Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-03-2020
Ran by jsem (05-04-2020 10:53:34)
Running from D:\Stažené soubory
Windows 10 Pro Version 1909 18363.720 (X64) (2019-12-28 15:43:00)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1480136373-461117007-2887068974-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1480136373-461117007-2887068974-503 - Limited - Disabled)
Guest (S-1-5-21-1480136373-461117007-2887068974-501 - Limited - Disabled)
jsem (S-1-5-21-1480136373-461117007-2887068974-1001 - Administrator - Enabled) => C:\Users\jsem
WDAGUtilityAccount (S-1-5-21-1480136373-461117007-2887068974-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

2HCS Fakturace v. 4.2019.67 (HKLM-x32\...\2HCS Fakturace 4_is1) (Version:  - 2H C.S. s.r.o.)
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 20.006.20042 - Adobe Systems Incorporated)
Adobe Photoshop CC 2019 (HKLM-x32\...\PHSP_20_0_4) (Version: 20.0.4 - Adobe Systems Incorporated)
Arduino (HKLM-x32\...\Arduino) (Version: 1.8.10 - Arduino LLC)
balenaEtcher 1.5.70 (HKU\S-1-5-21-1480136373-461117007-2887068974-1001\...\{d2f3b6c7-6f49-59e2-b8a5-f72e33900c2b}) (Version: 1.5.70 - Balena Inc.)
Balíček ovladače systému Windows - SIGMA Elektro GmbH (usbser) Ports  (02/20/2017 1.7.0000.0000) (HKLM\...\F11095F081576CA0F709F279E5FC84AC50628B78) (Version: 02/20/2017 1.7.0000.0000 - SIGMA Elektro GmbH)
Barvy 4.1 (HKLM\...\Barvy_is1) (Version:  - Vlastimil Burian)
BS.Player FREE (HKLM-x32\...\BSPlayerf) (Version: 2.74.1085 - AB Team, d.o.o.)
Canon MX350 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX350_series) (Version:  - )
eM Client (HKLM-x32\...\{5D8FE139-3B35-4F39-A0BE-47B68A30BC4E}) (Version: 7.2.37929.0 - eM Client Inc.)
f.lux (HKU\S-1-5-21-1480136373-461117007-2887068974-1001\...\Flux) (Version:  - f.lux Software LLC)
File Splitter and Joiner version 2.0.0.0 (HKLM-x32\...\{F571CFA1-1B85-4416-8FE1-318E04C7718D}_is1) (Version: 2.0.0.0 - 3nity Softwares)
FileZilla Client 3.47.2.1 (HKLM-x32\...\FileZilla Client) (Version: 3.47.2.1 - Tim Kosse)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 80.0.3987.149 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
Microsoft Office Professional Plus 2016 - cs-cz (HKLM\...\ProPlusRetail - cs-cz) (Version: 16.0.12527.20278 - Microsoft Corporation)
Microsoft OneDrive (HKLM-x32\...\OneDriveSetup.exe) (Version: 19.232.1124.0010 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.15.26706 (HKLM-x32\...\{95ac1cfa-f4fb-4d1b-8912-7f9d5fbb140d}) (Version: 14.15.26706.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (HKLM-x32\...\{7e9fae12-5bbf-47fb-b944-09c49e75c061}) (Version: 14.15.26706.0 - Microsoft Corporation)
Microsoft Visual Studio Code (User) (HKU\S-1-5-21-1480136373-461117007-2887068974-1001\...\{771FD6B0-FA20-440A-A002-3B3BAC16DC50}_is1) (Version: 1.43.2 - Microsoft Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.12527.20278 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.12527.20242 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0405-1000-0000000FF1CE}) (Version: 16.0.12527.20278 - Microsoft Corporation) Hidden
PSPad editor (HKLM-x32\...\PSPad editor_is1) (Version: 5.0.3.377 - Jan Fiala)
REALTEK Bluetooth Driver (HKLM-x32\...\{9D3D8C60-A5EF-4123-B2B9-172095903AB}) (Version: 1015.1016.1016.191212 - REALTEK Semiconductor Corp.)
SD Card Formatter (HKLM-x32\...\{A61131DC-B92D-4AD8-A925-E2D6D5FE217C}) (Version: 5.0.1 - SD Association)
Sigma Data Center 5.7 (HKLM-x32\...\Sigma Data Center5.7) (Version: 5.7 - Sigma Elektro GmbH)
Synology Drive Client (remove only) (HKLM\...\Synology Drive) (Version: 6.0.1.11061 - Synology, Inc.)
WinRAR 5.71 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.71.0 - win.rar GmbH)
Zoner Photo Studio 15 (HKLM\...\ZonerPhotoStudio15_CZ_is1) (Version: 15.0.1.8 - ZONER software)

Packages:
=========
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-12-29] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-12-29] (Microsoft Corporation) [MS Ad]
PLAY.CZ -> C:\Program Files\WindowsApps\PLAY.CZ.PLAY.CZ_1.2.0.5_x64__c4wb35dqfnwq0 [2020-03-26] (PLAY.CZ)
Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.129.592.0_x86__zpdnekdrzrea0 [2020-04-03] (Spotify AB) [Startup Task]

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1480136373-461117007-2887068974-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\jsem\AppData\Local\Microsoft\OneDrive\19.232.1124.0010\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-1480136373-461117007-2887068974-1001_Classes\CLSID\{2C4A5D61-009C-4561-9A33-6AFD542FD237}\InprocServer32 -> C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\icon-overlay\22\x64\ContextMenu.dll () [File not signed]
CustomCLSID: HKU\S-1-5-21-1480136373-461117007-2887068974-1001_Classes\CLSID\{472CE1AD-5D53-4BCF-A1FB-3982A5F55138}\InprocServer32 -> C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\icon-overlay\22\x64\iconOverlay.dll (TODO: <Company name>) [File not signed]
CustomCLSID: HKU\S-1-5-21-1480136373-461117007-2887068974-1001_Classes\CLSID\{48AB5ADA-36B1-4137-99C9-2BD97F8788AB}\InprocServer32 -> C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\icon-overlay\22\x64\iconOverlay.dll (TODO: <Company name>) [File not signed]
CustomCLSID: HKU\S-1-5-21-1480136373-461117007-2887068974-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\jsem\AppData\Local\Microsoft\OneDrive\19.232.1124.0010\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-1480136373-461117007-2887068974-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\jsem\AppData\Local\Microsoft\OneDrive\19.232.1124.0010\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-1480136373-461117007-2887068974-1001_Classes\CLSID\{A433C3E0-8B24-40EB-93C3-4B10D9959F58}\InprocServer32 -> C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\icon-overlay\22\x64\iconOverlay.dll (TODO: <Company name>) [File not signed]
CustomCLSID: HKU\S-1-5-21-1480136373-461117007-2887068974-1001_Classes\CLSID\{AEB16659-2125-4ADA-A4AB-45EE21E86469}\InprocServer32 -> C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\icon-overlay\22\x64\iconOverlay.dll (TODO: <Company name>) [File not signed]
CustomCLSID: HKU\S-1-5-21-1480136373-461117007-2887068974-1001_Classes\CLSID\{C701AD67-3DF0-47C9-89CB-DFA6207BE229}\InprocServer32 -> C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\icon-overlay\22\x64\iconOverlay.dll (TODO: <Company name>) [File not signed]
CustomCLSID: HKU\S-1-5-21-1480136373-461117007-2887068974-1001_Classes\CLSID\{ED90173A-3B4C-4E7E-B9CF-79714425D4B5}\InprocServer32 -> C:\Program Files (x86)\PSPad editor\pspshellx64.dll () [File not signed]
ShellIconOverlayIdentifiers: [    OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0010\amd64\FileSyncShell64.dll [2020-04-03] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [    OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0010\amd64\FileSyncShell64.dll [2020-04-03] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [    OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0010\amd64\FileSyncShell64.dll [2020-04-03] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [    OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0010\amd64\FileSyncShell64.dll [2020-04-03] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [    OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0010\amd64\FileSyncShell64.dll [2020-04-03] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [    OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0010\amd64\FileSyncShell64.dll [2020-04-03] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [    OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0010\amd64\FileSyncShell64.dll [2020-04-03] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [   01UnsuppModule] -> {AEB16659-2125-4ADA-A4AB-45EE21E86469} => C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\icon-overlay\22\x64\iconOverlay.dll [2020-03-11] (TODO: <Company name>) [File not signed]
ShellIconOverlayIdentifiers: [   02SyncingModule] -> {48AB5ADA-36B1-4137-99C9-2BD97F8788AB} => C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\icon-overlay\22\x64\iconOverlay.dll [2020-03-11] (TODO: <Company name>) [File not signed]
ShellIconOverlayIdentifiers: [   03SyncedModule] -> {472CE1AD-5D53-4BCF-A1FB-3982A5F55138} => C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\icon-overlay\22\x64\iconOverlay.dll [2020-03-11] (TODO: <Company name>) [File not signed]
ShellIconOverlayIdentifiers: [   04ReadOnlyModule] -> {A433C3E0-8B24-40EB-93C3-4B10D9959F58} => C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\icon-overlay\22\x64\iconOverlay.dll [2020-03-11] (TODO: <Company name>) [File not signed]
ShellIconOverlayIdentifiers: [   05NoPermModule] -> {C701AD67-3DF0-47C9-89CB-DFA6207BE229} => C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\icon-overlay\22\x64\iconOverlay.dll [2020-03-11] (TODO: <Company name>) [File not signed]
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0010\amd64\FileSyncShell64.dll [2020-04-03] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0010\amd64\FileSyncShell64.dll [2020-04-03] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0010\amd64\FileSyncShell64.dll [2020-04-03] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0010\amd64\FileSyncShell64.dll [2020-04-03] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0010\amd64\FileSyncShell64.dll [2020-04-03] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0010\amd64\FileSyncShell64.dll [2020-04-03] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0010\amd64\FileSyncShell64.dll [2020-04-03] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0010\amd64\FileSyncShell64.dll [2020-04-03] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0010\amd64\FileSyncShell64.dll [2020-04-03] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0010\amd64\FileSyncShell64.dll [2020-04-03] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2017-03-09] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1_S-1-5-21-1480136373-461117007-2887068974-1001: [CloudStation.SyncFolderContextMenu] -> {2C4A5D61-009C-4561-9A33-6AFD542FD237} => C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\icon-overlay\22\x64\ContextMenu.dll [2020-03-11] () [File not signed]
ContextMenuHandlers1_S-1-5-21-1480136373-461117007-2887068974-1001: [EditWithPSPad] -> {ED90173A-3B4C-4E7E-B9CF-79714425D4B5} => C:\Program Files (x86)\PSPad editor\pspshellx64.dll [2014-11-02] () [File not signed]
ContextMenuHandlers6_S-1-5-21-1480136373-461117007-2887068974-1001: [CloudStation.SyncFolderContextMenu] -> {2C4A5D61-009C-4561-9A33-6AFD542FD237} => C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\icon-overlay\22\x64\ContextMenu.dll [2020-03-11] () [File not signed]

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

ShortcutWithArgument: C:\Users\jsem\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\d249d9ddd424b688\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default

==================== Loaded Modules (Whitelisted) =============

2019-10-11 13:41 - 2019-10-11 13:41 - 093837312 _____ () [File not signed] C:\Program Files (x86)\eM Client\libcef\libcef.dll
2019-12-28 18:06 - 2014-11-02 19:45 - 000029184 _____ () [File not signed] C:\Program Files (x86)\PSPad editor\pspshellx64.dll
2020-03-11 19:21 - 2020-03-11 19:21 - 000345600 _____ () [File not signed] C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\bin\fct-qt.dll
2020-03-11 19:21 - 2020-03-11 19:21 - 021790171 _____ () [File not signed] C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\bin\icudt53.dll
2020-03-11 19:21 - 2020-03-11 19:21 - 003506395 _____ () [File not signed] C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\bin\icuin53.dll
2020-03-11 19:21 - 2020-03-11 19:21 - 002223218 _____ () [File not signed] C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\bin\icuuc53.dll
2020-03-11 19:21 - 2020-03-11 19:21 - 000033280 _____ () [File not signed] C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\bin\imageformats\qgif.dll
2020-03-11 19:21 - 2020-03-11 19:21 - 000043008 _____ () [File not signed] C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\bin\imageformats\qicns.dll
2020-03-11 19:21 - 2020-03-11 19:21 - 000032768 _____ () [File not signed] C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\bin\imageformats\qico.dll
2020-03-11 19:21 - 2020-03-11 19:21 - 000507904 _____ () [File not signed] C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\bin\imageformats\qjp2.dll
2020-03-11 19:21 - 2020-03-11 19:21 - 000239104 _____ () [File not signed] C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\bin\imageformats\qjpeg.dll
2020-03-11 19:21 - 2020-03-11 19:21 - 000430080 _____ () [File not signed] C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\bin\imageformats\qtiff.dll
2020-03-11 19:21 - 2020-03-11 19:21 - 000834555 _____ () [File not signed] C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\bin\libcurl-4.dll
2020-03-11 19:21 - 2020-03-11 19:21 - 000121524 _____ () [File not signed] C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\bin\libgcc_s_dw2-1.dll
2020-03-11 19:21 - 2020-03-11 19:21 - 003331103 _____ () [File not signed] C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\bin\libsqlite3-0.dll
2020-03-11 19:21 - 2020-03-11 19:21 - 001547595 _____ () [File not signed] C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\bin\libstdc++-6.dll
2020-03-11 19:21 - 2020-03-11 19:21 - 000691712 _____ () [File not signed] C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\bin\platforms\qwindows.dll
2020-03-11 19:21 - 2020-03-11 19:21 - 000156160 _____ () [File not signed] C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\bin\WinCFWrapper.dll
2020-03-11 19:21 - 2020-03-11 19:21 - 000124430 _____ () [File not signed] C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\bin\zlib1.dll
2020-03-11 19:21 - 2020-03-11 19:21 - 001367552 _____ () [File not signed] C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\icon-overlay\22\x64\ContextMenu.dll
2020-03-11 19:21 - 2020-03-11 19:21 - 000198144 _____ () [File not signed] C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\icon-overlay\22\x64\WinCFWrapper.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 001072128 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\HTMLEditorControl\62b65fbcced855db4e793bfd3688544c\HTMLEditorControl.ni.dll
2020-03-16 14:50 - 2020-03-16 14:50 - 000588288 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\LinqBridge\7668bbb8cf7dbf808135568c8da593bf\LinqBridge.ni.dll
2020-03-16 14:50 - 2020-03-16 14:50 - 000167424 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.1d52ed9e#\664eed3f48c2f876e52b0163e1c2706e\MailClient.Collections.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000664576 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.1fd7a4e5#\db3fdd47ea6b16e5363ae72b599eeb3b\MailClient.Storage.Mail.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000030720 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.1fe73d22#\e05b3d7d09274e94f667f05bc2c4b523\MailClient.Storage.Rule.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000036864 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.319ca19c#\d36d2175430036b4a3cc3dbb06a53470\MailClient.Storage.Template.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000075264 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.348c65cc#\a374f2bff4e84f3e4d147c2b778cd0ed\MailClient.Protocols.Pop3.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000088064 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.348e0a4a#\f14ca01221a551f0a747fde73631fe73\MailClient.Protocols.Smtp.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 001004544 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.3497b425#\f534015c237b5da450433a3042323efd\MailClient.Protocols.Imap.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000031744 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.4824fbfc#\ac10f521671c130082677eb705304685\MailClient.Storage.Category.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000162304 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.4e7296db#\19603f6dd60e1b4247b044f1c499cfe3\MailClient.Authentication.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000053248 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.5331ec95#\4ea52c4d91d040836c346cbeb482bbd0\MailClient.Storage.Attachment.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000399872 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.6df617c9#\8664e00260d0d4b38206b02cff4a11ba\MailClient.Storage.Schedule.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000069632 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.93969d60#\0386a1ee03652afb95058a025f2d160f\MailClient.HtmlOperations.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000091136 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.9a79bc48#\a218ee4e5341fb082140566a8d5ab9eb\MailClient.Storage.IM.ni.dll
2020-03-16 14:50 - 2020-03-16 14:50 - 000027136 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.a758b3a0#\2050ef72f787588a31c41050cb7589a9\MailClient.Storage.Widget.ni.dll
2020-03-16 14:50 - 2020-03-16 14:50 - 002310144 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.Accounts\5162e81e47ce16c45f326c7730c9e3fe\MailClient.Accounts.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000608256 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.Avatar\596944cd1854694da16d83b9d0cd148d\MailClient.Avatar.ni.dll
2020-03-16 14:50 - 2020-03-16 14:50 - 000119296 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.b2c914c9#\932c5f3dfe65ce0f8f5c061278fd537b\MailClient.Storage.Folders.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000387584 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.bc15bd4c#\b3ba220286e5862003bd9dd48643bc7c\MailClient.Protocols.Jabber.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000027136 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.c3eb0b89#\6d3957422eb2d808299db26855c4e9e1\MailClient.Storage.Snippet.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000517632 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.c7b0cd67#\5b31274356ce330c653ee081dcd798b0\MailClient.Protocols.Gdata.ni.dll
2020-03-16 14:50 - 2020-03-16 14:50 - 000048640 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.Commands\a4838952762f7a2a832ae32f063fc10b\MailClient.Commands.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 004545536 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.Common.UI\5a7abe22341615d85ce67ce138427bd5\MailClient.Common.UI.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000287744 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.Contact\40ae8a19164cc01038532e5288591ff0\MailClient.Contact.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000117760 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.d7176fba#\089c06b1bdaf340dbac00dd4ed34b1d9\MailClient.ErrorReporter.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000041472 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.d8481e79#\c1f8a95147da4aed2d84733d0f9bfca5\MailClient.Storage.Certificate.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000313344 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.f2c61d2c#\d958e9c4728fba92eaeb5ad341da54d7\MailClient.Storage.Contact.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000020992 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.ff7bbfa2#\c27265d08262675acd8d6b88df5bfba9\MailClient.Attachment.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000023040 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.IM\41d9f042939b9eabde568d2b3e789db2\MailClient.IM.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000266240 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.Imap.Base\76033904971d66d55772e10ed24b74fe\MailClient.Imap.Base.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000043520 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.Import\1747a3a6a3a1f69fd63efc22fa335867\MailClient.Import.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000020480 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.Interop\2659e47c047b1c5735572f4e6f8b436f\MailClient.Interop.ni.dll
2020-03-16 14:50 - 2020-03-16 14:50 - 000467968 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.Mail\fa3a86b3acd1c893eeefca5a3538a657\MailClient.Mail.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000830464 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.Protocols\fe3ec16219e17fa22fc46244a3dc5a91\MailClient.Protocols.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000679936 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.Schedule\e4de72d912e46c92b8320b70aba0a59a\MailClient.Schedule.ni.dll
2020-03-16 14:50 - 2020-03-16 14:50 - 000595968 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.Storage\a6976d0c769036ea8a511d9b9ba451f0\MailClient.Storage.ni.dll
2020-03-16 14:50 - 2020-03-16 14:50 - 000111104 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.Streams\f68e63c43270b3cf0b92c23dfb100305\MailClient.Streams.ni.dll
2020-03-16 14:50 - 2020-03-16 14:50 - 000070656 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.Threading\0c3cd67ab90f6b0490f1fa50685d9387\MailClient.Threading.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000542208 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.VObject\54698f31fb55c88f684f1149f9a95c40\MailClient.VObject.ni.dll
2020-03-16 14:50 - 2020-03-16 14:50 - 000027136 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.Widget\80f421236b99cd65c0e37851b71dc459\MailClient.Widget.ni.dll
2020-03-16 14:50 - 2020-03-16 14:50 - 000168448 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Sd25cd4a4#\9361e17d5883b8b75443dec6350c4c71\Microsoft.Search.Interop.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000084992 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\SystemCoreTimeZone\3b56c40d691fef041014a78fb00bf93b\SystemCoreTimeZone.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000228352 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\WinApi\5fc02519dc7b9fa164f19d047b97ba75\WinApi.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 001583616 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsAPICodePack\3934fdb9d1196c0f65b4cabf0dcfd76e\WindowsAPICodePack.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000079872 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\Xilium.CefG0f485e28#\61e9629441a1ec26a142348bff348527\Xilium.CefGlue.WindowsForms.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 002796032 _____ () [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\Xilium.CefGlue\b912ad7a753ddd601beb6656e4d5893d\Xilium.CefGlue.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 001761792 _____ (Cursive Systems, Inc.) [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\jabber-net\2fa831cdcbc85cc92e4bee77a722971f\jabber-net.ni.dll
2020-03-11 19:21 - 2020-03-11 19:21 - 000028672 _____ (Digia Plc and/or its subsidiary(-ies)) [File not signed] C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\bin\Qt5Concurrent.dll
2020-03-11 19:21 - 2020-03-11 19:21 - 004620288 _____ (Digia Plc and/or its subsidiary(-ies)) [File not signed] C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\bin\Qt5Core.dll
2020-03-11 19:21 - 2020-03-11 19:21 - 003921408 _____ (Digia Plc and/or its subsidiary(-ies)) [File not signed] C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\bin\Qt5Gui.dll
2020-03-11 19:21 - 2020-03-11 19:21 - 001448448 _____ (Digia Plc and/or its subsidiary(-ies)) [File not signed] C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\bin\Qt5Network.dll
2020-03-11 19:21 - 2020-03-11 19:21 - 006133760 _____ (Digia Plc and/or its subsidiary(-ies)) [File not signed] C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\bin\Qt5Widgets.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000119808 _____ (Google Corporation) [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\Google.GDat88526e68#\84afee46b0597e84515e58726b7ff09a\Google.GData.Contacts.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000686080 _____ (Google Corporation) [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\Google.GData.Client\8105b79497012348b291cbac2b7d36f9\Google.GData.Client.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 000250368 _____ (Google Corporation) [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\Google.GDatc9e696b1#\714ffd652317ed7516b5f91297b9f42c\Google.GData.Extensions.ni.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 001837056 _____ (Google Inc) [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\Google.Apis\25b2a9c1a9b8ba177c41f7d4541f3d57\Google.Apis.ni.dll
2020-03-16 14:50 - 2020-03-16 14:50 - 001121280 _____ (hxxps://system.data.sqlite.org/) [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data.SQLite\85ff7a1494dcb45083f8692fb24985a4\System.Data.SQLite.ni.dll
2020-03-11 19:21 - 2020-03-11 19:21 - 000065629 _____ (MingW-W64 Project. All rights reserved.) [File not signed] C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\bin\libwinpthread-1.dll
2020-03-16 14:51 - 2020-03-16 14:51 - 001615872 _____ (Newtonsoft) [File not signed] C:\Windows\assembly\NativeImages_v4.0.30319_32\Newtonsoft.58a71267#\15884a7ba6e87b46c867bbd77ca94a78\Newtonsoft.Json.Net20.ni.dll
2019-10-11 13:39 - 2019-10-11 13:39 - 000840078 _____ (SQLite Development Team) [File not signed] C:\Program Files (x86)\eM Client\SQLite\x86\sqlite3.dll
2019-10-11 13:41 - 2019-10-11 13:41 - 000729600 _____ (The Chromium Authors) [File not signed] C:\Program Files (x86)\eM Client\libcef\chrome_elf.dll
2020-03-11 19:21 - 2020-03-11 19:21 - 002781303 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\bin\LIBEAY32.dll
2020-03-11 19:21 - 2020-03-11 19:21 - 000809896 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\bin\SSLEAY32.dll
2020-03-11 19:21 - 2020-03-11 19:21 - 002822144 _____ (TODO: <Company name>) [File not signed] C:\Users\jsem\AppData\Local\SynologyDrive\SynologyDrive.app\icon-overlay\22\x64\iconOverlay.dll

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

==================== Internet Explorer trusted/restricted ==========

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2019-03-19 06:49 - 2019-03-19 06:49 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1480136373-461117007-2887068974-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\jsem\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\img13.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [TCP Query User{212A2013-0F7E-485E-9B99-CAC4F50CC3DE}C:\program files (x86)\pspad editor\pspad.exe] => (Allow) C:\program files (x86)\pspad editor\pspad.exe (Jan Fiala) [File not signed]
FirewallRules: [UDP Query User{32FF01CB-1712-4E42-8975-B18C9ACE9C8F}C:\program files (x86)\pspad editor\pspad.exe] => (Allow) C:\program files (x86)\pspad editor\pspad.exe (Jan Fiala) [File not signed]
FirewallRules: [TCP Query User{883C44BD-6499-40AC-88C2-B94F1CE98922}D:\stažené soubory\office_2016_x86_x64_cs_16.0.7571.2109\office\files\bin\kmss.exe] => (Allow) D:\stažené soubory\office_2016_x86_x64_cs_16.0.7571.2109\office\files\bin\kmss.exe No File
FirewallRules: [UDP Query User{5C376DB6-E220-4B37-8447-9439C98617DA}D:\stažené soubory\office_2016_x86_x64_cs_16.0.7571.2109\office\files\bin\kmss.exe] => (Allow) D:\stažené soubory\office_2016_x86_x64_cs_16.0.7571.2109\office\files\bin\kmss.exe No File
FirewallRules: [TCP Query User{17684C9C-9416-494C-B10B-B932C2867A6E}C:\program files (x86)\arduino\java\bin\javaw.exe] => (Block) C:\program files (x86)\arduino\java\bin\javaw.exe
FirewallRules: [UDP Query User{E89F5676-BAD8-4604-8EA6-0BBF743FB69A}C:\program files (x86)\arduino\java\bin\javaw.exe] => (Block) C:\program files (x86)\arduino\java\bin\javaw.exe
FirewallRules: [{DC21EA75-24AD-41AD-85A7-21CBD8B2B31C}] => (Allow) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Update\AcroBroker.exe No File
FirewallRules: [{FF97B380-BF1C-4FFA-8215-A36E4E29A11D}] => (Allow) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Update\AcroBroker.exe No File
FirewallRules: [TCP Query User{D920C441-2CE3-42F0-9602-ACBE79BA7A68}C:\users\jsem\appdata\local\synologydrive\synologydrive.app\bin\cloud-drive-ui.exe] => (Allow) C:\users\jsem\appdata\local\synologydrive\synologydrive.app\bin\cloud-drive-ui.exe (Synology Inc. -> Synology Inc.)
FirewallRules: [UDP Query User{D4301ADC-8D4C-4B47-B78F-D47B9CD418C8}C:\users\jsem\appdata\local\synologydrive\synologydrive.app\bin\cloud-drive-ui.exe] => (Allow) C:\users\jsem\appdata\local\synologydrive\synologydrive.app\bin\cloud-drive-ui.exe (Synology Inc. -> Synology Inc.)
FirewallRules: [TCP Query User{95F6B976-C3DA-4845-A88D-70394B968F66}C:\program files (x86)\pspad editor\pspad.exe] => (Allow) C:\program files (x86)\pspad editor\pspad.exe (Jan Fiala) [File not signed]
FirewallRules: [UDP Query User{6AD5CB77-3DD2-49B0-AD0A-3C945BC77E4B}C:\program files (x86)\pspad editor\pspad.exe] => (Allow) C:\program files (x86)\pspad editor\pspad.exe (Jan Fiala) [File not signed]
FirewallRules: [{C9AA3254-D618-43A3-B4C3-6359DD6B22A5}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{E55F0E3B-EA8C-41F5-BD06-4AB4B969A396}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.129.592.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{BC14D123-A3C9-4AC6-9813-ADF6907976AE}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.129.592.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{D882DB9E-A2AD-4EEA-AF9B-003FF8B93C2F}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.129.592.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{AB723EAE-486C-4D8E-A80D-92CF15B4DF9D}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.129.592.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{9A11DB91-F094-41D2-8431-07B808BF0BBE}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.129.592.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{B501EC01-AAB1-40C5-9E1F-ABA870475F4F}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.129.592.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{21674A01-56EE-497A-8904-4699FEF65B70}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.129.592.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{08FCDDEF-B056-4DA6-AD19-88150D6AF172}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.129.592.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{B1CC13BC-11A5-4B41-91D7-FD0949817A09}] => (Allow) C:\Users\jsem\AppData\Local\Java Runtime\transmission-daemon.exe (Mike Gelfand -> Transmission Project)
FirewallRules: [{7CC4738F-A75A-4013-A2B3-8BCDCCEF5FCD}] => (Allow) C:\Users\jsem\AppData\Local\Java Runtime\transmission-daemon.exe (Mike Gelfand -> Transmission Project)
FirewallRules: [{3524159D-3077-4E68-8F92-1EA38C648E4E}] => (Allow) C:\Users\jsem\AppData\Local\Java Runtime\transmission-remote.exe (Mike Gelfand -> Transmission Project)
FirewallRules: [{AFD89048-6DF4-4CFA-B618-2C0E78694DC0}] => (Allow) C:\Users\jsem\AppData\Local\Java Runtime\transmission-remote.exe (Mike Gelfand -> Transmission Project)
FirewallRules: [{F3CCD6B1-86AA-4EBD-BA4F-3C72E5729300}] => (Allow) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Update\firewall.exe () [File not signed]
FirewallRules: [{D4F86ECC-4243-4C31-9CAB-4E19A5BCA34B}] => (Allow) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Update\firewall.exe () [File not signed]

==================== Restore Points =========================

ATTENTION: System Restore is disabled (Total:111.22 GB) (Free:53.72 GB) (48%)

==================== Faulty Device Manager Devices ============

Name: Sériový port sběrnice PCI
Description: Sériový port sběrnice PCI
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: ========================

Application errors:
==================
Error: (04/04/2020 06:38:26 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: bsplayer.exe, verze: 2.7.4.1085, časové razítko: 0x2a425e19
Název chybujícího modulu: bsplayer.exe, verze: 2.7.4.1085, časové razítko: 0x2a425e19
Kód výjimky: 0xc000041d
Posun chyby: 0x000038c0
ID chybujícího procesu: 0x2b84
Čas spuštění chybující aplikace: 0x01d60a9b3c613a70
Cesta k chybující aplikaci: C:\Program Files (x86)\Webteh\BSPlayer\bsplayer.exe
Cesta k chybujícímu modulu: C:\Program Files (x86)\Webteh\BSPlayer\bsplayer.exe
ID zprávy: ff359f27-3c6a-4dd3-80f9-46c068b190c5
Úplný název chybujícího balíčku: 
ID aplikace související s chybujícím balíčkem:

Error: (04/04/2020 06:38:23 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: bsplayer.exe, verze: 2.7.4.1085, časové razítko: 0x2a425e19
Název chybujícího modulu: bsplayer.exe, verze: 2.7.4.1085, časové razítko: 0x2a425e19
Kód výjimky: 0xc0000005
Posun chyby: 0x000038c0
ID chybujícího procesu: 0x2b84
Čas spuštění chybující aplikace: 0x01d60a9b3c613a70
Cesta k chybující aplikaci: C:\Program Files (x86)\Webteh\BSPlayer\bsplayer.exe
Cesta k chybujícímu modulu: C:\Program Files (x86)\Webteh\BSPlayer\bsplayer.exe
ID zprávy: 821d6ed8-ba78-40b9-9ae4-b3ea5e731f2c
Úplný název chybujícího balíčku: 
ID aplikace související s chybujícím balíčkem:

Error: (04/03/2020 08:28:57 AM) (Source: Microsoft-Windows-Perflib) (EventID: 1020) (User: NT AUTHORITY)
Description: Velikost požadované vyrovnávací paměti je větší než velikost vyrovnávací paměti předané do funkce Collect knihovny DLL rozšiřitelných čítačů C:\Windows\System32\perfts.dll pro službu LSM. Velikost dané vyrovnávací paměti: 30632; požadovaná velikost: 31384.

Error: (04/01/2020 08:54:35 AM) (Source: Microsoft-Windows-Perflib) (EventID: 1020) (User: NT AUTHORITY)
Description: Velikost požadované vyrovnávací paměti je větší než velikost vyrovnávací paměti předané do funkce Collect knihovny DLL rozšiřitelných čítačů C:\Windows\System32\perfts.dll pro službu LSM. Velikost dané vyrovnávací paměti: 26376; požadovaná velikost: 30464.

Error: (03/30/2020 09:47:44 AM) (Source: Microsoft-Windows-Perflib) (EventID: 1020) (User: NT AUTHORITY)
Description: Velikost požadované vyrovnávací paměti je větší než velikost vyrovnávací paměti předané do funkce Collect knihovny DLL rozšiřitelných čítačů C:\Windows\System32\perfts.dll pro službu LSM. Velikost dané vyrovnávací paměti: 27568; požadovaná velikost: 27888.

Error: (03/25/2020 06:33:16 PM) (Source: Microsoft-Windows-Perflib) (EventID: 1020) (User: NT AUTHORITY)
Description: Velikost požadované vyrovnávací paměti je větší než velikost vyrovnávací paměti předané do funkce Collect knihovny DLL rozšiřitelných čítačů C:\Windows\System32\perfts.dll pro službu LSM. Velikost dané vyrovnávací paměti: 26216; požadovaná velikost: 29728.

Error: (03/19/2020 09:06:46 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: YourPhone.exe, verze: 1.20012.135.0, časové razítko: 0x5e618260
Název chybujícího modulu: ntdll.dll, verze: 10.0.18362.719, časové razítko: 0x64d10ee0
Kód výjimky: 0xc0000374
Posun chyby: 0x00000000000f92a9
ID chybujícího procesu: 0x2ccc
Čas spuštění chybující aplikace: 0x01d5fdb52f506fcc
Cesta k chybující aplikaci: C:\Program Files\WindowsApps\Microsoft.YourPhone_1.20012.135.0_x64__8wekyb3d8bbwe\YourPhone.exe
Cesta k chybujícímu modulu: C:\Windows\SYSTEM32\ntdll.dll
ID zprávy: 09d4c3bb-6c03-480b-96ef-b48cca0c2db8
Úplný název chybujícího balíčku: Microsoft.YourPhone_1.20012.135.0_x64__8wekyb3d8bbwe
ID aplikace související s chybujícím balíčkem: App

Error: (03/15/2020 05:08:24 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Aplikace: MailClient.exe
Verze Framework: v4.0.30319
Popis: Proces byl ukončen z důvodu neošetřené výjimky.
Informace o výjimce: System.Text.EncoderFallbackException
   na System.Text.EncoderExceptionFallbackBuffer.Fallback(Char, Int32)
   na System.Text.EncoderFallbackBuffer.InternalFallback(Char, Char* ByRef)
   na System.Text.UTF8Encoding.GetBytes(Char*, Int32, Byte*, Int32, System.Text.EncoderNLS)
   na System.Text.EncoderNLS.GetBytes(Char*, Int32, Byte*, Int32, Boolean)
   na System.Text.EncoderNLS.GetBytes(Char[], Int32, Int32, Byte[], Int32, Boolean)
   na System.IO.StreamWriter.Flush(Boolean, Boolean)
   na System.IO.StreamWriter.Write(Char[], Int32, Int32)
   na System.IO.TextWriter.WriteLine(System.String)
   na MailClient.Utils.LoggingMessageFilter.LogMessage(HookLib.CWPSTRUCT)
   na MailClient.Utils.LoggingMessageFilter.hook_WndProc(System.Object, HookLib.HookEventArgs)
   na HookLib.HookLibClass.ProcessMessage(HookLib.SWH_ID, HookEventHandler, Int32, IntPtr, IntPtr)
   na HookLib.HookLibClass+<>c__DisplayClass4_0.<SetHook>b__0(Int32, IntPtr, IntPtr)


System errors:
=============
Error: (04/05/2020 10:48:44 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Instalační služba modulů systému Windows byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 120000 milisekund: Restartovat službu.

Error: (04/05/2020 10:48:44 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba FileSyncHelper byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (04/05/2020 10:48:44 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Služba Microsoft Office Klikni a spusť byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 0 milisekund: Restartovat službu.

Error: (04/05/2020 10:48:44 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Synology Drive VSS Service x64 byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (04/05/2020 10:48:44 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Adobe Acrobat Update Service byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (04/05/2020 09:40:17 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4

Error: (04/04/2020 10:35:02 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4

Error: (04/04/2020 09:30:09 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-T411FCR)
Description: Server {FD06603A-2BDF-4BB1-B7DF-5DC68F353601} se v daném časovém limitu neregistroval u služby DCOM.


Windows Defender:
===================================
Date: 2020-04-03 08:33:55.033
Description: 
Antivirová ochrana v programu Windows Defender zjistil malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid=37020&name=Program:Win32/Unwaders.A!ml&threatid=242872&enterprise=0
Název: Program:Win32/Unwaders.A!ml
ID: 242872
Závažnost: Vážné
Kategorie: Potenciálně nežádoucí software
Cesta: file:_C:\Users\jsem\AppData\Roaming\Microsoft\Network\SystemArchitectureTranslation.exe; file:_C:\Windows\System32\Tasks\GoogleUpdateTask->(UTF-16LE); regkey:_HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6298F7F3-A317-400D-896F-050C273D3A47}; regkey:_HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTask; taskscheduler:_C:\Windows\System32\Tasks\GoogleUpdateTask
Původ detekce: Místní počítač
Typ detekce: FastPath
Zdroj detekce: Systém
Uživatel: NT AUTHORITY\SYSTEM
Název procesu: Unknown
Verze bezpečnostních informací: AV: 1.313.662.0, AS: 1.313.662.0, NIS: 1.313.662.0
Verze modulu: AM: 1.1.16900.4, NIS: 1.1.16900.4

Date: 2020-04-03 08:33:23.249
Description: 
Antivirová ochrana v programu Windows Defender zjistil malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid=37020&name=Program:Win32/Unwaders.A!ml&threatid=242872&enterprise=0
Název: Program:Win32/Unwaders.A!ml
ID: 242872
Závažnost: Vážné
Kategorie: Potenciálně nežádoucí software
Cesta: file:_C:\Users\jsem\AppData\Roaming\Microsoft\Network\SystemArchitectureTranslation.exe
Původ detekce: Místní počítač
Typ detekce: FastPath
Zdroj detekce: Systém
Uživatel: NT AUTHORITY\SYSTEM
Název procesu: Unknown
Verze bezpečnostních informací: AV: 1.313.662.0, AS: 1.313.662.0, NIS: 1.313.662.0
Verze modulu: AM: 1.1.16900.4, NIS: 1.1.16900.4

Date: 2020-03-26 19:09:24.201
Description: 
Antivirová ochrana v programu Windows Defender zjistil malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Wacatac.B!ml&threatid=2147735505&enterprise=0
Název: Trojan:Win32/Wacatac.B!ml
ID: 2147735505
Závažnost: Vážné
Kategorie: Trojský kůň
Cesta: file:_C:\Users\jsem\AppData\Roaming\Microsoft\Network\SystemArchitectureTranslation.exe; file:_C:\Windows\System32\Tasks\GoogleUpdateTask->(UTF-16LE); process:_pid:8016,ProcessStart:132297196218493500; regkey:_HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{580FE1EF-7455-459C-B2D8-AE6029429839}; regkey:_HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTask; taskscheduler:_C:\Windows\System32\Tasks\GoogleUpdateTask
Původ detekce: Místní počítač
Typ detekce: FastPath
Zdroj detekce: Systém
Uživatel: NT AUTHORITY\SYSTEM
Název procesu: C:\Users\jsem\AppData\Roaming\Microsoft\Network\SystemArchitectureTranslation.exe
Verze bezpečnostních informací: AV: 1.313.128.0, AS: 1.313.128.0, NIS: 1.313.128.0
Verze modulu: AM: 1.1.16900.4, NIS: 1.1.16900.4

Date: 2020-03-26 19:08:53.207
Description: 
Antivirová ochrana v programu Windows Defender zjistil malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Wacatac.B!ml&threatid=2147735505&enterprise=0
Název: Trojan:Win32/Wacatac.B!ml
ID: 2147735505
Závažnost: Vážné
Kategorie: Trojský kůň
Cesta: file:_C:\Users\jsem\AppData\Roaming\Microsoft\Network\SystemArchitectureTranslation.exe; process:_pid:8016,ProcessStart:132297196218493500
Původ detekce: Místní počítač
Typ detekce: FastPath
Zdroj detekce: Systém
Uživatel: NT AUTHORITY\SYSTEM
Název procesu: C:\Users\jsem\AppData\Roaming\Microsoft\Network\SystemArchitectureTranslation.exe
Verze bezpečnostních informací: AV: 1.313.128.0, AS: 1.313.128.0, NIS: 1.313.128.0
Verze modulu: AM: 1.1.16900.4, NIS: 1.1.16900.4

Date: 2020-03-26 08:23:01.203
Description: 
Antivirová ochrana v programu Windows Defender zjistil malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid=37020&name=Program:Win32/Contebrew.A!ml&threatid=251873&enterprise=0
Název: Program:Win32/Contebrew.A!ml
ID: 251873
Závažnost: Střední
Kategorie: Potenciálně nežádoucí software
Cesta: file:_C:\Users\jsem\AppData\Roaming\Microsoft\Network\SystemArchitectureTranslation.exe; process:_pid:6640,ProcessStart:132296131814462463
Původ detekce: Místní počítač
Typ detekce: FastPath
Zdroj detekce: Systém
Uživatel: NT AUTHORITY\SYSTEM
Název procesu: C:\Users\jsem\AppData\Roaming\Microsoft\Network\SystemArchitectureTranslation.exe
Verze bezpečnostních informací: AV: 1.313.26.0, AS: 1.313.26.0, NIS: 1.313.26.0
Verze modulu: AM: 1.1.16900.4, NIS: 1.1.16900.4

Date: 2020-03-27 10:58:14.737
Description: 
Antivirová ochrana v programu Windows Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací: 
Předchozí verze bezpečnostních informací: 1.313.128.0
Zdroj aktualizace: Server Microsoft Update
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu: 
Předchozí verze modulu: 1.1.16900.4
Kód chyby: 0x80240438
Popis chyby: Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře. 

==================== Memory info =========================== 

BIOS: Dell Inc. A18 09/24/2013
Motherboard: Dell Inc. 0D28YY
Processor: Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
Percentage of memory in use: 53%
Total physical RAM: 6025.05 MB
Available physical RAM: 2795.77 MB
Total Virtual: 6985.05 MB
Available Virtual: 3839.57 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:111.22 GB) (Free:53.72 GB) NTFS
Drive d: (Souborový disk) (Fixed) (Total:465.76 GB) (Free:167.66 GB) NTFS

\\?\Volume{671ae29b-0000-0000-0000-100000000000}\ (Rezervováno systémem) (Fixed) (Total:0.57 GB) (Free:0.12 GB) NTFS

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 111.8 GB) (Disk ID: 671AE29B)
Partition 1: (Active) - (Size=579 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=111.2 GB) - (Type=07 NTFS)

==========================================================
Disk: 1 (Size: 465.8 GB) (Disk ID: 534682A6)
Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS)

==================== End of Addition.txt =======================