ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [57304 2025-05-12] (ESET, spol. s r.o. -> ESET)
R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft Inc. -> SlySoft, Inc.)
R3 ElbyCDFL; C:\Windows\SysWOW64\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft Inc. -> SlySoft, Inc.)
R1 epfw; C:\Windows\system32\DRIVERS\epfw.sys [86200 2025-05-12] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [128512 2025-05-12] (ESET, spol. s r.o. -> ESET)
R3 HPCustomCapDriver; C:\Windows\System32\DriverStore\FileRepository\hpcustomcapdriver.inf_amd64_1421dec2010cc057\x64\hpcustomcapdriver.sys [18984 2024-05-07] (Microsoft Windows Hardware Compatibility Publisher -> HP Inc.)
R3 HPOmenCustomCapDriver; C:\Windows\System32\DriverStore\FileRepository\hpomencustomcapdriver.inf_amd64_326f2e1d16385daf\x64\hpomencustomcapdriver.sys [33464 2018-12-19] (HP Inc. -> HP Inc.)
S3 Ser2pl; C:\Windows\system32\DRIVERS\ser2pl64.sys [328784 2023-03-06] (Microsoft Windows Hardware Compatibility Publisher -> Prolific Technology Inc.)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [174112 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R1 VBoxNetAdp; C:\Windows\system32\DRIVERS\VBoxNetAdp6.sys [131144 2017-04-18] (Oracle Corporation -> Oracle Corporation)
R1 VBoxNetLwf; C:\Windows\system32\DRIVERS\VBoxNetLwf.sys [205952 2017-04-18] (Oracle Corporation -> Oracle Corporation)
R3 ViGEmBus; C:\Windows\System32\DriverStore\FileRepository\vigembus.inf_amd64_8a927fc43d8a7838\x64\ViGEmBus.sys [91432 2020-04-21] (HP Inc. -> Benjamin Hoeglinger-Stelzer)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [54200 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessButtonDriver64; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [40200 2023-11-17] (HP Inc. -> HP)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-06-30 08:14 - 2025-06-30 08:15 - 000020668 _____ C:\Users\trew1\Desktop\FRST.txt
2025-06-30 08:14 - 2025-06-30 08:15 - 000000000 ____D C:\FRST
2025-06-30 08:11 - 2025-06-30 08:12 - 002407936 _____ (Farbar) C:\Users\trew1\Desktop\FRST64.exe
2025-06-29 23:14 - 2025-06-29 23:14 - 996698027 _____ C:\Windows\MEMORY.DMP
2025-06-29 23:14 - 2025-06-29 23:14 - 001430884 _____ C:\Windows\Minidump\062925-9062-01.dmp
2025-06-27 21:30 - 2025-06-27 21:30 - 000000090 _____ C:\logUploaderSettings_temp.ini
2025-06-27 21:30 - 2025-06-27 21:30 - 000000090 _____ C:\logUploaderSettings.ini
2025-06-23 14:31 - 2025-06-23 14:31 - 000000000 ____D C:\Users\trew1\AppData\Local\FreeCAD
2025-06-23 14:23 - 2025-06-23 14:23 - 000001930 _____ C:\Users\Public\Desktop\FreeCAD 1.0.lnk
2025-06-23 14:23 - 2025-06-23 14:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeCAD 1.0
2025-06-23 14:21 - 2025-06-23 14:23 - 000000000 ____D C:\Program Files\FreeCAD 1.0
2025-06-23 13:33 - 2025-06-23 13:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2025-06-23 13:33 - 2025-06-23 13:33 - 000000000 ____D C:\Program Files\7-Zip
2025-06-23 13:32 - 2025-06-23 13:33 - 000000000 ____D C:\Users\trew1\Documents\ZIP
2025-06-23 13:27 - 2025-06-23 14:19 - 000000000 ____D C:\Users\trew1\Documents\FreeCAD
2025-06-23 13:27 - 2025-06-23 13:27 - 000000000 ____D C:\Users\trew1\Documents\Nová složka
2025-06-13 21:35 - 2025-06-13 21:35 - 000000000 ___HD C:\$WinREAgent
2025-06-11 17:39 - 2025-06-11 17:41 - 000000000 ____D C:\Users\trew1\Documents\Máma
2025-06-11 17:28 - 2025-06-11 17:28 - 000000000 ____D C:\Users\trew1\Documents\Fax
2025-06-08 13:04 - 2025-06-08 13:04 - 007754473 _____ C:\Users\trew1\Downloads\navod-na-pouziti.pdf
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2025-06-30 08:12 - 2022-05-11 13:38 - 000714500 _____ C:\Windows\system32\perfh005.dat
2025-06-30 08:12 - 2022-05-11 13:38 - 000144182 _____ C:\Windows\system32\perfc005.dat
2025-06-30 08:12 - 2022-03-06 13:55 - 000005620 _____ C:\Windows\system32\PerfStringBackup.INI
2025-06-30 08:09 - 2022-03-06 14:03 - 000000000 ___RD C:\Users\trew1\OneDrive
2025-06-30 08:09 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-06-30 08:07 - 2022-03-06 13:57 - 000000000 ____D C:\ProgramData\NVIDIA
2025-06-30 08:07 - 2022-03-06 13:49 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2025-06-30 08:07 - 2022-03-06 13:49 - 000000000 ____D C:\Windows\system32\SleepStudy
2025-06-30 08:07 - 2021-06-25 20:10 - 000008192 ___SH C:\DumpStack.log.tmp
2025-06-29 23:14 - 2022-07-22 16:08 - 000000000 ____D C:\Windows\Minidump
2025-06-29 23:14 - 2019-12-07 11:13 - 000000000 ____D C:\Windows\INF
2025-06-29 23:12 - 2022-03-06 13:57 - 000000000 ____D C:\Users\trew1
2025-06-29 23:08 - 2022-04-01 13:42 - 000000000 ____D C:\Windows\SystemTemp
2025-06-29 23:08 - 2019-12-07 11:03 - 000786432 _____ C:\Windows\system32\config\BBI
2025-06-29 23:03 - 2022-03-06 15:18 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2025-06-29 23:03 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2025-06-29 23:03 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\AppReadiness
2025-06-29 23:02 - 2022-03-26 11:12 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2025-06-29 23:02 - 2022-03-06 14:01 - 000000000 ____D C:\Users\trew1\AppData\Local\Packages
2025-06-29 20:02 - 2022-03-06 13:49 - 000002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-06-29 20:02 - 2022-03-06 13:49 - 000002281 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2025-06-28 00:24 - 2022-03-06 15:00 - 000002254 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2025-06-28 00:24 - 2022-03-06 15:00 - 000002213 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2025-06-27 21:30 - 2025-02-07 21:06 - 000003546 _____ C:\Windows\system32\Tasks\OneDrive Startup Task-S-1-5-21-2704875781-386717825-2673586809-1001
2025-06-27 21:30 - 2022-03-22 12:32 - 000003194 _____ C:\Windows\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2025-06-27 21:30 - 2022-03-22 12:32 - 000002137 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-06-27 21:30 - 2022-03-06 14:03 - 000003592 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2704875781-386717825-2673586809-1001
2025-06-27 20:03 - 2022-03-29 15:37 - 000000000 ____D C:\Users\trew1\AppData\Roaming\Microsoft\Excel
2025-06-27 19:55 - 2022-03-13 12:29 - 000000000 ____D C:\Users\trew1\Documents\Byt_SVJ_Údržba v domě
2025-06-23 22:31 - 2025-02-04 21:07 - 000000000 ____D C:\Users\trew1\AppData\Local\LightBurn
2025-06-23 16:07 - 2024-03-07 15:51 - 000000000 ____D C:\Users\trew1\AppData\Local\CrashDumps
2025-06-23 15:06 - 2022-09-21 14:41 - 000000000 ____D C:\Users\trew1\AppData\Roaming\FreeCAD
2025-06-23 14:10 - 2022-09-18 18:24 - 000000000 ____D C:\Users\trew1\AppData\Local\cache
2025-06-22 15:12 - 2022-03-06 15:05 - 000000000 ____D C:\Users\trew1\AppData\Roaming\vlc
2025-06-15 23:08 - 2022-03-06 14:01 - 000000000 ____D C:\Users\trew1\AppData\Local\D3DSCache
2025-06-14 06:42 - 2023-06-17 01:08 - 000000000 ____D C:\Users\trew1\AppData\Local\Notepad
2025-06-14 00:16 - 2022-11-08 22:47 - 000002080 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2025-06-14 00:16 - 2022-11-08 22:47 - 000002068 _____ C:\Users\Public\Desktop\Adobe Acrobat.lnk
2025-06-14 00:16 - 2022-08-03 21:08 - 000004562 _____ C:\Windows\system32\Tasks\Adobe Acrobat Update Task
2025-06-14 00:02 - 2022-05-29 19:57 - 000428304 _____ C:\Windows\system32\FNTCACHE.DAT
2025-06-14 00:01 - 2024-07-11 02:18 - 000000000 ____D C:\Windows\system32\compatrel
2025-06-14 00:01 - 2019-12-07 11:14 - 000000000 ___RD C:\Windows\PrintDialog
2025-06-14 00:01 - 2019-12-07 11:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2025-06-14 00:01 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SysWOW64\Dism
2025-06-14 00:01 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SystemResources
2025-06-14 00:01 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\ShellExperiences
2025-06-14 00:01 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\SecureBootUpdates
2025-06-14 00:01 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\PerceptionSimulation
2025-06-14 00:01 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\oobe
2025-06-14 00:01 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\Dism
2025-06-14 00:01 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\ShellExperiences
2025-06-14 00:01 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\ShellComponents
2025-06-14 00:01 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\bcastdvr
2025-06-14 00:01 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\Common Files\System
2025-06-13 21:47 - 2019-12-07 11:03 - 000000000 ____D C:\Windows\CbsTemp
2025-06-13 21:44 - 2022-03-06 13:52 - 003016192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2025-06-13 21:35 - 2022-03-15 13:06 - 000000000 ____D C:\Windows\system32\MRT
2025-06-13 21:28 - 2022-03-15 13:06 - 216824056 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2025-06-13 14:39 - 2022-09-14 17:09 - 000000000 ____D C:\Users\trew1\AppData\Roaming\PrusaSlicer
2025-06-11 18:22 - 2022-03-21 13:56 - 000000000 ____D C:\Users\trew1\AppData\Roaming\Microsoft\Word
2025-06-11 17:35 - 2023-12-18 16:22 - 000000000 ___RD C:\Users\trew1\Documents\Scanned Documents
2025-06-11 17:25 - 2025-03-26 23:19 - 000001717 _____ C:\Users\Public\Desktop\HP Print and Scan Doctor.lnk
2025-06-07 20:30 - 2025-02-01 22:18 - 000000000 ____D C:\Users\trew1\Documents\Výlety
==================== Files in the root of some directories ========
2024-12-27 19:25 - 2024-12-27 19:25 - 000006102 _____ () C:\Program Files (x86)\unins000.dat
2024-12-27 19:25 - 2024-12-27 19:25 - 000905381 _____ () C:\Program Files (x86)\unins000.exe
2022-06-15 08:37 - 2022-08-02 21:07 - 000000745 _____ () C:\Users\trew1\AppData\Local\CastleLinkProps.dat
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================