Additional scan result of Farbar Recovery Scan Tool (x64) Version: 18-04-2023
Ran by Peete (20-04-2023 20:06:59)
Running from C:\Users\Peete\Downloads
Microsoft Windows 10 Pro Version 22H2 19045.2846 (X64) (2020-06-05 00:01:44)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================


(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-191128902-3644307124-883229192-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-191128902-3644307124-883229192-503 - Limited - Disabled)
Guest (S-1-5-21-191128902-3644307124-883229192-501 - Limited - Disabled)
jaňule (S-1-5-21-191128902-3644307124-883229192-1002 - Limited - Enabled) => C:\Users\jaňule
Peete (S-1-5-21-191128902-3644307124-883229192-1001 - Administrator - Enabled) => C:\Users\Peete
WDAGUtilityAccount (S-1-5-21-191128902-3644307124-883229192-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 22.01 (x64) (HKLM\...\7-Zip) (Version: 22.01 - Igor Pavlov)
Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1029-1033-7760-BC15014EA700}) (Version: 23.001.20143 - Adobe)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601047}) (Version: 1.8.0 - Adobe Systems Incorporated) Hidden
AMD GPIO2 Driver (HKLM-x32\...\{E9DD399F-21A3-479E-A7DF-D6CF4B2ADBF3}) (Version: 2.2.0.130 - Advanced Micro Devices, Inc.) Hidden
AMD Chipset Software (HKLM-x32\...\AMD_Chipset_IODrivers) (Version: 4.11.15.342 - Advanced Micro Devices, Inc.)
AMD PCI Driver (HKLM-x32\...\{80EC3CEE-2940-42A1-A776-B5D810D39F1E}) (Version: 1.0.0.90 - Advanced Micro Devices, Inc.) Hidden
AMD PSP Driver (HKLM-x32\...\{988F14B8-79A8-475D-BAC7-83F96AD3D821}) (Version: 5.22.0.0 - Advanced Micro Devices, Inc.) Hidden
AMD Ryzen Balanced Driver (HKLM-x32\...\{A171D320-C42C-4F3B-A2D8-C6A09F6788CC}) (Version: 8.0.0.13 - Advanced Micro Devices, Inc.) Hidden
AMD SBxxx SMBus Driver (HKLM-x32\...\{AAE0E27D-C88A-49BA-8715-77ADCD4286A3}) (Version: 5.12.0.38 - Advanced Micro Devices, Inc.) Hidden
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 22.11.2 - Advanced Micro Devices, Inc.)
AMD_Chipset_Drivers (HKLM-x32\...\{f3aba9dc-defe-4038-beaa-f2b89df75a66}) (Version: 4.11.15.342 - Advanced Micro Devices, Inc.) Hidden
AutoHotkey 1.1.33.02 (HKLM\...\AutoHotkey) (Version: 1.1.33.02 - Lexikos)
Battle for Wesnoth 1.12.6 (HKU\S-1-5-21-191128902-3644307124-883229192-1001\...\Battle for Wesnoth 1.12.6) (Version: 1.12.6 - )
Battle for Wesnoth 1.13.0 (HKU\S-1-5-21-191128902-3644307124-883229192-1001\...\Battle for Wesnoth 1.13.0) (Version: 1.13.0 - )
Battle for Wesnoth 1.14.9 (HKU\S-1-5-21-191128902-3644307124-883229192-1001\...\Battle for Wesnoth 1.14.9) (Version: 1.14.9 - )
Battle for Wesnoth 1.16.1 (HKLM-x32\...\Battle for Wesnoth 1.16.1) (Version: 1.16.1 - )
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Branding64 (HKLM\...\{0DB6E0DC-607A-42C1-A3CE-7567A9F85AF4}) (Version: 1.00.0008 - Advanced Micro Devices, Inc.) Hidden
BS.Player FREE (HKLM-x32\...\BSPlayerf) (Version: 2.77.1092 - AB Team, d.o.o.)
Command & Conquer™ and The Covert Operations™ (HKLM-x32\...\{050E298D-C9B8-4582-A332-26201268A297}) (Version: 1.0.0.0 - Electronic Arts, Inc.)
Command & Conquer™ Red Alert 2 and Yuri’s Revenge (HKLM-x32\...\{F5275D1C-D133-486D-8F07-D6C571F0A8EC}) (Version: 1.0.0.0 - Electronic Arts, Inc.)
Command & Conquer™ Red Alert, Counterstrike and The Aftermath (HKLM-x32\...\{25456D58-2414-4CC4-AA1B-CF3A2BE00A79}) (Version: 1.0.0.0 - Electronic Arts, Inc.)
Command & Conquer™ Tiberian Sun™ and Firestorm™ (HKLM-x32\...\{517FAF1E-3045-49DE-8079-107C2851389E}) (Version: 1.0.0.0 - Electronic Arts, Inc.)
Core Temp 1.18 (HKLM\...\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 1.18 - ALCPU)
CPUID CPU-Z 2.04 (HKLM\...\CPUID CPU-Z_is1) (Version: 2.04 - CPUID, Inc.)
CurseForge (HKU\S-1-5-21-191128902-3644307124-883229192-1001\...\Overwolf_cchhcaiapeikjbdbpfplgmpobbcdkdaphclbmkbj) (Version: 0.223.1.9730 - Overwolf app)
CyberGhost TUN (HKLM\...\{677232D6-72D6-4821-8CB5-47969B15D4DF}) (Version: 1.0 - CyberGhost S.R.L.) Hidden
Diablo II (HKLM-x32\...\Diablo II) (Version: 0.0.0.0 - Blizzard Entertainment)
Diablo II Resurrected (HKLM-x32\...\Diablo II Resurrected) (Version:  - Blizzard Entertainment)
Discord (HKU\S-1-5-21-191128902-3644307124-883229192-1001\...\Discord) (Version: 0.0.309 - Discord Inc.)
Epic Games Launcher (HKLM-x32\...\{B2081DA9-6C73-403B-BA23-DCE21015C0A1}) (Version: 1.1.293.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{F9C5C994-F6B9-4D75-B3E7-AD01B84073E9}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Epic Online Services (HKLM-x32\...\{19695986-25CE-41AC-9C6F-54794653EDBA}) (Version: 2.0.36.0 - Epic Games, Inc.)
f.lux (HKU\S-1-5-21-191128902-3644307124-883229192-1001\...\Flux) (Version:  - f.lux Software LLC)
Firestone (HKU\S-1-5-21-191128902-3644307124-883229192-1001\...\Overwolf_lnknbakkpommmjjdnelmfbjjdbocfpnpbkijjnob) (Version: 11.0.20 - Overwolf app)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 112.0.5615.137 - Google LLC)
Greenshot 1.2.10.6 (HKLM\...\Greenshot_is1) (Version: 1.2.10.6 - Greenshot)
Hearthstone (HKLM-x32\...\Hearthstone) (Version:  - Blizzard Entertainment)
Chrome Remote Desktop Host (HKLM-x32\...\{B05732E7-300F-4AAA-A883-77C27150595C}) (Version: 112.0.5615.26 - Google LLC)
Launcher Prerequisites (x64) (HKLM-x32\...\{43a03b9c-4770-409c-a999-587b60700b63}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
League of Legends (HKLM-x32\...\League of Legends 1.0) (Version: 1.0 - Riot Games, Inc)
Malwarebytes version 4.4.10.144 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.4.10.144 - Malwarebytes)
Microsoft .NET Host - 5.0.13 (x64) (HKLM\...\{07FD769C-6C18-4038-A261-E9859C74E624}) (Version: 40.52.30715 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 5.0.13 (x64) (HKLM\...\{0F011389-4823-40D0-AB50-711628D820F5}) (Version: 40.52.30715 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 5.0.13 (x64) (HKLM\...\{C84C2DA1-52E2-4183-8F20-88176B77848F}) (Version: 40.52.30715 - Microsoft Corporation) Hidden
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 112.0.1722.48 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 112.0.1722.48 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-191128902-3644307124-883229192-1002\...\OneDriveSetup.exe) (Version: 23.011.0115.0009 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{89581302-705F-42C5-99B0-E368A845DAD5}) (Version: 3.70.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 (HKLM\...\{929FBD26-9020-399B-9A7A-751D61F0B942}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 (HKLM\...\{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (HKLM-x32\...\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (HKLM-x32\...\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}) (Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.31.31103 (HKLM-x32\...\{2aaf1df0-eb13-4099-9992-962bb4e596d1}) (Version: 14.31.31103.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.31.31103 (HKLM-x32\...\{41d7b770-418a-43b7-95a5-f925fff05789}) (Version: 14.31.31103.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.31.31103 (HKLM\...\{A977984B-9244-49E3-BD24-43F0A8009667}) (Version: 14.31.31103 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.31.31103 (HKLM\...\{A181A302-3F6D-4BAD-97A8-A426A6499D78}) (Version: 14.31.31103 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.31.31103 (HKLM-x32\...\{5720EC03-F26F-40B7-980C-50B5D420B5DE}) (Version: 14.31.31103 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.31.31103 (HKLM-x32\...\{799E3FFF-705C-461F-B400-6DE27398B3E5}) (Version: 14.31.31103 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 5.0.13 (x64) (HKLM\...\{E41C6EA8-A897-4008-835E-151A92FD6F95}) (Version: 40.52.30717 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 5.0.13 (x64) (HKLM-x32\...\{e2d1ae32-dd1d-4ad7-a298-10e42e7840fc}) (Version: 5.0.13.30717 - Microsoft Corporation)
Minecraft Launcher (HKLM-x32\...\{810F1419-7760-402E-8772-B4054FAA2B72}) (Version: 1.0.0.0 - Mojang)
Mozilla Firefox (x64 cs) (HKLM\...\Mozilla Firefox 112.0.1 (x64 cs)) (Version: 112.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 68.0.1 - Mozilla)
NVIDIA Systémový software PhysX 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation)
OpenRA (HKLM\...\OpenRA) (Version: release-20210321 - OpenRA developers)
Origin (HKLM-x32\...\Origin) (Version: 10.5.116.52126 - Electronic Arts, Inc.)
Overwolf (HKLM-x32\...\Overwolf) (Version: 0.221.109.13 - Overwolf Ltd.)
Promontory_GPIO Driver (HKLM-x32\...\{B5512BCC-F4CD-4159-86A4-B2AD7D38FFA9}) (Version: 3.0.0.0 - Advanced Micro Devices, Inc.) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.34.307.2019 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.9205.1 - Realtek Semiconductor Corp.)
RuneLite (HKU\S-1-5-21-191128902-3644307124-883229192-1001\...\RuneLite_is1) (Version: Launcher 1.6.0 - RuneLite)
RyzenMasterSDK (HKLM\...\{77685788-5072-4553-AF2B-A84E9CF040DA}) (Version: 1.2.3.5 - Advanced Micro Devices, Inc.) Hidden
SlimDX Runtime .NET 4.0 x64 (January 2012) (HKLM\...\{A2199A06-89C4-4187-AA4A-3A9676FB799D}) (Version: 2.0.13.43 - SlimDX Group)
StarCraft II (HKLM-x32\...\StarCraft II) (Version:  - Blizzard Entertainment)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
TAP-Windows 9.21.2 (HKLM\...\TAP-Windows) (Version: 9.21.2 - )
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.5.6 - TeamSpeak Systems GmbH)
The Battle for Middle-earth (tm) (HKLM-x32\...\{3F290582-3F4E-4B96-009C-E0BABAA40C42}) (Version:  - )
The Settlers II - 10th Anniversary (HKLM-x32\...\GOGPACKSETTLERS210TH_is1) (Version: 2.0.0.8 - GOG.com)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.17.4 - VideoLAN)
w3champions 1.2.2 (HKU\S-1-5-21-191128902-3644307124-883229192-1001\...\d525917c-cfaa-5bc0-bd12-f03cd29d8716) (Version: 1.2.2 - Deespul LLC)
Warcraft III (HKLM-x32\...\Warcraft III) (Version:  - Blizzard Entertainment)
Warcraft III: All Products (HKU\S-1-5-21-191128902-3644307124-883229192-1001\...\Warcraft III) (Version:  - )
Zoom (HKU\S-1-5-21-191128902-3644307124-883229192-1001\...\ZoomUMX) (Version: 5.11.11 (8425) - Zoom Video Communications, Inc.)

Packages:
=========
Doplněk multimediálního modulu pro aplikaci Fotografie -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2019-12-19] (Microsoft Corporation)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-07-28] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-07-28] (Microsoft Corporation) [MS Ad]
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.964.0_x64__56jybvy8sckqj [2023-03-10] (NVIDIA Corp.)
Solitaire & Casual Games -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.16.3140.0_x64__8wekyb3d8bbwe [2023-03-21] (Microsoft Studios) [MS Ad]

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-191128902-3644307124-883229192-1001_Classes\CLSID\{CB965DF1-B8EA-49C7-BDAD-5457FDC1BF92}\InprocServer32 -> C:\Users\Peete\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.20244.4\x64\Microsoft.Teams.AddinLoader.dll => No File
CustomCLSID: HKU\S-1-5-21-191128902-3644307124-883229192-1001_Classes\CLSID\{d1b22d3d-8585-53a6-acb3-0e803c7e8d2a}\localserver32 -> "C:\Users\Peete\AppData\Local\Microsoft\Teams\current\Teams.exe" --toast => No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2022-07-15] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [BB FlashBack 2] -> {A8065B9E-193F-4797-B62D-8F6321E7FCCB} =>  -> No File
ContextMenuHandlers1: [IObitUnstaler] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => C:\Program Files (x86)\IObit\IObit Uninstaller\IUMenuRight.dll -> No File
ContextMenuHandlers1: [PDFCreator.ShellContextMenu] -> {d9cea52e-100d-4159-89ea-76e845bc13e1} => C:\Program Files\PDFCreator\PDFCreatorShell.DLL -> No File
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-10-23] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2022-07-15] (Igor Pavlov) [File not signed]
ContextMenuHandlers4: [IObitUnstaler] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => C:\Program Files (x86)\IObit\IObit Uninstaller\IUMenuRight.dll -> No File
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files\AMD\CNext\CNext\atiacm64.dll [2022-11-30] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_009debfbd2e1619b\nvshext.dll [2022-11-15] (Nvidia Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2022-07-15] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [IObitUnstaler] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => C:\Program Files (x86)\IObit\IObit Uninstaller\IUMenuRight.dll -> No File
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-10-23] (Malwarebytes Corporation -> Malwarebytes)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

ShortcutWithArgument: C:\Users\Peete\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\Zpl Printer.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=phoidlklenidapnijkabnfdgmadlcmjo
ShortcutWithArgument: C:\Users\Peete\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\3b229b301d4bb615\Zpl Printer.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=phoidlklenidapnijkabnfdgmadlcmjo

==================== Loaded Modules (Whitelisted) =============

2019-09-19 21:01 - 2022-11-07 12:17 - 000387072 _____ () [File not signed] C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\libegl.dll
2019-09-19 21:01 - 2022-11-07 12:17 - 008052736 _____ () [File not signed] C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\libglesv2.dll
2019-09-15 11:49 - 2022-07-15 16:00 - 000094720 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll
2020-06-06 14:19 - 2020-06-06 14:19 - 001282048 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Origin\LIBEAY32.dll
2020-06-06 14:19 - 2020-06-06 14:19 - 000279040 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Origin\ssleay32.dll
2020-06-06 14:19 - 2020-06-06 14:19 - 001611264 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\platforms\qwindows.dll
2023-01-25 20:06 - 2020-06-06 14:19 - 005487104 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Core.dll
2023-01-25 20:06 - 2020-06-06 14:19 - 005841920 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Gui.dll
2023-01-25 20:06 - 2020-06-06 14:19 - 001179136 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Network.dll
2023-01-25 20:06 - 2020-06-06 14:19 - 000146432 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5WebSockets.dll
2023-01-25 20:06 - 2020-06-06 14:19 - 005089792 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Widgets.dll
2023-01-25 20:06 - 2020-06-06 14:19 - 000184832 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Xml.dll

==================== Alternate Data Streams (Whitelisted) ========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData:iSpring Solutions [128]
AlternateDataStreams: C:\Users\All Users:iSpring Solutions [128]
AlternateDataStreams: C:\ProgramData\Data aplikací:iSpring Solutions [128]
AlternateDataStreams: C:\Users\Peete\Data aplikací:00e481b5e22dbe1f649fcddd505d3eb7 [394]
AlternateDataStreams: C:\Users\Peete\Data aplikací:iSpring Solutions [128]
AlternateDataStreams: C:\Users\Peete\AppData\Roaming:00e481b5e22dbe1f649fcddd505d3eb7 [394]
AlternateDataStreams: C:\Users\Peete\AppData\Roaming:iSpring Solutions [128]

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) ==========


(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-191128902-3644307124-883229192-1001\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-191128902-3644307124-883229192-1001\...\plexonline.com -> hxxp://test.plexonline.com
IE trusted site: HKU\S-1-5-21-191128902-3644307124-883229192-1001\...\plexus-online.com -> plexus-online.com
IE trusted site: HKU\S-1-5-21-191128902-3644307124-883229192-1001\...\sharepoint.com -> hxxps://plexsystems-files.sharepoint.com

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2019-03-19 06:49 - 2022-06-16 13:44 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-191128902-3644307124-883229192-1001\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\theme1\img13.jpg
HKU\S-1-5-21-191128902-3644307124-883229192-1002\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\Run: => "Seagull Drivers V3"
HKLM\...\StartupApproved\Run: => "Logitech Download Assistant"
HKU\S-1-5-21-191128902-3644307124-883229192-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-191128902-3644307124-883229192-1001\...\StartupApproved\Run: => "com.squirrel.Teams.Teams"
HKU\S-1-5-21-191128902-3644307124-883229192-1001\...\StartupApproved\Run: => "Overwolf"
HKU\S-1-5-21-191128902-3644307124-883229192-1001\...\StartupApproved\Run: => "EpicGamesLauncher"
HKU\S-1-5-21-191128902-3644307124-883229192-1001\...\StartupApproved\Run: => "NordVPN"
HKU\S-1-5-21-191128902-3644307124-883229192-1001\...\StartupApproved\Run: => "CiscoMeetingDaemon"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [UDP Query User{B54D72CA-DD9B-412F-A24C-BFB0EA377834}C:\games\bfme1\game.dat] => (Allow) C:\games\bfme1\game.dat () [File not signed]
FirewallRules: [TCP Query User{978FE881-81B5-4DB7-ABC3-D574455D7D48}C:\games\bfme1\game.dat] => (Allow) C:\games\bfme1\game.dat () [File not signed]
FirewallRules: [{7351C2B5-A41A-4CAA-9119-1D4B97387178}] => (Allow) C:\Program Files (x86)\Diablo II\Diablo II.exe (Blizzard Entertainment, Inc. -> Blizzard North)
FirewallRules: [{38FF635B-4565-44B8-99AA-292501EE6B4C}] => (Allow) C:\Program Files (x86)\Diablo II\Diablo II.exe (Blizzard Entertainment, Inc. -> Blizzard North)
FirewallRules: [{0D834B83-53C9-4C76-B7F9-62FEC9EDA1E5}] => (Allow) C:\Program Files (x86)\Diablo II\Diablo II.exe (Blizzard Entertainment, Inc. -> Blizzard North)
FirewallRules: [{BC5C3EEE-C830-41E8-9ECA-E62352E5A9F0}] => (Allow) C:\Program Files (x86)\Diablo II\Diablo II.exe (Blizzard Entertainment, Inc. -> Blizzard North)
FirewallRules: [{73EBFA49-ABEE-4F86-B800-26CB2048CCA2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\UnderMine\UnderMine.exe () [File not signed]
FirewallRules: [{FFACE38A-E49A-48C4-A503-BBC5D12A2CE1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\UnderMine\UnderMine.exe () [File not signed]
FirewallRules: [UDP Query User{D87924A5-981E-440C-AE5A-5534865BCC30}C:\warcraft iii\war3.exe] => (Allow) C:\warcraft iii\war3.exe (Blizzard Entertainment) [File not signed]
FirewallRules: [TCP Query User{5CC83FA2-2BE0-4D50-8779-2974B75F9014}C:\warcraft iii\war3.exe] => (Allow) C:\warcraft iii\war3.exe (Blizzard Entertainment) [File not signed]
FirewallRules: [UDP Query User{F9112B3B-0FC7-4A94-96A6-226136AC840C}C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe
FirewallRules: [TCP Query User{FC9670CB-9693-4CBA-830A-52F0080FEC2A}C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe
FirewallRules: [{A7D525B4-5019-4E6F-A42A-3A8480B3058A}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{6AE9210D-0C43-490C-8F64-7788EB7D10E8}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{2A0251A4-C2D0-4799-9AB4-F259C7E08645}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{C5A089B7-F6DE-482C-9D92-5518CE206BA5}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [UDP Query User{420EC1D9-68E9-44F6-8D39-B430E7318B63}C:\riot games\league of legends\game\league of legends.exe] => (Allow) C:\riot games\league of legends\game\league of legends.exe (Riot Games, Inc. -> Riot Games, Inc.)
FirewallRules: [TCP Query User{C349C211-FF73-4C27-91FA-7EEAA4D0D6FB}C:\riot games\league of legends\game\league of legends.exe] => (Allow) C:\riot games\league of legends\game\league of legends.exe (Riot Games, Inc. -> Riot Games, Inc.)
FirewallRules: [{07ED5915-9FA1-470C-B195-025FED2C30C6}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{DBFD40EA-C0E0-4FAD-AD0A-844B04B33266}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{1F40CE4E-5C2D-4895-908B-2DBB85D5A567}] => (Allow) C:\Riot Games\League of Legends\LeagueClient.exe (Riot Games, Inc. -> Riot Games, Inc.)
FirewallRules: [{E24DE250-B01F-40D2-887D-94877B975A15}] => (Allow) C:\Riot Games\League of Legends\LeagueClient.exe (Riot Games, Inc. -> Riot Games, Inc.)
FirewallRules: [{389527CE-FE1D-45DD-9A35-7221D79CD6A7}] => (Allow) C:\Program Files (x86)\Origin Games\Command and Conquer Red Alert II\RA2Launcher.exe (Kalloc Studios, Inc. -> Kalloc Studios) [File not signed]
FirewallRules: [{1C369457-4822-4F64-AD7C-FC637CB05B42}] => (Allow) C:\Program Files (x86)\Origin Games\Command and Conquer Red Alert II\RA2Launcher.exe (Kalloc Studios, Inc. -> Kalloc Studios) [File not signed]
FirewallRules: [{F1156BD3-0436-474D-AE02-DEED4EDEE326}] => (Allow) C:\Program Files (x86)\Origin Games\Command and Conquer Red Alert\RA95Launcher.exe (Kalloc Studios, Inc. -> Kalloc Studios) [File not signed]
FirewallRules: [{9662613B-D37D-4CA4-A976-468C0DF49E8D}] => (Allow) C:\Program Files (x86)\Origin Games\Command and Conquer Red Alert\RA95Launcher.exe (Kalloc Studios, Inc. -> Kalloc Studios) [File not signed]
FirewallRules: [{A4095506-F390-4164-95E5-941C9C9B1B4E}] => (Allow) C:\Program Files (x86)\Origin Games\CNC and The Covert Operations\CNC95Launcher.exe (Kalloc Studios, Inc. -> Kalloc Studios) [File not signed]
FirewallRules: [{072997CE-6764-4092-83D7-972654B8C89E}] => (Allow) C:\Program Files (x86)\Origin Games\CNC and The Covert Operations\CNC95Launcher.exe (Kalloc Studios, Inc. -> Kalloc Studios) [File not signed]
FirewallRules: [{143BBD65-2797-4391-92DB-8D5BCAD8F5BD}] => (Allow) C:\Program Files (x86)\Origin Games\Command and Conquer Tiberian Sun\TSLauncher.exe (Kalloc Studios, Inc. -> Kalloc Studios) [File not signed]
FirewallRules: [{8ED51F5C-6C51-4277-ABCE-1B9EDC08E11C}] => (Allow) C:\Program Files (x86)\Origin Games\Command and Conquer Tiberian Sun\TSLauncher.exe (Kalloc Studios, Inc. -> Kalloc Studios) [File not signed]
FirewallRules: [TCP Query User{98FE6E11-D4ED-43BE-8573-C86F0E3646C5}C:\program files\openra\redalert.exe] => (Allow) C:\program files\openra\redalert.exe (RedAlert) [File not signed]
FirewallRules: [UDP Query User{A7ACE000-29FF-4CE3-938D-5C10107D0F89}C:\program files\openra\redalert.exe] => (Allow) C:\program files\openra\redalert.exe (RedAlert) [File not signed]
FirewallRules: [TCP Query User{65A60A79-9C3A-4EFC-9379-D4D09ECA0C7A}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{880EBF3D-FD90-4C50-9880-49911FF317CC}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{5D18B74F-47CA-4B0F-9333-DE79497B28F3}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Worms Armageddon\WA.exe (Team17 Software Ltd) [File not signed]
FirewallRules: [{59D47547-9A85-4972-A21B-F8AD3D4FBF8B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Worms Armageddon\WA.exe (Team17 Software Ltd) [File not signed]
FirewallRules: [{719F1015-C19F-4376-BC56-6679EF047D0A}] => (Allow) LPort=5130
FirewallRules: [TCP Query User{93FD9E7F-387C-4221-98D0-44CE10D4EC30}C:\program files (x86)\warcraft iii\_retail_\x86_64\warcraft iii.exe] => (Allow) C:\program files (x86)\warcraft iii\_retail_\x86_64\warcraft iii.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment, Inc)
FirewallRules: [UDP Query User{CAF4A20F-AA54-4137-A76A-839CC99389BF}C:\program files (x86)\warcraft iii\_retail_\x86_64\warcraft iii.exe] => (Allow) C:\program files (x86)\warcraft iii\_retail_\x86_64\warcraft iii.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment, Inc)
FirewallRules: [TCP Query User{1D013830-418E-4711-8A00-97F47D63CE3C}C:\games\starcraft ii\versions\base82457\sc2_x64.exe] => (Allow) C:\games\starcraft ii\versions\base82457\sc2_x64.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment, Inc.)
FirewallRules: [UDP Query User{0CD75F11-6B97-4942-B0AE-93014BAB2B96}C:\games\starcraft ii\versions\base82457\sc2_x64.exe] => (Allow) C:\games\starcraft ii\versions\base82457\sc2_x64.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment, Inc.)
FirewallRules: [TCP Query User{9A601340-1C81-4F7A-995F-1AC0A4A6EBDC}D:\mw2\call of duty modern warfare 2 full game  mp - sp+updater  -=aviara=-\iw4sp.exe] => (Block) D:\mw2\call of duty modern warfare 2 full game  mp - sp+updater  -=aviara=-\iw4sp.exe => No File
FirewallRules: [UDP Query User{CBBAC6DE-D52F-45DE-BB21-E38DB405EB0C}D:\mw2\call of duty modern warfare 2 full game  mp - sp+updater  -=aviara=-\iw4sp.exe] => (Block) D:\mw2\call of duty modern warfare 2 full game  mp - sp+updater  -=aviara=-\iw4sp.exe => No File
FirewallRules: [{B8DA2805-7F59-4AF8-9B5B-02895900E677}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Enter the Gungeon\EtG.exe () [File not signed]
FirewallRules: [{8E3BC472-3560-48B7-AC81-D4C3619635C0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Enter the Gungeon\EtG.exe () [File not signed]
FirewallRules: [{AF9498AC-94FB-4A87-8AA9-0A5C3A768B72}] => (Allow) D:\Dragon Age\bin_ship\daorigins.exe (BioWare -> BioWare) [File not signed]
FirewallRules: [{D66D46AA-FE12-4C9A-BFBF-23511BA40150}] => (Allow) D:\Dragon Age\bin_ship\daorigins.exe (BioWare -> BioWare) [File not signed]
FirewallRules: [{8EF7B800-6644-4EBB-AD83-C8EAF5DD139F}] => (Allow) D:\Dragon Age\DAOriginsLauncher.exe (BioWare -> BioWare)
FirewallRules: [{61A262CD-F305-4F3F-84E1-180900B96FD5}] => (Allow) D:\Dragon Age\DAOriginsLauncher.exe (BioWare -> BioWare)
FirewallRules: [{33283CD1-CCD7-4891-B54D-B71469E3AB78}] => (Allow) D:\Dragon Age\bin_ship\daupdatersvc.service.exe (BioWare -> BioWare)
FirewallRules: [{8F9ADCDD-94D2-4955-90FF-E9A070F12D7C}] => (Allow) D:\Dragon Age\bin_ship\daupdatersvc.service.exe (BioWare -> BioWare)
FirewallRules: [TCP Query User{1E819F2B-3FE0-440A-8985-889A7E8AA488}D:\wow\world of warcraft\_retail_\utils\wowvoiceproxy.exe] => (Block) D:\wow\world of warcraft\_retail_\utils\wowvoiceproxy.exe => No File
FirewallRules: [UDP Query User{4245329E-3F96-494E-98D5-51969B2AD0C1}D:\wow\world of warcraft\_retail_\utils\wowvoiceproxy.exe] => (Block) D:\wow\world of warcraft\_retail_\utils\wowvoiceproxy.exe => No File
FirewallRules: [TCP Query User{F9D7A1E2-1782-4918-BC26-CA65BA67399B}C:\games\remnantfromtheashes\remnant\binaries\win64\remnant-win64-shipping.exe] => (Allow) C:\games\remnantfromtheashes\remnant\binaries\win64\remnant-win64-shipping.exe => No File
FirewallRules: [UDP Query User{741AEA3C-B865-4B70-9D1D-2896FA3A74B5}C:\games\remnantfromtheashes\remnant\binaries\win64\remnant-win64-shipping.exe] => (Allow) C:\games\remnantfromtheashes\remnant\binaries\win64\remnant-win64-shipping.exe => No File
FirewallRules: [{7E20831B-B78A-4B89-9D42-D3C7619CF949}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\AoE2DE\AoE2DE_s.exe (Wicked Witch Software Pty Ltd -> Microsoft Corporation)
FirewallRules: [{1594742A-8AD9-42C2-974D-43CB046B8C20}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\AoE2DE\AoE2DE_s.exe (Wicked Witch Software Pty Ltd -> Microsoft Corporation)
FirewallRules: [{FD61FFCE-13B0-4922-BE46-17E6C45D66B4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\AoE2DE\BattleServer\BattleServer.exe () [File not signed]
FirewallRules: [{8DBB88CA-5640-493F-BD17-3CA10663B38B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\AoE2DE\BattleServer\BattleServer.exe () [File not signed]
FirewallRules: [{A22677C7-E404-49AC-B3C8-DD9EAA1668E6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Noita\noita.exe () [File not signed]
FirewallRules: [{0B54F61C-CCD6-48DE-8FC7-C6953623F399}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Noita\noita.exe () [File not signed]
FirewallRules: [TCP Query User{2754215C-34EE-42BE-9FF9-3BBC2C1D0BB9}C:\riot games\riot client\riotclientservices.exe] => (Allow) C:\riot games\riot client\riotclientservices.exe (Riot Games, Inc. -> Riot Games, Inc.)
FirewallRules: [UDP Query User{A3EFB2A9-4E5D-4BAF-81EE-1CF0C90C2B84}C:\riot games\riot client\riotclientservices.exe] => (Allow) C:\riot games\riot client\riotclientservices.exe (Riot Games, Inc. -> Riot Games, Inc.)
FirewallRules: [{0B493A93-2ADB-4D41-B890-347A1FD74003}] => (Block) C:\riot games\riot client\riotclientservices.exe (Riot Games, Inc. -> Riot Games, Inc.)
FirewallRules: [{486EA790-5175-49A2-9261-B807BB79E3F5}] => (Block) C:\riot games\riot client\riotclientservices.exe (Riot Games, Inc. -> Riot Games, Inc.)
FirewallRules: [{9816A4D5-6410-402E-B73A-757852C5111F}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe => No File
FirewallRules: [{DBBD58FB-73A3-444A-93FA-A3177BA7DFDE}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe => No File
FirewallRules: [{96BD2D8A-B7E9-40C6-AF90-DEC42D7B3816}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\They Are Billions\TheyAreBillions.exe (Numantian Games) [File not signed]
FirewallRules: [{0A466FD4-E77E-40AD-AE8C-EA602CD37F09}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\They Are Billions\TheyAreBillions.exe (Numantian Games) [File not signed]
FirewallRules: [{567B1C37-8825-41D2-A403-018F7F62F0E5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\This War of Mine\This War of Mine.exe () [File not signed]
FirewallRules: [{9C33709A-BDCF-4299-9FC6-F0427F7D7BE0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\This War of Mine\This War of Mine.exe () [File not signed]
FirewallRules: [{5C8346D8-F9E0-4DD4-ABEC-25A6E1E4504E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\This War of Mine\Storyteller.exe () [File not signed]
FirewallRules: [{F59F23CA-1FCF-4335-A706-011A92D857B7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\This War of Mine\Storyteller.exe () [File not signed]
FirewallRules: [{D0D4DD30-DF5E-4E47-AB15-1F3D9EE88A95}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\the witcher 2\Launcher.exe (CD Projekt RED) [File not signed]
FirewallRules: [{66C760C9-AA24-434B-978A-6FC85267E3ED}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\the witcher 2\Launcher.exe (CD Projekt RED) [File not signed]
FirewallRules: [TCP Query User{F41BA5BF-F8C1-4883-8B0A-C1B5D5F19838}C:\program files (x86)\steam\steamapps\common\the witcher 2\bin\witcher2.exe] => (Block) C:\program files (x86)\steam\steamapps\common\the witcher 2\bin\witcher2.exe () [File not signed]
FirewallRules: [UDP Query User{5AE5D00C-7ED9-45DB-A959-DC53EA80DAD6}C:\program files (x86)\steam\steamapps\common\the witcher 2\bin\witcher2.exe] => (Block) C:\program files (x86)\steam\steamapps\common\the witcher 2\bin\witcher2.exe () [File not signed]
FirewallRules: [{853B7907-0F91-47E4-8109-63BA4F0D85CA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\HeroSiege\bin\Hero_Siege.exe (Panic Art Studios) [File not signed]
FirewallRules: [{F6A8B982-0C48-4324-B2EE-753488B453DA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\HeroSiege\bin\Hero_Siege.exe (Panic Art Studios) [File not signed]
FirewallRules: [TCP Query User{F43561CE-54E7-478A-839B-99111D245B86}C:\users\peete\appdata\roaming\gameranger\gameranger\gameranger.exe] => (Allow) C:\users\peete\appdata\roaming\gameranger\gameranger\gameranger.exe => No File
FirewallRules: [UDP Query User{53E22C30-A062-4ADE-8030-C73F1810FCD5}C:\users\peete\appdata\roaming\gameranger\gameranger\gameranger.exe] => (Allow) C:\users\peete\appdata\roaming\gameranger\gameranger\gameranger.exe => No File
FirewallRules: [{67EEB8F0-AA9F-4C0F-A247-17332A88841D}] => (Block) C:\users\peete\appdata\roaming\gameranger\gameranger\gameranger.exe => No File
FirewallRules: [{8800C707-E6BE-4883-B0B9-4B6897D5A493}] => (Block) C:\users\peete\appdata\roaming\gameranger\gameranger\gameranger.exe => No File
FirewallRules: [TCP Query User{E5CDF5D9-ED5E-43DE-84FD-8CE0F2AA5641}C:\users\peete\appdata\local\programs\w3champions\resources\app.asar.unpacked\flo-worker.exe] => (Allow) C:\users\peete\appdata\local\programs\w3champions\resources\app.asar.unpacked\flo-worker.exe (Deespul LLC -> Ke Xu)
FirewallRules: [TCP Query User{32F1E383-B66B-4324-9C8C-925BE111C155}C:\users\peete\appdata\local\programs\w3champions\w3champions.exe] => (Allow) C:\users\peete\appdata\local\programs\w3champions\w3champions.exe (Deespul LLC -> Deespul LLC)
FirewallRules: [UDP Query User{8F4E4F3C-FE10-4562-94C7-7CE49558316C}C:\users\peete\appdata\local\programs\w3champions\w3champions.exe] => (Allow) C:\users\peete\appdata\local\programs\w3champions\w3champions.exe (Deespul LLC -> Deespul LLC)
FirewallRules: [{8A2AF1C5-2087-46BF-B93D-CF6348AE917C}] => (Block) C:\users\peete\appdata\local\programs\w3champions\w3champions.exe (Deespul LLC -> Deespul LLC)
FirewallRules: [{0050BAD1-5522-41AE-8FE3-2B6BBF12CC39}] => (Block) C:\users\peete\appdata\local\programs\w3champions\w3champions.exe (Deespul LLC -> Deespul LLC)
FirewallRules: [{116224E9-D144-4112-BDD2-2DBA21DB44C6}] => (Allow) C:\Users\Peete\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{720A9C97-F3F3-47C3-8115-93C684A4202E}] => (Allow) C:\Users\Peete\AppData\Roaming\Zoom\bin\airhost.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{42A14EFF-9245-4328-93A4-4BF12DC2C208}] => (Allow) C:\Users\Peete\AppData\Roaming\Zoom\bin\airhost.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [TCP Query User{BCFD606E-7964-48B5-BFD0-E500192703B9}C:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe] => (Allow) C:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{FF16BA0C-F95D-43C8-963A-FC0EE1477C66}C:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe] => (Allow) C:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [{04F4A476-2704-48E2-81C9-AD299F1CE110}] => (Block) C:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [{A8ED7020-344E-4496-A001-7C22A91EF610}] => (Block) C:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [{6579AFBE-9F28-4C10-8A2B-61432415BC95}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Call of Duty HQ\cod.exe (Activision Publishing Inc -> Activision)
FirewallRules: [{EAD6E361-E1E4-4660-B00D-92EDBC281D8C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Call of Duty HQ\cod.exe (Activision Publishing Inc -> Activision)
FirewallRules: [TCP Query User{CE25C325-30D8-41A9-B8A6-CC2911B6819D}C:\program files (x86)\battle.net\battle.net.exe] => (Allow) C:\program files (x86)\battle.net\battle.net.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [UDP Query User{4E930AB8-55E5-476C-A926-214D977DC097}C:\program files (x86)\battle.net\battle.net.exe] => (Allow) C:\program files (x86)\battle.net\battle.net.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [{EA438674-6974-4F43-9D18-8662792949AC}] => (Block) C:\program files (x86)\battle.net\battle.net.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [{88D3C3A5-FA53-4394-B630-30D7FCE248DF}] => (Block) C:\program files (x86)\battle.net\battle.net.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [{8A14CE11-4C40-41A3-A15C-771EA7554C58}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Grim Dawn\Grim Dawn.exe (Crate Entertainment, LLC) [File not signed]
FirewallRules: [{C8D8EFC6-9046-4351-9024-C0F00694C53F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Grim Dawn\Grim Dawn.exe (Crate Entertainment, LLC) [File not signed]
FirewallRules: [{2A645377-4271-4F33-B786-E4FF928CB52C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Grim Dawn\x64\Grim Dawn.exe (Crate Entertainment, LLC) [File not signed]
FirewallRules: [{7DAE6907-4CEF-47E5-870B-7B959C4F3570}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Grim Dawn\x64\Grim Dawn.exe (Crate Entertainment, LLC) [File not signed]
FirewallRules: [{DDB98DC5-3D4D-450C-9EF3-E0E37DFBF345}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.93.3404.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> )
FirewallRules: [{D298C8D2-BD1C-4337-8C2D-C55063BBA72A}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.93.3404.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> )
FirewallRules: [{97881526-E0C5-4DEF-B2FC-A7FF33FC8A27}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.93.3404.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> )
FirewallRules: [{FABB4D55-D489-430A-9FA0-220CBDE7548B}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.93.3404.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> )
FirewallRules: [{46185136-9935-4A19-A424-9BF64F1295FD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\HeroSiege\bin\start_protected_game.exe (EasyAntiCheat Oy -> Epic Games, Inc.)
FirewallRules: [{5DB5AFEB-F388-4DC0-94D9-C1ABC81B298A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\HeroSiege\bin\start_protected_game.exe (EasyAntiCheat Oy -> Epic Games, Inc.)
FirewallRules: [TCP Query User{B1771009-3271-4C30-9532-3219A2CA9FFB}C:\games\hearthstone\hearthstone.exe] => (Allow) C:\games\hearthstone\hearthstone.exe (Blizzard Entertainment, Inc. -> )
FirewallRules: [UDP Query User{B6DBE339-4C9B-4AC8-B406-93DCB05CA160}C:\games\hearthstone\hearthstone.exe] => (Allow) C:\games\hearthstone\hearthstone.exe (Blizzard Entertainment, Inc. -> )
FirewallRules: [{872B94A6-E3C5-49BC-B39E-35331B43919A}] => (Block) C:\games\hearthstone\hearthstone.exe (Blizzard Entertainment, Inc. -> )
FirewallRules: [{3663C934-7F0E-4EBA-AE2E-C77B93AE1EA9}] => (Block) C:\games\hearthstone\hearthstone.exe (Blizzard Entertainment, Inc. -> )
FirewallRules: [{A1EC1D5A-EB65-4EBA-A578-188D8339CBEA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Sons Of The Forest\SonsOfTheForest.exe () [File not signed]
FirewallRules: [{AE553293-8735-4C8A-9F38-07F83FDF1114}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Sons Of The Forest\SonsOfTheForest.exe () [File not signed]
FirewallRules: [{62408B50-E68C-403F-8CC0-B49F8A419534}] => (Allow) C:\Program Files (x86)\Google\Chrome Remote Desktop\112.0.5615.26\remoting_host.exe (Google LLC -> Google LLC)
FirewallRules: [{FC91B4D2-462C-4A60-AB57-4E45371E8F01}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\112.0.1722.48\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{70DA31C2-AF32-49F7-9279-0ED409F6436A}] => (Allow) C:\Program Files (x86)\Overwolf\0.221.0.4\OverwolfBrowser.exe => No File
FirewallRules: [{9DBF95C1-D1CD-4B06-947B-44AE3D311EB7}] => (Allow) C:\Program Files (x86)\Overwolf\0.221.0.4\OverwolfBrowser.exe => No File
FirewallRules: [{DDF8E111-882D-4266-A9E5-14D014E517CC}] => (Block) C:\Program Files (x86)\Overwolf\0.221.0.4\OverwolfBrowser.exe => No File
FirewallRules: [{AA322EB2-E8F7-43A9-848E-7475D13974A9}] => (Block) C:\Program Files (x86)\Overwolf\0.221.0.4\OverwolfBrowser.exe => No File
FirewallRules: [{0DD2F09D-CE12-46C8-8D3A-C9D622593A0C}] => (Allow) C:\Program Files (x86)\Overwolf\0.221.109.13\OverwolfBrowser.exe (Overwolf Ltd -> Overwolf LTD)
FirewallRules: [{522E3BFB-4B25-456C-B8C4-05D89C7022F1}] => (Allow) C:\Program Files (x86)\Overwolf\0.221.109.13\OverwolfBrowser.exe (Overwolf Ltd -> Overwolf LTD)
FirewallRules: [{EB17FBC4-EB19-4D3A-90DD-D6BE65EF5544}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{0034042C-9E33-477A-820A-58023F8A6C59}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.96.3409.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> )
FirewallRules: [{552CE2E2-5786-4EC6-B371-140FEB2891EB}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.96.3409.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> )
FirewallRules: [{0489B25E-37DE-4A2C-858C-29F352B22C52}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.96.3409.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> )
FirewallRules: [{C69C9DB9-96EE-49AD-95DD-C949A75FD679}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.96.3409.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> )

==================== Restore Points =========================

12-04-2023 22:24:48 Instalační služba modulů systému Windows
20-04-2023 10:44:19 Naplánovaný kontrolní bod
20-04-2023 19:52:24 Removed Nefarius Virtual Gamepad Emulation Bus Driver
20-04-2023 19:52:33 Removed Nefarius Software Solutions e.U. HidHide (x64)
20-04-2023 19:52:57 Removed FakerInput
20-04-2023 19:53:57 Removed PS Remote Play.

==================== Faulty Device Manager Devices ============

Name: Logitech Cordless Device
Description: Logitech Cordless Device
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Logitech Cordless Device
Description: Logitech Cordless Device
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: ========================

Application errors:
==================
Error: (04/17/2023 12:21:36 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na DATA (D:), protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)

Error: (04/10/2023 10:42:27 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na DATA (D:), protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)

Error: (04/02/2023 09:01:46 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na DATA (D:), protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)

Error: (03/25/2023 11:20:16 AM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na DATA (D:), protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)

Error: (03/19/2023 08:15:03 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na DATA (D:), protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)

Error: (03/16/2023 08:40:22 PM) (Source: VSS) (EventID: 12344) (User: )
Description: Chyba služby Stínová kopie svazku: Byla zjištěna chyba 0x00000000c000014d během přípravy registru pro stínovou kopii
nástrojem pro zápis do registru.  Vyhledejte všechny související chyby v protokolech událostí systému a aplikace.


Operace:
   Událost OnFreeze
   Událost zmrazení

Kontext:
   Kontext spuštění: Registry Writer
   Kontext spuštění: Writer
   ID třídy modulu pro zápis: {afbab4a2-367d-4d15-a586-71dbb18f8485}
   Název modulu pro zápis: Registry Writer
   ID instance modulu pro zápis: {c2f3d22e-46ba-420e-9300-939dc5c858a3}

Error: (03/11/2023 03:15:21 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na DATA (D:), protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)

Error: (03/04/2023 01:17:27 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: Optimalizátor úložiště nemohl dokončit opakovat operaci trim na DATA (D:), protože: Požadovaná operace není podporována hardwarem, který zálohuje svazek. (0x8900002A)


System errors:
=============
Error: (04/17/2023 12:09:57 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba CyberGhost8Service neuspěla při spuštění v důsledku následující chyby: 
Systém nemůže nalézt uvedený soubor.

Error: (04/13/2023 01:25:06 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba CyberGhost8Service neuspěla při spuštění v důsledku následující chyby: 
Systém nemůže nalézt uvedený soubor.

Error: (04/03/2023 03:53:43 PM) (Source: volsnap) (EventID: 36) (User: )
Description: Stínové kopie svazku C: byly přerušeny, protože z důvodu limitu stanoveného uživatelem se nepodařilo zvětšit úložiště stínové kopie.

Error: (03/29/2023 04:00:00 PM) (Source: volsnap) (EventID: 36) (User: )
Description: Stínové kopie svazku C: byly přerušeny, protože z důvodu limitu stanoveného uživatelem se nepodařilo zvětšit úložiště stínové kopie.

Error: (03/29/2023 11:02:28 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Instalace se nezdařila: Instalování následující aktualizace se nezdařilo z důvodu chyby (0x80073d02): 9NMPJ99VJBWV-Microsoft.YourPhone.

Error: (03/25/2023 07:37:21 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Steam Client Service neuspěla při spuštění v důsledku následující chyby: 
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.

Error: (03/25/2023 07:37:21 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby Steam Client Service bylo dosaženo časového limitu (30000 ms).

Error: (03/24/2023 10:59:56 AM) (Source: volsnap) (EventID: 36) (User: )
Description: Stínové kopie svazku C: byly přerušeny, protože z důvodu limitu stanoveného uživatelem se nepodařilo zvětšit úložiště stínové kopie.


Windows Defender:
================
Date: 2023-04-20 14:02:15
Description: 
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {CB039E38-701D-422B-8704-CFFCFB3D5404}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2023-04-19 11:46:35
Description: 
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {530CCDFA-4862-4928-81EB-56CB00293952}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2023-04-18 18:38:28
Description: 
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {4D7B97F0-37C9-4254-BFFA-DA2C6D526699}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2023-04-13 00:09:29
Description: 
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {77729CFD-0665-4F3B-ADA5-6011FD35A1BC}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2023-04-12 19:54:56
Description: 
Prohledávání Antivirová ochrana v programu Microsoft Defender bylo zastaveno před dokončením.
ID prohledávání: {E26752EC-B04F-43EB-9D20-968E7D13F619}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM
﻿
CodeIntegrity:
===============
Date: 2023-03-09 12:56:42
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.2301.6-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2023-02-03 11:29:34
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\ProgramData\Microsoft\Windows Defender\Platform\4.18.2211.5-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info =========================== 

BIOS: American Megatrends International, LLC. F14 01/04/2022
Motherboard: Gigabyte Technology Co., Ltd. B550 GAMING X V2
Processor: AMD Ryzen 5 5600X 6-Core Processor 
Percentage of memory in use: 37%
Total physical RAM: 16288.16 MB
Available physical RAM: 10187.67 MB
Total Virtual: 20384.16 MB
Available Virtual: 10320.29 MB

==================== Drives ================================

Drive c: (SYSTEM) (Fixed) (Total:465.13 GB) (Free:26.1 GB) (Model: Samsung SSD 970 EVO Plus 500GB) NTFS
Drive d: (DATA) (Fixed) (Total:465.76 GB) (Free:116.26 GB) (Model: ST500DM002-1BD142) NTFS ==>[system with boot components (obtained from drive)]

\\?\Volume{6aa98ea7-86da-46d3-b10d-bbf33b97c817}\ (Obnovení) (Fixed) (Total:0.52 GB) (Free:0.09 GB) NTFS
\\?\Volume{b5534067-9624-493e-bd24-4c0473233797}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: A6174616)
Partition 1: (Active) - (Size=465.8 GB) - (Type=07 NTFS)

==========================================================
Disk: 1 (Size: 465.8 GB) (Disk ID: 2480B291)

Partition: GPT.

==================== End of Addition.txt =======================