﻿Additional scan result of Farbar Recovery Scan Tool (x64) Version:07-06-2015
Ran by max at 2015-06-08 19:49:29
Running from C:\Users\max\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1046022572-2556649688-4208271907-500 - Administrator - Disabled) => C:\Users\Administrator
Guest (S-1-5-21-1046022572-2556649688-4208271907-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1046022572-2556649688-4208271907-1002 - Limited - Enabled)
max (S-1-5-21-1046022572-2556649688-4208271907-1000 - Administrator - Enabled) => C:\Users\max

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: ESET Smart Security 8.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET Smart Security 8.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
FW: ESET Personální firewall (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Acronis True Image 2015 (HKLM-x32\...\{1BAECCB2-EE26-4FBA-AE66-225F4ADBCFD5}Visible) (Version: 18.0.6525 - Acronis)
Acronis True Image 2015 (x32 Version: 18.0.6525 - Acronis) Hidden
Adobe Flash Player 17 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 17.0.0.188 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.188 - Adobe Systems Incorporated)
Adobe Reader XI - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AB0000000001}) (Version: 11.0.00 - Adobe Systems Incorporated)
Altap Salamander 3.06 (x64) (HKLM\...\Altap Salamander 3.06 (x64)) (Version: 3.06 - ALTAP)
AMD Catalyst Install Manager (HKLM\...\{EDC0E654-60C7-758D-6B81-C8D3ACCEDEE5}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.)
Ashampoo UnInstaller 5 v.5.0.4 (HKLM-x32\...\{4209F371-ABC8-B772-DB8E-93F4772F58FA}_is1) (Version: 5.04.00 - Ashampoo GmbH & Co. KG)
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.16.12.0 - Asmedia Technology)
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.5.5571 - CDBurnerXP)
DAEMON Tools Ultra (HKLM-x32\...\DAEMON Tools Ultra) (Version: 3.0.0.0309 - Disc Soft Ltd)
ESET Smart Security (HKLM\...\{443D1D0A-17E5-4F61-8074-8801BDB430CC}) (Version: 8.0.304.1 - ESET, spol s r. o.)
Java 8 Update 45 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418045F0}) (Version: 8.0.450 - Oracle Corporation)
KMSpico (HKLM\...\{8B29D47F-92E2-4C20-9EE0-F710991F5D7C}_is1) (Version:  - )
Microsoft .NET Framework 4.5.2 (čeština) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUSR) (Version: 15.0.4420.1017 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
MiniTool Partition Wizard Server Edition 9.0 (HKLM-x32\...\{0C286478-1D87-432F-9ADB-5C36FA58BB72}_is1) (Version:  - MiniTool Solution Ltd.)
Nástroje kontroly pravopisu pro Microsoft Office 2013 – čeština (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Nástroje korektúry balíka Microsoft Office 2013 - slovenčina (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.7.8 - Notepad++ Team)
OpenSSL 1.0.2a Light (32-bit) (HKLM-x32\...\OpenSSL Light (32-bit)_is1) (Version:  - OpenSSL Win32 Installer Team)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.67.1226.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7023 - Realtek Semiconductor Corp.)
TL-WN751ND Driver (HKLM-x32\...\{14770694-6C1C-4137-95F9-6F934D8491B4}) (Version: 1.00.0000 - TP-LINK)
Tweak-SSD v2 (HKLM\...\Tweak-SSD v2) (Version: 2.0.1 - Totalidea Software)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.1 - VideoLAN)
WinRAR 5.21 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1046022572-2556649688-4208271907-1000_Classes\CLSID\{C78B614C-F3EA-11D2-94A1-00E0292A01E3}\InprocServer32 -> C:\Program Files\Altap Salamander\utils\salextx64.dll (ALTAP)

==================== Restore Points =========================

ATTENTION: System Restore is disabled

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2015-05-17 18:40 - 00000861 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 activation.acronis.com 

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {53291C68-277A-4C65-BE6A-4045AD58AF56} - System32\Tasks\Bidaily Synchronize Task[973b] => c:\programdata\{8227153a-cf2b-1fb7-8227-7153acf254eb}\setup.exe <==== ATTENTION
Task: {59E1DA46-3169-4ECC-BE16-BFC741AC845A} - System32\Tasks\{5605AF1E-1631-43EF-81FA-6F8C1C67E76B} => pcalua.exe -a E:\Vypal\YTD\ytd-1.47.exe -d E:\Vypal\YTD
Task: {A7D7345C-7AB9-477F-A2DA-8D57A96099AC} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2012-10-01] (Microsoft Corporation)
Task: {A930314F-06E5-4835-9AF3-4364F277CC01} - System32\Tasks\ASUS\RunDAOD => C:\Windows\DAODx.exe [2009-03-30] ()
Task: {AE4C9B74-4F5C-4EF5-8484-A0782EEF75F7} - System32\Tasks\AutoPico Daily Restart => C:\Program Files\KMSpico\AutoPico.exe [2015-02-02] (@ByELDI)
Task: {B307775C-C0A5-44D4-A42A-9419F42D8D0D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
Task: {B31CD839-41F9-45ED-8487-0E680AFDC8AE} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-05-24] (Adobe Systems Incorporated)
Task: {D8B1D300-567E-4716-94EB-80CB21470CCB} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\Bidaily Synchronize Task[973b].job => c:\programdata\{8227153a-cf2b-1fb7-8227-7153acf254eb}\setup.exe <==== ATTENTION

==================== Loaded Modules (Whitelisted) ==============

2015-04-15 22:13 - 2015-04-15 22:13 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll
2009-03-30 08:32 - 2009-03-30 08:32 - 00032768 ____R () C:\Windows\DAODx.exe
2015-05-17 17:27 - 2014-01-15 14:12 - 02343816 _____ () C:\Program Files (x86)\Ashampoo\Ashampoo UnInstaller 5\UI5Guard.exe
2014-12-09 22:09 - 2014-12-09 22:09 - 00037696 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\qt_icontray_ex.dll
2014-12-09 22:10 - 2014-12-09 22:10 - 00034624 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\thread_pool.dll
2014-12-09 22:16 - 2014-12-09 22:16 - 00420160 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\ulxmlrpcpp.dll
2014-12-09 22:12 - 2014-12-09 22:12 - 00129344 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\EXPAT.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1046022572-2556649688-4208271907-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\max\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 10.0.2.254 - 10.0.1.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{17030B79-33EE-430B-ABE8-EAD9B0155F62}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
FirewallRules: [{9CA83BD0-A840-4FB4-8EC8-BF4CE409834F}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
FirewallRules: [{D96F1428-9952-44E7-AD6F-36E6C7D5DF41}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
FirewallRules: [{F2AF7E94-F504-44D1-99E1-2E75C0907FF6}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
FirewallRules: [{C6CA0D87-421B-4AB4-8D7D-4324802352C2}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
FirewallRules: [{20356508-88E9-4568-8BFC-9CC0AC8B4F52}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
FirewallRules: [{64EB6DC0-5285-44DD-9BB2-4133236DD5B1}] => (Allow) LPort=1688
FirewallRules: [{D2DB9A03-0369-48CE-8AA1-1A526340D64A}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe
FirewallRules: [{6B8BF7D3-342C-486D-A09F-9B13E215A10D}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe

==================== Faulty Device Manager Devices =============

Name: Kingmax 16GB
Description: Storage Device  
Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Manufacturer: Generic 
Service: WUDFRd
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (06/08/2015 07:47:43 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
Description: Failed to schedule Software Protection service for re-start at 2015-07-08T17:42:43Z. Error Code: 0x80071A90.

Error: (06/07/2015 08:01:44 PM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
Description: Nepodařilo se naplánovat restartování služby Ochrana softwaru na 2015-07-07T17:55:44Z. Kód chyby: 0x80071A90

Error: (06/07/2015 07:04:07 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
Description: Failed to schedule Software Protection service for re-start at 2015-07-07T16:58:07Z. Error Code: 0x80071A90.

Error: (06/07/2015 05:58:21 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
Description: Failed to schedule Software Protection service for re-start at 2015-07-07T15:43:21Z. Error Code: 0x80071A90.

Error: (06/07/2015 05:58:20 PM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
Description: Nepodařilo se naplánovat restartování služby Ochrana softwaru na 2015-07-07T15:35:20Z. Kód chyby: 0x80071A90

Error: (06/07/2015 03:18:36 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
Description: Failed to schedule Software Protection service for re-start at 2015-07-07T13:12:36Z. Error Code: 0x80071A90.

Error: (06/07/2015 03:18:35 PM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
Description: Nepodařilo se naplánovat restartování služby Ochrana softwaru na 2015-07-07T13:03:35Z. Kód chyby: 0x80071A90

Error: (06/07/2015 02:23:19 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
Description: Failed to schedule Software Protection service for re-start at 2015-07-07T12:17:19Z. Error Code: 0x80071A90.

Error: (06/07/2015 02:23:18 PM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
Description: Nepodařilo se naplánovat restartování služby Ochrana softwaru na 2015-07-07T11:55:18Z. Kód chyby: 0x80071A90

Error: (06/07/2015 00:55:06 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
Description: Failed to schedule Software Protection service for re-start at 2015-07-07T10:49:06Z. Error Code: 0x80071A90.


System errors:
=============
Error: (06/08/2015 07:37:45 PM) (Source: Disk) (EventID: 11) (User: )
Description: Ovladač zjistil chybu řadiče na \Device\Harddisk1\DR1.

Error: (06/08/2015 07:32:47 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Zavedení následujícího ovladače pro spouštění počítače nebo systému se nezdařilo: 
FNETHYRAMKFTS

Error: (06/07/2015 07:46:48 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Zavedení následujícího ovladače pro spouštění počítače nebo systému se nezdařilo: 
FNETHYRAMKFTS

Error: (06/07/2015 06:49:12 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Zavedení následujícího ovladače pro spouštění počítače nebo systému se nezdařilo: 
FNETHYRAMKFTS

Error: (06/07/2015 05:43:25 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Zavedení následujícího ovladače pro spouštění počítače nebo systému se nezdařilo: 
FNETHYRAMKFTS

Error: (06/07/2015 05:36:10 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Zavedení následujícího ovladače pro spouštění počítače nebo systému se nezdařilo: 
FNETHYRAMKFTS

Error: (06/07/2015 05:34:50 PM) (Source: Disk) (EventID: 11) (User: )
Description: Ovladač zjistil chybu řadiče na \Device\Harddisk1\DR1.

Error: (06/07/2015 03:03:40 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Zavedení následujícího ovladače pro spouštění počítače nebo systému se nezdařilo: 
FNETHYRAMKFTS

Error: (06/07/2015 02:08:24 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Zavedení následujícího ovladače pro spouštění počítače nebo systému se nezdařilo: 
FNETHYRAMKFTS

Error: (06/07/2015 02:04:24 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Zavedení následujícího ovladače pro spouštění počítače nebo systému se nezdařilo: 
FNETHYRAMKFTS


Microsoft Office:
=========================
Error: (06/08/2015 07:47:43 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
Description: 0x80071A902015-07-08T17:42:43Z

Error: (06/07/2015 08:01:44 PM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
Description: 0x80071A902015-07-07T17:55:44Z

Error: (06/07/2015 07:04:07 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
Description: 0x80071A902015-07-07T16:58:07Z

Error: (06/07/2015 05:58:21 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
Description: 0x80071A902015-07-07T15:43:21Z

Error: (06/07/2015 05:58:20 PM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
Description: 0x80071A902015-07-07T15:35:20Z

Error: (06/07/2015 03:18:36 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
Description: 0x80071A902015-07-07T13:12:36Z

Error: (06/07/2015 03:18:35 PM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
Description: 0x80071A902015-07-07T13:03:35Z

Error: (06/07/2015 02:23:19 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
Description: 0x80071A902015-07-07T12:17:19Z

Error: (06/07/2015 02:23:18 PM) (Source: Software Protection Platform Service) (EventID: 16385) (User: )
Description: 0x80071A902015-07-07T11:55:18Z

Error: (06/07/2015 00:55:06 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
Description: 0x80071A902015-07-07T10:49:06Z


==================== Memory info =========================== 

Processor: AMD FX(tm)-8300 Eight-Core Processor 
Percentage of memory in use: 18%
Total physical RAM: 8092.35 MB
Available physical RAM: 6606.03 MB
Total Pagefile: 16182.88 MB
Available Pagefile: 14604.87 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:238.37 GB) (Free:212.61 GB) NTFS
Drive e: (Kingmax 16GB) (Removable) (Total:14.81 GB) (Free:7.21 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 238.5 GB) (Disk ID: 5BB3C94E)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=238.4 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 14.8 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=14.8 GB) - (Type=07 NTFS)

==================== End of log ============================