Vyskakující okna vyzývají k instalaci McAffe
Odeslal: 08 Říj 2026 09:43
Dobrý den,
Eset poslal info o záchytu:
Typ detekce: Trojský kůň
Název detekce: HTML/FakeAlert.AAC
Na pc vyskakují okna a vyzývají k instalaci McAffe. Posílám logy a děkuji za pomoc:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 01-10-2026
Ran by lokadmin (administrator) on W-OUC-A-12 (LENOVO 10T8S5VR00) (08-10-2026 10:23:38)
Running from C:\Users\lokadmin\Desktop\FRST64.exe
Loaded Profiles: lokadmin
Platform: Microsoft Windows 11 Pro Version 25H2 26200.9457 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\154.0.4258.53\msedgewebview2.exe <6>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\UUS\amd64\MoNotificationUx.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\efwd.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\RemoteAdministrator\Agent\ERAAgent.exe
(services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_3e38e338bd327f33\LMS.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\Program Files\Windows Defender\MpDefenderCoreService.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_73592056cffa61ae\RtkAudUService64.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\NgcIso.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_73592056cffa61ae\RtkAudUService64.exe [1231944 2021-01-27] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [285104 2026-09-02] (ESET, spol. s r.o. -> ESET)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKLM\Software\Policies\...\system: [EnableLogonScriptDelay] 1
HKLM\Software\Policies\...\system: [AsyncScriptDelay] 2
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\131.0.2.0\GoogleDriveFS.exe [105726104 2026-09-23] (Google LLC -> Google LLC.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\131.0.2.0\GoogleDriveFS.exe [105726104 2026-09-23] (Google LLC -> Google LLC.)
HKU\S-1-5-21-2366292348-839854579-2745207565-1002\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\131.0.2.0\GoogleDriveFS.exe [105726104 2026-09-23] (Google LLC -> Google LLC.)
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\131.0.2.0\GoogleDriveFS.exe [105726104 2026-09-23] (Google LLC -> Google LLC.)
HKLM\...\Print\Monitors\Epson_Print_Admin: C:\WINDOWS\system32\epscpmon.dll [831488 2019-05-31] (Seiko Epson Corporation) [File not signed]
HKLM\...\Print\Monitors\rica1Ilm: C:\WINDOWS\system32\rica1Ilm.dll [28160 2013-12-26] (Microsoft Windows Hardware Compatibility Publisher -> RICOH CO.,Ltd.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{49210152-871f-4ffa-961d-a172abcbc09d}] -> C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [4924568 2026-08-11] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\154.0.8037.95\Installer\chrmstp.exe [8082584 2026-10-02] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Google Drive.lnk [2026-01-27]
ShortcutTarget: Google Drive.lnk -> C:\Program Files\Google\Drive File Stream\119.0.2.0\GoogleDriveFS.exe (No File)
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
"C:\Windows\System32\Tasks\Microsoft\Windows\GroupPolicy\{3E0A038B-D834-4930-9981-E89C9BFF83AA}" Access Denied. <==== ATTENTION
Task: {0B7B0F18-6685-4656-8016-ADD9B76919DB} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem152.0.7933.0{505555E6-ACE5-4D6B-B20E-19578C0AEA77} => C:\Program Files (x86)\Google\GoogleUpdater\152.0.7933.0\updater.exe [9512088 2026-07-05] (Google LLC -> Google LLC)
Task: {956E02E7-0424-4235-B9A2-EE518060148B} - System32\Tasks\GoogleUserPEH\RunPlatformExperienceHelper_Daily => C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [4924568 2026-08-11] (Google LLC -> Google LLC)
Task: {AFF517DA-B76D-43B4-A2C8-D9CA2E13C5B3} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => %ProgramFiles%\Common Files\Microsoft Shared\Office16\OLicenseHeartbeat.exe (No File)
Task: {6C3A1660-32EB-415E-BBB4-D3166D2EA3DF} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\Office16\msoia.exe [416432 2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {98049560-F074-4154-9019-E2130780952F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\Office16\msoia.exe [416432 2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {CBCCCEC3-E0E9-4A50-B809-15D3B987484A} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\krizpa@zs-vsechovice.local\Process policy => {E444E1B9-502C-44f9-B714-30DA330D0E8E} C:\Windows\System32\tsworkspace.dll [1171456 2026-09-09] (Microsoft Windows -> Microsoft Corporation)
Task: {C71F0C3E-AC3D-4E1B-9F95-46808FC6D901} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\krizpa@zs-vsechovice.local\Report update status => C:\WINDOWS\System32\RUNDLL32.exe [98304 2026-09-09] (Microsoft Windows -> Microsoft Corporation) -> tsworkspace,WorkspaceStatusNotify2
Task: {4B85079B-D1D1-46E5-B9E6-9D13185364D6} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\krizpa@zs-vsechovice.local\Start Workspace Runtime at logon => {4F1DFCA6-3AAD-48E1-8406-4BC21A501D7C} C:\WINDOWS\system32\wksprt.exe [425984 2026-09-09] (Microsoft Windows -> Microsoft Corporation)
Task: {ABA5D761-F07F-40D7-989C-1F99F34A34BE} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\krizpa@zs-vsechovice.local\Update connections => C:\WINDOWS\System32\RUNDLL32.exe [98304 2026-09-09] (Microsoft Windows -> Microsoft Corporation) -> tsworkspace,TaskUpdateWorkspaces2
Task: {9ECBAF72-E27D-4C6B-AD78-AAD2FF137590} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\papepa@zs-vsechovice.local\Process policy => {E444E1B9-502C-44F9-B714-30DA330D0E8E} C:\Windows\System32\tsworkspace.dll [1171456 2026-09-09] (Microsoft Windows -> Microsoft Corporation)
Task: {3EBDC8D6-1A2B-4125-9332-800ED0360813} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\papepa@zs-vsechovice.local\Report update status => C:\WINDOWS\System32\RUNDLL32.exe [98304 2026-09-09] (Microsoft Windows -> Microsoft Corporation) -> tsworkspace,WorkspaceStatusNotify2
Task: {54173460-7DAE-424D-9FD0-634B15A6631F} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\papepa@zs-vsechovice.local\Start Workspace Runtime at logon => {4F1DFCA6-3AAD-48E1-8406-4BC21A501D7C} C:\WINDOWS\system32\wksprt.exe [425984 2026-09-09] (Microsoft Windows -> Microsoft Corporation)
Task: {3D87E238-714B-411C-A112-E80EA26E1F4A} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\papepa@zs-vsechovice.local\Update connections => C:\WINDOWS\System32\RUNDLL32.exe [98304 2026-09-09] (Microsoft Windows -> Microsoft Corporation) -> tsworkspace,TaskUpdateWorkspaces2
Task: {4976A8E8-9336-41A6-A4A1-4CCA193676B2} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\pechve@zs-vsechovice.local\Process policy => {E444E1B9-502C-44f9-B714-30DA330D0E8E} C:\Windows\System32\tsworkspace.dll [1171456 2026-09-09] (Microsoft Windows -> Microsoft Corporation)
Task: {975A77A5-96E1-4B13-8933-FE58CB409D34} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\pechve@zs-vsechovice.local\Report update status => C:\WINDOWS\System32\RUNDLL32.exe [98304 2026-09-09] (Microsoft Windows -> Microsoft Corporation) -> tsworkspace,WorkspaceStatusNotify2
Task: {02FA6E0B-98A1-4B64-B911-1F5E529A1907} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\pechve@zs-vsechovice.local\Start Workspace Runtime at logon => {4F1DFCA6-3AAD-48E1-8406-4BC21A501D7C} C:\WINDOWS\system32\wksprt.exe [425984 2026-09-09] (Microsoft Windows -> Microsoft Corporation)
Task: {DD6D3BAA-E09B-413C-86C1-1F0D651BC074} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\pechve@zs-vsechovice.local\Update connections => C:\WINDOWS\System32\RUNDLL32.exe [98304 2026-09-09] (Microsoft Windows -> Microsoft Corporation) -> tsworkspace,TaskUpdateWorkspaces2
Task: {73233840-EE78-4656-A097-89680F4520E4} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\rysael@zs-vsechovice.local\Process policy => {E444E1B9-502C-44f9-B714-30DA330D0E8E} C:\Windows\System32\tsworkspace.dll [1171456 2026-09-09] (Microsoft Windows -> Microsoft Corporation)
Task: {6370C2B9-32BE-450A-8539-DC99FA5F851D} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\rysael@zs-vsechovice.local\Report update status => C:\WINDOWS\System32\RUNDLL32.exe [98304 2026-09-09] (Microsoft Windows -> Microsoft Corporation) -> tsworkspace,WorkspaceStatusNotify2
Task: {AB84C44D-60BB-4F2C-A142-AF6482C02F4A} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\rysael@zs-vsechovice.local\Start Workspace Runtime at logon => {4F1DFCA6-3AAD-48E1-8406-4BC21A501D7C} C:\WINDOWS\system32\wksprt.exe [425984 2026-09-09] (Microsoft Windows -> Microsoft Corporation)
Task: {285C4B2A-F2F3-4412-A218-F4DC0ABFF9C7} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\rysael@zs-vsechovice.local\Update connections => C:\WINDOWS\System32\RUNDLL32.exe [98304 2026-09-09] (Microsoft Windows -> Microsoft Corporation) -> tsworkspace,TaskUpdateWorkspaces2
Task: {EED85AB9-C5B1-4CAA-B052-1E6BBBA381D4} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\strilu@zs-vsechovice.local\Process policy => {E444E1B9-502C-44f9-B714-30DA330D0E8E} C:\Windows\System32\tsworkspace.dll [1171456 2026-09-09] (Microsoft Windows -> Microsoft Corporation)
Task: {D13CBDCA-90D3-4ACB-AB9D-0EFBEFDDC885} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\strilu@zs-vsechovice.local\Report update status => C:\WINDOWS\System32\RUNDLL32.exe [98304 2026-09-09] (Microsoft Windows -> Microsoft Corporation) -> tsworkspace,WorkspaceStatusNotify2
Task: {960EF27C-CBF4-4865-B1C7-98626BBDCBCE} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\strilu@zs-vsechovice.local\Start Workspace Runtime at logon => {4F1DFCA6-3AAD-48E1-8406-4BC21A501D7C} C:\WINDOWS\system32\wksprt.exe [425984 2026-09-09] (Microsoft Windows -> Microsoft Corporation)
Task: {A230E04F-52D2-4895-98C6-C814D50A10BF} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\strilu@zs-vsechovice.local\Update connections => C:\WINDOWS\System32\RUNDLL32.exe [98304 2026-09-09] (Microsoft Windows -> Microsoft Corporation) -> tsworkspace,TaskUpdateWorkspaces2
Task: {A0B71091-303E-4DED-80BA-0DEB76496532} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\suchza@zs-vsechovice.local\Process policy => {E444E1B9-502C-44F9-B714-30DA330D0E8E} C:\Windows\System32\tsworkspace.dll [1171456 2026-09-09] (Microsoft Windows -> Microsoft Corporation)
Task: {9EF659D5-8360-4F14-9F09-72BFC60F4042} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\suchza@zs-vsechovice.local\Report update status => C:\WINDOWS\System32\RUNDLL32.exe [98304 2026-09-09] (Microsoft Windows -> Microsoft Corporation) -> tsworkspace,WorkspaceStatusNotify2
Task: {3E7A2DEB-C5C8-420D-A582-30DD8853E7DE} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\suchza@zs-vsechovice.local\Start Workspace Runtime at logon => {4F1DFCA6-3AAD-48E1-8406-4BC21A501D7C} C:\WINDOWS\system32\wksprt.exe [425984 2026-09-09] (Microsoft Windows -> Microsoft Corporation)
Task: {8864A462-806F-4AAE-91EC-238614B769F8} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\suchza@zs-vsechovice.local\Update connections => C:\WINDOWS\System32\RUNDLL32.exe [98304 2026-09-09] (Microsoft Windows -> Microsoft Corporation) -> tsworkspace,TaskUpdateWorkspaces2
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {AD85F14F-96B7-4AF2-9E9D-2472079974F4} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-2366292348-839854579-2745207565-1002 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [680064 2026-01-26] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {2BD291C7-5599-490B-8369-95DB86DE71F1} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [34944 2026-01-26] (Mozilla Corporation -> Mozilla Foundation)
Task: {C83FC255-ECA6-4739-9E6F-F39843CB6823} - System32\Tasks\OneDrive Startup Task-S-1-5-21-2366292348-839854579-2745207565-1000 => C:\Users\Admin\AppData\Local\Microsoft\OneDrive\25.243.1211.0001_1\OneDriveLauncher.exe /startInstances (No File)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
FireFox:
========
FF TaskBarID: 308046B0AF4A39CB -> C:\Program Files\Mozilla Firefox
FF DefaultProfile: ljqv0jp9.default-release -> 308046B0AF4A39CB
FF ProfilePath: C:\Users\lokadmin\AppData\Roaming\Mozilla\Firefox\Profiles\vlj09jdc.default [2026-01-26]
FF ProfilePath: C:\Users\lokadmin\AppData\Roaming\Mozilla\Firefox\Profiles\ljqv0jp9.default-release [2026-01-27]
FF Plugin: @videolan.org/vlc,version=3.0.20 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2012-09-23] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2026-10-08]
Edge:
=======
Edge Profile: C:\Users\lokadmin\AppData\Local\Microsoft\Edge\User Data\Default [2026-10-08]
Edge Extension: (Dokumenty Google offline) - C:\Users\lokadmin\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-01-26]
Edge Extension: (Edge relevant text changes) - C:\Users\lokadmin\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2026-01-26]
Chrome:
=======
CHR Profile: C:\Users\lokadmin\AppData\Local\Google\Chrome\User Data\Default [2026-10-08]
CHR Extension: (Dokumenty Google offline) - C:\Users\lokadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-01-26]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\lokadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2026-01-26]
CHR HKU\S-1-5-21-2366292348-839854579-2745207565-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [65192 2012-09-23] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
R2 efwd; C:\Program Files\ESET\ESET Security\efwd.exe [5639600 2026-09-02] (ESET, spol. s r.o. -> ESET)
S3 EHttpSrv; C:\Program Files\ESET\ESET Security\ehttpsrv.exe [446384 2026-09-02] (ESET, spol. s r.o. -> ESET)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [5120032 2026-09-02] (ESET, spol. s r.o. -> ESET)
R2 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [5120032 2026-09-02] (ESET, spol. s r.o. -> ESET)
R2 EraAgentSvc; C:\Program Files\ESET\RemoteAdministrator\Agent\ERAAgent.exe [1647736 2026-06-15] (ESET, spol. s r.o. -> ESET)
R2 MDCoreSvc; C:\Program Files\Windows Defender\MpDefenderCoreService.exe [2009656 2026-01-27] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [914752 2026-09-09] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25110.6-0\NisSrv.exe [4426832 2026-01-26] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25110.6-0\MsMpEng.exe [290704 2026-01-26] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [573440 2024-10-05] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [200704 2024-10-05] (Microsoft Corporation) [File not signed]
S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [114688 2026-01-27] (Microsoft Corporation) [File not signed]
R3 e1dexpress; C:\WINDOWS\System32\DriverStore\FileRepository\e1d.inf_amd64_e64afe811c7e4662\e1d.sys [608464 2022-06-01] (Intel Corporation -> Intel Corporation)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [231912 2026-04-16] (ESET, spol. s r.o. -> ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [17840 2025-12-31] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [353864 2026-04-16] (ESET, spol. s r.o. -> ESET)
R1 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [87328 2026-04-16] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [127592 2026-04-16] (ESET, spol. s r.o. -> ESET)
R2 googledrivefs31931; \??\C:\Program Files\Google\Drive File Stream\Drivers\31931\googledrivefs31931.sys [386256 2026-01-27] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [333192 2026-01-26] (Microsoft Windows -> Microsoft Corporation)
R3 LBAI; C:\WINDOWS\System32\Drivers\LBAI.sys [31000 2020-08-03] (Microsoft Windows Hardware Compatibility Publisher -> Lenovo)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [21928 2026-01-26] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [635272 2026-01-26] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [102792 2026-01-26] (Microsoft Windows -> Microsoft Corporation)
==================== SvcHost (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-10-08 10:23 - 2026-10-08 10:24 - 000021269 _____ C:\Users\lokadmin\Desktop\FRST.txt
2026-10-08 10:23 - 2026-10-08 10:23 - 000000000 ____D C:\FRST
2026-10-08 10:23 - 2026-10-08 09:54 - 002456064 _____ (Farbar) C:\Users\lokadmin\Desktop\FRST64.exe
2026-10-08 10:22 - 2026-10-08 10:22 - 000000000 ____D C:\AdwCleaner
2026-10-08 10:05 - 2026-10-08 10:05 - 000677108 _____ C:\WINDOWS\system32\perfh005.dat
2026-10-08 10:05 - 2026-10-08 10:05 - 000144960 _____ C:\WINDOWS\system32\perfc005.dat
2026-10-05 11:07 - 2026-10-05 11:07 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2774596813-2351541506-2060952939-1294
2026-10-05 11:07 - 2026-10-05 11:07 - 000003578 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-2774596813-2351541506-2060952939-1294
2026-10-05 11:07 - 2026-10-05 11:07 - 000003378 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2774596813-2351541506-2060952939-1294
2026-10-05 11:07 - 2026-10-05 11:07 - 000002391 _____ C:\Users\strilu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-10-05 11:07 - 2026-10-05 11:07 - 000000000 ___RD C:\Users\strilu\OneDrive
2026-10-05 11:06 - 2026-10-05 11:29 - 000000000 ____D C:\Users\strilu
2026-10-05 11:06 - 2026-10-05 11:27 - 000000000 ____D C:\Users\strilu\AppData\Local\PlaceholderTileLogoFolder
2026-10-05 11:06 - 2026-10-05 11:23 - 000000000 ____D C:\Users\strilu\AppData\Local\Publishers
2026-10-05 11:06 - 2026-10-05 11:23 - 000000000 ____D C:\Users\strilu\AppData\Local\Packages
2026-10-05 11:06 - 2026-10-05 11:08 - 000000000 ____D C:\Users\strilu\AppData\Local\D3DSCache
2026-10-05 11:06 - 2026-10-05 11:06 - 000000020 ___SH C:\Users\strilu\ntuser.ini
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 _SHDL C:\Users\strilu\Šablony
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 _SHDL C:\Users\strilu\Soubory cookie
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 _SHDL C:\Users\strilu\Poslední
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 _SHDL C:\Users\strilu\Okolní tiskárny
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 _SHDL C:\Users\strilu\Okolní síť
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 _SHDL C:\Users\strilu\Nabídka Start
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 _SHDL C:\Users\strilu\Dokumenty
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 _SHDL C:\Users\strilu\Documents\Obrázky
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 _SHDL C:\Users\strilu\Documents\Hudba
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 _SHDL C:\Users\strilu\Documents\Filmy
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 _SHDL C:\Users\strilu\Data aplikací
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 _SHDL C:\Users\strilu\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 _SHDL C:\Users\strilu\AppData\Local\Data aplikací
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 __SHD C:\Users\strilu\IntelGraphicsProfiles
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ___SD C:\Users\strilu\AppData\Roaming\Microsoft\SystemCertificates
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ___SD C:\Users\strilu\AppData\Roaming\Microsoft\Protect
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ___SD C:\Users\strilu\AppData\Roaming\Microsoft\Crypto
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ___SD C:\Users\strilu\AppData\Roaming\Microsoft\Credentials
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ____D C:\Users\strilu\AppData\Roaming\Microsoft\Workspaces
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ____D C:\Users\strilu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Work Resources (RADC)
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ____D C:\Users\strilu\AppData\Roaming\Microsoft\Windows
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ____D C:\Users\strilu\AppData\Roaming\Microsoft\Vault
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ____D C:\Users\strilu\AppData\Roaming\Microsoft\Spelling
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ____D C:\Users\strilu\AppData\Roaming\Microsoft\Network
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ____D C:\Users\strilu\AppData\Roaming\Adobe
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ____D C:\Users\strilu\AppData\LocalLow\Intel
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ____D C:\Users\strilu\AppData\Local\VirtualStore
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ____D C:\Users\strilu\AppData\Local\Google
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ____D C:\Users\strilu\AppData\Local\ESET
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ____D C:\Users\strilu\AppData\Local\ConnectedDevicesPlatform
2026-10-05 10:09 - 2026-10-05 10:09 - 000000000 ____D C:\Users\krizpa\AppData\Roaming\Microsoft\Vault
2026-10-05 10:06 - 2026-10-05 10:06 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2774596813-2351541506-2060952939-2138
2026-10-05 10:06 - 2026-10-05 10:06 - 000003578 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-2774596813-2351541506-2060952939-2138
2026-10-05 10:06 - 2026-10-05 10:06 - 000003378 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2774596813-2351541506-2060952939-2138
2026-10-05 10:06 - 2026-10-05 10:06 - 000002391 _____ C:\Users\krizpa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-10-05 10:06 - 2026-10-05 10:06 - 000000000 ___RD C:\Users\krizpa\OneDrive
2026-10-05 10:05 - 2026-10-05 10:20 - 000000000 ____D C:\Users\krizpa
2026-10-05 10:05 - 2026-10-05 10:16 - 000000000 ____D C:\Users\krizpa\AppData\Local\Packages
2026-10-05 10:05 - 2026-10-05 10:10 - 000000000 ____D C:\Users\krizpa\AppData\Local\PlaceholderTileLogoFolder
2026-10-05 10:05 - 2026-10-05 10:08 - 000000000 ____D C:\Users\krizpa\AppData\Local\D3DSCache
2026-10-05 10:05 - 2026-10-05 10:05 - 000000020 ___SH C:\Users\krizpa\ntuser.ini
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 _SHDL C:\Users\krizpa\Šablony
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 _SHDL C:\Users\krizpa\Soubory cookie
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 _SHDL C:\Users\krizpa\Poslední
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 _SHDL C:\Users\krizpa\Okolní tiskárny
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 _SHDL C:\Users\krizpa\Okolní síť
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 _SHDL C:\Users\krizpa\Nabídka Start
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 _SHDL C:\Users\krizpa\Dokumenty
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 _SHDL C:\Users\krizpa\Documents\Obrázky
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 _SHDL C:\Users\krizpa\Documents\Hudba
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 _SHDL C:\Users\krizpa\Documents\Filmy
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 _SHDL C:\Users\krizpa\Data aplikací
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 _SHDL C:\Users\krizpa\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 _SHDL C:\Users\krizpa\AppData\Local\Data aplikací
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 __SHD C:\Users\krizpa\IntelGraphicsProfiles
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ___SD C:\Users\krizpa\AppData\Roaming\Microsoft\SystemCertificates
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ___SD C:\Users\krizpa\AppData\Roaming\Microsoft\Protect
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ___SD C:\Users\krizpa\AppData\Roaming\Microsoft\Crypto
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ___SD C:\Users\krizpa\AppData\Roaming\Microsoft\Credentials
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ____D C:\Users\krizpa\AppData\Roaming\Microsoft\Workspaces
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ____D C:\Users\krizpa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Work Resources (RADC)
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ____D C:\Users\krizpa\AppData\Roaming\Microsoft\Windows
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ____D C:\Users\krizpa\AppData\Roaming\Microsoft\Spelling
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ____D C:\Users\krizpa\AppData\Roaming\Microsoft\Network
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ____D C:\Users\krizpa\AppData\Roaming\Adobe
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ____D C:\Users\krizpa\AppData\LocalLow\Intel
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ____D C:\Users\krizpa\AppData\Local\VirtualStore
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ____D C:\Users\krizpa\AppData\Local\Publishers
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ____D C:\Users\krizpa\AppData\Local\Google
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ____D C:\Users\krizpa\AppData\Local\ESET
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ____D C:\Users\krizpa\AppData\Local\ConnectedDevicesPlatform
2026-10-02 11:27 - 2026-10-05 11:26 - 000000000 ____D C:\WINDOWS\CbsTemp
2026-09-21 10:47 - 2026-09-21 10:47 - 000000000 ____D C:\Users\suchza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Work Resources (RADC)
2026-09-16 10:03 - 2026-09-16 10:03 - 003261400 _____ () C:\Users\suchza\Downloads\OperaSetup.exe
2026-09-09 08:22 - 2026-09-09 08:22 - 000004646 _____ C:\WINDOWS\system32\ResPriUHMImageList
2026-09-09 08:22 - 2026-09-09 08:22 - 000004646 _____ C:\WINDOWS\system32\ResPriLMImageList
2026-09-09 08:22 - 2026-09-09 08:22 - 000004646 _____ C:\WINDOWS\system32\ResPriImageList
2026-09-09 08:22 - 2026-09-09 08:22 - 000004646 _____ C:\WINDOWS\system32\ResPriHMImageList
2026-09-09 08:22 - 2026-09-09 08:22 - 000004555 _____ C:\WINDOWS\system32\ResPriImageListLowCost
2026-09-09 08:22 - 2026-09-09 08:22 - 000004555 _____ C:\WINDOWS\system32\ResPriHMImageListLowCost
2026-09-09 08:21 - 2026-09-09 08:21 - 000039215 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2026-09-09 08:21 - 2026-09-09 08:21 - 000039215 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2026-09-09 08:21 - 2026-09-09 08:21 - 000014689 _____ C:\WINDOWS\system32\ecoscore_config.json
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-10-08 10:22 - 2026-01-26 14:09 - 000000000 ____D C:\Users\lokadmin\AppData\Roaming\Microsoft\Spelling
2026-10-08 10:21 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemTemp
2026-10-08 10:21 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-10-08 10:20 - 2026-01-26 14:09 - 000000000 __SHD C:\Users\lokadmin\IntelGraphicsProfiles
2026-10-08 10:20 - 2025-10-27 14:55 - 000000000 ____D C:\Intel
2026-10-08 10:20 - 2025-10-27 13:47 - 000012288 ___SH C:\DumpStack.log.tmp
2026-10-08 10:20 - 2025-10-27 13:47 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2026-10-08 10:19 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\AppReadiness
2026-10-08 10:19 - 2024-04-01 09:21 - 001310720 _____ C:\WINDOWS\system32\config\BBI
2026-10-08 10:05 - 2026-01-26 14:09 - 000000000 ____D C:\Users\lokadmin\AppData\Local\D3DSCache
2026-10-08 10:05 - 2025-10-27 14:56 - 001603790 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2026-10-08 10:05 - 2024-04-01 09:24 - 000000000 ____D C:\WINDOWS\INF
2026-10-08 10:03 - 2026-01-26 14:09 - 000000000 ____D C:\Users\lokadmin\AppData\Local\Packages
2026-10-08 10:02 - 2026-06-09 11:35 - 000000000 ____D C:\WINDOWS\system32\Tasks\SoftLanding
2026-10-08 10:00 - 2025-10-27 13:47 - 000001575 _____ C:\WINDOWS\system32\config\VSMIDK
2026-10-08 09:59 - 2025-10-27 13:47 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2026-10-08 09:59 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2026-10-06 12:58 - 2026-02-10 11:20 - 000000000 ____D C:\Users\suchza\AppData\Local\D3DSCache
2026-10-06 12:57 - 2026-02-10 11:20 - 000000000 __SHD C:\Users\suchza\IntelGraphicsProfiles
2026-10-06 12:57 - 2026-01-27 09:03 - 000000152 _____ C:\WINDOWS\system32\config\netlogon.ftl
2026-10-06 12:57 - 2025-10-27 13:48 - 000015768 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2026-10-06 08:42 - 2026-02-10 11:20 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2774596813-2351541506-2060952939-1295
2026-10-06 08:42 - 2026-02-10 11:20 - 000003578 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-2774596813-2351541506-2060952939-1295
2026-10-06 08:42 - 2026-02-10 11:20 - 000003378 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2774596813-2351541506-2060952939-1295
2026-10-06 08:42 - 2026-02-10 11:20 - 000002391 _____ C:\Users\suchza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-10-06 08:41 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps
2026-10-05 11:06 - 2025-10-27 14:53 - 000000000 __RHD C:\Users\Public\AccountPictures
2026-10-05 10:16 - 2025-10-27 13:48 - 000002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-10-05 10:16 - 2025-10-27 13:48 - 000002281 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2026-10-05 10:10 - 2025-10-27 13:48 - 000003716 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA{570C8069-807B-43CC-A370-55E5A3E26F4E}
2026-10-05 10:10 - 2025-10-27 13:48 - 000003644 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore{31C037CC-B904-4C36-BF46-52B507D70F84}
2026-10-02 11:49 - 2025-10-27 14:51 - 003381760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2026-10-02 11:46 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\USOPrivate
2026-10-02 11:27 - 2025-10-27 13:47 - 000474928 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2026-10-02 11:25 - 2026-01-27 07:47 - 000000000 ____D C:\WINDOWS\system32\ruxim
2026-10-02 11:25 - 2026-01-27 07:47 - 000000000 ____D C:\WINDOWS\system32\NarratorMCAT
2026-10-02 11:25 - 2024-04-01 18:30 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\UUS
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\InstallShield
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemResources
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\setup
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\oobe
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\migwiz
2026-10-02 11:24 - 2024-04-01 18:31 - 000000000 ____D C:\WINDOWS\InboxApps
2026-10-02 11:24 - 2024-04-01 18:31 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2026-10-02 11:24 - 2024-04-01 18:30 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
2026-10-02 11:24 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\system32\F12
2026-10-02 11:24 - 2024-04-01 09:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2026-10-02 11:24 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient
2026-10-02 11:24 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Dism
2026-10-02 11:24 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\appraiser
2026-10-02 11:24 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2026-10-02 11:24 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellExperiences
2026-10-02 11:24 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellComponents
2026-10-02 11:24 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\Provisioning
2026-10-02 11:24 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2026-10-02 11:24 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\L2Schemas
2026-10-02 11:24 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\BrowserCore
2026-10-02 11:24 - 2024-04-01 09:26 - 000000000 ____D C:\Program Files\Common Files\System
2026-10-02 11:24 - 2024-04-01 09:21 - 000000000 ____D C:\WINDOWS\servicing
2026-10-02 11:18 - 2026-01-26 14:37 - 000002254 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2026-10-02 11:18 - 2026-01-26 14:37 - 000002213 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2026-09-23 07:16 - 2026-02-10 11:20 - 000000000 ____D C:\Users\suchza
2026-09-23 07:16 - 2026-01-26 15:04 - 000002180 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk
2026-09-11 11:46 - 2026-01-26 15:08 - 000000000 ____D C:\WINDOWS\system32\MRT
2026-09-11 11:43 - 2026-01-26 15:08 - 230964456 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-10-2026
Ran by lokadmin (08-10-2026 10:25:19)
Running from C:\Users\lokadmin\Desktop
Microsoft Windows 11 Pro Version 25H2 26200.9457 (X64) (2025-10-27 11:50:32)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-2366292348-839854579-2745207565-500 - Administrators - Disabled)
DefaultAccount (S-1-5-21-2366292348-839854579-2745207565-503 - Limited - Disabled)
Guest (S-1-5-21-2366292348-839854579-2745207565-501 - Limited - Disabled)
lokadmin (S-1-5-21-2366292348-839854579-2745207565-1002 - Administrators - Enabled) => C:\Users\lokadmin
WDAGUtilityAccount (S-1-5-21-2366292348-839854579-2745207565-504 - Limited - Disabled)
ATTENTION: Domain
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: ESET Security (Enabled - Up to date) {26E0861C-6FB9-CEF9-E4F0-531986211ACE}
FW: ESET Firewall (Enabled) {1EDB0739-25D6-CFA1-CFAF-FA2C78F25DB5}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Reader XI - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AB0000000001}) (Version: 11.0.00 - Adobe Systems Incorporated)
Audacity 3.1.3 (HKLM\...\Audacity_is1) (Version: 3.1.3 - Audacity Team)
Copilot (HKLM-x32\...\Microsoft Copilot) (Version: 154.0.4258.53 - Microsoft Corporation)
Epson Print Admin Driver (HKLM-x32\...\{beb4b9b0-1b06-44ab-b492-d9e29ea4901a}) (Version: 3.1.4 - Seiko Epson Corporation)
ESET Endpoint Security (HKLM\...\{7D2FA44F-7A18-47D1-8BE4-F5CF72090349}) (Version: 13.0.2058.0 - ESET, spol. s r.o.)
ESET Management Agent (HKLM\...\{BF4449DD-3B01-479A-B23E-BE10430D56D6}) (Version: 13.2.1189.0 - ESET, spol. s r.o.)
FreeCommander XE Build 901 32-bit (HKLM-x32\...\{D3C705DC-9743-4FEF-8358-E1AC9FA69C73}_is1) (Version: 2024.0.0.901 - Marek Jasinski)
Google Drive (HKLM\...\{6BBAE539-2232-434A-A4E5-9A33560C6283}) (Version: 131.0.2.0 - Google LLC)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 154.0.8037.95 - Google LLC)
IrfanView 4.60 (64-bit) (HKLM\...\IrfanView64) (Version: 4.60 - Irfan Skiljan)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 154.0.4258.53 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 154.0.4258.53 - Microsoft Corporation) Hidden
Microsoft Excel MUI (Czech) 2016 (HKLM-x32\...\{90160000-0016-0405-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Groove MUI (Czech) 2016 (HKLM-x32\...\{90160000-00BA-0405-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Office 64-bit Components 2016 (HKLM\...\{90160000-002A-0000-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Office Korrekturhilfen 2016 – Deutsch (HKLM-x32\...\{90160000-001F-0407-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Office OSM MUI (Czech) 2016 (HKLM-x32\...\{90160000-00E1-0405-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Office OSM UX MUI (Czech) 2016 (HKLM-x32\...\{90160000-00E2-0405-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Office Proofing (Czech) 2016 (HKLM-x32\...\{90160000-002C-0405-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2016 - English (HKLM-x32\...\{90160000-001F-0409-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (Czech) 2016 (HKLM\...\{90160000-002A-0405-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (Czech) 2016 (HKLM-x32\...\{90160000-006E-0405-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Office Standard 2016 (HKLM-x32\...\{90160000-0012-0000-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Office Standard 2016 (HKLM-x32\...\Office16.STANDARD) (Version: 16.0.4266.1001 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2366292348-839854579-2745207565-1002\...\OneDriveSetup.exe) (Version: 25.243.1211.0001 - Microsoft Corporation)
Microsoft OneNote MUI (Czech) 2016 (HKLM-x32\...\{90160000-00A1-0405-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Outlook MUI (Czech) 2016 (HKLM-x32\...\{90160000-001A-0405-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft PowerPoint MUI (Czech) 2016 (HKLM-x32\...\{90160000-0018-0405-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Publisher MUI (Czech) 2016 (HKLM-x32\...\{90160000-0019-0405-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Windows Application Compatibility Fix Database (HKLM\...\{22221111-1111-1111-1111-111111111111}.sdb) (Version: - )
Microsoft Word MUI (Czech) 2016 (HKLM-x32\...\{90160000-001B-0405-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Mozilla Firefox (x64 cs) (HKLM\...\Mozilla Firefox) (Version: 147.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 127.0 - Mozilla)
MPC-HC 2.1.6.18 (4b55a1a2f) Nightly (64-bit) (HKLM\...\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1) (Version: 2.1.6.18 - MPC-HC Team)
Nástroje kontroly pravopisu pro Microsoft Office 2016 – čeština (HKLM-x32\...\{90160000-001F-0405-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Nástroje korektúry balíka Microsoft Office 2016 - slovenčina (HKLM-x32\...\{90160000-001F-041B-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
PhotoFiltre 7 (HKU\S-1-5-21-2366292348-839854579-2745207565-1002\...\PhotoFiltre 7) (Version: - )
PSPad editor (HKLM-x32\...\PSPad editor 32bit_is1) (Version: 5.0.7.775 - Jan Fiala)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.20 - VideoLAN)
Zoner Callisto 5 FREE (HKLM-x32\...\ZonerCallisto5_CZ_is1) (Version: 5.0.5000.16 - ZONER software)
Packages:
=========
AppUp.IntelGraphicsExperience -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5688.0_x64__8j3eq9eme6ctt [2025-10-27] (INTEL CORP) [Startup Task]
ESET Context Menu -> C:\Program Files\ESET\ESET Security [2026-10-02] (Sparse Package)
Intel® Optane™ Memory and Storage Management -> C:\Program Files\WindowsApps\AppUp.IntelOptaneMemoryandStorageManagement_18.1.1042.0_x64__8j3eq9eme6ctt [2025-10-27] (INTEL CORP)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.1.137.0_x64__dt26b99r8h8gj [2025-10-27] (Realtek Semiconductor Corp)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-2366292348-839854579-2745207565-1002_Classes\CLSID\{6e1f4e4d-65f7-4c83-be2e-9e6683cda268}\localserver32 -> C:\Program Files\ESET\ESET Security\egui.exe (ESET, spol. s r.o. -> ESET)
CustomCLSID: HKU\S-1-5-21-2366292348-839854579-2745207565-1002_Classes\CLSID\{DFF20505-B08F-455B-AD70-4FBD055088E0}\localserver32 -> C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe (Google LLC -> Google LLC)
CustomCLSID: HKU\S-1-5-21-2366292348-839854579-2745207565-1002_Classes\CLSID\{ED90173A-3B4C-4E7E-B9CF-79714425D4B5}\InprocServer32 -> C:\Program Files (x86)\PSPad editor\pspshellx64.dll () [File not signed]
ShellIconOverlayIdentifiers: [ GoogleDriveCloudOverlayIconHandler] -> {A8E52322-8734-481D-A7E2-27B309EF8D56} => C:\Program Files\Google\Drive File Stream\131.0.2.0\drivefsext.dll [2026-09-23] (Google LLC -> Google LLC.)
ShellIconOverlayIdentifiers: [ GoogleDriveMirrorBlacklistedOverlayIconHandler] -> {51EF1569-67EE-4AD6-9646-E726C3FFC8A2} => C:\Program Files\Google\Drive File Stream\131.0.2.0\drivefsext.dll [2026-09-23] (Google LLC -> Google LLC.)
ShellIconOverlayIdentifiers: [ GoogleDrivePinnedOverlayIconHandler] -> {CFE8B367-77A7-41D7-9C90-75D16D7DC6B6} => C:\Program Files\Google\Drive File Stream\131.0.2.0\drivefsext.dll [2026-09-23] (Google LLC -> Google LLC.)
ShellIconOverlayIdentifiers: [ GoogleDriveProgressOverlayIconHandler] -> {C973DA94-CBDF-4E77-81D1-E5B794FBD146} => C:\Program Files\Google\Drive File Stream\131.0.2.0\drivefsext.dll [2026-09-23] (Google LLC -> Google LLC.)
ShellIconOverlayIdentifiers-x32: [ GoogleDriveCloudOverlayIconHandler] -> {A8E52322-8734-481D-A7E2-27B309EF8D56} => C:\Program Files\Google\Drive File Stream\131.0.2.0\drivefsext.dll [2026-09-23] (Google LLC -> Google LLC.)
ShellIconOverlayIdentifiers-x32: [ GoogleDriveMirrorBlacklistedOverlayIconHandler] -> {51EF1569-67EE-4AD6-9646-E726C3FFC8A2} => C:\Program Files\Google\Drive File Stream\131.0.2.0\drivefsext.dll [2026-09-23] (Google LLC -> Google LLC.)
ShellIconOverlayIdentifiers-x32: [ GoogleDrivePinnedOverlayIconHandler] -> {CFE8B367-77A7-41D7-9C90-75D16D7DC6B6} => C:\Program Files\Google\Drive File Stream\131.0.2.0\drivefsext.dll [2026-09-23] (Google LLC -> Google LLC.)
ShellIconOverlayIdentifiers-x32: [ GoogleDriveProgressOverlayIconHandler] -> {C973DA94-CBDF-4E77-81D1-E5B794FBD146} => C:\Program Files\Google\Drive File Stream\131.0.2.0\drivefsext.dll [2026-09-23] (Google LLC -> Google LLC.)
ContextMenuHandlers1: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\131.0.2.0\drivefsext.dll [2026-09-23] (Google LLC -> Google LLC.)
ContextMenuHandlers1: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2026-09-02] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers2: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2026-09-02] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers4: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\131.0.2.0\drivefsext.dll [2026-09-23] (Google LLC -> Google LLC.)
ContextMenuHandlers5: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\131.0.2.0\drivefsext.dll [2026-09-23] (Google LLC -> Google LLC.)
ContextMenuHandlers6: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2026-09-02] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers1_S-1-5-21-2366292348-839854579-2745207565-1002: [EditWithPSPad] -> {ED90173A-3B4C-4E7E-B9CF-79714425D4B5} => C:\Program Files (x86)\PSPad editor\pspshellx64.dll [2014-11-02] () [File not signed]
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
2026-01-27 09:11 - 2018-10-22 12:49 - 005592064 _____ (Microsoft) [File not signed] C:\WINDOWS\System32\casablanca120.dll
2026-01-27 09:11 - 2019-05-31 10:25 - 000831488 _____ (Seiko Epson Corporation) [File not signed] C:\WINDOWS\System32\epscpmon.dll
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) =============
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2024-04-01 09:26 - 2024-04-01 09:24 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
==================== Network ===========================
(Currently there is no automatic fix for this section.)
DNS Servers: Media is not connected to internet.
Windows Firewall is enabled.
Network Binding:
=============
Wi-Fi: Intel(R) Dual Band Wireless-AC 8265 -> Netwtw06.sys
Ethernet: Intel(R) Ethernet Connection (7) I219-V -> e1d.sys
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2366292348-839854579-2745207565-1002\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\DesktopSpotlight\Assets\Images\image_3.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKU\S-1-5-21-2366292348-839854579-2745207565-1002\...\StartupApproved\Run: => "OneDrive"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{727CA964-2325-425C-BBF9-75126AE19A5E}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{338EE6E5-523C-4DCA-874E-E008052E65FA}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [EdgeWebView2-MDNS-In-UDP] => (Allow) C:\WINDOWS\system32\Microsoft-Edge-WebView\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{75CE35DB-9253-4E08-B78D-1FB9F38120C8}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2608.41021.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{7A2D5DDE-CC47-4292-83AD-D8C0B14A3B31}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2608.41021.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{AE749750-3DA6-4C61-829F-5369BC2B47F4}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2608.41021.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{E9E063DD-786E-444E-9103-777329B3B636}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2608.41021.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{AD4D52B1-E701-4330-8DD7-4A37B24889E9}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{5A968252-80B3-43B2-BE52-BDFD5DFD95C0}] => (Allow) C:\Program Files (x86)\Microsoft\Copilot\Application\mscopilot.exe (Microsoft Corporation -> Microsoft Corporation)
==================== Restore Points =========================
14-09-2026 10:35:04 Windows Update
18-09-2026 09:28:42 Windows Update
21-09-2026 10:36:43 Windows Update
02-10-2026 11:18:17 Windows Update
05-10-2026 11:21:06 Windows Update
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (08/12/2026 05:49:41 AM) (Source: CertEnroll) (EventID: 87) (User: NT AUTHORITY)
Description: Registrace certifikátu SCEP pro Místní systém přes https://IFX-KeyId-36598f22ec84c3c4f640d ... s/Aik/scep se nepovedla:
PkiStatus(11): SCEPDispositionPendingChallenge
EnrollStatus(32): EnrollUnknown
Operace byla dokončena úspěšně. 0x0 (WIN32: 0)
SubmitDone
SubmitV2Attestation: Bad Request
{"Message":"V2 Protocol AIK certificate requests with ECC public keys are not supported. Public key algorithm: 1.2.840.10045.2.1, Key length: 256."}
HTTP/1.1 400 Bad Request
Date: Wed, 12 Aug 2026 03:49:43 GMT
Content-Length: 148
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: 224ee9a3-a476-459e-8173-b7b1c679a874
Metoda: POST(3141ms)
Fáze: SubmitDone
Chybná žádost (400) 0x80190190 (-2145844848 HTTP_E_STATUS_BAD_REQUEST)
Error: (08/12/2026 05:48:11 AM) (Source: CertEnroll) (EventID: 87) (User: NT AUTHORITY)
Description: Registrace certifikátu SCEP pro Místní systém přes https://IFX-KeyId-36598f22ec84c3c4f640d ... s/Aik/scep se nepovedla:
PkiStatus(11): SCEPDispositionPendingChallenge
EnrollStatus(32): EnrollUnknown
Operace byla dokončena úspěšně. 0x0 (WIN32: 0)
SubmitDone
SubmitV2Attestation: Bad Request
{"Message":"V2 Protocol AIK certificate requests with ECC public keys are not supported. Public key algorithm: 1.2.840.10045.2.1, Key length: 256."}
HTTP/1.1 400 Bad Request
Date: Wed, 12 Aug 2026 03:48:13 GMT
Content-Length: 148
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: 41f19663-0406-4b62-96d4-9c859b1e4882
Metoda: POST(3312ms)
Fáze: SubmitDone
Chybná žádost (400) 0x80190190 (-2145844848 HTTP_E_STATUS_BAD_REQUEST)
Error: (07/27/2026 06:12:44 AM) (Source: CertEnroll) (EventID: 87) (User: NT AUTHORITY)
Description: Registrace certifikátu SCEP pro Místní systém přes https://IFX-KeyId-36598f22ec84c3c4f640d ... s/Aik/scep se nepovedla:
PkiStatus(11): SCEPDispositionPendingChallenge
EnrollStatus(32): EnrollUnknown
Operace byla dokončena úspěšně. 0x0 (WIN32: 0)
SubmitDone
SubmitV2Attestation: Bad Request
{"Message":"V2 Protocol AIK certificate requests with P-256 ECC public keys are not supported. Public key algorithm: 1.2.840.10045.2.1, Key length: 256."}
HTTP/1.1 400 Bad Request
Date: Mon, 27 Jul 2026 04:12:52 GMT
Content-Length: 154
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: f6e5716d-981f-4f81-b98c-062c12dc9ce3
Metoda: POST(2766ms)
Fáze: SubmitDone
Chybná žádost (400) 0x80190190 (-2145844848 HTTP_E_STATUS_BAD_REQUEST)
Error: (07/27/2026 06:11:22 AM) (Source: CertEnroll) (EventID: 87) (User: NT AUTHORITY)
Description: Registrace certifikátu SCEP pro Místní systém přes https://IFX-KeyId-36598f22ec84c3c4f640d ... s/Aik/scep se nepovedla:
PkiStatus(11): SCEPDispositionPendingChallenge
EnrollStatus(32): EnrollUnknown
Operace byla dokončena úspěšně. 0x0 (WIN32: 0)
SubmitDone
SubmitV2Attestation: Bad Request
{"Message":"V2 Protocol AIK certificate requests with P-256 ECC public keys are not supported. Public key algorithm: 1.2.840.10045.2.1, Key length: 256."}
HTTP/1.1 400 Bad Request
Date: Mon, 27 Jul 2026 04:11:29 GMT
Content-Length: 154
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: 98649312-a904-4139-8eb7-f9ae7ec2d998
Metoda: POST(2828ms)
Fáze: SubmitDone
Chybná žádost (400) 0x80190190 (-2145844848 HTTP_E_STATUS_BAD_REQUEST)
Error: (07/26/2026 04:37:23 AM) (Source: Application Error) (EventID: 1000) (User: NT AUTHORITY)
Description: Název chybující aplikace: ERAAgent.exe, verze: 13.1.1110.0, časové razítko: 0x69a93aef
Název chybujícího modulu: ucrtbase.dll, verze: 10.0.26100.8521, časové razítko: 0xc38f7a35
Kód výjimky: 0xc0000409
Posun chyby: 0x00000000000a527e
ID chybujícího procesu: 0x1070
Čas spuštění chybující aplikace: 0x1dd1c90f9b859e1
Cesta k chybující aplikaci: C:\Program Files\ESET\RemoteAdministrator\Agent\ERAAgent.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\ucrtbase.dll
ID sestavy: 5abe657e-4fd9-4e8b-b11d-6ecb038bbcd1
Celý název chybujícího balíčku:
ID chybující aplikace relativní vzhledem k balíčku:
Error: (04/09/2026 11:24:30 AM) (Source: Application Error) (EventID: 1000) (User: NT AUTHORITY)
Description: Název chybující aplikace: ERAAgent.exe, verze: 13.0.1400.0, časové razítko: 0x697ba162
Název chybujícího modulu: ucrtbase.dll, verze: 10.0.26100.7623, časové razítko: 0x53a0792e
Kód výjimky: 0xc0000409
Posun chyby: 0x00000000000a4ace
ID chybujícího procesu: 0xdc0
Čas spuštění chybující aplikace: 0x1dcc8029aade107
Cesta k chybující aplikaci: C:\Program Files\ESET\RemoteAdministrator\Agent\ERAAgent.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\ucrtbase.dll
ID sestavy: b3ee9abf-3271-435f-b67a-7ca3859faa12
Celý název chybujícího balíčku:
ID chybující aplikace relativní vzhledem k balíčku:
Error: (03/06/2026 11:24:49 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Generování kontextu aktivace pro C:\Program Files\Google\Chrome\Application\chrome.exe se nezdařilo.
Závislé sestavení 145.0.7632.160,language="*",type="win32",version="145.0.7632.160" nelze najít.
Podrobnější diagnostické údaje získáte pomocí programu sxstrace.exe.
Error: (02/17/2026 12:57:01 PM) (Source: Application Error) (EventID: 1000) (User: NT AUTHORITY)
Description: Název chybující aplikace: ERAAgent.exe, verze: 12.5.2104.0, časové razítko: 0x68ee4fdb
Název chybujícího modulu: ucrtbase.dll, verze: 10.0.26100.7623, časové razítko: 0x53a0792e
Kód výjimky: 0xc0000409
Posun chyby: 0x00000000000a4ace
ID chybujícího procesu: 0x10b4
Čas spuštění chybující aplikace: 0x1dc9ffbe082f81a
Cesta k chybující aplikaci: C:\Program Files\ESET\RemoteAdministrator\Agent\ERAAgent.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\ucrtbase.dll
ID sestavy: 39fbe5c8-f1d2-4597-8c0c-e41f3eb0e01c
Celý název chybujícího balíčku:
ID chybující aplikace relativní vzhledem k balíčku:
System errors:
=============
Error: (10/08/2026 10:22:40 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel® PROSet/Wireless Service byla neočekávaně ukončena. Tento stav nastal již 1krát.
Error: (10/08/2026 10:22:40 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) Storage Middleware Service byla neočekávaně ukončena. Tento stav nastal již 1krát.
Error: (10/08/2026 10:22:40 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) Graphics Command Center Service byla neočekávaně ukončena. Tento stav nastal již 1krát.
Error: (10/08/2026 10:22:40 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Realtek Audio Universal Service byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 0 milisekund: Restartovat službu.
Error: (10/08/2026 10:22:40 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) Dynamic Application Loader Host Interface Service byla neočekávaně ukončena. Tento stav nastal již 1krát.
Error: (10/08/2026 10:22:40 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) Content Protection HECI Service byla neočekávaně ukončena. Tento stav nastal již 1krát.
Error: (10/08/2026 10:22:40 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Adobe Acrobat Update Service byla neočekávaně ukončena. Tento stav nastal již 1krát.
Error: (10/08/2026 10:22:40 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) HD Graphics Control Panel Service byla neočekávaně ukončena. Tento stav nastal již 1krát.
Windows Defender:
================
CodeIntegrity:
===============
Date: 2026-10-08 10:24:11
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Memory info ===========================
BIOS: LENOVO M1UKT77A 04/10/2024
Motherboard: LENOVO 312D
Processor: Intel(R) Core(TM) i5-8400T CPU @ 1.70GHz
Percentage of memory in use: 44%
Total physical RAM: 8061.76 MB
Available physical RAM: 4471.11 MB
Total Virtual: 8573.76 MB
Available Virtual: 5658.33 MB
==================== Drives ================================
Disk 0 - Drive c: (Windows) (Fixed) (Total:237.29 GB) (Free:168.73 GB) (Model: SAMSUNG MZVLB256HAHQ-000L7) NTFS
Disk 1 - Drive d: (MALÁ ČERNÁ) (Removable) (Total:7.53 GB) (Free:7.52 GB) FAT32
Disk 0 - \\?\Volume{e9fbcbce-6722-4971-8e77-6de0ddf4a061}\ () (Fixed) (Total:890 MB) (Free:115.13 MB) NTFS
Disk 0 - \\?\Volume{861add29-6053-4f69-b527-d3061546469f}\ (SYSTEM) (Fixed) (Total:296 MB) (Free:261.26 MB) FAT32
==================== MBR & Partition Table ====================
============================================================
Disk: 0 (Size: 238.47 GB) (Disk ID: 11898291)
Partitions:
===========
Partition Style : GPT
Partition Count : 4
Disk ID : {0B74D375-893B-49FC-9C52-8D9FDE007BEF}
Usable Offset : 0.02 MB
Usable Length : 238.47 GB
Max Partitions : 128
Partition 1
Type : EFI System Partition
Size : 300 MB
Offset : 1 MB
Type GUID : {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}
Partition GUID : {861ADD29-6053-4F69-B527-D3061546469F}
Attributes : 0x0000000000000000
Attribute Flags : None
Hidden : Yes
Platform Required: No
------------------------------------------------------------
Partition 2
Type : Microsoft Reserved (MSR)
Size : 16 MB
Offset : 301 MB
Type GUID : {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}
Partition GUID : {E0ECE00C-7FA1-4FCC-81CE-FC5CE28E4082}
Attributes : 0x0000000000000000
Attribute Flags : None
Hidden : Yes
Platform Required: No
------------------------------------------------------------
Partition 3
Type : Basic Data Partition
Size : 237.29 GB
Offset : 317 MB
Type GUID : {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}
Partition GUID : {5F9AA19F-5479-48ED-A966-5335EA0E3C1E}
Attributes : 0x0000000000000000
Attribute Flags : None
Hidden : No
Platform Required: No
------------------------------------------------------------
Partition 4
Type : Windows Recovery
Size : 890 MB
Offset : 243307 MB
Type GUID : {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}
Partition GUID : {E9FBCBCE-6722-4971-8E77-6DE0DDF4A061}
Attributes : 0x8000000000000001
Attribute Flags : Platform Required, No Default Drive Letter
Hidden : Yes
Platform Required: Yes
------------------------------------------------------------
============================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 7.55 GB) (Disk ID: B467DEC6)
Partitions:
===========
Partition Style : MBR
Partition Count : 4
Disk Signature : 0xB467DEC6
Partition 1
Type : MBR 0x0C (FAT32 LBA)
Size : 7.55 GB
Offset : 1 MB
Partition GUID : {B467DEC6-0000-0000-0000-100000000000}
Bootable : Yes
Recognized : Yes
Hidden Sectors : 2048
------------------------------------------------------------
Partition Entries : 4
Actual Partitions : 1
============================================================
==================== End of Addition.txt =======================
Eset poslal info o záchytu:
Typ detekce: Trojský kůň
Název detekce: HTML/FakeAlert.AAC
Na pc vyskakují okna a vyzývají k instalaci McAffe. Posílám logy a děkuji za pomoc:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 01-10-2026
Ran by lokadmin (administrator) on W-OUC-A-12 (LENOVO 10T8S5VR00) (08-10-2026 10:23:38)
Running from C:\Users\lokadmin\Desktop\FRST64.exe
Loaded Profiles: lokadmin
Platform: Microsoft Windows 11 Pro Version 25H2 26200.9457 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(C:\Program Files\ESET\ESET Security\ekrn.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\154.0.4258.53\msedgewebview2.exe <6>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\UUS\amd64\MoNotificationUx.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\efwd.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(services.exe ->) (ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\RemoteAdministrator\Agent\ERAAgent.exe
(services.exe ->) (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_3e38e338bd327f33\LMS.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\Program Files\Windows Defender\MpDefenderCoreService.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_73592056cffa61ae\RtkAudUService64.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\NgcIso.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_73592056cffa61ae\RtkAudUService64.exe [1231944 2021-01-27] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [285104 2026-09-02] (ESET, spol. s r.o. -> ESET)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKLM\Software\Policies\...\system: [EnableLogonScriptDelay] 1
HKLM\Software\Policies\...\system: [AsyncScriptDelay] 2
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\131.0.2.0\GoogleDriveFS.exe [105726104 2026-09-23] (Google LLC -> Google LLC.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\131.0.2.0\GoogleDriveFS.exe [105726104 2026-09-23] (Google LLC -> Google LLC.)
HKU\S-1-5-21-2366292348-839854579-2745207565-1002\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\131.0.2.0\GoogleDriveFS.exe [105726104 2026-09-23] (Google LLC -> Google LLC.)
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\131.0.2.0\GoogleDriveFS.exe [105726104 2026-09-23] (Google LLC -> Google LLC.)
HKLM\...\Print\Monitors\Epson_Print_Admin: C:\WINDOWS\system32\epscpmon.dll [831488 2019-05-31] (Seiko Epson Corporation) [File not signed]
HKLM\...\Print\Monitors\rica1Ilm: C:\WINDOWS\system32\rica1Ilm.dll [28160 2013-12-26] (Microsoft Windows Hardware Compatibility Publisher -> RICOH CO.,Ltd.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{49210152-871f-4ffa-961d-a172abcbc09d}] -> C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [4924568 2026-08-11] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\154.0.8037.95\Installer\chrmstp.exe [8082584 2026-10-02] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Google Drive.lnk [2026-01-27]
ShortcutTarget: Google Drive.lnk -> C:\Program Files\Google\Drive File Stream\119.0.2.0\GoogleDriveFS.exe (No File)
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
"C:\Windows\System32\Tasks\Microsoft\Windows\GroupPolicy\{3E0A038B-D834-4930-9981-E89C9BFF83AA}" Access Denied. <==== ATTENTION
Task: {0B7B0F18-6685-4656-8016-ADD9B76919DB} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem152.0.7933.0{505555E6-ACE5-4D6B-B20E-19578C0AEA77} => C:\Program Files (x86)\Google\GoogleUpdater\152.0.7933.0\updater.exe [9512088 2026-07-05] (Google LLC -> Google LLC)
Task: {956E02E7-0424-4235-B9A2-EE518060148B} - System32\Tasks\GoogleUserPEH\RunPlatformExperienceHelper_Daily => C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [4924568 2026-08-11] (Google LLC -> Google LLC)
Task: {AFF517DA-B76D-43B4-A2C8-D9CA2E13C5B3} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => %ProgramFiles%\Common Files\Microsoft Shared\Office16\OLicenseHeartbeat.exe (No File)
Task: {6C3A1660-32EB-415E-BBB4-D3166D2EA3DF} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\Office16\msoia.exe [416432 2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {98049560-F074-4154-9019-E2130780952F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\Office16\msoia.exe [416432 2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {CBCCCEC3-E0E9-4A50-B809-15D3B987484A} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\krizpa@zs-vsechovice.local\Process policy => {E444E1B9-502C-44f9-B714-30DA330D0E8E} C:\Windows\System32\tsworkspace.dll [1171456 2026-09-09] (Microsoft Windows -> Microsoft Corporation)
Task: {C71F0C3E-AC3D-4E1B-9F95-46808FC6D901} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\krizpa@zs-vsechovice.local\Report update status => C:\WINDOWS\System32\RUNDLL32.exe [98304 2026-09-09] (Microsoft Windows -> Microsoft Corporation) -> tsworkspace,WorkspaceStatusNotify2
Task: {4B85079B-D1D1-46E5-B9E6-9D13185364D6} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\krizpa@zs-vsechovice.local\Start Workspace Runtime at logon => {4F1DFCA6-3AAD-48E1-8406-4BC21A501D7C} C:\WINDOWS\system32\wksprt.exe [425984 2026-09-09] (Microsoft Windows -> Microsoft Corporation)
Task: {ABA5D761-F07F-40D7-989C-1F99F34A34BE} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\krizpa@zs-vsechovice.local\Update connections => C:\WINDOWS\System32\RUNDLL32.exe [98304 2026-09-09] (Microsoft Windows -> Microsoft Corporation) -> tsworkspace,TaskUpdateWorkspaces2
Task: {9ECBAF72-E27D-4C6B-AD78-AAD2FF137590} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\papepa@zs-vsechovice.local\Process policy => {E444E1B9-502C-44F9-B714-30DA330D0E8E} C:\Windows\System32\tsworkspace.dll [1171456 2026-09-09] (Microsoft Windows -> Microsoft Corporation)
Task: {3EBDC8D6-1A2B-4125-9332-800ED0360813} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\papepa@zs-vsechovice.local\Report update status => C:\WINDOWS\System32\RUNDLL32.exe [98304 2026-09-09] (Microsoft Windows -> Microsoft Corporation) -> tsworkspace,WorkspaceStatusNotify2
Task: {54173460-7DAE-424D-9FD0-634B15A6631F} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\papepa@zs-vsechovice.local\Start Workspace Runtime at logon => {4F1DFCA6-3AAD-48E1-8406-4BC21A501D7C} C:\WINDOWS\system32\wksprt.exe [425984 2026-09-09] (Microsoft Windows -> Microsoft Corporation)
Task: {3D87E238-714B-411C-A112-E80EA26E1F4A} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\papepa@zs-vsechovice.local\Update connections => C:\WINDOWS\System32\RUNDLL32.exe [98304 2026-09-09] (Microsoft Windows -> Microsoft Corporation) -> tsworkspace,TaskUpdateWorkspaces2
Task: {4976A8E8-9336-41A6-A4A1-4CCA193676B2} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\pechve@zs-vsechovice.local\Process policy => {E444E1B9-502C-44f9-B714-30DA330D0E8E} C:\Windows\System32\tsworkspace.dll [1171456 2026-09-09] (Microsoft Windows -> Microsoft Corporation)
Task: {975A77A5-96E1-4B13-8933-FE58CB409D34} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\pechve@zs-vsechovice.local\Report update status => C:\WINDOWS\System32\RUNDLL32.exe [98304 2026-09-09] (Microsoft Windows -> Microsoft Corporation) -> tsworkspace,WorkspaceStatusNotify2
Task: {02FA6E0B-98A1-4B64-B911-1F5E529A1907} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\pechve@zs-vsechovice.local\Start Workspace Runtime at logon => {4F1DFCA6-3AAD-48E1-8406-4BC21A501D7C} C:\WINDOWS\system32\wksprt.exe [425984 2026-09-09] (Microsoft Windows -> Microsoft Corporation)
Task: {DD6D3BAA-E09B-413C-86C1-1F0D651BC074} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\pechve@zs-vsechovice.local\Update connections => C:\WINDOWS\System32\RUNDLL32.exe [98304 2026-09-09] (Microsoft Windows -> Microsoft Corporation) -> tsworkspace,TaskUpdateWorkspaces2
Task: {73233840-EE78-4656-A097-89680F4520E4} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\rysael@zs-vsechovice.local\Process policy => {E444E1B9-502C-44f9-B714-30DA330D0E8E} C:\Windows\System32\tsworkspace.dll [1171456 2026-09-09] (Microsoft Windows -> Microsoft Corporation)
Task: {6370C2B9-32BE-450A-8539-DC99FA5F851D} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\rysael@zs-vsechovice.local\Report update status => C:\WINDOWS\System32\RUNDLL32.exe [98304 2026-09-09] (Microsoft Windows -> Microsoft Corporation) -> tsworkspace,WorkspaceStatusNotify2
Task: {AB84C44D-60BB-4F2C-A142-AF6482C02F4A} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\rysael@zs-vsechovice.local\Start Workspace Runtime at logon => {4F1DFCA6-3AAD-48E1-8406-4BC21A501D7C} C:\WINDOWS\system32\wksprt.exe [425984 2026-09-09] (Microsoft Windows -> Microsoft Corporation)
Task: {285C4B2A-F2F3-4412-A218-F4DC0ABFF9C7} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\rysael@zs-vsechovice.local\Update connections => C:\WINDOWS\System32\RUNDLL32.exe [98304 2026-09-09] (Microsoft Windows -> Microsoft Corporation) -> tsworkspace,TaskUpdateWorkspaces2
Task: {EED85AB9-C5B1-4CAA-B052-1E6BBBA381D4} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\strilu@zs-vsechovice.local\Process policy => {E444E1B9-502C-44f9-B714-30DA330D0E8E} C:\Windows\System32\tsworkspace.dll [1171456 2026-09-09] (Microsoft Windows -> Microsoft Corporation)
Task: {D13CBDCA-90D3-4ACB-AB9D-0EFBEFDDC885} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\strilu@zs-vsechovice.local\Report update status => C:\WINDOWS\System32\RUNDLL32.exe [98304 2026-09-09] (Microsoft Windows -> Microsoft Corporation) -> tsworkspace,WorkspaceStatusNotify2
Task: {960EF27C-CBF4-4865-B1C7-98626BBDCBCE} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\strilu@zs-vsechovice.local\Start Workspace Runtime at logon => {4F1DFCA6-3AAD-48E1-8406-4BC21A501D7C} C:\WINDOWS\system32\wksprt.exe [425984 2026-09-09] (Microsoft Windows -> Microsoft Corporation)
Task: {A230E04F-52D2-4895-98C6-C814D50A10BF} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\strilu@zs-vsechovice.local\Update connections => C:\WINDOWS\System32\RUNDLL32.exe [98304 2026-09-09] (Microsoft Windows -> Microsoft Corporation) -> tsworkspace,TaskUpdateWorkspaces2
Task: {A0B71091-303E-4DED-80BA-0DEB76496532} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\suchza@zs-vsechovice.local\Process policy => {E444E1B9-502C-44F9-B714-30DA330D0E8E} C:\Windows\System32\tsworkspace.dll [1171456 2026-09-09] (Microsoft Windows -> Microsoft Corporation)
Task: {9EF659D5-8360-4F14-9F09-72BFC60F4042} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\suchza@zs-vsechovice.local\Report update status => C:\WINDOWS\System32\RUNDLL32.exe [98304 2026-09-09] (Microsoft Windows -> Microsoft Corporation) -> tsworkspace,WorkspaceStatusNotify2
Task: {3E7A2DEB-C5C8-420D-A582-30DD8853E7DE} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\suchza@zs-vsechovice.local\Start Workspace Runtime at logon => {4F1DFCA6-3AAD-48E1-8406-4BC21A501D7C} C:\WINDOWS\system32\wksprt.exe [425984 2026-09-09] (Microsoft Windows -> Microsoft Corporation)
Task: {8864A462-806F-4AAE-91EC-238614B769F8} - System32\Tasks\Microsoft\Windows\RemoteApp and Desktop Connections Update\suchza@zs-vsechovice.local\Update connections => C:\WINDOWS\System32\RUNDLL32.exe [98304 2026-09-09] (Microsoft Windows -> Microsoft Corporation) -> tsworkspace,TaskUpdateWorkspaces2
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
Task: {AD85F14F-96B7-4AF2-9E9D-2472079974F4} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-2366292348-839854579-2745207565-1002 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [680064 2026-01-26] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters).
Task: {2BD291C7-5599-490B-8369-95DB86DE71F1} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [34944 2026-01-26] (Mozilla Corporation -> Mozilla Foundation)
Task: {C83FC255-ECA6-4739-9E6F-F39843CB6823} - System32\Tasks\OneDrive Startup Task-S-1-5-21-2366292348-839854579-2745207565-1000 => C:\Users\Admin\AppData\Local\Microsoft\OneDrive\25.243.1211.0001_1\OneDriveLauncher.exe /startInstances (No File)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
FireFox:
========
FF TaskBarID: 308046B0AF4A39CB -> C:\Program Files\Mozilla Firefox
FF DefaultProfile: ljqv0jp9.default-release -> 308046B0AF4A39CB
FF ProfilePath: C:\Users\lokadmin\AppData\Roaming\Mozilla\Firefox\Profiles\vlj09jdc.default [2026-01-26]
FF ProfilePath: C:\Users\lokadmin\AppData\Roaming\Mozilla\Firefox\Profiles\ljqv0jp9.default-release [2026-01-27]
FF Plugin: @videolan.org/vlc,version=3.0.20 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2012-09-23] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2026-10-08]
Edge:
=======
Edge Profile: C:\Users\lokadmin\AppData\Local\Microsoft\Edge\User Data\Default [2026-10-08]
Edge Extension: (Dokumenty Google offline) - C:\Users\lokadmin\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-01-26]
Edge Extension: (Edge relevant text changes) - C:\Users\lokadmin\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2026-01-26]
Chrome:
=======
CHR Profile: C:\Users\lokadmin\AppData\Local\Google\Chrome\User Data\Default [2026-10-08]
CHR Extension: (Dokumenty Google offline) - C:\Users\lokadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2026-01-26]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\lokadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2026-01-26]
CHR HKU\S-1-5-21-2366292348-839854579-2745207565-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [65192 2012-09-23] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
R2 efwd; C:\Program Files\ESET\ESET Security\efwd.exe [5639600 2026-09-02] (ESET, spol. s r.o. -> ESET)
S3 EHttpSrv; C:\Program Files\ESET\ESET Security\ehttpsrv.exe [446384 2026-09-02] (ESET, spol. s r.o. -> ESET)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [5120032 2026-09-02] (ESET, spol. s r.o. -> ESET)
R2 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [5120032 2026-09-02] (ESET, spol. s r.o. -> ESET)
R2 EraAgentSvc; C:\Program Files\ESET\RemoteAdministrator\Agent\ERAAgent.exe [1647736 2026-06-15] (ESET, spol. s r.o. -> ESET)
R2 MDCoreSvc; C:\Program Files\Windows Defender\MpDefenderCoreService.exe [2009656 2026-01-27] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [914752 2026-09-09] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25110.6-0\NisSrv.exe [4426832 2026-01-26] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25110.6-0\MsMpEng.exe [290704 2026-01-26] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [573440 2024-10-05] (Microsoft Corporation) [File not signed]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [200704 2024-10-05] (Microsoft Corporation) [File not signed]
S3 BTHMODEM; C:\WINDOWS\System32\drivers\bthmodem.sys [114688 2026-01-27] (Microsoft Corporation) [File not signed]
R3 e1dexpress; C:\WINDOWS\System32\DriverStore\FileRepository\e1d.inf_amd64_e64afe811c7e4662\e1d.sys [608464 2022-06-01] (Intel Corporation -> Intel Corporation)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [231912 2026-04-16] (ESET, spol. s r.o. -> ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [17840 2025-12-31] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [353864 2026-04-16] (ESET, spol. s r.o. -> ESET)
R1 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [87328 2026-04-16] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [127592 2026-04-16] (ESET, spol. s r.o. -> ESET)
R2 googledrivefs31931; \??\C:\Program Files\Google\Drive File Stream\Drivers\31931\googledrivefs31931.sys [386256 2026-01-27] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [333192 2026-01-26] (Microsoft Windows -> Microsoft Corporation)
R3 LBAI; C:\WINDOWS\System32\Drivers\LBAI.sys [31000 2020-08-03] (Microsoft Windows Hardware Compatibility Publisher -> Lenovo)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [21928 2026-01-26] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [635272 2026-01-26] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [102792 2026-01-26] (Microsoft Windows -> Microsoft Corporation)
==================== SvcHost (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-10-08 10:23 - 2026-10-08 10:24 - 000021269 _____ C:\Users\lokadmin\Desktop\FRST.txt
2026-10-08 10:23 - 2026-10-08 10:23 - 000000000 ____D C:\FRST
2026-10-08 10:23 - 2026-10-08 09:54 - 002456064 _____ (Farbar) C:\Users\lokadmin\Desktop\FRST64.exe
2026-10-08 10:22 - 2026-10-08 10:22 - 000000000 ____D C:\AdwCleaner
2026-10-08 10:05 - 2026-10-08 10:05 - 000677108 _____ C:\WINDOWS\system32\perfh005.dat
2026-10-08 10:05 - 2026-10-08 10:05 - 000144960 _____ C:\WINDOWS\system32\perfc005.dat
2026-10-05 11:07 - 2026-10-05 11:07 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2774596813-2351541506-2060952939-1294
2026-10-05 11:07 - 2026-10-05 11:07 - 000003578 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-2774596813-2351541506-2060952939-1294
2026-10-05 11:07 - 2026-10-05 11:07 - 000003378 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2774596813-2351541506-2060952939-1294
2026-10-05 11:07 - 2026-10-05 11:07 - 000002391 _____ C:\Users\strilu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-10-05 11:07 - 2026-10-05 11:07 - 000000000 ___RD C:\Users\strilu\OneDrive
2026-10-05 11:06 - 2026-10-05 11:29 - 000000000 ____D C:\Users\strilu
2026-10-05 11:06 - 2026-10-05 11:27 - 000000000 ____D C:\Users\strilu\AppData\Local\PlaceholderTileLogoFolder
2026-10-05 11:06 - 2026-10-05 11:23 - 000000000 ____D C:\Users\strilu\AppData\Local\Publishers
2026-10-05 11:06 - 2026-10-05 11:23 - 000000000 ____D C:\Users\strilu\AppData\Local\Packages
2026-10-05 11:06 - 2026-10-05 11:08 - 000000000 ____D C:\Users\strilu\AppData\Local\D3DSCache
2026-10-05 11:06 - 2026-10-05 11:06 - 000000020 ___SH C:\Users\strilu\ntuser.ini
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 _SHDL C:\Users\strilu\Šablony
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 _SHDL C:\Users\strilu\Soubory cookie
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 _SHDL C:\Users\strilu\Poslední
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 _SHDL C:\Users\strilu\Okolní tiskárny
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 _SHDL C:\Users\strilu\Okolní síť
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 _SHDL C:\Users\strilu\Nabídka Start
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 _SHDL C:\Users\strilu\Dokumenty
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 _SHDL C:\Users\strilu\Documents\Obrázky
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 _SHDL C:\Users\strilu\Documents\Hudba
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 _SHDL C:\Users\strilu\Documents\Filmy
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 _SHDL C:\Users\strilu\Data aplikací
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 _SHDL C:\Users\strilu\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 _SHDL C:\Users\strilu\AppData\Local\Data aplikací
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 __SHD C:\Users\strilu\IntelGraphicsProfiles
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ___SD C:\Users\strilu\AppData\Roaming\Microsoft\SystemCertificates
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ___SD C:\Users\strilu\AppData\Roaming\Microsoft\Protect
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ___SD C:\Users\strilu\AppData\Roaming\Microsoft\Crypto
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ___SD C:\Users\strilu\AppData\Roaming\Microsoft\Credentials
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ____D C:\Users\strilu\AppData\Roaming\Microsoft\Workspaces
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ____D C:\Users\strilu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Work Resources (RADC)
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ____D C:\Users\strilu\AppData\Roaming\Microsoft\Windows
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ____D C:\Users\strilu\AppData\Roaming\Microsoft\Vault
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ____D C:\Users\strilu\AppData\Roaming\Microsoft\Spelling
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ____D C:\Users\strilu\AppData\Roaming\Microsoft\Network
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ____D C:\Users\strilu\AppData\Roaming\Adobe
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ____D C:\Users\strilu\AppData\LocalLow\Intel
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ____D C:\Users\strilu\AppData\Local\VirtualStore
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ____D C:\Users\strilu\AppData\Local\Google
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ____D C:\Users\strilu\AppData\Local\ESET
2026-10-05 11:06 - 2026-10-05 11:06 - 000000000 ____D C:\Users\strilu\AppData\Local\ConnectedDevicesPlatform
2026-10-05 10:09 - 2026-10-05 10:09 - 000000000 ____D C:\Users\krizpa\AppData\Roaming\Microsoft\Vault
2026-10-05 10:06 - 2026-10-05 10:06 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2774596813-2351541506-2060952939-2138
2026-10-05 10:06 - 2026-10-05 10:06 - 000003578 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-2774596813-2351541506-2060952939-2138
2026-10-05 10:06 - 2026-10-05 10:06 - 000003378 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2774596813-2351541506-2060952939-2138
2026-10-05 10:06 - 2026-10-05 10:06 - 000002391 _____ C:\Users\krizpa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-10-05 10:06 - 2026-10-05 10:06 - 000000000 ___RD C:\Users\krizpa\OneDrive
2026-10-05 10:05 - 2026-10-05 10:20 - 000000000 ____D C:\Users\krizpa
2026-10-05 10:05 - 2026-10-05 10:16 - 000000000 ____D C:\Users\krizpa\AppData\Local\Packages
2026-10-05 10:05 - 2026-10-05 10:10 - 000000000 ____D C:\Users\krizpa\AppData\Local\PlaceholderTileLogoFolder
2026-10-05 10:05 - 2026-10-05 10:08 - 000000000 ____D C:\Users\krizpa\AppData\Local\D3DSCache
2026-10-05 10:05 - 2026-10-05 10:05 - 000000020 ___SH C:\Users\krizpa\ntuser.ini
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 _SHDL C:\Users\krizpa\Šablony
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 _SHDL C:\Users\krizpa\Soubory cookie
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 _SHDL C:\Users\krizpa\Poslední
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 _SHDL C:\Users\krizpa\Okolní tiskárny
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 _SHDL C:\Users\krizpa\Okolní síť
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 _SHDL C:\Users\krizpa\Nabídka Start
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 _SHDL C:\Users\krizpa\Dokumenty
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 _SHDL C:\Users\krizpa\Documents\Obrázky
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 _SHDL C:\Users\krizpa\Documents\Hudba
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 _SHDL C:\Users\krizpa\Documents\Filmy
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 _SHDL C:\Users\krizpa\Data aplikací
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 _SHDL C:\Users\krizpa\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 _SHDL C:\Users\krizpa\AppData\Local\Data aplikací
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 __SHD C:\Users\krizpa\IntelGraphicsProfiles
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ___SD C:\Users\krizpa\AppData\Roaming\Microsoft\SystemCertificates
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ___SD C:\Users\krizpa\AppData\Roaming\Microsoft\Protect
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ___SD C:\Users\krizpa\AppData\Roaming\Microsoft\Crypto
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ___SD C:\Users\krizpa\AppData\Roaming\Microsoft\Credentials
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ____D C:\Users\krizpa\AppData\Roaming\Microsoft\Workspaces
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ____D C:\Users\krizpa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Work Resources (RADC)
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ____D C:\Users\krizpa\AppData\Roaming\Microsoft\Windows
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ____D C:\Users\krizpa\AppData\Roaming\Microsoft\Spelling
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ____D C:\Users\krizpa\AppData\Roaming\Microsoft\Network
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ____D C:\Users\krizpa\AppData\Roaming\Adobe
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ____D C:\Users\krizpa\AppData\LocalLow\Intel
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ____D C:\Users\krizpa\AppData\Local\VirtualStore
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ____D C:\Users\krizpa\AppData\Local\Publishers
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ____D C:\Users\krizpa\AppData\Local\Google
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ____D C:\Users\krizpa\AppData\Local\ESET
2026-10-05 10:05 - 2026-10-05 10:05 - 000000000 ____D C:\Users\krizpa\AppData\Local\ConnectedDevicesPlatform
2026-10-02 11:27 - 2026-10-05 11:26 - 000000000 ____D C:\WINDOWS\CbsTemp
2026-09-21 10:47 - 2026-09-21 10:47 - 000000000 ____D C:\Users\suchza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Work Resources (RADC)
2026-09-16 10:03 - 2026-09-16 10:03 - 003261400 _____ () C:\Users\suchza\Downloads\OperaSetup.exe
2026-09-09 08:22 - 2026-09-09 08:22 - 000004646 _____ C:\WINDOWS\system32\ResPriUHMImageList
2026-09-09 08:22 - 2026-09-09 08:22 - 000004646 _____ C:\WINDOWS\system32\ResPriLMImageList
2026-09-09 08:22 - 2026-09-09 08:22 - 000004646 _____ C:\WINDOWS\system32\ResPriImageList
2026-09-09 08:22 - 2026-09-09 08:22 - 000004646 _____ C:\WINDOWS\system32\ResPriHMImageList
2026-09-09 08:22 - 2026-09-09 08:22 - 000004555 _____ C:\WINDOWS\system32\ResPriImageListLowCost
2026-09-09 08:22 - 2026-09-09 08:22 - 000004555 _____ C:\WINDOWS\system32\ResPriHMImageListLowCost
2026-09-09 08:21 - 2026-09-09 08:21 - 000039215 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2026-09-09 08:21 - 2026-09-09 08:21 - 000039215 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2026-09-09 08:21 - 2026-09-09 08:21 - 000014689 _____ C:\WINDOWS\system32\ecoscore_config.json
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2026-10-08 10:22 - 2026-01-26 14:09 - 000000000 ____D C:\Users\lokadmin\AppData\Roaming\Microsoft\Spelling
2026-10-08 10:21 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemTemp
2026-10-08 10:21 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2026-10-08 10:20 - 2026-01-26 14:09 - 000000000 __SHD C:\Users\lokadmin\IntelGraphicsProfiles
2026-10-08 10:20 - 2025-10-27 14:55 - 000000000 ____D C:\Intel
2026-10-08 10:20 - 2025-10-27 13:47 - 000012288 ___SH C:\DumpStack.log.tmp
2026-10-08 10:20 - 2025-10-27 13:47 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2026-10-08 10:19 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\AppReadiness
2026-10-08 10:19 - 2024-04-01 09:21 - 001310720 _____ C:\WINDOWS\system32\config\BBI
2026-10-08 10:05 - 2026-01-26 14:09 - 000000000 ____D C:\Users\lokadmin\AppData\Local\D3DSCache
2026-10-08 10:05 - 2025-10-27 14:56 - 001603790 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2026-10-08 10:05 - 2024-04-01 09:24 - 000000000 ____D C:\WINDOWS\INF
2026-10-08 10:03 - 2026-01-26 14:09 - 000000000 ____D C:\Users\lokadmin\AppData\Local\Packages
2026-10-08 10:02 - 2026-06-09 11:35 - 000000000 ____D C:\WINDOWS\system32\Tasks\SoftLanding
2026-10-08 10:00 - 2025-10-27 13:47 - 000001575 _____ C:\WINDOWS\system32\config\VSMIDK
2026-10-08 09:59 - 2025-10-27 13:47 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2026-10-08 09:59 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\bcastdvr
2026-10-06 12:58 - 2026-02-10 11:20 - 000000000 ____D C:\Users\suchza\AppData\Local\D3DSCache
2026-10-06 12:57 - 2026-02-10 11:20 - 000000000 __SHD C:\Users\suchza\IntelGraphicsProfiles
2026-10-06 12:57 - 2026-01-27 09:03 - 000000152 _____ C:\WINDOWS\system32\config\netlogon.ftl
2026-10-06 12:57 - 2025-10-27 13:48 - 000015768 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2
2026-10-06 08:42 - 2026-02-10 11:20 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2774596813-2351541506-2060952939-1295
2026-10-06 08:42 - 2026-02-10 11:20 - 000003578 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-2774596813-2351541506-2060952939-1295
2026-10-06 08:42 - 2026-02-10 11:20 - 000003378 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2774596813-2351541506-2060952939-1295
2026-10-06 08:42 - 2026-02-10 11:20 - 000002391 _____ C:\Users\suchza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2026-10-06 08:41 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps
2026-10-05 11:06 - 2025-10-27 14:53 - 000000000 __RHD C:\Users\Public\AccountPictures
2026-10-05 10:16 - 2025-10-27 13:48 - 000002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2026-10-05 10:16 - 2025-10-27 13:48 - 000002281 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2026-10-05 10:10 - 2025-10-27 13:48 - 000003716 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA{570C8069-807B-43CC-A370-55E5A3E26F4E}
2026-10-05 10:10 - 2025-10-27 13:48 - 000003644 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore{31C037CC-B904-4C36-BF46-52B507D70F84}
2026-10-02 11:49 - 2025-10-27 14:51 - 003381760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2026-10-02 11:46 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\USOPrivate
2026-10-02 11:27 - 2025-10-27 13:47 - 000474928 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2026-10-02 11:25 - 2026-01-27 07:47 - 000000000 ____D C:\WINDOWS\system32\ruxim
2026-10-02 11:25 - 2026-01-27 07:47 - 000000000 ____D C:\WINDOWS\system32\NarratorMCAT
2026-10-02 11:25 - 2024-04-01 18:30 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\UUS
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\InstallShield
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemResources
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\setup
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\oobe
2026-10-02 11:25 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\migwiz
2026-10-02 11:24 - 2024-04-01 18:31 - 000000000 ____D C:\WINDOWS\InboxApps
2026-10-02 11:24 - 2024-04-01 18:31 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2026-10-02 11:24 - 2024-04-01 18:30 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView
2026-10-02 11:24 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\system32\F12
2026-10-02 11:24 - 2024-04-01 09:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2026-10-02 11:24 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient
2026-10-02 11:24 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Dism
2026-10-02 11:24 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\appraiser
2026-10-02 11:24 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2026-10-02 11:24 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellExperiences
2026-10-02 11:24 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellComponents
2026-10-02 11:24 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\Provisioning
2026-10-02 11:24 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2026-10-02 11:24 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\L2Schemas
2026-10-02 11:24 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\BrowserCore
2026-10-02 11:24 - 2024-04-01 09:26 - 000000000 ____D C:\Program Files\Common Files\System
2026-10-02 11:24 - 2024-04-01 09:21 - 000000000 ____D C:\WINDOWS\servicing
2026-10-02 11:18 - 2026-01-26 14:37 - 000002254 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2026-10-02 11:18 - 2026-01-26 14:37 - 000002213 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2026-09-23 07:16 - 2026-02-10 11:20 - 000000000 ____D C:\Users\suchza
2026-09-23 07:16 - 2026-01-26 15:04 - 000002180 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk
2026-09-11 11:46 - 2026-01-26 15:08 - 000000000 ____D C:\WINDOWS\system32\MRT
2026-09-11 11:43 - 2026-01-26 15:08 - 230964456 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-10-2026
Ran by lokadmin (08-10-2026 10:25:19)
Running from C:\Users\lokadmin\Desktop
Microsoft Windows 11 Pro Version 25H2 26200.9457 (X64) (2025-10-27 11:50:32)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
(If an entry is included in the fixlist, it will be removed.)
Administrator (S-1-5-21-2366292348-839854579-2745207565-500 - Administrators - Disabled)
DefaultAccount (S-1-5-21-2366292348-839854579-2745207565-503 - Limited - Disabled)
Guest (S-1-5-21-2366292348-839854579-2745207565-501 - Limited - Disabled)
lokadmin (S-1-5-21-2366292348-839854579-2745207565-1002 - Administrators - Enabled) => C:\Users\lokadmin
WDAGUtilityAccount (S-1-5-21-2366292348-839854579-2745207565-504 - Limited - Disabled)
ATTENTION: Domain
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: ESET Security (Enabled - Up to date) {26E0861C-6FB9-CEF9-E4F0-531986211ACE}
FW: ESET Firewall (Enabled) {1EDB0739-25D6-CFA1-CFAF-FA2C78F25DB5}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Reader XI - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AB0000000001}) (Version: 11.0.00 - Adobe Systems Incorporated)
Audacity 3.1.3 (HKLM\...\Audacity_is1) (Version: 3.1.3 - Audacity Team)
Copilot (HKLM-x32\...\Microsoft Copilot) (Version: 154.0.4258.53 - Microsoft Corporation)
Epson Print Admin Driver (HKLM-x32\...\{beb4b9b0-1b06-44ab-b492-d9e29ea4901a}) (Version: 3.1.4 - Seiko Epson Corporation)
ESET Endpoint Security (HKLM\...\{7D2FA44F-7A18-47D1-8BE4-F5CF72090349}) (Version: 13.0.2058.0 - ESET, spol. s r.o.)
ESET Management Agent (HKLM\...\{BF4449DD-3B01-479A-B23E-BE10430D56D6}) (Version: 13.2.1189.0 - ESET, spol. s r.o.)
FreeCommander XE Build 901 32-bit (HKLM-x32\...\{D3C705DC-9743-4FEF-8358-E1AC9FA69C73}_is1) (Version: 2024.0.0.901 - Marek Jasinski)
Google Drive (HKLM\...\{6BBAE539-2232-434A-A4E5-9A33560C6283}) (Version: 131.0.2.0 - Google LLC)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 154.0.8037.95 - Google LLC)
IrfanView 4.60 (64-bit) (HKLM\...\IrfanView64) (Version: 4.60 - Irfan Skiljan)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 154.0.4258.53 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 154.0.4258.53 - Microsoft Corporation) Hidden
Microsoft Excel MUI (Czech) 2016 (HKLM-x32\...\{90160000-0016-0405-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Groove MUI (Czech) 2016 (HKLM-x32\...\{90160000-00BA-0405-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Office 64-bit Components 2016 (HKLM\...\{90160000-002A-0000-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Office Korrekturhilfen 2016 – Deutsch (HKLM-x32\...\{90160000-001F-0407-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Office OSM MUI (Czech) 2016 (HKLM-x32\...\{90160000-00E1-0405-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Office OSM UX MUI (Czech) 2016 (HKLM-x32\...\{90160000-00E2-0405-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Office Proofing (Czech) 2016 (HKLM-x32\...\{90160000-002C-0405-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2016 - English (HKLM-x32\...\{90160000-001F-0409-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (Czech) 2016 (HKLM\...\{90160000-002A-0405-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (Czech) 2016 (HKLM-x32\...\{90160000-006E-0405-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Office Standard 2016 (HKLM-x32\...\{90160000-0012-0000-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Office Standard 2016 (HKLM-x32\...\Office16.STANDARD) (Version: 16.0.4266.1001 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2366292348-839854579-2745207565-1002\...\OneDriveSetup.exe) (Version: 25.243.1211.0001 - Microsoft Corporation)
Microsoft OneNote MUI (Czech) 2016 (HKLM-x32\...\{90160000-00A1-0405-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Outlook MUI (Czech) 2016 (HKLM-x32\...\{90160000-001A-0405-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft PowerPoint MUI (Czech) 2016 (HKLM-x32\...\{90160000-0018-0405-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Publisher MUI (Czech) 2016 (HKLM-x32\...\{90160000-0019-0405-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Microsoft Windows Application Compatibility Fix Database (HKLM\...\{22221111-1111-1111-1111-111111111111}.sdb) (Version: - )
Microsoft Word MUI (Czech) 2016 (HKLM-x32\...\{90160000-001B-0405-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Mozilla Firefox (x64 cs) (HKLM\...\Mozilla Firefox) (Version: 147.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 127.0 - Mozilla)
MPC-HC 2.1.6.18 (4b55a1a2f) Nightly (64-bit) (HKLM\...\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1) (Version: 2.1.6.18 - MPC-HC Team)
Nástroje kontroly pravopisu pro Microsoft Office 2016 – čeština (HKLM-x32\...\{90160000-001F-0405-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Nástroje korektúry balíka Microsoft Office 2016 - slovenčina (HKLM-x32\...\{90160000-001F-041B-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
PhotoFiltre 7 (HKU\S-1-5-21-2366292348-839854579-2745207565-1002\...\PhotoFiltre 7) (Version: - )
PSPad editor (HKLM-x32\...\PSPad editor 32bit_is1) (Version: 5.0.7.775 - Jan Fiala)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.20 - VideoLAN)
Zoner Callisto 5 FREE (HKLM-x32\...\ZonerCallisto5_CZ_is1) (Version: 5.0.5000.16 - ZONER software)
Packages:
=========
AppUp.IntelGraphicsExperience -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5688.0_x64__8j3eq9eme6ctt [2025-10-27] (INTEL CORP) [Startup Task]
ESET Context Menu -> C:\Program Files\ESET\ESET Security [2026-10-02] (Sparse Package)
Intel® Optane™ Memory and Storage Management -> C:\Program Files\WindowsApps\AppUp.IntelOptaneMemoryandStorageManagement_18.1.1042.0_x64__8j3eq9eme6ctt [2025-10-27] (INTEL CORP)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.1.137.0_x64__dt26b99r8h8gj [2025-10-27] (Realtek Semiconductor Corp)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-2366292348-839854579-2745207565-1002_Classes\CLSID\{6e1f4e4d-65f7-4c83-be2e-9e6683cda268}\localserver32 -> C:\Program Files\ESET\ESET Security\egui.exe (ESET, spol. s r.o. -> ESET)
CustomCLSID: HKU\S-1-5-21-2366292348-839854579-2745207565-1002_Classes\CLSID\{DFF20505-B08F-455B-AD70-4FBD055088E0}\localserver32 -> C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe (Google LLC -> Google LLC)
CustomCLSID: HKU\S-1-5-21-2366292348-839854579-2745207565-1002_Classes\CLSID\{ED90173A-3B4C-4E7E-B9CF-79714425D4B5}\InprocServer32 -> C:\Program Files (x86)\PSPad editor\pspshellx64.dll () [File not signed]
ShellIconOverlayIdentifiers: [ GoogleDriveCloudOverlayIconHandler] -> {A8E52322-8734-481D-A7E2-27B309EF8D56} => C:\Program Files\Google\Drive File Stream\131.0.2.0\drivefsext.dll [2026-09-23] (Google LLC -> Google LLC.)
ShellIconOverlayIdentifiers: [ GoogleDriveMirrorBlacklistedOverlayIconHandler] -> {51EF1569-67EE-4AD6-9646-E726C3FFC8A2} => C:\Program Files\Google\Drive File Stream\131.0.2.0\drivefsext.dll [2026-09-23] (Google LLC -> Google LLC.)
ShellIconOverlayIdentifiers: [ GoogleDrivePinnedOverlayIconHandler] -> {CFE8B367-77A7-41D7-9C90-75D16D7DC6B6} => C:\Program Files\Google\Drive File Stream\131.0.2.0\drivefsext.dll [2026-09-23] (Google LLC -> Google LLC.)
ShellIconOverlayIdentifiers: [ GoogleDriveProgressOverlayIconHandler] -> {C973DA94-CBDF-4E77-81D1-E5B794FBD146} => C:\Program Files\Google\Drive File Stream\131.0.2.0\drivefsext.dll [2026-09-23] (Google LLC -> Google LLC.)
ShellIconOverlayIdentifiers-x32: [ GoogleDriveCloudOverlayIconHandler] -> {A8E52322-8734-481D-A7E2-27B309EF8D56} => C:\Program Files\Google\Drive File Stream\131.0.2.0\drivefsext.dll [2026-09-23] (Google LLC -> Google LLC.)
ShellIconOverlayIdentifiers-x32: [ GoogleDriveMirrorBlacklistedOverlayIconHandler] -> {51EF1569-67EE-4AD6-9646-E726C3FFC8A2} => C:\Program Files\Google\Drive File Stream\131.0.2.0\drivefsext.dll [2026-09-23] (Google LLC -> Google LLC.)
ShellIconOverlayIdentifiers-x32: [ GoogleDrivePinnedOverlayIconHandler] -> {CFE8B367-77A7-41D7-9C90-75D16D7DC6B6} => C:\Program Files\Google\Drive File Stream\131.0.2.0\drivefsext.dll [2026-09-23] (Google LLC -> Google LLC.)
ShellIconOverlayIdentifiers-x32: [ GoogleDriveProgressOverlayIconHandler] -> {C973DA94-CBDF-4E77-81D1-E5B794FBD146} => C:\Program Files\Google\Drive File Stream\131.0.2.0\drivefsext.dll [2026-09-23] (Google LLC -> Google LLC.)
ContextMenuHandlers1: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\131.0.2.0\drivefsext.dll [2026-09-23] (Google LLC -> Google LLC.)
ContextMenuHandlers1: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2026-09-02] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers2: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2026-09-02] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers4: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\131.0.2.0\drivefsext.dll [2026-09-23] (Google LLC -> Google LLC.)
ContextMenuHandlers5: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => C:\Program Files\Google\Drive File Stream\131.0.2.0\drivefsext.dll [2026-09-23] (Google LLC -> Google LLC.)
ContextMenuHandlers6: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2026-09-02] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers1_S-1-5-21-2366292348-839854579-2745207565-1002: [EditWithPSPad] -> {ED90173A-3B4C-4E7E-B9CF-79714425D4B5} => C:\Program Files (x86)\PSPad editor\pspshellx64.dll [2014-11-02] () [File not signed]
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
2026-01-27 09:11 - 2018-10-22 12:49 - 005592064 _____ (Microsoft) [File not signed] C:\WINDOWS\System32\casablanca120.dll
2026-01-27 09:11 - 2019-05-31 10:25 - 000831488 _____ (Seiko Epson Corporation) [File not signed] C:\WINDOWS\System32\epscpmon.dll
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) =============
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2024-04-01 09:26 - 2024-04-01 09:24 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
==================== Network ===========================
(Currently there is no automatic fix for this section.)
DNS Servers: Media is not connected to internet.
Windows Firewall is enabled.
Network Binding:
=============
Wi-Fi: Intel(R) Dual Band Wireless-AC 8265 -> Netwtw06.sys
Ethernet: Intel(R) Ethernet Connection (7) I219-V -> e1d.sys
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2366292348-839854579-2745207565-1002\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\DesktopSpotlight\Assets\Images\image_3.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 1) (TamperProtectionSource: 5)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKU\S-1-5-21-2366292348-839854579-2745207565-1002\...\StartupApproved\Run: => "OneDrive"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{727CA964-2325-425C-BBF9-75126AE19A5E}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{338EE6E5-523C-4DCA-874E-E008052E65FA}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [EdgeWebView2-MDNS-In-UDP] => (Allow) C:\WINDOWS\system32\Microsoft-Edge-WebView\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{75CE35DB-9253-4E08-B78D-1FB9F38120C8}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2608.41021.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{7A2D5DDE-CC47-4292-83AD-D8C0B14A3B31}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2608.41021.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{AE749750-3DA6-4C61-829F-5369BC2B47F4}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2608.41021.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{E9E063DD-786E-444E-9103-777329B3B636}] => (Allow) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_19.2608.41021.0_x64__8wekyb3d8bbwe\M365Copilot.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{AD4D52B1-E701-4330-8DD7-4A37B24889E9}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{5A968252-80B3-43B2-BE52-BDFD5DFD95C0}] => (Allow) C:\Program Files (x86)\Microsoft\Copilot\Application\mscopilot.exe (Microsoft Corporation -> Microsoft Corporation)
==================== Restore Points =========================
14-09-2026 10:35:04 Windows Update
18-09-2026 09:28:42 Windows Update
21-09-2026 10:36:43 Windows Update
02-10-2026 11:18:17 Windows Update
05-10-2026 11:21:06 Windows Update
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (08/12/2026 05:49:41 AM) (Source: CertEnroll) (EventID: 87) (User: NT AUTHORITY)
Description: Registrace certifikátu SCEP pro Místní systém přes https://IFX-KeyId-36598f22ec84c3c4f640d ... s/Aik/scep se nepovedla:
PkiStatus(11): SCEPDispositionPendingChallenge
EnrollStatus(32): EnrollUnknown
Operace byla dokončena úspěšně. 0x0 (WIN32: 0)
SubmitDone
SubmitV2Attestation: Bad Request
{"Message":"V2 Protocol AIK certificate requests with ECC public keys are not supported. Public key algorithm: 1.2.840.10045.2.1, Key length: 256."}
HTTP/1.1 400 Bad Request
Date: Wed, 12 Aug 2026 03:49:43 GMT
Content-Length: 148
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: 224ee9a3-a476-459e-8173-b7b1c679a874
Metoda: POST(3141ms)
Fáze: SubmitDone
Chybná žádost (400) 0x80190190 (-2145844848 HTTP_E_STATUS_BAD_REQUEST)
Error: (08/12/2026 05:48:11 AM) (Source: CertEnroll) (EventID: 87) (User: NT AUTHORITY)
Description: Registrace certifikátu SCEP pro Místní systém přes https://IFX-KeyId-36598f22ec84c3c4f640d ... s/Aik/scep se nepovedla:
PkiStatus(11): SCEPDispositionPendingChallenge
EnrollStatus(32): EnrollUnknown
Operace byla dokončena úspěšně. 0x0 (WIN32: 0)
SubmitDone
SubmitV2Attestation: Bad Request
{"Message":"V2 Protocol AIK certificate requests with ECC public keys are not supported. Public key algorithm: 1.2.840.10045.2.1, Key length: 256."}
HTTP/1.1 400 Bad Request
Date: Wed, 12 Aug 2026 03:48:13 GMT
Content-Length: 148
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: 41f19663-0406-4b62-96d4-9c859b1e4882
Metoda: POST(3312ms)
Fáze: SubmitDone
Chybná žádost (400) 0x80190190 (-2145844848 HTTP_E_STATUS_BAD_REQUEST)
Error: (07/27/2026 06:12:44 AM) (Source: CertEnroll) (EventID: 87) (User: NT AUTHORITY)
Description: Registrace certifikátu SCEP pro Místní systém přes https://IFX-KeyId-36598f22ec84c3c4f640d ... s/Aik/scep se nepovedla:
PkiStatus(11): SCEPDispositionPendingChallenge
EnrollStatus(32): EnrollUnknown
Operace byla dokončena úspěšně. 0x0 (WIN32: 0)
SubmitDone
SubmitV2Attestation: Bad Request
{"Message":"V2 Protocol AIK certificate requests with P-256 ECC public keys are not supported. Public key algorithm: 1.2.840.10045.2.1, Key length: 256."}
HTTP/1.1 400 Bad Request
Date: Mon, 27 Jul 2026 04:12:52 GMT
Content-Length: 154
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: f6e5716d-981f-4f81-b98c-062c12dc9ce3
Metoda: POST(2766ms)
Fáze: SubmitDone
Chybná žádost (400) 0x80190190 (-2145844848 HTTP_E_STATUS_BAD_REQUEST)
Error: (07/27/2026 06:11:22 AM) (Source: CertEnroll) (EventID: 87) (User: NT AUTHORITY)
Description: Registrace certifikátu SCEP pro Místní systém přes https://IFX-KeyId-36598f22ec84c3c4f640d ... s/Aik/scep se nepovedla:
PkiStatus(11): SCEPDispositionPendingChallenge
EnrollStatus(32): EnrollUnknown
Operace byla dokončena úspěšně. 0x0 (WIN32: 0)
SubmitDone
SubmitV2Attestation: Bad Request
{"Message":"V2 Protocol AIK certificate requests with P-256 ECC public keys are not supported. Public key algorithm: 1.2.840.10045.2.1, Key length: 256."}
HTTP/1.1 400 Bad Request
Date: Mon, 27 Jul 2026 04:11:29 GMT
Content-Length: 154
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: 98649312-a904-4139-8eb7-f9ae7ec2d998
Metoda: POST(2828ms)
Fáze: SubmitDone
Chybná žádost (400) 0x80190190 (-2145844848 HTTP_E_STATUS_BAD_REQUEST)
Error: (07/26/2026 04:37:23 AM) (Source: Application Error) (EventID: 1000) (User: NT AUTHORITY)
Description: Název chybující aplikace: ERAAgent.exe, verze: 13.1.1110.0, časové razítko: 0x69a93aef
Název chybujícího modulu: ucrtbase.dll, verze: 10.0.26100.8521, časové razítko: 0xc38f7a35
Kód výjimky: 0xc0000409
Posun chyby: 0x00000000000a527e
ID chybujícího procesu: 0x1070
Čas spuštění chybující aplikace: 0x1dd1c90f9b859e1
Cesta k chybující aplikaci: C:\Program Files\ESET\RemoteAdministrator\Agent\ERAAgent.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\ucrtbase.dll
ID sestavy: 5abe657e-4fd9-4e8b-b11d-6ecb038bbcd1
Celý název chybujícího balíčku:
ID chybující aplikace relativní vzhledem k balíčku:
Error: (04/09/2026 11:24:30 AM) (Source: Application Error) (EventID: 1000) (User: NT AUTHORITY)
Description: Název chybující aplikace: ERAAgent.exe, verze: 13.0.1400.0, časové razítko: 0x697ba162
Název chybujícího modulu: ucrtbase.dll, verze: 10.0.26100.7623, časové razítko: 0x53a0792e
Kód výjimky: 0xc0000409
Posun chyby: 0x00000000000a4ace
ID chybujícího procesu: 0xdc0
Čas spuštění chybující aplikace: 0x1dcc8029aade107
Cesta k chybující aplikaci: C:\Program Files\ESET\RemoteAdministrator\Agent\ERAAgent.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\ucrtbase.dll
ID sestavy: b3ee9abf-3271-435f-b67a-7ca3859faa12
Celý název chybujícího balíčku:
ID chybující aplikace relativní vzhledem k balíčku:
Error: (03/06/2026 11:24:49 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Generování kontextu aktivace pro C:\Program Files\Google\Chrome\Application\chrome.exe se nezdařilo.
Závislé sestavení 145.0.7632.160,language="*",type="win32",version="145.0.7632.160" nelze najít.
Podrobnější diagnostické údaje získáte pomocí programu sxstrace.exe.
Error: (02/17/2026 12:57:01 PM) (Source: Application Error) (EventID: 1000) (User: NT AUTHORITY)
Description: Název chybující aplikace: ERAAgent.exe, verze: 12.5.2104.0, časové razítko: 0x68ee4fdb
Název chybujícího modulu: ucrtbase.dll, verze: 10.0.26100.7623, časové razítko: 0x53a0792e
Kód výjimky: 0xc0000409
Posun chyby: 0x00000000000a4ace
ID chybujícího procesu: 0x10b4
Čas spuštění chybující aplikace: 0x1dc9ffbe082f81a
Cesta k chybující aplikaci: C:\Program Files\ESET\RemoteAdministrator\Agent\ERAAgent.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\ucrtbase.dll
ID sestavy: 39fbe5c8-f1d2-4597-8c0c-e41f3eb0e01c
Celý název chybujícího balíčku:
ID chybující aplikace relativní vzhledem k balíčku:
System errors:
=============
Error: (10/08/2026 10:22:40 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel® PROSet/Wireless Service byla neočekávaně ukončena. Tento stav nastal již 1krát.
Error: (10/08/2026 10:22:40 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) Storage Middleware Service byla neočekávaně ukončena. Tento stav nastal již 1krát.
Error: (10/08/2026 10:22:40 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) Graphics Command Center Service byla neočekávaně ukončena. Tento stav nastal již 1krát.
Error: (10/08/2026 10:22:40 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Realtek Audio Universal Service byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 0 milisekund: Restartovat službu.
Error: (10/08/2026 10:22:40 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) Dynamic Application Loader Host Interface Service byla neočekávaně ukončena. Tento stav nastal již 1krát.
Error: (10/08/2026 10:22:40 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) Content Protection HECI Service byla neočekávaně ukončena. Tento stav nastal již 1krát.
Error: (10/08/2026 10:22:40 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Adobe Acrobat Update Service byla neočekávaně ukončena. Tento stav nastal již 1krát.
Error: (10/08/2026 10:22:40 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) HD Graphics Control Panel Service byla neočekávaně ukončena. Tento stav nastal již 1krát.
Windows Defender:
================
CodeIntegrity:
===============
Date: 2026-10-08 10:24:11
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Memory info ===========================
BIOS: LENOVO M1UKT77A 04/10/2024
Motherboard: LENOVO 312D
Processor: Intel(R) Core(TM) i5-8400T CPU @ 1.70GHz
Percentage of memory in use: 44%
Total physical RAM: 8061.76 MB
Available physical RAM: 4471.11 MB
Total Virtual: 8573.76 MB
Available Virtual: 5658.33 MB
==================== Drives ================================
Disk 0 - Drive c: (Windows) (Fixed) (Total:237.29 GB) (Free:168.73 GB) (Model: SAMSUNG MZVLB256HAHQ-000L7) NTFS
Disk 1 - Drive d: (MALÁ ČERNÁ) (Removable) (Total:7.53 GB) (Free:7.52 GB) FAT32
Disk 0 - \\?\Volume{e9fbcbce-6722-4971-8e77-6de0ddf4a061}\ () (Fixed) (Total:890 MB) (Free:115.13 MB) NTFS
Disk 0 - \\?\Volume{861add29-6053-4f69-b527-d3061546469f}\ (SYSTEM) (Fixed) (Total:296 MB) (Free:261.26 MB) FAT32
==================== MBR & Partition Table ====================
============================================================
Disk: 0 (Size: 238.47 GB) (Disk ID: 11898291)
Partitions:
===========
Partition Style : GPT
Partition Count : 4
Disk ID : {0B74D375-893B-49FC-9C52-8D9FDE007BEF}
Usable Offset : 0.02 MB
Usable Length : 238.47 GB
Max Partitions : 128
Partition 1
Type : EFI System Partition
Size : 300 MB
Offset : 1 MB
Type GUID : {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}
Partition GUID : {861ADD29-6053-4F69-B527-D3061546469F}
Attributes : 0x0000000000000000
Attribute Flags : None
Hidden : Yes
Platform Required: No
------------------------------------------------------------
Partition 2
Type : Microsoft Reserved (MSR)
Size : 16 MB
Offset : 301 MB
Type GUID : {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}
Partition GUID : {E0ECE00C-7FA1-4FCC-81CE-FC5CE28E4082}
Attributes : 0x0000000000000000
Attribute Flags : None
Hidden : Yes
Platform Required: No
------------------------------------------------------------
Partition 3
Type : Basic Data Partition
Size : 237.29 GB
Offset : 317 MB
Type GUID : {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}
Partition GUID : {5F9AA19F-5479-48ED-A966-5335EA0E3C1E}
Attributes : 0x0000000000000000
Attribute Flags : None
Hidden : No
Platform Required: No
------------------------------------------------------------
Partition 4
Type : Windows Recovery
Size : 890 MB
Offset : 243307 MB
Type GUID : {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}
Partition GUID : {E9FBCBCE-6722-4971-8E77-6DE0DDF4A061}
Attributes : 0x8000000000000001
Attribute Flags : Platform Required, No Default Drive Letter
Hidden : Yes
Platform Required: Yes
------------------------------------------------------------
============================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 7.55 GB) (Disk ID: B467DEC6)
Partitions:
===========
Partition Style : MBR
Partition Count : 4
Disk Signature : 0xB467DEC6
Partition 1
Type : MBR 0x0C (FAT32 LBA)
Size : 7.55 GB
Offset : 1 MB
Partition GUID : {B467DEC6-0000-0000-0000-100000000000}
Bootable : Yes
Recognized : Yes
Hidden Sectors : 2048
------------------------------------------------------------
Partition Entries : 4
Actual Partitions : 1
============================================================
==================== End of Addition.txt =======================