﻿Additional scan result of Farbar Recovery Scan Tool (x64) Version:29-08-2015
Ran by okay (2015-08-30 15:58:58)
Running from C:\Users\okay\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2154949696-2308494473-1947472548-500 - Administrator - Disabled)
Guest (S-1-5-21-2154949696-2308494473-1947472548-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2154949696-2308494473-1947472548-1098 - Limited - Enabled)
okay (S-1-5-21-2154949696-2308494473-1947472548-1000 - Administrator - Enabled) => C:\Users\okay

==================== Security Center ========================

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2015-07-25 00:27 - 00450709 ____R C:\windows\system32\Drivers\etc\hosts
127.0.0.1	www.007guard.com
127.0.0.1	007guard.com
127.0.0.1	008i.com
127.0.0.1	www.008k.com
127.0.0.1	008k.com
127.0.0.1	www.00hq.com
127.0.0.1	00hq.com
127.0.0.1	010402.com
127.0.0.1	www.032439.com
127.0.0.1	032439.com
127.0.0.1	www.0scan.com
127.0.0.1	0scan.com
127.0.0.1	1000gratisproben.com
127.0.0.1	www.1000gratisproben.com
127.0.0.1	1001namen.com
127.0.0.1	www.1001namen.com
127.0.0.1	100888290cs.com
127.0.0.1	www.100888290cs.com
127.0.0.1	www.100sexlinks.com
127.0.0.1	100sexlinks.com
127.0.0.1	10sek.com
127.0.0.1	www.10sek.com
127.0.0.1	www.1-2005-search.com
127.0.0.1	1-2005-search.com
127.0.0.1	123fporn.info
127.0.0.1	www.123fporn.info
127.0.0.1	123haustiereundmehr.com
127.0.0.1	www.123haustiereundmehr.com
127.0.0.1	123moviedownload.com

There are 1000 more lines.


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {02AF3B30-966B-47FF-9958-4BBD0BE7DEEF} - System32\Tasks\{5D04C217-BB7E-4894-B5DD-127D0A417105} => D:\Counter-Strike.exe
Task: {05702C88-1125-44FB-AD8D-8DD23465CABE} - System32\Tasks\{EC3598D0-9CA0-4A3E-97C6-EEC5F855CC59} => pcalua.exe -a "C:\Program Files (x86)\InstallShield Installation Information\{D1434266-0486-4469-B338-A60082CC04E1}\setup.exe" -c -runfromtemp -l0x0009 -removeonly
Task: {07D75F04-6961-4CAF-9BF1-34EFC8669619} - System32\Tasks\{38365E04-5F41-487C-BEE9-E38CE7D9B383} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-04-17] (Skype Technologies S.A.)
Task: {329DD632-5A8C-4FF0-8019-36F11D521A6E} - System32\Tasks\{43CB37D3-A4D4-4819-9FB2-4AC54743FF08} => C:\Program Files (x86)\AVG Secure Search\Uninstall.exe
Task: {3972932D-180A-412C-BA94-8224187FF19B} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2015-08-25] (AVAST Software)
Task: {3B990A66-CF92-43AD-B4ED-F27A1713024C} - System32\Tasks\{8C881E3E-CB14-47A8-A745-CC4E1DFED029} => C:\Program Files (x86)\AVG Secure Search\Uninstall.exe
Task: {3D338024-3A80-4DDC-8627-9CF83D547EDB} - System32\Tasks\EasyBatteryManager => C:\Program Files (x86)\Samsung\EasyBatteryManager\EasyBatteryMgr4.exe [2009-10-16] (SAMSUNG Electronics co., LTD.)
Task: {3EB38D5F-8792-4D66-94EC-E1DA2758F270} - System32\Tasks\EasyPartitionManager => C:\Windows\MSetup\BA46-05053A92\EPM.exe
Task: {3EFBE844-CC75-4AC1-9400-09857CE04046} - System32\Tasks\{896F60FA-860F-497A-AF2E-FA140A0A1701} => pcalua.exe -a "C:\Program Files\AVAST Software\Avast\aswRunDll.exe" -c "C:\Program Files\AVAST Software\Avast\Setup\setiface.dll" RunSetup
Task: {4FCA0743-3174-4B6A-A117-D555F2E8854D} - System32\Tasks\{6033D512-3F03-414A-A797-15BB1058A4CB} => D:\Counter-Strike.exe
Task: {5742CA4C-37C6-4B1A-9C8C-4866E502700D} - System32\Tasks\{A097E44C-0350-42B1-B3B3-E3968E400DBE} => pcalua.exe -a C:\windows\UniFish3.exe -c C:\Program Files (x86)\Hasbro Interactive\RollerCoaster Tycoon\RollerCoaster Tycoon.log
Task: {588864B1-3EC7-4C83-AEDA-4CBA96883259} - System32\Tasks\GoogleUpdateTaskMachineCore1d042128342d30a => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {5AE4C24B-4944-452B-9791-E82C58DFB302} - System32\Tasks\{BFA73E29-4554-45C7-A014-394D7323704A} => Iexplore.exe http://ui.skype.com/ui/0/7.5.0.102/cs/go/help.faq.installer?LastError=1603
Task: {654E9752-B6B0-456B-9B60-27B6AC05C02B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {7650D708-F2A6-410D-8449-BB902F6FB9E8} - System32\Tasks\SUPBackground => C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe
Task: {7C9AD1E6-0B70-4E5F-8841-2F14AF2FA87A} - System32\Tasks\EasyDisplayMgr => C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe [2010-06-08] (Samsung Electronics Co., Ltd.)
Task: {7D04CFC7-E37F-447F-9B2E-7660EDDDA286} - System32\Tasks\{304CA720-8E6E-4100-82D2-6FDDBF33F042} => pcalua.exe -a "C:\Program Files\AVAST Software\Avast\aswRunDll.exe" -c "C:\Program Files\AVAST Software\Avast\Setup\setiface.dll" RunSetup
Task: {8D139A53-6AFC-4448-BB5F-424195A665F2} - System32\Tasks\advSRS4 => C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe [2010-01-19] (SEC)
Task: {DE4F6A74-F85E-4498-8987-D0A0C64B16F8} - System32\Tasks\{F2041C1A-5C91-4D43-B9A2-0CFE4C3D9DA6} => C:\Users\okay\Desktop\Nero2014-15.0.07100_trial.exe
Task: {E3F7CB46-DF04-4B13-B68E-C40E597A177A} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-13] (Adobe Systems Incorporated)
Task: {E875552D-52CE-4CE3-8521-E5527705472C} - System32\Tasks\BatteryLifeExtender => C:\Program Files (x86)\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe [2010-06-01] (Samsung Electronics. Co. Ltd.)
Task: {EDF0E594-ABF0-424C-8C24-B03AE7F9530C} - System32\Tasks\{B98A1F97-D739-446F-9F06-1B57C22D690C} => pcalua.exe -a "D:\mafia\Mafia 1 – Plna Verze Hry – CZ\Setup.exe" -d "D:\mafia\Mafia 1 – Plna Verze Hry – CZ"
Task: {EE2308E3-0331-4AF0-AA63-F59797C8AC3E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {F8E657E4-94F1-4217-B148-0A92A3AC2B7B} - System32\Tasks\{F037AC9D-67DE-406D-AC11-2E5426869BE9} => C:\Program Files (x86)\AVG Secure Search\Uninstall.exe
Task: {FB8CAF7B-ACDE-4FA1-8AB2-628493E9919B} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-06-18] (Avast Software s.r.o.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore1d042128342d30a.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2011-01-27 04:41 - 2009-01-23 03:46 - 00203280 _____ () C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe
2014-11-08 18:39 - 2014-11-08 18:39 - 00066872 _____ () C:\windows\SysWOW64\PnkBstrA.exe
2014-11-08 18:39 - 2014-11-08 18:40 - 00107832 _____ () C:\windows\SysWOW64\PnkBstrB.exe
2011-01-27 04:24 - 2009-07-07 20:23 - 00247152 ____N () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
2015-04-02 14:09 - 2015-05-27 17:14 - 03042352 _____ () D:\GameforgeLive\gfl_client.exe
2014-09-27 20:48 - 2014-09-27 20:48 - 00301152 _____ () C:\Program Files\AVAST Software\Avast\aswProperty.dll
2015-08-30 10:29 - 2015-08-30 10:29 - 02961920 _____ () C:\Program Files\AVAST Software\Avast\defs\15083000\algo.dll
2011-07-04 20:27 - 2011-01-07 14:54 - 00767952 _____ () C:\windows\BDTSupport.dll
2011-01-27 04:28 - 2006-08-12 05:48 - 00049152 _____ () C:\Program Files (x86)\Samsung\Easy Display Manager\HookDllPS2.dll
2011-01-27 04:41 - 2009-01-23 03:46 - 00013840 _____ () C:\Program Files (x86)\McAfee\SiteAdvisor\saHook.dll
2011-01-27 04:41 - 2009-01-29 05:26 - 00117264 _____ () c:\Program Files (x86)\McAfee\SiteAdvisor\apengine.dll
2011-01-27 04:41 - 2009-01-23 03:46 - 00351248 _____ () c:\Program Files (x86)\McAfee\SiteAdvisor\saupkeep.dll
2011-01-27 04:41 - 2009-01-29 05:27 - 00071696 _____ () c:\Program Files (x86)\McAfee\SiteAdvisor\mcfrmwk.dll
2011-01-27 04:41 - 2009-01-29 05:27 - 00652304 _____ () C:\Program Files (x86)\McAfee\SiteAdvisor\SACore.dll
2011-01-27 04:41 - 2009-01-29 05:27 - 00310800 _____ () C:\Program Files (x86)\McAfee\SiteAdvisor\SASet.dll
2011-01-27 04:41 - 2009-01-23 03:46 - 00056336 _____ () c:\Program Files (x86)\McAfee\SiteAdvisor\McSACorePS.dll
2011-01-27 04:41 - 2009-01-29 05:27 - 00207376 _____ () c:\Program Files (x86)\McAfee\SiteAdvisor\cntscan.dll
2009-06-03 13:59 - 2009-06-03 13:59 - 00619816 ____N () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
2009-06-03 13:59 - 2009-06-03 13:59 - 00013096 ____N () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
2014-09-27 20:48 - 2014-09-27 20:48 - 19329904 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2015-08-21 19:12 - 2015-08-18 07:23 - 01405768 _____ () C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.157\libglesv2.dll
2015-08-21 19:12 - 2015-08-18 07:23 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.157\libegl.dll
2015-04-02 14:09 - 2015-05-27 11:48 - 00088064 _____ () D:\GameforgeLive\libgcc_s_sjlj-1.dll
2015-04-02 14:09 - 2015-05-27 11:48 - 00863744 _____ () D:\GameforgeLive\libstdc++-6.dll
2015-04-02 14:09 - 2015-05-27 11:48 - 05686669 _____ () D:\GameforgeLive\libtorrent.dll
2015-04-02 14:09 - 2015-05-27 11:48 - 00097659 _____ () D:\GameforgeLive\libboost_system-mgw47-mt-1_53.dll
2015-04-02 14:09 - 2015-05-27 11:48 - 01765301 _____ () D:\GameforgeLive\libgcrypt-11.dll
2015-04-02 14:09 - 2015-05-27 11:48 - 00126959 _____ () D:\GameforgeLive\libgpg-error-0.dll
2015-04-02 14:09 - 2015-05-27 11:48 - 00530432 _____ () D:\GameforgeLive\log4qt.dll
2015-04-02 14:09 - 2015-05-27 11:48 - 00141312 _____ () D:\GameforgeLive\qjson.dll
2015-08-21 19:12 - 2015-08-18 07:23 - 16393032 _____ () C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.157\PepperFlash\pepflashplayer.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\Temp:430C6D84
AlternateDataStreams: C:\ProgramData\Temp:D1B5B4F1
AlternateDataStreams: C:\ProgramData\Temp:DFC5A2B2

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com

There are 7866 more restricted sites.

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2154949696-2308494473-1947472548-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\okay\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 10.0.0.138
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{48FD8AAA-7FA4-41AD-BC1F-608BCD28F251}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector\PDR.EXE
FirewallRules: [{A0ED4C79-2455-4C3B-A5E2-A134B6771834}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD8\PowerDVD8.EXE
FirewallRules: [{30056B28-1513-4C47-861D-0B25CD27E6F6}] => (Allow) C:\Program Files (x86)\Common Files\Mcafee\MNA\McNaSvc.exe
FirewallRules: [{3F6C82BC-F16C-46C1-9249-7021884233DE}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{2E356CDC-16B7-4914-BC96-6BC6CEEA063D}] => (Allow) LPort=2869
FirewallRules: [{28D4A60D-DECE-47D7-85B0-23258DD6E374}] => (Allow) LPort=1900
FirewallRules: [{84CF7620-2A33-4DB5-809D-918EAD36C17B}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{91191C7B-ABA2-4113-B16A-E8DF4B725C8C}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{B6AB7B1D-73A9-4C09-A811-B28EB714DDC1}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{7E900775-8D84-4F25-B3A7-EF1267477AA4}] => (Allow) C:\Program Files (x86)\Opera\opera.exe
FirewallRules: [{03E639C5-406D-43A9-B559-F2BE0CE42906}] => (Allow) C:\Program Files (x86)\Opera\opera.exe
FirewallRules: [{F97CBC13-B72E-47A7-B79B-CD74F65AED92}] => (Allow) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
FirewallRules: [{A6F19958-58CF-4772-B903-BA983BC21060}] => (Allow) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
FirewallRules: [TCP Query User{9BD3F1F2-470C-41C0-B2E4-22F13C3510B9}C:\users\okay\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\okay\appdata\local\google\chrome\application\chrome.exe
FirewallRules: [UDP Query User{27073F99-D9D6-453F-A839-5183BDF6F4CF}C:\users\okay\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\okay\appdata\local\google\chrome\application\chrome.exe
FirewallRules: [TCP Query User{17D0656C-8BBE-435A-8DB3-82F750E128B0}C:\program files\flatout\flatout.exe] => (Block) C:\program files\flatout\flatout.exe
FirewallRules: [UDP Query User{AB3B8E3E-EE9A-4CB9-AD53-0386FB738EFF}C:\program files\flatout\flatout.exe] => (Block) C:\program files\flatout\flatout.exe
FirewallRules: [TCP Query User{30BB9C99-3CB7-4DF9-B782-D31562F5E75F}C:\counter-strike 1.6\csko.exe] => (Allow) C:\counter-strike 1.6\csko.exe
FirewallRules: [UDP Query User{169795BE-AFA8-4FB9-9C04-CB71899CDF9E}C:\counter-strike 1.6\csko.exe] => (Allow) C:\counter-strike 1.6\csko.exe
FirewallRules: [TCP Query User{7D029CF3-B18E-400B-8C10-F73031E89147}C:\counter-strike 1.6\csko.exe] => (Allow) C:\counter-strike 1.6\csko.exe
FirewallRules: [UDP Query User{BDC92007-0650-4547-AA37-B48D119DC31B}C:\counter-strike 1.6\csko.exe] => (Allow) C:\counter-strike 1.6\csko.exe
FirewallRules: [TCP Query User{FFA0F906-6611-46E1-B939-D8C5C99F3FE5}C:\counter-strike 1.6\hl.exe] => (Allow) C:\counter-strike 1.6\hl.exe
FirewallRules: [UDP Query User{499404F2-5B4A-454E-BF55-C26B1D553488}C:\counter-strike 1.6\hl.exe] => (Allow) C:\counter-strike 1.6\hl.exe
FirewallRules: [TCP Query User{57BBC09F-DE53-47A9-8D15-76D650170A8B}C:\program files (x86)\hasbro interactive\rollercoaster tycoon\rct.exe] => (Block) C:\program files (x86)\hasbro interactive\rollercoaster tycoon\rct.exe
FirewallRules: [UDP Query User{2E4468B6-2373-4395-B79B-D9849EE8CB04}C:\program files (x86)\hasbro interactive\rollercoaster tycoon\rct.exe] => (Block) C:\program files (x86)\hasbro interactive\rollercoaster tycoon\rct.exe
FirewallRules: [TCP Query User{608E7CA9-516A-465E-B89E-E4CD68243F74}C:\program files (x86)\hasbro interactive\rollercoaster tycoon\rct.exe] => (Block) C:\program files (x86)\hasbro interactive\rollercoaster tycoon\rct.exe
FirewallRules: [UDP Query User{8CFF76F1-8334-4F63-BF70-DEFA6F6F39A6}C:\program files (x86)\hasbro interactive\rollercoaster tycoon\rct.exe] => (Block) C:\program files (x86)\hasbro interactive\rollercoaster tycoon\rct.exe
FirewallRules: [TCP Query User{23549BBE-4B80-4FDA-8501-DF15C444179C}C:\program files (x86)\internet explorer\iexplore.exe] => (Allow) C:\program files (x86)\internet explorer\iexplore.exe
FirewallRules: [UDP Query User{8C443531-A466-4BE1-8EF8-C61FFAC64C4A}C:\program files (x86)\internet explorer\iexplore.exe] => (Allow) C:\program files (x86)\internet explorer\iexplore.exe
FirewallRules: [{D4C00DB5-6CC3-4E2F-B5EF-2E03C64A8597}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{02A28612-9AD5-4277-BD52-150C99DA0E73}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{3DD2E5F0-0150-4D45-A215-0D0B8FDA71E1}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{BAECF184-E661-4666-B7AD-58E7AAE3637F}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [TCP Query User{8FBC5AB1-4BEB-405E-A363-E2B8C3222B26}D:\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe] => (Allow) D:\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe
FirewallRules: [UDP Query User{067D2A79-4508-4838-AC74-EDF30CED75FB}D:\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe] => (Allow) D:\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcher.exe
FirewallRules: [TCP Query User{2B8B7D98-616A-493E-AD34-0BD1886C4B1F}D:\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe] => (Allow) D:\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe
FirewallRules: [UDP Query User{D57B9F75-B6F1-4AC6-B3F1-719098EE4C7F}D:\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe] => (Allow) D:\league of legends\rads\projects\lol_patcher\releases\0.0.0.14\deploy\lolpatcherux.exe
FirewallRules: [TCP Query User{256997CD-DFE9-4239-9BCC-089F71DA593E}D:\hl.exe] => (Allow) D:\hl.exe
FirewallRules: [UDP Query User{3D4DAAE7-5653-48E4-A212-72336FC82C20}D:\hl.exe] => (Allow) D:\hl.exe
FirewallRules: [TCP Query User{2B652103-5E46-488A-8497-D14DA458888B}D:\cs\hl.exe] => (Allow) D:\cs\hl.exe
FirewallRules: [UDP Query User{B6226594-8B09-4082-8A6A-93D73F878187}D:\cs\hl.exe] => (Allow) D:\cs\hl.exe
FirewallRules: [TCP Query User{A082852B-64AF-4F2E-A50D-6FF25F078F44}C:\program files (x86)\ncwest\nclauncher\ncupdatehelper.exe] => (Allow) C:\program files (x86)\ncwest\nclauncher\ncupdatehelper.exe
FirewallRules: [UDP Query User{615E05B6-2066-4B77-B03E-19AED2B80CD2}C:\program files (x86)\ncwest\nclauncher\ncupdatehelper.exe] => (Allow) C:\program files (x86)\ncwest\nclauncher\ncupdatehelper.exe
FirewallRules: [TCP Query User{49881476-789F-4544-869D-89BA962BD00A}D:\cs\hl.exe] => (Allow) D:\cs\hl.exe
FirewallRules: [UDP Query User{FFC050BF-DAFB-4585-90CD-7DE0E6B0D1A1}D:\cs\hl.exe] => (Allow) D:\cs\hl.exe
FirewallRules: [{D1AD9ABB-1717-4F08-BD97-DD66D6FD8B52}] => (Allow) D:\GameforgeLive\gfl_client.exe
FirewallRules: [TCP Query User{4D3A8828-5782-458D-9293-970928AFA175}D:\quake3.exe] => (Allow) D:\quake3.exe
FirewallRules: [UDP Query User{6F0C1B3D-D855-4B5C-8E87-2E94B107751B}D:\quake3.exe] => (Allow) D:\quake3.exe
FirewallRules: [TCP Query User{C3BBE5C8-EC4B-4F1E-9EE4-3844A25C84A6}D:\robin\quake3.exe] => (Block) D:\robin\quake3.exe
FirewallRules: [UDP Query User{F5F978E3-8D1B-41B2-9BAC-F1372A2462A8}D:\robin\quake3.exe] => (Block) D:\robin\quake3.exe
FirewallRules: [TCP Query User{F5F539D1-27A5-427B-BC0F-4C31A270CD7A}D:\world_of_tanks\wotlauncher.exe] => (Allow) D:\world_of_tanks\wotlauncher.exe
FirewallRules: [UDP Query User{80EC3452-4A2F-4FD6-B594-47CBAFE70901}D:\world_of_tanks\wotlauncher.exe] => (Allow) D:\world_of_tanks\wotlauncher.exe
FirewallRules: [TCP Query User{07A4AD70-1D91-4D0A-9A04-E94CE6075997}D:\world_of_tanks\worldoftanks.exe] => (Allow) D:\world_of_tanks\worldoftanks.exe
FirewallRules: [UDP Query User{34BD4E69-163A-433C-9C93-A70F947E6CEA}D:\world_of_tanks\worldoftanks.exe] => (Allow) D:\world_of_tanks\worldoftanks.exe
FirewallRules: [{3E520791-5B57-4DAF-A342-DF818BD6CE59}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Faulty Device Manager Devices =============

Name: avast! Firewall NDIS Filter Miniport
Description: avast! Firewall NDIS Filter Miniport
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: ALWIL Software
Service: aswNdis
Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
Resolution: A registry problem was detected.
 This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.

Name: avast! Firewall NDIS Filter Miniport
Description: avast! Firewall NDIS Filter Miniport
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: ALWIL Software
Service: aswNdis
Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
Resolution: A registry problem was detected.
 This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.


==================== Event log errors: =========================

Application errors:
==================
Error: (08/30/2015 01:21:43 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Vytvoření bodu obnovení se nezdařilo (Proces = C:\windows\system32\svchost.exe -k netsvcs; Popis = Windows Update; Chyba = 0x8004231f).

Error: (08/30/2015 01:07:38 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: chrome.exe, verze: 44.0.2403.157, časové razítko: 0x55d29eef
Název chybujícího modulu: YCWebCameraSource.ax, verze: 2.0.10175.3910, časové razítko: 0x4b9715b8
Kód výjimky: 0xc0000005
Posun chyby: 0x0000c9d8
ID chybujícího procesu: 0xff0
Čas spuštění chybující aplikace: 0xchrome.exe0
Cesta k chybující aplikaci: chrome.exe1
Cesta k chybujícímu modulu: chrome.exe2
ID zprávy: chrome.exe3

Error: (08/30/2015 01:06:17 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: chrome.exe, verze: 44.0.2403.157, časové razítko: 0x55d29eef
Název chybujícího modulu: YCWebCameraSource.ax, verze: 2.0.10175.3910, časové razítko: 0x4b9715b8
Kód výjimky: 0xc0000005
Posun chyby: 0x0000c9d8
ID chybujícího procesu: 0x32c
Čas spuštění chybující aplikace: 0xchrome.exe0
Cesta k chybující aplikaci: chrome.exe1
Cesta k chybujícímu modulu: chrome.exe2
ID zprávy: chrome.exe3

Error: (08/30/2015 10:29:51 AM) (Source: Wininit) (EventID: 1015) (User: )
Description: Došlo k selhání kritického systémového procesu C:\windows\system32\lsm.exe se stavovým kódem 255. Počítač je nyní nutné restartovat.

Error: (08/30/2015 10:29:48 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: lsm.exe, verze: 6.1.7601.17514, časové razítko: 0x4ce7abf0
Název chybujícího modulu: ntdll.dll, verze: 6.1.7601.18869, časové razítko: 0x556366f2
Kód výjimky: 0xc0000005
Posun chyby: 0x00000000000200fa
ID chybujícího procesu: 0x260
Čas spuštění chybující aplikace: 0xlsm.exe0
Cesta k chybující aplikaci: lsm.exe1
Cesta k chybujícímu modulu: lsm.exe2
ID zprávy: lsm.exe3

Error: (08/30/2015 10:28:44 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program Explorer.EXE verze 6.1.7601.17567 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.

ID procesu: 580

Čas spuštění: 01d0e2fd1c383c2f

Čas ukončení: 59

Cesta k aplikaci: C:\windows\Explorer.EXE

ID hlášení: 16670e5f-4ef1-11e5-a1df-e8113224d9f6

Error: (08/30/2015 10:15:10 AM) (Source: ESENT) (EventID: 482) (User: )
Description: Windows (4720) Windows: Pokus o zápis do souboru C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb s posunem 4620288 (0x0000000000468000) o 32768 (0x00008000) bajtů se po Windows0 sekundách nezdařil. Došlo k systémové chybě 112 (0x00000070): Na disku není dost místa. . Operace zápisu se nezdaří a dojde k chybě -1808 (0xfffff8f0). Pokud tyto potíže potrvají, je soubor pravděpodobně poškozen a bude nutné jej obnovit ze záložní kopie.

Error: (08/30/2015 10:14:21 AM) (Source: ESENT) (EventID: 428) (User: )
Description: Windows (1208) Windows: Databázový stroj odmítá operace aktualizace kvůli nedostatku místa na disku s protokolem.

Error: (08/30/2015 10:14:14 AM) (Source: ESENT) (EventID: 428) (User: )
Description: Windows (4392) Windows: Databázový stroj odmítá operace aktualizace kvůli nedostatku místa na disku s protokolem.

Error: (08/30/2015 10:13:29 AM) (Source: ESENT) (EventID: 428) (User: )
Description: Windows (4376) Windows: Databázový stroj odmítá operace aktualizace kvůli nedostatku místa na disku s protokolem.


System errors:
=============
Error: (08/30/2015 03:51:44 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Při čekání na odezvu transakce služby TrustedInstaller bylo dosaženo časového limitu (30000 ms).

Error: (08/30/2015 03:47:30 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Byla přijata následující výstraha o závažné chybě: 40.

Error: (08/30/2015 03:47:29 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Byla přijata následující výstraha o závažné chybě: 40.

Error: (08/30/2015 11:47:14 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Byla přijata následující výstraha o závažné chybě: 40.

Error: (08/30/2015 11:47:14 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Byla přijata následující výstraha o závažné chybě: 40.

Error: (08/30/2015 10:43:00 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Zavedení následujícího ovladače pro spouštění počítače nebo systému se nezdařilo: 
TfFsMon
TFSysMon

Error: (08/30/2015 10:40:15 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Instalační služba modulů systému Windows byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 120000 milisekund: Restartovat službu.

Error: (08/30/2015 10:40:15 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Windows Search byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 30000 milisekund: Restartovat službu.

Error: (08/30/2015 10:40:15 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Ochrana softwaru byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 120000 milisekund: Restartovat službu.

Error: (08/30/2015 10:40:15 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Windows Live ID Sign-in Assistant byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.


Microsoft Office:
=========================
Error: (08/30/2015 01:21:43 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: C:\windows\system32\svchost.exe -k netsvcsWindows Update0x8004231f

Error: (08/30/2015 01:07:38 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: chrome.exe44.0.2403.15755d29eefYCWebCameraSource.ax2.0.10175.39104b9715b8c00000050000c9d8ff001d0e313f17386a6C:\Program Files (x86)\Google\Chrome\Application\chrome.exeC:\Program Files (x86)\CyberLink\YouCam\YCWebCameraSource.ax52747762-4f07-11e5-905e-e8113224d9f6

Error: (08/30/2015 01:06:17 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: chrome.exe44.0.2403.15755d29eefYCWebCameraSource.ax2.0.10175.39104b9715b8c00000050000c9d832c01d0e300012ee9e8C:\Program Files (x86)\Google\Chrome\Application\chrome.exeC:\Program Files (x86)\CyberLink\YouCam\YCWebCameraSource.ax2219bb87-4f07-11e5-905e-e8113224d9f6

Error: (08/30/2015 10:29:51 AM) (Source: Wininit) (EventID: 1015) (User: )
Description: C:\windows\system32\lsm.exe255

Error: (08/30/2015 10:29:48 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: lsm.exe6.1.7601.175144ce7abf0ntdll.dll6.1.7601.18869556366f2c000000500000000000200fa26001d0e2fd037042b5C:\windows\system32\lsm.exeC:\windows\SYSTEM32\ntdll.dll464d02ad-4ef1-11e5-a1df-e8113224d9f6

Error: (08/30/2015 10:28:44 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Explorer.EXE6.1.7601.1756758001d0e2fd1c383c2f59C:\windows\Explorer.EXE16670e5f-4ef1-11e5-a1df-e8113224d9f6

Error: (08/30/2015 10:15:10 AM) (Source: ESENT) (EventID: 482) (User: )
Description: Windows4720Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb4620288 (0x0000000000468000)32768 (0x00008000)-1808 (0xfffff8f0)112 (0x00000070)Na disku není dost místa. 0

Error: (08/30/2015 10:14:21 AM) (Source: ESENT) (EventID: 428) (User: )
Description: Windows1208Windows:

Error: (08/30/2015 10:14:14 AM) (Source: ESENT) (EventID: 428) (User: )
Description: Windows4392Windows:

Error: (08/30/2015 10:13:29 AM) (Source: ESENT) (EventID: 428) (User: )
Description: Windows4376Windows:


==================== Memory info =========================== 

Processor: Intel(R) Pentium(R) CPU P6100 @ 2.00GHz
Percentage of memory in use: 75%
Total physical RAM: 2932.55 MB
Available physical RAM: 709.89 MB
Total Virtual: 5863.31 MB
Available Virtual: 2718.82 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:40 GB) (Free:0.05 GB) NTFS
Drive d: (TEMP_PART01) (Fixed) (Total:237.99 GB) (Free:150.53 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 298.1 GB) (Disk ID: E641D4EA)
Partition 1: (Not Active) - (Size=20 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=40 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=238 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================