Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-03-2020
Ran by Rastislav (20-03-2020 09:46:03)
Running from C:\Users\rasti\Downloads
Windows 10 Home Version 1809 17763.1098 (X64) (2019-05-04 17:53:29)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-215137528-2830479082-3927747001-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-215137528-2830479082-3927747001-503 - Limited - Disabled)
Guest (S-1-5-21-215137528-2830479082-3927747001-501 - Limited - Disabled)
hardi (S-1-5-21-215137528-2830479082-3927747001-1005 - Limited - Disabled)
rasti (S-1-5-21-215137528-2830479082-3927747001-1002 - Limited - Disabled)
Rastislav (S-1-5-21-215137528-2830479082-3927747001-1001 - Administrator - Enabled) => C:\Users\rasti
WDAGUtilityAccount (S-1-5-21-215137528-2830479082-3927747001-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: ESET Security (Enabled - Up to date) {885D845F-AF19-0124-FECE-FFF49D00F440}
AS: ESET Security (Enabled - Up to date) {333C65BB-8923-0EAA-C47E-C486E687BEFD}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC - Slovak (HKLM-x32\...\{AC76BA86-7AD7-1051-7B44-AC0F074E4100}) (Version: 20.006.20042 - Adobe Systems Incorporated)
Advertising Center (HKLM-x32\...\{b2ec4a38-b545-4a00-8214-13fe0e915e6d}) (Version: 0.0.0.1 - Nero AG) Hidden
Any Video Converter Ultimate 5.8.1 (HKLM-x32\...\Any Video Converter Ultimate_is1) (Version:  - Any-Video-Converter.com)
AOMEI Partition Assistant Standard Edition 8.5 (HKLM-x32\...\{02F850ED-FD0E-4ED1-BE0B-54981f5BD3D4}_is1) (Version:  - AOMEI Technology Co., Ltd.)
Apple Software Update (HKLM-x32\...\{A3985C05-7386-411F-A4BF-32A73F37EB44}) (Version: 2.6.3.1 - Apple Inc.)
Autodesk MapGuide(R) Viewer ActiveX Control Release 6.5 (HKLM-x32\...\{E031338C-839D-4EDD-9537-99B653C39D81}) (Version: 6.5.5.24 - Autodesk, Inc.)
Backup and Sync from Google (HKLM\...\{825F60D9-2633-4D52-B2B0-5DA143433BBC}) (Version: 3.48.8668.1933 - Google, Inc.)
BatteryCare 0.9.32.0 (HKLM-x32\...\{C6A6036D-FBD0-4324-BEAA-C0845257160C}_is1) (Version: 0.9.32.0 - Filipe Lourenço)
BeamNG Drive (HKLM-x32\...\BeamNG Drive 0.10.0.1) (Version: 0.10.0.1 - BeamNG)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Camtasia Studio 8 (HKLM-x32\...\{5303CFB5-D635-44F0-A94B-9611E81F07C4}) (Version: 8.3.0.1471 - TechSmith Corporation)
CCleaner (HKLM\...\CCleaner) (Version: 5.62 - Piriform)
CEWE FOTOSVET (HKLM-x32\...\CEWE FOTOSVET) (Version: 6.3.7 - CEWE Stiftung u Co. KGaA)
Counter-Strike 1.6 (HKLM-x32\...\{13B792AA-C078-43A4-8A3A-8B12D629940D}) (Version: 1.00.0000 - )
Counter-Strike 1.6 (HKLM-x32\...\Counter-Strike 1.6) (Version:  - )
Counter-Strike 1.6 Non-Steam patch v36 (HKLM-x32\...\{6889EE56-1816-4E89-94DF-9F56E7804039}_is1) (Version:  - Portál soe.cz)
CyberLink Power Media Player 14 (HKLM-x32\...\{32C8E300-BDB4-4398-92C2-E9B7D8A233DB}) (Version: 14.0.6.7428 - CyberLink Corp.)
DolbyFiles (HKLM-x32\...\{b1adf008-e898-4fe2-8a1f-690d9a06acaf}) (Version: 2.0 - Nero AG) Hidden
Dropbox 25 GB (HKLM-x32\...\{84D8451D-2ED6-3A59-ABA5-2A447F7C6310}) (Version: 4.1.2.0 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.295.1 - Dropbox, Inc.) Hidden
EasyScreenOCR (HKLM-x32\...\{2CE0F5B1-13AA-4422-81CD-A70F848492B9}) (Version: 2.0.0 - EasyScreenOCR)
Energy Star (HKLM\...\{5CB22648-35F8-41BC-9C35-1E41FE6E12A5}) (Version: 1.1.1 - HP Inc.)
Epic Games Launcher (HKLM-x32\...\{C69A2919-0662-4390-9418-67C931B44C18}) (Version: 1.1.236.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
ESET Security (HKLM\...\{F1544F11-BFCC-43CC-9D0C-169A7E99369E}) (Version: 13.0.24.0 - ESET, spol. s r.o.)
EVEREST Ultimate Edition v5.50 (HKLM-x32\...\EVEREST Ultimate Edition_is1) (Version: 5.50 - Lavalys, Inc.)
Farming Simulator 17 (HKLM-x32\...\FarmingSimulator2017_is1) (Version: 1.0.0.0 - GIANTS Software)
Free FLAC to MP3 Converter 1.4 (HKLM-x32\...\{A54C01BD-1277-4722-B42B-EC9800A90B1E}_is1) (Version: 1.4 - PolySoft Solutions)
Free Sound Recorder v6.7 (HKLM-x32\...\Free Sound Recorder_is1) (Version:  - CoolRecordEdit Inc.)
GeoSetter 3.5.0 (HKLM-x32\...\GeoSetter_is1) (Version:  - Friedemann Schmidt)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 80.0.3987.149 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.441 - Google LLC) Hidden
GTA San Andreas (HKLM-x32\...\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}) (Version: 1.00.00001 - Rockstar Games)
HP Audio Switch (HKLM-x32\...\{3A5141D4-47DB-4302-9B1C-272BE585BC8A}) (Version: 1.0.179.0 - HP Inc.)
HP Connection Optimizer (HKLM-x32\...\{6468C4A5-E47E-405F-B675-A70A70983EA6}) (Version: 2.0.16.0 - HP Inc.)
HP Documentation (HKLM\...\HP_Documentation) (Version: 1.0.0.1 - HP Inc.)
HP ePrint SW (HKLM-x32\...\{54da9769-2364-4bd3-8139-6400500778b3}) (Version: 5.3.22034 - HP Inc.)
HP JumpStart Bridge (HKLM-x32\...\{EB0912FF-C311-4E0F-A6B1-420FDD3C295E}) (Version: 1.3.0.407 - HP Inc.)
HP JumpStart Launch (HKLM-x32\...\{81CA40FD-E11B-4DC1-AE33-A71EB044B8B7}) (Version: 1.1.275.0 - HP Inc.)
HP LaserJet Professional CP1020 Series (HKLM\...\HP LaserJet Professional CP1020 Series) (Version:  - )
HP PC Hardware Diagnostics Windows (HKLM-x32\...\{46F34D1E-F5BA-4A03-9706-A2D8809BA62A}) (Version: 1.6.1.0 - HP Inc.)
HP Support Solutions Framework (HKLM-x32\...\{83D9E6C0-5F20-49B4-9ACF-80A24A1A045D}) (Version: 12.14.49.15 - HP Inc.)
HP System Event Utility (HKLM-x32\...\{9DD60999-A4F0-4333-9D00-E45C718EA6C1}) (Version: 1.4.30 - HP Inc.)
HPLJUT (HKLM-x32\...\{229D6185-BD7E-494B-A73B-C5215BE0690E}) (Version: 1.00.0012 - HP) Hidden
hppcp1025LaserJetService (HKLM-x32\...\{F31BF057-0D5E-485E-ADFD-560314A27912}) (Version: 1.00.0000 - Hewlett-Packard)
hppLaserJetService (HKLM-x32\...\{5093AE98-D510-4BEB-BAC1-7FC8ECE35B98}) (Version: 007.015.00635 - Hewlett-Packard) Hidden
HWiNFO32 Version 4.02 (HKLM-x32\...\HWiNFO32_is1) (Version: 4.02 - Martin Malík - REALiX)
HWiNFO64 Version 4.02 (HKLM\...\HWiNFO64_is1) (Version: 4.02 - Martin Malík - REALiX)
iCloud (HKLM\...\{576BC8FA-1891-47C8-8A23-F3DDB78C06DE}) (Version: 7.15.0.10 - Apple Inc.)
IDM Patch 6.25 build 03 (HKLM-x32\...\IDM Patch 6.25 build 03) (Version: build 03 - SandySeedings Team)
ImagXpress (HKLM-x32\...\{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}) (Version: 7.0.74.0 - Nero AG) Hidden
Intel(R) Dynamic Platform and Thermal Framework (HKLM-x32\...\{654EE65D-FAA4-4EA6-8C07-DC94E6A304D4}) (Version: 8.4.11000.6436 - Intel Corporation)
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 1824.12.0.1140 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 25.20.100.6518 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 15.9.1.1020 - Intel Corporation)
Intel(R) Trusted Connect Service Client x86 (HKLM-x32\...\{C9552825-7BF2-4344-BA91-D3CD46F4C441}) (Version: 1.49.213.1 - Intel Corporation) Hidden
Intel(R) Trusted Connect Services Client (HKLM-x32\...\{3b132227-4567-48a1-9f85-0d0dad4346ee}) (Version: 1.49.213.1 - Intel Corporation) Hidden
Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{00002060-0200-1033-84C8-B8D95FA3C8C3}) (Version: 20.60.2 - Intel Corporation)
Intel® Chipset Device Software (HKLM-x32\...\{eb0d4a41-3065-42b0-a868-c60d42d3ea98}) (Version: 10.1.17695.8086 - Intel(R) Corporation) Hidden
Intel® PROSet/Wireless Software (HKLM-x32\...\{f8c930bd-0a68-425f-8c11-87723d1e2c97}) (Version: 20.90.0 - Intel Corporation)
Internet Download Manager (HKLM-x32\...\Internet Download Manager) (Version:  - Tonec Inc.)
IrfanView 4.50 (32-bit) (HKLM-x32\...\IrfanView) (Version: 4.50 - Irfan Skiljan)
Java 8 Update 241 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180241F0}) (Version: 8.0.2410.7 - Oracle Corporation)
jetAudio Basic (HKLM-x32\...\{DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A}) (Version: 8.1.0 - COWON)
KMSpico v9.1.3 (HKLM\...\KMSpico_is1) (Version: 9.1.3 - )
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version:  - )
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Microsoft Office 2013 Professional Plus (HKLM\...\Office15.PROPLUS) (Version: 15.0.4420.1017 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-215137528-2830479082-3927747001-1001\...\OneDriveSetup.exe) (Version: 19.232.1124.0008 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23506 (HKLM-x32\...\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}) (Version: 14.0.23506.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.16.27033 (HKLM-x32\...\{624ba875-fdfc-4efa-9c66-b170dfebc3ec}) (Version: 14.16.27033.0 - Microsoft Corporation)
Minecraft 1.12.2 + Titan Launcher 3.7.0 (HKLM-x32\...\Minecraft 1.12.2 + Titan Launcher 3.7.0 1.12.2) (Version: 1.12.2 - Mojang)
Movavi Video Editor 15 Plus (HKU\S-1-5-21-215137528-2830479082-3927747001-1001\...\Movavi Video Editor 15 Plus) (Version: 15.4.0 - Movavi)
Mozilla Firefox 70.0.1 (x64 sk) (HKLM\...\Mozilla Firefox 70.0.1 (x64 sk)) (Version: 70.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 61.0.1 - Mozilla)
Mozilla Thunderbird 68.6.0 (x86 sk) (HKLM-x32\...\Mozilla Thunderbird 68.6.0 (x86 sk)) (Version: 68.6.0 - Mozilla)
Nástroje kontroly pravopisu pro Microsoft Office 2013 – čeština (HKLM\...\{90150000-001F-0405-1000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Nástroje korektúry balíka Microsoft Office 2013 - slovenčina (HKLM\...\{90150000-001F-041B-1000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Nero 2014 (HKLM-x32\...\{F384C1E1-3A16-4073-95C3-7271FE0ED4C2}) (Version: 15.0.02200 - Nero AG)
Nero 9 (HKLM-x32\...\{65fb074d-cd04-451e-bdaf-bcb8f58fee4b}) (Version:  - Nero AG)
NetSpot (HKU\S-1-5-21-215137528-2830479082-3927747001-1001\...\3f5cc802c04add82) (Version: 2.12.715.0 - Etwok Inc.)
OBD Auto Doctor 3.6.2 (HKLM-x32\...\{18AF283C-D77C-43B3-8C1F-B78CB3818820}_is1) (Version:  - Creosys)
Podpora Apple aplikácií (32-bit) (HKLM-x32\...\{BED24701-751B-41C5-8888-A8EABAB9FE8C}) (Version: 8.1 - Apple Inc.)
Podpora Apple aplikácií(64-bit) (HKLM\...\{88F21C94-88AF-4665-AF4F-FECB1FA059B9}) (Version: 8.1 - Apple Inc.)
Prerequisite installer (HKLM-x32\...\{5909A89E-C97F-407C-AE2B-47BDED86BF5D}) (Version: 15.0.0005 - Nero AG) Hidden
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.17134.31243 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.28.615.2018 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8544 - Realtek Semiconductor Corp.)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.5.35.15 - Synaptics Incorporated)
VirtualCloneDrive (HKLM-x32\...\VirtualCloneDrive) (Version: 5.5.0.0 - Elaborate Bytes)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.8 - VideoLAN)
Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1) (Version: 1.0.54.1 - LunarG, Inc.) Hidden
Vypínač na dobrou noc verze 2.0 (HKLM-x32\...\Vypínač na dobrou noc_is1) (Version:  - )
WinRAR 5.50 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.50.0 - win.rar GmbH)
Wise Care 365 5.3.4 (HKLM-x32\...\Wise Care 365_is1) (Version: 5.3.4 - WiseCleaner.com, Inc.)
Wise Care 365 version 1.82 (HKLM-x32\...\{E864A1C8-EEE1-47D0-A7F8-00CC86D26D5E}_is1) (Version: 1.82 - WiseCleaner.com)
Wise Force Deleter 1.5.1 (HKLM-x32\...\Wise Force Deleter_is1) (Version: 1.5.1 - WiseCleaner.com, Inc.)
XnView 2.43 (HKLM-x32\...\XnView_is1) (Version: 2.43 - Gougelet Pierre-e)

Packages:
=========
AdBlock -> C:\Program Files\WindowsApps\BetaFish.AdBlock_2.13.0.0_neutral__c1wakc4j0nefm [2020-01-10] (BetaFish)
All Video Player HD -> C:\Program Files\WindowsApps\22450.TotalVideoPlayer_2.0.19.0_x64__0aqw1zw0x2snt [2020-01-27] (韵华软件) [MS Ad]
Asphalt 8: Airborne -> C:\Program Files\WindowsApps\GAMELOFTSA.Asphalt8Airborne_4.8.0.7_x86__0pp20fcewvvtj [2020-01-24] (GAMELOFT  SA)
Audacity - Audio Editor and Recorder -> C:\Program Files\WindowsApps\BluskySoftwareInc.17062EE08491F_2.0.5.0_x86__61yk12x6sxn40 [2020-02-28] (Blusky Software Inc.)
Autodesk SketchBook -> C:\Program Files\WindowsApps\89006A2E.AutodeskSketchBook_5.1.0.0_x64__tf1gferkr813w [2019-11-06] (Autodesk Inc.)
Car Scanner ELM OBD2 -> C:\Program Files\WindowsApps\405470vZ.CarScannerbeta_1.2.0.92_x64__jypadspxyf576 [2020-03-11] (0vZ) [MS Ad]
iTunes -> C:\Program Files\WindowsApps\AppleInc.iTunes_12104.2.43056.0_x64__nzyj5cx40ttqa [2020-01-30] (Apple Inc.) [Startup Task]
Kalkulačka One -> C:\Program Files\WindowsApps\IPTGroup.LuckyCalculatorFree_17.1.57.0_x64__fbja025meezca [2019-09-02] (IPT International Technologies Corporation.)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-09-02] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-09-02] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.5.12061.0_x64__8wekyb3d8bbwe [2019-12-12] (Microsoft Studios) [MS Ad]
MSN Počasie -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.36.20503.0_x64__8wekyb3d8bbwe [2020-03-07] (Microsoft Corporation) [MS Ad]
Photo Location Viewer -> C:\Program Files\WindowsApps\38731basquang.vn.PhotoLocationViewer_1.1.3.0_x64__pyvvk3yw15sng [2019-09-02] (basquang) [MS Ad]
Pictureflect Photo Viewer -> C:\Program Files\WindowsApps\31258Ben48.BasicPhotoViewer_2.8.3.0_x64__2c5bccghv4cc2 [2020-03-02] (Pictureflect)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-215137528-2830479082-3927747001-1001_Classes\CLSID\{a6250172-8709-4cf7-a9d7-e34cb47d5123}\InprocServer32 -> C:\WINDOWS\system32\dfshim.dll (Microsoft Windows -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-215137528-2830479082-3927747001-1001_Classes\CLSID\{C591CFEA-E432-495d-A0BE-58E4CCD87B17}\Shell\Open\Command -> C:\Program Files\Synaptics\SynTP\SynTPCpl.dll (Synaptics Incorporated -> Synaptics Incorporated)
CustomCLSID: HKU\S-1-5-21-215137528-2830479082-3927747001-1001_Classes\CLSID\{c9d1d116-0cdb-4d5f-a748-31adbe77f7cb}\InprocServer32 -> C:\WINDOWS\system32\dfshim.dll (Microsoft Windows -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [   IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2015-08-14] (Tonec Inc. -> Tonec Inc.)
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync64.dll [2019-12-22] (Google LLC -> Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync64.dll [2019-12-22] (Google LLC -> Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync64.dll [2019-12-22] (Google LLC -> Google)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} =>  -> No File
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} =>  -> No File
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
ContextMenuHandlers1-x32: [Cover Designer] -> {73FCA462-9BD5-4065-A73F-A8E5F6904EF7} => C:\Program Files (x86)\Nero\Nero 9\Nero CoverDesigner\CoverEdExtension.dll [2009-05-08] (Nero AG -> Nero AG)
ContextMenuHandlers1: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2019-12-16] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu64.dll [2019-12-22] (Google LLC -> Google)
ContextMenuHandlers1-x32: [GeoSetterShellExt] -> {7506374C-A693-427B-8DDD-99DAFB79433D} => C:\Program Files (x86)\GeoSetter\GeoSetterShellExt.dll [2018-05-10] (Friedemann Schmidt) [File not signed]
ContextMenuHandlers1: [GeoSetterShellExt64] -> {A50BD5C6-4B18-44F3-8D6D-62DE89A969E9} => C:\Program Files (x86)\GeoSetter\GeoSetterShellExt64.dll [2018-05-10] (Friedemann Schmidt) [File not signed]
ContextMenuHandlers1: [PhotoStreamsExt] -> {89D984B3-813B-406A-8298-118AFA3A22AE} => C:\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll [2019-10-25] (Apple Inc. -> Apple Inc.)
ContextMenuHandlers1: [VirtualCloneDrive] -> {B7056B8E-4F99-44f8-8CBD-282390FE5428} => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll [2009-12-14] (Elaborate Bytes AG -> Elaborate Bytes AG)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-08-11] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-08-11] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2019-12-16] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers2: [VirtualCloneDrive] -> {B7056B8E-4F99-44f8-8CBD-282390FE5428} => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll [2009-12-14] (Elaborate Bytes AG -> Elaborate Bytes AG)
ContextMenuHandlers3: [jetAudio] -> {8D1636FD-CA49-4B4E-90E4-0A20E03A15E8} => C:\Program Files (x86)\JetAudio\JetFlExt64.dll [2013-05-09] (JetAudio) [File not signed]
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} =>  -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} =>  -> No File
ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu64.dll [2019-12-22] (Google LLC -> Google)
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\ki131191.inf_amd64_d668106cb6f2eae0\igfxDTCM.dll [2019-02-25] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
ContextMenuHandlers6: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2019-12-16] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers6-x32: [GeoSetterShellExt] -> {7506374C-A693-427B-8DDD-99DAFB79433D} => C:\Program Files (x86)\GeoSetter\GeoSetterShellExt.dll [2018-05-10] (Friedemann Schmidt) [File not signed]
ContextMenuHandlers6: [GeoSetterShellExt64] -> {A50BD5C6-4B18-44F3-8D6D-62DE89A969E9} => C:\Program Files (x86)\GeoSetter\GeoSetterShellExt64.dll [2018-05-10] (Friedemann Schmidt) [File not signed]
ContextMenuHandlers6: [jetAudio] -> {8D1636FD-CA49-4B4E-90E4-0A20E03A15E8} => C:\Program Files (x86)\JetAudio\JetFlExt64.dll [2013-05-09] (JetAudio) [File not signed]
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-08-11] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-08-11] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

ShortcutWithArgument: C:\Users\rasti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikácie Chrome\Fun rádio.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=pmmlkpdhfkjphiiocdnlollpoebkemdk

==================== Loaded Modules (Whitelisted) =============

2020-02-15 18:56 - 2020-02-15 18:56 - 000138240 _____ ( ) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Interop.IWs06dcaa36#\803ddc517fb122da5941404364d527d7\Interop.IWshRuntimeLibrary.ni.dll
2018-11-12 11:19 - 2014-03-22 14:08 - 000252928 _____ () [File not signed] C:\Program Files (x86)\BatteryCare\OpenHardwareMonitorLib.dll
2020-02-15 18:53 - 2020-02-15 18:53 - 000160256 _____ () [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\BRIDGECommon\c2f73cde20f10d7edce8166566075b01\BRIDGECommon.ni.dll
2020-02-15 18:55 - 2020-02-15 18:55 - 000120832 _____ () [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\BridgeExtension\5a4420eed041a4ec02c86aa42f1f8e5f\BridgeExtension.ni.dll
2020-02-15 18:55 - 2020-02-15 18:55 - 000348160 _____ () [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\CleanStartController\57482daf2db5489771c501362f90b23f\CleanStartController.ni.dll
2018-11-12 11:19 - 2018-08-21 00:43 - 000065536 _____ (Filipe Lourenço) [File not signed] C:\Program Files (x86)\BatteryCare\cs-CZ\BatteryCare.resources.dll
2020-02-15 18:56 - 2020-02-15 18:56 - 000134656 _____ (hardcodet.net) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Hardcodet.W6cab32f3#\71e1b3de68bbf0e60ccc7503889c4fd8\Hardcodet.Wpf.TaskbarNotification.ni.dll
2009-09-16 18:44 - 2009-09-16 18:44 - 000153088 _____ (Hewlett Packard) [File not signed] C:\WINDOWS\System32\hptcpmib.dll
2009-09-16 18:45 - 2009-09-16 18:45 - 000331264 _____ (Hewlett Packard) [File not signed] C:\WINDOWS\System32\HpTcpMon.dll
2009-09-16 11:44 - 2009-09-16 11:44 - 000132096 _____ (Hewlett Packard) [File not signed] C:\WINDOWS\System32\hpzjrd01.dll
2011-01-21 08:46 - 2011-01-21 08:46 - 000040960 _____ (Hewlett-Packard Company) [File not signed] C:\Program Files (x86)\HP\HPLaserJetService\HPHTTPProxy.dll
2011-01-21 08:46 - 2011-01-21 08:46 - 000073728 _____ (Hewlett-Packard Company) [File not signed] C:\Program Files (x86)\HP\HPLaserJetService\HPTools.dll
2011-01-21 08:46 - 2011-01-21 08:46 - 001113600 _____ (Hewlett-Packard Company) [File not signed] C:\Program Files (x86)\HP\HPLaserJetService\LEDMXMLObjects.dll
2020-02-15 18:55 - 2020-02-15 18:55 - 000134656 _____ (HP Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\CommonPortable\273c304757c6019dfcd679260753bf6c\CommonPortable.ni.dll
2011-01-21 08:46 - 2011-01-21 08:46 - 000032768 _____ (HP) [File not signed] C:\Program Files (x86)\HP\HPLaserJetService\HPServiceCommunicator.dll
2020-02-15 18:56 - 2020-02-15 18:56 - 001701888 _____ (Mark Heath & Contributors) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\NAudio\9916d9afb7a4640017518813b2dcbbf4\NAudio.ni.dll
2009-09-16 18:45 - 2009-09-16 18:45 - 000317440 _____ (Microsoft Corporation) [File not signed] C:\WINDOWS\System32\HPTcpMUI.dll
2020-02-15 18:56 - 2020-02-15 18:56 - 003060736 _____ (Newtonsoft) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Newtonsoft.Json\7b0f325f64aa9777a67acba7d9ae5e03\Newtonsoft.Json.ni.dll
2018-11-12 11:19 - 2014-03-22 14:10 - 000057856 _____ (OpenLibSys.org) [File not signed] C:\Program Files (x86)\BatteryCare\WinRing0x64.dll
2020-02-15 18:56 - 2020-02-15 18:56 - 000793088 _____ (The Apache Software Foundation) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\log4net\bcb2909b52552fdb2ac2c83f49f28a34\log4net.ni.dll

==================== Alternate Data Streams (Whitelisted) ========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\Public\AppData:CSM [476]
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [478]

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

==================== Internet Explorer trusted/restricted ==========

(If an entry is included in the fixlist, it will be removed from the registry.)

IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com

There are 7943 more sites.

IE trusted site: HKU\S-1-5-21-215137528-2830479082-3927747001-1001\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-215137528-2830479082-3927747001-1001\...\webcompanion.com -> hxxp://webcompanion.com
IE restricted site: HKU\S-1-5-21-215137528-2830479082-3927747001-1001\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-215137528-2830479082-3927747001-1001\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-215137528-2830479082-3927747001-1001\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-215137528-2830479082-3927747001-1001\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-215137528-2830479082-3927747001-1001\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-215137528-2830479082-3927747001-1001\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-215137528-2830479082-3927747001-1001\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-215137528-2830479082-3927747001-1001\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-215137528-2830479082-3927747001-1001\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-215137528-2830479082-3927747001-1001\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-215137528-2830479082-3927747001-1001\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-215137528-2830479082-3927747001-1001\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-215137528-2830479082-3927747001-1001\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-215137528-2830479082-3927747001-1001\...\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-215137528-2830479082-3927747001-1001\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-215137528-2830479082-3927747001-1001\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-215137528-2830479082-3927747001-1001\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-215137528-2830479082-3927747001-1001\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-215137528-2830479082-3927747001-1001\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-215137528-2830479082-3927747001-1001\...\123simsen.com -> www.123simsen.com

There are 7943 more sites.


==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2017-03-18 22:03 - 2020-03-20 08:26 - 000000841 _____ C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1       localhost 

2017-12-10 18:36 - 2020-02-14 19:47 - 000000600 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics
92.168.137.1 LAPTOP-IHOK0OQJ.mshome.net # 2023 2 2 21 9 14 1 788
92.168.137.1 LAPTOP-IHOK0OQJ.mshome.net # 2023 2 2 21 9 14 1 788
12
4 1 7 32 42 126

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\iCLS\;C:\Program Files\Intel\Intel(R) Management Engine Components\iCLS\;C:\ProgramData\Oracle\Java\javapath;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL
HKU\S-1-5-21-215137528-2830479082-3927747001-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\rasti\Desktop\plocha\download.jfif
DNS Servers: 192.168.88.1 - 192.168.100.100
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\StartupFolder: => "update.bat"
HKLM\...\StartupApproved\Run32: => "HPMessageService"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\...\StartupApproved\Run32: => "seznam-listicka-distribuce"
HKU\S-1-5-21-215137528-2830479082-3927747001-1001\...\StartupApproved\Run: => "GoogleDriveSync"
HKU\S-1-5-21-215137528-2830479082-3927747001-1001\...\StartupApproved\Run: => "cz.seznam.software.autoupdate"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [TCP Query User{DD8FCEA9-F949-4951-A577-170924B75002}C:\program files (x86)\google\chrome\application\chrome.exe] => (Block) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [UDP Query User{2A54E821-0CF8-4028-9C60-13675CF89D7F}C:\program files (x86)\google\chrome\application\chrome.exe] => (Block) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{ADC03B11-E1BD-4832-BC84-62611516473B}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{D30F274A-2EB6-43BA-8CF8-16FAEE3B0421}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{90CDD136-2F46-4B65-B62B-5F02D421BBC7}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{E8F341C1-23D5-48C8-BDC1-8F0ECF0F7AF5}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12104.2.43056.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{14C489EA-13B3-40A4-A10D-0A5EC6FA4002}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12104.2.43056.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{B00C0852-E138-4563-BA76-0556F9E821AC}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12104.2.43056.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{F16D0AE1-7813-4248-A8BC-1CA0527E29FC}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12104.2.43056.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{498495A7-B811-4EFE-B865-257301457F22}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12104.2.43056.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{9FCE81AB-ECAA-4F70-8522-8AD33BF6FB84}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12104.2.43056.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{F861429D-8867-441A-93AC-078BA475B6C2}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12104.2.43056.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{24A3BE81-BC4F-44A9-8A77-7FE69240AF5E}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12104.2.43056.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{B1572677-E749-4FD5-8178-6E7BB2B21F54}] => (Allow) C:\Program Files (x86)\Farming Simulator 2017\FarmingSimulator2017.exe (GIANTS Software GmbH -> GIANTS Software GmbH)
FirewallRules: [{6FFE7DCD-E44A-49AF-A561-F0E50A754CBB}] => (Allow) C:\Program Files (x86)\Farming Simulator 2017\FarmingSimulator2017.exe (GIANTS Software GmbH -> GIANTS Software GmbH)
FirewallRules: [{82D0C780-2B94-43B2-BA83-9C2B306B5816}] => (Allow) C:\Program Files (x86)\Farming Simulator 2017\x86\FarmingSimulator2017Game.exe (GIANTS Software GmbH -> GIANTS Software GmbH)
FirewallRules: [{24383825-0310-4DC7-AABF-0C01A5B8D091}] => (Allow) C:\Program Files (x86)\Farming Simulator 2017\x86\FarmingSimulator2017Game.exe (GIANTS Software GmbH -> GIANTS Software GmbH)
FirewallRules: [{1F490BA4-1484-4A09-99B9-2CBB0E8C3B2F}] => (Allow) C:\Program Files (x86)\Farming Simulator 2017\x64\FarmingSimulator2017Game.exe (GIANTS Software GmbH -> GIANTS Software GmbH)
FirewallRules: [{31150F0B-4036-4294-97B7-C5446AE3994D}] => (Allow) C:\Program Files (x86)\Farming Simulator 2017\x64\FarmingSimulator2017Game.exe (GIANTS Software GmbH -> GIANTS Software GmbH)
FirewallRules: [TCP Query User{B96B7257-56E1-4464-89BF-F25C0F28D79B}C:\program files (x86)\counter-strike 1.6\hl.exe] => (Allow) C:\program files (x86)\counter-strike 1.6\hl.exe (Valve) [File not signed]
FirewallRules: [UDP Query User{AD851D3C-06B0-45B0-8D6C-670AAC5CF1B0}C:\program files (x86)\counter-strike 1.6\hl.exe] => (Allow) C:\program files (x86)\counter-strike 1.6\hl.exe (Valve) [File not signed]
FirewallRules: [TCP Query User{05A79B6F-56DF-469C-9859-79171FF476B1}C:\program files (x86)\java\jre1.8.0_241\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre1.8.0_241\bin\javaw.exe
FirewallRules: [UDP Query User{0BCC078D-2766-49E9-8E9D-A1B9B20FC01A}C:\program files (x86)\java\jre1.8.0_241\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre1.8.0_241\bin\javaw.exe
FirewallRules: [{39D7BA4D-3A76-4C92-9F43-1C5CE9B31C77}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)

==================== Restore Points =========================

17-03-2020 21:44:45 AA11
20-03-2020 08:25:04 zoek.exe restore point
20-03-2020 08:27:34 JRT Pre-Junkware Removal
20-03-2020 09:08:02 Removed TouchScan

==================== Faulty Device Manager Devices ============

Name: Microsoft Wi-Fi Direct Virtual Adapter #2
Description: Microsoft Wi-Fi Direct Virtual Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: vwifimp
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: ========================

Application errors:
==================
Error: (03/20/2020 09:40:05 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybujúcej aplikácie: backgroundTaskHost.exe, verzia: 10.0.17763.1, časová značka: 0x6fe3727f
Názov chybujúceho modulu: twinapi.appcore.dll, verzia: 10.0.17763.1075, časová značka: 0x4a83aa8c
Kód výnimky: 0xc0000409
Odstup chyby: 0x0000000000095cc7
Identifikácia chybujúceho procesu: 0x6e8
Čas spustenia chybujúcej aplikácie: 0x01d5fe93274a0ca8
Cesta chybujúcej aplikácie: C:\WINDOWS\system32\backgroundTaskHost.exe
Cesta chybujúceho modulu: C:\Windows\System32\twinapi.appcore.dll
Identifikácia hlásenia: d9b64761-de53-4e5f-8d6d-5a0a91b7eb0e
Celé meno chybujúceho balíka: Microsoft.Windows.Cortana_1.11.6.17763_neutral_neutral_cw5n1h2txyewy
Identifikácia chybujúcej aplikácie vzhľadom na balík: CortanaUI

Error: (03/20/2020 09:39:48 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybujúcej aplikácie: SearchUI.exe, verzia: 10.0.17763.1075, časová značka: 0x5e4f64b8
Názov chybujúceho modulu: twinapi.appcore.dll, verzia: 10.0.17763.1075, časová značka: 0x4a83aa8c
Kód výnimky: 0xc0000409
Odstup chyby: 0x0000000000095cc7
Identifikácia chybujúceho procesu: 0x15e0
Čas spustenia chybujúcej aplikácie: 0x01d5fe931d349b3b
Cesta chybujúcej aplikácie: C:\WINDOWS\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
Cesta chybujúceho modulu: C:\Windows\System32\twinapi.appcore.dll
Identifikácia hlásenia: b9f38a2f-56a0-4dc7-be85-bb5998ed5e54
Celé meno chybujúceho balíka: Microsoft.Windows.Cortana_1.11.6.17763_neutral_neutral_cw5n1h2txyewy
Identifikácia chybujúcej aplikácie vzhľadom na balík: CortanaUI

Error: (03/20/2020 09:38:26 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybujúcej aplikácie: SearchUI.exe, verzia: 10.0.17763.1075, časová značka: 0x5e4f64b8
Názov chybujúceho modulu: twinapi.appcore.dll, verzia: 10.0.17763.1075, časová značka: 0x4a83aa8c
Kód výnimky: 0xc0000409
Odstup chyby: 0x0000000000095cc7
Identifikácia chybujúceho procesu: 0x253c
Čas spustenia chybujúcej aplikácie: 0x01d5fe92ec9efa8b
Cesta chybujúcej aplikácie: C:\WINDOWS\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
Cesta chybujúceho modulu: C:\Windows\System32\twinapi.appcore.dll
Identifikácia hlásenia: ff88b263-f464-4d9e-b3a9-b6093b4a8c93
Celé meno chybujúceho balíka: Microsoft.Windows.Cortana_1.11.6.17763_neutral_neutral_cw5n1h2txyewy
Identifikácia chybujúcej aplikácie vzhľadom na balík: CortanaUI

Error: (03/20/2020 09:38:24 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybujúcej aplikácie: ShellExperienceHost.exe, verzia: 10.0.17763.1075, časová značka: 0x5e4f9944
Názov chybujúceho modulu: twinapi.appcore.dll, verzia: 10.0.17763.1075, časová značka: 0x4a83aa8c
Kód výnimky: 0xc0000409
Odstup chyby: 0x0000000000095cc7
Identifikácia chybujúceho procesu: 0x1188
Čas spustenia chybujúcej aplikácie: 0x01d5fe92eb8a2386
Cesta chybujúcej aplikácie: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
Cesta chybujúceho modulu: C:\Windows\System32\twinapi.appcore.dll
Identifikácia hlásenia: 96b6f61a-26c5-4765-9a07-5b483ddf5c74
Celé meno chybujúceho balíka: Microsoft.Windows.ShellExperienceHost_10.0.17763.1_neutral_neutral_cw5n1h2txyewy
Identifikácia chybujúcej aplikácie vzhľadom na balík: App

Error: (03/20/2020 09:32:53 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybujúcej aplikácie: HxTsr.exe, verzia: 16.0.12624.20212, časová značka: 0x5e69428c
Názov chybujúceho modulu: twinapi.appcore.dll, verzia: 10.0.17763.1075, časová značka: 0x4a83aa8c
Kód výnimky: 0xc0000409
Odstup chyby: 0x0000000000095cc7
Identifikácia chybujúceho procesu: 0x21b4
Čas spustenia chybujúcej aplikácie: 0x01d5fe9226225cca
Cesta chybujúcej aplikácie: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.12624.20212.0_x64__8wekyb3d8bbwe\HxTsr.exe
Cesta chybujúceho modulu: C:\WINDOWS\SYSTEM32\twinapi.appcore.dll
Identifikácia hlásenia: 15006624-f2c1-4916-8946-f87267499ca4
Celé meno chybujúceho balíka: microsoft.windowscommunicationsapps_16005.12624.20212.0_x64__8wekyb3d8bbwe
Identifikácia chybujúcej aplikácie vzhľadom na balík: ppleae38af2e007f4358a809ac99a64a67c1

Error: (03/20/2020 09:32:53 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybujúcej aplikácie: backgroundTaskHost.exe, verzia: 10.0.17763.1, časová značka: 0x6fe3727f
Názov chybujúceho modulu: twinapi.appcore.dll, verzia: 10.0.17763.1075, časová značka: 0x4a83aa8c
Kód výnimky: 0xc0000409
Odstup chyby: 0x0000000000095cc7
Identifikácia chybujúceho procesu: 0x1d98
Čas spustenia chybujúcej aplikácie: 0x01d5fe9226285ec8
Cesta chybujúcej aplikácie: C:\WINDOWS\system32\backgroundTaskHost.exe
Cesta chybujúceho modulu: C:\Windows\System32\twinapi.appcore.dll
Identifikácia hlásenia: e1c89c5f-6464-4a3a-a244-40ed22f8e368
Celé meno chybujúceho balíka: Microsoft.WindowsStore_12003.1001.1.0_x64__8wekyb3d8bbwe
Identifikácia chybujúcej aplikácie vzhľadom na balík: App

Error: (03/20/2020 09:32:53 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybujúcej aplikácie: backgroundTaskHost.exe, verzia: 10.0.17763.1, časová značka: 0x6fe3727f
Názov chybujúceho modulu: twinapi.appcore.dll, verzia: 10.0.17763.1075, časová značka: 0x4a83aa8c
Kód výnimky: 0xc0000409
Odstup chyby: 0x0000000000095cc7
Identifikácia chybujúceho procesu: 0x25ec
Čas spustenia chybujúcej aplikácie: 0x01d5fe9226226449
Cesta chybujúcej aplikácie: C:\WINDOWS\system32\backgroundTaskHost.exe
Cesta chybujúceho modulu: C:\Windows\System32\twinapi.appcore.dll
Identifikácia hlásenia: be309ab1-aab4-43f5-8350-98263232b3e6
Celé meno chybujúceho balíka: Microsoft.Windows.Cortana_1.11.6.17763_neutral_neutral_cw5n1h2txyewy
Identifikácia chybujúcej aplikácie vzhľadom na balík: CortanaUI

Error: (03/20/2020 09:32:05 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybujúcej aplikácie: backgroundTaskHost.exe, verzia: 10.0.17763.1, časová značka: 0x6fe3727f
Názov chybujúceho modulu: twinapi.appcore.dll, verzia: 10.0.17763.1075, časová značka: 0x4a83aa8c
Kód výnimky: 0xc0000409
Odstup chyby: 0x0000000000095cc7
Identifikácia chybujúceho procesu: 0x558
Čas spustenia chybujúcej aplikácie: 0x01d5fe92091afa31
Cesta chybujúcej aplikácie: C:\WINDOWS\system32\backgroundTaskHost.exe
Cesta chybujúceho modulu: C:\Windows\System32\twinapi.appcore.dll
Identifikácia hlásenia: ad7a627f-420f-4c8b-9beb-3ad1a762d810
Celé meno chybujúceho balíka: Microsoft.OneConnect_5.2002.431.0_x64__8wekyb3d8bbwe
Identifikácia chybujúcej aplikácie vzhľadom na balík: App


System errors:
=============
Error: (03/20/2020 09:40:06 AM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-IHOK0OQJ)
Description: The server Microsoft.Windows.Cortana_1.11.6.17763_neutral_neutral_cw5n1h2txyewy!CortanaUI.AppXjytc7c0yvwb8n3cw0r82k4364sd1s7bv.mca did not register with DCOM within the required timeout.

Error: (03/20/2020 09:39:49 AM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-IHOK0OQJ)
Description: The server Microsoft.Windows.Cortana_1.11.6.17763_neutral_neutral_cw5n1h2txyewy!CortanaUI did not register with DCOM within the required timeout.

Error: (03/20/2020 09:38:27 AM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-IHOK0OQJ)
Description: The server Microsoft.Windows.Cortana_1.11.6.17763_neutral_neutral_cw5n1h2txyewy!CortanaUI did not register with DCOM within the required timeout.

Error: (03/20/2020 09:38:26 AM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-IHOK0OQJ)
Description: The server Microsoft.Windows.ShellExperienceHost_10.0.17763.1_neutral_neutral_cw5n1h2txyewy!App did not register with DCOM within the required timeout.

Error: (03/20/2020 09:32:58 AM) (Source: DCOM) (EventID: 10001) (User: LAPTOP-IHOK0OQJ)
Description: Unable to start a DCOM Server: Microsoft.WindowsStore_12003.1001.1.0_x64__8wekyb3d8bbwe!App.AppX65azfy60a5wn91mcvdd3dr2y0wj02n39.mca as Unavailable/Unavailable. The error:
"0"
Happened while starting this command:
"C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:App.AppXe9cvj1thv1hmcw0cs98xm3r97tyzy2xs.mca

Error: (03/20/2020 09:32:58 AM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-IHOK0OQJ)
Description: The server Microsoft.WindowsStore_12003.1001.1.0_x64__8wekyb3d8bbwe!App.AppX8h0bdkbb5frkt9s09fvshhbvqnntmvm1.mca did not register with DCOM within the required timeout.

Error: (03/20/2020 09:32:55 AM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-IHOK0OQJ)
Description: The server microsoft.windowscommunicationsapps_16005.12624.20212.0_x64__8wekyb3d8bbwe!microsoft.windowslive.calendar.AppXwkn9j84yh1kvnt49k5r8h6y1ecsv09hs.mca did not register with DCOM within the required timeout.

Error: (03/20/2020 09:32:54 AM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-IHOK0OQJ)
Description: The server Microsoft.Windows.Cortana_1.11.6.17763_neutral_neutral_cw5n1h2txyewy!CortanaUI.AppXjytc7c0yvwb8n3cw0r82k4364sd1s7bv.mca did not register with DCOM within the required timeout.


Windows Defender:
===================================
Date: 2020-03-12 18:56:59.127
Description: 
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {0BCE3A13-A806-44DA-9F43-E04B956C211A}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2020-03-12 18:56:32.292
Description: 
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {6B524923-550E-45F9-A0BD-FEAAC60CF187}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2020-03-12 18:53:42.615
Description: 
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {48D7860F-1F77-4322-9AC0-1BB222E1CD62}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2020-03-12 13:41:48.297
Description: 
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {6C1747D8-C9EA-47EE-8A35-50EC270EC5FA}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2020-03-12 12:26:53.979
Description: 
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {96AFCFFA-9E55-43A6-ADDA-6E80D41471BB}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2020-03-20 08:46:52.698
Description: 
Windows Defender Antivirus Real-Time Protection feature has encountered an error and failed.
Feature: Behavior Monitoring
Error Code: 0x80508023
Error description: Programu sa v tomto zariadení nepodarilo nájsť malvér ani ďalší potenciálne nežiaduci softvér. 
Reason: Antimalware protection has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.

Date: 2020-03-11 17:43:20.653
Description: 
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version: 
Previous Signature Version: 1.311.918.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.16800.2
Error code: 0x80240438
Error description: Počas vyhľadávania aktualizácií sa vyskytol neočakávaný problém. Informácie o inštalácii aktualizácií a riešení problémov s aktualizáciami nájdete v Pomoci a technickej podpore. 

Date: 2020-03-05 21:22:40.729
Description: 
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version: 
Previous Signature Version: 1.311.519.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.16800.2
Error code: 0x8024402c
Error description: Počas vyhľadávania aktualizácií sa vyskytol neočakávaný problém. Informácie o inštalácii aktualizácií a riešení problémov s aktualizáciami nájdete v Pomoci a technickej podpore. 

CodeIntegrity:
===================================

Date: 2020-03-20 09:27:57.054
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\ESET\ESET Security\ecmds.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-03-20 09:27:57.046
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\ESET\ESET Security\ecmds.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-03-20 09:27:57.031
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\ESET\ESET Security\ecmds.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-03-20 09:27:57.023
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\ESET\ESET Security\ecmds.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-03-20 09:27:57.009
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\ESET\ESET Security\ecmds.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-03-20 09:27:57.002
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\ESET\ESET Security\ecmds.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-03-20 09:27:48.915
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\ESET\ESET Security\ecmds.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-03-20 09:27:48.865
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\ESET\ESET Security\ecmds.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

==================== Memory info =========================== 

BIOS: Insyde F.52 03/04/2019
Motherboard: HP 8328
Processor: Intel(R) Core(TM) i3-6006U CPU @ 2.00GHz
Percentage of memory in use: 84%
Total physical RAM: 4012.91 MB
Available physical RAM: 610.94 MB
Total Virtual: 5996.91 MB
Available Virtual: 2709.03 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:222.85 GB) (Free:54.42 GB) NTFS
Drive d: (RECOVERY) (Fixed) (Total:14.39 GB) (Free:1.48 GB) NTFS ==>[system with boot components (obtained from drive)]

\\?\Volume{99b8501c-deb1-48f7-abb0-868a338efbc8}\ () (Fixed) (Total:0 GB) (Free:0 GB) 
\\?\Volume{b8d0ae99-0d58-4a9c-be66-0d0a54ec64d4}\ () (Fixed) (Total:0.25 GB) (Free:0.17 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Size: 238.5 GB) (Disk ID: 4DDC17A4)

Partition: GPT.

==================== End of Addition.txt =======================