Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 25-03-2026
Ran by sern (administrator) on KATANA (Micro-Star International Co., Ltd. Katana 15 B12VFK) (25-03-2026 16:08:11)
Running from D:\Stažené soubory\FRST64 (1).exe
Loaded Profiles: sern
Platform: Microsoft Windows 11 Pro Version 25H2 26200.8037 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(A225F3B5-240D-4EE9-BCF4-697A07F5E93E -> Micro-Star INT'L CO., LTD.) C:\Program Files\WindowsApps\9426MICRO-STARINTERNATION.MSICenter_2.0.67.0_x64__kzh8wxbdkxb8p\DCv2\DCv2.exe
(C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe ->) (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(C:\Program Files (x86)\MSI\MSI Center\MSI_Central_Service.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\MSI Center\MSI.CentralServer.exe
(C:\Program Files\Autodesk\AdODIS\V1\Access\AdskAccessCore.exe ->) (Autodesk, Inc. -> Autodesk, Inc.) C:\Program Files\Autodesk\AdODIS\V1\Setup\ui-launcher\AdskAccessUIHost.exe <4>
(C:\Program Files\Autodesk\AdODIS\V1\Access\AdskAccessCore.exe ->) (Autodesk, Inc. -> Autodesk, Inc.) C:\Program Files\Autodesk\AdskIdentityManager\1.16.5.1\AdskIdentityManager.exe
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eOppFrame.exe
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eServiceHost.exe <2>
(C:\Program Files\Google\Drive File Stream\122.0.1.0\GoogleDriveFS.exe ->) (Google LLC -> ) C:\Program Files\Google\Drive File Stream\122.0.1.0\crashpad_handler.exe
(C:\Program Files\Google\Chrome\Application\chrome.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA App\CEF\NVIDIA Overlay.exe <5>
(C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA App\ShadowPlay\nvsphelper64.exe
(cmd.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\BrowserPrivacyAndSecurity.exe
(D:\CADKON\2024\icad.exe ->) (GRAITEC INNOVATION SAS -> Graitec) C:\Program Files (x86)\Common Files\Graitec\grflexwserver.exe
(DriverStore\FileRepository\ipf_cpu.inf_amd64_09022c71eac15532\ipf_uf.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_09022c71eac15532\ipf_helper.exe
(explorer.exe ->) (Autodesk, Inc. -> Autodesk, Inc.) C:\Program Files\Autodesk\AdODIS\V1\Access\AdskAccessCore.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <47>
(explorer.exe ->) (Google LLC -> Google LLC.) C:\Program Files\Google\Drive File Stream\122.0.1.0\GoogleDriveFS.exe <2>
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE
(explorer.exe ->) (Wondershare Technology Group Co.,Ltd -> Wondershare) C:\Program Files\Wondershare\PDFelement11\PENotify.exe
(GRAITEC INNOVATION SAS -> Graitec) D:\CADKON\2024\icad.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\AI\aimgr.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
(NahimicService.exe ->) (SteelSeries France SASU -> Nahimic) C:\Windows\System32\NahimicAPO4Volume.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Proton AG -> ProtonVPN) C:\Program Files\Proton\VPN\v4.3.12\ProtonVPN.Client.exe
(services.exe ->) (Autodesk, Inc. -> ) C:\Program Files\Autodesk\Autodesk CER\service\cer_service.exe
(services.exe ->) (Autodesk, Inc. -> Autodesk, Inc.) C:\Program Files\Autodesk\AdODIS\V1\Setup\AdskAccessServiceHost.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\efwd.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(services.exe ->) (Even Balance, Inc. -> ) C:\Windows\SysWOW64\PnkBstrA.exe
(services.exe ->) (Flexera Software LLC -> Flexera Software LLC) C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe
(services.exe ->) (Flexera Software LLC -> Flexera) C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
(services.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Piriform\CCleaner 7\CCleaner_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_af50fdb80983f7bc\jhi_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_09022c71eac15532\ipf_uf.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d51901c26227fb29\WMIRegistrationService.exe
(services.exe ->) (Intel Corporation -> Intel) C:\Windows\System32\DriverStore\FileRepository\intcoed.inf_amd64_adc76e77cd818de5\AS\IAS\IntelAudioService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Windows (R) Win 7 DDK provider) C:\Program Files\Microsoft GameInput\x64\GameInputRedistService.exe
(services.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MidiSrv.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_4e93878658043b21\OneApp.IGCC.WinService.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_5b1252b3763da959\IntelCpHDCPSvc.exe
(services.exe ->) (Micro-Star International CO., LTD. -> Micro-Star International Co., Ltd.) C:\Windows\SysWOW64\MSIService.exe
(services.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\MSI Center\MSI_Central_Service.exe
(services.exe ->) (Native Instruments GmbH -> Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <4>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvmii.inf_amd64_5a00035b3c0dd9d1\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Proton AG -> ProtonVPN) C:\Program Files\Proton\VPN\v4.3.12\ProtonVPNService.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_31dd95d009763f70\RtkAudUService64.exe <2>
(services.exe ->) (SteelSeries France SASU -> Nahimic) C:\Windows\System32\NahimicService.exe
(SteelSeries France SASU -> A-Volute) C:\Windows\System32\NhNotifSys.exe
(svchost.exe ->) (Gen Digital Inc. -> Gen Digital Inc.) C:\Program Files\Piriform\CCleaner 7\CCleaner.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\SDXHelper.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.229.1.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\DataExchangeHost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\NgcIso.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\prevhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(svchost.exe ->) (Micro-Star International CO., LTD. -> Micro-Star International Co., Ltd.) C:\Program Files (x86)\MSI\MSI NBFoundation Service\OmApSvcBroker.exe
(svchost.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\MSI Center\MSI.TerminalServer.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_31dd95d009763f70\RtkAudUService64.exe [3282984 2025-12-10] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [Autodesk Access] => C:\Program Files\Autodesk\AdODIS\V1\Access\AdskAccessCore.exe [21229344 2024-04-16] (Autodesk, Inc. -> Autodesk, Inc.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [285616 2025-11-27] (ESET, spol. s r.o. -> ESET)
HKLM\...\Run: [Autodesk Access Service] => C:\Program Files\Autodesk\AdODIS\V1\Setup\AdskAccessService.exe [18170648 2025-06-07] (Autodesk, Inc. -> Autodesk, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [752264 2025-09-26] (Oracle America, Inc. -> Oracle Corporation)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\122.0.1.0\GoogleDriveFS.exe [92414616 2026-03-10] (Google LLC -> Google LLC.)
HKU\S-1-5-19\...\RunOnce: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4742504 2025-11-22] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\122.0.1.0\GoogleDriveFS.exe [92414616 2026-03-10] (Google LLC -> Google LLC.)
HKU\S-1-5-20\...\RunOnce: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4742504 2025-11-22] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2758214187-3853810005-2688088550-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4742504 2025-11-22] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2758214187-3853810005-2688088550-1001\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\122.0.1.0\GoogleDriveFS.exe [92414616 2026-03-10] (Google LLC -> Google LLC.)
HKU\S-1-5-21-2758214187-3853810005-2688088550-1001\...\Run: [Microsoft.Lists] => C:\Program Files\Microsoft OneDrive\25.209.1026.0002\OneDrive.Sync.Service.exe [951656 2025-11-22] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2758214187-3853810005-2688088550-1001\...\Run: [Proton VPN] => C:\Program Files\Proton\VPN\ProtonVPN.Launcher.exe [18781032 2026-02-02] (Proton AG -> ProtonVPN)
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\122.0.1.0\GoogleDriveFS.exe [92414616 2026-03-10] (Google LLC -> Google LLC.)
HKLM\...\Print\Monitors\EPSON PC-FAX Driver2 64Monitor: C:\WINDOWS\system32\EFXLM16A.DLL [182784 2023-07-20] (SEIKO EPSON CORPORATION) [File not signed]
HKLM\...\Print\Monitors\EPSON WF-7710 Series 64MonitorBE: C:\WINDOWS\system32\E_YLMBSBE.DLL [187392 2018-06-14] (Seiko Epson Corporation) [File not signed]
HKLM\...\Print\Monitors\Wondershare PDFelement Monitor: C:\WINDOWS\system32\PEPrinterMonitor.dll [420584 2025-05-12] (Wondershare Technology Group Co.,Ltd -> Wondershare Software)
HKLM\...\Print\Monitors\Wondershare PDFelement Toolbox Monitor: C:\WINDOWS\system32\PEToolboxMonitor.dll [420584 2025-05-12] (Wondershare Technology Group Co.,Ltd -> Wondershare Software)
HKLM\Software\Microsoft\Active Setup\Installed Components: [>OpenVPN_UserSetup] -> reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v OPENVPN-GUI /f
HKLM\Software\Microsoft\Active Setup\Installed Components: [{49210152-871f-4ffa-961d-a172abcbc09d}] -> C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [2026-03-18] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\146.0.7680.154\Installer\chrmstp.exe [2026-03-24] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Wondershare PEScreenshot.lnk [2025-06-12]
ShortcutTarget: Wondershare PEScreenshot.lnk -> C:\Program Files\Wondershare\PDFelement11\PENotify.exe (Wondershare Technology Group Co.,Ltd -> Wondershare)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Wondershare PEToolbox.lnk [2025-06-12]
ShortcutTarget: Wondershare PEToolbox.lnk -> C:\Program Files\Wondershare\PDFelement11\PENotify.exe (Wondershare Technology Group Co.,Ltd -> Wondershare)
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {7CB51A97-69A6-45DF-B459-3D7D2A497D55} - System32\Tasks\CLToast => C:\Program Files (x86)\CyberLink\Shared files\CLToast.exe [2317064 2024-03-14] (CyberLink Corp. -> )
Task: {3693C901-93C8-4957-8D99-2BE75CF53E8F} - System32\Tasks\CLToastRun => C:\Program Files (x86)\CyberLink\Shared files\CLToast.exe [2317064 2024-03-14] (CyberLink Corp. -> )
Task: {9908A0CD-6EED-4932-BC60-3A2A91ED716A} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem148.0.7730.0{78EF7658-2F2C-4C46-A83A-61D664630D62} => C:\Program Files (x86)\Google\GoogleUpdater\148.0.7730.0\updater.exe [8459416 2026-03-12] (Google LLC -> Google LLC)
Task: {18E2DE64-641B-415B-89E5-38D93DF57ED0} - System32\Tasks\Microsoft\Office\Office Actions Server => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ActionsServer\ActionsServer.exe [16300416 2026-03-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {E1986A30-127D-4DB2-8E65-DCFAAE6598F0} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28604736 2026-03-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {54E8E26B-32FF-4864-AC14-25550C768940} - System32\Tasks\Microsoft\Office\Office Background Push Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\opushutil.exe [73568 2026-03-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {CB92A31F-9A1D-4593-A6E7-1312A4A92EA3} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28604736 2026-03-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {52D3BB88-09F8-42C3-A291-02CC1DE2AA63} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [427800 2026-03-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {6CA30436-A334-48A3-92A3-428216FB6710} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [427800 2026-03-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {977E7326-C023-4936-BE84-9A2C96FBD2A6} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [1349992 2026-03-03] (Microsoft Corporation -> Microsoft Corporation)
Task: {5B16DA80-6FF1-46EC-80D4-3DA95C0580A5} - System32\Tasks\Microsoft\Office\Office Serviceability Manager => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\officesvcmgr.exe [4448800 2026-03-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {7973F5EA-1AF0-45BF-B0E1-C47659C1430A} - System32\Tasks\Microsoft\Office\Office Startup Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ActionsServer\ActionsServer.exe [16300416 2026-03-21] (Microsoft Corporation -> Microsoft Corporation)
Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File)
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {2F0A54DF-82E2-4E5E-85E8-A05DBDA1D571} - System32\Tasks\NVIDIA App SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA App\CEF\NVIDIA App.exe [3324528 2025-10-15] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {967F8D7A-F8AB-4F7B-99D2-DB29C1714F1C} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [908328 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {1F35071E-526E-4635-AC51-C3F69F012F4E} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [908328 2024-06-11] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {0A218D70-D7D8-411F-BFE2-005562CD8456} - System32\Tasks\OmApSvcBroker => C:\Program Files (x86)\MSI\MSI NBFoundation Service\OmApSvcBroker.exe [1380456 2026-02-10] (Micro-Star International CO., LTD. -> Micro-Star International Co., Ltd.)
Task: {A668AE3F-7211-4BC8-8190-A31F281DF783} - System32\Tasks\OneDC_Updater => C:\Program Files (x86)\MSI\MSI_Center_Updater\OneDC_Updater.exe [657968 2025-08-07] (Micro-Star International CO., LTD. -> Micro-Star International Co., Ltd.)
Task: {606DD8A2-30FD-4904-8C3A-B6CE3706ABE2} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4380008 2025-11-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {DAAF67D8-5020-4F8F-88E0-02E1ED99E884} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-2758214187-3853810005-2688088550-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4380008 2025-11-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {23A7E57E-0937-47E1-8CE9-610D32221FF0} - System32\Tasks\OneDrive Startup Task-S-1-5-21-2758214187-3853810005-2688088550-1001 => C:\Program Files\Microsoft OneDrive\25.209.1026.0002\OneDriveLauncher.exe [727440 2025-11-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {A89CDA43-AC42-4F74-85DA-B1E9E9961553} - System32\Tasks\Piriform\CCleaner 7 - S-1-5-21-2758214187-3853810005-2688088550-1001 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [5315192 2026-03-10] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {E53C4451-5A4F-446A-AF79-8840067B0665} - System32\Tasks\Piriform\CCleaner 7 - Scheduled Cleaning - default - S-1-5-21-2758214187-3853810005-2688088550-1001 => C:\Program Files\Piriform\CCleaner 7\CCleaner.exe [5315192 2026-03-10] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {A5C05250-ABA7-44FF-B173-3981BB92C9F8} - System32\Tasks\Piriform\CCleaner 7 BugReport => C:\Program Files\Piriform\CCleaner 7\CCleanerBugReport.exe [6461560 2026-03-10] (Gen Digital Inc. -> Gen Digital Inc.) -> --send "dumps|report" --product 234 --programpath "C:\Program Files\Piriform\CCleaner 7" --configpath "C:\Program Files\Piriform\CCleaner 7\data" --path "C:\Program Files\Piriform\CCleaner 7\log" --path "C:\Program Files\Piriform\CCleaner 7\data\dumps" --logpath "C:\Program Files\Piriform\CCleaner 7 (the data entry has 58 more characters).
Task: {A0496464-AFA8-43B6-A0BB-7020C176AAB0} - System32\Tasks\Piriform\CCleaner 7 Update => C:\Program Files\Common Files\Piriform\Icarus\piriform-ccl\icarus.exe [9274080 2026-01-19] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {1FA099D4-56A8-4B83-9948-D3CCECAC3F12} - System32\Tasks\PowerDirectorStyleAgent => C:\Program Files (x86)\CyberLink\Shared files\PDStyleAgent\PDStyleAgent.exe [97544 2024-03-14] (CyberLink Corp. -> CyberLink Corp.)
Task: {7C7AEC85-2BDD-4D1B-89E3-53C6FC264BE8} - System32\Tasks\Ubisoft\Ubisoft Connect Background Update => C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\upc.exe [17246392 2026-01-11] (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{21133100-e4b4-4af2-b642-52f3abb08058}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{21133100-e4b4-4af2-b642-52f3abb08058}\05F44414F523133353: [DhcpNameServer] 62.129.50.20 85.135.32.100
Tcpip\..\Interfaces\{21133100-e4b4-4af2-b642-52f3abb08058}\45556502355544027455543545: [DhcpNameServer] 8.8.8.8 8.8.4.4
Tcpip\..\Interfaces\{21133100-e4b4-4af2-b642-52f3abb08058}\7416C61687970207163737A31323334313233343: [DhcpNameServer] 10.67.105.152
Tcpip\..\Interfaces\{21133100-e4b4-4af2-b642-52f3abb08058}\E445B4D23596D607C656: [DhcpNameServer] 10.0.100.7
Tcpip\..\Interfaces\{21133100-e4b4-4af2-b642-52f3abb08058}\E445B4D23596D607C656: [DhcpDomain] ntkcz.cz
Tcpip\..\Interfaces\{444c531c-8e58-4e4f-8fe9-6ae83fad38d8}: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF DefaultProfile: rsau2dmf.default-release -> 308046B0AF4A39CB
FF ProfilePath: C:\Users\sern\AppData\Roaming\Mozilla\Firefox\Profiles\hqndhj3e.default [2025-06-12]
FF ProfilePath: C:\Users\sern\AppData\Roaming\Mozilla\Firefox\Profiles\rsau2dmf.default-release [2026-03-25]
FF Extension: (Print Friendly & PDF) - C:\Users\sern\AppData\Roaming\Mozilla\Firefox\Profiles\rsau2dmf.default-release\Extensions\
jid0-YQz0l1jthOIz179ehuitYAOdBEs@jetpack.xpi [2025-06-12]
FF Extension: (Udělej printscreen celé webové stránky - FireShot) - C:\Users\sern\AppData\Roaming\Mozilla\Firefox\Profiles\rsau2dmf.default-release\Extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}.xpi [2025-06-12]
FF Plugin: @java.com/DTPlugin,version=11.471.0 -> C:\Program Files\Java\jre1.8.0_471\bin\dtplugin\npDeployJava1.dll [2025-09-26] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.471.0 -> C:\Program Files\Java\jre1.8.0_471\bin\plugin2\npjp2.dll [2025-09-26] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2026-01-16] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.16 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2024-06-08] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.20 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2024-06-08] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.21 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2024-06-08] (VideoLAN -> VideoLAN)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2025-12-08] (Microsoft Corporation -> Microsoft Corporation)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2025-06-12]
Edge:
=======
Edge Profile: C:\Users\sern\AppData\Local\Microsoft\Edge\User Data\Default [2025-06-14]
Edge Extension: (Google Docs Offline) - C:\Users\sern\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-09-16]
Edge Extension: (Edge relevant text changes) - C:\Users\sern\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24]
Edge Extension: (ESET Browser Privacy & Security) - C:\Users\sern\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\nkapkmklnmidbbgjaipbgpcnbomnaakc [2024-09-22]
Edge HKLM-x32\...\Edge\Extension: [nkapkmklnmidbbgjaipbgpcnbomnaakc]
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\sern\AppData\Local\Google\Chrome\User Data\Default [2026-03-25]
Error reading preferences. Please check "Secure Preferences" file for possible corruption. <==== ATTENTION
CHR Extension: (No Name) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Default\Extensions\aahnibhpidkdaeaplfdogejgoajkjgob [2025-12-01] [UpdateUrl:0] <==== ATTENTION
CHR Extension: (No Name) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Default\Extensions\cicohiknlppcipjbfpoghjbncojncjgb [2024-12-20] [UpdateUrl:0] <==== ATTENTION
CHR Extension: (No Name) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-03-22] [UpdateUrl:0] <==== ATTENTION
CHR Extension: (No Name) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2026-03-19] [UpdateUrl:0] <==== ATTENTION
CHR Extension: (No Name) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2024-02-02] [UpdateUrl:0] <==== ATTENTION
CHR Extension: (No Name) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-11-20] [UpdateUrl:0] <==== ATTENTION
CHR Extension: (No Name) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Default\Extensions\oombnmpbbhbakfpfgdflaajkhicgfaam [2025-11-13] [UpdateUrl:0] <==== ATTENTION
CHR Extension: (No Name) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc [2025-10-13] [UpdateUrl:0] <==== ATTENTION
CHR Profile: C:\Users\sern\AppData\Local\Google\Chrome\User Data\Profile 1 [2026-03-25]
CHR Extension: (No Name) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2024-09-12] [UpdateUrl:0] <==== ATTENTION
CHR Extension: (No Name) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2026-03-18] [UpdateUrl:0] <==== ATTENTION
CHR Extension: (No Name) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fdpohaocaechififmbbbbbknoalclacl [2026-01-21] [UpdateUrl:0] <==== ATTENTION
CHR Extension: (No Name) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-03-19] [UpdateUrl:0] <==== ATTENTION
CHR Extension: (No Name) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2026-03-19] [UpdateUrl:0] <==== ATTENTION
CHR Extension: (No Name) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2024-02-02] [UpdateUrl:0] <==== ATTENTION
CHR Extension: (No Name) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-11-25] [UpdateUrl:0] <==== ATTENTION
CHR Extension: (No Name) - C:\Users\sern\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oombnmpbbhbakfpfgdflaajkhicgfaam [2025-11-16] [UpdateUrl:0] <==== ATTENTION
CHR Profile: C:\Users\sern\AppData\Local\Google\Chrome\User Data\System Profile [2026-03-22]
CHR HKU\S-1-5-21-2758214187-3853810005-2688088550-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKU\S-1-5-21-2758214187-3853810005-2688088550-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [oombnmpbbhbakfpfgdflaajkhicgfaam]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Autodesk Access Service Host; C:\Program Files\Autodesk\AdODIS\V1\Setup\AdskAccessServiceHost.exe [19981080 2025-06-07] (Autodesk, Inc. -> Autodesk, Inc.)
R2 Autodesk CER Service; C:\Program Files\Autodesk\Autodesk CER\service\cer_service.exe [24314480 2025-09-25] (Autodesk, Inc. -> )
R2 CCleaner7; C:\Program Files\Piriform\CCleaner 7\CCleaner_service.exe [29465352 2026-03-10] (Gen Digital Inc. -> Gen Digital Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13270328 2026-03-14] (Microsoft Corporation -> Microsoft Corporation)
R2 efwd; C:\Program Files\ESET\ESET Security\efwd.exe [5543856 2025-11-27] (ESET, spol. s r.o. -> ESET)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [4980040 2025-11-27] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [4980040 2025-11-27] (ESET, spol. s r.o. -> ESET)
S4 FileSyncHelper; C:\Program Files\Microsoft OneDrive\25.209.1026.0002\FileSyncHelper.exe [3608936 2025-11-22] (Microsoft Corporation -> Microsoft Corporation)
R2 GameInputRedistService; C:\Program Files\Microsoft GameInput\x64\GameInputRedistService.exe [385960 2026-03-09] (Microsoft Corporation -> Windows (R) Win 7 DDK provider)
S2 Intel(R) Platform License Manager Service; C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_fc84dfa25a6a7727\lib\PlatformLicenseManagerService.exe [741488 2023-12-14] (Intel Corporation -> Intel(R) Corporation)
R2 IntelAudioService; C:\WINDOWS\System32\DriverStore\FileRepository\intcoed.inf_amd64_adc76e77cd818de5\AS\IAS\IntelAudioService.exe [532920 2025-08-15] (Intel Corporation -> Intel)
R2 ipfsvc; C:\WINDOWS\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_09022c71eac15532\ipf_uf.exe [3333592 2025-09-03] (Intel Corporation -> Intel Corporation)
S3 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24080.9-0\MpDefenderCoreService.exe [1431160 2024-09-17] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 Micro Star SCM; C:\WINDOWS\SysWOW64\MSIService.exe [171544 2024-12-18] (Micro-Star International CO., LTD. -> Micro-Star International Co., Ltd.)
S4 MSI Foundation Service; C:\Program Files (x86)\MSI\MSI NBFoundation Service\MSIAPService.exe [105968 2025-03-24] (Micro-Star International CO., LTD. -> Micro-Star International Co., Ltd.)
S4 MSI Sendevsvc; C:\Program Files (x86)\MSI\MSI NBFoundation Service\Sendevsvc.exe [311536 2023-05-11] (Micro-Star International CO., LTD. -> )
R2 MSI_Center_Service; C:\Program Files (x86)\MSI\MSI Center\MSI_Central_Service.exe [181776 2025-04-17] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.)
R2 NahimicService; C:\WINDOWS\System32\NahimicService.exe [1910808 2025-06-30] (SteelSeries France SASU -> Nahimic)
S4 NTKDaemonService; C:\Program Files\Common Files\Native Instruments\NTK\NTKDaemon.exe [18193304 2025-10-09] (Native Instruments GmbH -> Native Instruments GmbH)
R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvmii.inf_amd64_5a00035b3c0dd9d1\Display.NvContainer\NVDisplay.Container.exe [1275608 2025-09-06] (NVIDIA Corporation -> NVIDIA Corporation)
S4 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\25.209.1026.0002\OneDriveUpdaterService.exe [3891560 2025-11-22] (Microsoft Corporation -> Microsoft Corporation)
R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [75136 2026-01-02] (Even Balance, Inc. -> )
R3 ProtonVPN Service; C:\Program Files\Proton\VPN\v4.3.12\ProtonVPNService.exe [477424 2026-02-02] (Proton AG -> ProtonVPN)
S3 ProtonVPN WireGuard; C:\Program Files\Proton\VPN\v4.3.12\ProtonVPN.WireGuardService.exe [476912 2026-02-02] (Proton AG -> ProtonVPN)
S4 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [625928 2024-03-14] (CyberLink Corp. -> CyberLink)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [811360 2026-03-10] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 UpcElevationService; C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher Core\UpcElevationService.exe [351928 2026-01-11] (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24080.9-0\NisSrv.exe [3199656 2024-09-17] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24080.9-0\MsMpEng.exe [133704 2024-09-17] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WondersharePDFelement11DispatchService; C:\Program Files\Common Files\Wondershare\PDFelement11\DispatchService\PEServiceProcess.exe [342784 2025-05-14] (Wondershare Technology Group Co.,Ltd -> Wondershare)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [232928 2025-11-03] (ESET, spol. s r.o. -> ESET)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [139904 2025-11-03] (Microsoft Windows Hardware Compatibility Publisher -> ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [17840 2025-11-27] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [273768 2025-11-03] (ESET, spol. s r.o. -> ESET)
R2 ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [57368 2025-11-03] (ESET, spol. s r.o. -> ESET)
R1 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [86800 2025-11-03] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [126552 2025-11-03] (ESET, spol. s r.o. -> ESET)
R2 googledrivefs31931; C:\Program Files\Google\Drive File Stream\Drivers\31931\googledrivefs31931.sys [386256 2025-05-12] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
R3 iaLPSS2_GPIO2_ADL; C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_gpio2_adl.inf_amd64_2325b3303ea42f05\iaLPSS2_GPIO2_ADL.sys [160864 2024-07-03] (Intel Corporation -> Intel Corporation)
R3 iaLPSS2_I2C_ADL; C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_i2c_adl.inf_amd64_faa1ee2d82393f4f\iaLPSS2_I2C_ADL.sys [231008 2024-07-03] (Intel Corporation -> Intel Corporation)
S0 iaStorVD; C:\WINDOWS\System32\drivers\iaStorVD.sys [1605296 2023-11-18] (Intel Corporation -> Intel Corporation)
R3 IntcUSB; C:\WINDOWS\System32\DriverStore\FileRepository\intcusb.inf_amd64_1c0211bf85dbecec\IntcUSB.sys [940984 2025-08-15] (Intel Corporation -> Intel(R) Corporation)
R3 IntelGNA; C:\WINDOWS\System32\DriverStore\FileRepository\gna.inf_amd64_8e2f374849f1eba9\gna.sys [90208 2024-01-26] (Intel Corporation -> Intel Corporation)
R3 ipf_acpi; C:\WINDOWS\System32\DriverStore\FileRepository\ipf_acpi.inf_amd64_741faa404ec5212c\ipf_acpi.sys [90552 2025-09-03] (Intel Corporation -> Intel Corporation)
R3 ipf_cpu; C:\WINDOWS\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_09022c71eac15532\ipf_cpu.sys [542168 2025-09-03] (Intel Corporation -> Intel Corporation)
S3 ipf_lf; C:\WINDOWS\System32\DriverStore\FileRepository\ipf_cpu.inf_amd64_049e38a37c46edc4\ipf_lf.sys [504912 2025-06-30] (Intel Corporation -> Intel Corporation)
R3 NahimicBTLink; C:\WINDOWS\System32\drivers\NahimicBTLink.sys [86200 2022-08-18] (A-Volute SAS -> Windows (R) Win 7 DDK provider)
S3 Nahimic_Mirroring; C:\WINDOWS\System32\drivers\Nahimic_Mirroring.sys [95896 2024-05-16] (A-Volute SAS -> Windows (R) Win 7 DDK provider)
R3 nvpcf; C:\WINDOWS\System32\drivers\nvpcf.sys [247000 2024-12-17] (NVIDIA Corporation -> NVIDIA Corporation)
S3 ProtonVPNCallout; C:\Program Files\Proton\VPN\v4.3.12\Resources\ProtonVPN.CalloutDriver.sys [41416 2025-12-05] (Proton AG -> Proton AG)
R3 rt68cx21; C:\WINDOWS\System32\DriverStore\FileRepository\rt68cx21x64.inf_amd64_71e10b6ede8d55f8\rt68cx21x64.sys [905256 2025-07-28] (Realtek Semiconductor Corp. -> Realtek)
S3 rtu53cx22x64; C:\WINDOWS\System32\DriverStore\FileRepository\rtu53cx22x64.inf_amd64_191dda4f2e7775ce\rtu53cx22x64.sys [1082344 2024-03-14] (Realtek Semiconductor Corp. -> Realtek Corporation)
R1 steamxbox; C:\WINDOWS\System32\drivers\steamxbox.sys [278208 2023-02-21] (Valve Corp. -> Valve Corporation)
S3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [39920 2019-10-23] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
S3 UsbNcm; C:\WINDOWS\System32\DriverStore\FileRepository\usbncm.inf_amd64_989230fcb4a5468f\UsbNcm.sys [208896 2026-03-10] (Microsoft Windows -> )
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [22080 2024-09-17] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [602392 2024-09-17] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105864 2024-09-17] (Microsoft Windows -> Microsoft Corporation)
S3 wintun; C:\WINDOWS\System32\drivers\wintun.sys [29592 2026-01-06] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
S3 WireGuard; C:\WINDOWS\System32\drivers\wireguard.sys [489368 2024-02-29] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-03-25 14:31 - 2026-03-25 14:31 - 003636021 _____ C:\Users\sern\Downloads\Návod_OPTIMA-LV-R_201909_CZ_v2 (3).pdf
2026-03-25 14:31 - 2026-03-25 14:31 - 003636021 _____ C:\Users\sern\Downloads\Návod_OPTIMA-LV-R_201909_CZ_v2 (2).pdf
2026-03-25 14:31 - 2026-03-25 14:31 - 003636021 _____ C:\Users\sern\Downloads\Návod_OPTIMA-LV-R_201909_CZ_v2 (1).pdf
2026-03-25 10:28 - 2026-03-25 10:29 - 000505876 _____ C:\Users\sern\Downloads\CN_UCB_2025_PENB.pdf
2026-03-23 21:44 - 2026-03-23 21:44 - 000560564 _____ C:\Users\sern\OneDrive\Desktop\260322_SOS Turnov-3NP.pdf
2026-03-22 15:47 - 2026-03-22 15:47 - 000714490 _____ C:\WINDOWS\system32\perfh005.dat
2026-03-22 15:47 - 2026-03-22 15:47 - 000153652 _____ C:\WINDOWS\system32\perfc005.dat
2026-03-22 11:49 - 2026-03-25 10:36 - 000000000 ____D C:\WINDOWS\CbsTemp
2026-03-22 03:04 - 2026-03-22 03:04 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2026-03-20 18:34 - 2026-03-20 18:34 - 000000000 ____D C:\Program Files\Microsoft GameInput
2026-03-19 11:19 - 2026-03-19 11:19 - 010545635 _____ C:\Users\sern\Downloads\Nepotvrzeno 451849.crdownload
2026-03-18 21:49 - 2026-03-18 21:49 - 000000000 ____D C:\Users\sern\Downloads\otazky
2026-03-18 18:16 - 2026-03-18 18:16 - 000000218 _____ C:\Users\sern\AppData\Local\recently-used.xbel
2026-03-18 14:37 - 2026-03-18 14:37 - 001655279 _____ C:\Users\sern\Downloads\otazky.zip
2026-03-16 07:46 - 2026-03-22 15:43 - 000000000 ____D C:\ProgramData\Realtek
2026-03-12 11:28 - 2026-03-12 19:03 - 000002890 _____ C:\WINDOWS\system32\Tasks\OneDC_Updater
2026-03-11 20:38 - 2026-03-11 20:38 - 000002974 _____ C:\WINDOWS\system32\Tasks\OmApSvcBroker
2026-03-10 23:31 - 2026-03-10 23:31 - 000083946 _____ C:\WINDOWS\SysWOW64\ctac.json
2026-03-10 23:31 - 2026-03-10 23:31 - 000083946 _____ C:\WINDOWS\system32\ctac.json
2026-03-10 23:31 - 2026-03-10 23:31 - 000036382 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2026-03-10 23:31 - 2026-03-10 23:31 - 000036382 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2026-03-03 16:33 - 2026-03-21 19:30 - 000453064 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingservicesproxy_d.dll.0
2026-02-27 23:46 - 2026-02-27 23:46 - 000071650 _____ C:\WINDOWS\system32\battery-report.html
2026-02-26 03:42 - 2026-02-26 03:42 - 000000000 ____D C:\Users\sern\AppData\Local\Robot Entertainment
2026-02-26 03:37 - 2026-02-26 03:37 - 000000223 _____ C:\Users\sern\OneDrive\Desktop\Orcs Must Die! 3.url
2026-02-26 01:11 - 2026-02-26 01:11 - 000000000 ____D C:\Users\sern\AppData\Roaming\Cuphead
2026-02-26 01:11 - 2026-02-26 01:11 - 000000000 ____D C:\Users\sern\AppData\LocalLow\Studio MDHR
2026-02-25 22:20 - 2026-02-25 22:20 - 000000222 _____ C:\Users\sern\OneDrive\Desktop\Cuphead.url
2026-02-25 22:20 - 2026-02-25 22:20 - 000000222 _____ C:\Users\sern\OneDrive\Desktop\Crawl.url
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-03-25 16:08 - 2024-07-08 19:50 - 000000000 ____D C:\FRST
2026-03-25 16:07 - 2024-04-01 08:24 - 000000000 ____D C:\WINDOWS\INF
2026-03-25 15:54 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\AppReadiness
2026-03-25 15:49 - 2024-12-23 09:06 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2026-03-25 15:49 - 2024-04-01 08:26 - 000000000 ___HD C:\Program Files\WindowsApps
2026-03-25 15:49 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SystemTemp
2026-03-25 15:49 - 2024-04-01 08:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-03-25 15:49 - 2023-11-20 21:48 - 000000000 ____D C:\Users\sern\AppData\Local\Packages
2026-03-25 15:49 - 2023-11-20 21:45 - 000000000 ___SD C:\Users\sern\AppData\Roaming\Microsoft\Credentials
2026-03-25 15:49 - 2023-11-20 21:41 - 000000000 ____D C:\ProgramData\Packages
2026-03-25 14:22 - 2023-12-20 09:57 - 000000000 ____D C:\Users\sern\AppData\Roaming\Microsoft\Word
2026-03-25 03:03 - 2025-12-01 21:03 - 000000000 ____D C:\Users\sern\AppData\Local\Ubisoft Game Launcher
2026-03-24 03:20 - 2023-11-20 22:55 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2026-03-23 22:05 - 2023-12-20 10:17 - 000000000 ____D C:\Users\sern\AppData\Roaming\Microsoft\Excel
2026-03-23 11:46 - 2023-11-20 21:52 - 000000000 ____D C:\Users\sern\AppData\Local\D3DSCache
2026-03-22 15:52 - 2024-02-09 18:36 - 000000000 ____D C:\ProgramData\boost_interprocess
2026-03-22 15:52 - 2023-11-22 20:07 - 000000000 ____D C:\Users\sern\AppData\Local\CrashDumps
2026-03-22 15:47 - 2024-12-23 10:24 - 001692332 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2026-03-22 15:43 - 2024-12-23 10:29 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2026-03-22 15:43 - 2024-12-23 10:22 - 000014162 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2026-03-22 15:43 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\ServiceState
2026-03-22 15:43 - 2023-11-20 21:51 - 000000000 ____D C:\ProgramData\NVIDIA
2026-03-22 15:43 - 2023-11-20 21:39 - 000012288 ___SH C:\DumpStack.log.tmp
2026-03-22 15:42 - 2024-04-01 08:21 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2026-03-21 19:30 - 2024-08-31 14:07 - 004590024 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgameruntime.dll
2026-03-21 19:30 - 2024-08-31 14:07 - 000911816 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameplatformservices.dll
2026-03-21 19:30 - 2024-08-31 14:07 - 000289224 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamelaunchhelper.dll
2026-03-21 19:30 - 2024-08-31 14:07 - 000260552 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameconfighelper.dll
2026-03-21 19:30 - 2024-08-31 14:07 - 000166344 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingtcuihelpers.dll
2026-03-21 19:30 - 2024-08-31 14:07 - 000154056 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgamehelper.exe
2026-03-21 19:30 - 2024-08-31 14:07 - 000084424 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgamecontrol.exe
2026-03-21 15:59 - 2024-09-24 10:18 - 000000000 ____D C:\Program Files\Microsoft Office
2026-03-16 22:27 - 2025-02-15 11:42 - 000000000 ____D C:\SteamLibrary
2026-03-12 19:06 - 2024-12-23 09:06 - 000001623 _____ C:\WINDOWS\system32\config\VSMIDK
2026-03-12 19:05 - 2024-12-23 09:06 - 000588920 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2026-03-12 19:04 - 2024-12-23 00:14 - 000000000 ____D C:\WINDOWS\system32\Drivers\en-GB
2026-03-12 19:04 - 2024-04-01 17:31 - 000000000 ____D C:\WINDOWS\InboxApps
2026-03-12 19:04 - 2024-04-01 17:31 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2026-03-12 19:04 - 2024-04-01 17:30 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
2026-03-12 19:04 - 2024-04-01 08:26 - 000000000 ___SD C:\WINDOWS\system32\F12
2026-03-12 19:04 - 2024-04-01 08:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2026-03-12 19:04 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\UUS
2026-03-12 19:04 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2026-03-12 19:04 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2026-03-12 19:04 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2026-03-12 19:04 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2026-03-12 19:04 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\SystemResources
2026-03-12 19:04 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2026-03-12 19:04 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2026-03-12 19:04 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\setup
2026-03-12 19:04 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2026-03-12 19:04 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\oobe
2026-03-12 19:04 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\migwiz
2026-03-12 19:04 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\Dism
2026-03-12 19:04 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\system32\appraiser
2026-03-12 19:04 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\ShellExperiences
2026-03-12 19:04 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\ShellComponents
2026-03-12 19:04 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2026-03-12 19:04 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\BrowserCore
2026-03-12 19:04 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2026-03-12 19:04 - 2024-04-01 08:26 - 000000000 ____D C:\WINDOWS\appcompat
2026-03-12 19:04 - 2024-04-01 08:21 - 000000000 ____D C:\WINDOWS\servicing
2026-03-11 20:49 - 2024-04-01 08:26 - 000282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2026-03-11 20:49 - 2024-04-01 08:26 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2026-03-11 20:38 - 2023-11-20 21:48 - 000000000 ____D C:\Program Files (x86)\MSI
2026-03-10 23:30 - 2024-12-23 10:22 - 003270144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2026-03-10 23:08 - 2024-12-23 10:29 - 000003638 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2026-03-10 23:08 - 2024-12-23 10:29 - 000003512 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2026-03-10 23:08 - 2024-02-02 12:40 - 000002173 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk
2026-03-10 23:08 - 2024-02-02 12:40 - 000002054 _____ C:\Users\sern\OneDrive\Desktop\Google Drive.lnk
2026-03-03 16:58 - 2025-03-13 08:55 - 000000374 _____ C:\Users\sern\OneDrive\Desktop\bio.txt
2026-02-26 03:37 - 2024-07-16 11:22 - 000000000 ____D C:\Users\sern\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
==================== Files in the root of some directories ========
2026-03-18 18:16 - 2026-03-18 18:16 - 000000218 _____ () C:\Users\sern\AppData\Local\recently-used.xbel
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================