Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-07-2025
Ran by xawie (16-07-2025 15:25:07)
Running from C:\Users\xawie\Downloads
Microsoft Windows 11 Home Version 24H2 26100.4652 (X64) (2025-02-22 09:39:52)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-65323361-3339110103-3339747079-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-65323361-3339110103-3339747079-503 - Limited - Disabled)
Guest (S-1-5-21-65323361-3339110103-3339747079-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-65323361-3339110103-3339747079-504 - Limited - Disabled)
xawie (S-1-5-21-65323361-3339110103-3339747079-1001 - Administrator - Enabled) => C:\Users\xawie

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Genuine Service (HKLM-x32\...\AdobeGenuineService) (Version: 9.0.0.29 - Adobe Inc.)
Adobe Photoshop (Beta) (HKLM\...\{KCF078A9-BA3F-458D-A4A0-3DBB7B169E6S}) (Version: 25.2.0 m.2357 - Adobe)
Adobe Photoshop 2025 (HKLM-x32\...\PHSP_26_1) (Version: 26.1.0.121 - Adobe Inc.)
Advanced Renamer (HKLM\...\Advanced Renamer_is1) (Version: 3.88 - Hulubulu Software)
AMD GPIO2 Driver (HKLM-x32\...\{E9DD399F-21A3-479E-A7DF-D6CF4B2ADBF3}) (Version: 2.2.0.134 - Advanced Micro Devices, Inc.) Hidden
AMD Chipset Software (HKLM-x32\...\AMD_Chipset_IODrivers) (Version: 7.04.09.545 - Advanced Micro Devices, Inc.)
AMD Install Manager (HKLM\...\{8D83B6D7-A61B-469A-B549-38A857A4D4AA}) (Version: 25.10.25126.1755 - Advanced Micro Devices, Inc.)
AMD PCI Driver (HKLM-x32\...\{80EC3CEE-2940-42A1-A776-B5D810D39F1E}) (Version: 1.0.0.9 - Advanced Micro Devices, Inc.) Hidden
AMD PSP Driver (HKLM-x32\...\{988F14B8-79A8-475D-BAC7-83F96AD3D821}) (Version: 5.39.0.0 - Advanced Micro Devices, Inc.) Hidden
AMD Ryzen Balanced Driver (HKLM-x32\...\{A171D320-C42C-4F3B-A2D8-C6A09F6788CC}) (Version: 8.0.0.13 - Advanced Micro Devices, Inc.) Hidden
AMD SBxxx SMBus Driver (HKLM-x32\...\{AAE0E27D-C88A-49BA-8715-77ADCD4286A3}) (Version: 5.12.0.44 - Advanced Micro Devices, Inc.) Hidden
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 25.Q2 - Advanced Micro Devices, Inc.)
AMD_Chipset_Drivers (HKLM-x32\...\{187898e5-7a9e-459f-a0ad-f2344c6f7f39}) (Version: 7.04.09.545 - Advanced Micro Devices, Inc.) Hidden
AniMeVisionFont_MB (HKLM\...\{93E38BA3-9745-4D67-91BC-F65F81523D0A}) (Version: 1.0.1 - ASUSTek Computer Inc.) Hidden
Anno 1800 (HKLM-x32\...\Uplay Install 4553) (Version:  - Ubisoft)
Apple Mobile Device Support (HKLM\...\{4D2C51C8-6939-4BBC-805B-B5B94DB4AE96}) (Version: 18.5.0.13 - Apple Inc.)
ArcGIS Pro (HKLM\...\{E3B1CE52-A1E6-4386-95C4-5AB450EF57BD}) (Version: 2.4.19948 - Environmental Systems Research Institute, Inc.) Hidden
ArcGIS Pro (HKLM\...\ArcGISPro) (Version: 2.4.19948 - Environmental Systems Research Institute, Inc.)
Armoury Crate Service (HKLM\...\Armoury Crate Service) (Version: 6.2.7 - ASUSTeK COMPUTER INC.)
ASUS AIOFan HAL (HKLM\...\{EAE80DED-1A39-41C5-9F60-87CC947F6454}) (Version: 1.4.6.0 - ASUSTeK COMPUTER INC.) Hidden
ASUS AIOFan HAL (HKLM-x32\...\{ec89ca82-ee79-4e81-b2de-dc9328a482f2}) (Version: 1.4.6.0 - ASUSTeK COMPUTER INC.) Hidden
ASUS AURA Extension Card HAL (HKLM\...\{237E1CAC-1708-4940-AC34-DF15C079AB70}) (Version: 1.1.0.20 - ASUSTeK COMPUTER INC.) Hidden
ASUS AURA Extension Card HAL (HKLM-x32\...\{49c4358d-054e-4cf1-9ec1-dca3487f304a}) (Version: 1.1.0.20 - ASUSTeK COMPUTER INC.) Hidden
ASUS AURA Motherboard HAL (HKLM\...\{359B9A9D-A289-4962-BCE2-13EBFD50D532}) (Version: 1.5.0.2 - ASUSTeK COMPUTER INC.) Hidden
ASUS AURA Motherboard HAL (HKLM-x32\...\{00aac91e-7198-484b-b29d-1c9990d843ae}) (Version: 1.5.0.2 - ASUSTeK COMPUTER INC.) Hidden
ASUS Framework Service (HKLM-x32\...\{339A6383-7862-46DA-8A9D-E84180EF9424}) (Version: 4.2.4.3 - ASUSTeK Computer Inc.)
ASUS Motherboard (HKLM-x32\...\{93795eb8-bd86-4d4d-ab27-ff80f9467b37}) (Version: 4.05.06 - ASUSTek Computer Inc.)
ASUS Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.107.139 - ASUSTeK Computer Inc.) Hidden
AURA DRAM Component (HKLM\...\{86D4C8A2-DB22-4948-950D-28DD5145F91C}) (Version: 1.1.29 - ASUS) Hidden
AURA DRAM Component (HKLM-x32\...\{f70a8a88-540d-485d-9aa8-001486fb050e}) (Version: 1.1.29 - ASUS) Hidden
Avast Secure Browser (HKLM-x32\...\Avast Secure Browser) (Version: 137.0.31047.122 - Autoři prohlížeče Avast Secure Browser)
Avast Update Helper (HKLM-x32\...\{19C3AB22-3718-4E4D-B203-242F5001565B}) (Version: 1.8.1697.6 - AVAST Software) Hidden
Balíček ovladače systému Windows - Google, Inc. (WinUSB) AndroidUsbDeviceClass  (08/27/2012 7.0.0000.00004) (HKLM\...\BE156A27AFEAEA39D6A7C9D25CFA8DAFAF91756B) (Version: 08/27/2012 7.0.0000.00004 - Google, Inc.)
Balíček ovladače systému Windows - Google, Inc. (WinUSB) AndroidUsbDeviceClass  (08/27/2012 7.0.0000.00004) (HKLM\...\D43FD4059F47ACA9539247D6CF690AAEA503AF2D) (Version: 08/27/2012 7.0.0000.00004 - Google, Inc.)
Balíček ovladače systému Windows - SAMSUNG Electronics Co., Ltd.  (dg_ssudbus) USB  (12/02/2015 2.12.1.0) (HKLM\...\85A33267F12961AF9ED9AE799DEDA5E62BEA236F) (Version: 12/02/2015 2.12.1.0 - SAMSUNG Electronics Co., Ltd. )
Balíček ovladače systému Windows - SAMSUNG Electronics Co., Ltd.  (ssudmdm) Modem  (12/02/2015 2.12.1.0) (HKLM\...\88ED314360B98E6E82E7CC3201FAEB4A9FD291B4) (Version: 12/02/2015 2.12.1.0 - SAMSUNG Electronics Co., Ltd. )
Balíček ovladače systému Windows - SAMSUNG Electronics Co., Ltd.  (WinUSB) AndroidUsbDeviceClass  (12/02/2015 2.12.1.0) (HKLM\...\701281E8283E9E3681220099A9DA5013A5A437AF) (Version: 12/02/2015 2.12.1.0 - SAMSUNG Electronics Co., Ltd. )
Bandicam (HKLM-x32\...\Bandicam) (Version: 8.1.1.2518 - Bandicam.com)
Bandicam MPEG-1 Decoder (HKLM-x32\...\BandiMPEG1) (Version:  - Bandicam.com)
BlueStacks App Player (HKLM\...\BlueStacks_nxt) (Version: 5.14.22.1003 - now.gg, Inc.)
BlueStacks Services (HKU\S-1-5-21-65323361-3339110103-3339747079-1001\...\BlueStacksServices) (Version: 3.0.9 - now.gg, Inc.)
BlueStacks X (HKU\S-1-5-21-65323361-3339110103-3339747079-1001\...\BlueStacks X) (Version: 10.5.22.1006 - now.gg, Inc.)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
CameraRaw (HKLM\...\{7EC5A83F-98E7-47B7-96DA-D2AD9C3908F9}) (Version: 16.0 - Adobe)
CCleaner (HKLM\...\CCleaner) (Version: 6.37 - Piriform)
Cisco AnyConnect Secure Mobility Client  (HKLM-x32\...\Cisco AnyConnect Secure Mobility Client) (Version: 4.10.07061 - Cisco Systems, Inc.)
Cisco AnyConnect Secure Mobility Client (HKLM-x32\...\{11E16B39-0FA6-4DF0-9736-73BB638C9924}) (Version: 4.10.07061 - Cisco Systems, Inc.) Hidden
Classic Sticky Notes (HKLM\...\Classic Sticky Notes_is1) (Version: 2.0 - Winaero)
Common Desktop Agent (HKLM\...\{031A0E14-0413-4C97-9772-2639B782F46F}) (Version: 1.62.0 - OEM) Hidden
Corel Graphics - Windows Shell Extension (HKLM\...\_{76E381CE-5AD1-4A02-9CF4-B407B1BE9BE0}) (Version: 24.0.0.293 - Corel Corporation)
Corel Graphics - Windows Shell Extension (HKLM\...\{76E381CE-5AD1-4A02-9CF4-B407B1BE9BE0}) (Version: 24.0.293 - Corel Corporation) Hidden
Corel Graphics - Windows Shell Extension 32 Bit Keys (HKLM\...\{98CFADA3-527D-4A92-9160-EE463FCE95A5}) (Version: 24.0.293 - Corel Corporation) Hidden
Corel Update Manager (HKLM\...\{4BAE1A4E-9E7A-4DEB-93DF-F2EB7539C3E2}) (Version: 2.17.698 - Corel corporation) Hidden
CorelDRAW Graphics Suite (HKLM\...\_{1E4B5F2C-0532-4CDA-AFCD-674E9C37521E}) (Version: 24.2.0.444 - Corel Corporation)
CorelDRAW Graphics Suite 2022 - IPM (x64) (HKLM\...\{C3AA2B13-47FD-4A79-8B12-371D41CEBA58}) (Version: 24.2 - Corel Corporation) Hidden
CorelDRAW Graphics Suite 2022 - IPM Content EN (x64) (HKLM\...\{E4106E1B-D15B-4BC1-94E7-F4D8BB5E4E8F}) (Version: 24.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite 2022 - Writing Tools (x64) (HKLM\...\{7DCFAD1B-69CB-4394-8EF6-E2ECECDF098C}) (Version: 24.2 -  Corel Corporation) Hidden
CurseForge (HKU\S-1-5-21-65323361-3339110103-3339747079-1001\...\Overwolf_cchhcaiapeikjbdbpfplgmpobbcdkdaphclbmkbj) (Version: 1.282.1.7170 - Overwolf app)
Discord (HKU\S-1-5-21-65323361-3339110103-3339747079-1001\...\Discord) (Version: 1.0.9003 - Discord Inc.)
EaseUS Data Recovery Wizard (HKLM\...\EaseUS Data Recovery Wizard_is1) (Version:  - EaseUS)
ENE RGB HAL (HKLM\...\{E050E98C-5524-4AFB-9E53-97700BEF2C02}) (Version: 1.1.57.0 - Ene Tech.) Hidden
ENE RGB HAL (HKLM-x32\...\{aed74e04-f110-4d4d-bcfc-e8e9ad5fc0aa}) (Version: 1.1.57.0 - Ene Tech.) Hidden
ENE_EHD_M2_HAL (HKLM\...\{37A48B7F-D4EA-4863-844E-A284E2AA3C5D}) (Version: 1.0.14.0 - ENE TECHNOLOGY INC.) Hidden
ENE_EHD_M2_HAL (HKLM-x32\...\{c1d017c2-8846-4000-9254-5689eccd462e}) (Version: 1.0.14.0 - ENE TECHNOLOGY INC.) Hidden
Epic Games Launcher (HKLM-x32\...\{FAC47927-1A6A-4C6E-AD7D-E9756794A4BC}) (Version: 1.3.23.0 - Epic Games, Inc.)
Epic Online Services (HKLM-x32\...\{758842D2-1538-4008-A8E3-66F65A061C52}) (Version: 2.0.33.0 - Epic Games, Inc.)
ffdshow v1.3.4533 [2014-09-29] (HKLM-x32\...\ffdshow_is1) (Version: 1.3.4533.0 - )
FileZilla 3.65.0 (HKLM-x32\...\FileZilla Client) (Version: 3.65.0 - Tim Kosse)
Folder Size (64-bit) (HKLM\...\{F24FF688-7138-4CCF-A83F-71E9FB01170E}) (Version: 2.6 - Brio)
Ghostscript GPL 8.64 (Msi Setup) (HKLM-x32\...\_{06CD45E6-FF5E-4D8E-BC01-B276A90DADF2}) (Version: 8.64 - Corel Corporation)
Ghostscript GPL 8.64 (Msi Setup) (HKLM-x32\...\{06CD45E6-FF5E-4D8E-BC01-B276A90DADF2}) (Version: 8.64 - Corel Corporation) Hidden
Git (HKLM\...\Git_is1) (Version: 2.50.1 - The Git Development Community)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 138.0.7204.157 - Google LLC)
Hamachi (HKLM-x32\...\{C00E2143-38F2-49BA-AB8A-03F22F02F0A4}) (Version: 2.3.0.111 - LogMeIn, Inc.) Hidden
Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.3.0.111 - LogMeIn, Inc.)
iMyFone D-Back 8.9.6.4 (HKLM-x32\...\{071B9303-5881-4BC6-B9E9-2E2D22C015C1}_is1) (Version: 8.9.6.4 - Shenzhen iMyFone Technology Co., Ltd.)
IntelliJ IDEA Community Edition 2021.3.1 (HKLM-x32\...\IntelliJ IDEA Community Edition 2021.3.1) (Version: 213.6461.79 - JetBrains s.r.o.)
Java 8 Update 451 (64-bit) (HKLM\...\{71024AE4-039E-4CA4-87B4-2F64180451F0}) (Version: 8.0.4510.10 - Oracle Corporation)
Java SE Development Kit 8 Update 311 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180311}) (Version: 8.0.3110.11 - Oracle Corporation)
Java(TM) SE Development Kit 17.0.9 (64-bit) (HKLM\...\{7CD8D9DB-19F2-57B0-8F04-99DA5B3C62D4}) (Version: 17.0.9.0 - Oracle Corporation)
Key Remapper 1.13 (HKLM-x32\...\Key Remapper_is1) (Version: 1.13.0.480 - ATNSOFT)
Kingston AURA DRAM Component (HKLM\...\{965CDF5F-901C-476F-B3A8-7396701B1129}) (Version: 1.1.39 - KINGSTON COMPONENTS INC.) Hidden
Kingston AURA DRAM Component (HKLM-x32\...\{20c88a0d-98f7-40db-b062-3f319a507889}) (Version: 1.1.39 - KINGSTON COMPONENTS INC.) Hidden
Kontrola stavu osobního počítače s Windows (HKLM\...\{E496AFB7-CB04-46CF-8FBB-5D665BC8811B}) (Version: 3.3.2110.22002 - Microsoft Corporation)
Launcher Prerequisites (x64) (HKLM-x32\...\{43a03b9c-4770-409c-a999-587b60700b63}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
League of Legends (HKU\S-1-5-21-65323361-3339110103-3339747079-1001\...\Riot Game league_of_legends.live) (Version:  - Riot Games, Inc)
Malwarebytes version 4.5.19.229 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.5.19.229 - Malwarebytes)
Medal (HKU\S-1-5-21-65323361-3339110103-3339747079-1001\...\Medal) (Version: 4.2790.0 - Medal B.V.)
Microsoft .NET Core Host - 3.1.32 (x64) (HKLM\...\{8A8E3A04-83BC-4CDE-9259-893B666C1AB1}) (Version: 24.192.31915 - Microsoft Corporation) Hidden
Microsoft .NET Core Host FX Resolver - 3.1.31 (x64) (HKLM\...\{4CF84AED-891D-4ECD-93FB-94B58A43F454}) (Version: 24.124.31813 - Microsoft Corporation) Hidden
Microsoft .NET Core Host FX Resolver - 3.1.32 (x64) (HKLM\...\{ABC6B3C2-1A8D-4C5E-AC16-C2AE44F02743}) (Version: 24.192.31915 - Microsoft Corporation) Hidden
Microsoft .NET Core Runtime - 3.1.31 (x64) (HKLM\...\{337A821B-2ED5-42BC-8699-238B600CBB73}) (Version: 24.124.31813 - Microsoft Corporation) Hidden
Microsoft .NET Core Runtime - 3.1.32 (x64) (HKLM\...\{A741B803-3F0E-4684-81EF-FC128D15A92C}) (Version: 24.192.31915 - Microsoft Corporation) Hidden
Microsoft .NET Core Runtime - 3.1.32 (x64) (HKLM-x32\...\{784973c8-d618-4ac8-97ed-1fd52c5bdf2f}) (Version: 3.1.32.31915 - Microsoft Corporation)
Microsoft .NET Host - 6.0.16 (x64) (HKLM\...\{1D0AC7F1-2B34-44AF-91F6-88757D768DA7}) (Version: 48.67.58427 - Microsoft Corporation) Hidden
Microsoft .NET Host - 7.0.17 (x64) (HKLM\...\{089B0F2C-87D9-4470-B6E6-154DD6961C56}) (Version: 56.68.10360 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 6.0.16 (x64) (HKLM\...\{B8537ACA-B210-4DF5-B928-E41CEB76723D}) (Version: 48.67.58427 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 7.0.17 (x64) (HKLM\...\{6B4D3428-4800-446B-971F-62A7377F06F6}) (Version: 56.68.10360 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 6.0.16 (x64) (HKLM\...\{C71E93D2-B8B4-4858-B2A1-4C967DBC1C5F}) (Version: 48.67.58427 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 6.0.16 (x64) (HKLM-x32\...\{2a8d0f2b-911b-4b58-8252-46b29e7a4590}) (Version: 6.0.16.32323 - Microsoft Corporation)
Microsoft .NET Runtime - 7.0.17 (x64) (HKLM\...\{A638EFAE-5229-46A8-9A18-D0FF9D9827D2}) (Version: 56.68.10360 - Microsoft Corporation) Hidden
Microsoft 365 Apps pro velké organizace - cs-cz (HKLM\...\O365ProPlusRetail - cs-cz) (Version: 16.0.18827.20202 - Microsoft Corporation)
Microsoft Access database engine 2016 (English) (HKLM\...\{90160000-00D1-0409-1000-0000000FF1CE}) (Version: 16.0.5044.1000 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 138.0.3351.83 - Microsoft Corporation)
Microsoft Edge WebView2 Runtime (HKLM-x32\...\Microsoft EdgeWebView) (Version: 138.0.3351.83 - Microsoft Corporation) Hidden
Microsoft GameInput (HKLM-x32\...\{1F2B6AF3-C260-8666-5950-E3FEDBC851D6}) (Version: 10.1.22621.3036 - Microsoft Corporation)
Microsoft OneDrive (HKLM\...\OneDriveSetup.exe) (Version: 25.115.0615.0002 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{C6FD611E-7EFE-488C-A0E0-974C09EF6473}) (Version: 5.72.0.0 - Microsoft Corporation)
Microsoft Visual Basic for Applications 7.1 (x64) (HKLM\...\{90120064-0070-0000-0000-4000000FF1CE}) (Version: 7.1.00.00 - Microsoft Corporation) Hidden
Microsoft Visual Basic for Applications 7.1 (x64) English (HKLM\...\{90F60409-7000-11D3-8CFE-0150048383C9}) (Version: 7.1.0.0 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{650c9b4a-60ec-4e4e-8d8e-32d85ce3b7c5}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (HKLM\...\{37B8F9C7-03FB-3253-8781-2517C99D7C00}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (HKLM\...\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\{042d26ef-3dbe-4c25-95d3-4c1b11b235a7}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM-x32\...\{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.36.32532 (HKLM-x32\...\{8bdfe669-9705-4184-9368-db9ce581e0e7}) (Version: 14.36.32532.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.42.34438 (HKLM-x32\...\{b49c10dd-4d54-45f8-ad13-fa25704456a4}) (Version: 14.42.34438.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.36.32532 (HKLM-x32\...\{410c0ee1-00bb-41b6-9772-e12c2828b02f}) (Version: 14.36.32532.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.42.34438 (HKLM-x32\...\{ba10fda9-f731-441f-a999-000bbb7ceec2}) (Version: 14.42.34438.0 - Microsoft Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.42.34438 (HKLM\...\{E528AD94-12D7-42C4-91A3-908BE28E9BD2}) (Version: 14.42.34438 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.42.34438 (HKLM\...\{2E15F519-4FDA-4834-B4EE-7EFCE7D8D4EE}) (Version: 14.42.34438 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.42.34438 (HKLM-x32\...\{A5592FEF-F948-4BA6-A066-8BBFC2DC7EE1}) (Version: 14.42.34438 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.42.34438 (HKLM-x32\...\{5D0C4511-3CA1-4FF8-A4BA-C0E1957ABEEA}) (Version: 14.42.34438 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2019 (HKLM-x32\...\{1edcd8d2-905a-4e93-bfdf-92ed5601528a}) (Version: 16.0.28801 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2019 x64 Hosting Support (HKLM\...\{9D6CE289-E12C-38BB-9999-E2377EC118B7}) (Version: 16.0.28801 - Microsoft Corporation) Hidden
Microsoft Visual Studio Tools for Applications 2019 x86 Hosting Support (HKLM-x32\...\{7C931D41-F302-3494-868C-320A4F4DD9F9}) (Version: 16.0.28801 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 3.1.31 (x64) (HKLM\...\{F3479C10-2CEA-4C17-8C49-5AD92965254D}) (Version: 24.124.31813 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 3.1.31 (x64) (HKLM-x32\...\{2c0fd312-a570-439d-8831-42fe66080acc}) (Version: 3.1.31.31813 - Microsoft Corporation)
Microsoft Windows Desktop Runtime - 7.0.17 (x64) (HKLM\...\{93812F65-BAA9-42E0-AF19-F15F39A92E3C}) (Version: 56.68.10379 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 7.0.17 (x64) (HKLM-x32\...\{24a68a65-6ac6-4276-9d7d-2c3939d8474e}) (Version: 7.0.17.33416 - Microsoft Corporation)
Neural Filters (HKLM\...\{70F9BD38-D373-4CC8-BF4A-414DE0D0C42F}) (Version: 1.15.0.100 - Adobe)
Notepad++ (64-bit x64) (HKLM\...\Notepad++) (Version: 8.8.3 - Notepad++ Team)
NVIDIA PhysX (HKLM-x32\...\{B455E95A-B804-439F-B533-336B1635AE97}) (Version: 9.14.0702 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.18827.20102 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.18827.20202 - Microsoft Corporation) Hidden
OpenVPN 2.6.14-I002 amd64 (HKLM\...\{9BE36F6C-258C-47FD-B966-65D2D0F47E0E}) (Version: 2.6.1402 - OpenVPN, Inc.)
Overwolf (HKLM-x32\...\Overwolf) (Version: 0.276.0.6 - Overwolf Ltd.)
Patriot Viper M2 SSD RGB (HKLM\...\{8B4C0A3D-C135-4E1F-98D8-3926494B4D61}) (Version: 1.1.0.3 - Patriot Memory) Hidden
Patriot Viper M2 SSD RGB (HKLM-x32\...\{6e0eff60-c502-43bb-8f56-360ca07e73d9}) (Version: 1.1.0.3 - Patriot Memory) Hidden
Plagius - Plagiarism Detector 2.4.24 (HKLM-x32\...\{4ADC8FAB-C60F-4984-9DC4-823F344F8AF3}_is1) (Version: 2.4.24 - GH Software Ltda.)
Pomocník s instalací Windows 11 (HKLM-x32\...\{115DF11E-4B4C-4EA9-9A79-00DB0C7EF02D}) (Version: 1.4.19041.1401 - Microsoft Corporation)
PotPlayer-64 bit (HKLM\...\PotPlayer64) (Version: 220905 - Kakao Corp.)
Razer Cortex (64-bit) (HKLM\...\Razer Cortex_is1) (Version: 11.2.10.0 - Razer Inc.)
Razer Synapse (HKLM-x32\...\Razer Synapse) (Version: 3.10.0630.070411 - Razer Inc.)
Riot Client  (HKU\S-1-5-21-65323361-3339110103-3339747079-1001\...\Riot Game Riot_Client.) (Version:  - Riot Games, Inc)
Riot Vanguard (HKLM\...\Riot Vanguard) (Version:  - Riot Games, Inc.)
Rockstar Games Launcher (HKLM-x32\...\Rockstar Games Launcher) (Version: 1.0.55.661 - Rockstar Games)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 2.0.9.3 - Rockstar Games)
ROG Live Service (HKLM\...\{2D87BFB6-C184-4A59-9BBE-3E20CE797631}) (Version: 3.1.15.0 - ASUSTek COMPUTER INC.)
Samsung C2620 Series (HKLM-x32\...\Samsung C2620 Series) (Version: 1.14 (18.07.2017) - Samsung Electronics Co., Ltd.)
Samsung C2670 Series (HKLM-x32\...\Samsung C2670 Series) (Version: 1.11 (21.07.2017) - Samsung Electronics Co., Ltd.)
Samsung Diagnostika tiskárny Samsung (HKLM-x32\...\Samsung Printer Diagnostics) (Version: 1.0.4.29 - HP Printing Korea Co., Ltd.)
Samsung Easy Printer Manager (HKLM-x32\...\Samsung Easy Printer Manager) (Version: 2.00.01.35 - HP Inc.)
Samsung Scan Process Machine (HKLM-x32\...\Samsung Scan Process Machine) (Version: 1.03.05.28 - Samsung Electronics Co., Ltd.) Hidden
SimSync Launcher 0.4.3 (HKU\S-1-5-21-65323361-3339110103-3339747079-1001\...\da313879-5037-5841-a9df-e8fb817718b4) (Version: 0.4.3 - SimSync)
SketchUp Language Pack [cs] (HKLM\...\{ca0041d2-4059-4b49-733d-708944038fd1}) (Version: 22.0.354 - Název společnosti:) Hidden
SketchUp Pro 2022 (HKLM-x32\...\{c631706c-1735-11ec-9621-0242ac130015}) (Version: 22.0.354 - Trimble, Inc.)
SketchUpPro 2022 (HKLM\...\{898ed298-4bc7-f67e-2e5b-6202a980787a}) (Version: 22.0.354.126 - Název společnosti:) Hidden
SmartShare (HKLM-x32\...\{BAB337AE-DD9E-45C3-BED6-0EE4732AEC60}) (Version: 2.3.1712.1202 - LG Electronics Inc.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Teams Machine-Wide Installer (HKLM-x32\...\{731F6BAA-A986-45A4-8936-7C3AAAAA760B}) (Version: 1.5.0.30767 - Microsoft Corporation)
TLauncher (HKLM-x32\...\TLauncher) (Version: 2.9323 - TLauncher Inc.)
U.GG 1.15.4 (HKU\S-1-5-21-65323361-3339110103-3339747079-1001\...\aca90cad-9059-53b1-8dc9-f846273ebdf3) (Version: 1.15.4 - Outplayed, Inc.)
Ubisoft Connect (HKLM-x32\...\Uplay) (Version: 139.2.10843 - Ubisoft)
UE Prerequisites (x64) (HKLM\...\{7A117EE9-1DCA-4DF2-816B-6810A95D67C5}) (Version: 1.0.22.0 - Epic Games, Inc.) Hidden
UE Prerequisites (x64) (HKLM-x32\...\{7675c6c6-b4bd-4206-855e-5e39d89ea708}) (Version: 1.0.22.0 - Epic Games, Inc.) Hidden
uTorrent Web (HKU\S-1-5-21-65323361-3339110103-3339747079-1001\...\utweb) (Version: 1.5.0 - BitTorrent Limited)
UXP WebView Support (HKLM-x32\...\UXPW_1_0_0) (Version: 1.0.0 - Adobe Inc.)
VALORANT (HKU\S-1-5-21-65323361-3339110103-3339747079-1001\...\Riot Game valorant.live) (Version:  - Riot Games, Inc)
Vector Magic (HKLM-x32\...\Vector Magic) (Version: 1.15 - Vector Magic, Inc.)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.21 - VideoLAN)
Voicemeeter, The Virtual Mixing Console (HKLM-x32\...\VB:Voicemeeter {17359A74-1236-5467}) (Version:  - VB-Audio Software)
WD_BLACK AN1500 (HKLM\...\{085E2365-0A70-4230-B664-02D5E4FE7E9C}) (Version: 1.0.14.0 - ENE TECHNOLOGY INC.) Hidden
WD_BLACK AN1500 (HKLM-x32\...\{e42c5874-37b0-4977-9e8d-70bf006e1f76}) (Version: 1.0.14.0 - ENE TECHNOLOGY INC.) Hidden
Webshare klient (HKLM-x32\...\Webshare klient) (Version:  - )
Windows Movie Maker 2022 (HKLM\...\{9CC29C6A-B5FE-497B-8F23-52A2557A92C0}}_is1) (Version:  - VideoWin)
WinHTTrack Website Copier 3.49-2 (x64) (HKLM\...\WinHTTrack Website Copier_is1) (Version: 3.49.2 - HTTrack)
WinRAR 6.11 (64-bit) (HKLM\...\WinRAR archiver) (Version: 6.11.0 - win.rar GmbH)
Wondershare Filmora 12(Build 12.0.9.1382) (HKU\S-1-5-21-65323361-3339110103-3339747079-1001\...\Wondershare Filmora 12_is1) (Version:  - Wondershare Software)
Wondershare NativePush(Build 1.0.0.7) (HKU\S-1-5-21-65323361-3339110103-3339747079-1001\...\Wondershare NativePush_is1) (Version:  - )
X-Mouse Button Control 2.19.2 (HKLM-x32\...\X-Mouse Button Control) (Version: 2.19.2 - Highresolution Enterprises)

Chrome apps:
============
Prismarine Web Client (HKU\S-1-5-21-65323361-3339110103-3339747079-1001\...\4e84a268555c87d844c3630e0fe9c1e2) (Version: 1.0 - Google\Chrome)

Packages:
=========
@{MicrosoftWindows.55182690.Taskbar_1000.26100.3775.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.55182690.Taskbar/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.55182690.Taskbar_cw5n1h2txyewy [2025-06-07] ()
@{MicrosoftWindows.55182690.Taskbar_1000.26100.3912.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.55182690.Taskbar/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.55182690.Taskbar_cw5n1h2txyewy [2025-06-07] ()
@{MicrosoftWindows.57074904.InpApp_1000.26100.4484.0_x64__cw5n1h2txyewy?ms-resource://MicrosoftWindows.57074904.InpApp/Resources/ProductPkgDisplayName} -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.57074904.InpApp_cw5n1h2txyewy [2025-07-15] (Microsoft Windows)
Armoury Crate -> C:\Program Files\WindowsApps\B9ECED6F.ArmouryCrate_6.2.11.0_x64__qmba6cd70vzyy [2025-07-02] (ASUSTeK COMPUTER INC.)
Balíček prostředí funkcí systému Windows -> C:\WINDOWS\SystemApps\SxS\MicrosoftWindows.57074904.InpApp_cw5n1h2txyewy [2025-07-15] (Microsoft Windows)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_160.1.1192.0_x64__v10z8vjag6ke6 [2025-07-03] (HP Inc.)
Microsoft Family -> C:\Program Files\WindowsApps\MicrosoftCorporationII.MicrosoftFamily_0.2.40.0_x64__8wekyb3d8bbwe [2023-09-15] (Microsoft Corp.)
Minecraft for Windows -> C:\Program Files\WindowsApps\Microsoft.MinecraftUWP_1.21.9401.0_x64__8wekyb3d8bbwe [2025-07-15] (Microsoft Studios)
Minecraft Launcher -> C:\Program Files\WindowsApps\Microsoft.4297127D64EC6_2.2.2.0_x64__8wekyb3d8bbwe [2025-02-19] (Microsoft Studios)
Minecraft: Java Edition -> C:\Program Files\WindowsApps\Microsoft.MinecraftJavaEdition_1.0.5.0_x64__8wekyb3d8bbwe [2023-07-19] (Microsoft Studios)
Notepad++ -> C:\Program Files\Notepad++\contextMenu [2025-07-15] (Notepad++)
Samsung Printer Experience -> C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCO.LTD.SamsungPrinterExperience_1.3.15.0_x64__3c1yjt4zspk6g [2022-02-06] (Samsung Electronics Co. Ltd.)
Two Point Campus -> C:\Program Files\WindowsApps\7904SEGAEuropeLtd.TwoPointCampus_10.2.13553.0_x64__zs7esxpzd8d5c [2024-04-08] (SEGA Europe Ltd)
WhatsApp -> C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2527.2.0_x64__cv1g1gvanyjgm [2025-07-14] (WhatsApp Inc.) [Startup Task]
WinAppRuntime.Main.1.5 -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Main.1.5_5001.373.1736.0_x64__8wekyb3d8bbwe [2025-01-29] (Microsoft Corp.)
WinAppRuntime.Singleton -> C:\Program Files\WindowsApps\MicrosoftCorporationII.WinAppRuntime.Singleton_7000.522.1444.0_x64__8wekyb3d8bbwe [2025-06-26] (Microsoft Corp.)
WinRAR -> C:\Program Files\WinRAR [2023-01-12] (win.rar GmbH)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-65323361-3339110103-3339747079-1001_Classes\CLSID\{21e5e993-2836-c1a8-d5f0-473d156b50b0}\localserver32 -> C:\Program Files (x86)\Razer\Razer Cortex\RazerCortex.exe (Razer USA Ltd. -> Razer Inc.)
ShellIconOverlayIdentifiers: [    OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\25.115.0615.0002\FileSyncShell64.dll [2025-07-15] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [    OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\25.115.0615.0002\FileSyncShell64.dll [2025-07-15] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [    OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\25.115.0615.0002\FileSyncShell64.dll [2025-07-15] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [    OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\25.115.0615.0002\FileSyncShell64.dll [2025-07-15] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [    OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\25.115.0615.0002\FileSyncShell64.dll [2025-07-15] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [    OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\25.115.0615.0002\FileSyncShell64.dll [2025-07-15] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [    OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\25.115.0615.0002\FileSyncShell64.dll [2025-07-15] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [   AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2022-01-24] (Adobe Inc. -> )
ShellIconOverlayIdentifiers: [   AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2022-01-24] (Adobe Inc. -> )
ShellIconOverlayIdentifiers: [   AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2022-01-24] (Adobe Inc. -> )
ShellIconOverlayIdentifiers-x32: [    OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\25.115.0615.0002\FileSyncShell64.dll [2025-07-15] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [    OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\25.115.0615.0002\FileSyncShell64.dll [2025-07-15] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [    OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\25.115.0615.0002\FileSyncShell64.dll [2025-07-15] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [    OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\25.115.0615.0002\FileSyncShell64.dll [2025-07-15] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [    OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\25.115.0615.0002\FileSyncShell64.dll [2025-07-15] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [    OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\25.115.0615.0002\FileSyncShell64.dll [2025-07-15] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [    OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\25.115.0615.0002\FileSyncShell64.dll [2025-07-15] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\25.115.0615.0002\FileSyncShell64.dll [2025-07-15] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2022-01-24] (Adobe Inc. -> )
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-01-12] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\25.115.0615.0002\FileSyncShell64.dll [2025-07-15] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\25.115.0615.0002\FileSyncShell64.dll [2025-07-15] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2022-01-24] (Adobe Inc. -> )
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2023-01-12] (Malwarebytes Inc. -> Malwarebytes)

==================== Codecs (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Drivers32: [vidc.mjpg] => C:\WINDOWS\system32\bdmjpeg64.dll [75248 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [vidc.mpeg] => C:\WINDOWS\system32\bdmpegv64.dll [75272 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [msacm.bdmpeg] => C:\WINDOWS\system32\bdmpega64.acm [75784 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [VIDC.FFDS] => C:\Windows\SysWOW64\ff_vfw.dll [112640 2014-09-29] () [File not signed]
HKLM\...\Drivers32: [vidc.mjpg] => C:\Windows\SysWOW64\bdmjpeg.dll [71152 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [vidc.mpeg] => C:\Windows\SysWOW64\bdmpegv.dll [71176 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [msacm.bdmpeg] => C:\Windows\SysWOW64\bdmpega.acm [71176 2017-01-26] (Bandicam Company -> )

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

ShortcutWithArgument: C:\Users\xawie\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_ahajeklejcjgaiekhphgnhppakflchcb\Prismarine Web Client.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=ahajeklejcjgaiekhphgnhppakflchcb
ShortcutWithArgument: C:\Users\xawie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\Prismarine Web Client.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=ahajeklejcjgaiekhphgnhppakflchcb
ShortcutWithArgument: C:\Users\xawie\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\225bb61db2f318c1\Jan - Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 3"

==================== Loaded Modules (Whitelisted) =============

2022-10-15 15:57 - 2022-08-17 10:59 - 000194048 _____ () [File not signed] C:\Program Files (x86)\EaseUS\ENS\libssh2.dll
2022-10-15 15:57 - 2022-08-17 10:59 - 000509064 _____ (CHENGDU YIWO Tech Development Co., Ltd. -> ) [File not signed] C:\Program Files (x86)\EaseUS\ENS\AliyunWrap.DLL
2022-10-15 15:57 - 2022-08-17 10:59 - 000140176 _____ (CHENGDU YIWO Tech Development Co., Ltd. -> ) [File not signed] C:\Program Files (x86)\EaseUS\ENS\EnsHelper.dll
2022-10-15 15:57 - 2022-08-17 10:59 - 000021672 _____ (CHENGDU YIWO Tech Development Co., Ltd. -> ) [File not signed] C:\Program Files (x86)\EaseUS\ENS\fsclog.dll
2022-10-15 15:57 - 2022-08-17 10:59 - 000097168 _____ (CHENGDU YIWO Tech Development Co., Ltd. -> ) [File not signed] C:\Program Files (x86)\EaseUS\ENS\register.dll
2022-10-15 15:57 - 2022-08-17 10:59 - 000461448 _____ (CHENGDU YIWO Tech Development Co., Ltd. -> ) [File not signed] C:\Program Files (x86)\EaseUS\ENS\wpnr.dll
2024-04-24 20:28 - 2024-04-24 20:28 - 000126976 ____N (Microsoft Corporation) [File not signed] C:\WINDOWS\SYSTEM32\UpdatePolicyScenarioReliabilityAggregator.dll
2025-07-09 01:41 - 2025-07-09 01:41 - 000382976 _____ (Notepad++ -> Bjarke I. Pedersen gurli@gurlinet.dk) [File not signed] C:\Program Files\Notepad++\contextMenu\NppShell.dll
2022-10-15 15:57 - 2022-08-17 10:59 - 000428544 _____ (The curl library, hxxps://curl.se/) [File not signed] C:\Program Files (x86)\EaseUS\ENS\libcurl.dll
2022-10-15 15:57 - 2022-08-17 10:59 - 002523136 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [File not signed] C:\Program Files (x86)\EaseUS\ENS\libcrypto-1_1.dll
2022-10-15 15:57 - 2022-08-17 10:59 - 000531456 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [File not signed] C:\Program Files (x86)\EaseUS\ENS\libssl-1_1.dll

==================== Alternate Data Streams (Whitelisted) ========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\goyslgxe.nnn:7297ACA992 [6874]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk:A1B76439FE [6874]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop 2025.lnk:5D18ABA0CA [6874]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks 5.lnk:088221F38A [6874]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks Multi-Instance Manager.lnk:FE00AE19CB [6874]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epic Games Launcher.lnk:BE32D07BC5 [6874]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk:B96E9B8455 [6874]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk:C5D586BE93 [6874]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote.lnk:60EC9648C0 [6874]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook (classic).lnk:5465085A2F [6874]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook (classic).lnk:BE800952D3 [6874]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk:1DC1525F34 [6874]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk:104946E0EA [6874]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype pro firmy.lnk:204831D10F [6874]
AlternateDataStreams: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk:7AD7FA8AB1 [6874]

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) =============

BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_451\bin\ssv.dll [2025-04-05] (Oracle America, Inc. -> Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_451\bin\jp2ssv.dll [2025-04-05] (Oracle America, Inc. -> Oracle Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-07-15] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-07-15] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-07-15] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-07-15] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-07-15] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-07-15] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2025-07-15] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2025-07-15] (Microsoft Corporation -> Microsoft Corporation)

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-65323361-3339110103-3339747079-1001\...\sharepoint.com -> hxxps://vsb-files.sharepoint.com

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2019-12-03 20:18 - 2024-09-21 11:32 - 000001367 __RSH C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1       localhost 
127.0.0.1                   license.piriform.com
127.0.0.1                   www.license.piriform.com
127.0.0.1                   speccy.piriform.com
127.0.0.1                   www.speccy.piriform.com
127.0.0.1                   recuva.piriform.com
127.0.0.1                   www.recuva.piriform.com
127.0.0.1                   defraggler.piriform.com
127.0.0.1                   www.defraggler.piriform.com
127.0.0.1                   ccleaner.piriform.com
127.0.0.1                   www.ccleaner.piriform.com
127.0.0.1                   license-api.ccleaner.com

==================== Network ===========================

(Currently there is no automatic fix for this section.)

DNS Servers: 192.168.1.1
Windows Firewall is enabled.

Network Binding:
=============
Ethernet: Realtek PCIe GbE Family Controller -> rt68cx21x64.sys
OpenVPN Data Channel Offload: OpenVPN Data Channel Offload -> ovpn-dco.sys
Ethernet 2: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 -> vpnva64-6.sys
OpenVPN Wintun: Wintun Userspace Tunnel -> wintun.sys
Wi-Fi: Intel(R) Wireless-AC 9260 160MHz -> Netwtw08.sys
Síťové připojení Bluetooth: Bluetooth Device (Personal Area Network) -> bthpan.sys
Připojení k místní síti: TAP-Windows Adapter V9 -> tap0901.sys
Ethernet 3: TunnelBear Adapter V9 -> tap-tb-0901.sys
Hamachi: LogMeIn Hamachi Virtual Ethernet Adapter -> Hamdrv.sys
Připojení k místní síti 3: Wintun Userspace Tunnel #2 -> wintun.sys
Panda: TAP-Windows Adapter V9 #2 -> tap0901.sys

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files\Common Files\Oracle\Java\javapath;C:\Program Files (x86)\Common Files\Oracle\Java\java8path;C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\ProgramData\Oracle\Java\javapath;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files\dotnet\;C:\Program Files\Git\cmd
HKU\S-1-5-21-65323361-3339110103-3339747079-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\xawie\OneDrive - VSB-TUO\Obrázky\Eclipse.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows Defender\Features => (TamperProtection: 5) (TamperProtectionSource: 2)
HKLM\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection => (DpaDisabled: 0)
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Program Files (x86)\Adobe
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Program Files\Corel
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Games\Satisfactory Build.12122022
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Users\xawie\AppData\Roaming\Panda\
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Games\Grounded
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Games
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Users\xawie\Downloads\CCleaner Professional 6.27.11214 Incl Patch - KhanPC
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Program Files\CCleaner
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes|acrobat.exe
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes|Antimalware Service Executable
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes|Panda.exe
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes|demon.exe
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes|doom.exe
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes|privoxy.exe
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\TemporaryPaths|\\?\C:\Users\xawie\Downloads\CCleaner v6.37.11523 (x64) (All Editions) + Fix {CracksHash}\Patch Fix\Patch Fix.zip


==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\Run: => "SecurityHealth"
HKLM\...\StartupApproved\Run: => "AdobeGCInvoker-1.0"
HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run: => "Logitech Download Assistant"
HKLM\...\StartupApproved\Run: => "Riot Vanguard"
HKLM\...\StartupApproved\Run: => "XMouseButtonControl"
HKLM\...\StartupApproved\Run: => "CDAServer"
HKLM\...\StartupApproved\Run: => "RazerCortex"
HKLM\...\StartupApproved\Run: => "Delete Cached Standalone Update Binary"
HKLM\...\StartupApproved\Run: => "Delete Cached Update Binary"
HKLM\...\StartupApproved\Run32: => "Acrobat Assistant 8.0"
HKLM\...\StartupApproved\Run32: => "Adobe CCXProcess"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\...\StartupApproved\Run32: => "ATNSOFT Key Remapper"
HKLM\...\StartupApproved\Run32: => "Cisco AnyConnect Secure Mobility Agent for Windows"
HKLM\...\StartupApproved\Run32: => "LogMeIn Hamachi Ui"
HKLM\...\StartupApproved\Run32: => "RazerCortex"
HKLM\...\StartupApproved\Run32: => "Wondershare Helper Compact.exe"
HKLM\...\StartupApproved\Run32: => "TeamsMachineInstaller"
HKLM\...\StartupApproved\Run32: => "CZC.Gaming Hellhound"
HKLM\...\StartupApproved\Run32: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run32: => "AdobeGCInvoker-1.0"
HKLM\...\StartupApproved\Run32: => "SecurityHealth"
HKU\S-1-5-21-65323361-3339110103-3339747079-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning"
HKU\S-1-5-21-65323361-3339110103-3339747079-1001\...\StartupApproved\Run: => "utweb"
HKU\S-1-5-21-65323361-3339110103-3339747079-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-65323361-3339110103-3339747079-1001\...\StartupApproved\Run: => "OpenVPN-GUI"
HKU\S-1-5-21-65323361-3339110103-3339747079-1001\...\StartupApproved\Run: => "Adobe Acrobat Synchronizer"
HKU\S-1-5-21-65323361-3339110103-3339747079-1001\...\StartupApproved\Run: => "Discord"
HKU\S-1-5-21-65323361-3339110103-3339747079-1001\...\StartupApproved\Run: => "EpicGamesLauncher"
HKU\S-1-5-21-65323361-3339110103-3339747079-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_EF26055A53941B8600C4FA645E59D117"
HKU\S-1-5-21-65323361-3339110103-3339747079-1001\...\StartupApproved\Run: => "Synapse3"
HKU\S-1-5-21-65323361-3339110103-3339747079-1001\...\StartupApproved\Run: => "EEDSpeedLauncher"
HKU\S-1-5-21-65323361-3339110103-3339747079-1001\...\StartupApproved\Run: => "AMDNoiseSuppression"
HKU\S-1-5-21-65323361-3339110103-3339747079-1001\...\StartupApproved\Run: => "electron.app.BlueStacks Services"
HKU\S-1-5-21-65323361-3339110103-3339747079-1001\...\StartupApproved\Run: => "Overwolf"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [UDP Query User{D44C0A62-49BB-458B-BB9F-CE469AB88520}C:\games\kingdom.come.deliverance.ii.gold.edition-insaneramzes\bin\win64mastermastersteampgo\kingdomcome.exe] => (Allow) C:\games\kingdom.come.deliverance.ii.gold.edition-insaneramzes\bin\win64mastermastersteampgo\kingdomcome.exe (Warhorse Studios sro) [File not signed]
FirewallRules: [TCP Query User{510AF918-4259-477F-8AA7-4AD8CFE0E74B}C:\games\kingdom.come.deliverance.ii.gold.edition-insaneramzes\bin\win64mastermastersteampgo\kingdomcome.exe] => (Allow) C:\games\kingdom.come.deliverance.ii.gold.edition-insaneramzes\bin\win64mastermastersteampgo\kingdomcome.exe (Warhorse Studios sro) [File not signed]
FirewallRules: [UDP Query User{5093703D-7B9E-4D2F-B08C-8037AA1CDD41}C:\program files\epic games\ue_5.5\engine\binaries\win64\unrealeditor.exe] => (Allow) C:\program files\epic games\ue_5.5\engine\binaries\win64\unrealeditor.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [TCP Query User{DFC08B66-C839-43E8-9535-1DFC298232FD}C:\program files\epic games\ue_5.5\engine\binaries\win64\unrealeditor.exe] => (Allow) C:\program files\epic games\ue_5.5\engine\binaries\win64\unrealeditor.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{FCA8DDEA-80AA-4E90-AB82-1A7297A32F9D}C:\users\xawie\appdata\local\unrealengine\common\unrealtrace\bin\00010015\unrealtraceserver.exe] => (Allow) C:\users\xawie\appdata\local\unrealengine\common\unrealtrace\bin\00010015\unrealtraceserver.exe (Epic Games Inc. -> Epic Games)
FirewallRules: [TCP Query User{FBDA752A-FAC8-4C89-9E42-B6294FE9EEE2}C:\users\xawie\appdata\local\unrealengine\common\unrealtrace\bin\00010015\unrealtraceserver.exe] => (Allow) C:\users\xawie\appdata\local\unrealengine\common\unrealtrace\bin\00010015\unrealtraceserver.exe (Epic Games Inc. -> Epic Games)
FirewallRules: [UDP Query User{E74D98A4-7DF0-42C3-9B9F-8C87FD57F585}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [TCP Query User{E8CD04F0-A02E-4AEE-AB1E-F8CC54C11F4A}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{C25A3E12-AC8A-44D4-B00C-E582A8F4EED4}C:\program files\epic games\helloneighbormodkit\engine\binaries\win64\ue4editor.exe] => (Allow) C:\program files\epic games\helloneighbormodkit\engine\binaries\win64\ue4editor.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [TCP Query User{2265CA1B-C547-4471-BB6B-B141A86C3EAF}C:\program files\epic games\helloneighbormodkit\engine\binaries\win64\ue4editor.exe] => (Allow) C:\program files\epic games\helloneighbormodkit\engine\binaries\win64\ue4editor.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [{87C763C5-4893-4820-95C1-DE081470A47E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LOCKDOWN Protocol\LockdownProtocol.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{22015620-A1B2-4BF9-B25B-4D72D8519325}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LOCKDOWN Protocol\LockdownProtocol.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{EF99F4AE-B35B-48ED-A7DF-28A69EE12A42}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Battlerite Royale\BattleriteRoyale.exe (Stunlock Studios AB -> )
FirewallRules: [{57773E2C-AFAB-458C-A5AB-2ED3564F6D84}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Battlerite Royale\BattleriteRoyale.exe (Stunlock Studios AB -> )
FirewallRules: [{9A45945C-6389-47D3-A68D-BF9F5BDA057E}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{4072F2FB-B4AB-4D70-A3E0-E114604799EA}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [UDP Query User{E3B6D674-E448-429B-98FD-B2A4DB3E44A0}C:\users\xawie\appdata\roaming\utorrent web\utweb.exe] => (Allow) C:\users\xawie\appdata\roaming\utorrent web\utweb.exe (BitTorrent Inc -> BitTorrent Limited)
FirewallRules: [TCP Query User{2AC27CF6-C441-42E8-9C12-8CAFF6B80BF6}C:\users\xawie\appdata\roaming\utorrent web\utweb.exe] => (Allow) C:\users\xawie\appdata\roaming\utorrent web\utweb.exe (BitTorrent Inc -> BitTorrent Limited)
FirewallRules: [{CF245C53-0930-44C8-84E0-9A2CB648035C}] => (Allow) C:\Program Files\BlueStacks_nxt\BlueStacksAppplayerWeb.exe (Now.gg, INC -> The Qt Company Ltd.)
FirewallRules: [{309C22AD-5FF2-4987-86A9-0BD74FC7B9D2}] => (Allow) C:\Program Files\BlueStacks_nxt\HD-Player.exe (Now.gg, INC -> BlueStack Systems)
FirewallRules: [{8649B2DE-4BD2-44B6-82A8-EC01D743D140}] => (Allow) C:\Program Files (x86)\BlueStacks X\Cloud Game.exe (Now.gg, INC -> COMPANY NAME)
FirewallRules: [{A8B1C211-62F0-4EBE-837E-4B5E405D3EEF}] => (Allow) C:\Program Files (x86)\BlueStacks X\BlueStacksWeb.exe (Now.gg, INC -> Bluestack Systems, Inc.)
FirewallRules: [UDP Query User{736474B7-E847-4CFA-B59F-41E9265F83BD}C:\riot games\riot client\riotclientelectron\riot client.exe] => (Allow) C:\riot games\riot client\riotclientelectron\riot client.exe (Riot Games, Inc. -> Riot Games, Inc.)
FirewallRules: [TCP Query User{CDBCC92C-275A-46AE-8C0F-168C96DAB3C7}C:\riot games\riot client\riotclientelectron\riot client.exe] => (Allow) C:\riot games\riot client\riotclientelectron\riot client.exe (Riot Games, Inc. -> Riot Games, Inc.)
FirewallRules: [{A1C5BD56-063A-41B9-A695-F84A0039342C}] => (Allow) C:\Users\xawie\AppData\Roaming\uTorrent Web\utweb.exe (BitTorrent Inc -> BitTorrent Limited)
FirewallRules: [{423B8279-11C8-4DA0-89E4-FD87ED645A49}] => (Allow) C:\Users\xawie\AppData\Roaming\uTorrent Web\utweb.exe (BitTorrent Inc -> BitTorrent Limited)
FirewallRules: [{38915E7B-F4D1-44A0-ABE9-C9908896CC70}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_23306.3309.2530.1346_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{5F19ED53-9A29-4466-94C0-6D1B99318FE5}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_23306.3309.2530.1346_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [UDP Query User{14110887-CA1A-4F60-A33F-D5FCAB408657}C:\users\xawie\appdata\roaming\.minecraft\runtime\java-runtime-gamma\windows\java-runtime-gamma\bin\javaw.exe] => (Allow) C:\users\xawie\appdata\roaming\.minecraft\runtime\java-runtime-gamma\windows\java-runtime-gamma\bin\javaw.exe
FirewallRules: [TCP Query User{515F41FD-8B79-4E15-AF7B-C12603C4BEC1}C:\users\xawie\appdata\roaming\.minecraft\runtime\java-runtime-gamma\windows\java-runtime-gamma\bin\javaw.exe] => (Allow) C:\users\xawie\appdata\roaming\.minecraft\runtime\java-runtime-gamma\windows\java-runtime-gamma\bin\javaw.exe
FirewallRules: [{0922E660-1376-4919-A2CA-93FB33394218}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{C24B5AEC-5F89-4A25-965B-7B055999371E}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{0F99E97F-70CA-4779-8495-DAB09A55FE9B}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Anno 1800\Bin\Win64\Anno1800.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [UDP Query User{706A1374-6AAA-480C-9E52-3F81A1C1B434}C:\riot games\valorant\live\shootergame\binaries\win64\valorant-win64-shipping.exe] => (Allow) C:\riot games\valorant\live\shootergame\binaries\win64\valorant-win64-shipping.exe () [File not signed]
FirewallRules: [TCP Query User{60444018-3D06-4A84-B7C4-643F736117CF}C:\riot games\valorant\live\shootergame\binaries\win64\valorant-win64-shipping.exe] => (Allow) C:\riot games\valorant\live\shootergame\binaries\win64\valorant-win64-shipping.exe () [File not signed]
FirewallRules: [{7EA1EDFE-D0B7-4A61-8D79-88C99B2ABDB7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\WitchIt\WitchIt\Binaries\Win64\PropWitchHuntModule-Win64-Shipping.exe (G=Barrel Roll Games) [File not signed]
FirewallRules: [{10EC9740-B230-427C-80D2-F3DD79A5C8B4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\WitchIt\WitchIt\Binaries\Win64\PropWitchHuntModule-Win64-Shipping.exe (G=Barrel Roll Games) [File not signed]
FirewallRules: [{0EC47E85-0D85-4B8E-8DC1-4D28D54471AF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Valheim\valheim.exe () [File not signed]
FirewallRules: [{EBCA9BDB-6653-415E-AA62-71B0A0AA48BA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Valheim\valheim.exe () [File not signed]
FirewallRules: [{B0845135-0A1A-49BA-9027-D128B6F5B021}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{6209185B-2341-4CD9-8C49-EF2B4459D764}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{0BE9DA99-BFD6-4432-B7F6-5CD716B27EE1}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [{C1A6F89A-0D2E-4AB9-B792-E8CA68D82566}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corp. -> Valve Corporation)
FirewallRules: [TCP Query User{3F4E0049-0BC5-45D7-AEDF-28CC041296EA}C:\riot games\riot client\riotclientservices.exe] => (Allow) C:\riot games\riot client\riotclientservices.exe (Riot Games, Inc. -> Riot Games, Inc.)
FirewallRules: [UDP Query User{C6CFC236-7B75-4D2E-AEB5-BDEFD01DF6F4}C:\riot games\riot client\riotclientservices.exe] => (Allow) C:\riot games\riot client\riotclientservices.exe (Riot Games, Inc. -> Riot Games, Inc.)
FirewallRules: [{DFE726D1-6277-4C34-82F8-ABD5BCB7D7C9}] => (Allow) C:\Program Files (x86)\LG Software\LG Smart Share\DMS\SmartShareDMS.exe (LG Electronics Inc. -> LG Electronics Inc.)
FirewallRules: [{96271259-284C-400B-90CF-A80A7221A3F1}] => (Allow) C:\Program Files (x86)\LG Software\LG Smart Share\DMS\SmartShareDMS.exe (LG Electronics Inc. -> LG Electronics Inc.)
FirewallRules: [{25A2B40E-8C21-4D63-A385-F60BFD4D12F9}] => (Allow) C:\Program Files (x86)\LG Software\LG Smart Share\DMR\SmartShareDMR.exe (LG Electronics Inc. -> )
FirewallRules: [{E3D0044B-FD8D-4B92-A0F3-90B2D49C697F}] => (Allow) C:\Program Files (x86)\LG Software\LG Smart Share\DMR\SmartShareDMR.exe (LG Electronics Inc. -> )
FirewallRules: [{54BDCA50-8542-4255-A1D8-B7BB72304435}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Battlerite\Battlerite.exe (Stunlock Studios AB -> )
FirewallRules: [{54F17759-154A-404D-AC5D-863B4327EC78}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Battlerite\Battlerite.exe (Stunlock Studios AB -> )
FirewallRules: [{E3981E15-2100-404E-A7B5-C78032D1729E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\ASTRONEER\Astro.exe (System Era Softworks) [File not signed]
FirewallRules: [{92695108-7F41-4BE7-A261-7F27022CD947}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\ASTRONEER\Astro.exe (System Era Softworks) [File not signed]
FirewallRules: [TCP Query User{C4C5DA4C-3149-484D-A44C-86D4C0792A58}C:\program files (x86)\steam\steamapps\common\astroneer\astro\binaries\win64\astro-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\astroneer\astro\binaries\win64\astro-win64-shipping.exe (System Era Softworks) [File not signed]
FirewallRules: [UDP Query User{0FB50FAA-30B6-4053-9BEF-AE0652333054}C:\program files (x86)\steam\steamapps\common\astroneer\astro\binaries\win64\astro-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\astroneer\astro\binaries\win64\astro-win64-shipping.exe (System Era Softworks) [File not signed]
FirewallRules: [TCP Query User{22125393-B8C6-49E3-A75C-A62A6346AF66}C:\users\xawie\appdata\roaming\.minecraft\runtime\java-runtime-beta\windows\java-runtime-beta\bin\javaw.exe] => (Allow) C:\users\xawie\appdata\roaming\.minecraft\runtime\java-runtime-beta\windows\java-runtime-beta\bin\javaw.exe
FirewallRules: [UDP Query User{A619AC9F-3D7D-468D-8F04-7FBCBC395E1F}C:\users\xawie\appdata\roaming\.minecraft\runtime\java-runtime-beta\windows\java-runtime-beta\bin\javaw.exe] => (Allow) C:\users\xawie\appdata\roaming\.minecraft\runtime\java-runtime-beta\windows\java-runtime-beta\bin\javaw.exe
FirewallRules: [TCP Query User{140A9549-C0DD-4152-B4ED-A50066054BAC}C:\program files\jetbrains\intellij idea community edition 2021.3.1\bin\idea64.exe] => (Allow) C:\program files\jetbrains\intellij idea community edition 2021.3.1\bin\idea64.exe (JetBrains s.r.o. -> JetBrains s.r.o.)
FirewallRules: [UDP Query User{35DF8567-F416-4431-8772-A42830E582DA}C:\program files\jetbrains\intellij idea community edition 2021.3.1\bin\idea64.exe] => (Allow) C:\program files\jetbrains\intellij idea community edition 2021.3.1\bin\idea64.exe (JetBrains s.r.o. -> JetBrains s.r.o.)
FirewallRules: [{2C3E0846-A6A4-45A2-BBDF-ECDA9D48860B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Going Medieval\Going Medieval.exe () [File not signed]
FirewallRules: [{E3E00AF9-689C-483A-972C-7B8509A2DD09}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Going Medieval\Going Medieval.exe () [File not signed]
FirewallRules: [{7D276CD6-68AC-4AE6-A79C-A847B33ABF9C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\VRising\VRising.exe (Stunlock Studios AB -> Stunlock Studios)
FirewallRules: [{5745FD42-F3A8-4D01-BEF2-6AAC0D252C57}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\VRising\VRising.exe (Stunlock Studios AB -> Stunlock Studios)
FirewallRules: [TCP Query User{6AD326EA-88ED-401E-9CA6-C2DD4DCC55EA}C:\program files (x86)\steam\steamapps\common\vrising\vrising_server\vrisingserver.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\vrising\vrising_server\vrisingserver.exe (Stunlock Studios AB -> Stunlock Studios)
FirewallRules: [UDP Query User{0B6538F2-D166-432A-9CF3-C1D7489BBF01}C:\program files (x86)\steam\steamapps\common\vrising\vrising_server\vrisingserver.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\vrising\vrising_server\vrisingserver.exe (Stunlock Studios AB -> Stunlock Studios)
FirewallRules: [{5E5E280C-AE00-4F7D-8D4F-768DBA064F3A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Raft\Raft.exe () [File not signed]
FirewallRules: [{E62152EC-ECF6-4EB3-89D1-31A8281A456B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Raft\Raft.exe () [File not signed]
FirewallRules: [TCP Query User{3E50CAC2-7D04-4D63-BAE4-C8EEEDD291C5}C:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe] => (Allow) C:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{12D8DB8A-F874-4F83-986D-5BA2DC3F7EAA}C:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe] => (Allow) C:\program files (x86)\epic games\launcher\engine\binaries\win64\epicwebhelper.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [{A141DC3E-4154-4D6A-B6E5-A156ED51897B}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Samsung Electronics CO., LTD. -> )
FirewallRules: [{8BCF12DF-AFAC-4169-B847-B8A981A6E0D7}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Samsung Electronics CO., LTD. -> )
FirewallRules: [{F1F82A8D-7888-4EF7-A76A-E7E1E2496D4E}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\EasyPrinterManagerV2.exe (HP Development Company, L.P.) [File not signed]
FirewallRules: [{3038B347-715D-4554-B3C7-F0E5B5ADCB2A}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\OrderSupplies.exe (HP Development Company, L.P.) [File not signed]
FirewallRules: [{8BD816B3-513A-402B-A0FD-2496E29DF242}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\EPM2AlertList.exe (HP Development Company, L.P.) [File not signed]
FirewallRules: [{35E34154-713A-4F15-977C-1A8D8919B1DD}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\EPM2Migrator.exe (HP Development Company, L.P.) [File not signed]
FirewallRules: [{DF5D6F57-B28A-41EA-A34F-254A8D056F2F}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Samsung Electronics CO., LTD. -> )
FirewallRules: [TCP Query User{19215C68-4D0E-441A-AE57-D43F942CD737}C:\users\xawie\appdata\roaming\.minecraft\runtime\java-runtime-gamma\windows\java-runtime-gamma\bin\javaw.exe] => (Allow) C:\users\xawie\appdata\roaming\.minecraft\runtime\java-runtime-gamma\windows\java-runtime-gamma\bin\javaw.exe
FirewallRules: [UDP Query User{E3D7C2E0-1CC0-42CD-AE2C-14B8F43FF7ED}C:\users\xawie\appdata\roaming\.minecraft\runtime\java-runtime-gamma\windows\java-runtime-gamma\bin\javaw.exe] => (Allow) C:\users\xawie\appdata\roaming\.minecraft\runtime\java-runtime-gamma\windows\java-runtime-gamma\bin\javaw.exe
FirewallRules: [TCP Query User{535E633E-B453-47FB-BE37-A5F12599C60A}C:\riot games\riot client\riotclientservices.exe] => (Allow) C:\riot games\riot client\riotclientservices.exe (Riot Games, Inc. -> Riot Games, Inc.)
FirewallRules: [UDP Query User{FD84429B-5A9D-49E9-9D55-D42769572029}C:\riot games\riot client\riotclientservices.exe] => (Allow) C:\riot games\riot client\riotclientservices.exe (Riot Games, Inc. -> Riot Games, Inc.)
FirewallRules: [TCP Query User{CCE1462E-B62E-4A69-8BCF-AE0AC9086C96}C:\program files (x86)\steam\steamapps\common\astroneer\astro\binaries\win64\astro-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\astroneer\astro\binaries\win64\astro-win64-shipping.exe (System Era Softworks) [File not signed]
FirewallRules: [UDP Query User{15C59290-26A4-46B4-B737-FAEF46A59758}C:\program files (x86)\steam\steamapps\common\astroneer\astro\binaries\win64\astro-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\astroneer\astro\binaries\win64\astro-win64-shipping.exe (System Era Softworks) [File not signed]
FirewallRules: [{E042D713-981C-4256-8A60-929D820486FE}] => (Allow) C:\Users\xawie\AppData\Local\Packages\B9ECED6F.ArmouryCrate_qmba6cd70vzyy\LocalState\GridUpdateFile\ASUSGCDriverUpdateClient.exe (ASUSTeK COMPUTER INC. -> ASUSTeK Computer Inc.)
FirewallRules: [TCP Query User{5A6186E1-3767-4D95-AD57-FBD63DCC91FF}C:\games\astronomics.build.18339759\astronomics\astronomics.exe] => (Allow) C:\games\astronomics.build.18339759\astronomics\astronomics.exe () [File not signed]
FirewallRules: [UDP Query User{46A1C57D-FD05-4A72-9EDD-E68DA7527938}C:\games\astronomics.build.18339759\astronomics\astronomics.exe] => (Allow) C:\games\astronomics.build.18339759\astronomics\astronomics.exe () [File not signed]
FirewallRules: [TCP Query User{4E20220F-2ADB-4DD5-A592-CB0E5A6BADCD}C:\users\xawie\appdata\roaming\.tlauncher\starter\jre_default\jre-21.0.61-windows-x64\bin\java.exe] => (Allow) C:\users\xawie\appdata\roaming\.tlauncher\starter\jre_default\jre-21.0.61-windows-x64\bin\java.exe
FirewallRules: [UDP Query User{111CB768-BE02-40C0-8D15-3B88203D18E9}C:\users\xawie\appdata\roaming\.tlauncher\starter\jre_default\jre-21.0.61-windows-x64\bin\java.exe] => (Allow) C:\users\xawie\appdata\roaming\.tlauncher\starter\jre_default\jre-21.0.61-windows-x64\bin\java.exe
FirewallRules: [TCP Query User{277EE24D-B5BC-4391-BB3C-2FB06F036776}C:\users\xawie\appdata\roaming\.minecraft\runtime\java-runtime-delta\windows\java-runtime-delta\bin\javaw.exe] => (Allow) C:\users\xawie\appdata\roaming\.minecraft\runtime\java-runtime-delta\windows\java-runtime-delta\bin\javaw.exe
FirewallRules: [UDP Query User{FCA4BDED-126A-42B2-9F83-6184985E745B}C:\users\xawie\appdata\roaming\.minecraft\runtime\java-runtime-delta\windows\java-runtime-delta\bin\javaw.exe] => (Allow) C:\users\xawie\appdata\roaming\.minecraft\runtime\java-runtime-delta\windows\java-runtime-delta\bin\javaw.exe
FirewallRules: [TCP Query User{5C111AFA-8501-479C-8A10-C0C3F4DF8218}C:\users\xawie\appdata\local\medal\app-4.2790.0\medal.exe] => (Allow) C:\users\xawie\appdata\local\medal\app-4.2790.0\medal.exe (Ferox Games B.V. -> Medal B.V.)
FirewallRules: [UDP Query User{4781508E-9F7E-4C9F-AF98-D5146E96F719}C:\users\xawie\appdata\local\medal\app-4.2790.0\medal.exe] => (Allow) C:\users\xawie\appdata\local\medal\app-4.2790.0\medal.exe (Ferox Games B.V. -> Medal B.V.)
FirewallRules: [{C61643B6-3ED4-43EC-B351-12DA85AA003B}] => (Allow) C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
FirewallRules: [{5F22B4BB-393A-425D-9757-93A27797B06C}] => (Allow) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmourySocketServer.exe (ASUSTeK COMPUTER INC. -> ASUSTeK COMPUTER INC.)
FirewallRules: [{1DF353E2-9C4D-4E61-BBEC-C0D9D2065535}] => (Allow) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmouryHtmlDebugServer.exe (ASUSTeK COMPUTER INC. -> ASUS)
FirewallRules: [{969EC7CB-9DF5-4D4D-80FE-00EB309F99DD}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{2A53E2C9-31C7-454F-BFA7-0EAFCAAE4C8B}] => (Allow) C:\Program Files (x86)\Overwolf\0.276.0.6\OverwolfBrowser.exe (Overwolf Ltd -> Overwolf LTD)
FirewallRules: [{B6B7BF0A-6B78-4C06-85DC-3817C07127C6}] => (Allow) C:\Program Files (x86)\Overwolf\0.276.0.6\OverwolfBrowser.exe (Overwolf Ltd -> Overwolf LTD)
FirewallRules: [{99F8164B-022E-4C51-9E56-43BB730F730F}] => (Allow) C:\Program Files\ASUS\ROG Live Service\ROGLiveService.exe (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.)
FirewallRules: [{DDEE235B-B03C-4C35-B2E4-F1B2785C2C0E}] => (Allow) C:\Program Files\ASUS\ROG Live Service\ROGLiveService.exe (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.)
FirewallRules: [{FEF1F932-5D41-470D-AEC7-54AE5741270A}] => (Allow) C:\Program Files\AVAST Software\Browser\Application\AvastBrowser.exe (Avast Software s.r.o. -> Gen Digital Inc.)
FirewallRules: [{FDB39A88-3A10-4BD9-A488-888965D4FBD0}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{1AB0210C-4222-47CF-B801-118C36510B52}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{5A8A2AE5-8818-405E-B5C9-3F8A7AE59594}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{FFA1D38C-9CF2-464E-98CB-BCA2E55487F8}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{91C23659-2046-444B-8448-9A3939573A2F}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)

==================== Restore Points =========================

14-07-2025 13:01:46 Naplánovaný kontrolní bod
15-07-2025 15:19:40 Piriform Driver Updater Restore Point

==================== Faulty Device Manager Devices ============
Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: vpnva
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: LogMeIn Hamachi Virtual Ethernet Adapter
Description: LogMeIn Hamachi Virtual Ethernet Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: LogMeIn Inc.
Service: Hamachi
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: ========================

Application errors:
==================
Error: (07/16/2025 03:16:25 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Inicializace registrace certifikátu SCEP pro WORKGROUP\DESKTOP-N4399C5$ přes https://AMD-KeyId-907d65e9b562315997dd5ad086b2b7598957b92c.microsoftaik.azure.net/templates/Aik/scep se nepovedla:

GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-907d65e9b562315997dd5ad086b2b7598957b92c.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Wed, 16 Jul 2025 13:16:25 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: 068baacc-7723-43f9-909b-a1df903dd68d

Metoda: GET(312ms)
Fáze: GetCACaps
Nenalezeno (404) 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)

Error: (07/16/2025 03:16:24 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Inicializace registrace certifikátu SCEP pro Místní systém přes https://AMD-KeyId-907d65e9b562315997dd5ad086b2b7598957b92c.microsoftaik.azure.net/templates/Aik/scep se nepovedla:

GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-907d65e9b562315997dd5ad086b2b7598957b92c.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Wed, 16 Jul 2025 13:16:24 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: 87d64f28-a858-4d95-938f-6f8a207093eb

Metoda: GET(438ms)
Fáze: GetCACaps
Nenalezeno (404) 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)

Error: (07/15/2025 03:36:00 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Inicializace registrace certifikátu SCEP pro WORKGROUP\DESKTOP-N4399C5$ přes https://AMD-KeyId-907d65e9b562315997dd5ad086b2b7598957b92c.microsoftaik.azure.net/templates/Aik/scep se nepovedla:

GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-907d65e9b562315997dd5ad086b2b7598957b92c.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Tue, 15 Jul 2025 13:35:59 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: 834594f1-fd05-40fa-866d-1e95f878fde4

Metoda: GET(360ms)
Fáze: GetCACaps
Nenalezeno (404) 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)

Error: (07/15/2025 03:35:59 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Inicializace registrace certifikátu SCEP pro Místní systém přes https://AMD-KeyId-907d65e9b562315997dd5ad086b2b7598957b92c.microsoftaik.azure.net/templates/Aik/scep se nepovedla:

GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-907d65e9b562315997dd5ad086b2b7598957b92c.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Tue, 15 Jul 2025 13:35:59 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: 277a36f4-8327-4b87-adfe-2b0a0ba03f8c

Metoda: GET(343ms)
Fáze: GetCACaps
Nenalezeno (404) 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)

Error: (07/15/2025 03:35:59 PM) (Source: CertEnroll) (EventID: 86) (User: NT AUTHORITY)
Description: Inicializace registrace certifikátu SCEP pro WORKGROUP\DESKTOP-N4399C5$ přes https://AMD-KeyId-907d65e9b562315997dd5ad086b2b7598957b92c.microsoftaik.azure.net/templates/Aik/scep se nepovedla:

GetCACaps
GetCACaps: Not Found
{"Message":"The authority \"amd-keyid-907d65e9b562315997dd5ad086b2b7598957b92c.microsoftaik.azure.net\" does not exist."}
HTTP/1.1 404 Not Found
Date: Tue, 15 Jul 2025 13:35:58 GMT
Content-Length: 121
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000;includeSubDomains
x-ms-request-id: 4d4d9d65-00b0-4168-bb40-b46aee632764

Metoda: GET(343ms)
Fáze: GetCACaps
Nenalezeno (404) 0x80190194 (-2145844844 HTTP_E_STATUS_NOT_FOUND)

Error: (07/15/2025 03:24:36 PM) (Source: Application Error) (EventID: 1000) (User: DESKTOP-N4399C5)
Description: Název chybující aplikace: Uninstall CZC.Gaming Hellhound.exe, verze: 1.0.2020.12, časové razítko: 0x00000000
Název chybujícího modulu: Uninstall CZC.Gaming Hellhound.exe, verze: 1.0.2020.12, časové razítko: 0x00000000
Kód výjimky: 0xc0000005
 Posun chyby: 0x00261c4e
ID chybujícího procesu: 0x21bc
Čas spuštění chybující aplikace: 0x1dbf58bcda357d3
Cesta k chybující aplikaci: C:\Program Files (x86)\CZC.Gaming Hellhound\Uninstall CZC.Gaming Hellhound.exe
Cesta k chybujícímu modulu: C:\Program Files (x86)\CZC.Gaming Hellhound\Uninstall CZC.Gaming Hellhound.exe
ID sestavy: f602303b-5565-4c77-9ef1-003837524805
Celý název chybujícího balíčku: 
ID chybující aplikace relativní vzhledem k balíčku:

Error: (07/15/2025 03:19:39 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Chyba služby Stínová kopie svazků: Při dotazu na rozhraní IVssWriterCallback došlo k neočekávané chybě. hr = 0x80070005, Přístup byl odepřen..To je často způsobeno nesprávným nastavením zabezpečení v modulu pro zápis nebo žadateli.


Operace:
   Shromažďování dat modulu pro zápis

Kontext:
   ID třídy modulu pro zápis: {e8132975-6f93-4464-a53e-1050253ae220}
   Název modulu pro zápis: System Writer
   ID instance modulu pro zápis: {2c774b80-6181-4f49-8c6e-e458b813c561}

Error: (07/15/2025 03:00:11 PM) (Source: Application Error) (EventID: 1000) (User: DESKTOP-N4399C5)
Description: Název chybující aplikace: EdgeGameAssist.exe, verze: 0.0.0.0, časové razítko: 0x682f8651
Název chybujícího modulu: Windows.UI.Xaml.dll, verze: 10.0.26100.4484, časové razítko: 0x952d1ac9
Kód výjimky: 0xc000027b
 Posun chyby: 0x000000000010c271
ID chybujícího procesu: 0x3680
Čas spuštění chybující aplikace: 0x1dbf54c8eb55f9c
Cesta k chybující aplikaci: C:\Program Files\WindowsApps\Microsoft.Edge.GameAssist_1.0.3336.0_x64__8wekyb3d8bbwe\EdgeGameAssist.exe
Cesta k chybujícímu modulu: C:\Windows\System32\Windows.UI.Xaml.dll
ID sestavy: 0ae2b701-5ece-4df4-8ca2-78320a344254
Celý název chybujícího balíčku: Microsoft.Edge.GameAssist_1.0.3336.0_x64__8wekyb3d8bbwe
ID chybující aplikace relativní vzhledem k balíčku: App


System errors:
=============
Error: (07/16/2025 03:18:22 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Služba Aktualizace Google (gupdate) neuspěla při spuštění v důsledku následující chyby: 
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.

Error: (07/16/2025 03:18:22 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby Služba Aktualizace Google (gupdate) bylo dosaženo časového limitu (30000 ms).

Error: (07/16/2025 03:16:25 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba GameInput Service byla neočekávaně ukončena. Tento stav nastal již 6krát.

Error: (07/16/2025 03:16:25 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Služba GameInput Service byla ukončena s následující chybou: 
Složený soubor GameInput Service byl vytvořen s novější verzi úložného prostoru.

Error: (07/16/2025 03:16:24 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba GameInput Service byla nečekaně ukončena. Stalo se to 5 krát. Následující opravná akce bude spuštěna za 1000 milisekund: Restartovat službu.

Error: (07/16/2025 03:16:24 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Služba GameInput Service byla ukončena s následující chybou: 
Složený soubor GameInput Service byl vytvořen s novější verzi úložného prostoru.

Error: (07/16/2025 03:16:23 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba GameInput Service byla nečekaně ukončena. Stalo se to 4 krát. Následující opravná akce bude spuštěna za 1000 milisekund: Restartovat službu.

Error: (07/16/2025 03:16:23 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Služba GameInput Service byla ukončena s následující chybou: 
Složený soubor GameInput Service byl vytvořen s novější verzi úložného prostoru.


Windows Defender:
================
Date: 2025-07-15 15:13:33
Description: 
Antivirová ochrana v programu Microsoft Defender śčãп ħăѕ ьèзŉ şтόрφεð ьєƒôřę сбмρľεťіσи.%п %ŧŠčáŉ ĪĐ:%ъ{ABB115EE-9B72-43A3-8077-CDDF1413DD2F}%ⁿ %τŜċâй Ŧуφĕ:%вAntimalwarový program%π %тЅсāπ Рãгåmэтзяŝ:%вRychlé prohledávání%и  %тŰşéѓ:%ъNT AUTHORITY\SYSTEM%ŉ %ŧŜτøр Ѓēāѕσή:%ъЃΡС ¢οлήèĉτìθπ řüņďøщл 

Date: 2025-07-15 14:44:36
Description: 
Antivirová ochrana v programu Microsoft Defender zjistil malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/Keygen!rfn&threatid=2147692398&enterprise=0
Název: HackTool:Win32/Keygen!rfn
Závažnost: Vysoké
Kategorie: Nástroj
Cesta: file:_C:\Users\xawie\Downloads\CCleaner v6.37.11523 (x64) (All Editions) + Fix {CracksHash}\Patch Fix\Patch Fix.zip
Původ detekce: Místní počítač
Typ detekce: Konkrétní
Zdroj detekce: Ochrana v reálném čase
Uživatel: DESKTOP-N4399C5\xawie
Název procesu: C:\Users\xawie\AppData\Roaming\uTorrent Web\utweb.exe
Verze bezpečnostních informací: AV: 1.431.631.0, AS: 1.431.631.0, NIS: 1.431.631.0
Verze modulu: AM: 1.1.25050.6, NIS: 1.1.25050.6 

Date: 2025-07-15 10:44:51
Description: 
Antivirová ochrana v programu Microsoft Defender zjistil malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/Keygen!rfn&threatid=2147692398&enterprise=0
Název: HackTool:Win32/Keygen!rfn
Závažnost: Vysoké
Kategorie: Nástroj
Cesta: file:_C:\Users\xawie\Downloads\CCleaner v6.37.11523 (x64) (All Editions) + Fix {CracksHash}\Patch Fix\Patch Fix.zip
Původ detekce: Místní počítač
Typ detekce: Konkrétní
Zdroj detekce: Ochrana v reálném čase
Uživatel: DESKTOP-N4399C5\xawie
Název procesu: C:\Users\xawie\AppData\Roaming\uTorrent Web\utweb.exe
Verze bezpečnostních informací: AV: 1.431.631.0, AS: 1.431.631.0, NIS: 1.431.631.0
Verze modulu: AM: 1.1.25050.6, NIS: 1.1.25050.6 

Date: 2025-07-15 10:34:58
Description: 
Antivirová ochrana v programu Microsoft Defender śčãп ħăѕ ьèзŉ şтόрφεð ьєƒôřę сбмρľεťіσи.%п %ŧŠčáŉ ĪĐ:%ъ{0C7E2607-9434-4D0A-A97D-E74C98CCA0DA}%ⁿ %τŜċâй Ŧуφĕ:%вAntimalwarový program%π %тЅсāπ Рãгåmэтзяŝ:%вRychlé prohledávání%и  %тŰşéѓ:%ъNT AUTHORITY\SYSTEM%ŉ %ŧŜτøр Ѓēāѕσή:%ъЃΡС ¢οлήèĉτìθπ řüņďøщл 

Date: 2025-07-15 10:09:02
Description: 
Antivirová ochrana v programu Microsoft Defender śčãп ħăѕ ьèзŉ şтόрφεð ьєƒôřę сбмρľεťіσи.%п %ŧŠčáŉ ĪĐ:%ъ{C7B91B48-2A44-41DE-8487-E2DADAA3C50F}%ⁿ %τŜċâй Ŧуφĕ:%вAntimalwarový program%π %тЅсāπ Рãгåmэтзяŝ:%вRychlé prohledávání%и  %тŰşéѓ:%ъNT AUTHORITY\SYSTEM%ŉ %ŧŜτøр Ѓēāѕσή:%ъЃΡС ¢οлήèĉτìθπ řüņďøщл 
﻿Event[0]

Date: 2025-07-15 14:51:19
Description: 
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o obnovení položky z karantény.
Další informace:
https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/Keygen!rfn&threatid=2147692398&enterprise=0
Název: HackTool:Win32/Keygen!rfn
Závažnost: Vysoké
Kategorie: Nástroj
Uživatel: DESKTOP-N4399C5\xawie
Kód chyby: 0x80508014
Popis chyby: Položku v karanténě nelze obnovit. 
Verze bezpečnostních informací: AV: 1.431.631.0, AS: 1.431.631.0
Verze modulu: 1.1.25050.6 

Date: 2025-07-15 14:51:18
Description: 
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o obnovení položky z karantény.
Další informace:
https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/Keygen!rfn&threatid=2147692398&enterprise=0
Název: HackTool:Win32/Keygen!rfn
Závažnost: Vysoké
Kategorie: Nástroj
Uživatel: DESKTOP-N4399C5\xawie
Kód chyby: 0x80508014
Popis chyby: Položku v karanténě nelze obnovit. 
Verze bezpečnostních informací: AV: 1.431.631.0, AS: 1.431.631.0
Verze modulu: 1.1.25050.6 

Date: 2025-07-15 14:51:10
Description: 
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o obnovení položky z karantény.
Další informace:
https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/Keygen!rfn&threatid=2147692398&enterprise=0
Název: HackTool:Win32/Keygen!rfn
Závažnost: Vysoké
Kategorie: Nástroj
Uživatel: DESKTOP-N4399C5\xawie
Kód chyby: 0x80508014
Popis chyby: Položku v karanténě nelze obnovit. 
Verze bezpečnostních informací: AV: 1.431.631.0, AS: 1.431.631.0
Verze modulu: 1.1.25050.6 

Date: 2025-07-15 14:51:08
Description: 
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o obnovení položky z karantény.
Další informace:
https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/Keygen!rfn&threatid=2147692398&enterprise=0
Název: HackTool:Win32/Keygen!rfn
Závažnost: Vysoké
Kategorie: Nástroj
Uživatel: DESKTOP-N4399C5\xawie
Kód chyby: 0x80508014
Popis chyby: Položku v karanténě nelze obnovit. 
Verze bezpečnostních informací: AV: 1.431.631.0, AS: 1.431.631.0
Verze modulu: 1.1.25050.6 

Date: 2025-07-15 14:50:56
Description: 
Antivirová ochrana v programu Microsoft Defender narazil na chybu při pokusu o obnovení položky z karantény.
Další informace:
https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/Keygen!rfn&threatid=2147692398&enterprise=0
Název: HackTool:Win32/Keygen!rfn
Závažnost: Vysoké
Kategorie: Nástroj
Uživatel: DESKTOP-N4399C5\xawie
Kód chyby: 0x80508014
Popis chyby: Položku v karanténě nelze obnovit. 
Verze bezpečnostních informací: AV: 1.431.631.0, AS: 1.431.631.0
Verze modulu: 1.1.25050.6 

CodeIntegrity:
===============
Date: 2025-07-16 15:22:22
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements. 


==================== Memory info =========================== 

BIOS: American Megatrends Inc. 1405 11/19/2019
Motherboard: ASUSTeK COMPUTER INC. PRIME X570-P
Processor: AMD Ryzen 5 3600X 6-Core Processor 
Percentage of memory in use: 9%
Total physical RAM: 130983.71 MB
Available physical RAM: 118107.53 MB
Total Virtual: 139175.71 MB
Available Virtual: 126087.95 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:952.44 GB) (Free:109.1 GB) (Model: XPG GAMMIX S11 Pro) NTFS
Drive d: () (Fixed) (Total:931.51 GB) (Free:462.84 GB) (Model: WDC WD1002FAEX-00Y9A0) NTFS
Drive e: (DATA) (Fixed) (Total:1862.89 GB) (Free:780.66 GB) (Model: ST2000LM007-1R8174) NTFS

\\?\Volume{32949bee-c318-41cc-832b-b759fab91497}\ (Obnovení) (Fixed) (Total:0.52 GB) (Free:0.1 GB) NTFS
\\?\Volume{8f180a30-777a-4351-9cd3-f9356f8de826}\ () (Fixed) (Total:0.8 GB) (Free:0.1 GB) NTFS
\\?\Volume{6805d56e-bd7f-4a4f-9977-5c724f75e684}\ () (Fixed) (Total:0.09 GB) (Free:0.06 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 1DCF2244)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)

==========================================================
Disk: 1 (Size: 1863 GB) (Disk ID: 58D266E8)

Partition: GPT.

==========================================================
Disk: 2 (MBR Code: Windows 7/8/10) (Size: 953.9 GB) (Disk ID: 0459F8B3)

Partition: GPT.

==================== End of Addition.txt =======================