Stránka 1 z 1

Prosím o kontrolu

Napsal: 20 bře 2026 17:39
od David27
Zdravím,Prosím o kontrolu.
Děkuji.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-03-2026
Ran by david (administrator) on DESKTOP-IJSLQ8R (Micro-Star International Co., Ltd MS-7B86) (20-03-2026 17:31:06)
Running from C:\Users\david\Desktop\FRST64.exe
Loaded Profiles: david
Platform: Microsoft Windows 11 Home Version 25H2 26200.8037 (X64) Language: Čeština (Česko)
Default browser: Edge
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eOppFrame.exe
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eServiceHost.exe <2>
(C:\ProgramData\Wargaming.net\GameCenter\wgc.exe ->) (Wargaming Group Limited -> Wargaming.net) C:\ProgramData\Wargaming.net\GameCenter\dlls\wgc_renderer_host.exe <5>
(C:\ProgramData\Wargaming.net\GameCenter\wgc.exe ->) (Wargaming.net Limited -> Wargaming.net) C:\ProgramData\Wargaming.net\GameCenter\wargamingerrormonitor.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\OneDrive.exe
(explorer.exe ->) (Wargaming Group Limited -> Wargaming.net) C:\ProgramData\Wargaming.net\GameCenter\wgc.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <5>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\26.032.0217.0003\OneDrive.Sync.Service.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Canon Inc. -> ) C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\efwd.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\26.032.0217.0003\FileSyncHelper.exe
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MidiSrv.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_4bf4c17fa8a478b5\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_0b6ff136fecebab7\RtkAudUService64.exe <2>
(services.exe ->) (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(services.exe ->) (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe
(services.exe ->) (SteelSeries France SASU -> Nahimic) C:\Windows\System32\NahimicService.exe
(SteelSeries France SASU -> A-Volute) C:\Users\david\AppData\Local\NhNotifSys\nahimic\nahimicNotifSys.exe
(svchost.exe ->) (21E1B422-257A-44A2-9C8F-379165856473 -> ) C:\Program Files\WindowsApps\A-Volute.Nahimic_1.10.9.0_x64__w2gh52qy24etm\Nahimic3.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\SDXHelper.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\26.032.0217.0003\FileCoAuth.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.229.1.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <4>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\NgcIso.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppActions.exe
(svchost.exe ->) (SteelSeries France SASU -> Nahimic) C:\Windows\System32\NahimicSvc64.exe
(svchost.exe ->) (SteelSeries France SASU -> Nahimic) C:\Windows\SysWOW64\NahimicSvc32.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_0b6ff136fecebab7\RtkAudUService64.exe [1650016 2023-03-15] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [285616 2025-11-28] (ESET, spol. s r.o. -> ESET)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-21-2920095854-1669752291-3635278505-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4746600 2026-03-14] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2920095854-1669752291-3635278505-1001\...\Run: [Wargaming.net Game Center] => C:\ProgramData\Wargaming.net\GameCenter\wgc.exe [2589432 2026-03-19] (Wargaming Group Limited -> Wargaming.net)
HKU\S-1-5-21-2920095854-1669752291-3635278505-1001\...\Run: [Proton VPN] => C:\Program Files\Proton\VPN\ProtonVPN.Launcher.exe [18781032 2025-11-28] (Proton AG -> ProtonVPN)
HKU\S-1-5-21-2920095854-1669752291-3635278505-1002\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4746600 2026-03-14] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2920095854-1669752291-3635278505-1002\...\Run: [MicrosoftEdgeAutoLaunch_976B15C38270B7405518FFD29BBCD6E4] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [5001296 2026-03-15] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Windows x64\Print Processors\Canon TS3300 series Print Processor: C:\Windows\System32\spool\prtprocs\x64\CNMPDG3.DLL [506368 2023-06-05] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)
HKLM\...\Print\Monitors\Canon BJ Language Monitor TS3300 series: C:\Windows\system32\CNMLMG3.DLL [1334784 2023-06-05] (Microsoft Windows Hardware Compatibility Publisher -> CANON INC.)

==================== Scheduled Tasks (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {45C4F61A-1C24-4A35-A626-A5CD8767EEAD} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1612800 2026-01-23] (Adobe Inc. -> Adobe Inc.)
Task: {20CC335E-A06F-4DDD-BB58-EDF4BBA788C9} - System32\Tasks\Microsoft\Office\Office Actions Server => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\ActionsServer\ActionsServer.exe [11419480 2025-10-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {491BDBB5-5DCD-4416-A3B4-B71FE776493F} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [29025120 2025-10-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {872A580E-273F-476E-BFBC-C15AE694BABC} - System32\Tasks\Microsoft\Office\Office Background Push Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\opushutil.exe [61280 2025-10-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {A48ED4ED-CA7A-4991-9515-C1530E9D56EB} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [29025120 2025-10-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {94E92F3A-59C3-4B3E-AC29-89CE4609F31C} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [224520 2025-10-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {71FBAE62-6500-42E4-B4EB-8451C8A68866} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [224520 2025-10-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {B1AADECF-5E91-4F9C-BB81-D3D5972710CF} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-2920095854-1669752291-3635278505-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [707200 2026-03-11] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {CA13F34A-2E69-4611-873D-BCAFB4B801BF} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-2920095854-1669752291-3635278505-1002 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [707200 2026-03-11] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {67B73CDE-D8EC-43A1-BA0E-2E4BCCB6FEE7} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [33920 2026-03-11] (Mozilla Corporation -> Mozilla Foundation)
Task: {653DA56B-3946-43B8-8423-1C6A61DC2AEF} - System32\Tasks\NahimicSvc32Run => C:\Windows\SysWOW64\NahimicSvc32.exe [1118128 2025-01-14] (SteelSeries France SASU -> Nahimic)
Task: {D59DBDC6-EC3D-4181-BC12-4C81E0D0A90C} - System32\Tasks\NahimicSvc64Run => C:\Windows\system32\NahimicSvc64.exe [1438128 2025-01-14] (SteelSeries France SASU -> Nahimic)
Task: {E3F98106-76B4-41BA-AA71-25D2C72C6C41} - System32\Tasks\NahimicTask32 => C:\Windows\System32\..\SysWOW64\NahimicSvc32.exe [1118128 0] (SteelSeries France SASU -> Nahimic)
Task: {9E7A33C5-47E6-4F9B-903C-8D69392D6E8C} - System32\Tasks\NahimicTask64 => C:\Windows\System32\.\NahimicSvc64.exe [1438128 0] (SteelSeries France SASU -> Nahimic)
Task: {A360E9BA-2A6D-48F8-89FB-D796507AEE20} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4428648 2026-03-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {0C642580-5160-4C97-8B9B-F25FCAE3A971} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2920095854-1669752291-3635278505-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4428648 2026-03-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {786121F6-529F-43B5-9307-AFCE5036EF9B} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2920095854-1669752291-3635278505-1002 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4428648 2026-03-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {2ACBAE90-3CBA-46D8-8AA6-DC21E9653A5E} - System32\Tasks\OneDrive Startup Task-S-1-5-21-2920095854-1669752291-3635278505-1001 => C:\Program Files\Microsoft OneDrive\26.032.0217.0003\OneDriveLauncher.exe [757608 2026-03-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {96BD36BE-0E0A-4C02-8ECE-B629D29F6993} - System32\Tasks\OneDrive Startup Task-S-1-5-21-2920095854-1669752291-3635278505-1002 => C:\Program Files\Microsoft OneDrive\26.032.0217.0003\OneDriveLauncher.exe [757608 2026-03-14] (Microsoft Corporation -> Microsoft Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{597a1605-d190-4301-8c5e-d20e46aa83ab}: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF TaskBarID: 308046B0AF4A39CB -> C:\Program Files\Mozilla Firefox
FF DefaultProfile: e4rv2yyu.default-release -> 308046B0AF4A39CB
FF ProfilePath: C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\loa9ywao.default [2025-06-10]
FF ProfilePath: C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\e4rv2yyu.default-release [2026-03-20]
FF Homepage: Mozilla\Firefox\Profiles\e4rv2yyu.default-release -> www.seznam.cz
FF Extension: (ESET Browser Privacy & Security) - C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\e4rv2yyu.default-release\Extensions\browserextension@eset.com.xpi [2025-11-17]
FF Extension: (New Tab) - C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\e4rv2yyu.default-release\Extensions\newtab@mozilla.org.xpi [2026-03-12]
FF Extension: (Google Translator for Firefox) - C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\e4rv2yyu.default-release\Extensions\translator@zoli.bod.xpi [2025-05-29]
FF Extension: (Lion Power) - C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\e4rv2yyu.default-release\Extensions\{7044fa00-e6bb-40d6-88a2-e087ac3f53e6}.xpi [2025-05-29]
FF Extension: (Firefox B) - C:\Users\david\AppData\Roaming\Mozilla\Firefox\Profiles\e4rv2yyu.default-release\Extensions\{ac40163c-8804-4dad-90fc-e25ebd6e9a57}.xpi [2025-05-29]
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2025-09-07] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2026-03-08] (Adobe Inc. -> Adobe Systems Inc.)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2026-03-20]

Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\david\AppData\Local\Microsoft\Edge\User Data\Default [2026-03-20]
Edge HomePage: Default -> hxxp://www.seznam.cz/
Edge StartupUrls: Default -> "hxxps://www.seznam.cz/"
Edge Extension: (Dokumenty Google offline) - C:\Users\david\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-03-03]
Edge Extension: (Edge relevant text changes) - C:\Users\david\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2025-05-29]
Edge Extension: (ESET Browser Privacy & Security) - C:\Users\david\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\nkapkmklnmidbbgjaipbgpcnbomnaakc [2025-11-12]
Edge HKLM-x32\...\Edge\Extension: [nkapkmklnmidbbgjaipbgpcnbomnaakc]

Chrome:
=======
CHR HKU\S-1-5-21-2920095854-1669752291-3635278505-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [180216 2026-01-23] (Adobe Inc. -> Adobe Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13288288 2025-10-07] (Microsoft Corporation -> Microsoft Corporation)
R2 efwd; C:\Program Files\ESET\ESET Security\efwd.exe [5543856 2025-11-28] (ESET, spol. s r.o. -> ESET)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [4980040 2025-11-28] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [4980040 2025-11-28] (ESET, spol. s r.o. -> ESET)
R3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\26.032.0217.0003\FileSyncHelper.exe [3600744 2026-03-14] (Microsoft Corporation -> Microsoft Corporation)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [460488 2024-04-03] (Canon Inc. -> )
S3 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\MpDefenderCoreService.exe [2067464 2026-02-14] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NahimicService; C:\Windows\System32\NahimicService.exe [1910704 2025-01-14] (SteelSeries France SASU -> Nahimic)
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_4bf4c17fa8a478b5\Display.NvContainer\NVDisplay.Container.exe [1702632 2026-03-06] (NVIDIA Corporation -> NVIDIA Corporation)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\26.032.0217.0003\OneDriveUpdaterService.exe [3995496 2026-03-14] (Microsoft Corporation -> Microsoft Corporation)
S3 ProtonVPN Service; C:\Program Files\Proton\VPN\v4.3.9\ProtonVPNService.exe [477424 2025-11-28] (Proton AG -> ProtonVPN)
S3 ProtonVPN WireGuard; C:\Program Files\Proton\VPN\v4.3.9\ProtonVPN.WireGuardService.exe [476912 2025-11-28] (Proton AG -> ProtonVPN)
R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2024-10-18] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.)
R2 ss_conn_service2; C:\Program Files\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe [933432 2024-10-18] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\NisSrv.exe [4435096 2026-02-14] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26010.5-0\MsMpEng.exe [290744 2026-02-14] (Microsoft Windows Publisher -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 amdgpio3; C:\Windows\System32\drivers\amdgpio3.sys [33592 2024-09-12] (ASMedia Technology Inc. -> Advanced Micro Devices, Inc)
S3 BthA2dp; C:\Windows\System32\drivers\BthA2dp.sys [602112 2025-09-10] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\Windows\System32\drivers\bthhfenum.sys [204800 2025-09-10] (Microsoft Corporation) [File not signed]
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus2.sys [175824 2024-10-18] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [232928 2025-10-21] (ESET, spol. s r.o. -> ESET)
R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [139904 2025-10-21] (Microsoft Windows Hardware Compatibility Publisher -> ESET)
S0 eelam; C:\Windows\System32\DRIVERS\eelam.sys [17840 2025-11-28] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [273768 2025-10-21] (ESET, spol. s r.o. -> ESET)
R2 ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [57368 2025-10-21] (ESET, spol. s r.o. -> ESET)
R1 epfw; C:\Windows\system32\DRIVERS\epfw.sys [86800 2025-10-21] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [126552 2025-10-21] (ESET, spol. s r.o. -> ESET)
S3 KslD; C:\Windows\System32\drivers\wd\KslD.sys [82352 2026-02-14] (Microsoft Windows -> Microsoft Corporation)
R3 Nahimic_Mirroring; C:\Windows\System32\drivers\Nahimic_Mirroring.sys [94784 2022-06-02] (A-Volute SAS -> Windows (R) Win 7 DDK provider)
S3 ProtonVPNCallout; C:\Program Files\Proton\VPN\v4.3.9\Resources\ProtonVPN.CalloutDriver.sys [41416 2025-11-20] (Proton AG -> Proton AG)
S3 rtcx21; C:\Windows\System32\DriverStore\FileRepository\rtcx21x64.inf_amd64_feec7a9662e785f0\rtcx21x64.sys [539648 2024-03-28] (Microsoft Windows -> Realtek)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [174264 2024-10-18] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 WdBoot; C:\Windows\system32\drivers\wd\WdBoot.sys [21888 2026-02-14] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\wd\WdFilter.sys [635272 2026-02-14] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [102832 2026-02-14] (Microsoft Windows -> Microsoft Corporation)
S3 wintun; C:\Windows\System32\drivers\wintun.sys [29592 2025-08-30] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
S3 WireGuard; C:\Windows\System32\drivers\wireguard.sys [489368 2025-08-28] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2026-03-20 17:31 - 2026-03-20 17:31 - 000021626 _____ C:\Users\david\Desktop\FRST.txt
2026-03-20 17:29 - 2026-03-20 17:31 - 000000000 ____D C:\FRST
2026-03-20 17:28 - 2026-03-20 17:28 - 002445312 _____ (Farbar) C:\Users\david\Desktop\FRST64.exe
2026-03-20 09:37 - 2026-03-20 09:37 - 000677108 _____ C:\Windows\system32\perfh005.dat
2026-03-20 09:37 - 2026-03-20 09:37 - 000144960 _____ C:\Windows\system32\perfc005.dat
2026-03-17 17:48 - 2026-03-17 17:48 - 000000000 ____D C:\Windows\LastGood.Tmp
2026-03-17 17:44 - 2026-03-06 16:21 - 002421296 _____ C:\Windows\system32\vulkaninfo-1-999-0-0-0.exe
2026-03-17 17:44 - 2026-03-06 16:21 - 002421296 _____ C:\Windows\system32\vulkaninfo.exe
2026-03-17 17:44 - 2026-03-06 16:21 - 001923120 _____ C:\Windows\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2026-03-17 17:44 - 2026-03-06 16:21 - 001923120 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2026-03-17 17:44 - 2026-03-06 16:21 - 001625648 _____ C:\Windows\system32\vulkan-1-999-0-0-0.dll
2026-03-17 17:44 - 2026-03-06 16:21 - 001625648 _____ C:\Windows\system32\vulkan-1.dll
2026-03-17 17:44 - 2026-03-06 16:21 - 001434672 _____ C:\Windows\SysWOW64\vulkan-1-999-0-0-0.dll
2026-03-17 17:44 - 2026-03-06 16:21 - 001434672 _____ C:\Windows\SysWOW64\vulkan-1.dll
2026-03-17 17:44 - 2026-03-06 16:21 - 000478952 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2026-03-17 17:44 - 2026-03-06 16:21 - 000375016 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2026-03-17 17:44 - 2026-03-06 16:17 - 028057832 _____ C:\Windows\system32\nvidia-pcc.exe
2026-03-17 17:44 - 2026-03-06 16:17 - 001621224 _____ (NVIDIA Corporation) C:\Windows\system32\nvidia-smi.exe
2026-03-17 17:44 - 2026-03-06 16:17 - 001583336 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2026-03-17 17:44 - 2026-03-06 16:17 - 001385704 _____ (NVIDIA Corporation) C:\Windows\system32\nvml.dll
2026-03-17 17:44 - 2026-03-06 16:17 - 001231592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2026-03-17 17:44 - 2026-03-06 16:17 - 000675048 _____ (NVIDIA Corporation) C:\Windows\system32\nvofapi64.dll
2026-03-17 17:44 - 2026-03-06 16:17 - 000509160 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvofapi.dll
2026-03-17 17:44 - 2026-03-06 16:16 - 002328296 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2026-03-17 17:44 - 2026-03-06 16:16 - 001724136 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2026-03-17 17:44 - 2026-03-06 16:16 - 001064680 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2026-03-17 17:44 - 2026-03-06 16:16 - 000820456 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2026-03-17 17:44 - 2026-03-06 16:15 - 029136616 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2026-03-17 17:44 - 2026-03-06 16:15 - 021713128 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2026-03-17 17:44 - 2026-03-06 16:15 - 008441064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2026-03-17 17:44 - 2026-03-06 16:15 - 005925096 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2026-03-17 17:44 - 2026-03-06 16:15 - 005674216 _____ (NVIDIA Corporation) C:\Windows\system32\nvcudadebugger.dll
2026-03-17 17:44 - 2026-03-06 16:15 - 004466920 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2026-03-17 17:44 - 2026-03-06 16:15 - 000469736 _____ (NVIDIA Corporation) C:\Windows\system32\nvdebugdump.exe
2026-03-17 17:44 - 2026-03-06 16:14 - 005516480 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2026-03-17 17:44 - 2026-03-06 16:14 - 005011440 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2026-03-17 17:44 - 2026-03-06 16:14 - 000853736 _____ (NVIDIA Corporation) C:\Windows\system32\MCU.exe
2026-03-17 17:44 - 2026-03-05 05:46 - 000162206 _____ C:\Windows\system32\nvinfo.pb
2026-03-14 15:07 - 2026-03-20 15:40 - 000000000 ____D C:\Windows\CbsTemp
2026-03-11 10:11 - 2026-03-11 10:11 - 000083946 _____ C:\Windows\SysWOW64\ctac.json
2026-03-11 10:11 - 2026-03-11 10:11 - 000083946 _____ C:\Windows\system32\ctac.json
2026-03-11 10:11 - 2026-03-11 10:11 - 000036382 _____ C:\Windows\SysWOW64\IntegratedServicesRegionPolicySet.json
2026-03-11 10:11 - 2026-03-11 10:11 - 000036382 _____ C:\Windows\system32\IntegratedServicesRegionPolicySet.json
2026-03-11 09:48 - 2026-03-11 10:37 - 000000000 ____D C:\Program Files\Mozilla Firefox
2026-03-03 18:35 - 2026-03-03 18:35 - 000000000 ____D C:\Windows\system32\Drivers\NVIDIA Corporation
2026-03-03 18:31 - 2026-02-28 00:32 - 000127208 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2026-03-20 17:31 - 2025-05-29 14:57 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2026-03-20 17:16 - 2025-05-29 12:32 - 000000000 ____D C:\Windows\system32\SleepStudy
2026-03-20 16:50 - 2024-04-01 08:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-03-20 11:24 - 2025-10-19 19:12 - 000000000 ____D C:\Program Files\CrystalDiskInfo
2026-03-20 09:37 - 2025-05-29 12:41 - 001603790 _____ C:\Windows\system32\PerfStringBackup.INI
2026-03-20 09:37 - 2024-04-01 08:26 - 000000000 ____D C:\Windows\SystemTemp
2026-03-20 09:37 - 2024-04-01 08:24 - 000000000 ____D C:\Windows\INF
2026-03-20 09:32 - 2025-06-24 19:01 - 000003108 _____ C:\Windows\system32\Tasks\NahimicTask32
2026-03-20 09:32 - 2025-06-24 19:01 - 000003088 _____ C:\Windows\system32\Tasks\NahimicTask64
2026-03-20 09:32 - 2025-05-29 13:01 - 000000000 ____D C:\ProgramData\NVIDIA
2026-03-20 09:32 - 2025-05-29 12:50 - 000000000 ___RD C:\Users\david\OneDrive
2026-03-20 09:32 - 2025-05-29 12:46 - 000000000 ____D C:\Users\david\AppData\Local\Packages
2026-03-20 09:32 - 2025-05-29 12:32 - 000074752 _____ C:\Windows\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2026-03-20 09:32 - 2025-05-29 12:32 - 000012288 ___SH C:\DumpStack.log.tmp
2026-03-20 09:32 - 2025-05-29 12:32 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2026-03-20 09:32 - 2024-04-01 08:26 - 000000000 ____D C:\Windows\AppReadiness
2026-03-19 21:56 - 2024-04-01 08:21 - 000524288 _____ C:\Windows\system32\config\BBI
2026-03-19 21:39 - 2024-04-01 08:26 - 000000000 ___HD C:\Program Files\WindowsApps
2026-03-19 19:39 - 2025-06-13 12:55 - 000004212 _____ C:\Windows\system32\Tasks\User_Feed_Synchronization-{29C9C97D-9D0C-4060-AB82-367C056F9AC0}
2026-03-19 12:56 - 2025-05-29 12:47 - 000000000 ____D C:\Users\david\AppData\Local\D3DSCache
2026-03-18 14:19 - 2025-07-21 20:40 - 000000000 ____D C:\Users\David Šplíchal
2026-03-18 10:22 - 2025-05-29 12:32 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-03-18 10:22 - 2025-05-29 12:32 - 000002274 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2026-03-17 20:14 - 2025-05-29 12:40 - 000000000 ____D C:\Users\david
2026-03-17 17:48 - 2025-06-07 14:10 - 000000000 ____D C:\Users\david\AppData\Local\NVIDIA
2026-03-15 09:22 - 2025-05-29 12:34 - 000000000 ____D C:\ProgramData\Packages
2026-03-15 08:59 - 2025-05-31 17:02 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2026-03-14 10:33 - 2025-07-26 07:40 - 000003552 _____ C:\Windows\system32\Tasks\OneDrive Startup Task-S-1-5-21-2920095854-1669752291-3635278505-1002
2026-03-14 10:33 - 2025-07-21 20:42 - 000003596 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2920095854-1669752291-3635278505-1002
2026-03-14 10:33 - 2025-05-31 17:02 - 000003596 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2920095854-1669752291-3635278505-1001
2026-03-14 10:33 - 2025-05-31 17:02 - 000003194 _____ C:\Windows\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2026-03-14 10:33 - 2025-05-31 17:02 - 000002023 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-03-14 10:33 - 2025-05-29 12:51 - 000003552 _____ C:\Windows\system32\Tasks\OneDrive Startup Task-S-1-5-21-2920095854-1669752291-3635278505-1001
2026-03-12 09:50 - 2025-11-19 22:29 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader.lnk
2026-03-12 09:50 - 2025-11-19 22:29 - 000002124 _____ C:\Users\Public\Desktop\Acrobat Reader.lnk
2026-03-11 10:39 - 2025-10-15 17:35 - 000001607 _____ C:\Windows\system32\config\VSMIDK
2026-03-11 10:38 - 2025-05-29 12:32 - 000344016 _____ C:\Windows\system32\FNTCACHE.DAT
2026-03-11 10:37 - 2025-05-29 14:56 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2026-03-11 10:37 - 2024-10-05 01:19 - 000000000 ____D C:\Windows\InboxApps
2026-03-11 10:37 - 2024-04-01 17:30 - 000000000 ____D C:\Windows\system32\Microsoft-Edge-WebView
2026-03-11 10:37 - 2024-04-01 08:26 - 000000000 ___SD C:\Windows\system32\F12
2026-03-11 10:37 - 2024-04-01 08:26 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2026-03-11 10:37 - 2024-04-01 08:26 - 000000000 ____D C:\Windows\UUS
2026-03-11 10:37 - 2024-04-01 08:26 - 000000000 ____D C:\Windows\SysWOW64\WinMetadata
2026-03-11 10:37 - 2024-04-01 08:26 - 000000000 ____D C:\Windows\SysWOW64\setup
2026-03-11 10:37 - 2024-04-01 08:26 - 000000000 ____D C:\Windows\SysWOW64\oobe
2026-03-11 10:37 - 2024-04-01 08:26 - 000000000 ____D C:\Windows\SysWOW64\Dism
2026-03-11 10:37 - 2024-04-01 08:26 - 000000000 ____D C:\Windows\SystemResources
2026-03-11 10:37 - 2024-04-01 08:26 - 000000000 ____D C:\Windows\system32\WinMetadata
2026-03-11 10:37 - 2024-04-01 08:26 - 000000000 ____D C:\Windows\system32\ShellExperiences
2026-03-11 10:37 - 2024-04-01 08:26 - 000000000 ____D C:\Windows\system32\setup
2026-03-11 10:37 - 2024-04-01 08:26 - 000000000 ____D C:\Windows\system32\SecureBootUpdates
2026-03-11 10:37 - 2024-04-01 08:26 - 000000000 ____D C:\Windows\system32\oobe
2026-03-11 10:37 - 2024-04-01 08:26 - 000000000 ____D C:\Windows\system32\migwiz
2026-03-11 10:37 - 2024-04-01 08:26 - 000000000 ____D C:\Windows\system32\Dism
2026-03-11 10:37 - 2024-04-01 08:26 - 000000000 ____D C:\Windows\system32\appraiser
2026-03-11 10:37 - 2024-04-01 08:26 - 000000000 ____D C:\Windows\ShellExperiences
2026-03-11 10:37 - 2024-04-01 08:26 - 000000000 ____D C:\Windows\ShellComponents
2026-03-11 10:37 - 2024-04-01 08:26 - 000000000 ____D C:\Windows\BrowserCore
2026-03-11 10:37 - 2024-04-01 08:26 - 000000000 ____D C:\Windows\bcastdvr
2026-03-11 10:37 - 2024-04-01 08:21 - 000000000 ____D C:\Windows\servicing
2026-03-11 10:36 - 2024-04-01 08:26 - 000000000 ____D C:\Windows\appcompat
2026-03-11 10:26 - 2025-05-29 14:56 - 000001073 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2026-03-11 10:26 - 2024-04-01 08:26 - 000282624 _____ (Microsoft Corporation) C:\Windows\system32\msclmd.dll
2026-03-11 10:26 - 2024-04-01 08:26 - 000235520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msclmd.dll
2026-03-11 10:11 - 2025-05-29 12:34 - 003270144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2026-03-11 09:49 - 2025-12-10 08:34 - 000392320 _____ (Mozilla Foundation) C:\Users\david\Desktop\Firefox.exe
2026-03-10 20:05 - 2025-05-29 19:55 - 000000000 ____D C:\Program Files\Kingston_SSD_Manager
2026-03-10 20:04 - 2025-05-29 19:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kingston SSD Manager x64
2026-03-07 10:16 - 2025-05-29 12:32 - 000003714 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA{01B088DA-A62B-4A48-BD8A-07CB154CA3F6}
2026-03-07 10:16 - 2025-05-29 12:32 - 000003588 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore{6CF29DA0-3906-413B-B017-6557F6DCB4DD}
2026-03-03 21:11 - 2025-06-01 09:42 - 000000000 ____D C:\Users\david\AppData\Local\CrashDumps
2026-03-03 18:35 - 2025-05-29 13:01 - 000000000 ____D C:\Users\david\AppData\LocalLow\NVIDIA
2026-03-03 18:35 - 2025-05-29 13:01 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2026-03-03 10:22 - 2025-05-31 20:43 - 000000000 ____D C:\ProgramData\CanonIJPLM

==================== Files in the root of some directories ========

2025-05-31 08:35 - 2025-10-04 17:13 - 000007653 _____ () C:\Users\david\AppData\Local\Resmon.ResmonCfg
2025-06-01 09:42 - 2025-06-01 09:42 - 000000036 _____ () C:\Users\david\AppData\Local\_LOCAL_GUID

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================


Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-03-2026
Ran by david (20-03-2026 17:32:34)
Running from C:\Users\david\Desktop
Microsoft Windows 11 Home Version 25H2 26200.8037 (X64) (2025-05-29 11:34:17)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-2920095854-1669752291-3635278505-500 - Administrators - Disabled)
david (S-1-5-21-2920095854-1669752291-3635278505-1001 - Administrators - Enabled) => C:\Users\david
David Šplíchal (S-1-5-21-2920095854-1669752291-3635278505-1002 - Limited - Enabled) => C:\Users\David Šplíchal
DefaultAccount (S-1-5-21-2920095854-1669752291-3635278505-503 - Limited - Disabled)
Guest (S-1-5-21-2920095854-1669752291-3635278505-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-2920095854-1669752291-3635278505-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: ESET Security (Enabled - Up to date) {26E0861C-6FB9-CEF9-E4F0-531986211ACE}
FW: ESET Firewall (Enabled) {1EDB0739-25D6-CFA1-CFAF-FA2C78F25DB5}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 26.00 (x64) (HKLM\...\7-Zip) (Version: 26.00 - Igor Pavlov)
Adobe Acrobat Reader - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 25.001.21288 - Adobe Systems Incorporated)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601149}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
AMD GPIO2 Driver (HKLM-x32\...\{E9DD399F-21A3-479E-A7DF-D6CF4B2ADBF3}) (Version: 2.2.0.134 - Advanced Micro Devices, Inc.) Hidden
AMD Chipset Software (HKLM-x32\...\AMD_Chipset_IODrivers) (Version: 7.06.02.123 - Advanced Micro Devices, Inc.)
AMD PCI Driver (HKLM-x32\...\{80EC3CEE-2940-42A1-A776-B5D810D39F1E}) (Version: 1.0.0.9 - Advanced Micro Devices, Inc.) Hidden
AMD PSP Driver (HKLM-x32\...\{988F14B8-79A8-475D-BAC7-83F96AD3D821}) (Version: 5.39.0.0 - Advanced Micro Devices, Inc.) Hidden
AMD Ryzen Balanced Driver (HKLM-x32\...\{A171D320-C42C-4F3B-A2D8-C6A09F6788CC}) (Version: 8.0.0.13 - Advanced Micro Devices, Inc.) Hidden
AMD SBxxx SMBus Driver (HKLM-x32\...\{AAE0E27D-C88A-49BA-8715-77ADCD4286A3}) (Version: 5.12.0.44 - Advanced Micro Devices, Inc.) Hidden
AMD_Chipset_Drivers (HKLM-x32\...\{43ab2cfd-3f71-4aa8-ab15-5f517f620c41}) (Version: 7.06.02.123 - Advanced Micro Devices, Inc.) Hidden
BS.Player FREE (HKLM-x32\...\BSPlayerf) (Version: 2.78.1094 - AB Team, d.o.o.)
Canon IJ Printer Assistant Tool (HKLM-x32\...\Canon IJ Printer Assistant Tool) (Version: 1.90.3.36 - Canon Inc.)
Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: 1.5.5.3 - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: 6.6.0 - Canon Inc.)
Canon TS3300 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_TS3300_series) (Version: 1.04 - Canon Inc.)
CrystalDiskInfo 9.7.2 (HKLM\...\CrystalDiskInfo_is1) (Version: 9.7.2 - Crystal Dew World)
ESET Security (HKLM\...\{0F3CB7F7-E580-4E9D-BC90-58BF9A860742}) (Version: 19.0.14.0 - ESET, spol. s r.o.)
IrfanView 4.70 (32-bit) (HKLM-x32\...\IrfanView) (Version: 4.70 - Irfan Skiljan)
Kingston SSD Manager x64 1.5.6.3 (HKLM-x32\...\{53F657CD-C4FC-4DCD-826E-6862917532AC}_is1) (Version: 1.5.6.3 - @2021 Kingston Digital, Inc.)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 146.0.3856.62 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 146.0.3856.62 - Microsoft Corporation) Hidden
Microsoft Office 2019 pro studenty a domácnosti - cs-cz (HKLM\...\HomeStudent2019Retail - cs-cz) (Version: 16.0.19127.20302 - Microsoft Corporation)
Microsoft OneDrive (HKLM\...\OneDriveSetup.exe) (Version: 26.032.0217.0003 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.36.32532 (HKLM-x32\...\{410c0ee1-00bb-41b6-9772-e12c2828b02f}) (Version: 14.36.32532.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.50.35719 (HKLM\...\{AECD4ED0-8A3B-41E9-92D1-6BEE0374CCAF}) (Version: 14.50.35719 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.50.35719 (HKLM\...\{61B44572-8722-4DAF-8ACF-8E742D30BCC5}) (Version: 14.50.35719 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.36.32532 (HKLM-x32\...\{C2C59CAB-8766-4ABD-A8EF-1151A36C41E5}) (Version: 14.36.32532 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.36.32532 (HKLM-x32\...\{73F77E4E-5A17-46E5-A5FC-8A061047725F}) (Version: 14.36.32532 - Microsoft Corporation) Hidden
Microsoft Visual C++ v14 Redistributable (x64) - 14.50.35719 (HKLM-x32\...\{91ee571b-0e8a-4c65-9eaf-2e2f5fc60c00}) (Version: 14.50.35719.0 - Microsoft Corporation)
Mozilla Firefox (x64 cs) (HKLM\...\Mozilla Firefox) (Version: 148.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 139.0 - Mozilla)
NVIDIA Ovladač HD audia 1.4.5.7 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.4.5.7 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 595.79 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 595.79 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.23.1019 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.23.1019 - NVIDIA Corporation)
NVIDIA USBC Driver 1.52.831.832 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_USBC) (Version: 1.52.831.832 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.19127.20154 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.19127.20154 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.19127.20302 - Microsoft Corporation) Hidden
Promontory_GPIO Driver (HKLM-x32\...\{B5512BCC-F4CD-4159-86A4-B2AD7D38FFA9}) (Version: 3.0.3.0 - Advanced Micro Devices, Inc.) Hidden
Proton VPN (HKLM\...\Proton VPN_is1) (Version: 4.3.9 - Proton AG)
Realtek Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.9492.1 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.74.1128.2024 - Realtek)
Registrace tiskárny (HKLM-x32\...\Canon EISRegistration) (Version: 1.9.2 - Canon Inc.)
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.9.0.0 - Samsung Electronics Co., Ltd.)
Smart Switch Service (HKLM\...\{7B46CD5E-C3FF-4CB4-A569-425C545A9992}) (Version: 5.0.40.0 - Samsung Electronics Co., Ltd.)
Wargaming.net Game Center (HKU\S-1-5-21-2920095854-1669752291-3635278505-1001\...\Wargaming.net Game Center) (Version: 26.1.0.1957 - Wargaming.net)
World of Tanks EU (HKU\S-1-5-21-2920095854-1669752291-3635278505-1001\...\2314027414) (Version: - Wargaming.net)

Packages:
=========
Adobe Acrobat Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Assets [2026-03-12] ()
ESET Context Menu -> C:\Program Files\ESET\ESET Security [2026-03-12] (Sparse Package)
Local Artificial Intelligence Manager -> C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\AI [2025-10-16] ()
Microsoft Family -> C:\Program Files\WindowsApps\MicrosoftCorporationII.MicrosoftFamily_0.2.40.0_x64__8wekyb3d8bbwe [2025-05-30] (Microsoft Corp.)
Microsoft.HEVCVideoExtensions -> C:\Program Files\WindowsApps\Microsoft.HEVCVideoExtensions_2.4.42.0_x64__8wekyb3d8bbwe [2026-02-04] (Microsoft Corporation)
Microsoft.Office.ActionsServer -> C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\ActionsServer [2025-10-16] ()
Nahimic -> C:\Program Files\WindowsApps\A-Volute.Nahimic_1.10.9.0_x64__w2gh52qy24etm [2025-12-29] (A-Volute)
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.969.0_x64__56jybvy8sckqj [2025-11-06] (NVIDIA Corp.)
OfficePushNotificationsUtility -> C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16 [2025-10-16] ()
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.1.137.0_x64__dt26b99r8h8gj [2025-05-29] (Realtek Semiconductor Corp)
Samsung SmartSwitch -> C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCO.LTD.SamsungSmartSwitch_5.0.42.0_x64__3c1yjt4zspk6g [2026-03-09] (Samsung Electronics Co. Ltd.)
SpotifyAB.SpotifyMusic -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0 [2026-03-16] (Spotify AB) [Startup Task]
WinAppRuntime.Main.1.8 -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Main.1.8_8000.770.947.0_x64__8wekyb3d8bbwe [2026-03-15] (Microsoft Corp.)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-2920095854-1669752291-3635278505-1001_Classes\CLSID\{04271989-C4D2-1C86-3D53-F2AC04DA8ED5} -> [OneDrive] => {a52bba46-e9e1-435f-b3d9-28daa648c0f6}
CustomCLSID: HKU\S-1-5-21-2920095854-1669752291-3635278505-1001_Classes\CLSID\{13357088-9834-0409-1600-134951500000}\localserver32 -> "C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2920095854-1669752291-3635278505-1001_Classes\CLSID\{38142727-3008-9161-1521-349515000000}\localserver32 -> "C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe" -ToastActivated => No File
CustomCLSID: HKU\S-1-5-21-2920095854-1669752291-3635278505-1001_Classes\CLSID\{50726f74-6f6e-2e56-504e-000000000000}\localserver32 -> C:\Program Files\Proton\VPN\v4.3.9\ProtonVPN.Client.exe (Proton AG -> ProtonVPN)
CustomCLSID: HKU\S-1-5-21-2920095854-1669752291-3635278505-1001_Classes\CLSID\{6e1f4e4d-65f7-4c83-be2e-9e6683cda268}\localserver32 -> C:\Program Files\ESET\ESET Security\egui.exe (ESET, spol. s r.o. -> ESET)
CustomCLSID: HKU\S-1-5-21-2920095854-1669752291-3635278505-1001_Classes\CLSID\{80172dde-4e20-4df0-81a2-0a48553e80bb}\localserver32 -> C:\Users\david\AppData\Local\NhNotifSys\nahimic\nahimicNotifSys.exe (SteelSeries France SASU -> A-Volute)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\26.032.0217.0003\FileSyncShell64.dll [2026-03-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\26.032.0217.0003\FileSyncShell64.dll [2026-03-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\26.032.0217.0003\FileSyncShell64.dll [2026-03-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\26.032.0217.0003\FileSyncShell64.dll [2026-03-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\26.032.0217.0003\FileSyncShell64.dll [2026-03-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\26.032.0217.0003\FileSyncShell64.dll [2026-03-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\26.032.0217.0003\FileSyncShell64.dll [2026-03-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\26.032.0217.0003\FileSyncShell64.dll [2026-03-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\26.032.0217.0003\FileSyncShell64.dll [2026-03-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\26.032.0217.0003\FileSyncShell64.dll [2026-03-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\26.032.0217.0003\FileSyncShell64.dll [2026-03-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\26.032.0217.0003\FileSyncShell64.dll [2026-03-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\26.032.0217.0003\FileSyncShell64.dll [2026-03-14] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\26.032.0217.0003\FileSyncShell64.dll [2026-03-14] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\26.032.0217.0003\FileSyncShell64.dll [2026-03-14] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2026-02-12] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files (x86)\Adobe\Acrobat Reader DC\Acrobat Elements\ContextMenuShim64.dll [2026-02-17] (Adobe Inc. -> Adobe Systems Inc.)
ContextMenuHandlers1: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2025-11-28] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers2: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2025-11-28] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\26.032.0217.0003\FileSyncShell64.dll [2026-03-14] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2026-02-12] (Igor Pavlov) [File not signed]
ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\26.032.0217.0003\FileSyncShell64.dll [2026-03-14] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_4bf4c17fa8a478b5\nvshext.dll [2026-03-06] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2026-02-12] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2025-11-28] (ESET, spol. s r.o. -> ESET)

==================== Codecs (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Drivers32: [MidisrvTransferComplete] => 1
HKLM\...\Drivers32: [midi1] => C:\Windows\system32\wdmaud2.drv [143360 2026-03-11] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Drivers32: [midi1] => C:\Windows\SysWOW64\wdmaud2.drv [91648 2026-03-11] (Microsoft Windows -> Microsoft Corporation)

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

2026-02-17 20:28 - 2026-02-12 11:00 - 000101888 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll
2025-05-31 16:11 - 2025-05-31 16:11 - 000000000 ____L (Microsoft Corporation) [symlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppvIsvSubsystems32.dll] C:\Program Files (x86)\Microsoft Office\Root\Office16\AppVIsvSubsystems32.dll
2025-05-31 16:11 - 2025-05-31 16:11 - 000000000 ____L (Microsoft Corporation) [symlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\C2R32.dll] C:\Program Files (x86)\Microsoft Office\Root\Office16\c2r32.dll

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) =============

BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2025-09-07] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-07] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-07] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-07] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2025-09-07] (Microsoft Corporation -> Microsoft Corporation)

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2024-04-01 08:26 - 2024-04-01 08:24 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts

==================== Network ===========================

(Currently there is no automatic fix for this section.)

DNS Servers: 192.168.0.1
Windows Firewall is enabled.

Network Binding:
=============
Ethernet: Realtek PCIe GbE Family Controller -> rt640x64.sys

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2920095854-1669752291-3635278505-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
HKU\S-1-5-21-2920095854-1669752291-3635278505-1002\Control Panel\Desktop\\Wallpaper -> C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\DesktopSpotlight\Assets\Images\image_2.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)


==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKU\S-1-5-21-2920095854-1669752291-3635278505-1001\...\StartupApproved\Run: => "Proton VPN"
HKU\S-1-5-21-2920095854-1669752291-3635278505-1001\...\StartupApproved\Run: => "Adobe Acrobat Synchronizer"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{C01BF982-ED25-431B-A17D-4F081C2CF53F}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{F3217FB1-4FE7-4BE6-A23C-46874AB49F1B}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{2158536F-ED40-4219-99AF-E31193C068EF}] => (Allow) LPort=33683
FirewallRules: [{5D15FE17-67D9-480B-ACC3-E9FD6B07BCC7}] => (Allow) LPort=26822
FirewallRules: [{5803E8F2-09C6-4A9B-B1CF-E8190D88A459}] => (Allow) LPort=32683
FirewallRules: [{E648F5E6-AC28-44EF-8DE8-656FA7B47343}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{27AB9E2E-45CE-4150-A61E-18D0C2A31DDE}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{6997CEC0-8728-456F-A540-98AEB8C45996}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{8F9FB10A-F9B4-40BD-92D1-BF16D64C4325}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{053609BC-D45E-4C5E-A937-9553E5DF9CBF}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{D0DB8B62-02A0-48B2-B2A4-99A772B5F067}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{2E490696-5E5B-4892-A7C2-E62F17079A54}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{D19DF7AF-3AE3-4EB2-980A-2F7BBF1FD28B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{CA68F02C-5AAA-4925-841F-C52D660318EF}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{EEC80658-D595-4C1A-AF5D-D03D85B9B8D9}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{D17D839C-C063-479F-84ED-8891C0711D6B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{25078796-7103-4846-8874-34CCB17604E0}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{458EE1E8-9A42-4DAA-AF1A-7EA9C517C2FC}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.285.519.0_x64__zpdnekdrzrea0\SpotifyLauncher.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)

==================== Restore Points =========================

20-03-2026 15:49:17 Naplánovaný kontrolní bod

==================== Faulty Device Manager Devices ============

==================== Event log errors: ========================

Application errors:
==================
Error: (03/20/2026 10:42:22 AM) (Source: Microsoft Security Client) (EventID: 3002) (User: )
Description: Event-ID 3002

Error: (03/20/2026 10:42:22 AM) (Source: Microsoft Security Client) (EventID: 2002) (User: )
Description: Event-ID 2002

Error: (03/20/2026 10:42:22 AM) (Source: Microsoft Security Client) (EventID: 2003) (User: )
Description: Event-ID 2003

Error: (03/20/2026 09:52:42 AM) (Source: Microsoft Security Client) (EventID: 3002) (User: )
Description: Event-ID 3002

Error: (03/20/2026 09:52:42 AM) (Source: Microsoft Security Client) (EventID: 2002) (User: )
Description: Event-ID 2002

Error: (03/20/2026 09:52:42 AM) (Source: Microsoft Security Client) (EventID: 2003) (User: )
Description: Event-ID 2003

Error: (03/20/2026 09:32:26 AM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Inicializace registrace certifikátu SCEP pro WORKGROUP\DESKTOP-IJSLQ8R$ přes https://AMD-KeyId-578c545f796951421221a ... s/Aik/scep se nepovedla:

GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-578c545f796951421221a4a578acdb5f682f89c8.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Fri, 20 Mar 2026 08:32:23 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: 973c2269-7498-49a5-8e4e-e0c5870b88f4

Metoda: GET(500ms)
Fáze: GetCACaps
Nenalezeno (404) 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)

Error: (03/20/2026 09:32:25 AM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Inicializace registrace certifikátu SCEP pro Místní systém přes https://AMD-KeyId-578c545f796951421221a ... s/Aik/scep se nepovedla:

GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-578c545f796951421221a4a578acdb5f682f89c8.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Fri, 20 Mar 2026 08:32:22 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: f6f821ed-311c-498d-8376-746b0ce53104

Metoda: GET(500ms)
Fáze: GetCACaps
Nenalezeno (404) 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)


System errors:
=============
Error: (03/20/2026 03:44:59 PM) (Source: volsnap) (EventID: 36) (User: )
Description: Stínové kopie svazku C: byly přerušeny, protože z důvodu limitu stanoveného uživatelem se nepodařilo zvětšit úložiště stínové kopie.

Error: (03/19/2026 09:56:05 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-IJSLQ8R)
Description: Server {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} se v daném časovém limitu neregistroval u služby DCOM.

Error: (03/19/2026 09:56:05 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-IJSLQ8R)
Description: Server {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} se v daném časovém limitu neregistroval u služby DCOM.

Error: (03/19/2026 07:35:21 PM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1023) (User: NT AUTHORITY)
Description: Tabulka zásad překladu IP adres byla poškozena. Překlad názvů DNS bude dále selhávat, dokud nebude tabulka opravena. Další informace: Čtení tabulky zásad pro pravidlo {AF27D1DD-4257-4502-BD0E-EC1F402B6103} se nepodařilo s chybou 87.

Error: (03/19/2026 09:52:01 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-IJSLQ8R)
Description: Server {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} se v daném časovém limitu neregistroval u služby DCOM.

Error: (03/19/2026 09:52:00 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-IJSLQ8R)
Description: Server {740FE937-01F7-4482-AA62-C83F0AD3D6D0} se v daném časovém limitu neregistroval u služby DCOM.

Error: (03/18/2026 09:52:59 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-IJSLQ8R)
Description: Server {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} se v daném časovém limitu neregistroval u služby DCOM.

Error: (03/18/2026 09:52:59 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-IJSLQ8R)
Description: Server {6FA05A24-B1DF-4155-909E-7B424F2D2BB5} se v daném časovém limitu neregistroval u služby DCOM.


Windows Defender:
================
Date: 2026-02-14 12:26:25
Description:
Antivirová ochrana v programu Microsoft Defender ѕĉåп нàś ъĕéń śţöрρέð вєƒόŕē сσмφℓēţĭòņ.%ŋ %ţŚсąη ĬÐ:%в{6F1BFD8A-47F1-475F-98F7-9F272DF62BBE}%л %тŠçáň Ŧýр℮:%ьAntimalwarový program%ⁿ %тŞçāň Ράřàmêţĕяѕ:%ьRychlé prohledávání%ʼn %ŧŬŝèѓ:%ъNT AUTHORITY\SYSTEM%ⁿ %ţŞτőρ Ŗĕąѕōñ:%ъŞĉђěδυŀзď şсåл ẃãŝ śкϊрρеđ ъè¢àϋšє тнè ŀаѕť ŝų¢сзŝšƒυĺ ѕçâń ωàş ώіτђĭʼn τђэ ľăŝŧ 7 đаўś

Date: 2026-01-04 12:11:29
Description:
Antivirová ochrana v programu Microsoft Defender ѕĉåп нàś ъĕéń śţöрρέð вєƒόŕē сσмφℓēţĭòņ.%ŋ %ţŚсąη ĬÐ:%в{AE9E3AFF-F184-4327-999F-F28AB9272554}%л %тŠçáň Ŧýр℮:%ьAntimalwarový program%ⁿ %тŞçāň Ράřàmêţĕяѕ:%ьRychlé prohledávání%ʼn %ŧŬŝèѓ:%ъNT AUTHORITY\SYSTEM%ⁿ %ţŞτőρ Ŗĕąѕōñ:%ъŞĉĥеδũĺέđ şĉāⁿ ŵāѕ ŝĸïφрёď вëčάùśε ŧĥе ℓдśт ŝůĉčęśśƒűł ѕčåñ щāś ώϊţђĭи ŧĥě ℓàŝт 7 ďàŷѕ

Date: 2026-01-04 11:33:11
Description:
Antivirová ochrana v programu Microsoft Defender ѕĉåп нàś ъĕéń śţöрρέð вєƒόŕē сσмφℓēţĭòņ.%ŋ %ţŚсąη ĬÐ:%в{FEA37172-9D1D-4668-8816-09B18C49BB21}%л %тŠçáň Ŧýр℮:%ьAntimalwarový program%ⁿ %тŞçāň Ράřàmêţĕяѕ:%ьÚplné prohledávání%ʼn %ŧŬŝèѓ:%ъDESKTOP-IJSLQ8R\david%ⁿ %ţŞτőρ Ŗĕąѕōñ:%ъŲŋκйòщп

Date: 2026-01-04 11:32:35
Description:
Antivirová ochrana v programu Microsoft Defender ѕĉåп нàś ъĕéń śţöрρέð вєƒόŕē сσмφℓēţĭòņ.%ŋ %ţŚсąη ĬÐ:%в{04F1B824-E32A-4886-BE57-754AF36BA760}%л %тŠçáň Ŧýр℮:%ьAntimalwarový program%ⁿ %тŞçāň Ράřàmêţĕяѕ:%ьRychlé prohledávání%ʼn %ŧŬŝèѓ:%ъNT AUTHORITY\SYSTEM%ⁿ %ţŞτőρ Ŗĕąѕōñ:%ъŜ¢ĥзδůŀėď ѕčаň ẃªś ѕκϊφρзđ ъε¢άύśé тнė ļǻşт šџ¢čзššƒцľ śĉåή ώãŝ щīŧнĩň τћė ľάŝŧ 7 đªγś

Date: 2025-11-03 16:20:52
Description:
Antivirová ochrana v programu Microsoft Defender ѕĉåп нàś ъĕéń śţöрρέð вєƒόŕē сσмφℓēţĭòņ.%ŋ %ţŚсąη ĬÐ:%в{3F5FCFB1-962F-4230-9407-68EA3FF1B256}%л %тŠçáň Ŧýр℮:%ьAntimalwarový program%ⁿ %тŞçāň Ράřàmêţĕяѕ:%ьRychlé prohledávání%ʼn %ŧŬŝèѓ:%ъNT AUTHORITY\SYSTEM%ⁿ %ţŞτőρ Ŗĕąѕōñ:%ъŜ¢ĥзδůŀėď ѕčаň ẃªś ѕκϊφρзđ ъε¢άύśé тнė ļǻşт šџ¢čзššƒцľ śĉåή ώãŝ щīŧнĩň τћė ľάŝŧ 7 đªγś
Event[0]

Date: 2025-06-18 12:02:35
Description:
Funkce Ochrana v reálném čase u prohledávání Antivirová ochrana v programu Microsoft Defender zjistila chybu a došlo k jejímu selhání.
Funkce: Při přístupu
Kód chyby: 0x8007043c
Popis chyby: Tuto službu nelze spustit v nouzovém režimu.
Důvod: Antimalwarové bezpečnostní informace přestaly z neznámých důvodů fungovat. V některých případech se tento problém dá vyřešit restartováním služby.

Date: 2025-06-18 08:52:07
Description:
Funkce Ochrana v reálném čase u prohledávání Antivirová ochrana v programu Microsoft Defender zjistila chybu a došlo k jejímu selhání.
Funkce: Při přístupu
Kód chyby: 0x8007043c
Popis chyby: Tuto službu nelze spustit v nouzovém režimu.
Důvod: Antimalwarové bezpečnostní informace přestaly z neznámých důvodů fungovat. V některých případech se tento problém dá vyřešit restartováním služby.

Date: 2025-06-07 20:05:52
Description:
Funkce Ochrana v reálném čase u prohledávání Antivirová ochrana v programu Microsoft Defender zjistila chybu a došlo k jejímu selhání.
Funkce: Při přístupu
Kód chyby: 0x8007043c
Popis chyby: Tuto službu nelze spustit v nouzovém režimu.
Důvod: Antimalwarové bezpečnostní informace přestaly z neznámých důvodů fungovat. V některých případech se tento problém dá vyřešit restartováním služby.

Date: 2025-05-29 18:40:46
Description:
Funkce Ochrana v reálném čase u prohledávání Antivirová ochrana v programu Microsoft Defender zjistila chybu a došlo k jejímu selhání.
Funkce: Při přístupu
Kód chyby: 0x8007043c
Popis chyby: Tuto službu nelze spustit v nouzovém režimu.
Důvod: Antimalwarové bezpečnostní informace přestaly z neznámých důvodů fungovat. V některých případech se tento problém dá vyřešit restartováním služby.

CodeIntegrity:
===============
Date: 2026-03-20 17:00:39
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\SecurityHealthService.exe) attempted to load \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll that did not meet the Windows signing level requirements.


==================== Memory info ===========================

BIOS: American Megatrends International, LLC. H.O0 09/01/2025
Motherboard: Micro-Star International Co., Ltd B450 GAMING PLUS MAX (MS-7B86)
Processor: AMD Ryzen 5 2600 Six-Core Processor
Percentage of memory in use: 41%
Total physical RAM: 16309.56 MB
Available physical RAM: 9519.39 MB
Total Virtual: 17333.56 MB
Available Virtual: 10465.44 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:299.17 GB) (Free:129.65 GB) (Model: KINGSTON SNV3S1000G) NTFS
Drive d: () (Fixed) (Total:631.51 GB) (Free:472.51 GB) (Model: KINGSTON SNV3S1000G) NTFS

\\?\Volume{626ee596-90b9-417c-9e79-037e89c2fd39}\ () (Fixed) (Total:0.71 GB) (Free:0.07 GB) NTFS
\\?\Volume{ebe85961-9060-4b84-ab32-783278932ad8}\ () (Fixed) (Total:0.09 GB) (Free:0.06 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt =======================

Re: Prosím o kontrolu

Napsal: 20 bře 2026 20:01
od JaRon
Ahoj,
nevidim tam nic zavazne, doporucujem preventivne prescanovat s MBAM

Re: Prosím o kontrolu

Napsal: 20 bře 2026 20:38
od David27
Přikládám log MBAM

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 3/20/2026
Scan Duration: 8:27 PM
Log File: d521094c-2492-11f1-a686-2cf05dd9140a.json

-Software Information-
Version: 5.5.2.242
Components Version: 152.0.5541
Update Package Version: 1.0.108074
License: Expired

-System Information-
OS: Windows 11 (Build 26200.8037)
CPU: x64
File System: NTFS
User: DESKTOP-IJSLQ8R\david

-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 199929
Threats Detected: 0
Threats Quarantined: 0
Time Elapsed: 4 min, 9 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
File system: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 0
(No malicious items detected)

Registry Value: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 0
(No malicious items detected)

Physical Sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)


(end)

Re: Prosím o kontrolu

Napsal: 21 bře 2026 11:31
od JaRon
Malo by to byt OK

Re: Prosím o kontrolu

Napsal: 21 bře 2026 11:43
od David27
Ještě jednou děkuji.
Hezký den.

Re: Prosím o kontrolu

Napsal: 21 bře 2026 13:52
od JaRon
Aj Tebe orajem pekny den :thumbsup: