Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04.03.2018
Ran by Jirka (08-03-2018 16:26:43)
Running from D:\DLed
Windows 10 Home Version 1709 16299.248 (X64) (2018-02-24 17:47:00)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3974176077-1731350340-1435568019-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3974176077-1731350340-1435568019-503 - Limited - Disabled)
Guest (S-1-5-21-3974176077-1731350340-1435568019-501 - Limited - Disabled)
Jirka (S-1-5-21-3974176077-1731350340-1435568019-1001 - Administrator - Enabled) => C:\Users\Jirka
WDAGUtilityAccount (S-1-5-21-3974176077-1731350340-1435568019-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avira Antivirus (Enabled - Up to date) {B3F630BD-538D-1B4A-14FA-14B63235278F}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avira Antivirus (Enabled - Up to date) {0897D159-75B7-14C4-2E4A-2FC449B26D32}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 18.011.20038 - Adobe Systems Incorporated)
Avira (HKLM-x32\...\{59d593c9-028b-4f00-a84d-7a71f5a28ad7}) (Version: 1.2.106.18629 - Avira Operations GmbH & Co. KG)
Avira (HKLM-x32\...\{64874AE0-1F9C-426A-96FC-C53A57C97ADE}) (Version: 1.2.106.18629 - Avira Operations GmbH & Co. KG) Hidden
Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.34.27 - Avira Operations GmbH & Co. KG)
Backup and Sync from Google (HKLM-x32\...\{AC62F3F2-61A2-4357-93EC-C308E3FEDF4E}) (Version: 3.39.8370.7843 - Google, Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.40 - Piriform)
DisplayDriverAnalyzer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_DisplayDriverAnalyzer) (Version: 391.01 - NVIDIA Corporation) Hidden
foobar2000 v1.3.17 (HKLM-x32\...\foobar2000) (Version: 1.3.17 - Peter Pawlowski)
GOM Player (HKLM-x32\...\GOM Player) (Version: 2.3.14.5270 - Gretech Corporation)
Google Chrome (HKLM\...\{E2B4C74E-210E-39AD-872C-DA95D0CCED99}) (Version: 64.0.3282.186 - Google, Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Greenshot 1.2.10.6 (HKLM\...\Greenshot_is1) (Version: 1.2.10.6 - Greenshot)
Java 8 Update 161 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180161F0}) (Version: 8.0.1610.12 - Oracle Corporation)
Java 8 Update 161 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180161F0}) (Version: 8.0.1610.12 - Oracle Corporation)
K-Lite Codec Pack 14.0.0 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 14.0.0 - KLCP)
Microsoft Office 365 ProPlus - en-us (HKLM\...\O365ProPlusRetail - en-us) (Version: 16.0.8431.2215 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3974176077-1731350340-1435568019-1001\...\OneDriveSetup.exe) (Version: 17.005.0107.0008 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
NVIDIA 3D Vision Controller Driver 390.41 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 390.41 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 391.01 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 391.01 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.12.0.84 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.12.0.84 - NVIDIA Corporation)
NVIDIA Graphics Driver 391.01 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 391.01 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.36.6 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.36.6 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.17.0524 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0524 - NVIDIA Corporation)
OBS Studio (HKLM-x32\...\OBS Studio) (Version: 21.0.1 - OBS Project)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.8431.2215 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.8431.2215 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.8326.2076 - Microsoft Corporation) Hidden
qBittorrent 4.0.4 (HKLM-x32\...\qBittorrent) (Version: 4.0.4 - The qBittorrent project)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
TeamViewer 13 (HKLM-x32\...\TeamViewer) (Version: 13.0.6447 - TeamViewer)
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
WinRAR 5.50 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.50.0 - win.rar GmbH)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2018-01-29] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2018-01-29] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2018-01-29] (Google)
ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2018-01-29] (Google)
ContextMenuHandlers1: [Shell Extension for Malware scanning] -> {45AC2688-0253-4ED8-97DE-B5370FA7D48A} => C:\Program Files (x86)\Avira\Antivirus\shlext64.dll [2018-02-01] (Avira Operations GmbH & Co. KG)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-08-11] (Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-08-11] (Alexander Roshal)
ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2018-01-29] (Google)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2018-02-23] (NVIDIA Corporation)
ContextMenuHandlers6: [Shell Extension for Malware scanning] -> {45AC2688-0253-4ED8-97DE-B5370FA7D48A} => C:\Program Files (x86)\Avira\Antivirus\shlext64.dll [2018-02-01] (Avira Operations GmbH & Co. KG)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-08-11] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-08-11] (Alexander Roshal)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0A6409CF-7E47-4371-885D-B04AEB3C17BE} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-01-10] (NVIDIA Corporation)
Task: {13C9CB73-97E4-497A-BF18-B2EBCDE32421} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-02-07] (Piriform Ltd)
Task: {15256A15-E754-4755-896D-830C915BAFCE} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2018-01-10] (NVIDIA Corporation)
Task: {1F7993B1-FD71-4C7E-A947-58983B934216} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-02-07] (Piriform Ltd)
Task: {4F62B2D3-A43B-4B0F-ACC2-DDCACDFE8002} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [2018-02-26] (Microsoft Corporation)
Task: {50C12719-7276-4564-BED7-BECC32F341A5} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-02-02] (Microsoft Corporation)
Task: {595103E6-F6D0-42DD-AC8C-D06631B9C8A0} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2018-01-10] (NVIDIA Corporation)
Task: {6CA6993F-634E-4D4F-8F81-014F8A296048} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2018-01-10] (NVIDIA Corporation)
Task: {6E632E5E-D6C1-40E8-A851-08552065562B} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-02-02] (Microsoft Corporation)
Task: {6F3D7DDC-B758-4D2E-8C0D-603955693CF5} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-02-26] ()
Task: {747402DA-80D4-4259-9DAE-368B189A297D} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2018-02-19] ()
Task: {75E44745-4AA4-44FE-B0B5-F292B486AAEA} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2018-01-10] (NVIDIA Corporation)
Task: {7E3B2BA4-D99C-4307-9640-CF095A2DCCDC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-02-24] (Google Inc.)
Task: {802A1035-251F-4068-BEB0-8CBE71047E4D} - System32\Tasks\Avira_Antivirus_Systray => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [2018-02-01] (Avira Operations GmbH & Co. KG)
Task: {860727DA-F17A-40F9-94B2-63A93A6054AA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-02-24] (Google Inc.)
Task: {86E6DA2F-FD11-40AB-A69B-B357BD085197} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2018-01-10] (NVIDIA Corporation)
Task: {9CB80E47-F149-4B89-AA78-0308139623CD} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-02-26] ()
Task: {B5701944-7B4D-4363-8FCE-1DE7CACE28E8} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2018-01-10] (NVIDIA Corporation)
Task: {BB69428A-F70E-4F0C-BCCF-B97CA7820555} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-02-09] (Adobe Systems Incorporated)
Task: {E110B024-6A4B-41A9-A2F4-EA1157C60C60} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2018-02-26] (Microsoft Corporation)
Task: {E3543027-38FC-46E7-9046-5B39AE7FEEA9} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-01-10] (NVIDIA Corporation)
Task: {E9129ECB-6912-4EF0-AFC9-228981BCD240} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [2018-02-26] (Microsoft Corporation)
Task: {F29F6CBD-F173-44EB-90AA-DE5A4FF491D6} - System32\Tasks\Optimize Push Notification Data File-S-1-5-21-3974176077-1731350340-1435568019-1001

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


Shortcut: C:\Users\Jirka\Google Drive\Private void dontShare()\Záloha - WD1TB\Extras\Adobe Reader Download.lnk -> hxxp://get.adobe.com/reader

==================== Loaded Modules (Whitelisted) ==============

2018-02-24 19:30 - 2018-02-24 05:36 - 000543248 _____ () C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem\DisplayDriverAnalyzer\_DisplayDriverCrashAnalyzer64.dll
2018-02-24 19:05 - 2018-01-10 15:05 - 001269096 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll
2017-09-29 14:41 - 2017-09-29 14:41 - 000184432 _____ () C:\Windows\SYSTEM32\inputhost.dll
2018-02-24 19:30 - 2018-02-23 20:22 - 000133464 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2018-02-25 11:40 - 2018-02-10 05:39 - 011044864 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2018-02-25 11:40 - 2018-02-10 05:36 - 001804288 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2018-01-29 12:42 - 2018-01-29 12:42 - 041100328 _____ () C:\Program Files (x86)\Google\Drive\googledrivesync.exe
2018-02-24 18:56 - 2018-02-22 04:57 - 004433752 _____ () C:\Program Files (x86)\Google\Chrome\Application\64.0.3282.186\libglesv2.dll
2018-02-24 18:56 - 2018-02-22 04:57 - 000099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\64.0.3282.186\libegl.dll
2018-02-24 19:28 - 2018-02-24 19:28 - 002250240 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11801.1001.6.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2018-03-02 13:33 - 2018-03-02 13:34 - 000477696 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18021.12420.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
2018-03-02 13:33 - 2018-03-02 13:34 - 059575808 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18021.12420.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
2018-02-24 19:28 - 2018-02-24 19:29 - 002523136 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18021.12420.0_x64__8wekyb3d8bbwe\UnityEngineDelegates.dll
2018-02-24 19:28 - 2018-02-24 19:29 - 000010240 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18021.12420.0_x64__8wekyb3d8bbwe\RenderingPlugin.dll
2018-03-02 13:33 - 2018-03-02 13:34 - 003741184 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18021.12420.0_x64__8wekyb3d8bbwe\MediaEngineCSWrapper.dll
2018-02-24 19:28 - 2018-02-24 19:29 - 002270720 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18021.12420.0_x64__8wekyb3d8bbwe\TrackingDLLUWP.dll
2018-03-02 13:33 - 2018-03-02 13:34 - 015986688 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18021.12420.0_x64__8wekyb3d8bbwe\PhotosApp.Windows.dll
2018-03-02 13:33 - 2018-03-02 13:34 - 003592704 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18021.12420.0_x64__8wekyb3d8bbwe\MediaEngine.dll
2018-03-02 13:33 - 2018-03-02 13:33 - 003231232 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18021.12420.0_x64__8wekyb3d8bbwe\AppCore.Windows.dll
2018-03-02 13:33 - 2018-03-02 13:34 - 001369088 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18021.12420.0_x64__8wekyb3d8bbwe\Microsoft.RichMedia.Ink.Controls.dll
2018-02-24 19:28 - 2018-02-24 19:29 - 004601048 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18021.12420.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2018-03-02 13:33 - 2018-03-02 13:33 - 000094208 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18021.12420.0_x64__8wekyb3d8bbwe\BendRealityNode.dll
2018-02-24 19:28 - 2018-02-24 19:29 - 000043520 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18021.12420.0_x64__8wekyb3d8bbwe\Microsoft.Photos.Edit.Services.dll
2018-03-02 13:33 - 2018-03-02 13:34 - 000628736 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18021.12420.0_x64__8wekyb3d8bbwe\RuntimeConfiguration.dll
2018-03-02 13:33 - 2018-03-02 13:34 - 000152064 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18021.12420.0_x64__8wekyb3d8bbwe\SKU.dll
2018-02-24 19:28 - 2018-02-24 19:28 - 004371456 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1802.311.0_x64__8wekyb3d8bbwe\Calculator.exe
2018-02-24 19:28 - 2018-02-24 19:28 - 000605696 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1802.311.0_x64__8wekyb3d8bbwe\AppsPreviewProgram.dll
2018-02-24 19:05 - 2018-01-10 15:05 - 001042280 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll
2018-02-24 19:05 - 2018-01-10 15:05 - 066908520 _____ () C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\libcef.dll
2018-02-24 19:33 - 2017-11-29 06:09 - 000781088 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2018-02-24 19:33 - 2017-12-15 20:59 - 002558752 _____ () C:\Program Files (x86)\Steam\video.dll
2018-02-24 19:33 - 2016-09-01 02:02 - 004969248 _____ () C:\Program Files (x86)\Steam\v8.dll
2018-02-24 19:33 - 2017-11-04 02:54 - 000695584 _____ () C:\Program Files (x86)\Steam\libavformat-57.dll
2018-02-24 19:33 - 2017-11-04 02:54 - 000351520 _____ () C:\Program Files (x86)\Steam\libavresample-3.dll
2018-02-24 19:33 - 2017-11-04 02:54 - 000847136 _____ () C:\Program Files (x86)\Steam\libavutil-55.dll
2018-02-24 19:33 - 2017-11-04 02:54 - 000783648 _____ () C:\Program Files (x86)\Steam\libswscale-4.dll
2018-02-24 19:33 - 2017-11-04 02:54 - 005137696 _____ () C:\Program Files (x86)\Steam\libavcodec-57.dll
2018-02-24 19:33 - 2016-09-01 02:02 - 001195296 _____ () C:\Program Files (x86)\Steam\icuuc.dll
2018-02-24 19:33 - 2016-09-01 02:02 - 001563936 _____ () C:\Program Files (x86)\Steam\icui18n.dll
2018-02-24 19:33 - 2017-12-15 20:59 - 000904992 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2018-02-24 19:33 - 2016-07-04 23:17 - 000266560 _____ () C:\Program Files (x86)\Steam\openvr_api.dll
2018-02-24 19:33 - 2017-09-07 03:04 - 000678400 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\SDL2.dll
2018-02-24 19:33 - 2017-10-31 05:44 - 071471904 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\libcef.dll
2018-02-24 19:33 - 2015-09-25 00:52 - 000119208 _____ () C:\Program Files (x86)\Steam\winh264.dll
2018-03-08 16:00 - 2018-03-08 16:00 - 000088064 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\_ctypes.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000069120 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\bz2.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000920064 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\_hashlib.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000098816 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\win32api.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000110080 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\pywintypes27.dll
2018-03-08 16:00 - 2018-03-08 16:00 - 000364544 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\pythoncom27.dll
2018-03-08 16:00 - 2018-03-08 16:00 - 000686080 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\unicodedata.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000320512 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\win32com.shell.shell.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 001177088 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\wx._core_.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000806912 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\wx._gdi_.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000816640 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\wx._windows_.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 001067520 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\wx._controls_.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000733696 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\wx._misc_.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000736256 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\pysqlite2._sqlite.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000119808 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\win32file.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000108544 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\win32security.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000007168 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\hashobjs_ext.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000017920 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\thumbnails_ext.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000082432 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\usb_ext.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000013824 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\common.time34.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000018432 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\win32event.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000027648 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\windows.conditional.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000017408 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\windows.winwrap.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000089088 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\windows.volumes.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000167936 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\win32gui.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000046080 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\_socket.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 001311232 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\_ssl.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000135680 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\_elementtree.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000133632 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\pyexpat.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000038912 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\win32inet.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000077824 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\wx._html2.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000036864 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\_psutil_windows.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000524248 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\windows._lib_cacheinvalidation.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000010240 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\select.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000011264 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\win32crypt.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000218624 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\PIL._imaging.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000027648 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\_multiprocessing.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000020480 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\_yappi.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000035840 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\win32process.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000024064 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\win32pipe.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000025600 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\win32pdh.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000059392 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\windows.device_monitor.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000017408 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\win32profile.pyd
2018-03-08 16:00 - 2018-03-08 16:00 - 000022528 _____ () C:\Users\Jirka\AppData\Local\Temp\_MEI94802\win32ts.pyd

==================== Alternate Data Streams (Whitelisted) =========

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2017-09-29 14:46 - 2017-09-29 14:44 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3974176077-1731350340-1435568019-1001\Control Panel\Desktop\\Wallpaper -> c:\users\jirka\appdata\local\packages\microsoft.windows.photos_8wekyb3d8bbwe\localstate\photosappbackground\starwars-1519504642851-3141.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

HKU\S-1-5-21-3974176077-1731350340-1435568019-1001\...\StartupApproved\Run: => "OneDrive"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{10DBE8F6-88EB-408D-8A37-98D1A89D48A4}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{8FBA41AA-4D94-4FA9-B91A-E29E122C3699}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{27610CCA-DB4A-4135-8B93-3DD872B1BBDC}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{2C3B363C-480C-40F5-99D5-F715CF126480}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{2CC6FB51-2DE6-4844-A827-83149211D373}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{E32C72CD-345F-45C9-B302-2C11CA2D5C96}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{7DDB4664-5E86-4BF6-93DF-873F6FDB8D72}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{F163E93C-A8A3-4586-BE8D-10A20F813FF5}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe
FirewallRules: [{CA75C0FF-BAF9-4641-9A2C-5FC6565F118B}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe
FirewallRules: [{A39ECA0C-5465-414F-A392-CC90D74FDDEA}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{168BE910-A243-4A30-8A3A-1A3130B81124}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{238D1BFC-01F4-4C26-B77A-98B7E1CECC08}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{0959FBAE-AC90-4B06-BBDF-43FCB2C54791}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{E7894707-9123-4BF1-AE4E-B2313203AA11}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{F30DBD71-87EA-49BC-8864-7B343214D5C1}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{B7F42FE4-5524-4BB4-8518-28B010020817}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{BD1EDF95-0B84-43AF-BFBF-71E79B74EAA9}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{739DDA90-CE5B-4CA8-9AFD-37A660D60FC0}] => (Allow) D:\Hry\SteamLibrary\steamapps\common\Torchlight II\ModLauncher.exe
FirewallRules: [{0D75B75E-40F9-4EB5-A3D9-335862F34C51}] => (Allow) D:\Hry\SteamLibrary\steamapps\common\Torchlight II\ModLauncher.exe
FirewallRules: [{6F293C3C-48C7-4574-BF02-4A980FCC5798}] => (Allow) D:\Hry\SteamLibrary\steamapps\common\Borderlands\Binaries\Borderlands.exe
FirewallRules: [{A763BF89-449A-449E-AAE3-2905C3966413}] => (Allow) D:\Hry\SteamLibrary\steamapps\common\Borderlands\Binaries\Borderlands.exe
FirewallRules: [{7F204490-C2D9-4637-8F23-8938DA24104F}] => (Allow) D:\Hry\SteamLibrary\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe
FirewallRules: [{59EF49A4-549F-42D5-9916-04DF8BF7C85A}] => (Allow) D:\Hry\SteamLibrary\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe
FirewallRules: [{9F7B51AF-2066-4DED-B08F-EDF06CF3F2FA}] => (Allow) D:\Hry\SteamLibrary\steamapps\common\BorderlandsPreSequel\Binaries\Win32\Launcher.exe
FirewallRules: [{CD48CAC5-F934-45B0-A28A-0F3317AE54C1}] => (Allow) D:\Hry\SteamLibrary\steamapps\common\BorderlandsPreSequel\Binaries\Win32\Launcher.exe
FirewallRules: [TCP Query User{37E6DD71-3734-4A14-B588-74973DB43D2E}D:\hry\steamlibrary\steamapps\common\borderlandspresequel\binaries\win32\borderlandspresequel.exe] => (Allow) D:\hry\steamlibrary\steamapps\common\borderlandspresequel\binaries\win32\borderlandspresequel.exe
FirewallRules: [UDP Query User{5F511F63-ACFB-4821-BCBD-C3FB182D72AB}D:\hry\steamlibrary\steamapps\common\borderlandspresequel\binaries\win32\borderlandspresequel.exe] => (Allow) D:\hry\steamlibrary\steamapps\common\borderlandspresequel\binaries\win32\borderlandspresequel.exe
FirewallRules: [{621479DF-0818-4A7D-8C62-578040F97D0B}] => (Block) D:\hry\steamlibrary\steamapps\common\borderlandspresequel\binaries\win32\borderlandspresequel.exe
FirewallRules: [{E3358BB4-2BF9-4175-BB95-40AB63A7CF99}] => (Block) D:\hry\steamlibrary\steamapps\common\borderlandspresequel\binaries\win32\borderlandspresequel.exe
FirewallRules: [{F9496CD8-4EB3-4CBB-A09D-4556B2541BC2}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{4400ABEC-A20B-4F3A-8FD2-3C4CE842B470}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{DABD7CE8-444F-48DF-9922-3F6BA32F56D1}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{3D3265A3-676A-4C26-ADB3-8BDD30CFE636}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{8C1FE6B1-10CD-4A0A-8E09-91D38B21C845}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{472C3DC0-E76A-43BC-8963-8627D861610E}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.75.483.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{CCEE090B-CD05-4F23-82DE-4A534D4D10FB}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.75.483.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{43BADCB7-7E8A-4520-8667-DC0E093E9648}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.75.483.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{7628C585-8F0D-47AD-A54C-16D316B3C104}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.75.483.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{075EA568-B0C8-4CA7-BE09-EC2EB7606339}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.75.483.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{D4A9BF53-C355-412E-A6B7-E811D36BC446}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.75.483.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{2C63ECB8-98C3-4338-91BF-17978FCCB3BB}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.75.483.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{B12151AD-36B8-43C0-B98B-6CE6A9B50E17}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.75.483.0_x86__zpdnekdrzrea0\Spotify.exe
FirewallRules: [{A351513D-4246-43EB-BC01-CBC1B00AD263}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.75.483.0_x86__zpdnekdrzrea0\SpotifyWebHelper.exe
FirewallRules: [{CC8AD15E-F21C-4442-96CD-F5A61850D055}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.75.483.0_x86__zpdnekdrzrea0\SpotifyWebHelper.exe

==================== Restore Points =========================

ATTENTION: System Restore is disabled

==================== Faulty Device Manager Devices =============

Name: WD SES Device USB Device
Description: WD SES Device USB Device
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (03/03/2018 10:00:12 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program svchost.exe version 10.0.16299.15 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

Process ID: 9d8

Start Time: 01d3b2c2f7987960

Termination Time: 4294967295

Application Path: C:\Windows\System32\svchost.exe

Report Id: dbeefeea-06e8-41e6-bbdc-de96a5f0ec34

Faulting package full name: 

Faulting package-relative application ID:

Error: (02/24/2018 08:43:06 PM) (Source: Application Error) (EventID: 1005) (User: )
Description: Windows cannot access the file  for one of the following reasons:
there is a problem with the network connection, the disk that the file is stored on, or the storage
drivers installed on this computer; or the disk is missing.
Windows closed the program Windows Explorer because of this error.

Program: Windows Explorer
File: 

The error value is listed in the Additional Data section.
User Action
1. Open the file again.
This situation might be a temporary problem that corrects itself when the program runs again.
2.
If the file still cannot be accessed and
	- It is on the network,
your network administrator should verify that there is not a problem with the network and that the server can be contacted.
	- It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.
4. If the problem persists, restore the file from a backup copy.
5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for
further assistance.

Additional Data
Error value: 00000000
Disk type: 0

Error: (02/24/2018 08:43:06 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: explorer.exe, version: 10.0.16299.125, time stamp: 0x98ed27dd
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000096
Fault offset: 0x00ecfb26
Faulting process ID: 0x1604
Faulting application start time: 0x01d3ada7ab32bdb5
Faulting application path: C:\Windows\SysWOW64\explorer.exe
Faulting module path: unknown
Report ID: 3d73f3d9-7ec6-4eb5-a872-a5ca8b06dfe9
Faulting package full name: 
Faulting package-relative application ID:

Error: (02/24/2018 08:41:41 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: nvcplui.exe, version: 8.1.940.0, time stamp: 0x5a67b73b
Faulting module name: nvcplui.exe, version: 8.1.940.0, time stamp: 0x5a67b73b
Exception code: 0xc0000409
Fault offset: 0x000000000028080d
Faulting process ID: 0xc0c
Faulting application start time: 0x01d3ada77d49e579
Faulting application path: C:\Program Files\NVIDIA Corporation\Control Panel Client\nvcplui.exe
Faulting module path: C:\Program Files\NVIDIA Corporation\Control Panel Client\nvcplui.exe
Report ID: 01916418-6b1c-4526-83f8-b31ab2ab32d3
Faulting package full name: 
Faulting package-relative application ID:

Error: (02/24/2018 08:39:11 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: readerdc_cz_xa_crd_install.exe, version: 2.0.0.163, time stamp: 0x59cb13d2
Faulting module name: readerdc_cz_xa_crd_install.exe, version: 2.0.0.163, time stamp: 0x59cb13d2
Exception code: 0xc0000005
Fault offset: 0x00005ac7
Faulting process ID: 0x5a4
Faulting application start time: 0x01d3ada7225e06f9
Faulting application path: D:\DLed\readerdc_cz_xa_crd_install.exe
Faulting module path: D:\DLed\readerdc_cz_xa_crd_install.exe
Report ID: e67d23a2-ddb1-418e-96cc-d005a234f298
Faulting package full name: 
Faulting package-relative application ID:

Error: (02/24/2018 06:53:45 PM) (Source: ESENT) (EventID: 522) (User: )
Description: ShellExperienceHost (4132,P,0) TILEREPOSITORYS-1-5-21-3974176077-1731350340-1435568019-1001: An attempt to open the device with name "\\.\C:" containing "C:\" failed with system error 5 (0x00000005): "Access is denied. ". The operation will fail with error -1032 (0xfffffbf8).

Error: (02/24/2018 06:53:45 PM) (Source: ESENT) (EventID: 522) (User: )
Description: ShellExperienceHost (4132,P,0) TILEREPOSITORYS-1-5-21-3974176077-1731350340-1435568019-1001: An attempt to open the device with name "\\.\C:" containing "C:\" failed with system error 5 (0x00000005): "Access is denied. ". The operation will fail with error -1032 (0xfffffbf8).

Error: (02/24/2018 06:53:45 PM) (Source: ESENT) (EventID: 522) (User: )
Description: ShellExperienceHost (4132,P,0) TILEREPOSITORYS-1-5-21-3974176077-1731350340-1435568019-1001: An attempt to open the device with name "\\.\C:" containing "C:\" failed with system error 5 (0x00000005): "Access is denied. ". The operation will fail with error -1032 (0xfffffbf8).


System errors:
=============
Error: (03/08/2018 04:01:57 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
Description: DCOM got error "1053" attempting to start the service gupdate with arguments "/comsvc" in order to run the server:
{4EB61BAC-A3B6-4760-9581-655041EF4D69}

Error: (03/08/2018 04:01:35 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Google Update Service (gupdate) service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.

Error: (03/08/2018 04:01:35 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Google Update Service (gupdate) service to connect.

Error: (03/08/2018 04:00:44 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-HBP4HDR)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user DESKTOP-HBP4HDR\Jirka SID (S-1-5-21-3974176077-1731350340-1435568019-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (03/08/2018 04:00:23 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (03/08/2018 04:00:23 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (03/08/2018 04:00:23 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (03/08/2018 04:00:23 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.


Windows Defender:
===================================
Date: 2018-03-02 11:28:57.940
Description: 
Windows Defender Antivirus Real-Time Protection feature has encountered an error and failed.
Feature: Behavior Monitoring
Error Code: 0x80508023
Error description: The program could not find the malware and other potentially unwanted software on this device. 
Reason: Real-time protection has stopped functioning for an unknown reason. Restart the service in order to recover.

Date: 2018-03-02 11:28:56.777
Description: 
Windows Defender Antivirus Real-Time Protection feature has encountered an error and failed.
Feature: Behavior Monitoring
Error Code: 0x80508023
Error description: The program could not find the malware and other potentially unwanted software on this device. 
Reason: Antimalware protection has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.

CodeIntegrity:
===================================

Date: 2018-02-26 20:43:54.173
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\NVIDIA Corporation\Ansel\Tools\NvCameraWhitelisting64.dll that did not meet the Microsoft signing level requirements.

Date: 2018-02-26 20:43:51.265
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\NVIDIA Corporation\Ansel\Tools\NvCameraWhitelisting64.dll that did not meet the Microsoft signing level requirements.

Date: 2018-02-26 20:43:24.298
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\NVIDIA Corporation\Ansel\Tools\NvCameraWhitelisting64.dll that did not meet the Microsoft signing level requirements.

Date: 2018-02-26 20:43:19.524
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\NVIDIA Corporation\Ansel\Tools\NvCameraWhitelisting64.dll that did not meet the Microsoft signing level requirements.

Date: 2018-02-26 20:42:10.708
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\NVIDIA Corporation\Ansel\Tools\NvCameraWhitelisting64.dll that did not meet the Microsoft signing level requirements.

Date: 2018-02-26 20:42:06.981
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\NVIDIA Corporation\Ansel\Tools\NvCameraWhitelisting64.dll that did not meet the Microsoft signing level requirements.

Date: 2018-02-26 20:42:06.939
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\NVIDIA Corporation\Ansel\Tools\NvCameraWhitelisting64.dll that did not meet the Microsoft signing level requirements.

Date: 2018-02-26 20:42:06.727
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\NVIDIA Corporation\Ansel\Tools\NvCameraWhitelisting64.dll that did not meet the Microsoft signing level requirements.

==================== Memory info =========================== 

Processor: AMD FX(tm)-8320 Eight-Core Processor 
Percentage of memory in use: 48%
Total physical RAM: 8140.04 MB
Available physical RAM: 4192.17 MB
Total Virtual: 10572.04 MB
Available Virtual: 5887.79 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:118.8 GB) (Free:76.54 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (Lair of Infinite Agony) (Fixed) (Total:931.51 GB) (Free:643.6 GB) NTFS
Drive e: (Lair of Passport) (Fixed) (Total:931.48 GB) (Free:893.78 GB) NTFS
Drive f: (Lair of Multimedia) (Fixed) (Total:4657.4 GB) (Free:3100.95 GB) NTFS

\\?\Volume{794b2fef-0000-0000-0000-40b31d000000}\ () (Fixed) (Total:0.44 GB) (Free:0.07 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 794B2FF7)
Partition 1: (Active) - (Size=931.5 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 119.2 GB) (Disk ID: 794B2FEF)
Partition 1: (Active) - (Size=118.8 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=450 MB) - (Type=27)

========================================================
Disk: 2 (Size: 931.5 GB) (Disk ID: B966A755)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)

========================================================
Disk: 3 (Size: 4657.5 GB) (Disk ID: BF767FAC)

Partition: GPT.

==================== End of Addition.txt ============================