prevence
Napsal: 01 čer 2026 17:29
Prosím o prevenci. občas je PC pomalé a pár se nereaguje.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 31-05-2026 01
Ran by admin (administrator) on DESKTOP-FS31EKR (HP HP Z240 Tower Workstation) (01-06-2026 18:20:57)
Running from C:\Users\admin\Desktop\FRST64.exe
Loaded Profiles: admin & MariaDB
Platform: Microsoft Windows 10 Pro Version 22H2 19045.6466 (X64) Language: Čeština (Česko)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe <2>
(C:\Program Files (x86)\EasyPHP-DevServer-14.1VC11\binaries\apache\bin\eds-httpd.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(C:\Program Files (x86)\EasyPHP-DevServer-14.1VC11\EasyPHP-DevServer-14.1VC11.exe ->) () [File not signed] C:\Program Files (x86)\EasyPHP-DevServer-14.1VC11\binaries\mysql\bin\eds-mysqld.exe
(C:\Program Files (x86)\EasyPHP-DevServer-14.1VC11\EasyPHP-DevServer-14.1VC11.exe ->) (Apache Software Foundation) [File not signed] C:\Program Files (x86)\EasyPHP-DevServer-14.1VC11\binaries\apache\bin\eds-httpd.exe <2>
(C:\Program Files (x86)\Zebra Technologies\Status Monitor\Status Monitor\StatusMonitor.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
(C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe ->) (Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe <6>
(C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe ->) (Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe <2>
(C:\Program Files\Google\Drive File Stream\125.0.0.0\GoogleDriveFS.exe ->) (Google LLC -> ) C:\Program Files\Google\Drive File Stream\125.0.0.0\crashpad_handler.exe
(C:\Program Files\Google\Drive File Stream\125.0.0.0\GoogleDriveFS.exe ->) (Google LLC -> Google LLC.) C:\Program Files\Google\Drive File Stream\126.0.5.0\GoogleDriveFS.exe
(C:\Program Files\Google\Drive File Stream\126.0.5.0\GoogleDriveFS.exe ->) (Google LLC -> ) C:\Program Files\Google\Drive File Stream\126.0.5.0\crashpad_handler.exe
(C:\Program Files\HP\HP Enabling Services\SysInfoCap.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Enabling Services\BridgeCommunication.exe
(C:\Program Files\LibreOffice\program\soffice.bin ->) (Power Software Limited -> Power Software Ltd) C:\Program Files\PowerISO\PWRISOVM.EXE
(C:\Program Files\LibreOffice\program\soffice.exe ->) (The Document Foundation -> The Document Foundation) C:\Program Files\LibreOffice\program\soffice.bin
(C:\Program Files\Mozilla Firefox\firefox.exe ->) (Mozilla Corporation -> Mozilla Foundation) C:\Program Files\Mozilla Firefox\crashhelper.exe
(C:\Program Files\Mozilla Thunderbird\thunderbird.exe ->) (Mozilla Corporation -> Mozilla Foundation) C:\Program Files\Mozilla Thunderbird\crashhelper.exe
(C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\SLDWORKS.exe ->) (Dassault Systemes SolidWorks Corp. -> Dassault Systèmes SolidWorks Corp.) C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\sldProcMon.exe
(C:\Program Files\TeamViewer\TeamViewer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.96\msedgewebview2.exe <6>
(C:\Program Files\TeamViewer\TeamViewer_Service.exe ->) (TeamViewer Germany GmbH -> ) C:\Program Files\TeamViewer\crashpad_handler.exe <2>
(C:\Program Files\TeamViewer\TeamViewer_Service.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files\TeamViewer\TeamViewer.exe
(C:\Program Files\TeamViewer\TeamViewer_Service.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files\TeamViewer\tv_w32.exe
(C:\Program Files\TeamViewer\TeamViewer_Service.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files\TeamViewer\tv_x64.exe
(C:\Program Files\totalcmd\TOTALCMD64.EXE ->) (Jan Fiala -> Jan Fiala) C:\Program Files\PSPad editor\PSPad.exe
(C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2616.100.0_x64__cv1g1gvanyjgm\WhatsApp.Root.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.83\msedgewebview2.exe <26>
(C:\Program Files\WindowsApps\Claude_1.9659.2.0_x64__pzs8sxrjxfjjc\app\claude.exe ->) (Anthropic, PBC -> Anthropic PBC) C:\Users\admin\AppData\Local\Packages\Claude_pzs8sxrjxfjjc\LocalCache\Roaming\Claude\claude-code\2.1.156\claude.exe <2>
(C:\Program Files\WindowsApps\Claude_1.9659.2.0_x64__pzs8sxrjxfjjc\app\claude.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
(C:\Program Files\WindowsApps\Microsoft.YourPhone_1.25072.79.0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.25072.79.0_x64__8wekyb3d8bbwe\YourPhoneAppProxy.exe
(C:\Users\admin\AppData\Roaming\ArduinoCloudAgent\Arduino_Cloud_Agent.exe ->) () [File not signed] C:\Users\admin\.arduino-create\builtin\serial-discovery\1.4.3\serial-discovery.exe
(C:\Windows\SysWOW64\cmd.exe ->) (Python Software Foundation -> Python Software Foundation) C:\Users\admin\AppData\Local\Programs\Python\Python312\python.exe
(cmd.exe ->) (The PHP Group) [File not signed] C:\Program Files (x86)\EasyPHP-DevServer-14.1VC11\binaries\php\php_runningversion\php.exe <6>
(explorer.exe ->) () [File not signed] C:\Users\admin\AppData\Roaming\ArduinoCloudAgent\Arduino_Cloud_Agent.exe
(explorer.exe ->) (24803D75-212C-471A-BC57-9EF86AB91435 -> WhatsApp.Root) C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2616.100.0_x64__cv1g1gvanyjgm\WhatsApp.Root.exe
(explorer.exe ->) (Dassault Systemes SolidWorks Corp. -> Dassault Systèmes SolidWorks Corp.) C:\Program Files (x86)\Common Files\Manažer instalací SOLIDWORKS\BackgroundDownloading\sldBgDwld.exe
(explorer.exe ->) (Dassault Systemes SolidWorks Corp. -> Dassault Systèmes SolidWorks Corp.) C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\SLDWORKS.exe
(explorer.exe ->) (Dassault Systemes SolidWorks Corp. -> Dassault Systèmes SolidWorks Corp.) C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\sldworks_fs.exe
(explorer.exe ->) (EasyPHP) [File not signed] C:\Program Files (x86)\EasyPHP-DevServer-14.1VC11\EasyPHP-DevServer-14.1VC11.exe
(explorer.exe ->) (Ghisler Software GmbH -> Ghisler Software GmbH) C:\Program Files\totalcmd\TOTALCMD64.EXE
(explorer.exe ->) (Google LLC -> Google LLC.) C:\Program Files\Google\Drive File Stream\125.0.0.0\GoogleDriveFS.exe
(explorer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(explorer.exe ->) (Open Source Developer, Stefan Kueng -> hxxps://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
(explorer.exe ->) (Petr Laštovička) [File not signed] C:\Program Files (x86)\hotkeyp\HotkeyP.exe
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(explorer.exe ->) (Star Micronics Co., Ltd.) [File not signed] C:\Program Files (x86)\StarMicronics\TSP100\Software\20221130\Ondemand.exe
(explorer.exe ->) (Zebra Technologies Corporation -> Zebra Technologies Corporation) [File not signed] C:\Program Files (x86)\Zebra Technologies\Status Monitor\Status Monitor\StatusMonitor.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotifyIcon.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\timeout.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <76>
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Thunderbird\thunderbird.exe <4>
(services.exe ->) () [File not signed] C:\Program Files (x86)\TRENDnet Wireless USB Adapter Driver\WPSService20.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Anthropic, PBC -> ) C:\Program Files\WindowsApps\Claude_1.9659.2.0_x64__pzs8sxrjxfjjc\app\resources\cowork-svc.exe
(services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(services.exe ->) (Flexera Software LLC -> Flexera Software LLC) C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
(services.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome Remote Desktop\148.0.7778.23\remoting_host.exe <2>
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Enabling Services\AppHelperCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Enabling Services\DiagsCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Enabling Services\NetworkCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Enabling Services\SysInfoCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_af50fdb80983f7bc\jhi_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_a55aa2cd52a3429d\LMS.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d51901c26227fb29\WMIRegistrationService.exe
(services.exe ->) (Intel Corporation -> Intel(R) Corporation) C:\Windows\System32\DriverStore\FileRepository\iclsclient.inf_amd64_fc84dfa25a6a7727\lib\TPMProvisioningService.exe
(services.exe ->) (Intel Corporation -> Intel(R) Corporation) C:\Windows\SysWOW64\XtuService.exe
(services.exe ->) (MariaDB Corporation Ab -> ) C:\Program Files\MariaDB 11.3\bin\mysqld.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\NisSrv.exe
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvwu.inf_amd64_3f2a4c162f79e81f\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvwu.inf_amd64_3f2a4c162f79e81f\NVWMI\nvWmi64.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
(sihost.exe ->) (Anthropic, PBC -> Anthropic) C:\Program Files\WindowsApps\Claude_1.9659.2.0_x64__pzs8sxrjxfjjc\app\claude.exe <9>
(sihost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_11.2508.4.0_x64__8wekyb3d8bbwe\CalculatorApp.exe <2>
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneMusic_11.2604.9.0_x64__8wekyb3d8bbwe\Microsoft.Media.Player.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\FileCoAuth.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe <8>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <4>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(The Document Foundation -> The Document Foundation) C:\Program Files\LibreOffice\program\soffice.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [18391120 2019-03-04] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [TSP100ecoOndemand] => C:\Program Files (x86)\StarMicronics\TSP100\Software\20221130\Ondemand.exe [476672 2017-12-22] (Star Micronics Co., Ltd.) [File not signed]
HKLM-x32\...\Run: [PWRISOVM.EXE] => C:\Program Files\PowerISO\PWRISOVM.EXE [463488 2025-04-30] (Power Software Limited -> Power Software Ltd)
HKLM\...\RunOnce: [msedge_cleanup_{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}] => C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.96\Installer\setup.exe [5324144 2026-05-30] (Microsoft Corporation -> Microsoft Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKLM\SYSTEM\...\Terminal Server: [fDenyTSConnections] = 0 <==== ATTENTION
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\126.0.5.0\GoogleDriveFS.exe [78282392 2026-05-28] (Google LLC -> Google LLC.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\126.0.5.0\GoogleDriveFS.exe [78282392 2026-05-28] (Google LLC -> Google LLC.)
HKU\S-1-5-21-4195152011-4283894360-3570850043-1001\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\126.0.5.0\GoogleDriveFS.exe [78282392 2026-05-28] (Google LLC -> Google LLC.)
HKU\S-1-5-21-4195152011-4283894360-3570850043-1001\...\Run: [EasyPHP] => C:\Program Files (x86)\EasyPHP-DevServer-14.1VC11\EasyPHP-DevServer-14.1VC11.exe [279552 2014-01-09] (EasyPHP) [File not signed]
HKU\S-1-5-21-4195152011-4283894360-3570850043-1001\...\Run: [HotkeyP] => C:\Program Files (x86)\hotkeyp\HotkeyP.exe [147456 2012-11-20] (Petr Laštovička) [File not signed]
HKU\S-1-5-21-4195152011-4283894360-3570850043-1001\...\Run: [Mozilla-Firefox-308046B0AF4A39CB] => "C:\Program Files\Mozilla Firefox\firefox.exe" -os-autostart [705152 2026-05-21] (Mozilla Corporation -> Mozilla Corporation)
HKU\S-1-5-21-4195152011-4283894360-3570850043-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [42087896 2026-05-13] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-4195152011-4283894360-3570850043-1001\...\RunOnce: [Delete Cached Update Binary] => C:\Windows\system32\cmd.exe /q /c del /q "C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" [117611880 2026-05-27] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-4195152011-4283894360-3570850043-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\Windows\system32\cmd.exe /q /c del /q "C:\Users\admin\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File)
HKU\S-1-5-21-4195152011-4283894360-3570850043-1001\...\RunOnce: [Uninstall 26.078.0426.0002] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.078.0426.0002" [0 2026-05-27]
HKU\S-1-5-21-4195152011-4283894360-3570850043-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [39936 2024-05-22] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-80-3070791953-3247979545-275873789-2352004973-969172767\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\126.0.5.0\GoogleDriveFS.exe [78282392 2026-05-28] (Google LLC -> Google LLC.)
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\126.0.5.0\GoogleDriveFS.exe [78282392 2026-05-28] (Google LLC -> Google LLC.)
HKLM\...\Print\Monitors\Star Language Monitor Host: C:\Windows\system32\SMJLMHOST.DLL [31048 2021-09-03] (Microsoft Windows Hardware Compatibility Publisher -> Star Micronics Co., Ltd.)
HKLM\...\Print\Monitors\TSP100LAN Port: C:\Windows\system32\smjt100epm.dll [360960 2021-10-06] (Star Micronics Co., Ltd.) [File not signed]
HKLM\...\Print\Monitors\ZDesigner Language Monitor: C:\Windows\system32\zdnNLM64.dll [892056 2023-08-28] (Euro Plus d.o.o. -> Euro Plus d.o.o.)
HKLM\...\Print\Monitors\ZDesigner Port Monitor: C:\Windows\system32\zdnPMS.dll [290968 2021-02-02] (Microsoft Windows Hardware Compatibility Publisher -> Euro Plus d.o.o.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{49210152-871f-4ffa-961d-a172abcbc09d}] -> C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [3995288 2026-05-21] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\148.0.7778.179\Installer\chrmstp.exe [7621272 2026-05-22] (Google LLC -> Google LLC)
Startup: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Arduino Cloud Agent.lnk [2024-12-14]
ShortcutTarget: Arduino Cloud Agent.lnk -> C:\Users\admin\AppData\Roaming\ArduinoCloudAgent\Arduino_Cloud_Agent.exe () [File not signed]
Startup: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LibreOffice 7.5.lnk [2024-07-08]
ShortcutTarget: LibreOffice 7.5.lnk -> C:\Program Files\LibreOffice\program\quickstart.exe (The Document Foundation -> The Document Foundation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SOLIDWORKS 2016 Rychlé spuštění.lnk [2023-10-29]
ShortcutTarget: SOLIDWORKS 2016 Rychlé spuštění.lnk -> C:\Windows\Installer\{768F3B65-1695-47B7-9002-B11400CB111D}\NewShortcut2_87EDF6C81D0A4B7B84F42FE0C6A9D608.exe (Flexera Software LLC) [File not signed]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SOLIDWORKS Nástroj pro stahování na pozadí.lnk [2023-10-29]
ShortcutTarget: SOLIDWORKS Nástroj pro stahování na pozadí.lnk -> C:\Program Files (x86)\Common Files\Manažer instalací SOLIDWORKS\BackgroundDownloading\sldBgDwld.exe (Dassault Systemes SolidWorks Corp. -> Dassault Systèmes SolidWorks Corp.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Zebra Status Monitor.lnk [2024-03-01]
ShortcutTarget: Zebra Status Monitor.lnk -> C:\Program Files (x86)\Zebra Technologies\Status Monitor\Status Monitor\StatusMonitor.exe (Zebra Technologies Corporation -> Zebra Technologies Corporation) [File not signed]
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {5D14D1C4-B128-45CD-A4AA-F55089B6C810} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1612800 2026-01-23] (Adobe Inc. -> Adobe Inc.)
Task: {2F040900-C75F-44EB-A3A9-68A581A8139C} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe (No File)
Task: {325799CC-9E03-484E-BF8D-D4A3D534CED2} - System32\Tasks\FIRMA EnviCon WIN CRON 231122 => C:\Users\admin\Documents\www\www.admin.loc\system\BAT\environment_control.bat [252 2023-12-21] () [File not signed]
Task: {A816C1B9-AFD2-418C-9CF4-D55E2508ADB1} - System32\Tasks\FIRMA IMAP syncro 231018 => C:\Users\admin\Documents\www\www.admin.loc\system\Python\imap_syncro.bat [120 2026-03-13] () [File not signed]
Task: {9D47B887-D9C3-40A0-A6D2-7ABFDEA1DB0E} - System32\Tasks\FIRMA machines_log => C:\Users\admin\Documents\www\www.admin.loc\system\BAT\machines_log_loop.bat [1099 2025-11-25] () [File not signed]
Task: {807ECA39-F18D-412D-A42C-984C2594A765} - System32\Tasks\FIRMA machines_log_babyplast => C:\Users\admin\Documents\www\www.admin.loc\system\BAT\machine_log_babyplast.bat [254 2025-04-18] () [File not signed]
Task: {F1219E15-2BD8-451F-A89E-6C690EEAB6BD} - System32\Tasks\FIRMA ModBus update_register_values => C:\Users\admin\Documents\www\www.admin.loc\system\BAT\update_modbus_register_values.bat [403 2025-10-28] () [File not signed]
Task: {2B61D230-7393-4B16-8082-D54EA0E74425} - System32\Tasks\FIRMA MySQL repair tables => C:\Users\admin\Documents\www\www.admin.loc\system\BAT\mysqlcheck_repair_database.bat [703 2023-10-10] () [File not signed]
Task: {57BE48EC-80C8-46FD-949A-A6630EC03B01} - System32\Tasks\FIRMA netatmo WIN CRON 231122 => C:\Users\admin\Documents\www\www.admin.loc\system\BAT\neatmo_datalogger_loop.bat [258 2025-01-05] () [File not signed]
Task: {C6A93376-162F-455D-8FE9-A23D15470163} - System32\Tasks\FIRMA shelly datalogger WIN CRON 250307 => C:\Users\admin\Documents\www\www.admin.loc\system\BAT\shelly_datalogger_loop .bat [253 2025-02-06] () [File not signed]
Task: {379A822F-7F92-4F00-AD58-C358692D6FA3} - System32\Tasks\FIRMA spot_data => C:\Users\admin\Documents\www\www.admin.loc\system\BAT\spot_datalogger.bat [246 2025-02-24] () [File not signed]
Task: {09A4D201-68D7-4D48-92E7-584D051C1066} - System32\Tasks\FIRMA update => C:\Users\admin\Documents\www\www.admin.loc\system\BAT\update_company_loop.bat [393 2023-07-26] () [File not signed]
Task: {BCDA2884-4FCF-4602-8A10-D8EDECB7EF0D} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem149.0.7814.0{32C9A04B-4E22-46C1-A482-DCAAE923982D} => C:\Program Files (x86)\Google\GoogleUpdater\149.0.7814.0\updater.exe [8770200 2026-04-28] (Google LLC -> Google LLC)
Task: {63F8C573-B758-4621-A1CE-737C519AC508} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Update Notice => C:\Program Files (x86)\HP\HP Support Framework\Resources\BingPopup\BingPopup.exe [1015880 2025-12-15] (HP Inc. -> HP Inc.) -> C:\Program Files (x86)\HP\HP Support Framework\\/show
Task: {2C06E407-82AE-49BB-8802-DCBA29FAEEB0} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPSFReport.exe [480264 2025-12-15] (HP Inc. -> HP Inc.)
Task: {EFFF80A3-16B0-4759-A841-7D89ECD47A52} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HPPrinterLowInk => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPPrinterLowInk\HPPrinterLowInk.exe [231944 2025-12-15] (HP Inc. -> HP Inc.) -> C:\Program Files (x86)\HP\HP Support Framework\\/show
Task: {80E18DBA-43D7-4154-93A7-C0BBD6808EA3} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [95240 2026-04-08] (HP Inc. -> HP Inc.)
Task: {8C27B44F-2F1E-4798-8B98-FF5A8217CCB1} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor Logon => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [95240 2026-04-08] (HP Inc. -> HP Inc.)
Task: {E57F4FC9-B3C3-4C3B-ACE6-746381E6C8B5} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe [1794752 2026-05-21] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {3B6EB3AC-7AEC-4817-8BA8-6042F8CE87C8} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe [1794752 2026-05-21] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {49055789-A444-4910-8742-8983633AB4BB} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe [1794752 2026-05-21] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {039AEE08-7B10-432D-8CDA-2D51E131B070} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe [1794752 2026-05-21] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {DBCE80E3-4681-4216-9E18-9FD4429CE123} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-4195152011-4283894360-3570850043-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [705152 2026-05-21] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {C86D8830-BD6E-4B3B-AF90-1A75C4CBE83B} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [33920 2026-05-21] (Mozilla Corporation -> Mozilla Foundation)
Task: {D5D95642-ED86-4F5B-A37D-6C737AAD7121} - System32\Tasks\nWizard_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [1554120 2023-10-29] (Nvidia Corporation -> NVIDIA Corporation) -> C:\Program Files\NVIDIA Corporation\nview\/installquiet
Task: {98BC8EB2-29D3-47B9-95C7-3E0A315224B8} - System32\Tasks\python beep => G:\Můj disk\#dev\Python\Zvuk\#RUN# demo.bat [34 2024-02-24] () [File not signed]
Task: {0D1EA15C-623A-4DAB-B05F-78E0B169BB76} - System32\Tasks\ZoomUpdateTaskUser-S-1-5-21-4195152011-4283894360-3570850043-1001 => C:\Users\admin\AppData\Roaming\Zoom\bin\Zoom.exe [434488 2025-03-07] (Zoom Video Communications, Inc. -> Zoom Communications, Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 08 C:\Program Files\Bonjour\mdnsNSP.dll [132968 2011-08-30] (Apple Inc. -> Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.11.1
Tcpip\..\Interfaces\{e8b2eadf-34b4-491c-8507-1c3a230950d9}: [DhcpNameServer] 192.168.11.1
Tcpip\..\Interfaces\{e8b2eadf-34b4-491c-8507-1c3a230950d9}: [DhcpDomain] suchomelplasty.loc
FireFox:
========
FF TaskBarID: 308046B0AF4A39CB -> C:\Program Files\Mozilla Firefox
FF Plugin: 3ds.com/ComposerPlayerWebPlugin_x86_64 -> C:\PROGRA~1\SOLIDW~1\SOLIDW~3\Bin\NPCOMP~1.DLL [2016-10-13] (DASSAULT SYSTEMES SA -> Dassault Systemes)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2026-05-13] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: 3ds.com/ComposerPlayerWebPlugin -> C:\PROGRA~1\SOLIDW~1\SOLIDW~3\Bin\x86\NPCOMP~1.DLL [2016-10-13] (DASSAULT SYSTEMES SA -> Dassault Systemes)
Edge:
=======
Edge Profile: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default [2026-05-25]
Edge Session Restore: Default -> is enabled.
Edge Extension: (Dokumenty Google offline) - C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-05-19]
Edge Extension: (Edge relevant text changes) - C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24]
Chrome:
=======
CHR Profile: C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default [2026-05-11]
CHR Notifications: Default -> hxxps://calendar.google.com; hxxps://home.netatmo.com
CHR StartupUrls: Default -> "hxxps://tvgo.t-mobile.cz/"
CHR Session Restore: Default -> is enabled.
CHR Extension: (Tablet Gestures) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\adpfjochlgeifbpfnlchcdcmoaafnoim [2023-10-28]
CHR Extension: (Adblock na Youtube™) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2026-05-10]
CHR Extension: (Type-ahead-find) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpecbmjeidppdiampimghndkikcmoadk [2025-04-14]
CHR Extension: (Sider: Chat with all AI: GPT-5, Claude, DeepSeek, Gemini, Grok) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\difoiogjjojoaoomphldepapgpbgkhkb [2026-05-10]
CHR Extension: (Typio Form Recovery) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\djkbihbnjhkjahbhjaadbepppbpoedaa [2023-10-28]
CHR Extension: (Go Back With Backspace) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\eekailopagacbcdloonjhbiecobagjci [2024-10-31]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2026-05-10]
CHR Extension: (I don't care about cookies) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fihnjjcciajhdojfnbdddfaoknhalnja [2024-07-11]
CHR Extension: (Dokumenty Google offline) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-05-10]
CHR Extension: (RestMan) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihgpcfpkpmdcghlnaofdmjkoemnlijdi [2025-03-09]
CHR Extension: (Chrome Remote Desktop) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\inomeogfingihgjfjlpeplalcfajhgai [2023-10-28]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-10-28]
CHR Extension: (x3d-viewer) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneaojlgmfmngeckfemdbfpgedgfpgdg [2024-03-23]
CHR Extension: (Open Email Client) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\oofmnabdpcibefadlibdpnnbglcehfpj [2024-07-31]
CHR HKU\S-1-5-21-4195152011-4283894360-3570850043-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKU\S-1-5-21-4195152011-4283894360-3570850043-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [180216 2026-01-23] (Adobe Inc. -> Adobe Inc.)
R2 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\148.0.7778.23\remoting_host.exe [74392 2026-04-13] (Google LLC -> Google LLC)
R2 CoworkVMService; C:\Program Files\WindowsApps\Claude_1.9659.2.0_x64__pzs8sxrjxfjjc\app\resources\cowork-svc.exe [12649808 2026-05-29] (Anthropic, PBC -> )
R2 HPAppHelperCap; C:\Program Files\HP\HP Enabling Services\AppHelperCap.exe [930400 2025-09-02] (HP Inc. -> HP Inc.)
R2 HPDiagsCap; C:\Program Files\HP\HP Enabling Services\DiagsCap.exe [928864 2025-09-02] (HP Inc. -> HP Inc.)
R2 HPNetworkCap; C:\Program Files\HP\HP Enabling Services\NetworkCap.exe [924784 2025-09-02] (HP Inc. -> HP Inc.)
R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [244232 2026-04-08] (HP Inc. -> HP Inc.)
R2 HPSysInfoCap; C:\Program Files\HP\HP Enabling Services\SysInfoCap.exe [929400 2025-09-02] (HP Inc. -> HP Inc.)
R2 MariaDB; C:\Program Files\MariaDB 11.3\bin\mysqld.exe [34728 2023-09-17] (MariaDB Corporation Ab -> )
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpDefenderCoreService.exe [2096384 2026-05-21] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVWMI; C:\Windows\System32\DriverStore\FileRepository\nvwu.inf_amd64_3f2a4c162f79e81f\NVWMI\nvWmi64.exe [4476632 2023-10-29] (Nvidia Corporation -> NVIDIA Corporation)
S3 PortEmulator; C:\Program Files\StarMicronics\TSP100\Software\20221130\portemu_umdf_tsp100.exe [207872 2016-02-26] () [File not signed]
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [803064 2025-11-21] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 SolidWorks Licensing Service; C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [79360 2023-10-29] (SolidWorks) [File not signed]
S3 TcpEmulatorTSP100LAN; C:\Program Files\StarMicronics\TSP100\Software\20221130\tcpemu_tsp100lan.exe [351744 2015-05-22] (STAR MICRONICS CO,.LTD) [File not signed]
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [26931024 2026-05-20] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\NisSrv.exe [4484680 2026-05-21] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MsMpEng.exe [290704 2026-05-21] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WPSService20; C:\Program Files (x86)\TRENDnet Wireless USB Adapter Driver\WPSService20.exe [96768 2017-01-06] () [File not signed]
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nvwu.inf_amd64_3f2a4c162f79e81f\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\Windows\System32\DriverStore\FileRepository\nvwu.inf_amd64_3f2a4c162f79e81f\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 FTDIBUS; C:\Windows\system32\drivers\ftdibus.sys [152608 2024-11-19] (WDKTestCert andy.miller,132291778652267126 -> Future Technology Devices International Ltd.)
R3 FTSER2K; C:\Windows\system32\drivers\ftser2k.sys [101520 2024-11-19] (WDKTestCert andy.miller,132291778652267126 -> Future Technology Devices International Ltd.)
R2 googledrivefs31931; C:\Program Files\Google\Drive File Stream\Drivers\31931\googledrivefs31931.sys [386256 2025-05-07] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
R3 KslD; C:\Windows\System32\drivers\wd\KslD.sys [82312 2026-05-21] (Microsoft Windows -> Microsoft Corporation)
R3 plser; C:\Windows\system32\DRIVERS\plser64.sys [336736 2026-01-28] (Microsoft Windows Hardware Compatibility Publisher -> Prolific Technology Inc.)
S3 ss_conn_usb_driver2; C:\Windows\System32\Drivers\ss_conn_usb_driver2.sys [50720 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [21888 2026-05-21] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [606600 2026-05-21] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [100784 2026-05-21] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-06-01 18:20 - 2026-06-01 18:23 - 000035753 _____ C:\Users\admin\Desktop\FRST.txt
2026-06-01 18:07 - 2026-06-01 18:07 - 002782208 _____ (Farbar) C:\Users\admin\Desktop\FRST64.exe
2026-06-01 18:04 - 2026-06-01 18:04 - 000025513 _____ C:\Users\admin\.claude.json
2026-05-27 17:23 - 2026-05-28 13:51 - 000000000 ____D C:\Program Files\Mozilla Thunderbird
2026-05-22 03:58 - 2026-05-22 03:58 - 000000000 ____D C:\Users\admin\AppData\Roaming\Python
2026-05-21 21:58 - 2026-05-21 21:58 - 000000000 ____D C:\Users\admin\AppData\Roaming\CadSoft
2026-05-21 21:58 - 2026-05-21 21:58 - 000000000 ____D C:\Users\admin\AppData\Local\ADPWebView
2026-05-21 21:11 - 2026-05-21 21:11 - 000000000 ____D C:\Users\admin\AppData\Local\Fusion360
2026-05-21 21:10 - 2026-05-21 21:10 - 000002674 _____ C:\Users\admin\Desktop\Autodesk Fusion.lnk
2026-05-21 21:10 - 2026-05-21 21:10 - 000000000 ____D C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Autodesk
2026-05-21 21:10 - 2026-05-21 21:10 - 000000000 ____D C:\Users\admin\AppData\Roaming\Fusion360
2026-05-21 21:03 - 2026-05-26 21:03 - 000000000 ____D C:\Program Files\Mozilla Firefox
2026-05-21 21:03 - 2026-05-21 21:03 - 013171144 _____ (Autodesk, Inc) C:\Users\admin\Downloads\Fusion Client Downloader.exe
2026-05-20 18:00 - 2026-05-20 18:00 - 000002933 _____ C:\Users\admin\Downloads\order_34730426.csv
2026-05-17 09:16 - 2026-05-17 09:16 - 000000000 ____D C:\Users\admin\.config
2026-05-11 14:11 - 2026-05-11 14:11 - 000000062 _____ C:\Users\admin\.gitconfig
2026-05-11 14:01 - 2026-05-21 05:13 - 000023291 _____ C:\Users\admin\.claude.json.backup
2026-05-11 13:57 - 2026-06-01 14:35 - 000000000 ____D C:\Users\admin\.claude
2026-05-11 13:54 - 2026-05-11 13:54 - 000000000 ____D C:\ProgramData\Claude
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-06-01 18:22 - 2024-01-26 20:41 - 000000000 ____D C:\FRST
2026-06-01 18:08 - 2023-10-28 21:32 - 000000000 ____D C:\Users\admin\AppData\Local\GHISLER
2026-06-01 18:04 - 2023-10-28 21:08 - 000000000 ____D C:\Users\admin
2026-06-01 17:39 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-06-01 17:35 - 2023-10-28 21:09 - 000000000 ___SD C:\Users\admin\AppData\Roaming\Microsoft\Credentials
2026-06-01 17:00 - 2023-10-28 20:58 - 000000000 ____D C:\Windows\system32\SleepStudy
2026-06-01 13:32 - 2022-09-08 05:11 - 000000000 ____D C:\Windows\SystemTemp
2026-06-01 11:54 - 2026-01-06 16:00 - 000000000 ____D C:\Program Files\TeamViewer
2026-06-01 11:54 - 2019-12-07 11:13 - 000000000 ____D C:\Windows\INF
2026-06-01 11:53 - 2023-10-28 21:33 - 000000000 ____D C:\Users\admin\AppData\Local\D3DSCache
2026-06-01 11:51 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2026-06-01 11:51 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\AppReadiness
2026-05-31 15:18 - 2023-10-29 21:01 - 000000000 ____D C:\ProgramData\NVIDIA
2026-05-30 17:11 - 2023-10-28 20:59 - 000003638 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2026-05-30 17:11 - 2023-10-28 20:59 - 000003512 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2026-05-30 11:12 - 2023-10-28 12:58 - 000001231 _____ C:\Users\admin\Desktop\!zaslat.cz.csv
2026-05-30 07:13 - 2023-10-28 20:59 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-05-29 14:37 - 2023-10-28 22:43 - 000002336 ____H C:\Users\admin\Documents\Default.rdp
2026-05-29 14:37 - 2019-12-07 16:45 - 000000000 ____D C:\Windows\system32\FxsTmp
2026-05-29 13:54 - 2023-10-29 16:04 - 000000000 ____D C:\Users\admin\AppData\Local\TempAdresářZálohySW
2026-05-28 23:20 - 2023-10-28 21:14 - 000002173 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk
2026-05-28 13:52 - 2023-10-29 15:25 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2026-05-28 13:51 - 2023-10-29 15:25 - 000001055 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thunderbird.lnk
2026-05-28 06:46 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\ServiceState
2026-05-27 13:41 - 2025-01-28 05:11 - 000003576 _____ C:\Windows\system32\Tasks\OneDrive Startup Task-S-1-5-21-4195152011-4283894360-3570850043-1001
2026-05-27 13:41 - 2023-10-28 21:11 - 000003592 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-4195152011-4283894360-3570850043-1001
2026-05-27 13:41 - 2023-10-28 21:10 - 000003380 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4195152011-4283894360-3570850043-1001
2026-05-27 13:41 - 2023-10-28 21:08 - 000002383 _____ C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-05-26 16:53 - 2024-03-14 10:07 - 000000000 ____D C:\Users\admin\Desktop\temp
2026-05-25 13:46 - 2023-10-29 17:11 - 000002146 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2026-05-25 13:34 - 2023-10-28 21:08 - 001694140 _____ C:\Windows\system32\PerfStringBackup.INI
2026-05-25 13:34 - 2019-12-07 16:43 - 000717008 _____ C:\Windows\system32\perfh005.dat
2026-05-25 13:34 - 2019-12-07 16:43 - 000145186 _____ C:\Windows\system32\perfc005.dat
2026-05-25 13:30 - 2023-10-29 15:25 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2026-05-25 13:27 - 2023-10-28 20:59 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2026-05-25 13:27 - 2023-10-28 20:58 - 000008192 ___SH C:\DumpStack.log.tmp
2026-05-22 13:59 - 2024-03-22 21:55 - 000001073 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2026-05-22 13:59 - 2024-03-22 21:55 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
2026-05-22 10:30 - 2023-10-29 15:29 - 000000000 ____D C:\Users\admin\Documents\1.SUCO
2026-05-22 04:21 - 2025-03-12 12:18 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2026-05-22 04:21 - 2025-03-12 12:18 - 000002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2026-05-21 21:58 - 2023-10-30 20:41 - 000000000 ____D C:\Users\admin\AppData\Roaming\Autodesk
2026-05-21 21:10 - 2023-10-30 20:41 - 000000000 ____D C:\Users\admin\AppData\Local\Autodesk
2026-05-21 21:10 - 2023-10-30 20:33 - 000000000 ____D C:\ProgramData\Autodesk
2026-05-21 20:50 - 2023-10-28 20:59 - 000000000 ____D C:\Windows\system32\Drivers\wd
2026-05-17 16:07 - 2023-10-29 00:23 - 000000000 ____D C:\Windows\system32\MRT
2026-05-17 15:56 - 2023-10-29 00:23 - 220340424 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2026-05-11 13:57 - 2023-10-28 21:57 - 000000000 ____D C:\Users\admin\Documents\www
2026-05-11 13:54 - 2023-10-28 21:09 - 000000000 ____D C:\Users\admin\AppData\Local\Packages
2026-05-11 13:54 - 2023-10-28 21:09 - 000000000 ____D C:\ProgramData\Packages
2026-05-03 11:46 - 2023-10-29 15:30 - 000000000 ____D C:\Users\admin\Documents\2.Suchomel PLASTY
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 31-05-2026 01
Ran by admin (administrator) on DESKTOP-FS31EKR (HP HP Z240 Tower Workstation) (01-06-2026 18:20:57)
Running from C:\Users\admin\Desktop\FRST64.exe
Loaded Profiles: admin & MariaDB
Platform: Microsoft Windows 10 Pro Version 22H2 19045.6466 (X64) Language: Čeština (Česko)
Default browser: FF
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe <2>
(C:\Program Files (x86)\EasyPHP-DevServer-14.1VC11\binaries\apache\bin\eds-httpd.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(C:\Program Files (x86)\EasyPHP-DevServer-14.1VC11\EasyPHP-DevServer-14.1VC11.exe ->) () [File not signed] C:\Program Files (x86)\EasyPHP-DevServer-14.1VC11\binaries\mysql\bin\eds-mysqld.exe
(C:\Program Files (x86)\EasyPHP-DevServer-14.1VC11\EasyPHP-DevServer-14.1VC11.exe ->) (Apache Software Foundation) [File not signed] C:\Program Files (x86)\EasyPHP-DevServer-14.1VC11\binaries\apache\bin\eds-httpd.exe <2>
(C:\Program Files (x86)\Zebra Technologies\Status Monitor\Status Monitor\StatusMonitor.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\splwow64.exe
(C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe ->) (Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe <6>
(C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe ->) (Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe <2>
(C:\Program Files\Google\Drive File Stream\125.0.0.0\GoogleDriveFS.exe ->) (Google LLC -> ) C:\Program Files\Google\Drive File Stream\125.0.0.0\crashpad_handler.exe
(C:\Program Files\Google\Drive File Stream\125.0.0.0\GoogleDriveFS.exe ->) (Google LLC -> Google LLC.) C:\Program Files\Google\Drive File Stream\126.0.5.0\GoogleDriveFS.exe
(C:\Program Files\Google\Drive File Stream\126.0.5.0\GoogleDriveFS.exe ->) (Google LLC -> ) C:\Program Files\Google\Drive File Stream\126.0.5.0\crashpad_handler.exe
(C:\Program Files\HP\HP Enabling Services\SysInfoCap.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Enabling Services\BridgeCommunication.exe
(C:\Program Files\LibreOffice\program\soffice.bin ->) (Power Software Limited -> Power Software Ltd) C:\Program Files\PowerISO\PWRISOVM.EXE
(C:\Program Files\LibreOffice\program\soffice.exe ->) (The Document Foundation -> The Document Foundation) C:\Program Files\LibreOffice\program\soffice.bin
(C:\Program Files\Mozilla Firefox\firefox.exe ->) (Mozilla Corporation -> Mozilla Foundation) C:\Program Files\Mozilla Firefox\crashhelper.exe
(C:\Program Files\Mozilla Thunderbird\thunderbird.exe ->) (Mozilla Corporation -> Mozilla Foundation) C:\Program Files\Mozilla Thunderbird\crashhelper.exe
(C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\SLDWORKS.exe ->) (Dassault Systemes SolidWorks Corp. -> Dassault Systèmes SolidWorks Corp.) C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\sldProcMon.exe
(C:\Program Files\TeamViewer\TeamViewer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.96\msedgewebview2.exe <6>
(C:\Program Files\TeamViewer\TeamViewer_Service.exe ->) (TeamViewer Germany GmbH -> ) C:\Program Files\TeamViewer\crashpad_handler.exe <2>
(C:\Program Files\TeamViewer\TeamViewer_Service.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files\TeamViewer\TeamViewer.exe
(C:\Program Files\TeamViewer\TeamViewer_Service.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files\TeamViewer\tv_w32.exe
(C:\Program Files\TeamViewer\TeamViewer_Service.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files\TeamViewer\tv_x64.exe
(C:\Program Files\totalcmd\TOTALCMD64.EXE ->) (Jan Fiala -> Jan Fiala) C:\Program Files\PSPad editor\PSPad.exe
(C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2616.100.0_x64__cv1g1gvanyjgm\WhatsApp.Root.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.83\msedgewebview2.exe <26>
(C:\Program Files\WindowsApps\Claude_1.9659.2.0_x64__pzs8sxrjxfjjc\app\claude.exe ->) (Anthropic, PBC -> Anthropic PBC) C:\Users\admin\AppData\Local\Packages\Claude_pzs8sxrjxfjjc\LocalCache\Roaming\Claude\claude-code\2.1.156\claude.exe <2>
(C:\Program Files\WindowsApps\Claude_1.9659.2.0_x64__pzs8sxrjxfjjc\app\claude.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
(C:\Program Files\WindowsApps\Microsoft.YourPhone_1.25072.79.0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.25072.79.0_x64__8wekyb3d8bbwe\YourPhoneAppProxy.exe
(C:\Users\admin\AppData\Roaming\ArduinoCloudAgent\Arduino_Cloud_Agent.exe ->) () [File not signed] C:\Users\admin\.arduino-create\builtin\serial-discovery\1.4.3\serial-discovery.exe
(C:\Windows\SysWOW64\cmd.exe ->) (Python Software Foundation -> Python Software Foundation) C:\Users\admin\AppData\Local\Programs\Python\Python312\python.exe
(cmd.exe ->) (The PHP Group) [File not signed] C:\Program Files (x86)\EasyPHP-DevServer-14.1VC11\binaries\php\php_runningversion\php.exe <6>
(explorer.exe ->) () [File not signed] C:\Users\admin\AppData\Roaming\ArduinoCloudAgent\Arduino_Cloud_Agent.exe
(explorer.exe ->) (24803D75-212C-471A-BC57-9EF86AB91435 -> WhatsApp.Root) C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2616.100.0_x64__cv1g1gvanyjgm\WhatsApp.Root.exe
(explorer.exe ->) (Dassault Systemes SolidWorks Corp. -> Dassault Systèmes SolidWorks Corp.) C:\Program Files (x86)\Common Files\Manažer instalací SOLIDWORKS\BackgroundDownloading\sldBgDwld.exe
(explorer.exe ->) (Dassault Systemes SolidWorks Corp. -> Dassault Systèmes SolidWorks Corp.) C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\SLDWORKS.exe
(explorer.exe ->) (Dassault Systemes SolidWorks Corp. -> Dassault Systèmes SolidWorks Corp.) C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS\sldworks_fs.exe
(explorer.exe ->) (EasyPHP) [File not signed] C:\Program Files (x86)\EasyPHP-DevServer-14.1VC11\EasyPHP-DevServer-14.1VC11.exe
(explorer.exe ->) (Ghisler Software GmbH -> Ghisler Software GmbH) C:\Program Files\totalcmd\TOTALCMD64.EXE
(explorer.exe ->) (Google LLC -> Google LLC.) C:\Program Files\Google\Drive File Stream\125.0.0.0\GoogleDriveFS.exe
(explorer.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(explorer.exe ->) (Open Source Developer, Stefan Kueng -> hxxps://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
(explorer.exe ->) (Petr Laštovička) [File not signed] C:\Program Files (x86)\hotkeyp\HotkeyP.exe
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(explorer.exe ->) (Star Micronics Co., Ltd.) [File not signed] C:\Program Files (x86)\StarMicronics\TSP100\Software\20221130\Ondemand.exe
(explorer.exe ->) (Zebra Technologies Corporation -> Zebra Technologies Corporation) [File not signed] C:\Program Files (x86)\Zebra Technologies\Status Monitor\Status Monitor\StatusMonitor.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MusNotifyIcon.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\timeout.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <76>
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Thunderbird\thunderbird.exe <4>
(services.exe ->) () [File not signed] C:\Program Files (x86)\TRENDnet Wireless USB Adapter Driver\WPSService20.exe
(services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(services.exe ->) (Anthropic, PBC -> ) C:\Program Files\WindowsApps\Claude_1.9659.2.0_x64__pzs8sxrjxfjjc\app\resources\cowork-svc.exe
(services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(services.exe ->) (Flexera Software LLC -> Flexera Software LLC) C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
(services.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome Remote Desktop\148.0.7778.23\remoting_host.exe <2>
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Enabling Services\AppHelperCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Enabling Services\DiagsCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Enabling Services\NetworkCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HP\HP Enabling Services\SysInfoCap.exe
(services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_af50fdb80983f7bc\jhi_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_a55aa2cd52a3429d\LMS.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d51901c26227fb29\WMIRegistrationService.exe
(services.exe ->) (Intel Corporation -> Intel(R) Corporation) C:\Windows\System32\DriverStore\FileRepository\iclsclient.inf_amd64_fc84dfa25a6a7727\lib\TPMProvisioningService.exe
(services.exe ->) (Intel Corporation -> Intel(R) Corporation) C:\Windows\SysWOW64\XtuService.exe
(services.exe ->) (MariaDB Corporation Ab -> ) C:\Program Files\MariaDB 11.3\bin\mysqld.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\NisSrv.exe
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvwu.inf_amd64_3f2a4c162f79e81f\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Nvidia Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nvwu.inf_amd64_3f2a4c162f79e81f\NVWMI\nvWmi64.exe <2>
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
(sihost.exe ->) (Anthropic, PBC -> Anthropic) C:\Program Files\WindowsApps\Claude_1.9659.2.0_x64__pzs8sxrjxfjjc\app\claude.exe <9>
(sihost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_11.2508.4.0_x64__8wekyb3d8bbwe\CalculatorApp.exe <2>
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneMusic_11.2604.9.0_x64__8wekyb3d8bbwe\Microsoft.Media.Player.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.084.0504.0007\FileCoAuth.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe <8>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <4>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(The Document Foundation -> The Document Foundation) C:\Program Files\LibreOffice\program\soffice.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [18391120 2019-03-04] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [TSP100ecoOndemand] => C:\Program Files (x86)\StarMicronics\TSP100\Software\20221130\Ondemand.exe [476672 2017-12-22] (Star Micronics Co., Ltd.) [File not signed]
HKLM-x32\...\Run: [PWRISOVM.EXE] => C:\Program Files\PowerISO\PWRISOVM.EXE [463488 2025-04-30] (Power Software Limited -> Power Software Ltd)
HKLM\...\RunOnce: [msedge_cleanup_{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}] => C:\Program Files (x86)\Microsoft\EdgeWebView\Application\148.0.3967.96\Installer\setup.exe [5324144 2026-05-30] (Microsoft Corporation -> Microsoft Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKLM\SYSTEM\...\Terminal Server: [fDenyTSConnections] = 0 <==== ATTENTION
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\126.0.5.0\GoogleDriveFS.exe [78282392 2026-05-28] (Google LLC -> Google LLC.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\126.0.5.0\GoogleDriveFS.exe [78282392 2026-05-28] (Google LLC -> Google LLC.)
HKU\S-1-5-21-4195152011-4283894360-3570850043-1001\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\126.0.5.0\GoogleDriveFS.exe [78282392 2026-05-28] (Google LLC -> Google LLC.)
HKU\S-1-5-21-4195152011-4283894360-3570850043-1001\...\Run: [EasyPHP] => C:\Program Files (x86)\EasyPHP-DevServer-14.1VC11\EasyPHP-DevServer-14.1VC11.exe [279552 2014-01-09] (EasyPHP) [File not signed]
HKU\S-1-5-21-4195152011-4283894360-3570850043-1001\...\Run: [HotkeyP] => C:\Program Files (x86)\hotkeyp\HotkeyP.exe [147456 2012-11-20] (Petr Laštovička) [File not signed]
HKU\S-1-5-21-4195152011-4283894360-3570850043-1001\...\Run: [Mozilla-Firefox-308046B0AF4A39CB] => "C:\Program Files\Mozilla Firefox\firefox.exe" -os-autostart [705152 2026-05-21] (Mozilla Corporation -> Mozilla Corporation)
HKU\S-1-5-21-4195152011-4283894360-3570850043-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [42087896 2026-05-13] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-4195152011-4283894360-3570850043-1001\...\RunOnce: [Delete Cached Update Binary] => C:\Windows\system32\cmd.exe /q /c del /q "C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" [117611880 2026-05-27] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-4195152011-4283894360-3570850043-1001\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\Windows\system32\cmd.exe /q /c del /q "C:\Users\admin\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No File)
HKU\S-1-5-21-4195152011-4283894360-3570850043-1001\...\RunOnce: [Uninstall 26.078.0426.0002] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\admin\AppData\Local\Microsoft\OneDrive\26.078.0426.0002" [0 2026-05-27]
HKU\S-1-5-21-4195152011-4283894360-3570850043-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [39936 2024-05-22] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-80-3070791953-3247979545-275873789-2352004973-969172767\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\126.0.5.0\GoogleDriveFS.exe [78282392 2026-05-28] (Google LLC -> Google LLC.)
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\126.0.5.0\GoogleDriveFS.exe [78282392 2026-05-28] (Google LLC -> Google LLC.)
HKLM\...\Print\Monitors\Star Language Monitor Host: C:\Windows\system32\SMJLMHOST.DLL [31048 2021-09-03] (Microsoft Windows Hardware Compatibility Publisher -> Star Micronics Co., Ltd.)
HKLM\...\Print\Monitors\TSP100LAN Port: C:\Windows\system32\smjt100epm.dll [360960 2021-10-06] (Star Micronics Co., Ltd.) [File not signed]
HKLM\...\Print\Monitors\ZDesigner Language Monitor: C:\Windows\system32\zdnNLM64.dll [892056 2023-08-28] (Euro Plus d.o.o. -> Euro Plus d.o.o.)
HKLM\...\Print\Monitors\ZDesigner Port Monitor: C:\Windows\system32\zdnPMS.dll [290968 2021-02-02] (Microsoft Windows Hardware Compatibility Publisher -> Euro Plus d.o.o.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{49210152-871f-4ffa-961d-a172abcbc09d}] -> C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [3995288 2026-05-21] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\148.0.7778.179\Installer\chrmstp.exe [7621272 2026-05-22] (Google LLC -> Google LLC)
Startup: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Arduino Cloud Agent.lnk [2024-12-14]
ShortcutTarget: Arduino Cloud Agent.lnk -> C:\Users\admin\AppData\Roaming\ArduinoCloudAgent\Arduino_Cloud_Agent.exe () [File not signed]
Startup: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LibreOffice 7.5.lnk [2024-07-08]
ShortcutTarget: LibreOffice 7.5.lnk -> C:\Program Files\LibreOffice\program\quickstart.exe (The Document Foundation -> The Document Foundation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SOLIDWORKS 2016 Rychlé spuštění.lnk [2023-10-29]
ShortcutTarget: SOLIDWORKS 2016 Rychlé spuštění.lnk -> C:\Windows\Installer\{768F3B65-1695-47B7-9002-B11400CB111D}\NewShortcut2_87EDF6C81D0A4B7B84F42FE0C6A9D608.exe (Flexera Software LLC) [File not signed]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SOLIDWORKS Nástroj pro stahování na pozadí.lnk [2023-10-29]
ShortcutTarget: SOLIDWORKS Nástroj pro stahování na pozadí.lnk -> C:\Program Files (x86)\Common Files\Manažer instalací SOLIDWORKS\BackgroundDownloading\sldBgDwld.exe (Dassault Systemes SolidWorks Corp. -> Dassault Systèmes SolidWorks Corp.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Zebra Status Monitor.lnk [2024-03-01]
ShortcutTarget: Zebra Status Monitor.lnk -> C:\Program Files (x86)\Zebra Technologies\Status Monitor\Status Monitor\StatusMonitor.exe (Zebra Technologies Corporation -> Zebra Technologies Corporation) [File not signed]
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {5D14D1C4-B128-45CD-A4AA-F55089B6C810} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1612800 2026-01-23] (Adobe Inc. -> Adobe Inc.)
Task: {2F040900-C75F-44EB-A3A9-68A581A8139C} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe (No File)
Task: {325799CC-9E03-484E-BF8D-D4A3D534CED2} - System32\Tasks\FIRMA EnviCon WIN CRON 231122 => C:\Users\admin\Documents\www\www.admin.loc\system\BAT\environment_control.bat [252 2023-12-21] () [File not signed]
Task: {A816C1B9-AFD2-418C-9CF4-D55E2508ADB1} - System32\Tasks\FIRMA IMAP syncro 231018 => C:\Users\admin\Documents\www\www.admin.loc\system\Python\imap_syncro.bat [120 2026-03-13] () [File not signed]
Task: {9D47B887-D9C3-40A0-A6D2-7ABFDEA1DB0E} - System32\Tasks\FIRMA machines_log => C:\Users\admin\Documents\www\www.admin.loc\system\BAT\machines_log_loop.bat [1099 2025-11-25] () [File not signed]
Task: {807ECA39-F18D-412D-A42C-984C2594A765} - System32\Tasks\FIRMA machines_log_babyplast => C:\Users\admin\Documents\www\www.admin.loc\system\BAT\machine_log_babyplast.bat [254 2025-04-18] () [File not signed]
Task: {F1219E15-2BD8-451F-A89E-6C690EEAB6BD} - System32\Tasks\FIRMA ModBus update_register_values => C:\Users\admin\Documents\www\www.admin.loc\system\BAT\update_modbus_register_values.bat [403 2025-10-28] () [File not signed]
Task: {2B61D230-7393-4B16-8082-D54EA0E74425} - System32\Tasks\FIRMA MySQL repair tables => C:\Users\admin\Documents\www\www.admin.loc\system\BAT\mysqlcheck_repair_database.bat [703 2023-10-10] () [File not signed]
Task: {57BE48EC-80C8-46FD-949A-A6630EC03B01} - System32\Tasks\FIRMA netatmo WIN CRON 231122 => C:\Users\admin\Documents\www\www.admin.loc\system\BAT\neatmo_datalogger_loop.bat [258 2025-01-05] () [File not signed]
Task: {C6A93376-162F-455D-8FE9-A23D15470163} - System32\Tasks\FIRMA shelly datalogger WIN CRON 250307 => C:\Users\admin\Documents\www\www.admin.loc\system\BAT\shelly_datalogger_loop .bat [253 2025-02-06] () [File not signed]
Task: {379A822F-7F92-4F00-AD58-C358692D6FA3} - System32\Tasks\FIRMA spot_data => C:\Users\admin\Documents\www\www.admin.loc\system\BAT\spot_datalogger.bat [246 2025-02-24] () [File not signed]
Task: {09A4D201-68D7-4D48-92E7-584D051C1066} - System32\Tasks\FIRMA update => C:\Users\admin\Documents\www\www.admin.loc\system\BAT\update_company_loop.bat [393 2023-07-26] () [File not signed]
Task: {BCDA2884-4FCF-4602-8A10-D8EDECB7EF0D} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem149.0.7814.0{32C9A04B-4E22-46C1-A482-DCAAE923982D} => C:\Program Files (x86)\Google\GoogleUpdater\149.0.7814.0\updater.exe [8770200 2026-04-28] (Google LLC -> Google LLC)
Task: {63F8C573-B758-4621-A1CE-737C519AC508} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Update Notice => C:\Program Files (x86)\HP\HP Support Framework\Resources\BingPopup\BingPopup.exe [1015880 2025-12-15] (HP Inc. -> HP Inc.) -> C:\Program Files (x86)\HP\HP Support Framework\\/show
Task: {2C06E407-82AE-49BB-8802-DCBA29FAEEB0} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPSFReport.exe [480264 2025-12-15] (HP Inc. -> HP Inc.)
Task: {EFFF80A3-16B0-4759-A841-7D89ECD47A52} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HPPrinterLowInk => C:\Program Files (x86)\HP\HP Support Framework\Resources\HPPrinterLowInk\HPPrinterLowInk.exe [231944 2025-12-15] (HP Inc. -> HP Inc.) -> C:\Program Files (x86)\HP\HP Support Framework\\/show
Task: {80E18DBA-43D7-4154-93A7-C0BBD6808EA3} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [95240 2026-04-08] (HP Inc. -> HP Inc.)
Task: {8C27B44F-2F1E-4798-8B98-FF5A8217CCB1} - System32\Tasks\HP\HP Print Scan Doctor\Printer Health Monitor Logon => C:\Program Files\HPPrintScanDoctor\HPPrinterHealthMonitor.exe [95240 2026-04-08] (HP Inc. -> HP Inc.)
Task: {E57F4FC9-B3C3-4C3B-ACE6-746381E6C8B5} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe [1794752 2026-05-21] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {3B6EB3AC-7AEC-4817-8BA8-6042F8CE87C8} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe [1794752 2026-05-21] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {49055789-A444-4910-8742-8983633AB4BB} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe [1794752 2026-05-21] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {039AEE08-7B10-432D-8CDA-2D51E131B070} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpCmdRun.exe [1794752 2026-05-21] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {DBCE80E3-4681-4216-9E18-9FD4429CE123} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-4195152011-4283894360-3570850043-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [705152 2026-05-21] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {C86D8830-BD6E-4B3B-AF90-1A75C4CBE83B} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [33920 2026-05-21] (Mozilla Corporation -> Mozilla Foundation)
Task: {D5D95642-ED86-4F5B-A37D-6C737AAD7121} - System32\Tasks\nWizard_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [1554120 2023-10-29] (Nvidia Corporation -> NVIDIA Corporation) -> C:\Program Files\NVIDIA Corporation\nview\/installquiet
Task: {98BC8EB2-29D3-47B9-95C7-3E0A315224B8} - System32\Tasks\python beep => G:\Můj disk\#dev\Python\Zvuk\#RUN# demo.bat [34 2024-02-24] () [File not signed]
Task: {0D1EA15C-623A-4DAB-B05F-78E0B169BB76} - System32\Tasks\ZoomUpdateTaskUser-S-1-5-21-4195152011-4283894360-3570850043-1001 => C:\Users\admin\AppData\Roaming\Zoom\bin\Zoom.exe [434488 2025-03-07] (Zoom Video Communications, Inc. -> Zoom Communications, Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 08 C:\Program Files\Bonjour\mdnsNSP.dll [132968 2011-08-30] (Apple Inc. -> Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.11.1
Tcpip\..\Interfaces\{e8b2eadf-34b4-491c-8507-1c3a230950d9}: [DhcpNameServer] 192.168.11.1
Tcpip\..\Interfaces\{e8b2eadf-34b4-491c-8507-1c3a230950d9}: [DhcpDomain] suchomelplasty.loc
FireFox:
========
FF TaskBarID: 308046B0AF4A39CB -> C:\Program Files\Mozilla Firefox
FF Plugin: 3ds.com/ComposerPlayerWebPlugin_x86_64 -> C:\PROGRA~1\SOLIDW~1\SOLIDW~3\Bin\NPCOMP~1.DLL [2016-10-13] (DASSAULT SYSTEMES SA -> Dassault Systemes)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2026-05-13] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin-x32: 3ds.com/ComposerPlayerWebPlugin -> C:\PROGRA~1\SOLIDW~1\SOLIDW~3\Bin\x86\NPCOMP~1.DLL [2016-10-13] (DASSAULT SYSTEMES SA -> Dassault Systemes)
Edge:
=======
Edge Profile: C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default [2026-05-25]
Edge Session Restore: Default -> is enabled.
Edge Extension: (Dokumenty Google offline) - C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-05-19]
Edge Extension: (Edge relevant text changes) - C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24]
Chrome:
=======
CHR Profile: C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default [2026-05-11]
CHR Notifications: Default -> hxxps://calendar.google.com; hxxps://home.netatmo.com
CHR StartupUrls: Default -> "hxxps://tvgo.t-mobile.cz/"
CHR Session Restore: Default -> is enabled.
CHR Extension: (Tablet Gestures) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\adpfjochlgeifbpfnlchcdcmoaafnoim [2023-10-28]
CHR Extension: (Adblock na Youtube™) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2026-05-10]
CHR Extension: (Type-ahead-find) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpecbmjeidppdiampimghndkikcmoadk [2025-04-14]
CHR Extension: (Sider: Chat with all AI: GPT-5, Claude, DeepSeek, Gemini, Grok) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\difoiogjjojoaoomphldepapgpbgkhkb [2026-05-10]
CHR Extension: (Typio Form Recovery) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\djkbihbnjhkjahbhjaadbepppbpoedaa [2023-10-28]
CHR Extension: (Go Back With Backspace) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\eekailopagacbcdloonjhbiecobagjci [2024-10-31]
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2026-05-10]
CHR Extension: (I don't care about cookies) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fihnjjcciajhdojfnbdddfaoknhalnja [2024-07-11]
CHR Extension: (Dokumenty Google offline) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-05-10]
CHR Extension: (RestMan) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihgpcfpkpmdcghlnaofdmjkoemnlijdi [2025-03-09]
CHR Extension: (Chrome Remote Desktop) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\inomeogfingihgjfjlpeplalcfajhgai [2023-10-28]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-10-28]
CHR Extension: (x3d-viewer) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneaojlgmfmngeckfemdbfpgedgfpgdg [2024-03-23]
CHR Extension: (Open Email Client) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\oofmnabdpcibefadlibdpnnbglcehfpj [2024-07-31]
CHR HKU\S-1-5-21-4195152011-4283894360-3570850043-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKU\S-1-5-21-4195152011-4283894360-3570850043-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [180216 2026-01-23] (Adobe Inc. -> Adobe Inc.)
R2 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\148.0.7778.23\remoting_host.exe [74392 2026-04-13] (Google LLC -> Google LLC)
R2 CoworkVMService; C:\Program Files\WindowsApps\Claude_1.9659.2.0_x64__pzs8sxrjxfjjc\app\resources\cowork-svc.exe [12649808 2026-05-29] (Anthropic, PBC -> )
R2 HPAppHelperCap; C:\Program Files\HP\HP Enabling Services\AppHelperCap.exe [930400 2025-09-02] (HP Inc. -> HP Inc.)
R2 HPDiagsCap; C:\Program Files\HP\HP Enabling Services\DiagsCap.exe [928864 2025-09-02] (HP Inc. -> HP Inc.)
R2 HPNetworkCap; C:\Program Files\HP\HP Enabling Services\NetworkCap.exe [924784 2025-09-02] (HP Inc. -> HP Inc.)
R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [244232 2026-04-08] (HP Inc. -> HP Inc.)
R2 HPSysInfoCap; C:\Program Files\HP\HP Enabling Services\SysInfoCap.exe [929400 2025-09-02] (HP Inc. -> HP Inc.)
R2 MariaDB; C:\Program Files\MariaDB 11.3\bin\mysqld.exe [34728 2023-09-17] (MariaDB Corporation Ab -> )
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MpDefenderCoreService.exe [2096384 2026-05-21] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVWMI; C:\Windows\System32\DriverStore\FileRepository\nvwu.inf_amd64_3f2a4c162f79e81f\NVWMI\nvWmi64.exe [4476632 2023-10-29] (Nvidia Corporation -> NVIDIA Corporation)
S3 PortEmulator; C:\Program Files\StarMicronics\TSP100\Software\20221130\portemu_umdf_tsp100.exe [207872 2016-02-26] () [File not signed]
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [803064 2025-11-21] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 SolidWorks Licensing Service; C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [79360 2023-10-29] (SolidWorks) [File not signed]
S3 TcpEmulatorTSP100LAN; C:\Program Files\StarMicronics\TSP100\Software\20221130\tcpemu_tsp100lan.exe [351744 2015-05-22] (STAR MICRONICS CO,.LTD) [File not signed]
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [26931024 2026-05-20] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\NisSrv.exe [4484680 2026-05-21] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26040.7-0\MsMpEng.exe [290704 2026-05-21] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WPSService20; C:\Program Files (x86)\TRENDnet Wireless USB Adapter Driver\WPSService20.exe [96768 2017-01-06] () [File not signed]
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nvwu.inf_amd64_3f2a4c162f79e81f\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\Windows\System32\DriverStore\FileRepository\nvwu.inf_amd64_3f2a4c162f79e81f\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 FTDIBUS; C:\Windows\system32\drivers\ftdibus.sys [152608 2024-11-19] (WDKTestCert andy.miller,132291778652267126 -> Future Technology Devices International Ltd.)
R3 FTSER2K; C:\Windows\system32\drivers\ftser2k.sys [101520 2024-11-19] (WDKTestCert andy.miller,132291778652267126 -> Future Technology Devices International Ltd.)
R2 googledrivefs31931; C:\Program Files\Google\Drive File Stream\Drivers\31931\googledrivefs31931.sys [386256 2025-05-07] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
R3 KslD; C:\Windows\System32\drivers\wd\KslD.sys [82312 2026-05-21] (Microsoft Windows -> Microsoft Corporation)
R3 plser; C:\Windows\system32\DRIVERS\plser64.sys [336736 2026-01-28] (Microsoft Windows Hardware Compatibility Publisher -> Prolific Technology Inc.)
S3 ss_conn_usb_driver2; C:\Windows\System32\Drivers\ss_conn_usb_driver2.sys [50720 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [21888 2026-05-21] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [606600 2026-05-21] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [100784 2026-05-21] (Microsoft Windows -> Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-06-01 18:20 - 2026-06-01 18:23 - 000035753 _____ C:\Users\admin\Desktop\FRST.txt
2026-06-01 18:07 - 2026-06-01 18:07 - 002782208 _____ (Farbar) C:\Users\admin\Desktop\FRST64.exe
2026-06-01 18:04 - 2026-06-01 18:04 - 000025513 _____ C:\Users\admin\.claude.json
2026-05-27 17:23 - 2026-05-28 13:51 - 000000000 ____D C:\Program Files\Mozilla Thunderbird
2026-05-22 03:58 - 2026-05-22 03:58 - 000000000 ____D C:\Users\admin\AppData\Roaming\Python
2026-05-21 21:58 - 2026-05-21 21:58 - 000000000 ____D C:\Users\admin\AppData\Roaming\CadSoft
2026-05-21 21:58 - 2026-05-21 21:58 - 000000000 ____D C:\Users\admin\AppData\Local\ADPWebView
2026-05-21 21:11 - 2026-05-21 21:11 - 000000000 ____D C:\Users\admin\AppData\Local\Fusion360
2026-05-21 21:10 - 2026-05-21 21:10 - 000002674 _____ C:\Users\admin\Desktop\Autodesk Fusion.lnk
2026-05-21 21:10 - 2026-05-21 21:10 - 000000000 ____D C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Autodesk
2026-05-21 21:10 - 2026-05-21 21:10 - 000000000 ____D C:\Users\admin\AppData\Roaming\Fusion360
2026-05-21 21:03 - 2026-05-26 21:03 - 000000000 ____D C:\Program Files\Mozilla Firefox
2026-05-21 21:03 - 2026-05-21 21:03 - 013171144 _____ (Autodesk, Inc) C:\Users\admin\Downloads\Fusion Client Downloader.exe
2026-05-20 18:00 - 2026-05-20 18:00 - 000002933 _____ C:\Users\admin\Downloads\order_34730426.csv
2026-05-17 09:16 - 2026-05-17 09:16 - 000000000 ____D C:\Users\admin\.config
2026-05-11 14:11 - 2026-05-11 14:11 - 000000062 _____ C:\Users\admin\.gitconfig
2026-05-11 14:01 - 2026-05-21 05:13 - 000023291 _____ C:\Users\admin\.claude.json.backup
2026-05-11 13:57 - 2026-06-01 14:35 - 000000000 ____D C:\Users\admin\.claude
2026-05-11 13:54 - 2026-05-11 13:54 - 000000000 ____D C:\ProgramData\Claude
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-06-01 18:22 - 2024-01-26 20:41 - 000000000 ____D C:\FRST
2026-06-01 18:08 - 2023-10-28 21:32 - 000000000 ____D C:\Users\admin\AppData\Local\GHISLER
2026-06-01 18:04 - 2023-10-28 21:08 - 000000000 ____D C:\Users\admin
2026-06-01 17:39 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-06-01 17:35 - 2023-10-28 21:09 - 000000000 ___SD C:\Users\admin\AppData\Roaming\Microsoft\Credentials
2026-06-01 17:00 - 2023-10-28 20:58 - 000000000 ____D C:\Windows\system32\SleepStudy
2026-06-01 13:32 - 2022-09-08 05:11 - 000000000 ____D C:\Windows\SystemTemp
2026-06-01 11:54 - 2026-01-06 16:00 - 000000000 ____D C:\Program Files\TeamViewer
2026-06-01 11:54 - 2019-12-07 11:13 - 000000000 ____D C:\Windows\INF
2026-06-01 11:53 - 2023-10-28 21:33 - 000000000 ____D C:\Users\admin\AppData\Local\D3DSCache
2026-06-01 11:51 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2026-06-01 11:51 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\AppReadiness
2026-05-31 15:18 - 2023-10-29 21:01 - 000000000 ____D C:\ProgramData\NVIDIA
2026-05-30 17:11 - 2023-10-28 20:59 - 000003638 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2026-05-30 17:11 - 2023-10-28 20:59 - 000003512 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2026-05-30 11:12 - 2023-10-28 12:58 - 000001231 _____ C:\Users\admin\Desktop\!zaslat.cz.csv
2026-05-30 07:13 - 2023-10-28 20:59 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-05-29 14:37 - 2023-10-28 22:43 - 000002336 ____H C:\Users\admin\Documents\Default.rdp
2026-05-29 14:37 - 2019-12-07 16:45 - 000000000 ____D C:\Windows\system32\FxsTmp
2026-05-29 13:54 - 2023-10-29 16:04 - 000000000 ____D C:\Users\admin\AppData\Local\TempAdresářZálohySW
2026-05-28 23:20 - 2023-10-28 21:14 - 000002173 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk
2026-05-28 13:52 - 2023-10-29 15:25 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2026-05-28 13:51 - 2023-10-29 15:25 - 000001055 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thunderbird.lnk
2026-05-28 06:46 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\ServiceState
2026-05-27 13:41 - 2025-01-28 05:11 - 000003576 _____ C:\Windows\system32\Tasks\OneDrive Startup Task-S-1-5-21-4195152011-4283894360-3570850043-1001
2026-05-27 13:41 - 2023-10-28 21:11 - 000003592 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-4195152011-4283894360-3570850043-1001
2026-05-27 13:41 - 2023-10-28 21:10 - 000003380 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4195152011-4283894360-3570850043-1001
2026-05-27 13:41 - 2023-10-28 21:08 - 000002383 _____ C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-05-26 16:53 - 2024-03-14 10:07 - 000000000 ____D C:\Users\admin\Desktop\temp
2026-05-25 13:46 - 2023-10-29 17:11 - 000002146 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk
2026-05-25 13:34 - 2023-10-28 21:08 - 001694140 _____ C:\Windows\system32\PerfStringBackup.INI
2026-05-25 13:34 - 2019-12-07 16:43 - 000717008 _____ C:\Windows\system32\perfh005.dat
2026-05-25 13:34 - 2019-12-07 16:43 - 000145186 _____ C:\Windows\system32\perfc005.dat
2026-05-25 13:30 - 2023-10-29 15:25 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2026-05-25 13:27 - 2023-10-28 20:59 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2026-05-25 13:27 - 2023-10-28 20:58 - 000008192 ___SH C:\DumpStack.log.tmp
2026-05-22 13:59 - 2024-03-22 21:55 - 000001073 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2026-05-22 13:59 - 2024-03-22 21:55 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
2026-05-22 10:30 - 2023-10-29 15:29 - 000000000 ____D C:\Users\admin\Documents\1.SUCO
2026-05-22 04:21 - 2025-03-12 12:18 - 000002247 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2026-05-22 04:21 - 2025-03-12 12:18 - 000002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2026-05-21 21:58 - 2023-10-30 20:41 - 000000000 ____D C:\Users\admin\AppData\Roaming\Autodesk
2026-05-21 21:10 - 2023-10-30 20:41 - 000000000 ____D C:\Users\admin\AppData\Local\Autodesk
2026-05-21 21:10 - 2023-10-30 20:33 - 000000000 ____D C:\ProgramData\Autodesk
2026-05-21 20:50 - 2023-10-28 20:59 - 000000000 ____D C:\Windows\system32\Drivers\wd
2026-05-17 16:07 - 2023-10-29 00:23 - 000000000 ____D C:\Windows\system32\MRT
2026-05-17 15:56 - 2023-10-29 00:23 - 220340424 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2026-05-11 13:57 - 2023-10-28 21:57 - 000000000 ____D C:\Users\admin\Documents\www
2026-05-11 13:54 - 2023-10-28 21:09 - 000000000 ____D C:\Users\admin\AppData\Local\Packages
2026-05-11 13:54 - 2023-10-28 21:09 - 000000000 ____D C:\ProgramData\Packages
2026-05-03 11:46 - 2023-10-29 15:30 - 000000000 ____D C:\Users\admin\Documents\2.Suchomel PLASTY
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================