﻿Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10.02.2018 01
Ran by th0ca (10-02-2018 14:37:30)
Running from C:\Users\th0ca\Desktop
Windows 10 Pro Version 1709 16299.192 (X64) (2017-12-13 18:32:27)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1437791008-316131555-1331501217-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1437791008-316131555-1331501217-503 - Limited - Disabled)
Guest (S-1-5-21-1437791008-316131555-1331501217-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1437791008-316131555-1331501217-1004 - Limited - Enabled)
th0ca (S-1-5-21-1437791008-316131555-1331501217-1000 - Administrator - Enabled) => C:\Users\th0ca
WDAGUtilityAccount (S-1-5-21-1437791008-316131555-1331501217-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

AC3Filter 2.5b (HKLM-x32\...\AC3Filter_is1) (Version: 2.5b - Alexander Vigovsky)
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 18.009.20050 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.3.9120 - Adobe Systems Inc.)
Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.0.0.400 - Adobe Systems Incorporated)
Adobe Flash Player 28 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 28.0.0.161 - Adobe Systems Incorporated)
Adobe Media Player (HKLM-x32\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.8 - Adobe Systems Incorporated)
Adobe Photoshop CS5 (HKLM-x32\...\{15FEDA5F-141C-4127-8D7E-B962D1742728}) (Version: 12.0 - Adobe Systems Incorporated)
Adobe Photoshop Lightroom 5.3 64-bit (HKLM\...\{2DD71ACB-552D-402C-9529-7906ACB95C30}) (Version: 5.3.1 - Adobe Systems Incorporated)
Aktualizace NVIDIA 2.11.3.5 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 2.11.3.5 - NVIDIA Corporation) Hidden
AMD Catalyst Install Manager (HKLM\...\{120EC191-78F8-CA89-3511-7E90C23F5261}) (Version: 8.0.881.0 - Advanced Micro Devices, Inc.)
Ansel (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel) (Version: 382.05 - NVIDIA Corporation) Hidden
Armored Warfare MyCom (HKU\S-1-5-21-1437791008-316131555-1331501217-1000\...\Armored Warfare MyCom) (Version: 1.117 - My.com B.V.)
Armored Warfare MyCom Beta (HKU\S-1-5-21-1437791008-316131555-1331501217-1000\...\Armored Warfare MyCom Beta) (Version: 1.59 - My.com B.V.)
ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.10 - Michael Tippach)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Bethesda.net Launcher (HKLM-x32\...\{3448917E-E4FE-4E30-9502-9FD52EABB6F5}_is1) (Version: 1.18.5 - Bethesda Softworks)
CDex - Digital Audio CD Extractor and Converter (HKLM-x32\...\CDex) (Version: 1.85.0.2017 - CDex.mu)
CEWE fotosvet (HKLM-x32\...\CEWE fotosvet) (Version: 6.0.5 - CEWE Stiftung u Co. KGaA)
Crysis®3 (HKLM-x32\...\{4198AE83-A3C6-4C41-85C8-EC63E990696E}) (Version: 1.0.0.0 - Electronic Arts)
Dark Souls Prepare to Die Edition (HKLM-x32\...\{4E4D0FA1-6B85-4824-88FC-051000028201}) (Version: 1.0.0002.130 - NAMCO BANDAI Games Europe S.A.S.) Hidden
Defrag launcher (HKLM-x32\...\Defrag launcher) (Version:  - )
Diablo III (HKLM-x32\...\Diablo III) (Version:  - Blizzard Entertainment)
Discord (HKU\S-1-5-21-1437791008-316131555-1331501217-1000\...\Discord) (Version: 0.0.300 - Discord Inc.)
Drumaxx (HKLM-x32\...\Drumaxx) (Version:  - Image-Line)
DVD Shrink 3.2 (HKLM-x32\...\DVD Shrink_is1) (Version:  - DVD Shrink)
Dying Light Update v1.2.1 (HKLM-x32\...\RHlpbmdMaWdodA==_is1) (Version: 1 - )
Etron USB3.0 Host Controller (HKLM-x32\...\{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}) (Version: 0.115 - Etron Technology) Hidden
Etron USB3.0 Host Controller (HKLM-x32\...\InstallShield_{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}) (Version: 0.115 - Etron Technology)
Exodus (HKU\S-1-5-21-1437791008-316131555-1331501217-1000\...\exodus) (Version: 1.43.4 - Exodus Movement Inc)
Far Cry 4 (HKLM-x32\...\Far Cry 4_is1) (Version: 1.4.0 - Ubisoft)
FL Studio 9.8 (HKLM-x32\...\FL Studio 9.8) (Version:  - Image-Line)
Fraps (remove only) (HKLM-x32\...\Fraps) (Version:  - )
Futuremark SystemInfo (HKLM-x32\...\{BEE64C14-BEF1-4610-8A68-A16EAA47B882}) (Version: 4.17.0 - Futuremark Corporation)
GtkRadiant-1.4.0  (HKLM-x32\...\{6C1196CF-B4AD-4847-B70C-F034A781445E}) (Version:  - )
Hardcore (HKLM-x32\...\Hardcore) (Version:  - Image-Line)
Huffyuv AVI lossless video codec (Remove Only) (HKLM\...\HUFFYUV) (Version:  - )
IL Download Manager (HKLM-x32\...\IL Download Manager) (Version:  - Image-Line)
LibreOffice 5.3.7.2 (HKLM\...\{117F3217-458C-4371-B222-00C69DE96CB2}) (Version: 5.3.7.2 - The Document Foundation)
LightScribe System Software (HKLM-x32\...\{E0E55FC1-C53D-4F8D-B14B-B59C312747C8}) (Version: 1.18.22.2 - LightScribe)
Medal of Honor (TM) (HKLM-x32\...\{415030B8-3E8B-462A-8C03-41D95AA3AB3B}) (Version: 1.0.0.0 - Electronic Arts)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{42AA4CA8-DCD8-4308-BCAB-0B6D75856A9D}) (Version: 3.5.95.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1437791008-316131555-1331501217-1000\...\OneDriveSetup.exe) (Version: 17.3.7294.0108 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61187 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61186 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.7523 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.7523 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.7523 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.7523 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 (HKLM\...\{929FBD26-9020-399B-9A7A-751D61F0B942}) (Version: 12.0.21005 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 (HKLM\...\{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}) (Version: 12.0.21005 - Microsoft Corporation)
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (HKLM-x32\...\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}) (Version: 12.0.21005 - Microsoft Corporation)
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (HKLM-x32\...\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}) (Version: 12.0.21005 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.10.25017 (HKLM-x32\...\{58b3beca-b999-4f6f-a48c-81681136a620}) (Version: 14.10.25017.0 - Microsoft Corporation)
Microsoft Visual F# 2.0 Runtime (HKLM-x32\...\{85467CBC-7A39-33C9-8940-D72D9269B84F}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{D9C50188-12D5-4D3E-8F00-682346C2AA5F}) (Version: 1.20.146.0 - Microsoft)
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
mIRC (HKLM-x32\...\mIRC) (Version: 7.36 - mIRC Co. Ltd.)
MKVToolNix 17.0.0 (32-bit) (HKLM-x32\...\MKVToolNix) (Version: 17.0.0 - Moritz Bunkus)
Mozilla Firefox 58.0.1 (x64 cs) (HKLM\...\Mozilla Firefox 58.0.1 (x64 cs)) (Version: 58.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 58.0.1.6602 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
My.com Game Center (HKU\S-1-5-21-1437791008-316131555-1331501217-1000\...\MyComGames) (Version: 3.184 - My.com B.V.)
Nero 12 (HKLM-x32\...\{560FC78C-A4B2-461D-9B47-820C1EEF87B8}) (Version: 12.0.02000 - Nero AG)
NVIDIA Ovladač řídící jednotky 3D Vision 364.44 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 364.44 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Origin (HKLM-x32\...\Origin) (Version: 9.3.2.2730 - Electronic Arts, Inc.)
Ovládací panel NVIDIA 388.13 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 388.13 - NVIDIA Corporation) Hidden
PDF Settings CS5 (HKLM-x32\...\{A78FE97A-C0C8-49CE-89D0-EDD524A17392}) (Version: 10.0 - Adobe Systems Incorporated) Hidden
Platform (HKLM-x32\...\{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.) Hidden
PoiZone (HKLM-x32\...\PoiZone) (Version:  - Image-Line)
Prerequisite installer (HKLM-x32\...\{3AAB08A3-F129-4BD5-B409-AE674F93759D}) (Version: 12.0.0002 - Nero AG) Hidden
Quake Champions (HKLM-x32\...\Quake Champions) (Version:  - Bethesda Softworks)
Rapture3D 2.4.8 Game (HKLM-x32\...\{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1) (Version:  - Blue Ripple Sound)
Razer Diamondback (HKLM-x32\...\{DE4CF159-4AD2-4754-BDA0-5FB088C8B58B}) (Version: 5.01 - Razer USA Ltd.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.49.927.2011 - Realtek)
Sakura (HKLM-x32\...\Sakura) (Version:  - Image-Line)
Sawer (HKLM-x32\...\Sawer) (Version:  - Image-Line)
SHIELD Streaming (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv) (Version: 7.1.0280 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController) (Version: 2.11.3.5 - NVIDIA Corporation) Hidden
StarCraft (HKLM-x32\...\StarCraft) (Version:  - Blizzard Entertainment)
StarCraft II (HKLM-x32\...\StarCraft II) (Version:  - Blizzard Entertainment)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Sudden Strike 4 (HKLM-x32\...\2146639313_is1) (Version: 1.00.19037 - GOG.com)
Synthesia (HKLM-x32\...\Synthesia) (Version: 9 - Synthesia LLC)
Telegram Desktop version 1.2.6 (HKU\S-1-5-21-1437791008-316131555-1331501217-1000\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 1.2.6 - Telegram Messenger LLP)
Titanfall™ (HKLM-x32\...\{347EE0C3-0690-48F6-A231-53853C2A80D6}) (Version: 1.0.10.1 - Electronic Arts)
TL-WN851ND Driver (HKLM-x32\...\{4BAE4C76-44C3-418F-B715-6BBF5A65323E}) (Version: 1.00.0000 - TP-LINK)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.01 - Ghisler Software GmbH)
Toxic Biohazard (HKLM-x32\...\Toxic Biohazard) (Version:  - Image-Line)
UE4 Prerequisites (x64) (HKLM\...\{36EAD5CF-44EF-4FCF-8BE1-D96C4835D7A4}) (Version: 1.0.11.0 - Epic Games, Inc.) Hidden
UE4 Prerequisites (x64) (HKLM-x32\...\{2890ae6b-90e9-448d-b3e6-97e43c21e2fd}) (Version: 1.0.13.0 - Epic Games, Inc.) Hidden
Uplay (HKLM-x32\...\Uplay) (Version: 3.0 - Ubisoft)
Vegas Pro 13.0 (64-bit) (HKLM\...\{3814DB30-091D-11E4-BDE0-F04DA23A5C58}) (Version: 13.0.373 - Sony)
VIA Platforma Ovladače zařízení (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.)
Virtual Audio Cable 4.10 (HKLM\...\Virtual Audio Cable 4.10) (Version:  - )
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN)
Vulkan Run Time Libraries 1.0.11.1 (HKLM\...\VulkanRT1.0.11.1) (Version: 1.0.11.1 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.42.1 (HKLM\...\VulkanRT1.0.42.1) (Version: 1.0.42.1 - LunarG, Inc.)
War Thunder Launcher 1.0.1.629 (HKLM-x32\...\{ed8deea4-29fa-3932-9612-e2122d8a62d9}}_is1) (Version:  - Gaijin Entertainment)
Welcome App (Start-up experience) (HKLM-x32\...\{828175FA-7307-4DBF-95AD-9CEE086B6F45}) (Version: 12.0.14000 - Nero AG) Hidden
Winamp (HKLM-x32\...\Winamp) (Version: 5.63  - Nullsoft, Inc)
Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation)
WinRAR 4.20 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ContextMenuHandlers1: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\ShellExt.dll [2017-09-29] (Microsoft Corporation)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2012-06-09] (Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2012-06-09] (Alexander Roshal)
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\ShellExt.dll [2017-09-29] (Microsoft Corporation)
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\ShellExt.dll [2017-09-29] (Microsoft Corporation)
ContextMenuHandlers5: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} =>  -> No File
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2017-10-27] (NVIDIA Corporation)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2012-06-09] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2012-06-09] (Alexander Roshal)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0387B212-4CC1-45A8-A667-787EF1275352} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {06003D1F-6745-42FC-BF60-EF83F41D6841} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {080A60F8-0F5F-41A5-ADEC-527FE3B71553} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {0B1D0502-4B67-4CCA-A828-392D506EA8DA} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {1D3F44C7-2C9C-4B41-B3D5-2456B8737F5C} - System32\Tasks\S-1-5-21-1437791008-316131555-1331501217-1000\DataSenseLiveTileTask => C:\WINDOWS\System32\DataUsageLiveTileTask.exe [2017-09-29] (Microsoft Corporation)
Task: {1E3BE772-4F42-410D-AFAE-84C041D1D9BE} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
Task: {21D6D854-D78D-46C8-BCD5-691F1CC56151} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {2B09EABF-4D74-48F7-A12B-E96618CF259E} - \CCleanerSkipUAC -> No File <==== ATTENTION
Task: {2C3A7804-5E96-449E-B825-58C51AD27A86} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {2C4585B7-9C76-490E-AA95-F9D3BB0D7B37} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {2CB6F834-39C9-42C0-95EA-A32AB765CDB7} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {3BE86D14-21E4-4275-89F4-8F0B5E2AA66A} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {3ED2D689-9E97-49A4-85EA-242F0F18E24F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\MpCmdRun.exe [2018-01-21] (Microsoft Corporation)
Task: {4A4E16FD-4194-41A3-BE34-1EF102C03C28} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {5FAE4AFA-FDA4-4794-B492-75B90288FFD3} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {61C39318-73E6-43E0-B855-A63B49152926} - System32\Tasks\{35EAA191-F437-4779-88C5-B5EF2FA10CEC} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Origin Games\Battlefield 4 Beta\__Installer\vc\vc2010sp1\redist\vcredist_x64.exe" -d "C:\Program Files (x86)\Origin Games\Battlefield 4 Beta\__Installer\vc\vc2010sp1\redist"
Task: {67362EC3-1549-4F49-A4E0-B112E53256FD} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {7571BDAB-CC56-4007-901E-CE6F90860DD5} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\MpCmdRun.exe [2018-01-21] (Microsoft Corporation)
Task: {75C0F726-E6D2-483E-8C80-EFF97DF35AAD} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {772938CA-A85D-49E1-AEE2-46DF6F3D0898} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {774CB3DF-6E04-4C6A-B5A6-F0A4B70FC0E4} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\WINDOWS\ehome\ehrec.exe
Task: {88933DA8-57AB-467B-9F0A-0C2A9CEB639E} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {88ED17BC-BB4B-4676-AEB8-A64075DB9539} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2018-01-09] (Microsoft Corporation)
Task: {8B27983A-DDBF-403B-A8AF-1D5497D1B159} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {9396FE3D-AB22-4488-A09D-D83DBA7D8FDB} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {9BC6B57F-BC29-4842-89C9-9723B84CA2EC} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {A4C9C5AD-1313-4269-B658-CDD440AD6D51} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe
Task: {A81937DE-0326-4AC3-9B3B-34690BD75075} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-02-06] (Adobe Systems Incorporated)
Task: {AD1CE6DE-6A1A-43F4-B665-A76A578C51F1} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {BB52E404-0AEA-42CB-B254-85CF4D6CBAC4} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {C465FDD1-C77C-40D3-A4CC-39F5FAF0FAC2} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {C9131EC7-F841-451D-B9C2-0B78DCB5AFD8} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {C92B4F44-0781-49EA-B838-8CB563B02B3B} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {CCAE7929-4208-43F9-87DE-CD959288FE13} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe
Task: {CF856B3C-F7C2-4DF0-9CAF-3C5E647B9636} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {D11387E9-9069-4F92-8362-0854D1F63FFD} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-09-27] (Adobe Systems Incorporated)
Task: {D1D85FCA-CF36-4639-94D8-6C50B305E468} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe
Task: {D527EF78-3E4C-4649-B46E-9296707A9261} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {D61D798D-F071-43A5-96D2-CCFFAB3A7F86} - System32\Tasks\Microsoft\Windows\PLA\System\{D9F69FFD-87AE-4C2C-8F9C-5DA3697F2A84}_System Diagnostics => Command(1): C:\Windows\system32\rundll32.exe -> C:\Windows\system32\pla.dll,PlaHost "system\System Diagnostics" "$(Arg0)"
Task: {D61D798D-F071-43A5-96D2-CCFFAB3A7F86} - System32\Tasks\Microsoft\Windows\PLA\System\{D9F69FFD-87AE-4C2C-8F9C-5DA3697F2A84}_System Diagnostics => Command(2): C:\Windows\system32\schtasks.exe -> /delete /f /tn "\Microsoft\Windows\PLA\System\{D9F69FFD-87AE-4C2C-8F9C-5DA3697F2A84}_System Diagnostics"
Task: {D8166C1B-7C89-415A-9292-90DD7F740D5C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\MpCmdRun.exe [2018-01-21] (Microsoft Corporation)
Task: {E18C6E00-1074-40AB-B08B-E83C58739FCB} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {EEE75B5C-C6C4-4935-9199-068DCE9D5C90} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\MpCmdRun.exe [2018-01-21] (Microsoft Corporation)
Task: {F3073D42-474F-43B9-99B0-D516F6A0577D} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {F3136896-B824-4088-ACDC-17030DAA83FF} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {F65BFD9C-E729-45F4-801D-AC7D61B03E52} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {FDA6E667-A2F4-4877-9CCF-4ADA41C72141} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


Shortcut: C:\Users\th0ca\Desktop\DeFRaG.lnk -> C:\Thoca\Quake III Arena\defrag.bat ()
Shortcut: C:\Users\th0ca\Desktop\Radiant DeFRaG.lnk -> C:\Thoca\q3 radiant\defrag.bat ()
Shortcut: C:\Users\th0ca\Desktop\Start Quake 3 Moviemaker's Edition.lnk -> D:\game_videa\tvorba videii\q3 mme\Start Quake 3 Moviemaker's Edition.bat ()
Shortcut: C:\Users\th0ca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line\FL Studio 9.8\Additional\SynthMaker website.lnk -> hxxp://www.synthmaker.co.uk

==================== Loaded Modules (Whitelisted) ==============

2017-09-29 14:41 - 2017-09-29 14:41 - 000184432 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
2012-08-06 11:24 - 2012-08-06 11:24 - 000212480 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.PerformanceTuning.dll
2012-02-16 13:53 - 2012-02-16 13:53 - 003642880 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Platform.dll
2012-03-05 15:03 - 2012-03-05 15:03 - 000677376 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll
2012-08-06 11:24 - 2012-08-06 11:24 - 000073728 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
2013-11-11 18:42 - 2015-04-23 18:21 - 000076152 _____ () C:\Windows\system32\PnkBstrA.exe
2017-12-11 21:01 - 2017-12-11 21:01 - 011044864 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-12-11 21:01 - 2017-12-11 21:01 - 001804288 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2013-09-03 19:57 - 2009-10-09 19:11 - 000226816 _____ () C:\Program Files (x86)\Razer\Diamondback\Razer\Diamondback\razerhid.exe
2013-09-03 19:57 - 2007-02-07 15:00 - 000131072 _____ () C:\Program Files (x86)\Razer\Diamondback\Razer\Diamondback\razertra.exe
2017-12-15 21:50 - 2017-12-15 21:50 - 004307968 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1712.3351.0_x64__8wekyb3d8bbwe\Calculator.exe
2018-02-02 17:36 - 2018-02-02 17:36 - 002250240 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11801.1001.6.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2017-12-13 20:09 - 2017-12-13 20:12 - 000477184 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
2017-12-13 20:09 - 2017-12-13 20:12 - 058590720 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
2017-10-05 18:31 - 2017-10-05 18:32 - 002523136 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\UnityEngineDelegates.dll
2017-11-11 13:33 - 2017-11-11 13:34 - 000164864 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\VideoPlugin.dll
2017-10-05 18:31 - 2017-10-05 18:32 - 000675328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\IPPNativePlugin.dll
2017-12-13 20:09 - 2017-12-13 20:11 - 003727360 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\MediaEngineCSWrapper.dll
2017-12-13 20:09 - 2017-12-13 20:13 - 002270720 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\TrackingDLLUWP.dll
2017-12-13 20:09 - 2017-12-13 20:13 - 016395264 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\PhotosApp.Windows.dll
2017-12-13 20:09 - 2017-12-13 20:11 - 003579904 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\MediaEngine.dll
2017-12-13 20:09 - 2017-12-13 20:09 - 003204096 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\AppCore.Windows.dll
2017-08-29 19:24 - 2017-08-29 19:24 - 003553704 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2017-12-13 20:09 - 2017-12-13 20:12 - 000043520 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\Microsoft.Photos.Edit.Services.dll
2017-12-13 20:09 - 2017-12-13 20:12 - 004038144 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\Microsoft.People.PeoplePicker.dll
2017-12-13 20:09 - 2017-12-13 20:12 - 001367040 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\Microsoft.RichMedia.Ink.Controls.dll
2017-12-13 20:09 - 2017-12-13 20:13 - 000214528 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.39101.16720.0_x64__8wekyb3d8bbwe\SKU.dll
2015-08-05 23:54 - 2016-05-02 07:02 - 000020536 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2018-01-30 20:45 - 2018-01-08 17:52 - 001891832 _____ () C:\Users\th0ca\AppData\Local\Discord\app-0.0.300\ffmpeg.dll
2018-01-30 20:45 - 2018-02-10 13:19 - 001780216 _____ () \\?\C:\Users\th0ca\AppData\Roaming\discord\0.0.300\modules\discord_overlay2\discord_overlay2.node
2018-01-30 20:45 - 2018-01-08 17:52 - 001937912 _____ () C:\Users\th0ca\AppData\Local\Discord\app-0.0.300\libglesv2.dll
2018-01-30 20:45 - 2018-01-08 17:52 - 000095736 _____ () C:\Users\th0ca\AppData\Local\Discord\app-0.0.300\libegl.dll
2018-01-30 20:45 - 2018-01-30 20:45 - 009817080 _____ () \\?\C:\Users\th0ca\AppData\Roaming\discord\0.0.300\modules\discord_voice\discord_voice.node
2018-01-30 20:45 - 2018-02-01 17:11 - 001508344 _____ () \\?\C:\Users\th0ca\AppData\Roaming\discord\0.0.300\modules\discord_utils\discord_utils.node
2018-01-30 20:45 - 2018-01-30 20:45 - 000513016 _____ () \\?\C:\Users\th0ca\AppData\Roaming\discord\0.0.300\modules\discord_erlpack\discord_erlpack.node
2018-01-30 20:45 - 2018-01-30 20:45 - 002662904 _____ () \\?\C:\Users\th0ca\AppData\Roaming\discord\0.0.300\modules\discord_rpc\discord_rpc.node
2018-01-30 20:45 - 2018-02-01 17:11 - 001518072 _____ () \\?\C:\Users\th0ca\AppData\Roaming\discord\0.0.300\modules\discord_game_utils\discord_game_utils.node
2018-01-30 20:46 - 2018-01-30 20:46 - 002749944 _____ () \\?\C:\Users\th0ca\AppData\Roaming\discord\0.0.300\modules\discord_contact_import\discord_contact_import.node

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2009-06-10 22:00 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1437791008-316131555-1331501217-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\th0ca\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 192.168.1.20
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run32: => "AdobeCS5ServiceManager"
HKLM\...\StartupApproved\Run32: => "SwitchBoard"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{FACFE286-BAE6-47A9-A647-9102169F6E1F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\BioShock 2 Remastered\Build\Final\Bioshock2HD.exe
FirewallRules: [{815F5DFA-5EB5-41E6-A69E-511E71D56DF1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\BioShock 2 Remastered\Build\Final\Bioshock2HD.exe
FirewallRules: [{CF374CB8-E8C8-45E2-A008-8FEC3F89C188}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\BioShock Remastered\Build\Final\BioshockHD.exe
FirewallRules: [{E64C1756-574A-4656-B6BF-A0CD827A3F18}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\BioShock Remastered\Build\Final\BioshockHD.exe
FirewallRules: [{22E17142-B8BE-458C-8ECD-15DB61DEC443}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dead Space 2\deadspace2.exe
FirewallRules: [{7E79ED53-A163-4F34-9AB3-4000CB0A9CC7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dead Space 2\deadspace2.exe
FirewallRules: [{4CFA244B-16A2-4E6D-BABC-C9A5BFA15C84}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\BioShock Infinite\Binaries\Win32\BioShockInfinite.exe
FirewallRules: [{3EBFDD17-5B8E-4CF8-AA0F-667518DF73B4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\BioShock Infinite\Binaries\Win32\BioShockInfinite.exe
FirewallRules: [{0058204E-F1F3-4EE8-9932-86BD3AAC897E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dead Space\Dead Space.exe
FirewallRules: [{331B5F95-4E8D-4E55-9CC8-848CEE79222B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dead Space\Dead Space.exe
FirewallRules: [{C182B577-98C8-4883-8F5C-0A74844955A6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DARK SOULS III\Game\DarkSoulsIII.exe
FirewallRules: [{4075B7BF-F377-42F1-BEF2-9A7EBE7C87DC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DARK SOULS III\Game\DarkSoulsIII.exe
FirewallRules: [UDP Query User{570D877D-0FDE-48B6-A89A-B23DDC775FE1}C:\gog games\inner chains\innerchains\binaries\win64\innerchains-win64-shipping.exe] => (Block) C:\gog games\inner chains\innerchains\binaries\win64\innerchains-win64-shipping.exe
FirewallRules: [TCP Query User{9EB85243-93F1-4C51-BF1B-B306B87DC570}C:\gog games\inner chains\innerchains\binaries\win64\innerchains-win64-shipping.exe] => (Block) C:\gog games\inner chains\innerchains\binaries\win64\innerchains-win64-shipping.exe
FirewallRules: [{5925144D-9D16-49AD-A5D6-A4A19AC5FE63}] => (Allow) C:\Users\th0ca\AppData\Roaming\uTorrent\utorrent.exe
FirewallRules: [{BE111D58-98E7-4876-BF6C-237B6B8B14E7}] => (Allow) C:\Users\th0ca\AppData\Roaming\uTorrent\utorrent.exe
FirewallRules: [UDP Query User{C6B1648C-58C5-4F6D-BC59-595E4902367A}C:\thoca\quake_epsilon\darkplaces.exe] => (Allow) C:\thoca\quake_epsilon\darkplaces.exe
FirewallRules: [TCP Query User{8B959548-7731-4885-870E-C2009CAD6553}C:\thoca\quake_epsilon\darkplaces.exe] => (Allow) C:\thoca\quake_epsilon\darkplaces.exe
FirewallRules: [{E469010B-99D2-4CD5-B627-E82D05264271}] => (Allow) %systemroot%\system32\alg.exe
FirewallRules: [UDP Query User{9E32AC3C-C1D3-4679-88BB-9462ED3E7340}C:\thoca\quake_epsilon\darkplaces.exe] => (Allow) C:\thoca\quake_epsilon\darkplaces.exe
FirewallRules: [TCP Query User{81FC350E-831D-467F-AF0B-A0A9E50E053F}C:\thoca\quake_epsilon\darkplaces.exe] => (Allow) C:\thoca\quake_epsilon\darkplaces.exe
FirewallRules: [UDP Query User{F92DDF58-8A4A-4B82-97A4-2B5FB801A18A}C:\thoca\quake\darkplaces.exe] => (Allow) C:\thoca\quake\darkplaces.exe
FirewallRules: [TCP Query User{74421E78-26C5-4E22-9D64-A9C2E20F3275}C:\thoca\quake\darkplaces.exe] => (Allow) C:\thoca\quake\darkplaces.exe
FirewallRules: [{1461E7E8-84E0-4443-9DD1-D0650183079E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Quake 2\quake2.exe
FirewallRules: [{72D0D437-6723-4DCE-8932-CA00904393FC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Quake 2\quake2.exe
FirewallRules: [{1AC89147-6FCA-4B6E-9496-6C221A450717}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Quake\glqwcl.exe
FirewallRules: [{FC9E87AD-31EE-4FA6-A31E-7FB1CC25D71B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Quake\glqwcl.exe
FirewallRules: [{298F81B8-25B8-401B-ABD7-200AC18FE4A1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Quake\Glquake.exe
FirewallRules: [{AB61A151-AD54-4E4A-AF43-1A68D663F09D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Quake\Glquake.exe
FirewallRules: [{460B5DFF-72EA-4C8D-955B-7B59308F4158}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Quake\qwcl.exe
FirewallRules: [{6E61ED47-3F58-4F1A-869C-3123FBB54BF5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Quake\qwcl.exe
FirewallRules: [{28443D15-9980-4947-B74E-41BD5E463C61}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Quake\Winquake.exe
FirewallRules: [{F283D3EE-4DD5-4543-A8DB-8FAFC477E7E6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Quake\Winquake.exe
FirewallRules: [UDP Query User{6133751E-D752-4883-8CB9-1CF2B2BCE2B3}C:\program files (x86)\bethesda.net launcher\games\quakechampions\client\bin\pc\quakechampions.exe] => (Allow) C:\program files (x86)\bethesda.net launcher\games\quakechampions\client\bin\pc\quakechampions.exe
FirewallRules: [TCP Query User{CC939704-544A-4383-8355-67A2C2FD7E2E}C:\program files (x86)\bethesda.net launcher\games\quakechampions\client\bin\pc\quakechampions.exe] => (Allow) C:\program files (x86)\bethesda.net launcher\games\quakechampions\client\bin\pc\quakechampions.exe
FirewallRules: [{8ECE3863-DD0E-4901-B1DC-57B59315A8B0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dark Souls II Scholar of the First Sin\Game\DarkSoulsII.exe
FirewallRules: [{0E49EA65-09B5-45C6-8862-CDFAB5112E49}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dark Souls II Scholar of the First Sin\Game\DarkSoulsII.exe
FirewallRules: [UDP Query User{30D11BDB-696B-4BD3-A032-0E42F56DDACB}C:\users\th0ca\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\th0ca\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [TCP Query User{CB8AA80A-A011-4ABB-8B4E-85A9AD78D92A}C:\users\th0ca\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\th0ca\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [UDP Query User{B57F632D-4DFC-4BE8-A7E4-FFCB8C10077F}C:\program files (x86)\libreoffice 4\program\soffice.bin] => (Allow) C:\program files (x86)\libreoffice 4\program\soffice.bin
FirewallRules: [TCP Query User{9F7181D3-F58D-4421-BB68-2CAD2D73D75E}C:\program files (x86)\libreoffice 4\program\soffice.bin] => (Allow) C:\program files (x86)\libreoffice 4\program\soffice.bin
FirewallRules: [UDP Query User{74A67AB3-C36A-47E9-B37F-F9E50812F00F}C:\users\th0ca\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\th0ca\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [TCP Query User{FA46C5CF-11EA-4697-BBC4-C587F27FCAFC}C:\users\th0ca\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\th0ca\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [UDP Query User{6802C125-0974-4DF5-B564-22D81735AA78}C:\users\th0ca\appdata\local\mycomgames\mycomgames.exe] => (Allow) C:\users\th0ca\appdata\local\mycomgames\mycomgames.exe
FirewallRules: [TCP Query User{7E7291B7-8D50-4595-8B11-2C13A646710E}C:\users\th0ca\appdata\local\mycomgames\mycomgames.exe] => (Allow) C:\users\th0ca\appdata\local\mycomgames\mycomgames.exe
FirewallRules: [UDP Query User{65863242-E92C-4C8C-891D-E987ABD9B0D4}C:\warthunder\win64\aces.exe] => (Allow) C:\warthunder\win64\aces.exe
FirewallRules: [TCP Query User{AE461B2E-5969-4EE7-883C-501C63115970}C:\warthunder\win64\aces.exe] => (Allow) C:\warthunder\win64\aces.exe
FirewallRules: [{DB8ED608-1D9C-42E9-8B75-3D6A643C7281}] => (Allow) LPort=8090
FirewallRules: [{0908EFE7-460F-469A-861A-AB6C369EED17}] => (Allow) LPort=20443
FirewallRules: [{5297C9B7-2AA9-4E1C-AE01-2F203075851F}] => (Allow) LPort=33333
FirewallRules: [{16274A76-A8AF-4D90-B193-9002B096832A}] => (Allow) LPort=6881
FirewallRules: [{9E4E47C9-A47B-481A-976B-7BCE844CF0C2}] => (Allow) LPort=27022
FirewallRules: [{1079C39F-559C-42B4-B31E-00F6523465CD}] => (Allow) LPort=7853
FirewallRules: [{2CD3208B-35AF-442E-BBF5-425030B130FF}] => (Allow) LPort=7852
FirewallRules: [{7A396464-C06D-4717-B8ED-81699C176581}] => (Allow) LPort=7850
FirewallRules: [{E0656C2E-A51D-4C9E-BA24-90DE0B5FAC19}] => (Allow) LPort=3478
FirewallRules: [{791164A5-5A03-4E80-917A-C695CD9DAE00}] => (Allow) LPort=20010
FirewallRules: [{3D07CD63-1AB8-4382-BBAE-BE1C54773434}] => (Allow) LPort=443
FirewallRules: [{CCB0D203-3755-499D-92B7-DEA0CF875F51}] => (Allow) LPort=80
FirewallRules: [{D4D66A02-0C57-4A84-A9B9-42ADC897D95B}] => (Allow) C:\WarThunder\bpreport.exe
FirewallRules: [{8A85DDA6-EC3C-40E3-9507-2175323025E0}] => (Allow) C:\WarThunder\bpreport.exe
FirewallRules: [{8A27771F-3B12-40E4-AC3E-CD39FB8D70C0}] => (Allow) C:\WarThunder\launcher.exe
FirewallRules: [{C0548B90-D004-42E1-B52B-F032FCF2D547}] => (Allow) C:\WarThunder\launcher.exe
FirewallRules: [{78BC4B84-E19C-4515-B082-C50BAA9DE8E5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\ShadowOfMordor\x64\ShadowOfMordor.exe
FirewallRules: [{DC15D4CC-FFE0-4067-9131-464E7D8ABD42}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\ShadowOfMordor\x64\ShadowOfMordor.exe
FirewallRules: [{042CEF26-0731-458A-B3EB-D32457F17166}] => (Allow) C:\Program Files (x86)\Origin Games\Titanfall\Titanfall.exe
FirewallRules: [{89D8AF93-FE7A-4BC9-8509-04E4490D42EF}] => (Allow) C:\Program Files (x86)\Origin Games\Titanfall\Titanfall.exe
FirewallRules: [{3F647F83-F7AC-4621-A06C-872FAC45FEA2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dark Souls II\Game\DarkSoulsII.exe
FirewallRules: [{5BC86065-830C-4ACC-B2D4-98C09037BD5F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dark Souls II\Game\DarkSoulsII.exe
FirewallRules: [UDP Query User{8A1F7ED0-6C0D-4BEB-927F-0336094536F1}C:\program files (x86)\lichdom battlemage\bin64\lichdombattlemage.exe] => (Block) C:\program files (x86)\lichdom battlemage\bin64\lichdombattlemage.exe
FirewallRules: [TCP Query User{2C85FF67-6636-4444-A828-578B0EF64418}C:\program files (x86)\lichdom battlemage\bin64\lichdombattlemage.exe] => (Block) C:\program files (x86)\lichdom battlemage\bin64\lichdombattlemage.exe
FirewallRules: [UDP Query User{6BDAD7E0-4F56-42F7-A49C-8AE4EF004813}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{8E2D0016-4FB5-4C7F-80C7-422A07702C3B}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{40E3419A-2E5B-4D10-A0BE-940ACC71EECF}C:\program files (x86)\starcraft ii\versions\base32283\sc2.exe] => (Allow) C:\program files (x86)\starcraft ii\versions\base32283\sc2.exe
FirewallRules: [TCP Query User{FE59F5AE-0E3E-4FB3-B9F0-3D34A5912FF5}C:\program files (x86)\starcraft ii\versions\base32283\sc2.exe] => (Allow) C:\program files (x86)\starcraft ii\versions\base32283\sc2.exe
FirewallRules: [{7F4045CC-338A-4A7B-9E7B-61C690F22227}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II Public Test.exe
FirewallRules: [{FAA2EDFA-503A-4957-9A7A-40EB7DC41D31}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II Public Test.exe
FirewallRules: [{DE083EAD-5C35-44D0-9064-13BA38CE2D88}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II.exe
FirewallRules: [{B895434F-5F6C-44A0-9756-26789ADB371D}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II.exe
FirewallRules: [{47BEC41F-B106-465B-8031-448D4D6EC799}] => (Allow) C:\Program Files (x86)\Grey Goo\InstanceServerG.cdx
FirewallRules: [{2817809D-D3E7-470E-B7B6-91EFC58A6EE1}] => (Allow) C:\Program Files (x86)\Grey Goo\InstanceServerG.cdx
FirewallRules: [{DE429BD4-EBAD-4006-A6FE-6F60A36D0FEF}] => (Allow) C:\Program Files (x86)\Grey Goo\GooG.cdx
FirewallRules: [{C1586B2A-E929-475D-9D03-54B5990F7C36}] => (Allow) C:\Program Files (x86)\Grey Goo\GooG.cdx
FirewallRules: [{4379E67A-1224-486C-BA56-152CD0FC9192}] => (Allow) C:\Program Files (x86)\Grey Goo\ClientLauncherG.cdx
FirewallRules: [{15C9F2CB-7C17-4A0A-A910-7E52617FDA6B}] => (Allow) C:\Program Files (x86)\Grey Goo\ClientLauncherG.cdx
FirewallRules: [{06A3F9B8-F6AC-42E8-B659-8D320FB6001B}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3715\Agent.exe
FirewallRules: [{D819B450-3976-41BF-94F1-7B2FDA2AA58D}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3715\Agent.exe
FirewallRules: [UDP Query User{B69C78CB-C463-4814-A5D1-EACBEB5CB291}C:\hry\wolfenstein - the new order\wolfneworder_x64.exe] => (Block) C:\hry\wolfenstein - the new order\wolfneworder_x64.exe
FirewallRules: [TCP Query User{034E016F-CB9D-4763-981D-4978E438A13B}C:\hry\wolfenstein - the new order\wolfneworder_x64.exe] => (Block) C:\hry\wolfenstein - the new order\wolfneworder_x64.exe
FirewallRules: [{6600B386-AA61-4184-AAD2-3E9E22CB0D46}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{EE0690DC-7208-4023-BC79-99E6FF9C4236}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [UDP Query User{10958BBC-6244-4857-A6EC-376376CE221C}C:\totalcmd\totalcmd64.exe] => (Allow) C:\totalcmd\totalcmd64.exe
FirewallRules: [TCP Query User{102212C1-D519-4403-AD18-380185067044}C:\totalcmd\totalcmd64.exe] => (Allow) C:\totalcmd\totalcmd64.exe
FirewallRules: [UDP Query User{D1624410-A847-4A9F-9DC5-8535734A938B}C:\program files (x86)\mirc\mirc.exe] => (Allow) C:\program files (x86)\mirc\mirc.exe
FirewallRules: [TCP Query User{9C016069-B660-4186-99D7-1531EA00BB9A}C:\program files (x86)\mirc\mirc.exe] => (Allow) C:\program files (x86)\mirc\mirc.exe
FirewallRules: [UDP Query User{A7C21712-AF4D-4F10-97DC-8AF52C0FF407}C:\program files (x86)\mirc\mirc.exe] => (Allow) C:\program files (x86)\mirc\mirc.exe
FirewallRules: [TCP Query User{B4F2801D-6655-43F1-8B8D-977E0BFB86E1}C:\program files (x86)\mirc\mirc.exe] => (Allow) C:\program files (x86)\mirc\mirc.exe
FirewallRules: [UDP Query User{83EA352E-FF8C-483B-AED5-0DFE13ED05CA}C:\thoca\gtkradiant\gtkradiant-1.6.4-20131213\radiant.exe] => (Allow) C:\thoca\gtkradiant\gtkradiant-1.6.4-20131213\radiant.exe
FirewallRules: [TCP Query User{5B1A1438-0C82-4854-903B-E430B851E87D}C:\thoca\gtkradiant\gtkradiant-1.6.4-20131213\radiant.exe] => (Allow) C:\thoca\gtkradiant\gtkradiant-1.6.4-20131213\radiant.exe
FirewallRules: [UDP Query User{353540E7-C535-4ACE-8577-A4400B1F7400}C:\program files\gtkradiant-1.4\gtkradiant-1.4.0.exe] => (Allow) C:\program files\gtkradiant-1.4\gtkradiant-1.4.0.exe
FirewallRules: [TCP Query User{3C41A6AB-5408-4531-9246-18A3F8A684A1}C:\program files\gtkradiant-1.4\gtkradiant-1.4.0.exe] => (Allow) C:\program files\gtkradiant-1.4\gtkradiant-1.4.0.exe
FirewallRules: [{BEDC0E7E-B922-4A44-8C6E-F921D774BABE}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Metro Last Light\MetroLL.exe
FirewallRules: [{78FD2161-0950-4821-97D5-A26D15DEF3C3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Metro Last Light\MetroLL.exe
FirewallRules: [{9589F88F-8840-49BE-85B9-CE10E9DF3E31}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{5DDF57AD-67F7-420E-9294-08C93D79817B}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [UDP Query User{B8297C51-DA51-4611-8444-4FC84CFAA29B}C:\program files\gtkradiant-1.4\gtkradiant-1.4.0.exe] => (Allow) C:\program files\gtkradiant-1.4\gtkradiant-1.4.0.exe
FirewallRules: [TCP Query User{A96AEFB5-B75C-4348-A59C-4D3B52F12ECB}C:\program files\gtkradiant-1.4\gtkradiant-1.4.0.exe] => (Allow) C:\program files\gtkradiant-1.4\gtkradiant-1.4.0.exe
FirewallRules: [UDP Query User{57E9A374-E9AC-47D2-82DB-DC96C69EAEA3}C:\thoca\q3 radiant\quake3.exe] => (Allow) C:\thoca\q3 radiant\quake3.exe
FirewallRules: [TCP Query User{2EDFE0CF-918F-4BFF-BAC8-1DBE4188225E}C:\thoca\q3 radiant\quake3.exe] => (Allow) C:\thoca\q3 radiant\quake3.exe
FirewallRules: [UDP Query User{A92F1EC0-4C49-4A04-8C8F-BB9F5F6196B6}C:\program files (x86)\winamp\winamp.exe] => (Block) C:\program files (x86)\winamp\winamp.exe
FirewallRules: [TCP Query User{80D3BF16-11DE-4128-BC56-640DFA90D73D}C:\program files (x86)\winamp\winamp.exe] => (Block) C:\program files (x86)\winamp\winamp.exe
FirewallRules: [UDP Query User{EFDB44D6-794A-4889-B921-C1C30B887248}C:\thoca\quake iii arena\quake3.exe] => (Allow) C:\thoca\quake iii arena\quake3.exe
FirewallRules: [TCP Query User{1FBBCEC8-3ACE-4866-8C06-BDD04A782FD2}C:\thoca\quake iii arena\quake3.exe] => (Allow) C:\thoca\quake iii arena\quake3.exe
FirewallRules: [UDP Query User{F385CEB0-4A62-4506-983E-AF2F0ECC682A}D:\game_videa\tvorba videii\q3 mme\quake3mme.exe] => (Block) D:\game_videa\tvorba videii\q3 mme\quake3mme.exe
FirewallRules: [TCP Query User{DA9D4E1B-06B5-4B1F-9848-BBD741D47671}D:\game_videa\tvorba videii\q3 mme\quake3mme.exe] => (Block) D:\game_videa\tvorba videii\q3 mme\quake3mme.exe
FirewallRules: [UDP Query User{6C8334B5-E354-4A9A-B40D-EBCE4313E72D}C:\thoca\quake iii arena\quake3mme.exe] => (Block) C:\thoca\quake iii arena\quake3mme.exe
FirewallRules: [TCP Query User{68E9E145-8470-44C1-8054-8B170C3D818E}C:\thoca\quake iii arena\quake3mme.exe] => (Block) C:\thoca\quake iii arena\quake3mme.exe
FirewallRules: [{1FF13959-0171-4C70-A4E6-A94A152149E0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Company of Heroes 2\RelicCoH2.exe
FirewallRules: [{55EF5940-45C2-4BDD-BA96-C96D55F23215}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Company of Heroes 2\RelicCoH2.exe
FirewallRules: [{8B145D3C-6EC2-4035-9432-8A3999A4152D}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{98BB0A28-00E3-4C9E-9AD2-94F13F025C27}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{8D153E94-42C4-407A-BEB5-E5918B584214}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{3D5353A8-66C8-49E5-AE67-FAA3A121E2F5}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [UDP Query User{1CEFC87F-2937-44F3-AFFD-2BA79D5023A6}C:\program files (x86)\mozilla firefox\plugin-container.exe] => (Allow) C:\program files (x86)\mozilla firefox\plugin-container.exe
FirewallRules: [TCP Query User{E94ABED1-860F-4935-82CC-0119B7A8F17D}C:\program files (x86)\mozilla firefox\plugin-container.exe] => (Allow) C:\program files (x86)\mozilla firefox\plugin-container.exe
FirewallRules: [UDP Query User{135338C9-B235-45DF-AE6C-097857BC218A}C:\thoca\q3 radiant\quake3.exe] => (Allow) C:\thoca\q3 radiant\quake3.exe
FirewallRules: [TCP Query User{15E6F76B-1408-498B-9FCF-B38023AC95E9}C:\thoca\q3 radiant\quake3.exe] => (Allow) C:\thoca\q3 radiant\quake3.exe
FirewallRules: [UDP Query User{973D4F8F-FF82-4A72-8C6A-DFD1D0ADA9CF}D:\game_videa\tvorba videii\q3 mme\quake3mme.exe] => (Allow) D:\game_videa\tvorba videii\q3 mme\quake3mme.exe
FirewallRules: [TCP Query User{3EFB8B77-E030-4255-B9FC-AFFE53714DE9}D:\game_videa\tvorba videii\q3 mme\quake3mme.exe] => (Allow) D:\game_videa\tvorba videii\q3 mme\quake3mme.exe
FirewallRules: [UDP Query User{05325045-1664-4D81-89D1-F223F1E45B55}C:\thoca\quake iii arena\quake3.exe] => (Allow) C:\thoca\quake iii arena\quake3.exe
FirewallRules: [TCP Query User{58DBCA5A-91E2-4764-A22A-2B1AE396E3B5}C:\thoca\quake iii arena\quake3.exe] => (Allow) C:\thoca\quake iii arena\quake3.exe
FirewallRules: [{9B0C551E-E426-48AA-A16D-07FE52634F7E}] => (Allow) C:\Program Files (x86)\Diablo III\Diablo III.exe
FirewallRules: [{A6075899-ECB5-487B-9FFC-EBC95228D446}] => (Allow) C:\Program Files (x86)\Diablo III\Diablo III.exe
FirewallRules: [{3E025DF3-E435-419B-A381-599E47331B5E}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{72539DA3-25E1-4A33-910F-8F340C6ED8A6}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{9BE18236-C3A8-4CEB-8BD7-CD8E2006D1F9}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe
FirewallRules: [{EE3EC7A6-E679-4F2C-8AF4-DB3F08405D45}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2753\Agent.exe
FirewallRules: [{57B9FFFB-2299-48BB-8EB4-39B48B1F1BE2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Remember Me\Binaries\Win32\RememberMe.exe
FirewallRules: [{42B00452-4760-4540-8CC0-FF6CEA829590}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Remember Me\Binaries\Win32\RememberMe.exe
FirewallRules: [{5721408E-6CAC-4E0C-BCD7-43F05D8DB25E}] => (Allow) C:\Program Files (x86)\Origin Games\Crysis 3\Bin32\Crysis3.exe
FirewallRules: [{636A596F-A7DA-460E-B248-E453C6F4BCD5}] => (Allow) C:\Program Files (x86)\Origin Games\Crysis 3\Bin32\Crysis3.exe
FirewallRules: [{86E8C81D-4A9A-4560-B006-490A36DC2E0F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{A27DCFF3-38A6-4219-905B-8C5DEDAB2951}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [UDP Query User{60AC752A-51D1-48FA-A8A0-045548C5D412}C:\program files (x86)\winamp\winamp.exe] => (Allow) C:\program files (x86)\winamp\winamp.exe
FirewallRules: [TCP Query User{515D0FEA-DF01-41EA-9729-055921F8A561}C:\program files (x86)\winamp\winamp.exe] => (Allow) C:\program files (x86)\winamp\winamp.exe
FirewallRules: [UDP Query User{EB692C6F-97C3-4B87-9F1E-A796667BB579}C:\program files (x86)\origin games\medal of honor\mp\mohmpgame.exe] => (Allow) C:\program files (x86)\origin games\medal of honor\mp\mohmpgame.exe
FirewallRules: [TCP Query User{57C6D87C-43F7-483C-B0EA-084D53B8FA15}C:\program files (x86)\origin games\medal of honor\mp\mohmpgame.exe] => (Allow) C:\program files (x86)\origin games\medal of honor\mp\mohmpgame.exe
FirewallRules: [{80761CA7-3766-4B3B-97A8-61D4AAD29B9B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{AAF11F1E-F7DC-4EB0-B0A7-0E1D6C678C90}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{157123F5-FA90-46C5-A453-B28DFD116BFA}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{9D64ADA7-AA6D-4266-A646-13F06CEB60CB}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{BCCDE8D6-E86A-4115-A0E9-323948C0F767}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{05EF3042-98F9-4D71-A360-8250A0D10D5D}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{D97FF4E0-BAEA-455A-8E4C-29342D60DC92}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [TCP Query User{A7CA198D-9610-427D-A10C-A1274D7E6787}C:\program files (x86)\steam\steamapps\common\war thunder\aces.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\war thunder\aces.exe
FirewallRules: [UDP Query User{3050D0B7-9C78-4A23-A445-19C8119F89C2}C:\program files (x86)\steam\steamapps\common\war thunder\aces.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\war thunder\aces.exe
FirewallRules: [{FB58D9E7-9BA7-47D1-87D5-F93F3F749690}] => (Allow) C:\Games\World_of_Tanks\WoTLauncher.exe
FirewallRules: [{72FAF095-0488-44F7-A1BE-0C19D3BD51E0}] => (Allow) C:\Games\World_of_Tanks\WorldofTanks.exe
FirewallRules: [TCP Query User{114E250C-1354-4B93-A701-61EA58943804}C:\users\th0ca\appdata\local\mycomgames\mycomgames.exe] => (Allow) C:\users\th0ca\appdata\local\mycomgames\mycomgames.exe
FirewallRules: [UDP Query User{0021A4B9-5D2E-4D4C-A665-2D9D04EB905A}C:\users\th0ca\appdata\local\mycomgames\mycomgames.exe] => (Allow) C:\users\th0ca\appdata\local\mycomgames\mycomgames.exe
FirewallRules: [TCP Query User{F2DBB608-A265-4F30-B56F-A73FE8E75424}D:\mygames\armored warfare mycom beta\bin64\armoredwarfare.exe] => (Allow) D:\mygames\armored warfare mycom beta\bin64\armoredwarfare.exe
FirewallRules: [UDP Query User{A90C87B4-F3F6-4F41-8F42-57B5C6C36045}D:\mygames\armored warfare mycom beta\bin64\armoredwarfare.exe] => (Allow) D:\mygames\armored warfare mycom beta\bin64\armoredwarfare.exe
FirewallRules: [{43364F47-6773-47B0-A581-BD5F011E9DE4}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{706CB2E8-0ABB-48D0-B6CC-FB8F0216FA9E}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{45886844-95D4-4706-BFF2-D12D9853316E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{389409A9-1482-410A-9031-3DB8E16A2B7C}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{4097211D-105B-4CBA-93E9-6F3507149C12}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{697F26BE-EC22-414B-81DC-9F60B8A397AB}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{82D1BA13-507F-429C-BC04-9560446D9C6E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Deadlight\Binaries\Win32\LOTDGame.exe
FirewallRules: [{6629FD14-240F-40E2-A40F-805C9293EA30}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Deadlight\Binaries\Win32\LOTDGame.exe
FirewallRules: [TCP Query User{09FB4B81-6AAC-4C13-8C03-546E90DD2279}C:\hry\dying light\dyinglightgame.exe] => (Block) C:\hry\dying light\dyinglightgame.exe
FirewallRules: [UDP Query User{90803900-EA2C-475F-AC07-F62AAA2BAB71}C:\hry\dying light\dyinglightgame.exe] => (Block) C:\hry\dying light\dyinglightgame.exe
FirewallRules: [TCP Query User{439737D6-432B-456E-A85D-182BB6117F0E}C:\hry\far cry 4\bin\farcry4.exe] => (Block) C:\hry\far cry 4\bin\farcry4.exe
FirewallRules: [UDP Query User{08669B86-FCEC-4E69-9553-4ED3804FD02B}C:\hry\far cry 4\bin\farcry4.exe] => (Block) C:\hry\far cry 4\bin\farcry4.exe
FirewallRules: [TCP Query User{010E1F44-B271-4AE9-9A0C-175165036B7F}C:\warthunder\launcher.exe] => (Allow) C:\warthunder\launcher.exe
FirewallRules: [UDP Query User{F760F8E0-4306-4BEE-917D-E1E5E738E782}C:\warthunder\launcher.exe] => (Allow) C:\warthunder\launcher.exe

==================== Restore Points =========================

02-02-2018 23:57:01 Installed LibreOffice 5.3.7.2
07-02-2018 21:20:25 Windows Update

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (02/10/2018 01:28:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: utorrent.exe, verze: 2.2.1.25534, časové razítko: 0x4e4594ce
Název chybujícího modulu: GDI32.dll, verze: 10.0.16299.15, časové razítko: 0xbf7b6630
Kód výjimky: 0xc000041d
Posun chyby: 0x00005b36
ID chybujícího procesu: 0x1e38
Čas spuštění chybující aplikace: 0x01d3a26a7f15201a
Cesta k chybující aplikaci: C:\Users\th0ca\AppData\Roaming\uTorrent\utorrent.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\GDI32.dll
ID zprávy: 0549793a-3f6b-4501-8ee1-9f5c23df9f76
Úplný název chybujícího balíčku: 
ID aplikace související s chybujícím balíčkem:

Error: (02/10/2018 01:20:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: utorrent.exe, verze: 2.2.1.25534, časové razítko: 0x4e4594ce
Název chybujícího modulu: GDI32.dll, verze: 10.0.16299.15, časové razítko: 0xbf7b6630
Kód výjimky: 0xc000041d
Posun chyby: 0x00005b36
ID chybujícího procesu: 0x14d0
Čas spuštění chybující aplikace: 0x01d3a269398cca91
Cesta k chybující aplikaci: C:\Users\th0ca\AppData\Roaming\uTorrent\utorrent.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\GDI32.dll
ID zprávy: bed93ebe-caae-424d-8d98-e0176ed90a1b
Úplný název chybujícího balíčku: 
ID aplikace související s chybujícím balíčkem:

Error: (02/09/2018 05:21:35 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: utorrent.exe, verze: 2.2.1.25534, časové razítko: 0x4e4594ce
Název chybujícího modulu: GDI32.dll, verze: 10.0.16299.15, časové razítko: 0xbf7b6630
Kód výjimky: 0xc000041d
Posun chyby: 0x00005b36
ID chybujícího procesu: 0x29f4
Čas spuštění chybující aplikace: 0x01d3a1c1295e1cc9
Cesta k chybující aplikaci: C:\Users\th0ca\AppData\Roaming\uTorrent\utorrent.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\GDI32.dll
ID zprávy: 0c00e49f-051c-4330-98aa-d044589a65c1
Úplný název chybujícího balíčku: 
ID aplikace související s chybujícím balíčkem:

Error: (02/08/2018 05:53:59 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: utorrent.exe, verze: 2.2.1.25534, časové razítko: 0x4e4594ce
Název chybujícího modulu: GDI32.dll, verze: 10.0.16299.15, časové razítko: 0xbf7b6630
Kód výjimky: 0xc000041d
Posun chyby: 0x00005b36
ID chybujícího procesu: 0x22ac
Čas spuštění chybující aplikace: 0x01d3a0fd3ea6be40
Cesta k chybující aplikaci: C:\Users\th0ca\AppData\Roaming\uTorrent\utorrent.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\GDI32.dll
ID zprávy: 0386f268-d651-4330-a589-d840e939fbcc
Úplný název chybujícího balíčku: 
ID aplikace související s chybujícím balíčkem:

Error: (02/07/2018 05:42:22 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: utorrent.exe, verze: 2.2.1.25534, časové razítko: 0x4e4594ce
Název chybujícího modulu: GDI32.dll, verze: 10.0.16299.15, časové razítko: 0xbf7b6630
Kód výjimky: 0xc000041d
Posun chyby: 0x00005b36
ID chybujícího procesu: 0x2528
Čas spuštění chybující aplikace: 0x01d3a031a334aa67
Cesta k chybující aplikaci: C:\Users\th0ca\AppData\Roaming\uTorrent\utorrent.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\GDI32.dll
ID zprávy: 97f72590-3e8a-40bf-b3c4-523ef694b753
Úplný název chybujícího balíčku: 
ID aplikace související s chybujícím balíčkem:

Error: (02/06/2018 10:00:58 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: utorrent.exe, verze: 2.2.1.25534, časové razítko: 0x4e4594ce
Název chybujícího modulu: GDI32.dll, verze: 10.0.16299.15, časové razítko: 0xbf7b6630
Kód výjimky: 0xc000041d
Posun chyby: 0x00005b36
ID chybujícího procesu: 0x1520
Čas spuštění chybující aplikace: 0x01d39f78f4e51114
Cesta k chybující aplikaci: C:\Users\th0ca\AppData\Roaming\uTorrent\utorrent.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\GDI32.dll
ID zprávy: f2a32760-4fb1-4edb-afd8-d3fd3954aa31
Úplný název chybujícího balíčku: 
ID aplikace související s chybujícím balíčkem:

Error: (02/05/2018 05:21:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: utorrent.exe, verze: 2.2.1.25534, časové razítko: 0x4e4594ce
Název chybujícího modulu: GDI32.dll, verze: 10.0.16299.15, časové razítko: 0xbf7b6630
Kód výjimky: 0xc000041d
Posun chyby: 0x00005b36
ID chybujícího procesu: 0x22bc
Čas spuštění chybující aplikace: 0x01d39e9cb5db41a0
Cesta k chybující aplikaci: C:\Users\th0ca\AppData\Roaming\uTorrent\utorrent.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\GDI32.dll
ID zprávy: d2ed7178-37ab-452e-9589-2311baeb6854
Úplný název chybujícího balíčku: 
ID aplikace související s chybujícím balíčkem:

Error: (02/04/2018 01:12:01 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program soffice.bin verze 5.3.7.2 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Zabezpečení a údržba.

ID procesu: 1024

Čas spuštění: 01d39dae4b49031c

Čas ukončení: 7

Cesta k aplikaci: C:\Program Files\LibreOffice 5\program\soffice.bin

ID hlášení: b6acd1c7-2849-4afe-849e-395254f23042

Úplný název balíčku s chybou: 

ID aplikace související s balíčkem s chybou:

Error: (02/04/2018 12:34:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: utorrent.exe, verze: 2.2.1.25534, časové razítko: 0x4e4594ce
Název chybujícího modulu: GDI32.dll, verze: 10.0.16299.15, časové razítko: 0xbf7b6630
Kód výjimky: 0xc000041d
Posun chyby: 0x00005b36
ID chybujícího procesu: 0x27fc
Čas spuštění chybující aplikace: 0x01d39daa0718437e
Cesta k chybující aplikaci: C:\Users\th0ca\AppData\Roaming\uTorrent\utorrent.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\GDI32.dll
ID zprávy: ecfa0d72-f385-4901-a677-b41d85e928b7
Úplný název chybujícího balíčku: 
ID aplikace související s chybujícím balíčkem:

Error: (02/03/2018 09:10:38 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: Procedura Open pro službu BITS v knihovně DLL C:\Windows\System32\bitsperf.dll se nezdařila. Výkonnostní data pro tuto službu nebudou k dispozici. Vrácený kód stavu představují první čtyři bajty (DWORD) datové části.


System errors:
=============
Error: (02/10/2018 01:26:42 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 a APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (02/10/2018 01:26:42 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 a APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (02/10/2018 01:26:42 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 a APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (02/10/2018 01:26:42 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 a APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (02/10/2018 01:26:24 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Služba W3SVC závisí na službě WAS, která neuspěla při spuštění v důsledku následující chyby: 
Neplatné údaje.

Error: (02/10/2018 01:26:24 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Služba NetMsmqActivator závisí na službě WAS, která neuspěla při spuštění v důsledku následující chyby: 
Neplatné údaje.

Error: (02/10/2018 01:26:24 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Služba NetPipeActivator závisí na službě WAS, která neuspěla při spuštění v důsledku následující chyby: 
Neplatné údaje.

Error: (02/10/2018 01:26:24 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Služba NetTcpActivator závisí na službě WAS, která neuspěla při spuštění v důsledku následující chyby: 
Neplatné údaje.

Error: (02/10/2018 01:26:24 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Služba WAS byla ukončena s následující chybou: 
Neplatné údaje.

Error: (02/10/2018 01:26:23 PM) (Source: WAS) (EventID: 5005) (User: )
Description: Aktivační služba procesů systému Windows (WAS) je zastavována, protože zjistila chybu. Datové pole obsahuje číslo chyby.


==================== Memory info =========================== 

Processor: AMD FX(tm)-6300 Six-Core Processor 
Percentage of memory in use: 20%
Total physical RAM: 16344.74 MB
Available physical RAM: 12924.34 MB
Total Virtual: 32728.74 MB
Available Virtual: 28622.05 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.32 GB) (Free:47.09 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (Disk na data) (Fixed) (Total:931.51 GB) (Free:443.61 GB) NTFS
Drive e: (Disk na data 2) (Fixed) (Total:465.76 GB) (Free:183.52 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: D6FE87A5)
Partition 1: (Active) - (Size=465.3 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=450 MB) - (Type=27)

========================================================
Disk: 1 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 38888F15)
Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS)

========================================================
Disk: 2 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 45E4C5A3)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================