﻿Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16-05-2015 02
Ran by note at 2015-05-16 16:52:10
Running from C:\Users\note\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3087545661-4222239971-938059260-500 - Administrator - Disabled)
Guest (S-1-5-21-3087545661-4222239971-938059260-501 - Limited - Enabled) => C:\Users\Guest.note-PC
HomeGroupUser$ (S-1-5-21-3087545661-4222239971-938059260-1003 - Limited - Enabled)
note (S-1-5-21-3087545661-4222239971-938059260-1000 - Administrator - Enabled) => C:\Users\note

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Aktualizace produktu Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISE_{0A1FAC46-B899-421D-B1A2-470896DC45DB}) (Version:  - Microsoft)
Aktualizace produktu Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISE_{5260BB53-C1F7-4A3B-9AEB-3EC9B37FF194}) (Version:  - Microsoft)
Aktualizace produktu Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISE_{E68DD413-B834-4923-8181-0A03B7555187}) (Version:  - Microsoft)
AMD Catalyst Install Manager (HKLM\...\{ACD449FA-9DF3-779D-DA68-11D486963225}) (Version: 3.0.847.0 - Advanced Micro Devices, Inc.)
Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 9.2 - Atheros)
CCleaner (HKLM\...\CCleaner) (Version: 5.05 - Piriform)
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.48.1.0347 - Disc Soft Ltd)
Glyph (HKLM-x32\...\Glyph) (Version:  - Trion Worlds, Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 42.0.2311.152 - Google Inc.)
Google Update Helper (x32 Version: 1.3.21.169 - Google Inc.) Hidden
Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HP Support Assistant (HKLM-x32\...\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}) (Version: 7.4.45.4 - Hewlett-Packard Company)
Chromodo (HKLM-x32\...\Chromodo) (Version: 36.7.0.8 - Comodo)
Java 8 Update 40 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418040F0}) (Version: 8.0.400 - Oracle Corporation)
Java 8 Update 40 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218040F0}) (Version: 8.0.400 - Oracle Corporation)
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)
League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden
Malwarebytes Anti-Malware verze 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (čeština) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 365 ProPlus - cs-cz (HKLM\...\O365ProPlusRetail - cs-cz) (Version: 15.0.4711.1003 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
NVIDIA PhysX (HKLM-x32\...\{DA909E62-3B45-4BA1-8B58-FCAEBA4BCEC9}) (Version: 9.12.0213 - NVIDIA Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4711.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4711.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4711.1003 - Microsoft Corporation) Hidden
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.40.126.2011 - Realtek)
Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7601.83 - Realtek Semiconductor Corp.)
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 7.4 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.4.102 - Skype Technologies S.A.)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.29.0 - Synaptics Incorporated)
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.41459 - TeamViewer)
Trove (HKLM-x32\...\Glyph Trove) (Version:  - Trion Worlds, Inc.)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
WinRAR 5.00 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points  =========================

04-05-2015 16:34:24 Windows Update
08-05-2015 09:37:09 Windows Update
11-05-2015 16:31:58 Windows Update
13-05-2015 16:59:00 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {02DE90D6-450E-4F3B-96EB-3BB941357409} - System32\Tasks\{207D9965-8B69-4D4C-96ED-B21CCA28E2AF} => pcalua.exe -a "C:\Program Files (x86)\SaVeREexettension\9TGgAAiBeHrwcy.exe" -c /s /n /i:"ExecuteCommands;UninstallCommands" ""
Task: {0FA40204-4644-4ACC-8C8D-5AFCD09E49C2} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-04-22] (Microsoft Corporation)
Task: {182E5D12-FAA3-4A4B-9305-71A0F13ED7B3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
Task: {3CF1D793-196C-41F8-86D4-8D3B0AFE106A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-17] (Adobe Systems Incorporated)
Task: {461B934B-EFD8-4236-A3C3-0332DAECFDD9} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {4DCBC762-84A7-4F52-A1DB-17CF4E7DF21B} - System32\Tasks\HPCeeScheduleFornote => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15] (Hewlett-Packard)
Task: {53D8C4E7-EE58-4310-8D1C-BBA01B3C2602} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation)
Task: {56750D45-0CCB-40A0-968E-247A8B85FAAC} - System32\Tasks\{7A4ACB17-C191-4FA1-A87D-EE0E04141DA0} => pcalua.exe -a "C:\ProgramData\The AdBlocker\The AdBlocker.exe" -c /progname=The AdBlocker /progver=3.4.2 /progpub=The AdBlocker /proguninstallurl=asdahjka.com /deleteappfolder=0  /VERYSILENT
Task: {77C2F9D5-A9FE-4443-B39F-DE413B92DE1C} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {7EFE8F98-E19D-4BB8-BDCD-602CE43281CF} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
Task: {830DC5B7-EA8E-4E47-930D-972D9FB1EA68} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-02-03] (Microsoft Corporation)
Task: {95E8350E-1D40-4B7C-9169-B3932370DC01} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
Task: {A0E4A17D-5B53-49E4-B3B1-2E96EFED598F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-05-15] (Google Inc.)
Task: {A95629B2-8D70-4BAD-B6EB-85DAAC5C731B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-04-23] (Piriform Ltd)
Task: {AB621106-521B-4236-91DF-308262277266} - System32\Tasks\COMODO CertSentry Updater => C:\Windows\system32\certsentry.exe [2015-04-23] (COMODO CA Limited)
Task: {B4332224-6C88-46EC-B652-270676D18144} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2014-05-12] (Hewlett-Packard Company)
Task: {BBB17A0B-68C6-430B-88E1-CDCF76DA3DAE} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2015-04-22] (Microsoft Corporation)
Task: {BCB8FB5F-A0A5-42A6-A64C-571AE2248B6D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-05-15] (Google Inc.)
Task: {CE1B9C18-3E36-44A8-B2F9-996CDD44717D} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-04-22] (Microsoft Corporation)
Task: {DDD7A904-5756-44DE-B1A7-CA49B9874A45} - System32\Tasks\{5D2349F8-7F62-4E94-A0CE-D86663A4FB86} => pcalua.exe -a "C:\ProgramData\Mini - Adblocker\Mini - Adblocker.exe" -c /progname=Mini - Adblocker /progver=3.4.2 /progpub=Mini - Adblocker /proguninstallurl=asdahjka.com /deleteappfolder=0 /VERYSILENT
Task: {E628716D-8982-4E2A-8C73-EF166BBA9D4F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-02-03] (Microsoft Corporation)
Task: {F73F11DA-AACF-4B97-8858-6FE57ECB3644} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {FBFAE0F5-7A73-4A08-AF61-97045898C681} - System32\Tasks\{BE1568FC-6951-4B05-8A56-B59F597B5A32} => pcalua.exe -a E:\SETUP.EXE -d E:\
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HPCeeScheduleFornote.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

==================== Loaded Modules (Whitelisted) ==============

2011-09-28 07:19 - 2011-09-28 07:19 - 00073728 _____ () c:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
2015-04-08 21:53 - 2015-04-08 21:53 - 00053248 _____ () C:\Program Files\CCleaner\lang\lang-1029.dll
2015-02-07 20:15 - 2014-05-20 09:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2014-08-25 07:38 - 2014-08-25 07:38 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2011-09-28 07:19 - 2011-09-28 07:19 - 00103424 _____ () c:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2011-09-28 07:06 - 2011-09-28 07:06 - 00369152 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2011-06-17 14:42 - 2011-06-17 14:42 - 00016384 _____ () c:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:373E1720

==================== Safe Mode (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, the associated entry will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3087545661-4222239971-938059260-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\note\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 8.26.56.26 - 8.20.247.20

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

FirewallRules: [{5C3D8F91-BA5F-47AF-8D4E-9AB171135AB4}] => (Allow) C:\Program Files (x86)\Warframe\Downloaded\Public\Warframe.exe
FirewallRules: [{592EA3C4-255C-4C88-86B8-D7ABD48AB966}] => (Allow) C:\Program Files (x86)\Warframe\Downloaded\Public\Warframe.x64.exe
FirewallRules: [{A04E6A9C-3CE2-484C-BB6D-9069420BD202}] => (Allow) C:\Program Files (x86)\Warframe\Downloaded\Public\Warframe.exe
FirewallRules: [{12523B5B-5854-4B64-A320-E7B7980017FD}] => (Allow) C:\Program Files (x86)\Warframe\Downloaded\Public\Warframe.x64.exe
FirewallRules: [{94E41F88-4C35-4C16-8602-64D32E238683}] => (Allow) C:\Program Files (x86)\Warframe\Downloaded\Public\Warframe.exe
FirewallRules: [{4FF4AF68-49E1-413F-B943-4EE1C63B3509}] => (Allow) C:\Program Files (x86)\Warframe\Downloaded\Public\Warframe.x64.exe
FirewallRules: [{D128A910-95E4-471F-97B8-94247BE05D5B}] => (Allow) C:\Users\note\AppData\Local\Warframe\Downloaded\Public\Tools\Launcher.exe
FirewallRules: [{F981DC38-DB3C-4BBA-9ABC-AEA1B02FAC28}] => (Allow) C:\Users\note\AppData\Local\Warframe\Downloaded\Public\Tools\RemoteCrashSender.exe
FirewallRules: [TCP Query User{7D4D5AFC-08B9-4BF2-89D2-24434B86E2E5}C:\games\world_of_warplanes\wowplauncher.exe] => (Allow) C:\games\world_of_warplanes\wowplauncher.exe
FirewallRules: [UDP Query User{66195025-392C-42C2-B8FB-5F37B275CB5A}C:\games\world_of_warplanes\wowplauncher.exe] => (Allow) C:\games\world_of_warplanes\wowplauncher.exe
FirewallRules: [TCP Query User{B833F868-DFDE-405B-8EED-E5B04828350C}C:\program files (x86)\tera\tera-launcher.exe] => (Allow) C:\program files (x86)\tera\tera-launcher.exe
FirewallRules: [UDP Query User{9EED6C2D-00C1-444C-877E-BF78583FA8D9}C:\program files (x86)\tera\tera-launcher.exe] => (Allow) C:\program files (x86)\tera\tera-launcher.exe
FirewallRules: [TCP Query User{011B79D3-B2D8-4C60-BCD1-FF00F1AF8109}C:\program files (x86)\warframe\downloaded\public\warframe.x64.exe] => (Allow) C:\program files (x86)\warframe\downloaded\public\warframe.x64.exe
FirewallRules: [UDP Query User{1E54203F-9308-4A78-BE67-EFE83AF50438}C:\program files (x86)\warframe\downloaded\public\warframe.x64.exe] => (Allow) C:\program files (x86)\warframe\downloaded\public\warframe.x64.exe
FirewallRules: [TCP Query User{98FA8AC1-2EFC-44DD-B85B-2CA1B691D51B}C:\program files (x86)\ncwest\nclauncher\ncupdatehelper.exe] => (Block) C:\program files (x86)\ncwest\nclauncher\ncupdatehelper.exe
FirewallRules: [UDP Query User{8917C549-705D-439E-9599-5357E51EE4B3}C:\program files (x86)\ncwest\nclauncher\ncupdatehelper.exe] => (Block) C:\program files (x86)\ncwest\nclauncher\ncupdatehelper.exe
FirewallRules: [TCP Query User{123E6FA3-3BBA-4D86-B03C-A21BA928BCE9}C:\program files (x86)\ncwest\nclauncher\ncupdatehelper.exe] => (Block) C:\program files (x86)\ncwest\nclauncher\ncupdatehelper.exe
FirewallRules: [UDP Query User{DDEA12F3-E0BC-439C-A89E-9CD05C35DFD3}C:\program files (x86)\ncwest\nclauncher\ncupdatehelper.exe] => (Block) C:\program files (x86)\ncwest\nclauncher\ncupdatehelper.exe
FirewallRules: [TCP Query User{13C1F47E-9EA6-4175-A41E-4DEFED440498}C:\program files (x86)\cenega czech\vietcong\vietcong.exe] => (Block) C:\program files (x86)\cenega czech\vietcong\vietcong.exe
FirewallRules: [UDP Query User{8B56F4B4-AA5B-4347-A32E-CA9CAE9FA06A}C:\program files (x86)\cenega czech\vietcong\vietcong.exe] => (Block) C:\program files (x86)\cenega czech\vietcong\vietcong.exe
FirewallRules: [TCP Query User{7233F6C4-2B87-4B42-856D-F96115FF000D}C:\games\panzar\bin64\pnzcl.exe] => (Allow) C:\games\panzar\bin64\pnzcl.exe
FirewallRules: [UDP Query User{840AB564-5816-4724-B750-5A0784A708D6}C:\games\panzar\bin64\pnzcl.exe] => (Allow) C:\games\panzar\bin64\pnzcl.exe
FirewallRules: [TCP Query User{E35FCF91-A5A8-4EDA-9083-6B2078E1FEB8}C:\program files (x86)\ubisoft\assassin's creed liberation hd\ac3lhd_32.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed liberation hd\ac3lhd_32.exe
FirewallRules: [UDP Query User{6711E284-A6EF-4448-BE78-841BA4C54A4D}C:\program files (x86)\ubisoft\assassin's creed liberation hd\ac3lhd_32.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed liberation hd\ac3lhd_32.exe
FirewallRules: [TCP Query User{D94CEED5-9F08-458B-8C96-38AB0994253D}C:\program files (x86)\gameforgelive\games\cze_ces\aion\nclauncher.exe] => (Allow) C:\program files (x86)\gameforgelive\games\cze_ces\aion\nclauncher.exe
FirewallRules: [UDP Query User{B14B0ED7-12E7-4ABF-B2EB-EBC25CE1512B}C:\program files (x86)\gameforgelive\games\cze_ces\aion\nclauncher.exe] => (Allow) C:\program files (x86)\gameforgelive\games\cze_ces\aion\nclauncher.exe
FirewallRules: [{32EB3996-B900-4B69-ACAC-3A25513EC310}] => (Allow) C:\Program Files (x86)\Kill3rCombo\Elsword\data\x2.exe
FirewallRules: [{8542FE0B-21A0-4E40-A596-FD31C57D4EF9}] => (Allow) C:\Program Files (x86)\Kill3rCombo\Elsword\data\x2.exe
FirewallRules: [{C299FE3E-EFA4-4466-9223-AE34CEA1689A}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [TCP Query User{60D89DDF-1819-42DE-8D39-DC1CBAC3B882}C:\program files (x86)\mkjogo\mklol\bin\mkim.exe] => (Allow) C:\program files (x86)\mkjogo\mklol\bin\mkim.exe
FirewallRules: [UDP Query User{C6718446-E8C8-4BC4-BAC9-035BC174BAD1}C:\program files (x86)\mkjogo\mklol\bin\mkim.exe] => (Allow) C:\program files (x86)\mkjogo\mklol\bin\mkim.exe
FirewallRules: [TCP Query User{69D744D8-5F98-463E-ADB6-D20DCC406F67}C:\program files (x86)\gameforgelive\games\gbr_eng\orcs must die! unchained\omdu.exe] => (Allow) C:\program files (x86)\gameforgelive\games\gbr_eng\orcs must die! unchained\omdu.exe
FirewallRules: [UDP Query User{A8415253-4C3A-458D-8B2D-C0080F7D751F}C:\program files (x86)\gameforgelive\games\gbr_eng\orcs must die! unchained\omdu.exe] => (Allow) C:\program files (x86)\gameforgelive\games\gbr_eng\orcs must die! unchained\omdu.exe
FirewallRules: [TCP Query User{AC3C8484-B0A6-45C4-8BA5-4C11F0A21EEF}C:\hry\the elder scrolls v - skyrim\creationkit.exe] => (Allow) C:\hry\the elder scrolls v - skyrim\creationkit.exe
FirewallRules: [UDP Query User{AA01DBDB-C02C-4B95-9466-5D238A99148D}C:\hry\the elder scrolls v - skyrim\creationkit.exe] => (Allow) C:\hry\the elder scrolls v - skyrim\creationkit.exe
FirewallRules: [TCP Query User{E72AAF8C-79E0-4D0E-A70C-5EDF629CA4B9}C:\program files (x86)\dishonored\binaries\win32\dishonored.exe] => (Allow) C:\program files (x86)\dishonored\binaries\win32\dishonored.exe
FirewallRules: [UDP Query User{1FD97C8F-CC94-44DF-A834-B4AFFBE6C7D8}C:\program files (x86)\dishonored\binaries\win32\dishonored.exe] => (Allow) C:\program files (x86)\dishonored\binaries\win32\dishonored.exe
FirewallRules: [TCP Query User{DB3F205C-F539-4502-9491-4E5B2E9BCC38}C:\hry\far cry 3\bin\farcry3.exe] => (Allow) C:\hry\far cry 3\bin\farcry3.exe
FirewallRules: [UDP Query User{A9669DDA-F75B-4000-9133-A1AFBC067991}C:\hry\far cry 3\bin\farcry3.exe] => (Allow) C:\hry\far cry 3\bin\farcry3.exe
FirewallRules: [{1487D9E7-976A-4A4D-AF96-253FF633A612}] => (Allow) C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe
FirewallRules: [{3674BFDE-A522-4238-8523-2029572E2AAF}] => (Allow) C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe
FirewallRules: [TCP Query User{75880981-FCE2-45E1-B64B-0C55BCF07F21}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{B54DDE81-1505-47B9-A0E4-AF7A911143C6}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [{36A64ACB-F982-4E66-8600-4829ED729763}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
FirewallRules: [{5B8877DC-B9B8-466C-9558-01321391111F}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
FirewallRules: [{62009A0B-3359-4D81-91B2-0B33944545F6}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
FirewallRules: [TCP Query User{6EF59820-6F17-4E2D-8A8D-A92179F9D966}C:\program files\java\jre1.8.0_40\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_40\bin\javaw.exe
FirewallRules: [UDP Query User{3E5DB9ED-A02E-4BCA-A43D-3CB48ACC5CAF}C:\program files\java\jre1.8.0_40\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_40\bin\javaw.exe
FirewallRules: [TCP Query User{AEFBC1F2-71DF-4486-90A8-367839440E83}F:\číčoviny !!\cs\hl.exe] => (Allow) F:\číčoviny !!\cs\hl.exe
FirewallRules: [UDP Query User{DA3364BC-A4A7-4032-853B-15A141A23FCD}F:\číčoviny !!\cs\hl.exe] => (Allow) F:\číčoviny !!\cs\hl.exe
FirewallRules: [{8E3A4D47-1B86-4095-91B5-4B9B1102C8B4}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{9919F8C2-42C0-4316-A10A-E1FEB9337D6C}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{45BD8AAA-B5C5-4841-A5C2-0A460225D72F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{6B2B00A6-A83F-4C88-B270-3D6BEFB9EAC7}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{722A6296-D044-442A-868D-9DC3BE452E8F}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
FirewallRules: [{6CEB65F9-D5BE-43AE-B68F-2E84B4E94535}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
FirewallRules: [TCP Query User{E855EF4D-F0FF-419C-9485-54E32703A3DB}C:\program files (x86)\remote mouse\remotemouse.exe] => (Block) C:\program files (x86)\remote mouse\remotemouse.exe
FirewallRules: [UDP Query User{E6E8A9D6-E5DE-4CFA-83DA-76B47A27E747}C:\program files (x86)\remote mouse\remotemouse.exe] => (Block) C:\program files (x86)\remote mouse\remotemouse.exe
FirewallRules: [TCP Query User{A31EFF2E-3175-45D7-9C0A-9E88BCC1AA2D}C:\program files\java\jre1.8.0_40\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_40\bin\javaw.exe
FirewallRules: [UDP Query User{651C1C1C-AECA-4D01-A0E5-072AE51047B7}C:\program files\java\jre1.8.0_40\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_40\bin\javaw.exe
FirewallRules: [{1EBCB88C-61CA-4EC3-B07C-25ABB75DE5E9}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Faulty Device Manager Devices =============

Name: lirsgt
Description: lirsgt
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer: 
Service: lirsgt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: Generic Bluetooth Adapter
Description: Generic Bluetooth Adapter
Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
Manufacturer: GenericAdapter
Service: BTHUSB
Problem: : Windows has stopped this device because it has reported problems. (Code 43)
Resolution: One of the drivers controlling the device notified the operating system that the device failed in some manner. For more information about how to diagnose the problem, see the hardware documentation. 


==================== Event log errors: =========================

Application errors:
==================
Error: (05/16/2015 04:50:52 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program FRST64.exe verze 16.5.2015.2 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.

ID procesu: 16ac

Čas spuštění: 01d08fe77ddd36fa

Čas ukončení: 5

Cesta k aplikaci: C:\Users\note\Desktop\FRST-OlderVersion\FRST64.exe

ID hlášení:

Error: (05/16/2015 04:48:56 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program FRST64.exe verze 16.5.2015.2 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.

ID procesu: 1bbc

Čas spuštění: 01d08fe7418bcf71

Čas ukončení: 6

Cesta k aplikaci: C:\Users\note\Desktop\FRST64.exe

ID hlášení:

Error: (05/15/2015 11:52:59 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: chromodo.exe, verze: 36.7.0.8, časové razítko: 0x5513a77e
Název chybujícího modulu: chromodo_s.dll, verze: 36.7.0.8, časové razítko: 0x5513a73a
Kód výjimky: 0xc0000005
Posun chyby: 0x00367459
ID chybujícího procesu: 0x122c
Čas spuštění chybující aplikace: 0xchromodo.exe0
Cesta k chybující aplikaci: chromodo.exe1
Cesta k chybujícímu modulu: chromodo.exe2
ID zprávy: chromodo.exe3

Error: (05/15/2015 10:20:53 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Uvolnění řetězců čítačů výkonu pro službu WmiApRpl (WmiApRpl) se nezdařilo. První hodnota DWORD v datové oblasti obsahuje kód chyby.

Error: (05/15/2015 10:20:53 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: Hodnota řetězce výkonu v registru výkonu je poškozena, pokud proces Performance zprostředkovatele čítače rozšíření. Hodnotu BaseIndex z registru výkonu obsahuje první hodnota DWORD datové části. Hodnotu LastCounter obsahuje druhá hodnota DWORD a hodnotu LastHelp obsahuje třetí hodnota DWORD datové části.

Error: (05/15/2015 10:20:53 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: Hodnota řetězce výkonu v registru výkonu je poškozena, pokud proces Performance zprostředkovatele čítače rozšíření. Hodnotu BaseIndex z registru výkonu obsahuje první hodnota DWORD datové části. Hodnotu LastCounter obsahuje druhá hodnota DWORD a hodnotu LastHelp obsahuje třetí hodnota DWORD datové části.

Error: (05/13/2015 09:53:00 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe_DiagTrack, verze: 6.1.7600.16385, časové razítko: 0x4a5bc3c1
Název chybujícího modulu: ntdll.dll, verze: 6.1.7601.18839, časové razítko: 0x553e8bfa
Kód výjimky: 0xc000000d
Posun chyby: 0x000000000006ec12
ID chybujícího procesu: 0x6b0
Čas spuštění chybující aplikace: 0xsvchost.exe_DiagTrack0
Cesta k chybující aplikaci: svchost.exe_DiagTrack1
Cesta k chybujícímu modulu: svchost.exe_DiagTrack2
ID zprávy: svchost.exe_DiagTrack3

Error: (05/13/2015 05:49:47 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Uvolnění řetězců čítačů výkonu pro službu WmiApRpl (WmiApRpl) se nezdařilo. První hodnota DWORD v datové oblasti obsahuje kód chyby.

Error: (05/13/2015 05:49:47 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: Hodnota řetězce výkonu v registru výkonu je poškozena, pokud proces Performance zprostředkovatele čítače rozšíření. Hodnotu BaseIndex z registru výkonu obsahuje první hodnota DWORD datové části. Hodnotu LastCounter obsahuje druhá hodnota DWORD a hodnotu LastHelp obsahuje třetí hodnota DWORD datové části.

Error: (05/13/2015 05:49:47 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: Hodnota řetězce výkonu v registru výkonu je poškozena, pokud proces Performance zprostředkovatele čítače rozšíření. Hodnotu BaseIndex z registru výkonu obsahuje první hodnota DWORD datové části. Hodnotu LastCounter obsahuje druhá hodnota DWORD a hodnotu LastHelp obsahuje třetí hodnota DWORD datové části.


System errors:
=============
Error: (05/16/2015 10:35:43 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba lirsgt neuspěla při spuštění v důsledku následující chyby: 
%%577

Error: (05/16/2015 10:35:41 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba atksgt neuspěla při spuštění v důsledku následující chyby: 
%%577

Error: (05/16/2015 10:35:14 AM) (Source: BTHUSB) (EventID: 17) (User: )
Description: Místní adaptér Bluetooth selhal. Důvod selhaní nebylo možno určit a adaptér nebude používán. Ovladač vysílače byl vyjmut z paměti.

Error: (05/15/2015 10:46:49 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba lirsgt neuspěla při spuštění v důsledku následující chyby: 
%%577

Error: (05/15/2015 10:46:48 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba atksgt neuspěla při spuštění v důsledku následující chyby: 
%%577

Error: (05/15/2015 10:46:23 PM) (Source: BTHUSB) (EventID: 17) (User: )
Description: Místní adaptér Bluetooth selhal. Důvod selhaní nebylo možno určit a adaptér nebude používán. Ovladač vysílače byl vyjmut z paměti.

Error: (05/15/2015 06:52:28 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba lirsgt neuspěla při spuštění v důsledku následující chyby: 
%%577

Error: (05/15/2015 06:52:26 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba atksgt neuspěla při spuštění v důsledku následující chyby: 
%%577

Error: (05/15/2015 06:51:50 PM) (Source: BTHUSB) (EventID: 17) (User: )
Description: Místní adaptér Bluetooth selhal. Důvod selhaní nebylo možno určit a adaptér nebude používán. Ovladač vysílače byl vyjmut z paměti.

Error: (05/15/2015 04:29:08 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba ESET Service je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.


Microsoft Office Sessions:
=========================

CodeIntegrity Errors:
===================================
  Date: 2015-05-16 10:35:43.057
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\lirsgt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-05-16 10:35:43.003
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\lirsgt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-05-16 10:35:41.135
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\atksgt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-05-16 10:35:41.075
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\atksgt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-05-15 22:46:49.436
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\lirsgt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-05-15 22:46:49.374
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\lirsgt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-05-15 22:46:48.297
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\atksgt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-05-15 22:46:48.235
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\atksgt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-05-15 18:52:28.646
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\lirsgt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-05-15 18:52:28.586
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\lirsgt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info =========================== 

Processor: AMD Phenom(tm) II N660 Dual-Core Processor
Percentage of memory in use: 33%
Total physical RAM: 5882.9 MB
Available physical RAM: 3926.91 MB
Total Pagefile: 11764.01 MB
Available Pagefile: 9505.53 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.66 GB) (Free:364.91 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: FD65E542)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS)

==================== End Of Log ============================