Additional scan result of Farbar Recovery Scan Tool (x64) Version: 30-01-2022
Ran by D (30-01-2022 15:44:32)
Running from C:\Users\D\Desktop
Microsoft Windows 10 Pro Version 21H2 19044.1503 (X64) (2020-09-01 13:08:59)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================


(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-3879116872-396271162-1637455061-500 - Administrator - Disabled)
D (S-1-5-21-3879116872-396271162-1637455061-1001 - Administrator - Enabled) => C:\Users\D
DefaultAccount (S-1-5-21-3879116872-396271162-1637455061-503 - Limited - Disabled)
Guest (S-1-5-21-3879116872-396271162-1637455061-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-3879116872-396271162-1637455061-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

. . (HKLM\...\{EAA6C597-BD0D-454D-AEB7-FF0A57905C1C}) (Version: 7.1 - Intel) Hidden
. . . (HKLM-x32\...\{8CBC102C-34F4-4EB9-9529-3B222367621F}) (Version: 3.7.0.6 - Intel) Hidden
64 Bit HP CIO Components Installer (HKLM\...\{13DA9C7C-EBFB-40D0-94A1-55B42883DF21}) (Version: 21.2.1 - HP Inc.) Hidden
Active@ KillDisk 11 (HKLM\...\{0218BA4B-0594-40E2-B3C6-40A859A348FF}_is1) (Version: 11 - LSoft Technologies Inc)
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 21.011.20039 - Adobe Systems Incorporated)
AMD Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD)
AMD Catalyst Install Manager (HKLM\...\{66AFB595-BC05-2913-7696-6D58F9B733E1}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
ANT Drivers Installer x64 (HKLM\...\{AB7F8484-10C7-430B-8062-BA4D840BC328}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
Any Video Converter 6.2.3 (HKLM-x32\...\Any Video Converter) (Version: 6.2.3 - Anvsoft)
Avidemux VC++ 64bits (HKU\S-1-5-21-3879116872-396271162-1637455061-1001\...\{2168895a-8c41-422b-a734-b51c43afe1fa}) (Version: 2.7.5 - Mean)
Balíček ovladače systému Windows - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Balíček ovladače systému Windows - SIGMA Elektro GmbH (usbser) Ports  (02/20/2017 1.7.0000.0000) (HKLM\...\F11095F081576CA0F709F279E5FC84AC50628B78) (Version: 02/20/2017 1.7.0000.0000 - SIGMA Elektro GmbH)
Balíček ovladače systému Windows - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
CMS (HKLM-x32\...\CMS) (Version:  - )
CrystalDiskInfo 7.7.0 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 7.7.0 - Crystal Dew World)
CrystalDiskMark 6.0.2 (HKLM\...\CrystalDiskMark6_is1) (Version: 6.0.2 - Crystal Dew World)
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Data Lifeguard Diagnostic for Windows 1.31 (HKLM-x32\...\{519C4DB6-B53B-4F5C-8297-89B2BE949FA5}_is1) (Version:  - Western Digital Corporation)
EaseUS Partition Master 13.0 (HKLM-x32\...\EaseUS Partition Master_is1) (Version:  - EaseUS)
EaseUS Todo Backup Free 12.0 (HKLM-x32\...\EaseUS Todo Backup_is1) (Version: 12.0 - CHENGDU YIWO Tech Development Co., Ltd)
Elevated Installer (HKLM-x32\...\{917F39C7-FBD3-45F2-99DF-3A97EB981D5D}) (Version: 7.11.0.0 - Garmin Ltd or its subsidiaries) Hidden
FileZilla Client 3.45.1 (HKLM-x32\...\FileZilla Client) (Version: 3.45.1 - Tim Kosse)
Fotogalerie (HKLM-x32\...\{F37D360D-9308-4BB1-8515-DC6B637B9486}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Garmin Express (HKLM-x32\...\{3e2be2c6-99a0-4538-8f40-231106165750}) (Version: 7.11.0.0 - Garmin Ltd or its subsidiaries)
Garmin Express (HKLM-x32\...\{A0D75BFE-F68C-450A-8353-C42A3F264BED}) (Version: 7.11.0.0 - Garmin Ltd or its subsidiaries) Hidden
GIMP 2.10.24 (HKLM\...\GIMP-2_is1) (Version: 2.10.24 - The GIMP Team)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 97.0.4692.99 - Google LLC)
HDClone 4 Professional Edition (HKLM-x32\...\HDClone.Professional.4.0.4.1033-{E686620F-2485-4932-9BDF-8F22ED91B2FB}) (Version:  - )
hubiC - x64 (HKLM\...\{CE2A3177-F286-4F6A-9694-DE8EED87D583}) (Version: 2.1.1.145 - OVH) Hidden
hubiC (HKLM-x32\...\{51fea8cc-5bb6-4312-86f5-1802a10e030d}) (Version: 2.1.1.145 - OVH)
HWiNFO64 Version 6.26 (HKLM\...\HWiNFO64_is1) (Version: 6.26 - Martin Malik - REALiX)
Intel(R) Computing Improvement Program (HKLM\...\{44C40B2E-7285-4A9F-A9BC-DF433772AAEE}) (Version: 2.4.05929 - Intel Corporation)
Intel® Driver & Support Assistant (HKLM-x32\...\{f0bbb6e9-80c3-4fe8-8691-b51d1281d69e}) (Version: 3.7.0.6 - Intel)
IrfanView 4.54 (64-bit) (HKLM\...\IrfanView64) (Version: 4.54 - Irfan Skiljan)
iSpy (64 bit) (HKLM\...\{8D976365-F122-421C-A56D-BA0F482A0614}) (Version: 7.2.1.0 - DeveloperInABox)
iSpy package installer (64 bit) (HKLM-x32\...\{4d185fcc-2f23-4c5e-985f-e0a4edc054bd}) (Version: 7.2.1.0 - DeveloperInABox)
KeePass Password Safe 2.46 (HKLM-x32\...\KeePassPasswordSafe2_is1) (Version: 2.46 - Dominik Reichl)
Kontrola stavu osobního počítače s Windows (HKLM\...\{88EC8D4A-54AB-4A7F-BDE9-4AD906D9D11F}) (Version: 3.2.2110.14001 - Microsoft Corporation)
Kontrola stavu osobního počítače s Windows (HKLM\...\{E496AFB7-CB04-46CF-8FBB-5D665BC8811B}) (Version: 3.3.2110.22002 - Microsoft Corporation)
LibreOffice 6.2.1.2 (HKLM\...\{28B8E75D-44A5-4057-8369-5951A15BAF08}) (Version: 6.2.1.2 - The Document Foundation)
Macrium Reflect Free Edition (HKLM\...\{E00F3578-4849-40C8-91DE-58F02AF087A8}) (Version: 8.0.6392 - Paramount Software (UK) Ltd.) Hidden
Macrium Reflect Free Edition (HKLM\...\MacriumReflect) (Version: 8.0 - Paramount Software (UK) Ltd.)
MediaMonkey 4.1 (HKLM-x32\...\MediaMonkey_is1) (Version: 4.1 - Ventis Media Inc.)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 97.0.1072.76 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3879116872-396271162-1637455061-1001\...\OneDriveSetup.exe) (Version: 22.002.0103.0004 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{E876418F-BE59-4D8C-B9A5-74B056B676FA}) (Version: 2.93.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.23.27820 (HKLM-x32\...\{45231ab4-69fd-486a-859d-7a59fcd11013}) (Version: 14.23.27820.0 - Microsoft Corporation)
MiniTool Partition Wizard Free 10.2.3 (HKLM\...\{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1) (Version:  - MiniTool Solution Ltd.)
Movie Maker (HKLM-x32\...\{3D2CF65C-B544-4308-B996-700D3E5F6C4C}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox (x64 cs) (HKLM\...\Mozilla Firefox 96.0.3 (x64 cs)) (Version: 96.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 54.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 96.0.3.8061 - Mozilla)
Mozilla Thunderbird (x86 cs) (HKLM-x32\...\Mozilla Thunderbird 91.5.1 (x86 cs)) (Version: 91.5.1 - Mozilla)
Mp3tag v3.03 (HKLM-x32\...\Mp3tag) (Version: 3.03 - Florian Heidenreich)
Notepad++ (32-bit x86) (HKLM-x32\...\Notepad++) (Version: 7.8.5 - Notepad++ Team)
ONVIF Device Manager v2.2.250 (HKLM-x32\...\{6AC771CF-4EAA-41B7-A398-61A33701E076}) (Version: 2.2.250 - Synesis)
OpenTTD (HKLM-x32\...\OpenTTD) (Version: 1.11.2 - OpenTTD)
OSFMount v2.0 (HKLM\...\OSFMount_is1) (Version: 2.0.1001 - Passmark Software)
Pomocník s aktualizací Windows 10 (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.23072 - Microsoft Corporation)
PowerChute Business Edition Agent (HKLM-x32\...\{BCE9F441-9027-4911-82E0-5FB28057897D}) (Version: 10.0.2.301 - Schneider Electric)
PowerChute Business Edition Server (HKLM-x32\...\{A6491A4A-AAA0-4892-BFEF-ECD6CECE2FF3}) (Version: 9.1.1.604 - Schneider Electric)
SADPTool (HKLM-x32\...\{7D9B79C2-B1B2-433B-844F-F4299B86F26E}) (Version: 3.0.1.8 - hikvision)
Samsung Magician (HKLM-x32\...\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 5.3.0.1910 - Samsung Electronics)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Synology Assistant (remove only) (HKLM-x32\...\Synology Assistant) (Version: 6.1-15030 - Synology)
TeamViewer (HKLM-x32\...\TeamViewer) (Version: 15.25.8 - TeamViewer)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 9.0a - Ghisler Software GmbH)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.16 - VideoLAN)
Web Components (HKLM-x32\...\{03B13AF8-9625-478A-AF0E-205337B9415A}_is1) (Version: 3.0.6.46 - )
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinRAR 5.90 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.90.0 - win.rar GmbH)

Packages:
=========
Doplněk multimediálního modulu pro aplikaci Fotografie -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2021-11-19] (Microsoft Corporation)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-02-13] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-02-13] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.12.1050.0_x64__8wekyb3d8bbwe [2022-01-28] (Microsoft Studios) [MS Ad]
Rozšíření pro video MPEG-2 -> C:\Program Files\WindowsApps\Microsoft.MPEG2VideoExtension_1.0.42152.0_x64__8wekyb3d8bbwe [2021-09-10] (Microsoft Corporation)
Twitter -> C:\Program Files\WindowsApps\9E2F88E3.Twitter_6.1.4.1000_neutral__wgeqdkkx372wm [2018-09-08] (Twitter Inc.)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3879116872-396271162-1637455061-1001_Classes\CLSID\{227C9E8F-71A1-4B23-9076-682A1A8EAAED}\localserver32 -> c:\program files\macrium\common\reflectmonitor.exe (Paramount Software UK Ltd -> Paramount Software UK Ltd)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ShellIconOverlayIdentifiers: [HubicBackupRootOverlayHandler] -> {2DF0C6DB-1E85-4894-9D4F-63CB0EAB17EA} => C:\Program Files\OVH\hubiC\ShellExtension.dll [2015-03-03] (OVH) [File not signed] [File is in use]
ShellIconOverlayIdentifiers: [HubicPublishedItemOverlayHandler] -> {7C76B697-27DF-4CFF-9909-863905561298} => C:\Program Files\OVH\hubiC\ShellExtension.dll [2015-03-03] (OVH) [File not signed] [File is in use]
ShellIconOverlayIdentifiers: [HubicSyncItemOverlayHandler] -> {9B497753-D273-4A80-9DE8-72248D7FA595} => C:\Program Files\OVH\hubiC\ShellExtension.dll [2015-03-03] (OVH) [File not signed] [File is in use]
ShellIconOverlayIdentifiers: [HubicUnsyncItemOverlayHandler] -> {D5454A6E-0904-4BA3-9E4A-240A5080259D} => C:\Program Files\OVH\hubiC\ShellExtension.dll [2015-03-03] (OVH) [File not signed] [File is in use]
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files (x86)\Notepad++\NppShell_06.dll [2017-11-27] (Notepad++ -> )
ContextMenuHandlers1: [Mp3tagShell] -> {6351E20C-35FA-4BE3-98FB-4CABF1363E12} => C:\Program Files (x86)\Mp3tag\Mp3tagShell64.dll [2020-10-02] (Florian Heidenreich) [File not signed]
ContextMenuHandlers1: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2021-11-17] (Paramount Software UK Ltd -> Paramount Software UK Ltd)
ContextMenuHandlers1: [SimpleShlExt] -> {45203D3B-3D73-4497-8AFE-D29950AC6C55} => C:\Program Files (x86)\EaseUS\Todo Backup\bin\x64\ImageSh.dll [2019-11-15] (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co.,Ltd)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-03-26] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-03-26] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [Mp3tagShell] -> {6351E20C-35FA-4BE3-98FB-4CABF1363E12} => C:\Program Files (x86)\Mp3tag\Mp3tagShell64.dll [2020-10-02] (Florian Heidenreich) [File not signed]
ContextMenuHandlers2: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2021-11-17] (Paramount Software UK Ltd -> Paramount Software UK Ltd)
ContextMenuHandlers2: [SimpleShlExt] -> {45203D3B-3D73-4497-8AFE-D29950AC6C55} => C:\Program Files (x86)\EaseUS\Todo Backup\bin\x64\ImageSh.dll [2019-11-15] (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co.,Ltd)
ContextMenuHandlers2-x32: [VMDiskMenuHandler] -> {271DC252-6FE1-4D59-9053-E4CF50AB99DE} => C:\Program Files (x86)\VMware\VMware Workstation\vmdkShellExt.dll [2017-09-18] (VMware, Inc. -> VMware, Inc.)
ContextMenuHandlers2: [VMDiskMenuHandler64] -> {E4D28EDC-8C0B-43EE-9E7D-C8A8682334DC} => C:\Program Files (x86)\VMware\VMware Workstation\x64\vmdkShellExt64.dll [2017-09-18] (VMware, Inc. -> VMware, Inc.)
ContextMenuHandlers4: [Mp3tagShell] -> {6351E20C-35FA-4BE3-98FB-4CABF1363E12} => C:\Program Files (x86)\Mp3tag\Mp3tagShell64.dll [2020-10-02] (Florian Heidenreich) [File not signed]
ContextMenuHandlers4: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} =>  -> No File
ContextMenuHandlers4: [SimpleShlExt] -> {45203D3B-3D73-4497-8AFE-D29950AC6C55} => C:\Program Files (x86)\EaseUS\Todo Backup\bin\x64\ImageSh.dll [2019-11-15] (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co.,Ltd)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\atiacm64.dll [2015-08-04] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
ContextMenuHandlers6: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} =>  -> No File
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-03-26] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-03-26] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

2020-11-27 03:38 - 2020-11-27 03:38 - 000961536 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Garmin\Express\CefSharp.BrowserSubprocess.Core.dll
2020-11-27 03:38 - 2020-11-27 03:38 - 001446400 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Garmin\Express\CefSharp.Core.dll
2022-01-12 11:08 - 2022-01-12 11:08 - 000073216 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Garmin\Express\FixBootSector.dll
2017-05-08 09:35 - 2017-05-08 09:35 - 000325632 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Garmin\Express\GpsImgWrapper.dll
2018-09-17 11:31 - 2019-06-28 10:09 - 001291264 _____ () [File not signed] C:\Program Files (x86)\EaseUS\Todo Backup\bin\libxml2.dll
2018-09-17 11:31 - 2019-06-28 10:09 - 000055808 _____ () [File not signed] C:\Program Files (x86)\EaseUS\Todo Backup\bin\zlib1.dll
2020-11-18 09:14 - 2020-11-18 09:14 - 117340672 _____ () [File not signed] C:\Program Files (x86)\Garmin\Express\libcef.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000031232 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\A4.Foundation\e614377a8018bd14691fa1722ec0fc25\A4.Foundation.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000022528 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\AEM.Actions5dc83b46#\09bc8d48868482575c42971c19c67d23\AEM.Actions.CCAA.Shared.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000013312 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\AEM.Plugin.0a1309f7#\699f226142e9bd02a901378dc96a7f35\AEM.Plugin.EEU.Shared.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000017408 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\AEM.Plugin.2b6a6775#\47c2e2d2bec66c299ad0d5be5d621296\AEM.Plugin.Hotkeys.Shared.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000281600 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\AEM.Plugin.5d945b6b#\6618d2db07c5b4c0c7e70661af5e96a2\AEM.Plugin.Source.Kit.Server.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000014848 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\AEM.Plugin.674d2b8a#\5ace94dbda47d8ead74cf19739b9867c\AEM.Plugin.WinMessages.Shared.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000012800 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\AEM.Plugin.88aba5d2#\ccef5ef9fd2da33c9aac39ed8f87d142\AEM.Plugin.REG.Shared.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000011776 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\AEM.Plugin.GD.Shared\e3c01f1693b08f4eeee6eb9ebf233da8\AEM.Plugin.GD.Shared.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000013312 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\AEM.Server.Shared\3ceb8a6fe2274cb941e2e1216ae77624\AEM.Server.Shared.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000267776 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\AEM.Server\c43e1bb5c391e86b01bd437d3f8ae69f\AEM.Server.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000055808 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\APM.Foundation\1c82f817b39bc9f4318ec9ec17d5d3a7\APM.Foundation.ni.dll
2022-01-28 19:47 - 2022-01-28 19:47 - 000122880 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\ATICCCom\29c2a4ceddf9d1be814fb1b7c247cd2c\ATICCCom.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000204288 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CCC.Implementation\278e24955bed51fb8c70ed58ada4628a\CCC.Implementation.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000128000 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.3399d0ec#\94ff5d576b2708bc1f5207b69f29bf0c\CLI.Aspect.CustomFormats.Graphics.Shared.ni.dll
2022-01-28 19:47 - 2022-01-28 19:47 - 000045568 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.382a3def#\9a8b96b450652e8aba9d67ab6286a757\CLI.Aspect.AMDOverDrive.Platform.Shared.ni.dll
2022-01-28 19:47 - 2022-01-28 19:47 - 000263168 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.73911eb5#\7f04ebc098abc2b7307bf4c5fa9065a9\CLI.Aspect.WirelessDisplay.Graphics.Shared.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000365056 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.7ec2db45#\2ded7d22dfe35b837c60c995be2c580a\CLI.Aspect.DeviceDFP.Graphics.Shared.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000462336 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.acb9d930#\5964f38c768da57a270b7c48b9444418\CLI.Aspect.DeviceProperty.Graphics.Shared.ni.dll
2022-01-28 19:47 - 2022-01-28 19:47 - 000340992 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Aspect.c7aaa0f8#\7a38ce2246251b66994699feb8b4c3e9\CLI.Aspect.OverDrive5.Graphics.Shared.ni.dll
2022-01-28 19:47 - 2022-01-28 19:47 - 000051200 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.A4.Runtime\fc414d656610e2e71cb23bdbf8501c05\CLI.Caste.A4.Runtime.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000044544 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.A4.Shared\dd0e68d3a905116112768f43599e60b7\CLI.Caste.A4.Shared.ni.dll
2022-01-28 19:47 - 2022-01-28 19:47 - 000027136 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.Af820fedc#\9ff238390de82909ce21eb20746f9796\CLI.Caste.A4.Dashboard.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000044544 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.F24de14fe#\d4b4234d4f2087e2a664771a67aa18b1\CLI.Caste.Fuel.Shared.ni.dll
2022-01-28 19:47 - 2022-01-28 19:47 - 000311296 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.F36b07a2b#\03c74ba093c9085cf88a8c139e1462db\CLI.Caste.Fuel.Runtime.ni.dll
2022-01-28 19:47 - 2022-01-28 19:47 - 000027136 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.Ff3085433#\d83da7f2e91ecfdbbdc90b6f7240727b\CLI.Caste.Fuel.Dashboard.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 001555456 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.Gd9d9b43b#\41355831f40321a97f8462bda9b9d7ef\CLI.Caste.Graphics.Dashboard.Shared.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000587776 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.Gee7d2dbc#\f9452395ce2480ce0791e8d9b977a59f\CLI.Caste.Graphics.Dashboard.ni.dll
2022-01-28 19:47 - 2022-01-28 19:47 - 000045056 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.H18c99613#\19325f55dd8219218c8a19555fb08014\CLI.Caste.HydraVision.Runtime.ni.dll
2022-01-28 19:47 - 2022-01-28 19:47 - 000030720 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.H92ba4e46#\f3caf797d39aa80657cb1e9c1fd84f58\CLI.Caste.HydraVision.Shared.ni.dll
2022-01-28 19:47 - 2022-01-28 19:47 - 000025600 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.Hbb906c0b#\ea94ca972eae6fbc9c440a5a09d810f5\CLI.Caste.HydraVision.Dashboard.ni.dll
2022-01-28 19:47 - 2022-01-28 19:47 - 000030720 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.Pac40511b#\e9a1aa10ced8a13fb760a61b0b06bab4\CLI.Caste.Platform.Shared.ni.dll
2022-01-28 19:47 - 2022-01-28 19:47 - 000044032 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.Pdb36d56e#\0117eb7ec3597fd9bfd036da1e0cae14\CLI.Caste.Platform.Runtime.ni.dll
2022-01-28 19:47 - 2022-01-28 19:47 - 000024064 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.Pfeefa2b6#\23ab1c44c32c58188acc5baa99bf2240\CLI.Caste.Platform.Dashboard.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000012288 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Compone1b4a8c97#\bfe87fc0114ad6d4c5682b6bd415aea1\CLI.Component.Runtime.Shared.ni.dll
2022-01-28 19:47 - 2022-01-28 19:47 - 000901632 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Compone26c9c557#\5d04f5fc4bf5ff7b45a6da9124a6bc90\CLI.Component.Systemtray.ni.dll
2022-01-28 19:47 - 2022-01-28 19:47 - 000173568 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Compone29e547cc#\c28ade984c945bf49e5de8af2877f599\CLI.Component.Dashboard.ProfileManager2.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000151040 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Compone59f353b4#\173d5aed0509d86c88d58348000fd24c\CLI.Component.Runtime.Shared.Private.ni.dll
2022-01-28 19:47 - 2022-01-28 19:47 - 000017408 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Componeb4d0485c#\2cdd2d1916e8d8062b0d5e59e15e77d8\CLI.Component.Runtime.Extension.EEU.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 001609728 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Componec89c3bec#\256178ff999c54e72937ef34d3774201\CLI.Component.Dashboard.Shared.Private.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000018432 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Componef1fd67b2#\2b167f2d01c713a770d3decc56a678f9\CLI.Component.Client.Shared.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000085504 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Componef4cf054f#\75c88e014e68a129b9f996e22ee1e8af\CLI.Component.Dashboard.Shared.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000089600 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Foundat3d5d3945#\2b433f8a7e5d7ea7cf40e419534e0be5\CLI.Foundation.Private.ni.dll
2022-01-28 19:47 - 2022-01-28 19:47 - 000061440 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Foundat60cdf5df#\037e2426b9803b80d675eb9d47ae5e7f\CLI.Foundation.XManifest.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000091136 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Foundat619559bd#\18abf967f9de56d2639cfc96abbaf7ac\CLI.Foundation.CoreAudioAPI.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 001079296 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Foundatd3771151#\d188345fb3b4624f087c0c43afb69ade\CLI.Foundation.Client.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000301568 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Foundation\5649a849e47d8013155d901dde578653\CLI.Foundation.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000025600 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\DEM.Foundation\9fa8cbad75572ca179de0fbe83f1f2b5\DEM.Foundation.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000115200 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\DEM.Graphics.I0601\69204f03c3257a5432860768ddba6bac\DEM.Graphics.I0601.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000015360 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\DEM.Graphics\5980d262187365215206f6885d2058d7\DEM.Graphics.ni.dll
2022-01-28 19:47 - 2022-01-28 19:47 - 000037376 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Fuel.Foundation\0ff19ae965c964420eccbc81f4fa8907\Fuel.Foundation.ni.dll
2022-01-28 19:47 - 2022-01-28 19:47 - 000296960 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\LOG.Foundat03490438#\e52a2d2e14766271d34263963f662f2b\LOG.Foundation.Implementation.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000150016 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\LOG.Foundat5023f8e7#\77565ec04d426ac7fecfe5dd24ec5a56\LOG.Foundation.Private.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000087552 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\LOG.Foundatcaafa75b#\c456d124f11173a213237dddcf81aaaa\LOG.Foundation.Implementation.Private.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000132608 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\LOG.Foundation\2807fd87738679b7ec2aa96092b6d3c2\LOG.Foundation.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000012288 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\MOM.Foundation\05d0d9638ca54b3f4a856a181321a2b3\MOM.Foundation.ni.dll
2022-01-28 19:47 - 2022-01-28 19:47 - 000402944 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\MOM.Implementation\ff4933cb100e88414ee4e8647da2fb1b\MOM.Implementation.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000055296 _____ (Advanced Micro Devices Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\NEWAEM.Foundation\658c753de01ecf63674568eadbe66d38\NEWAEM.Foundation.ni.dll
2015-08-03 23:14 - 2015-08-03 23:14 - 000005120 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\atiamcsy.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000897024 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\ADL.Foundation\a4fbecf4ccac1e5646bd7459461b9fab\ADL.Foundation.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000256000 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\APM.Server\ec41124bc4e26c5988c22a91ea3db041\APM.Server.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000136704 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Compone168638d1#\a333858753699d6004aa1944b0ee4f2a\CLI.Component.Client.Shared.Private.ni.dll
2022-01-28 19:47 - 2022-01-28 19:47 - 000234496 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Compone6692ca50#\b2d96b2f1a5aaea5a7b990e8518472cf\CLI.Component.Runtime.ni.dll
2022-01-28 19:47 - 2022-01-28 19:47 - 000929280 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Compone6bf88b08#\5e5929b3d6755486736963bfe1271486\CLI.Component.Dashboard.ni.dll
2022-01-28 19:47 - 2022-01-28 19:47 - 000084480 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\DEM.Graphics.I0709\f248369267ec9ebaf13239fbc7e1570f\DEM.Graphics.I0709.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000018432 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\DEM.Graphics.I0804\c64a1a1ec05a281173efae3e7f673a2c\DEM.Graphics.I0804.ni.dll
2022-01-28 19:47 - 2022-01-28 19:47 - 000035840 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\DEM.Graphics.I1010\fe965c3c075816525190992ed5fdb1b2\DEM.Graphics.I1010.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 001139200 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Localizatio01dbc1c0#\90cf100df249cdceaabb6e1fa91c22e7\Localization.Foundation.Private.ni.dll
2022-01-28 19:47 - 2022-01-28 19:47 - 000244736 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\ResourceMan446ca0e5#\604e9bd383d2be3f339b46acb2fbef52\ResourceManagement.Foundation.Implementation.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 000023552 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\ResourceManf163905a#\a82fc6416c7201017a3be0cdd70a1b59\ResourceManagement.Foundation.Private.ni.dll
2022-01-28 19:46 - 2022-01-28 19:46 - 002845696 _____ (Advanced Mirco Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.G60a7b4d1#\1e19a9b16feb41a5bf1d473821db556f\CLI.Caste.Graphics.Shared.ni.dll
2022-01-28 19:47 - 2022-01-28 19:47 - 003268096 _____ (Advanced Mirco Devices, Inc.) [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\CLI.Caste.G962aa464#\9e531f72eba5ff928fb7985d650ac962\CLI.Caste.Graphics.Runtime.ni.dll
2022-01-12 11:08 - 2022-01-12 11:08 - 001976832 _____ (Apache Software Foundation) [File not signed] C:\Program Files (x86)\Garmin\Express\XercesLib.dll
2022-01-12 11:12 - 2022-01-12 11:12 - 000234496 _____ (Dynastream Innovations Inc.) [File not signed] C:\Program Files (x86)\Garmin\Express\ANT_WrappedLib.dll
2020-10-02 17:34 - 2020-10-02 17:34 - 000398336 _____ (Florian Heidenreich) [File not signed] C:\Program Files (x86)\Mp3tag\Mp3tagShell64.dll
2018-09-17 11:31 - 2019-06-28 10:09 - 000892928 _____ (Free Software Foundation) [File not signed] C:\Program Files (x86)\EaseUS\Todo Backup\bin\iconv.dll
2022-01-12 11:08 - 2022-01-12 11:08 - 002711552 _____ (Garmin International) [File not signed] [File is in use] C:\Program Files (x86)\Garmin\Express\legacyio.dll
2017-05-08 09:35 - 2017-05-08 09:35 - 000343552 _____ (Garmin International, Inc.) [File not signed] C:\Program Files (x86)\Garmin\Express\IMG_GPSMAP.dll
2022-01-12 11:08 - 2022-01-12 11:08 - 000425472 _____ (Garmin) [File not signed] C:\Program Files (x86)\Garmin\Express\XMLdll.dll
2020-06-16 16:28 - 2020-06-16 16:28 - 000016896 _____ (Intel Corporation) [File not signed] C:\Program Files\Intel\SUR\QUEENCREEK\esrv_lib_security.dll
2020-06-16 16:28 - 2020-06-16 16:28 - 001688576 _____ (Robert Simpson, et al.) [File not signed] C:\Program Files\Intel\SUR\QUEENCREEK\x64\SQLite.Interop.dll
2022-01-12 11:10 - 2022-01-12 11:10 - 000090112 _____ (Silicon Laboratories, Inc.) [File not signed] C:\Program Files (x86)\Garmin\Express\DSI_SiUSBXp_3_1.DLL
2020-06-16 16:28 - 2020-06-16 16:28 - 001918464 _____ (SQLite Development Team) [File not signed] C:\Program Files\Intel\SUR\QUEENCREEK\x64\sqlite3.dll
2020-11-18 07:39 - 2020-11-18 07:39 - 000843264 _____ (The Chromium Authors) [File not signed] C:\Program Files (x86)\Garmin\Express\chrome_elf.dll
2020-06-22 08:20 - 2019-10-09 08:05 - 001359872 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\EaseUS\Todo Backup\bin\LIBEAY32.dll
2020-06-22 08:20 - 2019-10-09 08:05 - 000365056 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\EaseUS\Todo Backup\bin\SSLEAY32.dll

==================== Alternate Data Streams (Whitelisted) ========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:4FC01C57 [134]

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) ==========

SearchScopes: HKU\S-1-5-21-3879116872-396271162-1637455061-1001 -> {BDF61FAE-9D19-40F0-8F34-688DEB334CA9} URL = hxxp://securedsearch.lavasoft.com/results.php?pr=vmn&id=webcompa&ent=ch_WCYID10420__190122&q={searchTerms}

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-3879116872-396271162-1637455061-1001\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-3879116872-396271162-1637455061-1001\...\webcompanion.com -> hxxp://webcompanion.com

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2017-03-18 22:03 - 2017-03-18 22:01 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3879116872-396271162-1637455061-1001\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\theme1\img2.jpg
DNS Servers: 82.202.120.1 - 81.19.33.2
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.

Network Binding:
=============
Síťové připojení Bluetooth: VMware Bridge Protocol -> vmware_bridge (enabled) 
VMware Network Adapter VMnet8: VMware Bridge Protocol -> vmware_bridge (enabled) 
Ethernet: VMware Bridge Protocol -> vmware_bridge (enabled) 
Ethernet 2: VMware Bridge Protocol -> vmware_bridge (enabled) 
VMware Network Adapter VMnet1: VMware Bridge Protocol -> vmware_bridge (enabled) 

==================== MSCONFIG/TASK MANAGER disabled items ==

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{E59C01A3-2B58-4CAB-A645-6DE286706163}] => (Allow) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
FirewallRules: [{B435D009-A3EA-490A-8681-08B643ECC4E4}] => (Allow) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
FirewallRules: [{EA861A7C-9006-4822-BC70-B7EB3BC11F9C}] => (Block) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
FirewallRules: [{766D5F92-D65A-4110-9733-3FFE54F5D48B}] => (Block) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
FirewallRules: [UDP Query User{E73C2765-1CA5-4648-8A47-2B616EC50682}C:\program files (x86)\sadptool\sadptool.exe] => (Allow) C:\program files (x86)\sadptool\sadptool.exe (HIKVISION DIGITAL TECHNOLOGY CO.,LTD. -> )
FirewallRules: [TCP Query User{07BABA1D-37B5-4C5D-8B4E-4DAB99C35292}C:\program files (x86)\sadptool\sadptool.exe] => (Allow) C:\program files (x86)\sadptool\sadptool.exe (HIKVISION DIGITAL TECHNOLOGY CO.,LTD. -> )
FirewallRules: [{A9865930-2708-40BA-AC83-9B3523440842}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe (CHENGDU YIWO Tech Development Co., Ltd. -> )
FirewallRules: [{5305AB17-F7A4-4C5F-941A-934D6358FA16}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe (CHENGDU YIWO Tech Development Co., Ltd. -> )
FirewallRules: [{B8CB6BA8-004B-440D-BBCD-3F90885BB6D2}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBConsoleUI.exe (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co., Ltd)
FirewallRules: [{E3E58311-619A-4561-82D9-97F780603C40}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBConsoleUI.exe (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co., Ltd)
FirewallRules: [{68007B44-16D5-4854-AFCD-CD6D1DA231B3}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbService.exe (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co., Ltd)
FirewallRules: [{06088A62-AD71-4911-81F7-0E959EFCE6CC}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbService.exe (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co., Ltd)
FirewallRules: [{76821AEF-E83A-4B01-9C7E-4B5F5C331BCE}] => (Allow) LPort=1900
FirewallRules: [{7B51D0B5-CD82-46E9-8F1D-BFA030482B73}] => (Allow) LPort=2869
FirewallRules: [{00D0EF8E-ABD6-4622-B199-F099D764E391}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{071B85B4-B2A2-4669-8E9B-9BEEBB4F7DF5}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe (VMware, Inc. -> )
FirewallRules: [{C5992CC6-8CA2-44ED-829E-B0B202132D44}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe (VMware, Inc. -> )
FirewallRules: [{BA613CBE-C76A-43F8-BA3F-433D4A849564}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc. -> VMware, Inc.)
FirewallRules: [{CDB91B25-2B1E-4E55-A357-6D7CB8A8CC26}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc. -> VMware, Inc.)
FirewallRules: [{2E554763-14E1-4C10-A906-B9D5194E0BFE}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{1C8CD511-0D11-442F-981F-4F4372E608EA}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{2AAABEAD-315D-4A2D-8EA6-A5F0AC28F026}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{2D05AB07-ED27-4B43-A73C-E40B788A1FB8}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{3CE2D329-2222-4D82-A53A-39D853A5CD07}] => (Block) C:\program files\ cms\cms.exe () [File not signed]
FirewallRules: [{7CF66856-602B-4A2B-A7DB-575FEA8D8256}] => (Block) C:\program files\ cms\cms.exe () [File not signed]
FirewallRules: [UDP Query User{C685B188-3665-493B-A9F8-46A5328B35B9}C:\program files\ cms\cms.exe] => (Allow) C:\program files\ cms\cms.exe () [File not signed]
FirewallRules: [TCP Query User{6DE5875E-33A5-4422-88B2-A95B7A8A5CB2}C:\program files\ cms\cms.exe] => (Allow) C:\program files\ cms\cms.exe () [File not signed]
FirewallRules: [UDP Query User{5DAC1650-7FCD-4D9C-9144-AC8F51350413}C:\program files (x86)\synology\assistant\dsassistant.exe] => (Allow) C:\program files (x86)\synology\assistant\dsassistant.exe (Synology Inc. -> ) [File not signed]
FirewallRules: [TCP Query User{392A542E-D42F-49E1-B36E-12AB5E13B70D}C:\program files (x86)\synology\assistant\dsassistant.exe] => (Allow) C:\program files (x86)\synology\assistant\dsassistant.exe (Synology Inc. -> ) [File not signed]
FirewallRules: [{35485CA5-6684-4278-82BC-0AB0D35C741D}] => (Allow) C:\Program Files\RealVNC\VNC Server\vncserver.exe => No File
FirewallRules: [{485F7AC8-F20D-4508-BB87-07E1A4729598}] => (Allow) C:\Program Files\RealVNC\VNC Server\vncserver.exe => No File
FirewallRules: [UDP Query User{CD58778A-162A-4F24-89D3-FB37714F2B81}C:\program files (x86)\cms\cms.exe] => (Allow) C:\program files (x86)\cms\cms.exe () [File not signed]
FirewallRules: [TCP Query User{E0DC39C3-3B8B-49DE-A812-C6BC1CB792E0}C:\program files (x86)\cms\cms.exe] => (Allow) C:\program files (x86)\cms\cms.exe () [File not signed]
FirewallRules: [UDP Query User{FDF35092-0793-4723-AB68-54C34A1B8FEA}C:\program files (x86)\synesis\onvif device manager\odm.player.host.exe] => (Allow) C:\program files (x86)\synesis\onvif device manager\odm.player.host.exe (Synesis) [File not signed]
FirewallRules: [TCP Query User{FE68C21D-4318-4CD6-A98A-81468416C257}C:\program files (x86)\synesis\onvif device manager\odm.player.host.exe] => (Allow) C:\program files (x86)\synesis\onvif device manager\odm.player.host.exe (Synesis) [File not signed]
FirewallRules: [UDP Query User{F4DDBF77-FBE7-4D00-AF0B-F0EC4A320A95}C:\program files (x86)\synesis\onvif device manager\odm.exe] => (Allow) C:\program files (x86)\synesis\onvif device manager\odm.exe (Synesis) [File not signed]
FirewallRules: [TCP Query User{A16C6563-1C44-4132-9168-BD0F894752AA}C:\program files (x86)\synesis\onvif device manager\odm.exe] => (Allow) C:\program files (x86)\synesis\onvif device manager\odm.exe (Synesis) [File not signed]
FirewallRules: [UDP Query User{FE0B71FD-D763-41FE-8633-BD6CF9B7DC5D}C:\program files (x86)\synology\assistant\dsassistant.exe] => (Allow) C:\program files (x86)\synology\assistant\dsassistant.exe (Synology Inc. -> ) [File not signed]
FirewallRules: [TCP Query User{C05E3A3D-C648-4A8C-9E43-B9E702219111}C:\program files (x86)\synology\assistant\dsassistant.exe] => (Allow) C:\program files (x86)\synology\assistant\dsassistant.exe (Synology Inc. -> ) [File not signed]
FirewallRules: [UDP Query User{1826D08E-5B0B-47AA-9CA7-BEA3FB458D8A}C:\program files\ispy\ispy.exe] => (Allow) C:\program files\ispy\ispy.exe (www.ispyconnect.com) [File not signed]
FirewallRules: [TCP Query User{12E7B2EC-0FD4-4E92-AC21-0439831B75FF}C:\program files\ispy\ispy.exe] => (Allow) C:\program files\ispy\ispy.exe (www.ispyconnect.com) [File not signed]
FirewallRules: [{FF43890E-60A1-42D8-A971-4B6EE8096123}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{6DA5647B-14C1-41C0-94A1-E360C3607385}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{12D72B28-C799-4D4E-BA8F-EFF0F121B125}C:\program files (x86)\synesis\onvif device manager\odm.exe] => (Allow) C:\program files (x86)\synesis\onvif device manager\odm.exe (Synesis) [File not signed]
FirewallRules: [UDP Query User{147A4EC1-3C27-46AA-82F3-D9FA8C840838}C:\program files (x86)\synesis\onvif device manager\odm.exe] => (Allow) C:\program files (x86)\synesis\onvif device manager\odm.exe (Synesis) [File not signed]
FirewallRules: [TCP Query User{202FDE03-25E1-4FE4-B924-B6F6720CDCF3}C:\program files (x86)\synesis\onvif device manager\odm.player.host.exe] => (Allow) C:\program files (x86)\synesis\onvif device manager\odm.player.host.exe (Synesis) [File not signed]
FirewallRules: [UDP Query User{DC108A19-5FF7-4D04-98EF-32246BAA2321}C:\program files (x86)\synesis\onvif device manager\odm.player.host.exe] => (Allow) C:\program files (x86)\synesis\onvif device manager\odm.player.host.exe (Synesis) [File not signed]
FirewallRules: [TCP Query User{C536E886-C1BA-4796-ADCE-12A5358E2D59}C:\windows\syswow64\dpnsvr.exe] => (Block) C:\windows\syswow64\dpnsvr.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [UDP Query User{B83CA1E3-1BE4-4A8D-B8FB-0167185026BC}C:\windows\syswow64\dpnsvr.exe] => (Block) C:\windows\syswow64\dpnsvr.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{C7503F2F-8E5C-40E4-AB2B-B1686C727CDC}] => (Allow) C:\Program Files (x86)\APC\PowerChute Business Edition\server\pbeserver.exe (Schneider Electric -> APC)
FirewallRules: [{8CA43B3D-D5D4-40C6-8F8A-72EE98AF1D2C}] => (Allow) C:\Program Files (x86)\APC\PowerChute Business Edition\server\pbeserver.exe (Schneider Electric -> APC)
FirewallRules: [{DD48BDA3-9CDD-4733-BA4B-746305E3D72E}] => (Allow) C:\Program Files (x86)\APC\PowerChute Business Edition\agent\pbeagent.exe (Schneider Electric USA Inc. -> Schneider Electric)
FirewallRules: [{84241164-12D0-4BFA-9AD6-0642A8F71EF4}] => (Allow) C:\Program Files (x86)\APC\PowerChute Business Edition\agent\pbeagent.exe (Schneider Electric USA Inc. -> Schneider Electric)
FirewallRules: [{8A5DA271-828D-45C7-8F79-D0AA46E9E921}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe (CHENGDU YIWO Tech Development Co., Ltd. -> )
FirewallRules: [{247D6467-9CF8-4DF4-8637-6553808220F5}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe (CHENGDU YIWO Tech Development Co., Ltd. -> )
FirewallRules: [{521FB22D-4251-43F8-9C88-589F718A8313}] => (Allow) C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe (Ventis Media, Inc. -> Ventis Media Inc.)
FirewallRules: [{97238B39-51DC-4AFB-844D-01D00E35D50A}] => (Allow) C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe (Ventis Media, Inc. -> Ventis Media Inc.)
FirewallRules: [{57B9FC4B-F1E5-4BCB-B2C8-AD722E6744C8}] => (Allow) C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe (Ventis Media, Inc. -> Ventis Media Inc.)
FirewallRules: [TCP Query User{2631584F-0B6A-4E35-85E5-5DB482D07B33}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [UDP Query User{E542514E-F78E-4102-8BE8-14414948BF23}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [{0DAAC618-53C0-4157-8C31-7CFF7F186443}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{90AC7CDA-4446-4118-86ED-33DEA49ABFEB}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{72E6826A-28E7-4207-9C4F-41ACC92B93D5}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{21547869-B033-483C-A5BD-0914414B7031}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.68.96.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{A3683923-E3E8-4269-AB06-3CBA1DBD002A}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{83AB3A56-4C7A-4224-A244-7938930E148A}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{F17FD226-B3EF-4C41-92BF-6BD402B638DD}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{F6F284CC-F249-4D53-8986-239C392221C3}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{E8991F4E-EDD9-43C7-80F3-EB5A0797D1ED}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout Shelter\FalloutShelter.exe () [File not signed]
FirewallRules: [{DD243535-B8FF-423A-A117-70887A117B30}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout Shelter\FalloutShelter.exe () [File not signed]
FirewallRules: [{AA0378E9-C81F-4FB6-AE32-FA55D0985E17}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{E49AF27F-C76C-4CE9-BEBA-97CFE234ADF6}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{BD28E4D2-2462-4A44-8B50-D4203A16C26B}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{4C77DAD2-4C65-4F14-8EE3-48F5D65928AF}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.79.95.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{FFFBD5F1-E8EE-42E8-8EC6-786BC034952E}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{F908EE75-488E-4F87-B244-0E5C2927A896}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{5B2259AF-8838-42DF-B839-9AE3BFB47136}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{45DA6656-5EB3-40C9-813B-DC946C374116}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{F323F1E7-50C0-430F-B9A0-444ADD2A977F}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)

==================== Restore Points =========================

28-01-2022 18:48:12 Garmin Express
28-01-2022 18:55:18 Instalační služba modulů systému Windows
28-01-2022 18:56:33 Instalační služba modulů systému Windows
28-01-2022 19:00:06 Instalační služba modulů systému Windows
28-01-2022 19:04:39 Instalační služba modulů systému Windows
28-01-2022 19:18:15 Instalační služba modulů systému Windows

==================== Faulty Device Manager Devices ============

Name: LAMAX Storm1 A2DP SNK
Description: Jímka Microsoft Bluetooth A2dp
Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: BthA2dp
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver


==================== Event log errors: ========================

Application errors:
==================
Error: (01/28/2022 08:44:54 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na DATA (D:), protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)

Error: (01/28/2022 08:37:52 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na iSPY (E:), protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)

Error: (01/28/2022 07:34:26 PM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: DESKTOP-D)
Description: Nelze otevřít objekt výkonu služby serveru. Vrácený kód stavu představují první čtyři bajty (DWORD) datové části.

Error: (01/28/2022 07:14:25 PM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: DESKTOP-D)
Description: Nelze otevřít objekt výkonu služby serveru. Vrácený kód stavu představují první čtyři bajty (DWORD) datové části.

Error: (01/28/2022 07:09:55 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny CoCreateInstance došlo k neočekávané chybě. hr= 0x8007045b, Probíhá vypnutí systému.
.

Error: (01/28/2022 07:09:55 PM) (Source: VSS) (EventID: 13) (User: )
Description: Informace služby Stínová kopie svazku: Server COM s identifikátorem CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} a názvem CEventSystem nelze spustit. [0x8007045b, Probíhá vypnutí systému.
]

Error: (01/28/2022 07:09:55 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny CoCreateInstance došlo k neočekávané chybě. hr= 0x8007045b, Probíhá vypnutí systému.
.

Error: (01/28/2022 07:09:55 PM) (Source: VSS) (EventID: 13) (User: )
Description: Informace služby Stínová kopie svazku: Server COM s identifikátorem CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} a názvem CEventSystem nelze spustit. [0x8007045b, Probíhá vypnutí systému.
]


System errors:
=============
Error: (01/30/2022 03:45:18 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba APC PBE Agent byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 60000 milisekund: Restartovat službu.

Error: (01/30/2022 03:44:17 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba APC PBE Agent byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 60000 milisekund: Restartovat službu.

Error: (01/30/2022 03:43:16 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba APC PBE Agent byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 60000 milisekund: Restartovat službu.

Error: (01/30/2022 03:42:15 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba APC PBE Agent byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 60000 milisekund: Restartovat službu.

Error: (01/30/2022 03:41:14 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba APC PBE Agent byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 60000 milisekund: Restartovat službu.

Error: (01/30/2022 03:40:13 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba APC PBE Agent byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 60000 milisekund: Restartovat službu.

Error: (01/30/2022 03:39:12 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba APC PBE Agent byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 60000 milisekund: Restartovat službu.

Error: (01/30/2022 03:38:11 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba APC PBE Agent byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 60000 milisekund: Restartovat službu.


Windows Defender:
================
Date: 2022-01-29 19:30:10
Description: 
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {D94C73B6-1A72-4954-8B9D-6349E886F1B4}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2022-01-28 18:46:32
Description: 
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {660EA784-FF3E-4783-B260-57313D9C732C}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Vlastní prohledávání
Uživatel: DESKTOP-D\D

Date: 2021-12-04 10:32:19
Description: 
Antivirová ochrana v programu Microsoft Defender zjistil malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid=37020&name=PUADlManager:Win32/InstallCore&threatid=311991&enterprise=0
Název: PUADlManager:Win32/InstallCore
Závažnost: Nízké
Kategorie: Potenciálně nežádoucí software
Cesta: file:_C:\WINDOWS\system32\drivers\scdemu.sys
Původ detekce: Místní počítač
Typ detekce: FastPath
Zdroj detekce: Systém
Uživatel: NT AUTHORITY\SYSTEM
Název procesu: Unknown
Verze bezpečnostních informací: AV: 1.353.2062.0, AS: 1.353.2062.0, NIS: 1.353.2062.0
Verze modulu: AM: 1.1.18700.4, NIS: 1.1.18700.4

Date: 2021-11-07 15:30:00
Description: 
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {D131B4F3-34BE-4595-9F94-BAEE61294C48}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\NETWORK SERVICE
﻿Event[0]:

Date: 2021-12-23 18:14:58
Description: 
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací: 
Předchozí verze bezpečnostních informací: 1.355.726.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\NETWORK SERVICE
Aktuální verze modulu: 
Předchozí verze modulu: 1.1.18800.4
Kód chyby: 0x80070003
Popis chyby: Systém nemůže nalézt uvedenou cestu. 

Date: 2021-12-23 18:14:58
Description: 
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací: 
Předchozí verze bezpečnostních informací: 1.355.726.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ bezpečnostních informací: Antispywarový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\NETWORK SERVICE
Aktuální verze modulu: 
Předchozí verze modulu: 1.1.18800.4
Kód chyby: 0x80070003
Popis chyby: Systém nemůže nalézt uvedenou cestu. 

Date: 2021-12-23 18:14:58
Description: 
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací: 
Předchozí verze bezpečnostních informací: 1.355.726.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\NETWORK SERVICE
Aktuální verze modulu: 
Předchozí verze modulu: 1.1.18800.4
Kód chyby: 0x80070003
Popis chyby: Systém nemůže nalézt uvedenou cestu. 

Date: 2021-09-07 17:16:16
Description: 
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací: 
Předchozí verze bezpečnostních informací: 1.347.54.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\NETWORK SERVICE
Aktuální verze modulu: 
Předchozí verze modulu: 1.1.18400.5
Kód chyby: 0x80072ee7
Popis chyby: Nelze rozpoznat název nebo adresu serveru. 

Date: 2021-09-07 17:16:16
Description: 
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací: 
Předchozí verze bezpečnostních informací: 1.347.54.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ bezpečnostních informací: Antispywarový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\NETWORK SERVICE
Aktuální verze modulu: 
Předchozí verze modulu: 1.1.18400.5
Kód chyby: 0x80072ee7
Popis chyby: Nelze rozpoznat název nebo adresu serveru. 

CodeIntegrity:
===============
Date: 2021-08-19 21:44:37
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.2107.4-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVG\Antivirus\aswAMSI.dll that did not meet the Microsoft signing level requirements.

Date: 2021-08-19 21:44:37
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MpCmdRun.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVG\Antivirus\aswAMSI.dll that did not meet the Microsoft signing level requirements.

Date: 2020-10-26 02:00:10
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\vdsldr.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\TeamViewer\tv_x64.dll that did not meet the Microsoft signing level requirements.

Date: 2020-09-01 15:06:12
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\drivers\nuidfltr.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info =========================== 

BIOS: American Megatrends Inc. 2702 03/28/2016
Motherboard: ASUSTeK COMPUTER INC. H97M-E
Processor: Intel(R) Core(TM) i5-4590S CPU @ 3.00GHz
Percentage of memory in use: 32%
Total physical RAM: 20422.01 MB
Available physical RAM: 13829.14 MB
Total Virtual: 23494.01 MB
Available Virtual: 15991.89 MB

==================== Drives ================================

Drive b: () (Network) (Total:0 GB) (Free:0 GB) 
Drive c: () (Fixed) (Total:464.65 GB) (Free:352.42 GB) NTFS
Drive d: (DATA) (Fixed) (Total:931.51 GB) (Free:474.64 GB) NTFS
Drive e: (iSPY) (Fixed) (Total:3726.02 GB) (Free:3492.89 GB) NTFS
Drive h: () (Network) (Total:0 GB) (Free:0 GB) 
Drive s: () (Network) (Total:0 GB) (Free:0 GB) 
Drive w: () (Network) (Total:0 GB) (Free:0 GB) 
Drive y: () (Network) (Total:0 GB) (Free:0 GB) 
Drive z: (sda1) (Network) (Total:465.73 GB) (Free:149.39 GB) NTFS

\\?\Volume{f54d63ed-105d-11e9-9c7e-382c4ab642a4}\ (Obnovení) (Fixed) (Total:0.44 GB) (Free:0.06 GB) NTFS
\\?\Volume{eb1efb60-de23-4300-a802-66408f56834c}\ () (Fixed) (Total:0.55 GB) (Free:0.13 GB) NTFS
\\?\Volume{a811f07c-ad21-46aa-85fc-abd8986738e2}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 18E72284)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=42)

==========================================================
Disk: 1 (Size: 3726 GB) (Disk ID: 76C7FBEC)

Partition: GPT.

==========================================================
Disk: 2 (Size: 465.8 GB) (Disk ID: E754619C)

Partition: GPT.

==================== End of Addition.txt =======================