Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-11-2020
Ran by Kitti (04-11-2020 10:28:19)
Running from C:\Users\Kitti\Desktop
Windows 8.1 (Update) (X64) (2016-11-12 06:55:06)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-1470621731-751767047-2422543840-500 - Administrator - Disabled)
Guest (S-1-5-21-1470621731-751767047-2422543840-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1470621731-751767047-2422543840-1004 - Limited - Enabled)
Kitti (S-1-5-21-1470621731-751767047-2422543840-1002 - Administrator - Enabled) => C:\Users\Kitti
Majko (S-1-5-21-1470621731-751767047-2422543840-1005 - Administrator - Enabled) => C:\Users\Majko
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Avast Antivirus (Enabled - Up to date) {EB19B86E-3998-C706-90EF-92B41EB091AF}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {5078598A-1FA2-C888-AA5F-A9C66537DB12}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKU\S-1-5-21-1470621731-751767047-2422543840-1002\...\uTorrent) (Version: 3.5.5.45395 - BitTorrent Inc.)
Absolute Reminder (HKLM-x32\...\{40F4FF7A-B214-4453-B973-080B09CED019}) (Version: 2.3.0.1 - Absolute Software)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.4.0.2710 - Adobe Systems Incorporated)
Aktualizácie NVIDIA 10.4.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 10.4.0 - NVIDIA Corporation)
Apple Mobile Device Support (HKLM\...\{B5A46811-3612-4DA5-8A5A-E6DED5D7C523}) (Version: 12.2.1.12 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{A30EA700-5515-48F0-88B0-9E99DC356B88}) (Version: 2.6.0.1 - Apple Inc.)
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 20.8.2432 - Avast Software)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Caesar IV (HKLM-x32\...\1460037487_is1) (Version: 2.0.0.5 - GOG.com)
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.65.55.62 - Conexant)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.9.0.0650 - Disc Soft Ltd)
ExpressCache (HKLM\...\{6E55C9F8-138E-4128-8A9F-6464725BE98A}) (Version: 1.0.102.0 - Condusiv Technologies)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 86.0.4240.111 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.36.31 - Google LLC) Hidden
iCloud (HKLM\...\{DA6D808E-3629-4933-8FB3-583F9BCB0DEF}) (Version: 7.12.0.14 - Apple Inc.)
Integrated Camera (HKLM-x32\...\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.9200.10224 - Realtek Semiconductor Corp.)
Intel Collaborative Processor Performance Control (HKLM-x32\...\0E7DAF70-FB54-4B91-B192-7E771C25AEEB) (Version: 1.0.0.1011 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.10.1372 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.14.4264 - Intel Corporation)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology(patch version 3.0.1332.1) (HKLM\...\{302600C1-6BDF-4FD1-1307-148929CC1385}) (Version: 3.1.1307.0366 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 3.0.0.66956 - Intel Corporation)
Intel(R) Update Manager (HKLM-x32\...\{20D9D0D9-1659-4775-992E-5F5650AD9B87}) (Version: 1.6.0.56 - Intel Corporation) Hidden
Intel(R) Update Manager (HKLM-x32\...\{608E1B9B-A2E8-4A1F-8BAB-874EB0DD25E3}) (Version: 1.0.0.36888 - Intel Corporation) Hidden
Intel(R) WiDi (HKLM\...\{AD5700DA-F9C5-432B-9927-F555204E38CE}) (Version: 4.1.52.0 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{12fc27dc-b637-4ebb-b424-26feff9598c5}) (Version: 16.0.4 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{c9967fbd-e3c3-4ed0-992a-5b33260f2944}) (Version: 16.1.5 - Intel Corporation)
IntelliJ IDEA 2017.1.5 (HKLM-x32\...\IntelliJ IDEA 2017.1.5) (Version: 171.4694.70 - JetBrains s.r.o.)
iTunes (HKLM\...\{3239AFA9-496A-4D7C-A706-E04F2173338F}) (Version: 12.9.5.7 - Apple Inc.)
Java 8 Update 101 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180101F0}) (Version: 8.0.1010.13 - Oracle Corporation)
Java 8 Update 181 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180181F0}) (Version: 8.0.1810.13 - Oracle Corporation)
Java SE Development Kit 8 Update 101 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180101}) (Version: 8.0.1010.13 - Oracle Corporation)
Java SE Development Kit 8 Update 181 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180181}) (Version: 8.0.1810.13 - Oracle Corporation)
JavaFX 2.2.21 (64-bit) (HKLM\...\{1111706F-666A-4037-7777-222106464D10}) (Version: 2.2.21 - Oracle Corporation)
JavaFX 2.2.21 SDK (64-bit) (HKLM\...\{2222706F-666A-4037-7777-222106464D10}) (Version: 2.2.21 - Oracle Corporation)
Lenovo Auto Scroll Utility (HKLM\...\LenovoAutoScrollUtility) (Version: 2.01 - )
Lenovo Fingerprint Manager (HKLM\...\{3CD9E377-7148-4319-A14E-B64FCA008FE9}) (Version: 4.5.132.0 - Validity Sensors, Inc.)
Lenovo Fingerprint Manager (HKLM\...\{F7AB2C19-6A27-4C75-A92A-8CC7C59E5FA2}) (Version: 4.5.132.0 - )
Lenovo Patch Utility (HKLM-x32\...\{E8F27ADF-B1ED-41AF-A7EF-D5E71778480C}) (Version: 1.3.2.6 - Lenovo Group Limited) Hidden
Lenovo Patch Utility 64 bit (HKLM\...\{49A09C2C-FFF4-478E-B397-5E0979F67F5D}) (Version: 1.3.2.6 - Lenovo Group Limited) Hidden
Lenovo Power Management Driver (HKLM\...\Power Management Driver) (Version: 1.67.12.23 - Lenovo) Hidden
Lenovo QuickControl (HKLM-x32\...\{4855C42F-5197-4AAD-A50D-5066D2CC4647}) (Version: 1.10 - Lenovo Group Limited)
Lenovo Settings Dependency Package (HKLM\...\{3694BA2E-BE31-4B7E-886B-A0B559E69D4D}_is1) (Version: 1.2.5.8 - Lenovo Group Limited)
Lenovo Settings Mobile Hotspot (HKLM\...\{42603F7D-B08D-436B-B0D8-3E2DEF1AFD41}_is1) (Version: 1.2.0.80 - Lenovo)
Lenovo Solution Center (HKLM\...\{B73D2BF9-2C82-40A4-AFA8-32CE2E501640}) (Version: 2.2.002.00 - Lenovo Group Limited)
Lenovo Solutions for Small Business (HKLM-x32\...\{6A6D86CD-B004-46b7-8951-7BB75A776F8C}) (Version: 2.0.32.7350 - Intel(R) Corporation)
Lenovo Solutions for Small Business Customizations (HKLM-x32\...\{AFD7B869-3B70-40C7-8983-769256BA3BD2}) (Version: 2.0.0005.00 - Lenovo Group Limited)
Lenovo User Guide (HKLM-x32\...\{13F59938-C595-479C-B479-F171AB9AF64F}) (Version: 1.0.0012.00 - Lenovo Group Limited)
Lenovo Warranty Information (HKLM-x32\...\{FD4EC278-C1B1-4496-99ED-C0BE1B0AA521}) (Version: 1.0.0011.00 - Lenovo)
MCS783x Windows 8.x Drivers (HKLM-x32\...\{2BDD8E68-208B-45E0-BEE7-FB379FBA5D78}) (Version: 1.0.1.0 - ASIX Electronics Corporation) Hidden
MCS783x Windows 8.x Drivers (HKLM-x32\...\InstallShield_{2BDD8E68-208B-45E0-BEE7-FB379FBA5D78}) (Version: 1.0.1.0 - ASIX Electronics Corporation)
Microsoft 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.13328.20292 - Microsoft Corporation)
Microsoft Office Professional 2016 - en-us (HKLM\...\ProfessionalRetail - en-us) (Version: 16.0.13328.20292 - Microsoft Corporation)
Microsoft OneDrive (HKU\.DEFAULT\...\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1470621731-751767047-2422543840-1002\...\OneDriveSetup.exe) (Version: 20.169.0823.0008 - Microsoft Corporation)
Microsoft Project Standard 2013 (HKLM-x32\...\Office15.PRJSTD) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation)
NVIDIA Grafický ovládač 376.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 376.54 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.13.0725 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0725 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.13328.20278 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.13328.20278 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.13328.20292 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.13328.20278 - Microsoft Corporation) Hidden
Opera Stable 72.0.3815.186 (HKU\S-1-5-21-1470621731-751767047-2422543840-1002\...\Opera 72.0.3815.186) (Version: 72.0.3815.186 - Opera Software)
Outils de vérification linguistique 2013 de Microsoft Office - Français (HKLM-x32\...\{90150000-001F-040C-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Ovládací panel NVIDIA 376.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 376.54 - NVIDIA Corporation) Hidden
pgJDBC 42.1.1 (HKLM-x32\...\pgJDBC 42.1.1-1) (Version: 42.1.1-1 - EnterpriseDB)
Podpora Apple aplikácií (32-bit) (HKLM-x32\...\{C1BCFECF-6EC2-4750-9072-5E2489423F8F}) (Version: 7.5 - Apple Inc.)
Podpora Apple aplikácií(64-bit) (HKLM\...\{B202C7F5-7DE3-4FBF-B259-E70E625F56FC}) (Version: 7.5 - Apple Inc.)
PostgreSQL 9.6 (HKLM\...\PostgreSQL 9.6) (Version: 9.6 - PostgreSQL Global Development Group)
PowerDVD Create (HKLM-x32\...\InstallShield_{DE485075-8CD3-4A1E-9ABC-6412EBA44872}) (Version: 10.0 - CyberLink Corp.)
PowerDVD Create 10 (HKLM-x32\...\{D6E853EC-8960-4D44-AF03-7361BB93227C}) (Version: 10.0.1.2704 - CyberLink Corp.) Hidden
psqlODBC 09.06.0310 (HKLM\...\psqlODBC 09.06.0310-1) (Version: 09.06.0310-1 - EnterpriseDB)
RapidBoot HDD Accelerator (HKLM-x32\...\Fastboot) (Version: 2.1.1.0 - Lenovo)
rcssserver3d 0.6.7 (HKLM-x32\...\rcssserver3d 0.6.7) (Version: 0.6.7 - RoboCup Soccer Server 3D Maintenance Group)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.21234 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.19.726.2013 - Realtek)
simspark (HKLM-x32\...\simspark) (Version: 0.2.4 - RoboCup Soccer Server 3D Maintenance Group)
SourceMonitor V3.5.6.334 (HKLM-x32\...\{6B0F5080-66F9-11D0-B63D-00A0240C90F6}_is1) (Version: 3.5.6.334 - Campwood Software)
SourceTree (HKU\S-1-5-21-1470621731-751767047-2422543840-1002\...\SourceTree) (Version: 2.6.10 - Atlassian)
Spotify (HKU\S-1-5-21-1470621731-751767047-2422543840-1002\...\Spotify) (Version: 1.1.3.259.g8172f63a - Spotify AB)
SugarSync Manager (HKLM-x32\...\SugarSync) (Version: 1.9.80.99066 - SugarSync, Inc.)
TeamViewer 14 (HKLM-x32\...\TeamViewer) (Version: 14.0.13488 - TeamViewer)
ThinkPad UltraNav Driver (HKLM\...\SynTPDeinstKey) (Version: 16.6.4.27 - )
ThinkVantage Active Protection System (HKLM\...\{46A84694-59EC-48F0-964C-7E76E9F8A2ED}) (Version: 1.77.0.26 - Lenovo)
Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.)
WaveEditor (HKLM-x32\...\{324F76CC-D8DD-4D87-B77D-D4AF5E1AA7B3}) (Version: 1.0.1.4514 - CyberLink Corp.) Hidden
WebAdvisor od McAfee (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.1.1.163 - McAfee, LLC)
Windows Driver Package - Intel Corporation (iaStorA) HDC (08/01/2013 12.8.0.1016) (HKLM\...\C8A921233C0C441A4E4EAABC2AB08C872FD77A6E) (Version: 08/01/2013 12.8.0.1016 - Intel Corporation)
Windows Driver Package - Lenovo 1.67.00.02 (04/17/2013 1.67.00.02) (HKLM\...\907DA143458FE258EFEB416B946DE8DF2B87A0BA) (Version: 04/17/2013 1.67.00.02 - Lenovo)
WinRAR 5.40 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH)
Wireshark 2.2.1 (64-bit) (HKLM-x32\...\Wireshark) (Version: 2.2.1 - The Wireshark developer community, hxxps://
www.wireshark.org)
Packages:
=========
AccuWeather for Windows 8 -> C:\Program Files\WindowsApps\AccuWeather.AccuWeatherforWindows8_4.1.0.31_x64__8zz2pj9h1h1d8 [2016-11-13] (AccuWeather)
Companion -> C:\Program Files\WindowsApps\E046963F.LenovoCompanion_2.2.26.0_x86__k1h2ywk1493x8 [2016-11-13] (LENOVO INC.)
Evernote Touch -> C:\Program Files\WindowsApps\Evernote.Evernote_3.3.0.102_x86__q4d96b2w5wcc2 [2016-11-13] (Evernote)
Hry -> C:\Program Files\WindowsApps\Microsoft.XboxLIVEGames_2.0.139.0_x64__8wekyb3d8bbwe [2014-11-21] (Microsoft Corporation) [MS Ad]
Hudba -> C:\Program Files\WindowsApps\Microsoft.ZuneMusic_2.6.672.0_x64__8wekyb3d8bbwe [2016-11-13] (Microsoft Corporation) [MS Ad]
Kindle -> C:\Program Files\WindowsApps\AMZNMobileLLC.KindleforWindows8_2.1.0.2_neutral__stfe6vwa9jnbp [2016-11-13] (AMZN Mobile LLC)
Lenovo Cloud Storage by SugarSync -> C:\Program Files\WindowsApps\C59AD0AF.LenovoCloudStorageBySugarSync_1.3.0.889_neutral__m3tnjedffpfhj [2016-10-02] (SugarSync Inc.)
Lenovo QuickCast -> C:\Program Files\WindowsApps\E046963F.LenovoQuickCast_2.5.11.0_x86__k1h2ywk1493x8 [2016-11-13] (Lenovo, INC.)
Lenovo Settings -> C:\Program Files\WindowsApps\LenovoCorporation.LenovoSettings_2.4.0.24644_x86__4642shxvsv8s2 [2016-11-13] (LENOVO INCORPORATED.)
Lenovo Support -> C:\Program Files\WindowsApps\E046963F.LenovoSupport_2.0.5.0_x86__k1h2ywk1493x8 [2016-11-13] (Lenovo, INC.)
MSN Cestovanie -> C:\Program Files\WindowsApps\Microsoft.BingTravel_3.0.4.336_x64__8wekyb3d8bbwe [2016-11-13] (Microsoft Corporation) [MS Ad]
MSN Financie -> C:\Program Files\WindowsApps\Microsoft.BingFinance_3.0.4.344_x64__8wekyb3d8bbwe [2016-11-13] (Microsoft Corporation) [MS Ad]
MSN Jedlá a nápoje -> C:\Program Files\WindowsApps\Microsoft.BingFoodAndDrink_3.0.4.336_x64__8wekyb3d8bbwe [2016-11-13] (Microsoft Corporation) [MS Ad]
MSN Počasie -> C:\Program Files\WindowsApps\Microsoft.BingWeather_3.0.4.350_x64__8wekyb3d8bbwe [2016-11-26] (Microsoft Corporation) [MS Ad]
MSN Správy -> C:\Program Files\WindowsApps\Microsoft.BingNews_3.0.4.344_x64__8wekyb3d8bbwe [2016-11-13] (Microsoft Corporation) [MS Ad]
MSN Šport -> C:\Program Files\WindowsApps\Microsoft.BingSports_3.0.4.345_x64__8wekyb3d8bbwe [2016-11-13] (Microsoft Corporation) [MS Ad]
MSN Zdravie a fitnes -> C:\Program Files\WindowsApps\Microsoft.BingHealthAndFitness_3.0.4.336_x64__8wekyb3d8bbwe [2016-11-13] (Microsoft Corporation) [MS Ad]
Norton Studio -> C:\Program Files\WindowsApps\SymantecCorporation.NortonStudio_1.5.0.41_x86__v68kp9n051hdp [2016-11-13] (Symantec Corporation)
PowerDVD for Lenovo Think -> C:\Program Files\WindowsApps\CyberLinkCorp.th.PowerDVDforLenovoThink_4.1.731.32473_x86__m916jedk64snt [2016-11-13] (CYBERLINKCOM CORPORATION)
Skype -> C:\Program Files\WindowsApps\Microsoft.SkypeApp_3.1.0.1016_x86__kzf8qxf38zg5c [2016-11-19] (Skype) [MS Ad]
Video -> C:\Program Files\WindowsApps\Microsoft.ZuneVideo_2.6.446.0_x64__8wekyb3d8bbwe [2016-11-13] (Microsoft Corporation) [MS Ad]
Zinio -> C:\Program Files\WindowsApps\ZinioLLC.Zinio_2.1.0.317_x64__0q6dqzpp40p2e [2016-11-13] (Zinio LLC)
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-1470621731-751767047-2422543840-1002_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation - pGFX -> Intel Corporation)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-11-02] (Avast Software s.r.o. -> AVAST Software)
ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-09-18] (SugarSync, Inc. -> SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-09-18] (SugarSync, Inc. -> SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {A759AFF6-5851-457D-A540-F4ECED148351} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-09-18] (SugarSync, Inc. -> SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-09-18] (SugarSync, Inc. -> SugarSync, Inc.)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-11-02] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers1: [PhotoStreamsExt] -> {89D984B3-813B-406A-8298-118AFA3A22AE} => C:\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll [2019-05-08] (Apple Inc. -> Apple Inc.)
ContextMenuHandlers1: [SugarSync] -> {305BC11B-5175-492B-B569-866547FCDA40} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-09-18] (SugarSync, Inc. -> SugarSync, Inc.)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-14] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-08-14] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [DaemonShellExtDriveLite] -> {C06369D6-E77D-4626-9656-1256312BD576} => C:\Program Files\DAEMON Tools Lite\DTShl64.dll [2018-10-19] (AVB Disc Soft, SIA -> Disc Soft Ltd)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-11-02] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers3: [DaemonShellExtImageLite] -> {1D1B5D7B-0FC9-452E-902C-12BACD4FBC20} => C:\Program Files\DAEMON Tools Lite\DTShl64.dll [2018-10-19] (AVB Disc Soft, SIA -> Disc Soft Ltd)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2015-08-09] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2016-12-29] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-11-02] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers6: [SugarSync] -> {305BC11B-5175-492B-B569-866547FCDA40} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-09-18] (SugarSync, Inc. -> SugarSync, Inc.)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-14] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-08-14] (win.rar GmbH -> Alexander Roshal)
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
ShortcutWithArgument: C:\Users\Kitti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Keep - Notes and Lists.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=hmjkmjkepdijhoojdojkdfohbdgmmhki
==================== Loaded Modules (Whitelisted) =============
2015-01-22 14:56 - 2013-08-01 07:42 - 000104960 _____ () [File not signed] C:\Program Files (x86)\ThinkPad\Utilities\US\PWMRT64V.DLL
2017-07-23 22:00 - 2017-07-18 14:26 - 000183296 _____ () [File not signed] C:\Program Files\PostgreSQL\9.6\bin\LIBPQ.dll
2017-07-23 22:02 - 2016-08-01 03:29 - 002264576 _____ () [File not signed] C:\Program Files\PostgreSQL\9.6\bin\libxml2.dll
2013-07-03 12:02 - 2013-07-03 12:02 - 000236032 _____ (Condusiv Technologies) [File not signed] C:\Program Files\Condusiv Technologies\ExpressCache\NsNtfsAutoAnalyze.dll
2013-07-03 12:02 - 2013-07-03 12:02 - 000455168 _____ (Condusiv Technologies) [File not signed] C:\Program Files\Condusiv Technologies\ExpressCache\NsNtfsBootOptimization.dll
2013-07-03 12:02 - 2013-07-03 12:02 - 000310272 _____ (Condusiv Technologies) [File not signed] C:\Program Files\Condusiv Technologies\ExpressCache\NsNtfsTVE-Ex.dll
2013-07-03 12:02 - 2013-07-03 12:02 - 000087552 _____ (Condusiv Technologies) [File not signed] C:\Program Files\Condusiv Technologies\ExpressCache\PrFacade.dll
2017-07-23 22:02 - 2016-01-12 02:14 - 001690490 _____ (Free Software Foundation) [File not signed] C:\Program Files\PostgreSQL\9.6\bin\libiconv-2.dll
2017-07-23 22:02 - 2016-01-13 19:34 - 000685747 _____ (Free Software Foundation) [File not signed] C:\Program Files\PostgreSQL\9.6\bin\libintl-8.dll
2015-01-22 14:53 - 2015-01-22 14:53 - 000348160 _____ (Microsoft Corporation) [File not signed] C:\Program Files (x86)\CyberLink\PowerDVD10\MSVCR71.dll
2017-07-23 22:02 - 2017-06-01 22:32 - 001660928 _____ (The OpenSSL Project, hxxp://
www.openssl.org/) [File not signed] C:\Program Files\PostgreSQL\9.6\bin\LIBEAY32.dll
2017-07-23 22:02 - 2017-06-01 22:32 - 000351744 _____ (The OpenSSL Project, hxxp://
www.openssl.org/) [File not signed] C:\Program Files\PostgreSQL\9.6\bin\SSLEAY32.dll
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
==================== Association (Whitelisted) =================
==================== Internet Explorer (Whitelisted) ==========
HKU\S-1-5-21-1470621731-751767047-2422543840-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13-comm.msn.com/?pc=LNJB
HKU\S-1-5-21-1470621731-751767047-2422543840-1002\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://
www.lenovo.com/welcome/thinkpad
SearchScopes: HKU\S-1-5-21-1470621731-751767047-2422543840-1002 -> DefaultScope {02A260C8-D34C-412D-9B26-F2DB90C02459} URL =
SearchScopes: HKU\S-1-5-21-1470621731-751767047-2422543840-1002 -> {02A260C8-D34C-412D-9B26-F2DB90C02459} URL =
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2020-11-02] (Microsoft Corporation -> Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_181\bin\ssv.dll [2018-10-09] (Oracle America, Inc. -> Oracle Corporation)
BHO: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\x64\IEPlugin.dll [2020-11-02] (McAfee, LLC -> McAfee, LLC)
BHO: No Name -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> No File
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_181\bin\jp2ssv.dll [2018-10-09] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll [2020-11-02] (McAfee, LLC -> McAfee, LLC)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-11-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-11-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-11-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2020-11-02] (Microsoft Corporation -> Microsoft Corporation)
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\.DEFAULT\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-1470621731-751767047-2422543840-1002\...\localhost -> localhost
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 05:25 - 2019-01-12 16:53 - 000000847 _____ C:\WINDOWS\system32\drivers\etc\hosts
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\ProgramData\Oracle\Java\javapath;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\Condusiv Technologies\ExpressCache\;C:\ProgramData\Lenovo\ReadyApps;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\
HKU\S-1-5-21-1470621731-751767047-2422543840-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\Kitti\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\{0f1a7bb3-1351-432e-80a0-586abe1d9364}.jpg
DNS Servers: 192.168.100.1 - 194.1.157.28
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp (No File)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
HKLM\...\StartupApproved\Run: => "BTMTrayAgent"
HKLM\...\StartupApproved\Run: => "cAudioFilterAgent"
HKLM\...\StartupApproved\Run: => "ForteConfig"
HKLM\...\StartupApproved\Run: => "LnvMobHotspotClient"
HKLM\...\StartupApproved\Run32: => "PWMTRV"
HKLM\...\StartupApproved\Run32: => "IMSS"
HKLM\...\StartupApproved\Run32: => "Fastboot"
HKU\S-1-5-21-1470621731-751767047-2422543840-1002\...\StartupApproved\Run: => "uTorrent"
HKU\S-1-5-21-1470621731-751767047-2422543840-1002\...\StartupApproved\Run: => "Spotify"
HKU\S-1-5-21-1470621731-751767047-2422543840-1002\...\StartupApproved\Run: => "DAEMON Tools Lite Automount"
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{53C664A1-6D8D-4DB2-A9B0-45A2CFA17307}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe (Intel Corporation-Mobile Wireless Group -> )
FirewallRules: [{16C045E2-4B3B-488A-B4F6-2DDE4CD89809}] => (Allow) C:\Program Files\Intel Corporation\Intel WiDi\WiDiApp.exe (Intel Wireless Display -> Intel Corporation)
FirewallRules: [{E987AD0A-7BFF-49AC-BD09-E96BDBB520EB}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE (CyberLink Corp. -> CyberLink Corp.)
FirewallRules: [{2AB2721D-79AD-4894-A123-3984866C679F}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe (CyberLink Corp. -> CyberLink Corp.)
FirewallRules: [{8F0A8E09-8D8B-416F-A9B0-FE74EAE91576}] => (Allow) C:\Program Files (x86)\Lenovo\QuickControl\QuickControlService.exe (LENOVO(JAPAN)LTD. -> Lenovo Group Limited)
FirewallRules: [{BA35AB06-3A0F-433F-BFF6-78AE8A392A5B}] => (Allow) C:\Program Files (x86)\Lenovo\QuickControl\QuickControlService.exe (LENOVO(JAPAN)LTD. -> Lenovo Group Limited)
FirewallRules: [{1191CC85-42F5-4DA0-9C97-76056110C9D2}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe => No File
FirewallRules: [{D13412ED-5192-4E29-8C5E-946897B859B6}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe => No File
FirewallRules: [{B7560904-4C17-4B39-9AB1-ED1774994D92}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{138596AE-7FCC-478A-A2CC-1E85064355F3}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{8F1B5080-FE35-4D7E-BB1F-8DB301ED9291}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{B3A36153-A03C-4FED-92E7-45EE4B85F4CF}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{973FC60B-96B5-4AAC-869D-0B133E8D2926}] => (Allow) C:\Users\Kitti\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{F8D20480-EE3E-42F0-9A7A-476E09720B86}] => (Allow) C:\Users\Kitti\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [TCP Query User{FC897C19-2485-4A53-8E0B-600A3D910473}C:\users\kitti\appdata\roaming\utorrent\updates\3.5.3_44494.exe] => (Block) C:\users\kitti\appdata\roaming\utorrent\updates\3.5.3_44494.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [UDP Query User{722CC47A-6F40-4701-8848-6091296E31D1}C:\users\kitti\appdata\roaming\utorrent\updates\3.5.3_44494.exe] => (Block) C:\users\kitti\appdata\roaming\utorrent\updates\3.5.3_44494.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [TCP Query User{0626BFD4-F495-41BE-A035-B5ACE29145F0}C:\users\kitti\downloads\eclipse-jee-mars-2-win32-x86_64\eclipse\eclipse.exe] => (Allow) C:\users\kitti\downloads\eclipse-jee-mars-2-win32-x86_64\eclipse\eclipse.exe (Eclipse Foundation, Inc. -> )
FirewallRules: [UDP Query User{7FC68554-F082-475D-B47C-3647D45678BA}C:\users\kitti\downloads\eclipse-jee-mars-2-win32-x86_64\eclipse\eclipse.exe] => (Allow) C:\users\kitti\downloads\eclipse-jee-mars-2-win32-x86_64\eclipse\eclipse.exe (Eclipse Foundation, Inc. -> )
FirewallRules: [TCP Query User{DE53752C-33F6-4F48-B49B-49B0FB6E9140}C:\users\kitti\downloads\jetbrains.intellij.idea.ultimate.2017.1.5.incl.keymaker-dvt\windows\dvt-jb_licsrv.amd64.exe] => (Allow) C:\users\kitti\downloads\jetbrains.intellij.idea.ultimate.2017.1.5.incl.keymaker-dvt\windows\dvt-jb_licsrv.amd64.exe () [File not signed]
FirewallRules: [UDP Query User{5DC466C8-72A6-4729-80A7-9B2132797A08}C:\users\kitti\downloads\jetbrains.intellij.idea.ultimate.2017.1.5.incl.keymaker-dvt\windows\dvt-jb_licsrv.amd64.exe] => (Allow) C:\users\kitti\downloads\jetbrains.intellij.idea.ultimate.2017.1.5.incl.keymaker-dvt\windows\dvt-jb_licsrv.amd64.exe () [File not signed]
FirewallRules: [TCP Query User{BBDFD981-8555-4D68-B308-B6538C01142B}C:\program files (x86)\rcssserver3d 0.6.7\bin\rcssserver3d.exe] => (Allow) C:\program files (x86)\rcssserver3d 0.6.7\bin\rcssserver3d.exe () [File not signed]
FirewallRules: [UDP Query User{E957FC7F-3B5B-4C50-8B82-2A89A4026D0C}C:\program files (x86)\rcssserver3d 0.6.7\bin\rcssserver3d.exe] => (Allow) C:\program files (x86)\rcssserver3d 0.6.7\bin\rcssserver3d.exe () [File not signed]
FirewallRules: [TCP Query User{56E72853-24C5-4309-9CCB-DF1CE2B3A0F3}C:\users\kitti\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\kitti\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{EFE02111-C491-4BC3-B351-C98CF93A11D0}C:\users\kitti\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\kitti\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{504AF97B-B4F8-4987-A6D6-808CE43AABAF}] => (Allow) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe (AVB Disc Soft, SIA -> Disc Soft Ltd)
FirewallRules: [{6187FCFA-2912-4747-B20B-74AE26C866C9}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{5BD11A60-1090-4238-A396-85AA5BF2267F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{AEAA25CE-8706-4D68-81E3-5FFF9C09C825}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{761D2EF3-7F34-4E55-A4FD-47E0D312675A}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [TCP Query User{0DACCB64-236F-4B38-AEDC-E67226671673}C:\users\kitti\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\kitti\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{737B60C7-A242-48AF-BC1E-8FC45548C069}C:\users\kitti\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\kitti\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{44CA60E1-66B5-40C7-8C73-3E10BB1873C2}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{D50235B3-5543-4D7D-A94B-1E415C835E53}] => (Allow) C:\Program Files\iTunes\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{42A49617-16B0-4237-9C29-830991A60766}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\UNCServer.exe => No File
FirewallRules: [{DF2099C7-2015-47DF-A76C-AF2878368EA1}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\UNCServer.exe => No File
FirewallRules: [{143888C0-57A1-42FD-ACDB-15618FE18A4F}] => (Allow) C:\Users\Kitti\AppData\Local\Programs\Opera\71.0.3770.271\opera.exe (Opera Software AS -> Opera Software)
FirewallRules: [{8AF19252-8B4C-4F6B-A183-A6ECDE5442EE}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\UNCServer.exe => No File
FirewallRules: [{1D1FC30A-D228-4F00-930B-8F55B6D1A1C2}] => (Allow) C:\Program Files (x86)\Lenovo\System Update\UNCServer.exe => No File
FirewallRules: [{6D960A02-6BAB-4EA1-9B6A-FD1255BB3511}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{2A7FCEF3-9702-4BC8-910F-6D8E3DB7516B}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{7D5F7A01-851F-4F67-862A-7F8F7A027764}] => (Allow) C:\Users\Kitti\AppData\Local\Programs\Opera\72.0.3815.186\opera.exe (Opera Software AS -> Opera Software)
==================== Restore Points =========================
01-08-2020 17:52:37 Windows Update
02-11-2020 10:04:23 AdwCleaner_BeforeCleaning_02/11/2020_10:04:22
==================== Faulty Device Manager Devices ============
Name: IWD Bus Enumerator
Description: IWD Bus Enumerator
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard system devices)
Service: iwdbus
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver
==================== Event log errors: ========================
Application errors:
==================
Error: (11/04/2020 09:25:28 AM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0
Error: (11/03/2020 09:31:39 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO)
Description: Aktivácia aplikácie Microsoft.BingWeather_8wekyb3d8bbwe!App zlyhala pre chybu: -2144927148 Ďalšie informácie nájdete v denníku Microsoft-Windows-TWinUI/Operational.
Error: (11/03/2020 07:31:39 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO)
Description: Aktivácia aplikácie Microsoft.BingWeather_8wekyb3d8bbwe!App zlyhala pre chybu: -2144927148 Ďalšie informácie nájdete v denníku Microsoft-Windows-TWinUI/Operational.
Error: (11/03/2020 05:33:14 PM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0
Error: (11/02/2020 02:33:10 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO)
Description: Aktivácia aplikácie Microsoft.BingWeather_8wekyb3d8bbwe!App zlyhala pre chybu: -2144927148 Ďalšie informácie nájdete v denníku Microsoft-Windows-TWinUI/Operational.
Error: (11/02/2020 09:55:27 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Adobe AIR Installer.exe version 18.0.0.144 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: 1664
Start Time: 01d6b13a3c3619c2
Termination Time: 130
Application Path: C:\Users\Kitti\AppData\Local\Temp\AIRC8DF.tmp\Adobe AIR Installer.exe
Report Id: 8b126046-1d34-11eb-bea6-a0a8cdeebc9e
Faulting package full name:
Faulting package-relative application ID:
Error: (11/02/2020 09:20:24 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: LENOVO)
Description: Aktivácia aplikácie Microsoft.BingWeather_8wekyb3d8bbwe!App zlyhala pre chybu: -2144927148 Ďalšie informácie nájdete v denníku Microsoft-Windows-TWinUI/Operational.
Error: (11/02/2020 08:56:10 AM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0
System errors:
=============
Error: (11/03/2020 06:35:13 PM) (Source: Service Control Manager) (EventID: 7046) (User: )
Description: Nasledujúca služba sa opakovane zastavila pri reakcii na požiadavky riadenia služieb: Lenovo QuickControl Service
Informujte sa u dodávateľa služby alebo správcu systému, kde možno túto službu vypnúť, kým sa nezistí problém.
Pred vypnutím služby možno budete musieť reštartovať počítač v bezpečnom režime.
Error: (11/03/2020 06:23:00 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Počas čakania na odpoveď transakcie od služby QuickControlService bol dosiahnutý časový limit (30000 ms).
Error: (11/03/2020 05:24:23 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Počas čakania na odpoveď transakcie od služby QuickControlService bol dosiahnutý časový limit (30000 ms).
Error: (11/03/2020 05:21:26 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Počas čakania na odpoveď transakcie od služby QuickControlService bol dosiahnutý časový limit (30000 ms).
Error: (11/03/2020 05:20:56 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Počas čakania na odpoveď transakcie od služby QuickControlService bol dosiahnutý časový limit (30000 ms).
Error: (11/03/2020 05:20:26 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Počas čakania na odpoveď transakcie od služby QuickControlService bol dosiahnutý časový limit (30000 ms).
Error: (11/02/2020 09:19:07 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Počas čakania na odpoveď transakcie od služby QuickControlService bol dosiahnutý časový limit (30000 ms).
Error: (11/02/2020 09:18:36 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Počas čakania na odpoveď transakcie od služby QuickControlService bol dosiahnutý časový limit (30000 ms).
Windows Defender:
===================================
Date: 2018-09-22 15:03:16.495
Description:
Windows Defender has detected malware or other potentially unwanted software.
For more information please see the following:
http://go.microsoft.com/fwlink/?linkid= ... terprise=0
Name: HackTool:Win32/Keygen
ID: 2147593794
Severity: Vysoká
Category: Nástroj
Path: file:_C:\Users\Kitti\Downloads\Windows 7 Loader Extreme Edition v3.503.exe
Detection Origin: Local machine
Detection Type: FastPath
Detection Source: Real-Time Protection
Process Name: C:\Users\Kitti\AppData\Roaming\uTorrent\updates\3.5.3_44494.exe
Signature Version: AV: 1.275.1628.0, AS: 1.275.1628.0, NIS: 119.0.0.0
Engine Version: AM: 1.1.15300.6, NIS: 2.1.14600.4
Date: 2018-09-22 12:53:58.959
Description:
Windows Defender scan has been stopped before completion.
Scan ID: {BA8154C0-53D7-4610-B05F-C97802EAED17}
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2018-09-22 12:48:51.410
Description:
Windows Defender scan has been stopped before completion.
Scan ID: {6AF8208C-DD86-4E60-9B95-015CF2A217AC}
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2018-09-22 12:33:28.105
Description:
Windows Defender scan has been stopped before completion.
Scan ID: {C1472B73-D40C-4828-84D4-9EF728297310}
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2018-09-22 12:19:22.189
Description:
Windows Defender scan has been stopped before completion.
Scan ID: {6C3A2D5A-C13B-4D78-A1EA-9EDB86204651}
Scan Type: Antimalware
Scan Parameters: Quick Scan
Date: 2018-02-03 14:26:38.707
Description:
Windows Defender has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 118.2.0.0
Update Source: Microsoft Malware Protection Center
Signature Type: Network Inspection System
Update Type: Full
Current Engine Version:
Previous Engine Version: 2.1.14202.0
Error code: 0x80070652
Error description: Práve prebieha iná inštalácia. Pred spustením novej inštalácie je nutné danú inštaláciu dokončiť.
Date: 2018-02-03 14:26:37.286
Description:
Windows Defender has encountered an error trying to update the engine.
New Engine Version:
Previous Engine Version: 2.1.14202.0
Error Code: 0x80070666
Error description: Už je nainštalovaná iná verzia produktu. Inštaláciu tejto verzie nemožno dokončiť. Ak chcete existujúcu verziu produktu nakonfigurovať alebo odstrániť, použite ovládací panel Pridať alebo odstrániť programy.
Date: 2018-02-03 14:26:37.286
Description:
Windows Defender has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 118.2.0.0
Update Source: User
Signature Type: Network Inspection System
Update Type: Full
Current Engine Version:
Previous Engine Version: 2.1.14202.0
Error code: 0x80070666
Error description: Už je nainštalovaná iná verzia produktu. Inštaláciu tejto verzie nemožno dokončiť. Ak chcete existujúcu verziu produktu nakonfigurovať alebo odstrániť, použite ovládací panel Pridať alebo odstrániť programy.
Date: 2018-02-03 14:26:37.005
Description:
Windows Defender has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version:
Update Source: User
Signature Type:
Update Type:
Current Engine Version:
Previous Engine Version:
Error code: 0x80070652
Error description: Práve prebieha iná inštalácia. Pred spustením novej inštalácie je nutné danú inštaláciu dokončiť.
Date: 2018-02-03 14:26:33.772
Description:
Windows Defender has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version:
Update Source: User
Signature Type:
Update Type:
Current Engine Version:
Previous Engine Version:
Error code: 0x80070652
Error description: Práve prebieha iná inštalácia. Pred spustením novej inštalácie je nutné danú inštaláciu dokončiť.
CodeIntegrity:
===================================
Date: 2018-09-21 20:50:44.569
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2018-02-18 23:19:01.008
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2018-02-18 23:18:19.929
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-12-11 16:26:49.516
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-12-11 16:26:49.300
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-12-11 16:26:48.753
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-12-11 16:26:48.544
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-12-09 00:11:31.327
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Memory info ===========================
BIOS: LENOVO J9ET92WW (2.12 ) 07/31/2014
Motherboard: LENOVO 20C60044MC
Processor: Intel(R) Core(TM) i7-4702MQ CPU @ 2.20GHz
Percentage of memory in use: 49%
Total physical RAM: 8082.58 MB
Available physical RAM: 4076 MB
Total Virtual: 9362.58 MB
Available Virtual: 5153.63 MB
==================== Drives ================================
Drive c: (Windows8_OS) (Fixed) (Total:916.45 GB) (Free:744.96 GB) NTFS ==>[system with boot components (obtained from drive)]
\\?\Volume{996bd3b6-73e8-4e2a-8195-c69126bbf90d}\ (WINRE_DRV) (Fixed) (Total:0.98 GB) (Free:0.67 GB) NTFS
\\?\Volume{484770d0-5bfe-40e0-8ed0-d3af161a22fb}\ () (Fixed) (Total:0.49 GB) (Free:0.18 GB) NTFS
\\?\Volume{241a46c0-f7a8-448b-86da-c123e9328b25}\ (Lenovo_Recovery) (Fixed) (Total:13.21 GB) (Free:2.93 GB) NTFS
==================== MBR & Partition Table ====================
==========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: F2FF3AE7)
Partition: GPT.
==========================================================
Disk: 1 (Size: 14.9 GB) (Disk ID: F2FF3ABE)
Partition: GPT.
==================== End of Addition.txt =======================