Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-11-2020
Ran by Anjela (03-11-2020 01:17:46)
Running from C:\Users\Anjela\Desktop
Windows 8.1 Connected (Update) (X64) (2015-09-12 20:26:56)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-698779785-4081944849-852420755-500 - Administrator - Disabled)
Anjela (S-1-5-21-698779785-4081944849-852420755-1001 - Administrator - Enabled) => C:\Users\Anjela
Guest (S-1-5-21-698779785-4081944849-852420755-501 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Avast Antivirus (Disabled - Up to date) {EB19B86E-3998-C706-90EF-92B41EB091AF}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Disabled - Up to date) {5078598A-1FA2-C888-AA5F-A9C66537DB12}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 20.012.20048 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 18.0.0.199 - Adobe Systems Incorporated)
Adobe Flash Player 32 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 32.0.0.192 - Adobe)
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 20.8.2432 - Avast Software)
ČSOBP Kalkulátory 1.27.0.x (HKLM-x32\...\Kalkulátory_is1) (Version:  - )
Elements (HKU\S-1-5-21-698779785-4081944849-852420755-1001\...\Elements Browser) (Version: 64.25.3282.140 - The Elements Authors)
eModel - MetLife (HKU\S-1-5-21-698779785-4081944849-852420755-1001\...\eModel) (Version: 3.0.0.22 - MetLife)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 86.0.4240.183 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.36.31 - Google LLC) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.169 - Google Inc.) Hidden
Herramientas de corrección de Microsoft Office 2016: español (HKLM-x32\...\{90160000-001F-0C0A-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Intel Security True Key (HKLM\...\TrueKey) (Version: 4.4.135.1 - Intel Security)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3496 - Intel Corporation)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology(patch version 17.0.1347.2) (HKLM\...\{302600C1-6BDF-4FD1-1312-148929CC1385}) (Version: 17.0.1312.0414 - Intel Corporation)
Intel(R) Sideband Fabric Device Driver (HKLM-x32\...\C5A8BC6E-723A-4C0F-96E1-C426D1A4BCA9) (Version: 1.0.0.1002 - Intel Corporation)
Intel(R) Trusted Execution Engine (HKLM\...\{176E2755-0A17-42C6-88E2-192AB2131278}) (Version: 1.0.0.1064 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{2f4d8103-e601-4d48-b81d-d508d760aaba}) (Version: 17.0.3 - Intel Corporation)
Lenovo EasyCamera (HKLM-x32\...\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}) (Version: 6.0.1321.0_WHQL - Sonix)
Malwarebytes version 4.2.1.89 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.2.1.89 - Malwarebytes)
Metric Collection SDK 35 (HKLM-x32\...\{C2B5B5B0-2545-4E94-B4BA-548D4BF0B196}) (Version: 1.2.0001.00 - Lenovo Group Limited) Hidden
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Office Professional Plus 2016 (HKLM-x32\...\Office16.PROPLUS) (Version: 16.0.4266.1001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Outils de vérification linguistique 2016 de Microsoft Office - Français (HKLM-x32\...\{90160000-001F-040C-0000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9600.39053 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.20.815.2013 - Realtek)
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.93450 - TeamViewer)
Viber (HKLM-x32\...\{73684132-A91A-4BC2-8449-83D15CA2BAAD}) (Version: 6.7.0.1082 - Viber Media Inc.) Hidden
Viber (HKU\S-1-5-21-698779785-4081944849-852420755-1001\...\{6cab77d1-a9f3-4365-a5e3-077a88666259}) (Version: 6.7.0.1082 - Viber Media Inc.)
WhatsApp (HKU\S-1-5-21-698779785-4081944849-852420755-1001\...\WhatsApp) (Version: 0.3.2276 - WhatsApp)
WinRAR 5.21 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
Zoom (HKU\S-1-5-21-698779785-4081944849-852420755-1001\...\ZoomUMX) (Version: 5.4.1 (58698.1027) - Zoom Video Communications, Inc.)

Packages:
=========
Skype -> C:\Program Files\WindowsApps\Microsoft.SkypeApp_3.1.0.1016_x86__kzf8qxf38zg5c [2015-09-14] (Skype) [MS Ad]
Translator -> C:\Program Files\WindowsApps\Microsoft.BingTranslator_1.17.0.0_x64__8wekyb3d8bbwe [2016-06-15] (Microsoft Corporation)
Viber - Free Phone Calls & Text -> C:\Program Files\WindowsApps\2414FC7A.Viber-FreePhoneCallsText_4.1.3.0_x86__p61zvh252yqyr [2016-02-27] (VIBER MEDIA S.à r.l.)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-698779785-4081944849-852420755-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\windows\system32\igfxEM.exe (Intel Corporation - Software and Firmware Products -> Intel Corporation)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-10-26] (Avast Software s.r.o. -> AVAST Software)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-10-26] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-10-26] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2015-02-15] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2015-02-15] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-10-26] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-09-06] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\windows\system32\igfxDTCM.dll [2014-03-07] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers5: [igfxOSP] -> {FA507C3F-30C6-4DCA-9EE5-2656072EEC14} => C:\windows\system32\igfxOSP.dll [2014-03-07] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-10-26] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-09-06] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2015-02-15] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2015-02-15] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

2016-07-23 15:49 - 2016-07-23 15:49 - 000274944 _____ (hxxp://system.data.sqlite.org/) [File not signed] [File is in use] C:\Program Files\TrueKey\System.Data.SQLite.dll
2016-07-23 15:49 - 2016-07-23 15:49 - 000415744 _____ (NLog) [File not signed] [File is in use] C:\Program Files\TrueKey\NLog.dll
2016-07-23 15:49 - 2016-07-23 15:49 - 001148928 _____ (Robert Simpson, et al.) [File not signed] C:\Program Files\TrueKey\SQLite.Interop.dll
2016-07-23 15:49 - 2016-07-23 15:49 - 000052736 _____ (The Apache Software Foundation) [File not signed] [File is in use] C:\Program Files\TrueKey\Thrift.dll

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) ==========

HKU\S-1-5-21-698779785-4081944849-852420755-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://search.gmx.com/start?src=p_jkld_pl&p=jkld&p_brw=ie&p_mkt=cz&p_tsrc=301&p_w=y1w07
HKU\S-1-5-21-698779785-4081944849-852420755-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com/?pc=LCJB
SearchScopes: HKU\S-1-5-21-698779785-4081944849-852420755-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?PC=WCUG&FORM=WCUGDF&q={searchTerms}
SearchScopes: HKU\S-1-5-21-698779785-4081944849-852420755-1001 -> 8AEE70024EACC8AFA61F8D2C1B03DA61 URL = hxxp://www.mapy.cz/?sourceid=quicksearch_6826&query={searchTerms}
SearchScopes: HKU\S-1-5-21-698779785-4081944849-852420755-1001 -> 90AD33DA452E93B1D46010102BF212F2 URL = hxxp://www.zbozi.cz/?sourceid=quicksearch_6826&q={searchTerms}
SearchScopes: HKU\S-1-5-21-698779785-4081944849-852420755-1001 -> B4E392082348B02800D21B859C43BE12 URL = hxxp://www.firmy.cz/phr/{searchTerms}
SearchScopes: HKU\S-1-5-21-698779785-4081944849-852420755-1001 -> DA1AEDB063FE2B93AD9D9A1040B7D360 URL = hxxp://videa.seznam.cz/?q={searchTerms}
SearchScopes: HKU\S-1-5-21-698779785-4081944849-852420755-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?PC=WCUG&FORM=WCUGDF&q={searchTerms}
Handler-x32: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)

(If an entry is included in the fixlist, it will be removed from the registry.)

IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com

There are 7869 more sites.

IE restricted site: HKU\S-1-5-21-698779785-4081944849-852420755-1001\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-698779785-4081944849-852420755-1001\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-698779785-4081944849-852420755-1001\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-698779785-4081944849-852420755-1001\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-698779785-4081944849-852420755-1001\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-698779785-4081944849-852420755-1001\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-698779785-4081944849-852420755-1001\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-698779785-4081944849-852420755-1001\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-698779785-4081944849-852420755-1001\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-698779785-4081944849-852420755-1001\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-698779785-4081944849-852420755-1001\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-698779785-4081944849-852420755-1001\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-698779785-4081944849-852420755-1001\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-698779785-4081944849-852420755-1001\...\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-698779785-4081944849-852420755-1001\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-698779785-4081944849-852420755-1001\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-698779785-4081944849-852420755-1001\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-698779785-4081944849-852420755-1001\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-698779785-4081944849-852420755-1001\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-698779785-4081944849-852420755-1001\...\123simsen.com -> www.123simsen.com

There are 7869 more sites.


==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2017-05-18 08:10 - 2020-11-01 21:35 - 000000027 _____ C:\windows\system32\drivers\etc\hosts
127.0.0.1       localhost

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Intel\TXE Components\TCS\;C:\Program Files\Intel\TXE Components\TCS\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\
HKU\S-1-5-21-698779785-4081944849-852420755-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Anjela\Desktop\viber_image_2019-09-08_09-16-38.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\Run32: => "Adobe ARM"
HKU\S-1-5-21-698779785-4081944849-852420755-1001\...\StartupApproved\Run: => "CCleaner Monitoring"
HKU\S-1-5-21-698779785-4081944849-852420755-1001\...\StartupApproved\Run: => "Viber"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{14C5E3A4-F495-45C4-A741-9BCDE7DF72D2}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{24A8114D-A13E-40B8-B3B5-AD7C44EE167C}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{ABE54B77-0C06-4CCB-A493-DCB8E2C4C0C4}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{5AA0201B-2F49-4455-8331-2F7F1C52BA30}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{1F2E986D-237E-4DC9-A3D8-19D315C1DDF6}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{8D4E6BBB-93B2-4854-BE8B-AB0DF1B94693}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{666B2ADE-8431-44EA-B387-92C7EB731748}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{78126CAA-3B51-4B50-9E0A-52DF11DF6F13}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{23001BF6-B0AF-4A57-8D6B-B297C6F40AD9}] => (Allow) C:\Users\Anjela\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{DE48DEEA-A057-4AAD-8251-F97E7EE541AD}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)

==================== Restore Points =========================

07-10-2020 16:01:02 Naplánovaný kontrolní bod
22-10-2020 14:53:15 Naplánovaný kontrolní bod
29-10-2020 19:05:33 Naplánovaný kontrolní bod

==================== Faulty Device Manager Devices ============

Name: 
Description: 
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: ========================

Application errors:
==================
Error: (11/03/2020 12:41:45 AM) (Source: TrueKey) (EventID: 0) (User: )
Description: Zpracování změny relace se nezdařilo. System.ArgumentException: Data Source cannot be empty.  Use :memory: to open an in-memory database
   v System.Data.SQLite.SQLiteConnection.Open()
   v McAfee.YAP.Service.Data.McBioSQLite.GetConnection()
   v McAfee.YAP.Service.Data.McBioSQLite.StoreInServiceInfo(String key, String value)
   v McAfee.YAP.Service.Data.McBioSQLite.StoreSpoofing(String value)
   v McAfee.YAP.Service.Common.McBioBCAService.DisableSpoofingMode()
   v McAfee.YAP.Service.Service.OnSessionChange(SessionChangeDescription changeDescription)
   v System.ServiceProcess.ServiceBase.DeferredSessionChange(Int32 eventType, Int32 sessionId)

Error: (11/02/2020 08:28:18 PM) (Source: TrueKey) (EventID: 0) (User: )
Description: Zpracování změny relace se nezdařilo. System.ArgumentException: Data Source cannot be empty.  Use :memory: to open an in-memory database
   v System.Data.SQLite.SQLiteConnection.Open()
   v McAfee.YAP.Service.Data.McBioSQLite.GetConnection()
   v McAfee.YAP.Service.Data.McBioSQLite.StoreInServiceInfo(String key, String value)
   v McAfee.YAP.Service.Data.McBioSQLite.StoreSpoofing(String value)
   v McAfee.YAP.Service.Common.McBioBCAService.DisableSpoofingMode()
   v McAfee.YAP.Service.Service.OnSessionChange(SessionChangeDescription changeDescription)
   v System.ServiceProcess.ServiceBase.DeferredSessionChange(Int32 eventType, Int32 sessionId)

Error: (11/02/2020 08:21:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe_PcaSvc, verze: 6.3.9600.17415, časové razítko: 0x54504177
Název chybujícího modulu: ntdll.dll, verze: 6.3.9600.18233, časové razítko: 0x56bb4ebb
Kód výjimky: 0xc0000008
Posun chyby: 0x00000000000925fa
ID chybujícího procesu: 0x828
Čas spuštění chybující aplikace: 0x01d6b14c799b6fa0
Cesta k chybující aplikaci: C:\windows\System32\svchost.exe
Cesta k chybujícímu modulu: C:\windows\SYSTEM32\ntdll.dll
ID zprávy: a573b263-1d40-11eb-8333-68f7280bcc29
Úplný název chybujícího balíčku: 
ID aplikace související s chybujícím balíčkem:

Error: (11/02/2020 08:17:00 PM) (Source: LenovoWiFiHotspotSvr) (EventID: 1) (User: )
Description: LenovoWiFiHotspotSvrm_WlanMgr stop HN error. failed with 0

Error: (11/02/2020 08:17:00 PM) (Source: PhoneCompanionVap_WLAN) (EventID: 1) (User: )
Description: Event-ID 1

Error: (11/02/2020 08:14:59 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe_PcaSvc, verze: 6.3.9600.17415, časové razítko: 0x54504177
Název chybujícího modulu: ntdll.dll, verze: 6.3.9600.18233, časové razítko: 0x56bb4ebb
Kód výjimky: 0xc0000008
Posun chyby: 0x00000000000925fa
ID chybujícího procesu: 0x408
Čas spuštění chybující aplikace: 0x01d6b1468d85ce23
Cesta k chybující aplikaci: C:\windows\System32\svchost.exe
Cesta k chybujícímu modulu: C:\windows\SYSTEM32\ntdll.dll
ID zprávy: b2e1dc7b-1d3f-11eb-8333-68f7280bcc29
Úplný název chybujícího balíčku: 
ID aplikace související s chybujícím balíčkem:

Error: (11/01/2020 09:54:14 PM) (Source: TrueKey) (EventID: 0) (User: )
Description: Zpracování změny relace se nezdařilo. System.ArgumentException: Data Source cannot be empty.  Use :memory: to open an in-memory database
   v System.Data.SQLite.SQLiteConnection.Open()
   v McAfee.YAP.Service.Data.McBioSQLite.GetConnection()
   v McAfee.YAP.Service.Data.McBioSQLite.StoreInServiceInfo(String key, String value)
   v McAfee.YAP.Service.Data.McBioSQLite.StoreSpoofing(String value)
   v McAfee.YAP.Service.Common.McBioBCAService.DisableSpoofingMode()
   v McAfee.YAP.Service.Service.OnSessionChange(SessionChangeDescription changeDescription)
   v System.ServiceProcess.ServiceBase.DeferredSessionChange(Int32 eventType, Int32 sessionId)

Error: (11/01/2020 09:49:04 PM) (Source: TrueKey) (EventID: 0) (User: )
Description: Zpracování změny relace se nezdařilo. System.ArgumentException: Data Source cannot be empty.  Use :memory: to open an in-memory database
   v System.Data.SQLite.SQLiteConnection.Open()
   v McAfee.YAP.Service.Data.McBioSQLite.GetConnection()
   v McAfee.YAP.Service.Data.McBioSQLite.StoreInServiceInfo(String key, String value)
   v McAfee.YAP.Service.Data.McBioSQLite.StoreSpoofing(String value)
   v McAfee.YAP.Service.Common.McBioBCAService.DisableSpoofingMode()
   v McAfee.YAP.Service.Service.OnSessionChange(SessionChangeDescription changeDescription)
   v System.ServiceProcess.ServiceBase.DeferredSessionChange(Int32 eventType, Int32 sessionId)


System errors:
=============
Error: (11/03/2020 12:41:08 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba RalinkRegistryWriter neuspěla při spuštění v důsledku následující chyby: 
Systém nemůže nalézt uvedený soubor.

Error: (11/03/2020 12:40:25 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: Rozšiřující modul sítě WLAN byl neočekávaně ukončen.

Cesta k modulu: C:\windows\System32\IWMSSvc.dll

Error: (11/03/2020 12:40:25 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: Rozšiřující modul sítě WLAN byl neočekávaně ukončen.

Cesta k modulu: C:\windows\System32\IWMSSvc.dll

Error: (11/03/2020 12:40:21 AM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: Správce služeb se pokusil o opravnou akci (Restartovat službu) po nečekaném ukončení služby Windows Search, ale tato akce selhala kvůli následující chybě: 
Instance této služby je již spuštěna.

Error: (11/03/2020 12:40:09 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: Rozšiřující modul sítě WLAN byl neočekávaně ukončen.

Cesta k modulu: C:\windows\System32\IWMSSvc.dll

Error: (11/03/2020 12:39:50 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Windows Search byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 30000 milisekund: Restartovat službu.

Error: (11/03/2020 12:39:50 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Služba Windows Media Player Network Sharing byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 30000 milisekund: Restartovat službu.

Error: (11/03/2020 12:39:50 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Intel Security True Key Scheduler byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 0 milisekund: Restartovat službu.


Windows Defender:
===================================
Date: 2017-05-06 15:58:41.129
Description: 
Vyhledávání Windows Defender bylo zastaveno před dokončením.
ID vyhledávání: {FE359264-E121-41FF-94EC-E99C8C207DA6}
Typ vyhledávání: Antimalwarový program
Parametry vyhledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2017-05-06 10:30:16.798
Description: 
Vyhledávání Windows Defender bylo zastaveno před dokončením.
ID vyhledávání: {6F212381-5F60-47D2-B129-CF36F27EEADB}
Typ vyhledávání: Antimalwarový program
Parametry vyhledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2017-05-06 09:50:22.908
Description: 
Windows Defender Funkce ochrany v reálném čase zjistila chybu a nezdařila se.
Funkce: Systém kontroly sítě
Kód chyby: 0x80070002
Popis chyby: Systém nemůže nalézt uvedený soubor. 
Důvod: V systému chybí aktualizace potřebné ke spuštění systému pro kontrolu sítě.  Nainstalujte požadované aktualizace a restartujte počítač.

Date: 2017-05-05 18:38:54.405
Description: 
Program Windows Defender zjistil chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu: 
Předchozí verze podpisu: 0.0.0.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ podpisu: Systém kontroly sítě
Typ aktualizace: Úplné
Uživatel: Anjela-PC\Anjela
Aktuální verze modulu: 
Předchozí verze modulu: 0.0.0.0
Kód chyby: 0x80072ee7
Popis chyby: Nelze rozpoznat název nebo adresu serveru. 

Date: 2017-05-05 18:38:54.373
Description: 
Program Windows Defender zjistil chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu: 
Předchozí verze podpisu: 0.0.0.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ podpisu: Antispywarový program
Typ aktualizace: Úplné
Uživatel: Anjela-PC\Anjela
Aktuální verze modulu: 
Předchozí verze modulu: 0.0.0.0
Kód chyby: 0x80072ee7
Popis chyby: Nelze rozpoznat název nebo adresu serveru. 

Date: 2017-05-05 18:38:54.371
Description: 
Program Windows Defender zjistil chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu: 
Předchozí verze podpisu: 0.0.0.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: Anjela-PC\Anjela
Aktuální verze modulu: 
Předchozí verze modulu: 0.0.0.0
Kód chyby: 0x80072ee7
Popis chyby: Nelze rozpoznat název nebo adresu serveru. 

Date: 2017-05-05 18:38:54.330
Description: 
Program Windows Defender zjistil chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu: 
Předchozí verze podpisu: 0.0.0.0
Zdroj aktualizace: Server Microsoft Update
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu: 
Předchozí verze modulu: 0.0.0.0
Kód chyby: 0x8024402c
Popis chyby: Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře. 

CodeIntegrity:
===================================

Date: 2018-02-21 08:25:14.424
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.

Date: 2018-02-21 08:25:13.374
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.

Date: 2018-02-21 08:25:12.108
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.

Date: 2018-02-21 08:25:11.093
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.

Date: 2018-02-21 08:25:10.108
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.

Date: 2018-02-21 08:25:09.103
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.

Date: 2018-02-21 08:25:08.100
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.

Date: 2018-02-21 08:25:07.065
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.

==================== Memory info =========================== 

BIOS: LENOVO A7CN40WW 07/18/2014
Motherboard: LENOVO Lancer 5A6
Processor: Intel(R) Celeron(R) CPU N2840 @ 2.16GHz
Percentage of memory in use: 39%
Total physical RAM: 3979.21 MB
Available physical RAM: 2419.78 MB
Total Virtual: 5387.21 MB
Available Virtual: 3491.71 MB

==================== Drives ================================

Drive c: (Windows8_OS) (Fixed) (Total:425.14 GB) (Free:349.99 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:24.53 GB) NTFS

\\?\Volume{3d43015c-eced-43bb-82fb-a07fcc0d1749}\ (WINRE_DRV) (Fixed) (Total:0.98 GB) (Free:0.64 GB) NTFS
\\?\Volume{0554686e-3df1-46c6-80c4-4603d8c58bc5}\ (PBR_DRV) (Fixed) (Total:13.29 GB) (Free:4.18 GB) NTFS

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 9A92D935)

Partition: GPT.

==================== End of Addition.txt =======================