Prosím o pomoc - vyšší výkon
Napsal: 17 kvě 2020 11:23
Dobrý den, v poslední době se mi v průběhu dne zapíná často zapíná větrák a dedikovaná grafická karta, ale prakticky nepoužívám žádné nové programy. Takže mám pocit, jak kdyby běželo něco na pozadí, co nemá.
Děkuji za pomoc. Vyřešilo by to naformatování disku? A čistá instalace.
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-05-2020 01
Ran by Matej (17-05-2020 12:18:15)
Running from C:\Users\Matej\Downloads
Windows 10 Home Version 1909 18363.836 (X64) (2019-09-17 10:52:27)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-105526560-3629586505-1581754559-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-105526560-3629586505-1581754559-503 - Limited - Disabled)
Guest (S-1-5-21-105526560-3629586505-1581754559-501 - Limited - Disabled)
Matej (S-1-5-21-105526560-3629586505-1581754559-1001 - Administrator - Enabled) => C:\Users\Matej
WDAGUtilityAccount (S-1-5-21-105526560-3629586505-1581754559-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 20.009.20063 - Adobe Systems Incorporated)
Atom (HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\atom) (Version: 1.42.0 - GitHub Inc.)
Backup and Sync from Google (HKLM\...\{FE296942-D2D3-4149-8895-60655FE4CFDE}) (Version: 3.49.9800.0000 - Google, Inc.)
Bad North (HKLM-x32\...\1656388860_is1) (Version: 8236d7f - GOG.com)
Battery Calibration (HKLM-x32\...\{634AC01E-49DB-4AD2-B87C-90D4DCC6AFA1}) (Version: 1.0.1505.2901 - Micro-Star International Co., Ltd.) Hidden
Battery Calibration (HKLM-x32\...\InstallShield_{634AC01E-49DB-4AD2-B87C-90D4DCC6AFA1}) (Version: 1.0.1505.2901 - Micro-Star International Co., Ltd.)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
BitTorrent (HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\BitTorrent) (Version: 7.10.5.45312 - BitTorrent Inc.)
Brave (HKLM-x32\...\BraveSoftware Brave-Browser) (Version: 81.1.8.96 - Brave Software Inc)
CCleaner (HKLM\...\CCleaner) (Version: 5.55 - Piriform)
CopyTrans HEIC for Windows (HKLM\...\CopyTrans HEIC for Windows_is1) (Version: 1.0.0.5 - Ursa Minor Ltd)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.11.0.0939 - Disc Soft Ltd)
Dragon Center (HKLM-x32\...\{C65B26BC-5A6F-4135-9678-55A877655471}) (Version: 2.5.1904.1201 - Micro-Star International Co., Ltd.) Hidden
Dragon Center (HKLM-x32\...\InstallShield_{C65B26BC-5A6F-4135-9678-55A877655471}) (Version: 2.5.1904.1201 - Micro-Star International Co., Ltd.)
Evernote v. 6.17.7 (HKLM-x32\...\{B47B6F80-6143-11E9-9F8E-005056951CAD}) (Version: 6.17.7.8474 - Evernote Corp.)
f.lux (HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\Flux) (Version: - f.lux Software LLC)
FileZilla Client 3.43.0 (HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\FileZilla Client) (Version: 3.43.0 - Tim Kosse)
Git version 2.22.0.windows.1 (HKLM\...\Git_is1) (Version: 2.22.0.windows.1 - The Git Development Community)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 81.0.4044.138 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.99.0 - Google Inc.) Hidden
gretl version 2020b (x86_64) (HKLM\...\gretl_is1) (Version: 2020b - The gretl team)
Icecream Ebook Reader version 5.12 (HKLM-x32\...\{B8C30F0F-1F23-49E1-A3ED-44DE17660EE2}_is1) (Version: 5.12 - Icecream Apps)
Intel(R) Chipset Device Software (HKLM-x32\...\{55d73ea7-6354-42db-8831-02d048ae57f8}) (Version: 10.1.17541.8066 - Intel(R) Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 1808.12.0.1102 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 23.20.16.4974 - Intel Corporation)
Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{00000030-0200-1033-84C8-B8D95FA3C8C3}) (Version: 20.30.0 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{f8c930bd-0a68-425f-8c11-87723d1e2c97}) (Version: 20.90.0 - Intel Corporation)
KB9X Radio Switch Driver (HKLM\...\3498B7189B13CBC3673674CD226F4540F628CCB8) (Version: 1.1.5.0 - ENE TECHNOLOGY INC.)
LYNX Trading (HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\5556-0005-2700-0000) (Version: (978.1d) 20191023 12:51:36 - LYNX)
Malwarebytes version 4.1.0.56 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.1.0.56 - Malwarebytes)
Microsoft 365 - cs-cz (HKLM\...\O365HomePremRetail - cs-cz) (Version: 16.0.12827.20160 - Microsoft Corporation)
Microsoft 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.12827.20160 - Microsoft Corporation)
Microsoft 365 for enterprise - cs-cz (HKLM\...\O365ProPlusRetail - cs-cz) (Version: 16.0.12827.20160 - Microsoft Corporation)
Microsoft 365 for enterprise - en-us (HKLM\...\O365ProPlusRetail - en-us) (Version: 16.0.12827.20160 - Microsoft Corporation)
Microsoft Mouse and Keyboard Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 12.181.137.0 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.12.25810 (HKLM-x32\...\{e2ee15e2-a480-4bc5-bfb7-e9803d1d9823}) (Version: 14.12.25810.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.10.25008 (HKLM-x32\...\{c239cea1-d49e-4e16-8e87-8c055765f7ec}) (Version: 14.10.25008.0 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Mozilla Firefox 69.0.1 (x64 cs) (HKLM\...\Mozilla Firefox 69.0.1 (x64 cs)) (Version: 69.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 67.0.4 - Mozilla)
Node.js (HKLM\...\{E3C2DC65-9DCA-4422-BDDE-0489B89A16D2}) (Version: 10.16.0 - Node.js Foundation)
Notion 1.0.8 (HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\fcdf0d7f-424b-5f10-a1c7-a8f643f21adf) (Version: 1.0.8 - Notion Labs, Incorporated)
Notion 2.0.8 (HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\{fcdf0d7f-424b-5f10-a1c7-a8f643f21adf}) (Version: 2.0.8 - Notion Labs, Incorporated)
NVIDIA HD Audio Driver 1.3.38.16 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.16 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation)
OBS Studio (HKLM-x32\...\OBS Studio) (Version: 24.0.3 - OBS Project)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.12827.20160 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.12827.20160 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0405-1000-0000000FF1CE}) (Version: 16.0.12827.20160 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.12827.20160 - Microsoft Corporation) Hidden
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
PotPlayer-64 bit (HKLM\...\PotPlayer64) (Version: 200317 - Kakao Corp.)
Pushbullet version 338 (HKLM-x32\...\{7578F204-49E7-4830-B051-14C23F408BFE}_is1) (Version: 338 - Pushbullet Inc)
Python 3.8.0 (32-bit) (HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\{37ec7371-0827-49f1-be8a-63c158184b9c}) (Version: 3.8.150.0 - Python Software Foundation)
Python 3.8.0 Core Interpreter (32-bit) (HKLM-x32\...\{8C9832C5-C3B1-4596-B8E9-F32ED263FC56}) (Version: 3.8.150.0 - Python Software Foundation) Hidden
Python 3.8.0 Development Libraries (32-bit) (HKLM-x32\...\{5618017B-A985-45EB-9253-E5287C8EC89E}) (Version: 3.8.150.0 - Python Software Foundation) Hidden
Python 3.8.0 Documentation (32-bit) (HKLM-x32\...\{36FB0376-2B32-4BD4-A75C-865B56AA8021}) (Version: 3.8.150.0 - Python Software Foundation) Hidden
Python 3.8.0 Executables (32-bit) (HKLM-x32\...\{4623ABA8-AE5C-4799-B9F4-ECE858AE5429}) (Version: 3.8.150.0 - Python Software Foundation) Hidden
Python 3.8.0 pip Bootstrap (32-bit) (HKLM-x32\...\{F9A73836-C424-41DA-A8E6-9438FC6F30F5}) (Version: 3.8.150.0 - Python Software Foundation) Hidden
Python 3.8.0 Standard Library (32-bit) (HKLM-x32\...\{9A26DCB3-CCB9-4BCD-B9A6-00613011F5C9}) (Version: 3.8.150.0 - Python Software Foundation) Hidden
Python 3.8.0 Tcl/Tk Support (32-bit) (HKLM-x32\...\{978278A0-0090-4A9C-8610-001061A495AF}) (Version: 3.8.150.0 - Python Software Foundation) Hidden
Python 3.8.0 Test Suite (32-bit) (HKLM-x32\...\{C66B9C40-21E1-4CEC-A34F-130346F298A9}) (Version: 3.8.150.0 - Python Software Foundation) Hidden
Python 3.8.0 Utility Scripts (32-bit) (HKLM-x32\...\{0D64158A-8DFB-46E6-B455-3A6F73D5E412}) (Version: 3.8.150.0 - Python Software Foundation) Hidden
Python Launcher (HKLM-x32\...\{7DBA9B7D-924F-4CE8-8AE8-65977EF62744}) (Version: 3.8.6860.0 - Python Software Foundation)
qBittorrent 4.2.3 (HKLM-x32\...\qBittorrent) (Version: 4.2.3 - The qBittorrent project)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8383 - Realtek Semiconductor Corp.)
RescueTime 2.14.5.1 (HKLM-x32\...\{2505571C-03B3-4F9F-AC35-33F1CB4B5E9E}_is1) (Version: - RescueTime.com)
Slack (HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\slack) (Version: 4.5.1 - Slack Technologies Inc.)
Spotify (HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\Spotify) (Version: 1.1.12.449.g4109e645 - Spotify AB)
SteelSeries Engine 3.14.0 (HKLM\...\SteelSeries Engine 3) (Version: 3.14.0 - SteelSeries ApS)
TAP-Windows 9.21.2 (HKLM\...\TAP-Windows) (Version: 9.21.2 - )
TeamViewer 14 (HKLM-x32\...\TeamViewer) (Version: 14.5.5819 - TeamViewer)
Thunderbolt™ Software (HKLM-x32\...\{B43DE90F-2638-4FCC-982E-383200E80797}) (Version: 17.3.74.400 - Intel Corporation)
Typora version 0.9.86 (HKLM\...\{37771A20-7167-44C0-B322-FD3E54C56156}_is1) (Version: 0.9.86 - typora.io)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{32DC821E-4A7D-4878-BEE8-337FA153D7F2}) (Version: 2.63.0.0 - Microsoft Corporation) Hidden
Update for Windows 10 for x64-based Systems (KB4480730) (HKLM\...\{2E8B8BDD-03DF-4C1C-8C99-E6A4BCBF43CE}) (Version: 2.51.0.0 - Microsoft Corporation)
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-2) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-3) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
WinRAR 5.71 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.71.0 - win.rar GmbH)
World of Warcraft Classic (HKLM-x32\...\World of Warcraft Classic) (Version: - Blizzard Entertainment)
Packages:
=========
Killer Control Center -> C:\Program Files\WindowsApps\RivetNetworks.KillerControlCenter_1.6.2163.0_x64__rh07ty8m5nkag [2019-05-07] (Rivet Networks LLC)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-04-03] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-04-03] (Microsoft Corporation) [MS Ad]
Nahimic -> C:\Program Files\WindowsApps\A-Volute.Nahimic_1.4.4.0_x64__w2gh52qy24etm [2020-05-09] (A-Volute)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.2.168.0_x64__dt26b99r8h8gj [2019-04-07] (Realtek Semiconductor Corp)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync64.dll [2020-04-06] (Google LLC -> Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync64.dll [2020-04-06] (Google LLC -> Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync64.dll [2020-04-06] (Google LLC -> Google)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu64.dll [2020-04-06] (Google LLC -> Google)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [DaemonShellExtDriveLite] -> {C06369D6-E77D-4626-9656-1256312BD576} => C:\Program Files\DAEMON Tools Lite\dtshl64.dll [2019-06-13] (AVB Disc Soft, SIA -> Disc Soft Ltd)
ContextMenuHandlers3: [DaemonShellExtImageLite] -> {1D1B5D7B-0FC9-452E-902C-12BACD4FBC20} => C:\Program Files\DAEMON Tools Lite\dtshl64.dll [2019-06-13] (AVB Disc Soft, SIA -> Disc Soft Ltd)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-04-13] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu64.dll [2020-04-06] (Google LLC -> Google)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\cui_component.inf_amd64_df4f60b1cae9b14a\igfxDTCM.dll [2018-03-30] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2019-04-17] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-04-13] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
ShortcutWithArgument: C:\Users\Matej\Desktop\Software\Asana.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=gijpcmgkkjdlelnbnjmklkjpgcmamndb
ShortcutWithArgument: C:\Users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Simple EPUB Reader.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 6" --app-id=ojhbgcchcbdjdenibfmjofobklkkhofc
ShortcutWithArgument: C:\Users\Matej\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9501e18d7c2ab92e\Social Media - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 2"
ShortcutWithArgument: C:\Users\Matej\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Work - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 1"
ShortcutWithArgument: C:\Users\Matej\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\371b6590bc8d800\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 6"
ShortcutWithArgument: C:\Users\Matej\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\225bb61db2f318c1\Fun - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 3"
==================== Loaded Modules (Whitelisted) =============
2020-05-17 11:38 - 2020-05-17 11:38 - 000114176 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\_ctypes.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000173056 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\_elementtree.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 002133504 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\_hashlib.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000032256 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\_multiprocessing.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000046080 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\_psutil_windows.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000047616 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\_socket.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 002701824 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\_ssl.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000026112 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\_yappi.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000080896 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\bz2.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000016384 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\common.time34.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000007680 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\hashobjs_ext.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000301568 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\PIL._imaging.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000169472 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\pyexpat.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 001084416 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\pysqlite2._sqlite.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000548864 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\pythoncom27.dll
2020-05-17 11:38 - 2020-05-17 11:38 - 000137728 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\pywintypes27.dll
2020-05-17 11:38 - 2020-05-17 11:38 - 000010752 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\select.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000020992 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\thumbnails_ext.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000689664 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\unicodedata.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000119808 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\usb_ext.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000128512 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\win32api.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000438784 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\win32com.shell.shell.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000011776 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\win32crypt.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000023040 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\win32event.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000149504 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\win32file.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000223232 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\win32gui.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000048128 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\win32inet.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000029696 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\win32pdh.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000027648 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\win32pipe.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000044032 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\win32process.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000020480 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\win32profile.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000136192 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\win32security.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000026624 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\win32ts.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000034816 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\windows.conditional.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000038400 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\windows.connectivity.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000071680 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\windows.device_monitor.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000109056 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\windows.volumes.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000020480 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\windows.winwrap.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 001325056 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\wx._controls_.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 001489408 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\wx._core_.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 001007104 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\wx._gdi_.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000103424 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\wx._html2.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000916992 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\wx._misc_.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 001039872 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\wx._windows_.pyd
2018-04-25 22:30 - 2018-04-25 22:30 - 000240128 _____ (A-Volute) [File not signed] C:\Program Files (x86)\MSI\Dragon Center\NahimicAPI.dll
2018-11-23 17:01 - 2018-11-23 17:01 - 000438784 _____ (A-Volute) [File not signed] C:\Program Files (x86)\MSI\Dragon Center\YooMixCOM.dll
2016-08-11 06:34 - 2016-08-11 06:34 - 000047816 _____ (MICRO-STAR INTERNATIONAL CO., LTD -> www.internals.com) [File not signed] C:\Program Files (x86)\MSI\Dragon Center\MSIAPP_Service\WinIo64.dll
2015-06-12 05:35 - 2015-06-12 05:35 - 000047816 _____ (MICRO-STAR INTERNATIONAL CO., LTD -> www.internals.com) [File not signed] C:\Program Files (x86)\MSI\Dragon Center\WinIo64.dll
2020-05-17 11:38 - 2020-05-17 11:38 - 003042816 _____ (Python Software Foundation) [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\python27.dll
2020-05-17 11:38 - 2020-05-17 11:38 - 000202240 _____ (wxWidgets development team) [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\wxbase30u_net_vc90_x64.dll
2020-05-17 11:38 - 2020-05-17 11:38 - 002831872 _____ (wxWidgets development team) [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\wxbase30u_vc90_x64.dll
2020-05-17 11:38 - 2020-05-17 11:38 - 001654784 _____ (wxWidgets development team) [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\wxmsw30u_adv_vc90_x64.dll
2020-05-17 11:38 - 2020-05-17 11:38 - 006542336 _____ (wxWidgets development team) [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\wxmsw30u_core_vc90_x64.dll
2020-05-17 11:38 - 2020-05-17 11:38 - 000773632 _____ (wxWidgets development team) [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\wxmsw30u_html_vc90_x64.dll
2020-05-17 11:38 - 2020-05-17 11:38 - 000137216 _____ (wxWidgets development team) [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\wxmsw30u_webview_vc90_x64.dll
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Association (Whitelisted) =================
==================== Internet Explorer trusted/restricted ==========
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\sharepoint.com -> hxxps://vse-files.sharepoint.com
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2017-09-29 15:46 - 2019-08-18 12:28 - 000000027 _____ C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1 localhost
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-105526560-3629586505-1581754559-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Matej\Desktop\722739-wallpaper-of-bears-1920x1200-for-iphone-6.jpg
DNS Servers: 10.0.0.138
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKLM\...\StartupApproved\StartupFolder: => "SteelSeries Engine 3.lnk"
HKLM\...\StartupApproved\Run: => "SecurityHealth"
HKLM\...\StartupApproved\Run: => "RtkAudUService"
HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\StartupApproved\StartupFolder: => "EvernoteClipper.lnk"
HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\StartupApproved\Run: => "com.squirrel.slack.slack"
HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\StartupApproved\Run: => "OneDriveSetup"
HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\StartupApproved\Run: => "DAEMON Tools Lite Automount"
HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\StartupApproved\Run: => "Lync"
HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\StartupApproved\Run: => "Battle.net"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{CCB138A2-CD2C-461B-80DA-9CE32ABE7603}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{685C2BCA-AE63-43C5-A341-074DEC948032}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{0C0C1318-1ADD-4928-9DFF-6146E2501737}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{BBC7A81D-6C83-4348-9AC5-DCB54F3146E5}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{F5F69316-2CB1-47F2-B882-CE0F86D82852}] => (Allow) C:\Users\Matej\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{F1E853C7-FBFD-44DC-BC48-F295208D8331}] => (Allow) C:\Users\Matej\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [UDP Query User{6825F6F1-F7CB-4F4F-9F66-AD4B58ED085D}C:\program files (x86)\total war three kingdoms\three_kingdoms.exe] => (Block) C:\program files (x86)\total war three kingdoms\three_kingdoms.exe => No File
FirewallRules: [TCP Query User{8F0E75BD-0681-4AB4-8DCF-7C04C362D54F}C:\program files (x86)\total war three kingdoms\three_kingdoms.exe] => (Block) C:\program files (x86)\total war three kingdoms\three_kingdoms.exe => No File
FirewallRules: [{683EEC04-FBCC-4087-8F7C-67C9D7D5A595}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{1E1A1659-AF50-45A2-A3CB-D1D912684779}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{6F32E161-C017-4088-B88D-1815AFFB2B6F}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [{34B2DE71-4C42-4464-854D-60F0EFA69C63}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [{53FD5C46-3509-4B09-983C-12F3CBA258F1}] => (Allow) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe (AVB Disc Soft, SIA -> Disc Soft Ltd)
FirewallRules: [{B5B8DBDA-CE72-46BE-B453-0DECAC007A99}] => (Allow) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe (AVB Disc Soft, SIA -> Disc Soft Ltd)
FirewallRules: [UDP Query User{BD4C61A6-B966-4F49-9DEA-08B86EC1CBCA}C:\users\matej\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\matej\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [TCP Query User{C7093E7D-54A1-4F1B-89A9-E97387FF9068}C:\users\matej\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\matej\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{004A46C5-9FC5-4084-B6FE-ACF744C2A616}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe (Intel Corporation -> )
FirewallRules: [{1A52BF34-C912-44B0-B9C8-D2C1ED08A3C7}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe => No File
FirewallRules: [{16C2767B-4249-4877-BC47-529F07F9AA8F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe => No File
FirewallRules: [{D8F30375-3C72-454B-8118-32490EE41161}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe => No File
FirewallRules: [{F2206DE6-0D14-4261-AB24-34811173626D}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe => No File
FirewallRules: [TCP Query User{A87F28E8-907D-4664-AA28-5FAA8C93F0F0}C:\users\matej\appdata\local\temp\temp1_msiproductreghelper31.zip\msiproductreghelper.exe] => (Allow) C:\users\matej\appdata\local\temp\temp1_msiproductreghelper31.zip\msiproductreghelper.exe => No File
FirewallRules: [UDP Query User{FF8CDA2D-027A-409B-8160-78D2D96E3734}C:\users\matej\appdata\local\temp\temp1_msiproductreghelper31.zip\msiproductreghelper.exe] => (Allow) C:\users\matej\appdata\local\temp\temp1_msiproductreghelper31.zip\msiproductreghelper.exe => No File
FirewallRules: [{35240BEF-8581-414D-BF29-5A55B25D7DB6}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{814D32AB-B28C-4A0D-BFA7-52BC66CCD8E1}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{0007E957-4B5A-4314-8755-91FA71995FBE}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{99EDF490-637C-43AC-9F13-4A7250F5CEDF}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{56D57F84-A3D0-404B-A9B7-BA53DCA8721B}C:\program files\sap predictive analytics\desktop\expert\desktop\sappredictiveanalysis.exe] => (Allow) C:\program files\sap predictive analytics\desktop\expert\desktop\sappredictiveanalysis.exe => No File
FirewallRules: [UDP Query User{98E34F87-711F-48B0-8D52-522AC59561E6}C:\program files\sap predictive analytics\desktop\expert\desktop\sappredictiveanalysis.exe] => (Allow) C:\program files\sap predictive analytics\desktop\expert\desktop\sappredictiveanalysis.exe => No File
FirewallRules: [TCP Query User{8F6C0E61-7E57-4637-AB3F-176F0A532313}C:\program files (x86)\world of warcraft\_classic_\utils\wowvoiceproxy.exe] => (Allow) C:\program files (x86)\world of warcraft\_classic_\utils\wowvoiceproxy.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [UDP Query User{58D74510-171C-45A9-8CA3-3BABA31D1420}C:\program files (x86)\world of warcraft\_classic_\utils\wowvoiceproxy.exe] => (Allow) C:\program files (x86)\world of warcraft\_classic_\utils\wowvoiceproxy.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [{CE252584-F4AB-479A-B1E6-78ADAB96E90B}] => (Allow) C:\Program Files (x86)\RescueTime\RescueTime.exe (RescueTime, Inc.) [File not signed]
FirewallRules: [{158D0DD0-CC92-41CE-8110-BD97631AAD6A}] => (Allow) C:\Program Files (x86)\RescueTime\RescueTime.exe (RescueTime, Inc.) [File not signed]
FirewallRules: [TCP Query User{3C5BE22D-FC7C-4975-96D3-FF8D549EA864}C:\program files (x86)\hearts of iron iv\hoi4.exe] => (Allow) C:\program files (x86)\hearts of iron iv\hoi4.exe => No File
FirewallRules: [UDP Query User{A82B0E0B-E553-46E8-BD74-913B2D2E0AF9}C:\program files (x86)\hearts of iron iv\hoi4.exe] => (Allow) C:\program files (x86)\hearts of iron iv\hoi4.exe => No File
FirewallRules: [{8D8ADA86-0F62-47EB-8731-EB56FA7FCAB2}] => (Block) C:\program files (x86)\hearts of iron iv\hoi4.exe => No File
FirewallRules: [{74C99011-05D2-4CFA-A63E-D21429321086}] => (Block) C:\program files (x86)\hearts of iron iv\hoi4.exe => No File
FirewallRules: [TCP Query User{CC003030-DFEB-48AB-AD45-724858ACBE7A}C:\users\matej\appdata\local\slack\app-4.3.2\slack.exe] => (Allow) C:\users\matej\appdata\local\slack\app-4.3.2\slack.exe => No File
FirewallRules: [UDP Query User{23916BC1-16DD-4FD9-AE2A-08F025A8119A}C:\users\matej\appdata\local\slack\app-4.3.2\slack.exe] => (Allow) C:\users\matej\appdata\local\slack\app-4.3.2\slack.exe => No File
FirewallRules: [{05EFA4C5-1B35-440A-844A-533669276B58}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{451C9070-CB89-437B-B3D2-6F3714FB0767}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe () [File not signed]
FirewallRules: [{84458AD3-8553-480E-8273-FB22D218AD43}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe () [File not signed]
FirewallRules: [TCP Query User{5EDFE9FF-229B-4AA7-8399-181BF65F6162}C:\users\matej\downloads\factorio.v0.18.15\tests\x64\factorio-test.exe] => (Allow) C:\users\matej\downloads\factorio.v0.18.15\tests\x64\factorio-test.exe => No File
FirewallRules: [UDP Query User{78F3C97E-8907-40F8-9F72-74E13E0A02D4}C:\users\matej\downloads\factorio.v0.18.15\tests\x64\factorio-test.exe] => (Allow) C:\users\matej\downloads\factorio.v0.18.15\tests\x64\factorio-test.exe => No File
FirewallRules: [TCP Query User{0898A2BB-3EB1-42E1-8AF6-9F4AC8F7B434}C:\users\matej\downloads\ostriv v0.3.2.0\x64\ostriv.exe] => (Block) C:\users\matej\downloads\ostriv v0.3.2.0\x64\ostriv.exe => No File
FirewallRules: [UDP Query User{1A127617-571E-43D2-B7AD-5AE10A6CF989}C:\users\matej\downloads\ostriv v0.3.2.0\x64\ostriv.exe] => (Block) C:\users\matej\downloads\ostriv v0.3.2.0\x64\ostriv.exe => No File
FirewallRules: [TCP Query User{AD0D2FF8-5EF7-4F71-838B-FAC8FB6FBEA9}C:\users\matej\downloads\good company\goodcompany.exe] => (Block) C:\users\matej\downloads\good company\goodcompany.exe => No File
FirewallRules: [UDP Query User{3BDE8017-42CC-4891-B969-AF126F8262C1}C:\users\matej\downloads\good company\goodcompany.exe] => (Block) C:\users\matej\downloads\good company\goodcompany.exe => No File
FirewallRules: [TCP Query User{4477359B-E1F0-4A3F-AB16-53A04F3EF62B}C:\program files (x86)\steam\steamapps\common\europa universalis iv\eu4.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\europa universalis iv\eu4.exe => No File
FirewallRules: [UDP Query User{DBE504D4-A508-4A89-A070-2B20CFDFBAE2}C:\program files (x86)\steam\steamapps\common\europa universalis iv\eu4.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\europa universalis iv\eu4.exe => No File
FirewallRules: [TCP Query User{3A3D99E7-85A1-41EB-8C41-9F6AFA8C91EA}C:\users\matej\desktop\software\ostriv v0.3.2.0\x64\ostriv.exe] => (Block) C:\users\matej\desktop\software\ostriv v0.3.2.0\x64\ostriv.exe => No File
FirewallRules: [UDP Query User{01430204-D9F8-4F13-8974-F576223894DD}C:\users\matej\desktop\software\ostriv v0.3.2.0\x64\ostriv.exe] => (Block) C:\users\matej\desktop\software\ostriv v0.3.2.0\x64\ostriv.exe => No File
FirewallRules: [{C5AFD6EF-1501-4BCE-BA9C-2B45CE50EA31}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{AA7B9479-FBF6-436D-8E65-85128AEBDAE1}] => (Allow) C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\brave.exe (Brave Software, Inc. -> Brave Software, Inc.)
==================== Restore Points =========================
29-04-2020 13:53:48 Microsoft Visual C++ 2017 Redistributable (x64) - 14.12.25810
01-05-2020 17:55:49 Installed Paradox Launcher v2
10-05-2020 19:28:17 Scheduled Checkpoint
11-05-2020 20:10:44 Windows Modules Installer
14-05-2020 17:14:02 Removed Paradox Launcher v2
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (05/17/2020 11:49:25 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (5844,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (05/16/2020 11:28:12 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x8007045b, A system shutdown is in progress.
.
Error: (05/16/2020 11:28:12 PM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started. [0x8007045b, A system shutdown is in progress.
]
Error: (05/16/2020 11:28:12 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x8007045b, A system shutdown is in progress.
.
Error: (05/16/2020 11:28:12 PM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started. [0x8007045b, A system shutdown is in progress.
]
Error: (05/16/2020 11:15:19 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (11476,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (05/16/2020 11:06:08 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (4848,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (05/16/2020 04:00:16 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (2784,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
System errors:
=============
Error: (05/16/2020 11:28:09 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-QMQ3BRT)
Description: The server A-Volute.Nahimic_1.4.4.0_x64__w2gh52qy24etm!App did not register with DCOM within the required timeout.
Error: (05/16/2020 04:11:35 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-QMQ3BRT)
Description: The server A-Volute.Nahimic_1.4.4.0_x64__w2gh52qy24etm!App did not register with DCOM within the required timeout.
Error: (05/15/2020 07:09:39 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-QMQ3BRT)
Description: The server A-Volute.Nahimic_1.4.4.0_x64__w2gh52qy24etm!App did not register with DCOM within the required timeout.
Error: (05/14/2020 07:48:54 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-QMQ3BRT)
Description: The server A-Volute.Nahimic_1.4.4.0_x64__w2gh52qy24etm!App did not register with DCOM within the required timeout.
Error: (05/14/2020 01:42:08 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-QMQ3BRT)
Description: The server A-Volute.Nahimic_1.4.4.0_x64__w2gh52qy24etm!App did not register with DCOM within the required timeout.
Error: (05/13/2020 10:18:37 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-QMQ3BRT)
Description: The server A-Volute.Nahimic_1.4.4.0_x64__w2gh52qy24etm!App did not register with DCOM within the required timeout.
Error: (05/13/2020 10:14:20 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-QMQ3BRT)
Description: The server A-Volute.Nahimic_1.4.4.0_x64__w2gh52qy24etm!App did not register with DCOM within the required timeout.
Error: (05/13/2020 10:10:14 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-QMQ3BRT)
Description: The server A-Volute.Nahimic_1.4.4.0_x64__w2gh52qy24etm!App did not register with DCOM within the required timeout.
Windows Defender:
===================================
Date: 2020-05-04 10:36:37.805
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {7666FDC6-AF7D-4C12-BEC9-82880A024933}
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2020-04-07 17:43:22.278
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {E887CA2F-38AC-458A-A885-7AFF65FAB725}
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2020-03-31 11:59:02.224
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {35CC6010-740C-41EE-9009-B45EFEFDCD9B}
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2020-03-31 11:17:51.238
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {96E44935-9E1C-498E-B143-C7C39038C2B3}
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2020-03-21 13:04:46.321
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {FF3B7EAD-CC53-4705-84C7-7335CC1633F4}
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2020-05-13 11:09:15.984
Description:
Windows Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 1.315.501.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.17000.7
Error code: 0x80240438
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
Date: 2020-05-10 21:43:51.721
Description:
Windows Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 1.315.359.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.17000.7
Error code: 0x80240022
Error description: The program can't check for definition updates.
Date: 2020-05-10 21:43:51.720
Description:
Windows Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 1.315.359.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.17000.7
Error code: 0x80240022
Error description: The program can't check for definition updates.
Date: 2020-04-20 18:59:56.648
Description:
Windows Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 1.313.1441.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.16900.4
Error code: 0x8007045b
Error description: A system shutdown is in progress.
Date: 2020-03-19 16:21:29.857
Description:
Windows Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 1.311.1454.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.16800.2
Error code: 0x80240022
Error description: The program can't check for definition updates.
CodeIntegrity:
===================================
Date: 2020-05-13 22:24:22.136
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe) attempted to load \Device\HarddiskVolume3\ProgramData\A-Volute\A-Volute.Nahimic\Modules\Scheduled\x64\A-Volute.NahimicDevProps2.dll that did not meet the Store signing level requirements.
Date: 2020-05-13 22:24:22.129
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe) attempted to load \Device\HarddiskVolume3\ProgramData\A-Volute\A-Volute.Nahimic\Modules\Scheduled\x64\NahimicOSD.dll that did not meet the Store signing level requirements.
Date: 2020-05-13 22:24:19.865
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe) attempted to load \Device\HarddiskVolume3\ProgramData\A-Volute\A-Volute.Nahimic\Modules\Scheduled\x64\A-Volute.NahimicDevProps2.dll that did not meet the Store signing level requirements.
Date: 2020-05-13 22:24:19.857
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe) attempted to load \Device\HarddiskVolume3\ProgramData\A-Volute\A-Volute.Nahimic\Modules\Scheduled\x64\NahimicOSD.dll that did not meet the Store signing level requirements.
Date: 2020-04-13 17:47:50.195
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe) attempted to load \Device\HarddiskVolume3\ProgramData\A-Volute\A-Volute.Nahimic\Modules\Scheduled\x64\A-Volute.NahimicDevProps2.dll that did not meet the Store signing level requirements.
Date: 2020-04-13 17:47:50.188
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe) attempted to load \Device\HarddiskVolume3\ProgramData\A-Volute\A-Volute.Nahimic\Modules\Scheduled\x64\NahimicOSD.dll that did not meet the Store signing level requirements.
Date: 2020-04-13 17:47:48.771
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe) attempted to load \Device\HarddiskVolume3\ProgramData\A-Volute\A-Volute.Nahimic\Modules\Scheduled\x64\A-Volute.NahimicDevProps2.dll that did not meet the Store signing level requirements.
Date: 2020-04-13 17:47:48.763
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe) attempted to load \Device\HarddiskVolume3\ProgramData\A-Volute\A-Volute.Nahimic\Modules\Scheduled\x64\NahimicOSD.dll that did not meet the Store signing level requirements.
==================== Memory info ===========================
BIOS: American Megatrends Inc. E16Q2IMS.111 12/05/2018
Motherboard: Micro-Star International Co., Ltd. MS-16Q2
Processor: Intel(R) Core(TM) i7-8750H CPU @ 2.20GHz
Percentage of memory in use: 35%
Total physical RAM: 16227.03 MB
Available physical RAM: 10444.67 MB
Total Virtual: 18659.03 MB
Available Virtual: 11812.35 MB
==================== Drives ================================
Drive c: (Windows) (Fixed) (Total:237.18 GB) (Free:95.49 GB) NTFS
\\?\Volume{e8093537-c30a-4149-a597-ef38ab14678e}\ (WinRE tools) (Fixed) (Total:0.88 GB) (Free:0.44 GB) NTFS
\\?\Volume{bdd51151-22c4-48e6-bb71-2dbd94302ddc}\ (SYSTEM) (Fixed) (Total:0.29 GB) (Free:0.26 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Size: 238.5 GB) (Disk ID: B5C93904)
Partition: GPT.
==================== End of Addition.txt =======================
Děkuji za pomoc. Vyřešilo by to naformatování disku? A čistá instalace.
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-05-2020 01
Ran by Matej (17-05-2020 12:18:15)
Running from C:\Users\Matej\Downloads
Windows 10 Home Version 1909 18363.836 (X64) (2019-09-17 10:52:27)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-105526560-3629586505-1581754559-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-105526560-3629586505-1581754559-503 - Limited - Disabled)
Guest (S-1-5-21-105526560-3629586505-1581754559-501 - Limited - Disabled)
Matej (S-1-5-21-105526560-3629586505-1581754559-1001 - Administrator - Enabled) => C:\Users\Matej
WDAGUtilityAccount (S-1-5-21-105526560-3629586505-1581754559-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 20.009.20063 - Adobe Systems Incorporated)
Atom (HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\atom) (Version: 1.42.0 - GitHub Inc.)
Backup and Sync from Google (HKLM\...\{FE296942-D2D3-4149-8895-60655FE4CFDE}) (Version: 3.49.9800.0000 - Google, Inc.)
Bad North (HKLM-x32\...\1656388860_is1) (Version: 8236d7f - GOG.com)
Battery Calibration (HKLM-x32\...\{634AC01E-49DB-4AD2-B87C-90D4DCC6AFA1}) (Version: 1.0.1505.2901 - Micro-Star International Co., Ltd.) Hidden
Battery Calibration (HKLM-x32\...\InstallShield_{634AC01E-49DB-4AD2-B87C-90D4DCC6AFA1}) (Version: 1.0.1505.2901 - Micro-Star International Co., Ltd.)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
BitTorrent (HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\BitTorrent) (Version: 7.10.5.45312 - BitTorrent Inc.)
Brave (HKLM-x32\...\BraveSoftware Brave-Browser) (Version: 81.1.8.96 - Brave Software Inc)
CCleaner (HKLM\...\CCleaner) (Version: 5.55 - Piriform)
CopyTrans HEIC for Windows (HKLM\...\CopyTrans HEIC for Windows_is1) (Version: 1.0.0.5 - Ursa Minor Ltd)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.11.0.0939 - Disc Soft Ltd)
Dragon Center (HKLM-x32\...\{C65B26BC-5A6F-4135-9678-55A877655471}) (Version: 2.5.1904.1201 - Micro-Star International Co., Ltd.) Hidden
Dragon Center (HKLM-x32\...\InstallShield_{C65B26BC-5A6F-4135-9678-55A877655471}) (Version: 2.5.1904.1201 - Micro-Star International Co., Ltd.)
Evernote v. 6.17.7 (HKLM-x32\...\{B47B6F80-6143-11E9-9F8E-005056951CAD}) (Version: 6.17.7.8474 - Evernote Corp.)
f.lux (HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\Flux) (Version: - f.lux Software LLC)
FileZilla Client 3.43.0 (HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\FileZilla Client) (Version: 3.43.0 - Tim Kosse)
Git version 2.22.0.windows.1 (HKLM\...\Git_is1) (Version: 2.22.0.windows.1 - The Git Development Community)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 81.0.4044.138 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.99.0 - Google Inc.) Hidden
gretl version 2020b (x86_64) (HKLM\...\gretl_is1) (Version: 2020b - The gretl team)
Icecream Ebook Reader version 5.12 (HKLM-x32\...\{B8C30F0F-1F23-49E1-A3ED-44DE17660EE2}_is1) (Version: 5.12 - Icecream Apps)
Intel(R) Chipset Device Software (HKLM-x32\...\{55d73ea7-6354-42db-8831-02d048ae57f8}) (Version: 10.1.17541.8066 - Intel(R) Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 1808.12.0.1102 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 23.20.16.4974 - Intel Corporation)
Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{00000030-0200-1033-84C8-B8D95FA3C8C3}) (Version: 20.30.0 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{f8c930bd-0a68-425f-8c11-87723d1e2c97}) (Version: 20.90.0 - Intel Corporation)
KB9X Radio Switch Driver (HKLM\...\3498B7189B13CBC3673674CD226F4540F628CCB8) (Version: 1.1.5.0 - ENE TECHNOLOGY INC.)
LYNX Trading (HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\5556-0005-2700-0000) (Version: (978.1d) 20191023 12:51:36 - LYNX)
Malwarebytes version 4.1.0.56 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.1.0.56 - Malwarebytes)
Microsoft 365 - cs-cz (HKLM\...\O365HomePremRetail - cs-cz) (Version: 16.0.12827.20160 - Microsoft Corporation)
Microsoft 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.12827.20160 - Microsoft Corporation)
Microsoft 365 for enterprise - cs-cz (HKLM\...\O365ProPlusRetail - cs-cz) (Version: 16.0.12827.20160 - Microsoft Corporation)
Microsoft 365 for enterprise - en-us (HKLM\...\O365ProPlusRetail - en-us) (Version: 16.0.12827.20160 - Microsoft Corporation)
Microsoft Mouse and Keyboard Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 12.181.137.0 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.12.25810 (HKLM-x32\...\{e2ee15e2-a480-4bc5-bfb7-e9803d1d9823}) (Version: 14.12.25810.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.10.25008 (HKLM-x32\...\{c239cea1-d49e-4e16-8e87-8c055765f7ec}) (Version: 14.10.25008.0 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Mozilla Firefox 69.0.1 (x64 cs) (HKLM\...\Mozilla Firefox 69.0.1 (x64 cs)) (Version: 69.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 67.0.4 - Mozilla)
Node.js (HKLM\...\{E3C2DC65-9DCA-4422-BDDE-0489B89A16D2}) (Version: 10.16.0 - Node.js Foundation)
Notion 1.0.8 (HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\fcdf0d7f-424b-5f10-a1c7-a8f643f21adf) (Version: 1.0.8 - Notion Labs, Incorporated)
Notion 2.0.8 (HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\{fcdf0d7f-424b-5f10-a1c7-a8f643f21adf}) (Version: 2.0.8 - Notion Labs, Incorporated)
NVIDIA HD Audio Driver 1.3.38.16 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.16 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation)
OBS Studio (HKLM-x32\...\OBS Studio) (Version: 24.0.3 - OBS Project)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.12827.20160 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.12827.20160 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0405-1000-0000000FF1CE}) (Version: 16.0.12827.20160 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.12827.20160 - Microsoft Corporation) Hidden
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
PotPlayer-64 bit (HKLM\...\PotPlayer64) (Version: 200317 - Kakao Corp.)
Pushbullet version 338 (HKLM-x32\...\{7578F204-49E7-4830-B051-14C23F408BFE}_is1) (Version: 338 - Pushbullet Inc)
Python 3.8.0 (32-bit) (HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\{37ec7371-0827-49f1-be8a-63c158184b9c}) (Version: 3.8.150.0 - Python Software Foundation)
Python 3.8.0 Core Interpreter (32-bit) (HKLM-x32\...\{8C9832C5-C3B1-4596-B8E9-F32ED263FC56}) (Version: 3.8.150.0 - Python Software Foundation) Hidden
Python 3.8.0 Development Libraries (32-bit) (HKLM-x32\...\{5618017B-A985-45EB-9253-E5287C8EC89E}) (Version: 3.8.150.0 - Python Software Foundation) Hidden
Python 3.8.0 Documentation (32-bit) (HKLM-x32\...\{36FB0376-2B32-4BD4-A75C-865B56AA8021}) (Version: 3.8.150.0 - Python Software Foundation) Hidden
Python 3.8.0 Executables (32-bit) (HKLM-x32\...\{4623ABA8-AE5C-4799-B9F4-ECE858AE5429}) (Version: 3.8.150.0 - Python Software Foundation) Hidden
Python 3.8.0 pip Bootstrap (32-bit) (HKLM-x32\...\{F9A73836-C424-41DA-A8E6-9438FC6F30F5}) (Version: 3.8.150.0 - Python Software Foundation) Hidden
Python 3.8.0 Standard Library (32-bit) (HKLM-x32\...\{9A26DCB3-CCB9-4BCD-B9A6-00613011F5C9}) (Version: 3.8.150.0 - Python Software Foundation) Hidden
Python 3.8.0 Tcl/Tk Support (32-bit) (HKLM-x32\...\{978278A0-0090-4A9C-8610-001061A495AF}) (Version: 3.8.150.0 - Python Software Foundation) Hidden
Python 3.8.0 Test Suite (32-bit) (HKLM-x32\...\{C66B9C40-21E1-4CEC-A34F-130346F298A9}) (Version: 3.8.150.0 - Python Software Foundation) Hidden
Python 3.8.0 Utility Scripts (32-bit) (HKLM-x32\...\{0D64158A-8DFB-46E6-B455-3A6F73D5E412}) (Version: 3.8.150.0 - Python Software Foundation) Hidden
Python Launcher (HKLM-x32\...\{7DBA9B7D-924F-4CE8-8AE8-65977EF62744}) (Version: 3.8.6860.0 - Python Software Foundation)
qBittorrent 4.2.3 (HKLM-x32\...\qBittorrent) (Version: 4.2.3 - The qBittorrent project)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8383 - Realtek Semiconductor Corp.)
RescueTime 2.14.5.1 (HKLM-x32\...\{2505571C-03B3-4F9F-AC35-33F1CB4B5E9E}_is1) (Version: - RescueTime.com)
Slack (HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\slack) (Version: 4.5.1 - Slack Technologies Inc.)
Spotify (HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\Spotify) (Version: 1.1.12.449.g4109e645 - Spotify AB)
SteelSeries Engine 3.14.0 (HKLM\...\SteelSeries Engine 3) (Version: 3.14.0 - SteelSeries ApS)
TAP-Windows 9.21.2 (HKLM\...\TAP-Windows) (Version: 9.21.2 - )
TeamViewer 14 (HKLM-x32\...\TeamViewer) (Version: 14.5.5819 - TeamViewer)
Thunderbolt™ Software (HKLM-x32\...\{B43DE90F-2638-4FCC-982E-383200E80797}) (Version: 17.3.74.400 - Intel Corporation)
Typora version 0.9.86 (HKLM\...\{37771A20-7167-44C0-B322-FD3E54C56156}_is1) (Version: 0.9.86 - typora.io)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{32DC821E-4A7D-4878-BEE8-337FA153D7F2}) (Version: 2.63.0.0 - Microsoft Corporation) Hidden
Update for Windows 10 for x64-based Systems (KB4480730) (HKLM\...\{2E8B8BDD-03DF-4C1C-8C99-E6A4BCBF43CE}) (Version: 2.51.0.0 - Microsoft Corporation)
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-2) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-3) (Version: 1.0.65.1 - LunarG, Inc.) Hidden
WinRAR 5.71 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.71.0 - win.rar GmbH)
World of Warcraft Classic (HKLM-x32\...\World of Warcraft Classic) (Version: - Blizzard Entertainment)
Packages:
=========
Killer Control Center -> C:\Program Files\WindowsApps\RivetNetworks.KillerControlCenter_1.6.2163.0_x64__rh07ty8m5nkag [2019-05-07] (Rivet Networks LLC)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-04-03] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-04-03] (Microsoft Corporation) [MS Ad]
Nahimic -> C:\Program Files\WindowsApps\A-Volute.Nahimic_1.4.4.0_x64__w2gh52qy24etm [2020-05-09] (A-Volute)
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.2.168.0_x64__dt26b99r8h8gj [2019-04-07] (Realtek Semiconductor Corp)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync64.dll [2020-04-06] (Google LLC -> Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync64.dll [2020-04-06] (Google LLC -> Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync64.dll [2020-04-06] (Google LLC -> Google)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu64.dll [2020-04-06] (Google LLC -> Google)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [DaemonShellExtDriveLite] -> {C06369D6-E77D-4626-9656-1256312BD576} => C:\Program Files\DAEMON Tools Lite\dtshl64.dll [2019-06-13] (AVB Disc Soft, SIA -> Disc Soft Ltd)
ContextMenuHandlers3: [DaemonShellExtImageLite] -> {1D1B5D7B-0FC9-452E-902C-12BACD4FBC20} => C:\Program Files\DAEMON Tools Lite\dtshl64.dll [2019-06-13] (AVB Disc Soft, SIA -> Disc Soft Ltd)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-04-13] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu64.dll [2020-04-06] (Google LLC -> Google)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\cui_component.inf_amd64_df4f60b1cae9b14a\igfxDTCM.dll [2018-03-30] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2019-04-17] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-04-13] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
ShortcutWithArgument: C:\Users\Matej\Desktop\Software\Asana.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=gijpcmgkkjdlelnbnjmklkjpgcmamndb
ShortcutWithArgument: C:\Users\Matej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Simple EPUB Reader.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory="Profile 6" --app-id=ojhbgcchcbdjdenibfmjofobklkkhofc
ShortcutWithArgument: C:\Users\Matej\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9501e18d7c2ab92e\Social Media - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 2"
ShortcutWithArgument: C:\Users\Matej\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Work - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 1"
ShortcutWithArgument: C:\Users\Matej\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\371b6590bc8d800\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 6"
ShortcutWithArgument: C:\Users\Matej\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\225bb61db2f318c1\Fun - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 3"
==================== Loaded Modules (Whitelisted) =============
2020-05-17 11:38 - 2020-05-17 11:38 - 000114176 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\_ctypes.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000173056 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\_elementtree.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 002133504 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\_hashlib.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000032256 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\_multiprocessing.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000046080 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\_psutil_windows.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000047616 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\_socket.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 002701824 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\_ssl.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000026112 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\_yappi.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000080896 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\bz2.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000016384 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\common.time34.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000007680 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\hashobjs_ext.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000301568 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\PIL._imaging.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000169472 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\pyexpat.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 001084416 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\pysqlite2._sqlite.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000548864 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\pythoncom27.dll
2020-05-17 11:38 - 2020-05-17 11:38 - 000137728 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\pywintypes27.dll
2020-05-17 11:38 - 2020-05-17 11:38 - 000010752 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\select.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000020992 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\thumbnails_ext.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000689664 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\unicodedata.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000119808 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\usb_ext.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000128512 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\win32api.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000438784 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\win32com.shell.shell.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000011776 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\win32crypt.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000023040 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\win32event.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000149504 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\win32file.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000223232 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\win32gui.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000048128 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\win32inet.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000029696 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\win32pdh.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000027648 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\win32pipe.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000044032 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\win32process.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000020480 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\win32profile.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000136192 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\win32security.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000026624 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\win32ts.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000034816 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\windows.conditional.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000038400 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\windows.connectivity.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000071680 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\windows.device_monitor.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000109056 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\windows.volumes.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000020480 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\windows.winwrap.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 001325056 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\wx._controls_.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 001489408 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\wx._core_.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 001007104 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\wx._gdi_.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000103424 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\wx._html2.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 000916992 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\wx._misc_.pyd
2020-05-17 11:38 - 2020-05-17 11:38 - 001039872 _____ () [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\wx._windows_.pyd
2018-04-25 22:30 - 2018-04-25 22:30 - 000240128 _____ (A-Volute) [File not signed] C:\Program Files (x86)\MSI\Dragon Center\NahimicAPI.dll
2018-11-23 17:01 - 2018-11-23 17:01 - 000438784 _____ (A-Volute) [File not signed] C:\Program Files (x86)\MSI\Dragon Center\YooMixCOM.dll
2016-08-11 06:34 - 2016-08-11 06:34 - 000047816 _____ (MICRO-STAR INTERNATIONAL CO., LTD -> www.internals.com) [File not signed] C:\Program Files (x86)\MSI\Dragon Center\MSIAPP_Service\WinIo64.dll
2015-06-12 05:35 - 2015-06-12 05:35 - 000047816 _____ (MICRO-STAR INTERNATIONAL CO., LTD -> www.internals.com) [File not signed] C:\Program Files (x86)\MSI\Dragon Center\WinIo64.dll
2020-05-17 11:38 - 2020-05-17 11:38 - 003042816 _____ (Python Software Foundation) [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\python27.dll
2020-05-17 11:38 - 2020-05-17 11:38 - 000202240 _____ (wxWidgets development team) [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\wxbase30u_net_vc90_x64.dll
2020-05-17 11:38 - 2020-05-17 11:38 - 002831872 _____ (wxWidgets development team) [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\wxbase30u_vc90_x64.dll
2020-05-17 11:38 - 2020-05-17 11:38 - 001654784 _____ (wxWidgets development team) [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\wxmsw30u_adv_vc90_x64.dll
2020-05-17 11:38 - 2020-05-17 11:38 - 006542336 _____ (wxWidgets development team) [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\wxmsw30u_core_vc90_x64.dll
2020-05-17 11:38 - 2020-05-17 11:38 - 000773632 _____ (wxWidgets development team) [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\wxmsw30u_html_vc90_x64.dll
2020-05-17 11:38 - 2020-05-17 11:38 - 000137216 _____ (wxWidgets development team) [File not signed] C:\Users\Matej\AppData\Local\Temp\_MEI105442\wxmsw30u_webview_vc90_x64.dll
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Association (Whitelisted) =================
==================== Internet Explorer trusted/restricted ==========
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\sharepoint.com -> hxxps://vse-files.sharepoint.com
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2017-09-29 15:46 - 2019-08-18 12:28 - 000000027 _____ C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1 localhost
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-105526560-3629586505-1581754559-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Matej\Desktop\722739-wallpaper-of-bears-1920x1200-for-iphone-6.jpg
DNS Servers: 10.0.0.138
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKLM\...\StartupApproved\StartupFolder: => "SteelSeries Engine 3.lnk"
HKLM\...\StartupApproved\Run: => "SecurityHealth"
HKLM\...\StartupApproved\Run: => "RtkAudUService"
HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\StartupApproved\StartupFolder: => "EvernoteClipper.lnk"
HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\StartupApproved\Run: => "com.squirrel.slack.slack"
HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\StartupApproved\Run: => "OneDriveSetup"
HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\StartupApproved\Run: => "DAEMON Tools Lite Automount"
HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\StartupApproved\Run: => "Lync"
HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-105526560-3629586505-1581754559-1001\...\StartupApproved\Run: => "Battle.net"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{CCB138A2-CD2C-461B-80DA-9CE32ABE7603}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{685C2BCA-AE63-43C5-A341-074DEC948032}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{0C0C1318-1ADD-4928-9DFF-6146E2501737}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{BBC7A81D-6C83-4348-9AC5-DCB54F3146E5}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{F5F69316-2CB1-47F2-B882-CE0F86D82852}] => (Allow) C:\Users\Matej\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{F1E853C7-FBFD-44DC-BC48-F295208D8331}] => (Allow) C:\Users\Matej\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [UDP Query User{6825F6F1-F7CB-4F4F-9F66-AD4B58ED085D}C:\program files (x86)\total war three kingdoms\three_kingdoms.exe] => (Block) C:\program files (x86)\total war three kingdoms\three_kingdoms.exe => No File
FirewallRules: [TCP Query User{8F0E75BD-0681-4AB4-8DCF-7C04C362D54F}C:\program files (x86)\total war three kingdoms\three_kingdoms.exe] => (Block) C:\program files (x86)\total war three kingdoms\three_kingdoms.exe => No File
FirewallRules: [{683EEC04-FBCC-4087-8F7C-67C9D7D5A595}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{1E1A1659-AF50-45A2-A3CB-D1D912684779}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{6F32E161-C017-4088-B88D-1815AFFB2B6F}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [{34B2DE71-4C42-4464-854D-60F0EFA69C63}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => No File
FirewallRules: [{53FD5C46-3509-4B09-983C-12F3CBA258F1}] => (Allow) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe (AVB Disc Soft, SIA -> Disc Soft Ltd)
FirewallRules: [{B5B8DBDA-CE72-46BE-B453-0DECAC007A99}] => (Allow) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe (AVB Disc Soft, SIA -> Disc Soft Ltd)
FirewallRules: [UDP Query User{BD4C61A6-B966-4F49-9DEA-08B86EC1CBCA}C:\users\matej\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\matej\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [TCP Query User{C7093E7D-54A1-4F1B-89A9-E97387FF9068}C:\users\matej\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\matej\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{004A46C5-9FC5-4084-B6FE-ACF744C2A616}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe (Intel Corporation -> )
FirewallRules: [{1A52BF34-C912-44B0-B9C8-D2C1ED08A3C7}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe => No File
FirewallRules: [{16C2767B-4249-4877-BC47-529F07F9AA8F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe => No File
FirewallRules: [{D8F30375-3C72-454B-8118-32490EE41161}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe => No File
FirewallRules: [{F2206DE6-0D14-4261-AB24-34811173626D}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe => No File
FirewallRules: [TCP Query User{A87F28E8-907D-4664-AA28-5FAA8C93F0F0}C:\users\matej\appdata\local\temp\temp1_msiproductreghelper31.zip\msiproductreghelper.exe] => (Allow) C:\users\matej\appdata\local\temp\temp1_msiproductreghelper31.zip\msiproductreghelper.exe => No File
FirewallRules: [UDP Query User{FF8CDA2D-027A-409B-8160-78D2D96E3734}C:\users\matej\appdata\local\temp\temp1_msiproductreghelper31.zip\msiproductreghelper.exe] => (Allow) C:\users\matej\appdata\local\temp\temp1_msiproductreghelper31.zip\msiproductreghelper.exe => No File
FirewallRules: [{35240BEF-8581-414D-BF29-5A55B25D7DB6}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{814D32AB-B28C-4A0D-BFA7-52BC66CCD8E1}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{0007E957-4B5A-4314-8755-91FA71995FBE}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{99EDF490-637C-43AC-9F13-4A7250F5CEDF}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{56D57F84-A3D0-404B-A9B7-BA53DCA8721B}C:\program files\sap predictive analytics\desktop\expert\desktop\sappredictiveanalysis.exe] => (Allow) C:\program files\sap predictive analytics\desktop\expert\desktop\sappredictiveanalysis.exe => No File
FirewallRules: [UDP Query User{98E34F87-711F-48B0-8D52-522AC59561E6}C:\program files\sap predictive analytics\desktop\expert\desktop\sappredictiveanalysis.exe] => (Allow) C:\program files\sap predictive analytics\desktop\expert\desktop\sappredictiveanalysis.exe => No File
FirewallRules: [TCP Query User{8F6C0E61-7E57-4637-AB3F-176F0A532313}C:\program files (x86)\world of warcraft\_classic_\utils\wowvoiceproxy.exe] => (Allow) C:\program files (x86)\world of warcraft\_classic_\utils\wowvoiceproxy.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [UDP Query User{58D74510-171C-45A9-8CA3-3BABA31D1420}C:\program files (x86)\world of warcraft\_classic_\utils\wowvoiceproxy.exe] => (Allow) C:\program files (x86)\world of warcraft\_classic_\utils\wowvoiceproxy.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [{CE252584-F4AB-479A-B1E6-78ADAB96E90B}] => (Allow) C:\Program Files (x86)\RescueTime\RescueTime.exe (RescueTime, Inc.) [File not signed]
FirewallRules: [{158D0DD0-CC92-41CE-8110-BD97631AAD6A}] => (Allow) C:\Program Files (x86)\RescueTime\RescueTime.exe (RescueTime, Inc.) [File not signed]
FirewallRules: [TCP Query User{3C5BE22D-FC7C-4975-96D3-FF8D549EA864}C:\program files (x86)\hearts of iron iv\hoi4.exe] => (Allow) C:\program files (x86)\hearts of iron iv\hoi4.exe => No File
FirewallRules: [UDP Query User{A82B0E0B-E553-46E8-BD74-913B2D2E0AF9}C:\program files (x86)\hearts of iron iv\hoi4.exe] => (Allow) C:\program files (x86)\hearts of iron iv\hoi4.exe => No File
FirewallRules: [{8D8ADA86-0F62-47EB-8731-EB56FA7FCAB2}] => (Block) C:\program files (x86)\hearts of iron iv\hoi4.exe => No File
FirewallRules: [{74C99011-05D2-4CFA-A63E-D21429321086}] => (Block) C:\program files (x86)\hearts of iron iv\hoi4.exe => No File
FirewallRules: [TCP Query User{CC003030-DFEB-48AB-AD45-724858ACBE7A}C:\users\matej\appdata\local\slack\app-4.3.2\slack.exe] => (Allow) C:\users\matej\appdata\local\slack\app-4.3.2\slack.exe => No File
FirewallRules: [UDP Query User{23916BC1-16DD-4FD9-AE2A-08F025A8119A}C:\users\matej\appdata\local\slack\app-4.3.2\slack.exe] => (Allow) C:\users\matej\appdata\local\slack\app-4.3.2\slack.exe => No File
FirewallRules: [{05EFA4C5-1B35-440A-844A-533669276B58}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{451C9070-CB89-437B-B3D2-6F3714FB0767}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe () [File not signed]
FirewallRules: [{84458AD3-8553-480E-8273-FB22D218AD43}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe () [File not signed]
FirewallRules: [TCP Query User{5EDFE9FF-229B-4AA7-8399-181BF65F6162}C:\users\matej\downloads\factorio.v0.18.15\tests\x64\factorio-test.exe] => (Allow) C:\users\matej\downloads\factorio.v0.18.15\tests\x64\factorio-test.exe => No File
FirewallRules: [UDP Query User{78F3C97E-8907-40F8-9F72-74E13E0A02D4}C:\users\matej\downloads\factorio.v0.18.15\tests\x64\factorio-test.exe] => (Allow) C:\users\matej\downloads\factorio.v0.18.15\tests\x64\factorio-test.exe => No File
FirewallRules: [TCP Query User{0898A2BB-3EB1-42E1-8AF6-9F4AC8F7B434}C:\users\matej\downloads\ostriv v0.3.2.0\x64\ostriv.exe] => (Block) C:\users\matej\downloads\ostriv v0.3.2.0\x64\ostriv.exe => No File
FirewallRules: [UDP Query User{1A127617-571E-43D2-B7AD-5AE10A6CF989}C:\users\matej\downloads\ostriv v0.3.2.0\x64\ostriv.exe] => (Block) C:\users\matej\downloads\ostriv v0.3.2.0\x64\ostriv.exe => No File
FirewallRules: [TCP Query User{AD0D2FF8-5EF7-4F71-838B-FAC8FB6FBEA9}C:\users\matej\downloads\good company\goodcompany.exe] => (Block) C:\users\matej\downloads\good company\goodcompany.exe => No File
FirewallRules: [UDP Query User{3BDE8017-42CC-4891-B969-AF126F8262C1}C:\users\matej\downloads\good company\goodcompany.exe] => (Block) C:\users\matej\downloads\good company\goodcompany.exe => No File
FirewallRules: [TCP Query User{4477359B-E1F0-4A3F-AB16-53A04F3EF62B}C:\program files (x86)\steam\steamapps\common\europa universalis iv\eu4.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\europa universalis iv\eu4.exe => No File
FirewallRules: [UDP Query User{DBE504D4-A508-4A89-A070-2B20CFDFBAE2}C:\program files (x86)\steam\steamapps\common\europa universalis iv\eu4.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\europa universalis iv\eu4.exe => No File
FirewallRules: [TCP Query User{3A3D99E7-85A1-41EB-8C41-9F6AFA8C91EA}C:\users\matej\desktop\software\ostriv v0.3.2.0\x64\ostriv.exe] => (Block) C:\users\matej\desktop\software\ostriv v0.3.2.0\x64\ostriv.exe => No File
FirewallRules: [UDP Query User{01430204-D9F8-4F13-8974-F576223894DD}C:\users\matej\desktop\software\ostriv v0.3.2.0\x64\ostriv.exe] => (Block) C:\users\matej\desktop\software\ostriv v0.3.2.0\x64\ostriv.exe => No File
FirewallRules: [{C5AFD6EF-1501-4BCE-BA9C-2B45CE50EA31}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{AA7B9479-FBF6-436D-8E65-85128AEBDAE1}] => (Allow) C:\Program Files (x86)\BraveSoftware\Brave-Browser\Application\brave.exe (Brave Software, Inc. -> Brave Software, Inc.)
==================== Restore Points =========================
29-04-2020 13:53:48 Microsoft Visual C++ 2017 Redistributable (x64) - 14.12.25810
01-05-2020 17:55:49 Installed Paradox Launcher v2
10-05-2020 19:28:17 Scheduled Checkpoint
11-05-2020 20:10:44 Windows Modules Installer
14-05-2020 17:14:02 Removed Paradox Launcher v2
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================
Application errors:
==================
Error: (05/17/2020 11:49:25 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (5844,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (05/16/2020 11:28:12 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x8007045b, A system shutdown is in progress.
.
Error: (05/16/2020 11:28:12 PM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started. [0x8007045b, A system shutdown is in progress.
]
Error: (05/16/2020 11:28:12 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x8007045b, A system shutdown is in progress.
.
Error: (05/16/2020 11:28:12 PM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started. [0x8007045b, A system shutdown is in progress.
]
Error: (05/16/2020 11:15:19 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (11476,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (05/16/2020 11:06:08 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (4848,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
Error: (05/16/2020 04:00:16 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (2784,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) occurred while opening logfile C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.
System errors:
=============
Error: (05/16/2020 11:28:09 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-QMQ3BRT)
Description: The server A-Volute.Nahimic_1.4.4.0_x64__w2gh52qy24etm!App did not register with DCOM within the required timeout.
Error: (05/16/2020 04:11:35 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-QMQ3BRT)
Description: The server A-Volute.Nahimic_1.4.4.0_x64__w2gh52qy24etm!App did not register with DCOM within the required timeout.
Error: (05/15/2020 07:09:39 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-QMQ3BRT)
Description: The server A-Volute.Nahimic_1.4.4.0_x64__w2gh52qy24etm!App did not register with DCOM within the required timeout.
Error: (05/14/2020 07:48:54 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-QMQ3BRT)
Description: The server A-Volute.Nahimic_1.4.4.0_x64__w2gh52qy24etm!App did not register with DCOM within the required timeout.
Error: (05/14/2020 01:42:08 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-QMQ3BRT)
Description: The server A-Volute.Nahimic_1.4.4.0_x64__w2gh52qy24etm!App did not register with DCOM within the required timeout.
Error: (05/13/2020 10:18:37 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-QMQ3BRT)
Description: The server A-Volute.Nahimic_1.4.4.0_x64__w2gh52qy24etm!App did not register with DCOM within the required timeout.
Error: (05/13/2020 10:14:20 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-QMQ3BRT)
Description: The server A-Volute.Nahimic_1.4.4.0_x64__w2gh52qy24etm!App did not register with DCOM within the required timeout.
Error: (05/13/2020 10:10:14 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-QMQ3BRT)
Description: The server A-Volute.Nahimic_1.4.4.0_x64__w2gh52qy24etm!App did not register with DCOM within the required timeout.
Windows Defender:
===================================
Date: 2020-05-04 10:36:37.805
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {7666FDC6-AF7D-4C12-BEC9-82880A024933}
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2020-04-07 17:43:22.278
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {E887CA2F-38AC-458A-A885-7AFF65FAB725}
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2020-03-31 11:59:02.224
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {35CC6010-740C-41EE-9009-B45EFEFDCD9B}
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2020-03-31 11:17:51.238
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {96E44935-9E1C-498E-B143-C7C39038C2B3}
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2020-03-21 13:04:46.321
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {FF3B7EAD-CC53-4705-84C7-7335CC1633F4}
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2020-05-13 11:09:15.984
Description:
Windows Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 1.315.501.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.17000.7
Error code: 0x80240438
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
Date: 2020-05-10 21:43:51.721
Description:
Windows Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 1.315.359.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.17000.7
Error code: 0x80240022
Error description: The program can't check for definition updates.
Date: 2020-05-10 21:43:51.720
Description:
Windows Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 1.315.359.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.17000.7
Error code: 0x80240022
Error description: The program can't check for definition updates.
Date: 2020-04-20 18:59:56.648
Description:
Windows Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 1.313.1441.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.16900.4
Error code: 0x8007045b
Error description: A system shutdown is in progress.
Date: 2020-03-19 16:21:29.857
Description:
Windows Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version:
Previous security intelligence Version: 1.311.1454.0
Update Source: Microsoft Update Server
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.16800.2
Error code: 0x80240022
Error description: The program can't check for definition updates.
CodeIntegrity:
===================================
Date: 2020-05-13 22:24:22.136
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe) attempted to load \Device\HarddiskVolume3\ProgramData\A-Volute\A-Volute.Nahimic\Modules\Scheduled\x64\A-Volute.NahimicDevProps2.dll that did not meet the Store signing level requirements.
Date: 2020-05-13 22:24:22.129
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe) attempted to load \Device\HarddiskVolume3\ProgramData\A-Volute\A-Volute.Nahimic\Modules\Scheduled\x64\NahimicOSD.dll that did not meet the Store signing level requirements.
Date: 2020-05-13 22:24:19.865
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe) attempted to load \Device\HarddiskVolume3\ProgramData\A-Volute\A-Volute.Nahimic\Modules\Scheduled\x64\A-Volute.NahimicDevProps2.dll that did not meet the Store signing level requirements.
Date: 2020-05-13 22:24:19.857
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe) attempted to load \Device\HarddiskVolume3\ProgramData\A-Volute\A-Volute.Nahimic\Modules\Scheduled\x64\NahimicOSD.dll that did not meet the Store signing level requirements.
Date: 2020-04-13 17:47:50.195
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe) attempted to load \Device\HarddiskVolume3\ProgramData\A-Volute\A-Volute.Nahimic\Modules\Scheduled\x64\A-Volute.NahimicDevProps2.dll that did not meet the Store signing level requirements.
Date: 2020-04-13 17:47:50.188
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe) attempted to load \Device\HarddiskVolume3\ProgramData\A-Volute\A-Volute.Nahimic\Modules\Scheduled\x64\NahimicOSD.dll that did not meet the Store signing level requirements.
Date: 2020-04-13 17:47:48.771
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe) attempted to load \Device\HarddiskVolume3\ProgramData\A-Volute\A-Volute.Nahimic\Modules\Scheduled\x64\A-Volute.NahimicDevProps2.dll that did not meet the Store signing level requirements.
Date: 2020-04-13 17:47:48.763
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe) attempted to load \Device\HarddiskVolume3\ProgramData\A-Volute\A-Volute.Nahimic\Modules\Scheduled\x64\NahimicOSD.dll that did not meet the Store signing level requirements.
==================== Memory info ===========================
BIOS: American Megatrends Inc. E16Q2IMS.111 12/05/2018
Motherboard: Micro-Star International Co., Ltd. MS-16Q2
Processor: Intel(R) Core(TM) i7-8750H CPU @ 2.20GHz
Percentage of memory in use: 35%
Total physical RAM: 16227.03 MB
Available physical RAM: 10444.67 MB
Total Virtual: 18659.03 MB
Available Virtual: 11812.35 MB
==================== Drives ================================
Drive c: (Windows) (Fixed) (Total:237.18 GB) (Free:95.49 GB) NTFS
\\?\Volume{e8093537-c30a-4149-a597-ef38ab14678e}\ (WinRE tools) (Fixed) (Total:0.88 GB) (Free:0.44 GB) NTFS
\\?\Volume{bdd51151-22c4-48e6-bb71-2dbd94302ddc}\ (SYSTEM) (Fixed) (Total:0.29 GB) (Free:0.26 GB) FAT32
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Size: 238.5 GB) (Disk ID: B5C93904)
Partition: GPT.
==================== End of Addition.txt =======================