Additional scan result of Farbar Recovery Scan Tool (x64) Version: 23-08-2020
Ran by roman (26-08-2020 11:32:24)
Running from C:\Users\roman\Desktop
Windows 10 Pro Version 1909 18363.1016 (X64) (2020-05-09 14:09:18)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3360966048-3804889038-406055420-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3360966048-3804889038-406055420-503 - Limited - Disabled)
Guest (S-1-5-21-3360966048-3804889038-406055420-501 - Limited - Disabled)
roman (S-1-5-21-3360966048-3804889038-406055420-1002 - Limited - Disabled)
Roman-E (S-1-5-21-3360966048-3804889038-406055420-1003 - Administrator - Enabled) => C:\Users\Roman-E
roman (S-1-5-21-3360966048-3804889038-406055420-1001 - Administrator - Enabled) => C:\Users\roman
WDAGUtilityAccount (S-1-5-21-3360966048-3804889038-406055420-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

4K Video Downloader (HKLM\...\{E9B4998F-85C5-4694-B95F-2390B6E63756}) (Version: 4.13.0.3800 - Open Media LLC)
7+ Taskbar Tweaker v5.9 (HKU\S-1-5-21-3360966048-3804889038-406055420-1001\...\7 Taskbar Tweaker) (Version: 5.9 - RaMMicHaeL)
7+ Taskbar Tweaker v5.9 (HKU\S-1-5-21-3360966048-3804889038-406055420-1003\...\7 Taskbar Tweaker) (Version: 5.9 - RaMMicHaeL)
Active Directory Authentication Library for SQL Server (HKLM\...\{6BF11ECE-3CE8-4FBA-991A-1F55AA6BE5BF}) (Version: 15.0.1300.359 - Microsoft Corporation) Hidden
Adobe Bridge CC 2018 8.0 (HKLM\...\{2660902D-D9C8-40CF-AFF5-27D17F5D651C}) (Version: 8.0 - Adobe Systems Incorporated)
Adobe Photoshop 2020 (HKLM-x32\...\PHSP_21_1_3) (Version: 21.1.3 - Adobe Inc.)
Allway Sync (HKLM\...\{6E2A6AEF-1397-4888-BD6F-4C0D4968014D}) (Version: 20.0.5 - Botkind Inc.)
AMD Ryzen Master SDK (HKLM\...\{DBD50508-5F75-416B-995D-C42433A00944}) (Version: 2.2.0.1506 - Advanced Micro Devices, Inc.)
Autodesk 3ds Max 2021 (HKLM\...\{63853A48-EB3A-4456-B788-1C010950D62C}) (Version: 23.1.0.1314 - Autodesk) Hidden
Autodesk 3ds Max 2021 (HKLM\...\Autodesk 3ds Max 2021) (Version: 23.1.0.1314 - Autodesk)
Autodesk Advanced Material Library Base Resolution Image Library 2021 (HKLM-x32\...\{C9FDA270-A0B9-45EE-8748-F37DF1370767}) (Version: 19.1.23.0 - Autodesk)
Autodesk Advanced Material Library Low Resolution Image Library 2021 (HKLM-x32\...\{AB7DC10F-1D72-4F90-988F-CDC2D6323A48}) (Version: 19.1.23.0 - Autodesk)
Autodesk Advanced Material Library Medium Resolution Image Library 2021 (HKLM-x32\...\{B4545986-9002-4090-9E58-44F985F2FF4F}) (Version: 19.1.23.0 - Autodesk)
Autodesk Material Library 2021 (HKLM-x32\...\{8C559572-4A10-43C2-9346-6E7C7E012487}) (Version: 19.1.23.0 - Autodesk)
Autodesk Material Library Base Resolution Image Library 2021 (HKLM-x32\...\{EFC36459-CD89-44F3-BA04-B7C5804199AF}) (Version: 19.1.23.0 - Autodesk)
Autodesk Material Library Medium Resolution Image Library 2021 (HKLM-x32\...\{69D8FFED-B14E-4998-BBC2-535006E195D6}) (Version: 19.1.23.0 - Autodesk)
Azure Data Studio (User) (HKU\S-1-5-21-3360966048-3804889038-406055420-1001\...\{1F0FD1CE-9703-4734-8F50-5B5CEEDAE6B9}_is1) (Version: 1.20.1 - Microsoft Corporation)
Azure Data Studio (User) (HKU\S-1-5-21-3360966048-3804889038-406055420-1003\...\{1F0FD1CE-9703-4734-8F50-5B5CEEDAE6B9}_is1) (Version: 1.21.0 - Microsoft Corporation)
calibre 64bit (HKLM\...\{1D7FDE88-92F2-44FE-A937-D394A0A0984D}) (Version: 4.19.0 - Kovid Goyal)
CCleaner (HKLM\...\CCleaner) (Version: 5.68 - Piriform)
CDisplayEx 1.10.33 (HKLM\...\CDisplayEx_is1) (Version:  - Progdigy Software S.A.R.L.)
ClickOnce Bootstrapper Package for Microsoft .NET Framework (HKLM-x32\...\{0243F145-076D-423A-8F77-218DC8840261}) (Version: 4.8.04119 - Microsoft Corporation) Hidden
Control v.1.0.3 (HKLM-x32\...\Control_is1) (Version:  - )
DiagnosticsHub_CollectionService (HKLM\...\{1F3C3AAC-9F7A-47DA-A082-0ACE770041BE}) (Version: 16.1.28901 - Microsoft Corporation) Hidden
DVDFab (x64) 10.0.9.0 (20/04/2018) (HKLM-x32\...\DVDFab 10(x64)) (Version: 10.0.9.0 - Fengtao Software Inc.)
ENE IO Driver (HKLM-x32\...\{D0512FFD-6194-4D2E-967E-25B82A3322FF}) (Version: 3.2.0 - ENE TECHNOLOGY INC.) Hidden
ENE RGB HAL (HKLM\...\{63DDE2BB-2798-4F3C-A0FD-5C751AB0DA41}) (Version: 1.0.20.0 - Ene Tech.) Hidden
ENE RGB HAL (HKLM-x32\...\{87ed2353-bb2c-4aa0-8a03-1414566199fb}) (Version: 1.0.20.0 - Ene Tech.) Hidden
ENE_DRAM_RGB_AURA42 (HKLM\...\{978E8FD1-5778-47EF-91A4-F891DA415DDE}) (Version: 1.0.4.0 - Ene Tech.) Hidden
ENE_DRAM_RGB_AURA42 (HKLM-x32\...\{587316c6-4804-4857-af01-1f2f78d4a0e5}) (Version: 1.0.4.0 - Ene Tech.) Hidden
ENE_EHD_M2_HAL (HKLM\...\{1CD178C9-BB49-4E59-9DA6-3C152E2A9844}) (Version: 1.00.01 - ENE TECHNOLOGY INC.) Hidden
ENE_EHD_M2_HAL (HKLM-x32\...\{fe81cfd3-9db4-409d-b0f9-26707d1423c6}) (Version: 1.00.01 - ENE TECHNOLOGY INC.) Hidden
ENE_EHD_SSS_HAL (HKLM\...\{CF703694-01C6-4062-B797-84DB215662BC}) (Version: 1.0.1.0 - ENE TECHNOLOGY INC.) Hidden
ENE_EHD_SSS_HAL (HKLM-x32\...\{20610ecc-e094-423e-af0c-7d0bcfe117e9}) (Version: 1.0.1.0 - ENE TECHNOLOGY INC.) Hidden
Entity Framework 6.2.0 Tools  for Visual Studio 2019 (HKLM-x32\...\{7C2070BF-8E07-4B5F-A182-FADB0B95AB39}) (Version: 6.2.0.0 - Microsoft Corporation) Hidden
Equalizer APO (HKLM\...\EqualizerAPO) (Version: 1.2.1 - )
EXPERTool v10.32 (HKLM\...\{551D9481-9487-4D0C-9A1D-6BC3E7B6D991}_is1) (Version: 10.32.0.1 - Gainward Co. Ltd.)
Git version 2.24.1.2 (HKLM\...\Git_is1) (Version: 2.24.1.2 - The Git Development Community)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 85.0.4183.83 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
Chaos Cloud Client (HKU\S-1-5-21-3360966048-3804889038-406055420-1001\...\Chaos Cloud Client) (Version: 1.6.5 - Chaos Software Ltd)
icecap_collection_neutral (HKLM-x32\...\{2A00DCB3-752F-446C-B3B3-1B6ADFBFF3E3}) (Version: 16.6.30014 - Microsoft Corporation) Hidden
icecap_collection_x64 (HKLM\...\{BE5E54C4-6B68-4AE3-A7F4-45F0D29D48D3}) (Version: 16.6.30014 - Microsoft Corporation) Hidden
icecap_collectionresources (HKLM-x32\...\{1E6E5904-E97F-41F7-B3DB-0C8CD3180E3C}) (Version: 16.6.30014 - Microsoft Corporation) Hidden
icecap_collectionresourcesx64 (HKLM-x32\...\{7FD392DF-51A1-4DC1-9C6F-BF7C58A576AC}) (Version: 16.6.30014 - Microsoft Corporation) Hidden
IIS 10.0 Express (HKLM\...\{2B8326B6-4202-4239-B9A9-F3EC8812E82D}) (Version: 10.0.03917 - Microsoft Corporation)
IIS Express Application Compatibility Database for x64 (HKLM\...\{08274920-8908-45c2-9258-8ad67ff77b09}.sdb) (Version:  - ) Hidden
IIS Express Application Compatibility Database for x86 (HKLM\...\{ad846bae-d44b-4722-abad-f7420e08bcd9}.sdb) (Version:  - ) Hidden
IntelliTraceProfilerProxy (HKLM-x32\...\{7D94CF67-6666-4111-B027-D7AB7F189F70}) (Version: 15.0.18198.01 - Microsoft Corporation) Hidden
JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH)
JetBrains Rider 2020.1.4 (HKLM-x32\...\JetBrains Rider 2020.1.4) (Version: 201.8538.1 - JetBrains s.r.o.)
KeePass Password Safe 2.45 (HKLM-x32\...\KeePassPasswordSafe2_is1) (Version: 2.45 - Dominik Reichl)
Kodi (HKU\S-1-5-21-3360966048-3804889038-406055420-1001\...\Kodi) (Version:  - XBMC Foundation)
Logitech Gaming Software 9.02 (HKLM\...\Logitech Gaming Software) (Version: 9.02.65 - Logitech Inc.)
Microsoft .NET Core 3.1.5 - Windows Server Hosting (HKLM-x32\...\{5098fc91-c8e9-4cfd-aa13-90c283e9dec3}) (Version: 3.1.5.20271 - Microsoft Corporation)
Microsoft .NET Core Runtime - 3.1.5 (x64) (HKLM-x32\...\{55c799db-4541-4d55-8fa5-7c0f4f59ebb2}) (Version: 3.1.5.28920 - Microsoft Corporation)
Microsoft .NET Core Runtime - 3.1.5 (x86) (HKLM-x32\...\{09024a32-fa29-4e57-a385-5f66d21ef115}) (Version: 3.1.5.28920 - Microsoft Corporation)
Microsoft .NET Core SDK 2.2.207 (x64) (HKLM-x32\...\{aeb031fb-888b-4f24-ac5f-919322ceb39e}) (Version: 2.2.207 - Microsoft Corporation)
Microsoft .NET Core SDK 3.1.302 (x64) (HKLM-x32\...\{117e26c4-4c61-4908-b96d-e17ac0bc5d90}) (Version: 3.1.302.15188 - Microsoft Corporation)
Microsoft .NET Core SDK 3.1.302 (x64) from Visual Studio (HKLM\...\{539053B2-E414-46BC-B4CD-365E79AFEA79}) (Version: 3.1.302.015188 - Microsoft Corporation)
Microsoft .NET Framework 4.6.2 SDK (HKLM-x32\...\{5F01B3C4-9BEC-465D-9C68-BB97D381FFAD}) (Version: 4.6.01590 - Microsoft Corporation)
Microsoft .NET Framework 4.6.2 Targeting Pack (ENU) (HKLM-x32\...\{C80951BD-6904-474F-BBC5-03A6C777F37C}) (Version: 4.6.01590 - Microsoft Corporation)
Microsoft .NET Framework 4.6.2 Targeting Pack (HKLM-x32\...\{A18D4C2A-07A8-40E4-9797-DD324E6EA4FC}) (Version: 4.6.01590 - Microsoft Corporation)
Microsoft .NET Framework 4.7.2 SDK (HKLM-x32\...\{F42C96C1-746B-442A-B58C-9F0FD5F3AB8A}) (Version: 4.7.03081 - Microsoft Corporation)
Microsoft .NET Framework 4.7.2 Targeting Pack (ENU) (HKLM-x32\...\{B517DBD3-B542-4FC8-9957-FFB2C3E65D1D}) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft .NET Framework 4.7.2 Targeting Pack (HKLM-x32\...\{1784A8CD-F7FE-47E2-A87D-1F31E7242D0D}) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft Azure Authoring Tools - v2.9.6 (HKLM\...\{EDADFA19-7F96-4075-A4AB-2209910626C5}) (Version: 2.9.8899.26 - Microsoft Corporation)
Microsoft Azure Compute Emulator - v2.9.6 (HKLM\...\Microsoft Azure Compute Emulator - v2.9.6) (Version: 2.9.8899.26 - Microsoft Corporation)
Microsoft Azure Libraries for .NET – v2.9 (HKLM\...\{C5C91AA6-3E83-430E-8B7A-6B790083F28D}) (Version: 3.0.0127.060 - Microsoft Corporation)
Microsoft Azure PowerShell - April 2018 (HKLM\...\{3BA7CAA9-97BA-4528-B7E1-B640910BB149}) (Version: 5.7.0.18831 - Microsoft Corporation)
Microsoft Azure Storage Emulator - v5.10 (HKLM-x32\...\Microsoft Azure Storage Emulator - v5.10) (Version: 5.10.19227.2113 - Microsoft Corporation)
Microsoft Azure Storage Explorer version 1.14.2 (HKU\S-1-5-21-3360966048-3804889038-406055420-1003\...\{8E14ADF3-1B18-4711-87BD-E3827D395466}_is1) (Version: 1.14.2 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 84.0.522.63 - Microsoft Corporation)
Microsoft Edge Update (HKLM-x32\...\Microsoft Edge Update) (Version: 1.3.135.29 - )
Microsoft ODBC Driver 17 for SQL Server (HKLM\...\{8D98AC2C-FC5C-440D-A2D3-6C9655F957D8}) (Version: 17.2.0.1 - Microsoft Corporation)
Microsoft Office 2019 Professional Plus - sk-sk (HKLM\...\Proplus2019Retail - sk-sk) (Version: 16.0.13029.20344 - Microsoft Corporation)
Microsoft Office Professional Plus 2019 - en-us (HKLM\...\Proplus2019Retail - en-us) (Version: 16.0.13029.20344 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3360966048-3804889038-406055420-1001\...\OneDriveSetup.exe) (Version: 20.134.0705.0008 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3360966048-3804889038-406055420-1003\...\OneDriveSetup.exe) (Version: 20.143.0716.0003 - Microsoft Corporation)
Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft SQL Server 2016 LocalDB  (HKLM\...\{9097BF1A-13A0-4A4A-A1F8-473E2A669863}) (Version: 13.1.4001.0 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2019 CTP2.2 (HKLM\...\{8D7CE3B0-5379-46FE-9F4B-A65D9F4CC1F1}) (Version: 15.0.1200.24 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2019 CTP2.2 (HKLM-x32\...\{725CC962-98BD-42C7-87D8-51C680FB1779}) (Version: 15.0.1200.24 - Microsoft Corporation)
Microsoft Teams (HKU\S-1-5-21-3360966048-3804889038-406055420-1001\...\Teams) (Version: 1.3.00.15561 - Microsoft Corporation)
Microsoft Teams (HKU\S-1-5-21-3360966048-3804889038-406055420-1003\...\Teams) (Version: 1.3.00.19173 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{8e24fb65-31aa-446d-9c3e-35c5e11cb367}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.26.28720 (HKLM-x32\...\{7d607fb4-7e28-4c7a-a92f-3fcdaf555faf}) (Version: 14.26.28720.3 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.23.27820 (HKLM-x32\...\{45231ab4-69fd-486a-859d-7a59fcd11013}) (Version: 14.23.27820.0 - Microsoft Corporation)
Microsoft Visual Studio Code (HKLM\...\{EA457B21-F73E-494C-ACAB-524FDE069978}_is1) (Version: 1.47.3 - Microsoft Corporation)
Microsoft Visual Studio Installer (HKLM\...\{6F320B93-EE3C-4826-85E0-ADF79F8D4C61}) (Version: 2.6.2037.624 - Microsoft Corporation)
Microsoft Web Deploy 4.0 (HKLM\...\{BBCDB523-F5B7-4E53-A911-C85191E3BDF0}) (Version: 10.0.2606 - Microsoft Corporation)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 60.6.1 - Mozilla)
Mozilla Thunderbird 60.6.1 (x86 sk) (HKLM-x32\...\Mozilla Thunderbird 60.6.1 (x86 sk)) (Version: 60.6.1 - Mozilla)
MSI SDK (HKLM-x32\...\{EE7D557C-3AE7-4348-8DCA-3A89790D0002}}_is1) (Version: 1.0.0.54 - MSI)
Node.js (HKLM\...\{F64B3297-0B1F-4C1C-9F48-126F7CF7CF3C}) (Version: 12.18.2 - Node.js Foundation)
Notepad++ (32-bit x86) (HKLM-x32\...\Notepad++) (Version: 7.8.8 - Notepad++ Team)
NVIDIA Graphics Driver 451.67 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 451.67 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.38.34 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.34 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation)
NVIDIA USBC Driver 1.42.831.832 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_USBC) (Version: 1.42.831.832 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.13029.20200 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.13029.20236 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.13029.20200 - Microsoft Corporation) Hidden
OpenVPN Connect (HKLM\...\{0D24D233-76D6-4DF0-9044-AE7BAD37E4EB}) (Version: 3.1.3 - OpenVPN Technologies)
Opera Stable 70.0.3728.106 (HKLM-x32\...\Opera 70.0.3728.106) (Version: 70.0.3728.106 - Opera Software)
PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.322.10 - Tracker Software Products Ltd)
PotPlayer-64 bit (HKLM\...\PotPlayer64) (Version: 200616 - Kakao Corp.)
Spotify (HKU\S-1-5-21-3360966048-3804889038-406055420-1001\...\Spotify) (Version: 1.1.40.508.gd5bc2931 - Spotify AB)
Spotify (HKU\S-1-5-21-3360966048-3804889038-406055420-1003\...\Spotify) (Version: 1.1.40.508.gd5bc2931 - Spotify AB)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 9.51 - Ghisler Software GmbH)
TrueCrypt (HKLM-x32\...\TrueCrypt) (Version: 7.1a - TrueCrypt Foundation)
TypeScript SDK (HKLM-x32\...\{87FA8DC5-850D-408C-8A29-3B925DFD5F41}) (Version: 3.8.3.0 - Microsoft Corporation) Hidden
Update for  (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
vcpp_crt.redist.clickonce (HKLM-x32\...\{B2AC4CE4-2533-4485-B3B5-2F645C2DD325}) (Version: 14.26.28808 - Microsoft Corporation) Hidden
Visual Studio Community 2019 (HKLM-x32\...\d653bee1) (Version: 16.6.30320.27 - Microsoft Corporation)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.11 - VideoLAN)
V-Ray for 3dsmax 2021 for x64 (HKLM\...\V-Ray for 3dsmax 2021 for x64) (Version: 5.00.3 - Chaos Software Ltd)
VS Immersive Activate Helper (HKLM-x32\...\{A71406B5-E487-4B01-8E59-D466841350F5}) (Version: 16.0.102.0 - Microsoft Corporation) Hidden
VS JIT Debugger (HKLM\...\{C7E8A4F2-EF09-42A8-B892-69D5ED99D965}) (Version: 16.0.102.0 - Microsoft Corporation) Hidden
VS Script Debugging Common (HKLM\...\{A4272808-82F5-410F-A5F9-1BF6F63F6B9A}) (Version: 16.0.102.0 - Microsoft Corporation) Hidden
vs_BlendMsi (HKLM-x32\...\{B5E3A3E1-1529-4D5A-9E95-34971FA07825}) (Version: 16.0.28329 - Microsoft Corporation) Hidden
vs_clickoncebootstrappermsi (HKLM-x32\...\{BAF91847-0A64-405E-98EC-A0BA6FB4BC4E}) (Version: 16.0.28329 - Microsoft Corporation) Hidden
vs_clickoncebootstrappermsires (HKLM-x32\...\{271F1F42-B547-4498-825F-590DBB1774F7}) (Version: 16.0.28329 - Microsoft Corporation) Hidden
vs_clickoncesigntoolmsi (HKLM-x32\...\{30D97A69-3C0F-4552-9A72-60E591B210C7}) (Version: 16.0.28329 - Microsoft Corporation) Hidden
vs_communitymsi (HKLM-x32\...\{2CCEC45B-1462-4FFD-8214-90E3C25000F7}) (Version: 16.6.30014 - Microsoft Corporation) Hidden
vs_communitymsires (HKLM-x32\...\{95E79BBC-97FD-4FEB-91B5-CC0231324812}) (Version: 16.0.28329 - Microsoft Corporation) Hidden
vs_devenvmsi (HKLM-x32\...\{AD0C92A4-1514-4BC1-A723-A272A8343924}) (Version: 16.0.28329 - Microsoft Corporation) Hidden
vs_filehandler_amd64 (HKLM-x32\...\{7A991159-9069-471D-B85F-89B1E4E66822}) (Version: 16.6.30014 - Microsoft Corporation) Hidden
vs_filehandler_x86 (HKLM-x32\...\{16E73A5A-339C-4177-A0BD-04278C06625C}) (Version: 16.6.30014 - Microsoft Corporation) Hidden
vs_FileTracker_Singleton (HKLM-x32\...\{C8E7C1FC-925C-4163-BAB3-769E6C7961D2}) (Version: 16.6.30014 - Microsoft Corporation) Hidden
vs_minshellinteropmsi (HKLM-x32\...\{27B16914-BC5D-4018-8074-071262A27F6D}) (Version: 16.2.28917 - Microsoft Corporation) Hidden
vs_minshellmsi (HKLM-x32\...\{DA7AB063-D1A3-4D5A-8221-598ACF4574B4}) (Version: 16.6.30014 - Microsoft Corporation) Hidden
vs_minshellmsires (HKLM-x32\...\{EC04CD66-C03A-470D-B0D2-4BBC87F6382D}) (Version: 16.0.28329 - Microsoft Corporation) Hidden
vs_SQLClickOnceBootstrappermsi (HKLM-x32\...\{0A54CADD-CBA1-4BC9-A134-6C9F91F41B9A}) (Version: 16.5.29521 - Microsoft Corporation) Hidden
vs_tipsmsi (HKLM-x32\...\{E208E682-50EE-4F2F-9860-C91B906B8A03}) (Version: 16.0.28329 - Microsoft Corporation) Hidden
vs_vswebprotocolselectormsi (HKLM-x32\...\{5F2E2347-2042-4340-BBDD-262BB1791EC7}) (Version: 16.6.30014 - Microsoft Corporation) Hidden
WinDirStat 1.1.2 (HKU\S-1-5-21-3360966048-3804889038-406055420-1001\...\WinDirStat) (Version:  - )
XnViewMP 0.96.4 (HKLM\...\XnViewMP_is1) (Version: 0.96.4 - Gougelet Pierre-e)

Packages:
=========
DragonCenter -> C:\Program Files\WindowsApps\9426MICRO-STARINTERNATION.DragonCenter_2.0.65.0_x64__kzh8wxbdkxb8p [2020-08-18] (MICRO-STAR INTERNATIONAL CO., LTD) [Startup Task]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2020-06-30] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2020-06-30] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.7.8101.0_x64__8wekyb3d8bbwe [2020-08-19] (Microsoft Studios) [MS Ad]
Microsoft To Do -> C:\Program Files\WindowsApps\Microsoft.Todos_2.24.32162.0_x64__8wekyb3d8bbwe [2020-08-12] (Microsoft Corporation)
MSN Počasie -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.36.20714.0_x64__8wekyb3d8bbwe [2020-06-30] (Microsoft Corporation) [MS Ad]
Musixmatch Lyrics - Sing along Spotify, iTunes, Windows Media Player -> C:\Program Files\WindowsApps\MUSIXMATCH.LYRICS_3.14.4564.0_x86__7gejyv32yt3te [2020-08-06] (Musixmatch) [Startup Task]
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.958.0_x64__56jybvy8sckqj [2020-06-30] (NVIDIA Corp.)
SpotBright — Windows Wallpaper -> C:\Program Files\WindowsApps\49297T.Partl.SpotBright_1.4.6.0_x64__jr9bq2af9farr [2020-07-10] (T. Partl) [MS Ad]

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3360966048-3804889038-406055420-1001_Classes\CLSID\{19A6E644-14E6-4A60-B8D7-DD20610A871D}\InprocServer32 -> C:\Users\roman\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.20091.2\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3360966048-3804889038-406055420-1001_Classes\CLSID\{CB965DF1-B8EA-49C7-BDAD-5457FDC1BF92}\InprocServer32 -> C:\Users\roman\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.20091.2\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3360966048-3804889038-406055420-1003_Classes\CLSID\{19A6E644-14E6-4A60-B8D7-DD20610A871D}\InprocServer32 -> C:\Users\Roman-E\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.20107.1\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3360966048-3804889038-406055420-1003_Classes\CLSID\{CB965DF1-B8EA-49C7-BDAD-5457FDC1BF92}\InprocServer32 -> C:\Users\Roman-E\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.20107.1\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files (x86)\Notepad++\NppShell_06.dll [2020-06-24] (Notepad++ -> )
ContextMenuHandlers4: [BotkindSyncShellExtension] -> {9E2E6460-89FF-452A-A9BA-E62EB80B8539} => C:\Program Files\Allway Sync\Bin\ShellExtension.dll [2020-04-07] () [File not signed]
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_edab19158bdd0d0a\nvshext.dll [2020-07-07] (NVIDIA Corporation -> NVIDIA Corporation)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

Shortcut: C:\Users\roman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DVDFab 10 (x64)\DVDFab (x64) Online.lnk -> hxxp://www.dvdfab.cn/?s=dvdfab10&p=x64&v=10.0.9.

==================== Loaded Modules (Whitelisted) =============

2020-05-09 16:22 - 2017-08-03 05:48 - 000237568 _____ () [File not signed] C:\Program Files (x86)\MSI\One Dragon Center\Mystic_Light\LEDControl.dll
2020-05-09 16:22 - 2019-09-27 14:08 - 000037376 _____ () [File not signed] C:\Program Files (x86)\MSI\One Dragon Center\Mystic_Light\Phison.dll
2019-06-28 10:51 - 2019-06-28 10:51 - 000184832 _____ () [File not signed] C:\Program Files\ENE\Aac_ENE_EHD_M2_HAL\AacHal_x86.dll
2018-10-05 10:13 - 2018-10-05 10:13 - 000144896 _____ () [File not signed] C:\Program Files\Logitech Gaming Software\LAClient\libssh2.dll
2018-10-05 10:13 - 2018-10-05 10:13 - 000077824 _____ () [File not signed] C:\Program Files\Logitech Gaming Software\LAClient\zlib.dll
2020-07-10 19:12 - 2020-07-10 19:12 - 000948736 _____ () [File not signed] C:\Program Files\WindowsApps\49297T.Partl.SpotBright_1.4.6.0_x64__jr9bq2af9farr\e_sqlite3.dll
2020-07-10 19:12 - 2020-07-10 19:12 - 011501056 _____ () [File not signed] C:\Program Files\WindowsApps\49297T.Partl.SpotBright_1.4.6.0_x64__jr9bq2af9farr\SpotBright.dll
2020-02-24 17:38 - 2020-02-24 17:38 - 000176128 _____ (ENE Technology inc.) [File not signed] C:\Program Files\ENE\Aac_ENE_EHD_SSS_HAL\AacHal_x86.dll
2020-07-02 18:44 - 2020-07-02 18:44 - 000000000 ____L (Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\AppVIsvSubsystems64.dll
2020-07-02 18:44 - 2020-07-02 18:44 - 000000000 ____L (Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\c2r64.dll
2020-05-09 16:20 - 2020-05-09 16:20 - 003610624 _____ (Micro-Star INT'L CO., LTD.) [File not signed] C:\Program Files\WindowsApps\9426MICRO-STARINTERNATION.DragonCenter_2.0.65.0_x64__kzh8wxbdkxb8p\DCv2\API_LiveUpdate_x64.dll
2020-05-09 16:22 - 2018-04-04 06:22 - 000053248 _____ (MS) [File not signed] C:\Program Files (x86)\MSI\One Dragon Center\Mystic_Light\MsIo32.dll
2020-05-09 16:22 - 2018-08-31 07:26 - 000053760 _____ (MS) [File not signed] C:\Program Files (x86)\MSI\One Dragon Center\Mystic_Light\MsIo32_Galax.dll
2020-06-27 14:57 - 2020-06-27 14:57 - 000317440 _____ (RaMMicHaeL) [File not signed] C:\Users\Roman-E\AppData\Roaming\7+ Taskbar Tweaker\inject.dll
2020-06-27 14:57 - 2020-06-27 14:57 - 000317440 _____ (RaMMicHaeL) [File not signed] C:\Users\roman\AppData\Roaming\7+ Taskbar Tweaker\inject.dll
2020-05-09 16:20 - 2020-05-09 16:20 - 001612800 _____ (Robert Simpson, et al.) [File not signed] C:\Program Files\WindowsApps\9426MICRO-STARINTERNATION.DragonCenter_2.0.65.0_x64__kzh8wxbdkxb8p\DCv2\SQLite.Interop.dll
2018-10-05 10:13 - 2018-10-05 10:13 - 000355840 _____ (The cURL library, hxxp://curl.haxx.se/) [File not signed] C:\Program Files\Logitech Gaming Software\LAClient\LIBCURL.dll
2018-10-05 10:13 - 2018-10-05 10:13 - 002286747 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files\Logitech Gaming Software\LAClient\LIBEAY32.dll
2018-10-05 10:13 - 2018-10-05 10:13 - 000416627 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files\Logitech Gaming Software\LAClient\SSLEAY32.dll
2018-04-06 20:29 - 2018-04-06 20:29 - 002286747 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files\Logitech Gaming Software\LIBEAY32.dll
2018-04-06 20:29 - 2018-04-06 20:29 - 000416627 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files\Logitech Gaming Software\ssleay32.dll
2020-05-09 16:23 - 2016-10-04 04:43 - 000399872 _____ (TODO: <公司名稱>) [File not signed] C:\Program Files (x86)\MSI\One Dragon Center\Mystic_Light\Lib\SDKDLL.dll

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

==================== Internet Explorer trusted/restricted ==========

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2019-03-19 06:49 - 2020-08-06 07:56 - 000001072 _____ C:\Windows\system32\drivers\etc\hosts
10.1.100.14 bitbucket.hq.eset.com
40.68.37.158 ssnm9hjpv0.database.windows.net
104.42.238.205 yz6e5noagd.database.windows.net
10.1.86.16 jira.hq.eset.com
10.1.86.17 confluence.hq.eset.com
10.1.81.180 mail.sk.eset.com
10.1.85.11 attendance

2020-07-22 18:18 - 2020-07-22 18:26 - 000000500 _____ C:\Windows\system32\drivers\etc\hosts.ics

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3360966048-3804889038-406055420-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\roman\AppData\Roaming\XnViewMP\\Wallpaper-2020-08-16_20-15.bmp
HKU\S-1-5-21-3360966048-3804889038-406055420-1003\Control Panel\Desktop\\Wallpaper -> C:\Users\Roman-E\AppData\Roaming\XnViewMP\\Wallpaper-2020-08-18_09-26.bmp
DNS Servers: 192.168.100.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\Run: => "Logitech Download Assistant"
HKU\S-1-5-21-3360966048-3804889038-406055420-1001\...\StartupApproved\Run: => "com.squirrel.Teams.Teams"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [TCP Query User{8D3A9936-D717-42CE-86C7-1B5EBD083D53}C:\users\roman\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\roman\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{6535A3A8-4023-49EB-9F0F-21BDB40C10E3}C:\users\roman\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\roman\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [TCP Query User{71463380-9F52-4B91-8742-5D41DDE3A599}C:\program files\jetbrains\jetbrains rider 2020.1.4\bin\rider64.exe] => (Allow) C:\program files\jetbrains\jetbrains rider 2020.1.4\bin\rider64.exe (JetBrains s.r.o. -> JetBrains s.r.o.)
FirewallRules: [UDP Query User{712947E4-20F7-4149-B0A5-0BEC79BD0CFA}C:\program files\jetbrains\jetbrains rider 2020.1.4\bin\rider64.exe] => (Allow) C:\program files\jetbrains\jetbrains rider 2020.1.4\bin\rider64.exe (JetBrains s.r.o. -> JetBrains s.r.o.)
FirewallRules: [TCP Query User{C45ADDD9-C232-4B20-9C33-6FFA675FB485}C:\users\roman\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\roman\appdata\local\microsoft\teams\current\teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [UDP Query User{977DFEC4-A659-47BE-AC8A-3635B9209D28}C:\users\roman\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\roman\appdata\local\microsoft\teams\current\teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{C4DCBE80-BE72-4B43-81D4-7CCD1C5943FB}] => (Allow) C:\Windows\system32\alg.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [TCP Query User{579AE8D5-BAD8-478C-85D4-B6D777ED34AF}C:\program files\dvdfab 10\dvdfab64.exe] => (Block) C:\program files\dvdfab 10\dvdfab64.exe (Fengtao Software Inc. -> FengTao Software Inc.)
FirewallRules: [UDP Query User{E1E42519-8F89-4E90-BEA7-C8F89604DD10}C:\program files\dvdfab 10\dvdfab64.exe] => (Block) C:\program files\dvdfab 10\dvdfab64.exe (Fengtao Software Inc. -> FengTao Software Inc.)
FirewallRules: [{790D0534-5D9C-4205-BFBD-A942AF99894A}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{65177136-F9E7-4343-A38C-E7E98584F351}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{B09BDE33-2EFF-480A-91B2-DC4C1AA33847}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{0588DE09-10D9-42BA-8524-896D482B873C}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{3369471B-AA14-4EAE-B8C4-9657FB93494A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Ori DE\oriDE.exe () [File not signed]
FirewallRules: [{4AC5E7A0-C0C4-4B89-9F80-107E5ED55CF0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Ori DE\oriDE.exe () [File not signed]
FirewallRules: [{62AB83D8-DB1A-4C08-BAE1-63D79BAB6522}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{88AD1DD0-5919-430E-9D06-C88FC5D4A747}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [TCP Query User{BC51A34D-E331-4A6D-AF3F-DED68E2AD2AD}C:\users\roman-e\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\roman-e\appdata\local\microsoft\teams\current\teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [UDP Query User{EB9D962A-40E3-4B72-8E22-09F63BFE375E}C:\users\roman-e\appdata\local\microsoft\teams\current\teams.exe] => (Allow) C:\users\roman-e\appdata\local\microsoft\teams\current\teams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{8594FD3E-0422-4FBB-A135-40FE4B4599F0}] => (Allow) C:\Program Files\Opera\69.0.3686.95\opera.exe (Opera Software AS -> Opera Software)
FirewallRules: [TCP Query User{1A14DA72-508B-4B14-992D-E73747CB97E5}M:\zaloha2\portable\opera\69.0.3686.95\opera.exe] => (Block) M:\zaloha2\portable\opera\69.0.3686.95\opera.exe => No File
FirewallRules: [UDP Query User{CCC0F44B-D6FA-4D36-B4C7-D99D46EF0632}M:\zaloha2\portable\opera\69.0.3686.95\opera.exe] => (Block) M:\zaloha2\portable\opera\69.0.3686.95\opera.exe => No File
FirewallRules: [{00418E4F-CB27-4B64-BCAA-5640E75E84B4}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{5B18E809-D7DB-48C6-89B3-454D6A9AD60B}C:\totalcmd\totalcmd64.exe] => (Allow) C:\totalcmd\totalcmd64.exe (Ghisler Software GmbH -> Ghisler Software GmbH)
FirewallRules: [UDP Query User{9496E34A-23BE-4AEB-8AE3-03B811CE5949}C:\totalcmd\totalcmd64.exe] => (Allow) C:\totalcmd\totalcmd64.exe (Ghisler Software GmbH -> Ghisler Software GmbH)
FirewallRules: [TCP Query User{A0F5B2F2-0FCB-45FD-AE03-C95C5A81FD72}C:\users\roman-e\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\roman-e\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{F63053D0-4787-44F7-B4B3-7E917CCA9040}C:\users\roman-e\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\roman-e\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{36ED285E-411B-4AD0-91FF-4D7CBC684C30}] => (Allow) C:\Program Files\WindowsApps\MUSIXMATCH.LYRICS_3.14.4564.0_x86__7gejyv32yt3te\app\Musixmatch.exe (Musixmatch) [File not signed]
FirewallRules: [{C68754E5-B9B7-4F06-AD50-C064C5779A07}] => (Allow) C:\Program Files\WindowsApps\MUSIXMATCH.LYRICS_3.14.4564.0_x86__7gejyv32yt3te\app\Musixmatch.exe (Musixmatch) [File not signed]
FirewallRules: [{080DAE5D-19DA-4F8B-8F35-4351E574A219}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{757C78A2-8C12-4389-BF0E-713B7F0D77A8}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{AF954EFB-7CEF-4CFC-B3DE-AB2F353D05E2}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{3D03D4AD-2B7C-4884-BA99-7A4F0D56093B}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{7C904C7A-D72B-44DD-A8A6-58DEFC0047A7}] => (Allow) C:\Program Files\Opera\70.0.3728.106\opera.exe (Opera Software AS -> Opera Software)
FirewallRules: [TCP Query User{1B228C73-F5F4-49BD-BEB2-A222A10FFF75}M:\zaloha2\portable\opera\70.0.3728.106\opera.exe] => (Allow) M:\zaloha2\portable\opera\70.0.3728.106\opera.exe => No File
FirewallRules: [UDP Query User{FD898292-521F-4008-9379-B4B423167199}M:\zaloha2\portable\opera\70.0.3728.106\opera.exe] => (Allow) M:\zaloha2\portable\opera\70.0.3728.106\opera.exe => No File
FirewallRules: [TCP Query User{F1CD5975-F78F-4A3D-909A-D6D12E34CB6F}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe (Logitech Inc -> Logitech Inc.)
FirewallRules: [UDP Query User{D710FB2D-F565-46C7-912C-E9DC42BDD338}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe (Logitech Inc -> Logitech Inc.)
FirewallRules: [{C4C8803E-A8E8-4834-BD22-DF5625841917}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{91B05DF4-2C49-422E-A4D1-213CAADF389F}] => (Allow) LPort=32682

==================== Restore Points =========================

20-08-2020 18:38:55 Scheduled Checkpoint
24-08-2020 19:19:13 Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501
24-08-2020 19:19:21 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501

==================== Faulty Device Manager Devices ============

Name: PCI Device
Description: PCI Device
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: PCI Encryption/Decryption Controller
Description: PCI Encryption/Decryption Controller
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: PCI Device
Description: PCI Device
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: ========================

Application errors:
==================
Error: (08/23/2020 07:21:00 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: WMPRemoteStandalone.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.NullReferenceException
   at WMPRemoteStandalone.Program+<>c__DisplayClass0_0.<Main>b__0()
   at System.Threading.ThreadHelper.ThreadStart_Context(System.Object)
   at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
   at System.Threading.ThreadHelper.ThreadStart()

Error: (08/13/2020 03:16:02 PM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: FRACTAL)
Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code.

Error: (08/13/2020 03:15:58 PM) (Source: Microsoft-Windows-Perflib) (EventID: 1018) (User: FRACTAL)
Description: Disabled performance counter data collection for this session from the "ASP.NET_2.0.50727" service because the performance counter library for that service has generated one or more errors. The errors that forced this action have been written to the application event log.

Error: (08/13/2020 03:15:58 PM) (Source: Microsoft-Windows-Perflib) (EventID: 1021) (User: FRACTAL)
Description: Windows cannot open the 32-bit extensible counter DLL "C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_perf.dll" in a 64-bit environment (Win32 error code 193). Contact the file vendor to obtain a 64-bit version. Alternatively, you can open the 32-bit extensible counter DLL by using the 32-bit version of Performance Monitor. To use this tool, open the Windows folder, open the Syswow64 folder, and then start Perfmon.exe.

Error: (08/13/2020 02:27:17 PM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: FRACTAL)
Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code.

Error: (08/13/2020 02:27:13 PM) (Source: Microsoft-Windows-Perflib) (EventID: 1018) (User: FRACTAL)
Description: Disabled performance counter data collection for this session from the "ASP.NET_2.0.50727" service because the performance counter library for that service has generated one or more errors. The errors that forced this action have been written to the application event log.

Error: (08/13/2020 02:27:13 PM) (Source: Microsoft-Windows-Perflib) (EventID: 1021) (User: FRACTAL)
Description: Windows cannot open the 32-bit extensible counter DLL "C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_perf.dll" in a 64-bit environment (Win32 error code 193). Contact the file vendor to obtain a 64-bit version. Alternatively, you can open the 32-bit extensible counter DLL by using the 32-bit version of Performance Monitor. To use this tool, open the Windows folder, open the Syswow64 folder, and then start Perfmon.exe.

Error: (08/13/2020 09:35:18 AM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: FRACTAL)
Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code.


System errors:
=============
Error: (08/26/2020 11:27:58 AM) (Source: DCOM) (EventID: 10010) (User: FRACTAL)
Description: The server Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c!App.AppXtwmqn4em5r5dpafgj4t4yyxgjfe0hr50.mca did not register with DCOM within the required timeout.

Error: (08/26/2020 11:27:37 AM) (Source: DCOM) (EventID: 10010) (User: FRACTAL)
Description: The server Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c!App.AppXtwmqn4em5r5dpafgj4t4yyxgjfe0hr50.mca did not register with DCOM within the required timeout.

Error: (08/26/2020 11:02:18 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 10:22:10 on ‎26/‎08/‎2020 was unexpected.

Error: (08/26/2020 07:43:00 AM) (Source: DCOM) (EventID: 10010) (User: FRACTAL)
Description: The server Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c!App.AppXtwmqn4em5r5dpafgj4t4yyxgjfe0hr50.mca did not register with DCOM within the required timeout.

Error: (08/26/2020 07:42:25 AM) (Source: DCOM) (EventID: 10010) (User: FRACTAL)
Description: The server Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c!App.AppXtwmqn4em5r5dpafgj4t4yyxgjfe0hr50.mca did not register with DCOM within the required timeout.

Error: (08/26/2020 07:40:57 AM) (Source: DCOM) (EventID: 10010) (User: FRACTAL)
Description: The server Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c!App.AppXtwmqn4em5r5dpafgj4t4yyxgjfe0hr50.mca did not register with DCOM within the required timeout.

Error: (08/26/2020 07:40:31 AM) (Source: DCOM) (EventID: 10010) (User: FRACTAL)
Description: The server Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c!App.AppXtwmqn4em5r5dpafgj4t4yyxgjfe0hr50.mca did not register with DCOM within the required timeout.

Error: (08/25/2020 10:15:36 PM) (Source: DCOM) (EventID: 10010) (User: FRACTAL)
Description: The server Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c!App.AppXtwmqn4em5r5dpafgj4t4yyxgjfe0hr50.mca did not register with DCOM within the required timeout.


Windows Defender:
===================================
Date: 2020-08-14 08:07:21.661
Description: 
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {99A50054-9D1E-4113-BB89-4B4B99D08EED}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2020-08-10 18:08:07.528
Description: 
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {055ADDED-2437-4799-8672-C0FDA7308D8F}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2020-07-27 19:47:09.959
Description: 
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {60CBBC4F-66FD-45F9-820D-FF06652B7E3D}
Scan Type: Antimalware
Scan Parameters: Quick Scan

CodeIntegrity:
===================================

Date: 2020-08-13 07:53:08.387
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\FlightSettings.dll because the set of per-page image hashes could not be found on the system.

Date: 2020-08-13 07:53:08.382
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\FlightSettings.dll because the set of per-page image hashes could not be found on the system.

Date: 2020-08-13 07:53:08.317
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\FlightSettings.dll because the set of per-page image hashes could not be found on the system.

Date: 2020-08-13 07:53:08.312
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\FlightSettings.dll because the set of per-page image hashes could not be found on the system.

Date: 2020-08-13 07:53:08.306
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\dsreg.dll because the set of per-page image hashes could not be found on the system.

Date: 2020-08-13 07:53:08.302
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\dsreg.dll because the set of per-page image hashes could not be found on the system.

Date: 2020-08-13 07:53:07.987
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\aepic.dll because the set of per-page image hashes could not be found on the system.

Date: 2020-08-13 07:53:07.970
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\aepic.dll because the set of per-page image hashes could not be found on the system.

==================== Memory info =========================== 

BIOS: American Megatrends Inc. 3.50 11/07/2019
Motherboard: Micro-Star International Co., Ltd B450 TOMAHAWK MAX (MS-7C02)
Processor: AMD Ryzen 7 3700X 8-Core Processor 
Percentage of memory in use: 25%
Total physical RAM: 32717.04 MB
Available physical RAM: 24279.66 MB
Total Virtual: 37581.04 MB
Available Virtual: 25583.14 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:953.24 GB) (Free:434.4 GB) NTFS
Drive d: (Data) (Fixed) (Total:931.51 GB) (Free:356.21 GB) NTFS
Drive j: (Storage) (Fixed) (Total:1863.01 GB) (Free:1169.6 GB) NTFS
Drive t: (Data5) (Fixed) (Total:368.1 GB) (Free:217.74 GB) NTFS
Drive v: (Video) (Fixed) (Total:2794.39 GB) (Free:277.88 GB) NTFS

\\?\Volume{b76b30df-0000-0000-0000-100000000000}\ (WorkData) (Fixed) (Total:97.66 GB) (Free:78.51 GB) NTFS
\\?\Volume{d8a0bca7-67c9-46d1-abfb-e49d0c049afb}\ (Recovery) (Fixed) (Total:0.52 GB) (Free:0.08 GB) NTFS
\\?\Volume{00e72a5c-b3f6-46bd-aa98-71085d03bcab}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Partition Table ====================

==================== End of Addition.txt =======================