﻿Additional scan result of Farbar Recovery Scan Tool (x64) Version:21-08-2015 03
Ran by Tulop (2015-08-22 08:27:05)
Running from C:\Users\Tulop\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3823212912-1411402344-4175709835-500 - Administrator - Disabled)
Guest (S-1-5-21-3823212912-1411402344-4175709835-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3823212912-1411402344-4175709835-1003 - Limited - Enabled)
Tulop (S-1-5-21-3823212912-1411402344-4175709835-1001 - Administrator - Enabled) => C:\Users\Tulop

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Disabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Digital Editions 4.0 (HKLM-x32\...\Adobe Digital Editions 4.0) (Version: 4.0.3 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.239 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.12) - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.4.144 - Adobe Systems, Inc.)
Aloha TriPeaks (x32 Version: 2.2.0.98 - WildTangent) Hidden
AMD Catalyst Install Manager (HKLM\...\{95EF3DDB-27C8-CDA9-9E72-5EC3F02C1B02}) (Version: 8.0.881.0 - Advanced Micro Devices, Inc.)
Atheros Bluetooth Filter Driver Package (HKLM\...\{026B819B-4D60-4C8B-892D-33A0D8666F60}) (Version: 2.0.0.3 - Atheros Communications)
Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 10.0 - Atheros)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.3.2225 - AVAST Software)
Bejeweled 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Bluetooth Stack for Windows by Toshiba (HKLM\...\{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}) (Version: v9.10.32(T) - TOSHIBA CORPORATION)
Canon Camera Access Library (HKLM-x32\...\CAL) (Version: 8.2.0.1 - )
Canon Camera Window DC_DV 6 for ZoomBrowser EX (HKLM-x32\...\CameraWindowDVC6) (Version: 6.3.0.11 - )
Canon Camera Window MC 6 for ZoomBrowser EX (HKLM-x32\...\CameraWindowMC) (Version: 6.2.0.11 - )
Canon G.726 WMP-Decoder (HKLM-x32\...\Canon G.726 WMP-Decoder) (Version: 1.0.1.3 - )
Canon MovieEdit Task for ZoomBrowser EX (HKLM-x32\...\MovieEditTask) (Version: 2.3.0.19 - )
Canon RAW Image Task for ZoomBrowser EX (HKLM-x32\...\RAW Image Task) (Version: 2.4.0.7 - )
Canon RemoteCapture Task for ZoomBrowser EX (HKLM-x32\...\RemoteCaptureTask) (Version: 1.6.0.9 - )
Canon Utilities EOS Utility (HKLM-x32\...\EOS Utility) (Version: 1.0.4.18 - )
Canon Utilities PhotoStitch (HKLM-x32\...\PhotoStitch) (Version: 3.1.18.42 - )
Canon Utilities ZoomBrowser EX (HKLM-x32\...\ZoomBrowser EX) (Version: 5.7.0.74 - )
CCleaner (HKLM\...\CCleaner) (Version: 5.08 - Piriform)
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.2.4478 - CDBurnerXP)
CyberLink YouCam 6 (HKLM-x32\...\{A9CEDD6E-4792-493e-BB35-D86D2E188A5A}) (Version: 6.0.3918.0 - CyberLink Corp.)
Empress of the Deep - The Darkest Secret (x32 Version: 2.2.0.98 - WildTangent) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 44.0.2403.157 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden
Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.5.2.1001 - Intel Corporation)
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.36 - Irfan Skiljan)
Island Tribe (x32 Version: 2.2.0.98 - WildTangent) Hidden
Java 7 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
Jewel Quest Solitaire 2 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Magic Academy (x32 Version: 2.2.0.98 - WildTangent) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Mozilla Firefox 39.0 (x86 cs) (HKLM-x32\...\Mozilla Firefox 39.0 (x86 cs)) (Version: 39.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
Mozilla Thunderbird 31.7.0 (x86 cs) (HKLM-x32\...\Mozilla Thunderbird 31.7.0 (x86 cs)) (Version: 31.7.0 - Mozilla)
OpenOffice 4.0.1 (HKLM-x32\...\{220C463A-2890-4C7F-B97C-C49FE175B849}) (Version: 4.01.9714 - Apache Software Foundation)
PDF-XChange Editor (HKLM-x32\...\{b703b1ac-a887-4137-9665-4efe9ddebcce}) (Version: 5.5.313.1 - Tracker Software Products (Canada) Ltd.)
PDF-XChange Editor (Version: 5.5.313.1 - Tracker Software Products (Canada) Ltd.) Hidden
Peggle Nights (x32 Version: 2.2.0.98 - WildTangent) Hidden
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden
Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden
Premium Sound HD (HKLM\...\{94F03B8E-CB73-4653-AFE9-79112C01FED2}) (Version: 1.12.4600 - SRS Labs, Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.3.730.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6687 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.8400.30136 - Realtek Semiconductor Corp.)
Seznam Software (HKU\S-1-5-21-3823212912-1411402344-4175709835-1001\...\SeznamInstall) (Version:  - Seznam.cz)
Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
StartW8 1.2.111.0 (HKLM-x32\...\{2FA895E0-C8CF-4216-90AB-C2E21A62BCB1}) (Version: 1.2.111.0 - SODATSW spol. s r. o.)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.7.1026 - SUPERAntiSpyware.com)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.10.5 - Synaptics Incorporated)
TOSHIBA Desktop Assist (HKLM\...\{95CCACF0-010D-45F0-82BF-858643D8BC02}) (Version: 1.00.0007.00002 - Toshiba Corporation)
TOSHIBA eco Utility (HKLM\...\{5944B9D4-3C2A-48DE-931E-26B31714A2F7}) (Version: 2.0.0.6415 - Toshiba Corporation)
TOSHIBA Function Key (HKLM\...\{16562A90-71BC-41A0-B890-D91B0C267120}) (Version: 1.00.6425 - Toshiba Corporation)
TOSHIBA Manuals (HKLM-x32\...\{90FF4432-21B7-4AF6-BA6E-FB8C1FED9173}) (Version: 10.10 - TOSHIBA)
Toshiba Password Utility (HKLM-x32\...\InstallShield_{6D35FF17-A8B3-43D3-917E-5A1F2C3FB628}) (Version: 2.00.910 - Toshiba Corporation)
TOSHIBA PC Health Monitor (HKLM\...\{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}) (Version: 1.8.17.640104 - Toshiba Corporation)
Toshiba Places Icon Utility (HKLM\...\{C991A8C4-307C-4FDD-8AAE-A1BF44881E95}) (Version: 2.1.1 - TOSHIBA)
TOSHIBA Recovery Media Creator (HKLM-x32\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 2.2.0.54043005 - Toshiba Corporation)
TOSHIBA Resolution+ Plug-in for Windows Media Player (HKLM-x32\...\{6CB76C9D-80C2-4CB3-A4CD-D96B239E3F94}) (Version: 1.2.2.00 - TOSHIBA Corporation)
TOSHIBA Service Station (HKLM\...\{B8C8422F-01F1-4791-B084-047AAFF9BFCC}) (Version: 2.4.4 - TOSHIBA)
TOSHIBA System Driver (HKLM-x32\...\{1E6A96A1-2BAB-43EF-8087-30437593C66C}) (Version: 1.00.0012 - Toshiba Corporation)
TOSHIBA System Settings (HKLM-x32\...\{05A55927-DB9B-4E26-BA44-828EBFF829F0}) (Version: 1.00.0002.32002 - Toshiba Corporation)
Toshiba TEMPRO (HKLM-x32\...\{F76F5214-83A8-4030-80C9-1EF57391D72A}) (Version: 4.6.0 - Toshiba Europe GmbH)
TOSHIBA VIDEO PLAYER (HKLM\...\{FF07604E-C860-40E9-A230-E37FA41F103A}) (Version: 5.3.49.124  - Toshiba Corporation)
Unity Web Player (HKU\S-1-5-21-3823212912-1411402344-4175709835-1001\...\UnityWebPlayer) (Version: 5.0.1f1 - Unity Technologies ApS)
Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden
Virtual Villagers 4 - The Tree of Life (x32 Version: 2.2.0.98 - WildTangent) Hidden
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN)
WildTangent Games (HKLM-x32\...\WildTangent toshiba Master Uninstall) (Version: 1.0.3.0 - WildTangent)
WildTangent Games App (Toshiba Games) (x32 Version: 4.0.5.37 - WildTangent) Hidden
WinRAR 5.11 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.11.0 - win.rar GmbH)
Wondershare Dr.Fone for Android(Build 5.4.0.48) (HKLM-x32\...\{1DB91A95-C548-4BA5-9D4C-18C7DEAAC39F}_is1) (Version: 5.4.0.48 - Wondershare Software Co.,Ltd.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3823212912-1411402344-4175709835-1001_Classes\CLSID\{00000001-0E3A-4123-8B32-4B68A91E104A}\InprocServer32 -> C:\Program Files\TOSHIBA\TOSHIBA Places Icon Utility\TosDIBasePlace.dll (Toshiba Corporation)

==================== Restore Points =========================

21-08-2015 13:08:41 PDF-XChange Editor

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2012-07-26 07:26 - 2015-08-21 08:13 - 00450831 ____R C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1	www.007guard.com
127.0.0.1	007guard.com
127.0.0.1	008i.com
127.0.0.1	www.008k.com
127.0.0.1	008k.com
127.0.0.1	www.00hq.com
127.0.0.1	00hq.com
127.0.0.1	010402.com
127.0.0.1	www.032439.com
127.0.0.1	032439.com
127.0.0.1	www.0scan.com
127.0.0.1	0scan.com
127.0.0.1	1000gratisproben.com
127.0.0.1	www.1000gratisproben.com
127.0.0.1	1001namen.com
127.0.0.1	www.1001namen.com
127.0.0.1	100888290cs.com
127.0.0.1	www.100888290cs.com
127.0.0.1	www.100sexlinks.com
127.0.0.1	100sexlinks.com
127.0.0.1	10sek.com
127.0.0.1	www.10sek.com
127.0.0.1	www.1-2005-search.com
127.0.0.1	1-2005-search.com
127.0.0.1	123fporn.info
127.0.0.1	www.123fporn.info
127.0.0.1	123haustiereundmehr.com
127.0.0.1	www.123haustiereundmehr.com
127.0.0.1	123moviedownload.com

There are 1000 more lines.


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {193243E3-6756-4D9A-B25D-C5F7F8D17CBA} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-25] (Adobe Systems Incorporated)
Task: {224B6F82-86CD-40F8-AA43-CD1BB52246E2} - System32\Tasks\TOSHIBA\Service Station => C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe [2012-07-28] (TOSHIBA Corporation)
Task: {32640A3D-5C88-4AFB-B2A6-B44F37999339} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-08-18] (Microsoft Corporation)
Task: {469BAFE6-F3EC-40E9-ADB3-A585CF67BE49} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-07-17] (Piriform Ltd)
Task: {4F3174C7-4D66-4263-B152-6047198EBAAA} - \SomotoUpdateCheckerAutoStart -> No File <==== ATTENTION
Task: {569D2319-7B61-4E09-A560-298F3B5838C4} - System32\Tasks\{6F616D6E-ABFB-4DA7-B2C8-22338B3B141F} => pcalua.exe -a "C:\Program Files (x86)\Advanced Driver Updater\unins000.exe" -c /silent
Task: {5A984CA5-3036-4241-B107-E8D1AF1E6847} - System32\Tasks\Toshiba\CommonNotifier => C:\Program Files (x86)\Toshiba TEMPRO\Toshiba.Tempro.UI.CommonNotifier.exe [2013-07-18] (Toshiba Europe GmbH)
Task: {83136937-8A1B-41C7-AF90-2BC9B449B95B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-01] (Google Inc.)
Task: {9EA6ECF2-33C3-4269-A9E3-8AFF39C2B6B0} - System32\Tasks\{C07AD212-84B0-4345-A599-72011848B150} => pcalua.exe -a "C:\Program Files (x86)\YouTube Accelerator\YTAUninstall.exe"
Task: {B1088997-FA36-42A3-AA85-E7607AB3C595} - System32\Tasks\Synaptics TouchPad Enhancements => \Program Files\Synaptics\SynTP\SynTPEnh.exe [2012-08-18] (Synaptics Incorporated)
Task: {B2418296-B87F-47AF-862C-425C190D8228} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
Task: {B6CCCC83-A0DF-4828-967D-BA99CB047B10} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-01] (Google Inc.)
Task: {CF6B5811-EA09-4B49-A2CB-3995F40DE15C} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe invagent.dll,RunUpdate -noappraiser
Task: {E09D851D-791E-4A2B-A091-4C5D6586221C} - System32\Tasks\{78DAC6AA-3E1E-4670-B78B-E9015C468B1B} => pcalua.exe -a "C:\Program Files (x86)\Advanced System Protector\unins000.exe"
Task: {F2BF15E4-E2B6-4370-A05D-E21110E47C92} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-08-17] (AVAST Software)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

==================== Loaded Modules (Whitelisted) ==============

2011-10-14 00:38 - 2011-10-14 00:38 - 00156672 _____ () C:\Program Files (x86)\TOSHIBA\Password Utility\GFNEXSrv.exe
2012-07-19 04:38 - 2012-07-19 04:38 - 00020904 _____ () C:\Program Files\TOSHIBA\Hotkey\SmoothView.dll
2012-07-19 04:38 - 2012-07-19 04:38 - 00049064 _____ () C:\Program Files\TOSHIBA\Hotkey\Hotkey\FnZ.dll
2015-08-17 16:18 - 2015-08-17 16:18 - 00102864 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2015-08-17 16:18 - 2015-08-17 16:18 - 00123976 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2015-08-20 18:21 - 2015-08-20 18:21 - 02960384 _____ () C:\Program Files\AVAST Software\Avast\defs\15082001\algo.dll
2015-04-22 20:17 - 2015-04-22 20:17 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2012-12-13 05:10 - 2012-06-25 20:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2015-08-21 22:43 - 2015-08-18 07:23 - 01405768 _____ () C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.157\libglesv2.dll
2015-08-21 22:43 - 2015-08-18 07:23 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.157\libegl.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:56E2E879

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com

There are 7868 more restricted sites.

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3823212912-1411402344-4175709835-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Tulop\AppData\Roaming\IrfanView\IrfanView_Wallpaper.bmp
DNS Servers: 192.168.1.250 - 80.251.240.33
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

HKLM\...\StartupApproved\Run: => "Logitech Download Assistant"
HKLM\...\StartupApproved\Run: => "TecoResident"
HKLM\...\StartupApproved\Run: => "RtHDVCpl"
HKLM\...\StartupApproved\Run: => "SRS Premium Sound HD"
HKLM\...\StartupApproved\Run: => "TPUReg"
HKLM\...\StartupApproved\Run32: => "ToshibaDynamicIconUtility"
HKLM\...\StartupApproved\Run32: => "Adobe ARM"
HKLM\...\StartupApproved\Run32: => "StartCCC"
HKLM\...\StartupApproved\Run32: => "SynTPEnh"
HKLM\...\StartupApproved\Run32: => "TCrdMain"
HKLM\...\StartupApproved\Run32: => "TODDMain"
HKLM\...\StartupApproved\Run32: => "TosWaitSrv"
HKLM\...\StartupApproved\Run32: => "TSleepSrv"
HKLM\...\StartupApproved\Run32: => "CleanSetup"
HKLM\...\StartupApproved\Run32: => "SDTray"
HKU\S-1-5-21-3823212912-1411402344-4175709835-1001\...\StartupApproved\Run: => "cz.seznam.software.autoupdate"
HKU\S-1-5-21-3823212912-1411402344-4175709835-1001\...\StartupApproved\Run: => "cz.seznam.software.szndesktop"
HKU\S-1-5-21-3823212912-1411402344-4175709835-1001\...\StartupApproved\Run: => "SUPERAntiSpyware"
HKU\S-1-5-21-3823212912-1411402344-4175709835-1001\...\StartupApproved\Run: => "CCleaner Monitoring"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{A6C2B855-110D-4D12-94EF-98A91805C324}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{2E6ED992-A584-49B0-AD49-1F09DF0114E4}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{546BEDFB-1B4D-4526-9843-D8A7CA165499}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{B0999F4B-FAB6-44AD-B5E0-9DB312043FCA}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{B96C5C72-1F44-4504-915D-B47C6287F2C5}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{CC58E6D8-7A47-4DFF-A878-4466EE3FE0B0}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{9FE28606-1063-44FE-9AE4-C9B38ABEAA8A}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{EB23DD9C-F7B1-4873-9FC3-FBC47148BDA0}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (08/21/2015 04:58:23 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: CALMAIN.exe, verze: 8.2.0.1, časové razítko: 0x442b232e
Název chybujícího modulu: MSVCRT.dll, verze: 7.0.9600.17415, časové razítko: 0x54504b2e
Kód výjimky: 0xc0000005
Posun chyby: 0x0000b3f2
ID chybujícího procesu: 0xb50
Čas spuštění chybující aplikace: 0xCALMAIN.exe0
Cesta k chybující aplikaci: CALMAIN.exe1
Cesta k chybujícímu modulu: CALMAIN.exe2
ID zprávy: CALMAIN.exe3
Úplný název chybujícího balíčku: CALMAIN.exe4
ID aplikace související s chybujícím balíčkem: CALMAIN.exe5

Error: (08/21/2015 02:56:33 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: CALMAIN.exe, verze: 8.2.0.1, časové razítko: 0x442b232e
Název chybujícího modulu: MSVCRT.dll, verze: 7.0.9600.17415, časové razítko: 0x54504b2e
Kód výjimky: 0xc0000005
Posun chyby: 0x0000b3f2
ID chybujícího procesu: 0xb8c
Čas spuštění chybující aplikace: 0xCALMAIN.exe0
Cesta k chybující aplikaci: CALMAIN.exe1
Cesta k chybujícímu modulu: CALMAIN.exe2
ID zprávy: CALMAIN.exe3
Úplný název chybujícího balíčku: CALMAIN.exe4
ID aplikace související s chybujícím balíčkem: CALMAIN.exe5

Error: (08/21/2015 10:39:56 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: IntelMeFWService.exe, verze: 8.1.0.1256, časové razítko: 0x4feb6176
Název chybujícího modulu: unknown, verze: 0.0.0.0, časové razítko: 0x00000000
Kód výjimky: 0xc0000005
Posun chyby: 0x2e183560
ID chybujícího procesu: 0x1064
Čas spuštění chybující aplikace: 0xIntelMeFWService.exe0
Cesta k chybující aplikaci: IntelMeFWService.exe1
Cesta k chybujícímu modulu: IntelMeFWService.exe2
ID zprávy: IntelMeFWService.exe3
Úplný název chybujícího balíčku: IntelMeFWService.exe4
ID aplikace související s chybujícím balíčkem: IntelMeFWService.exe5

Error: (08/19/2015 06:43:48 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: CALMAIN.exe, verze: 8.2.0.1, časové razítko: 0x442b232e
Název chybujícího modulu: MSVCRT.dll, verze: 7.0.9600.17415, časové razítko: 0x54504b2e
Kód výjimky: 0xc0000005
Posun chyby: 0x0000b3f2
ID chybujícího procesu: 0xa48
Čas spuštění chybující aplikace: 0xCALMAIN.exe0
Cesta k chybující aplikaci: CALMAIN.exe1
Cesta k chybujícímu modulu: CALMAIN.exe2
ID zprávy: CALMAIN.exe3
Úplný název chybujícího balíčku: CALMAIN.exe4
ID aplikace související s chybujícím balíčkem: CALMAIN.exe5

Error: (08/17/2015 04:29:22 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: CALMAIN.exe, verze: 8.2.0.1, časové razítko: 0x442b232e
Název chybujícího modulu: MSVCRT.dll, verze: 7.0.9600.17415, časové razítko: 0x54504b2e
Kód výjimky: 0xc0000005
Posun chyby: 0x0000b3f2
ID chybujícího procesu: 0x97c
Čas spuštění chybující aplikace: 0xCALMAIN.exe0
Cesta k chybující aplikaci: CALMAIN.exe1
Cesta k chybujícímu modulu: CALMAIN.exe2
ID zprávy: CALMAIN.exe3
Úplný název chybujícího balíčku: CALMAIN.exe4
ID aplikace související s chybujícím balíčkem: CALMAIN.exe5

Error: (08/13/2015 05:48:30 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005

Error: (08/11/2015 04:41:26 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: CALMAIN.exe, verze: 8.2.0.1, časové razítko: 0x442b232e
Název chybujícího modulu: MSVCRT.dll, verze: 7.0.9600.17415, časové razítko: 0x54504b2e
Kód výjimky: 0xc0000005
Posun chyby: 0x0000b3f2
ID chybujícího procesu: 0xd0c
Čas spuštění chybující aplikace: 0xCALMAIN.exe0
Cesta k chybující aplikaci: CALMAIN.exe1
Cesta k chybujícímu modulu: CALMAIN.exe2
ID zprávy: CALMAIN.exe3
Úplný název chybujícího balíčku: CALMAIN.exe4
ID aplikace související s chybujícím balíčkem: CALMAIN.exe5

Error: (08/05/2015 11:27:05 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: CALMAIN.exe, verze: 8.2.0.1, časové razítko: 0x442b232e
Název chybujícího modulu: MSVCRT.dll, verze: 7.0.9600.17415, časové razítko: 0x54504b2e
Kód výjimky: 0xc0000005
Posun chyby: 0x0000b3f2
ID chybujícího procesu: 0xd64
Čas spuštění chybující aplikace: 0xCALMAIN.exe0
Cesta k chybující aplikaci: CALMAIN.exe1
Cesta k chybujícímu modulu: CALMAIN.exe2
ID zprávy: CALMAIN.exe3
Úplný název chybujícího balíčku: CALMAIN.exe4
ID aplikace související s chybujícím balíčkem: CALMAIN.exe5

Error: (08/05/2015 11:56:49 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005

Error: (08/04/2015 07:47:41 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Notebook)
Description: Aplikaci Microsoft.BingNews_8wekyb3d8bbwe!AppexNews se nepovedlo aktivovat, protože došlo k chybě: -2144927142. Další informace najdete v protokolu Microsoft-Windows-TWinUI/Operational.


System errors:
=============
Error: (08/22/2015 08:08:55 AM) (Source: DCOM) (EventID: 10010) (User: Notebook)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}

Error: (08/22/2015 08:08:16 AM) (Source: DCOM) (EventID: 10010) (User: Notebook)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}

Error: (08/22/2015 07:37:57 AM) (Source: DCOM) (EventID: 10010) (User: Notebook)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}

Error: (08/22/2015 07:37:27 AM) (Source: DCOM) (EventID: 10010) (User: Notebook)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}

Error: (08/21/2015 04:58:23 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Canon Camera Access Library 8 byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (08/21/2015 03:01:30 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Služba Služba Windows Media Player Network Sharing závisí na službě Windows Search, která neuspěla při spuštění v důsledku následující chyby: 
%%1069

Error: (08/21/2015 03:01:30 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Windows Search neuspěla při spuštění v důsledku následující chyby: 
%%1069

Error: (08/21/2015 03:01:30 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Služba WSearch se nemohla přihlásit jako NT AUTHORITY\SYSTEM s aktuálně konfigurovaným heslem z důvodu následující chyby:
%%50

Chcete-li zajistit správnou konfiguraci služby, použijte modul snap-in Služby konzoly Microsoft Management Console (MMC).

Error: (08/21/2015 03:01:29 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Windows Search neuspěla při spuštění v důsledku následující chyby: 
%%1069

Error: (08/21/2015 03:01:29 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Služba WSearch se nemohla přihlásit jako NT AUTHORITY\SYSTEM s aktuálně konfigurovaným heslem z důvodu následující chyby:
%%50

Chcete-li zajistit správnou konfiguraci služby, použijte modul snap-in Služby konzoly Microsoft Management Console (MMC).


Microsoft Office:
=========================
Error: (08/21/2015 04:58:23 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: CALMAIN.exe8.2.0.1442b232eMSVCRT.dll7.0.9600.1741554504b2ec00000050000b3f2b5001d0dc11adcc0c7eC:\Program Files (x86)\Canon\CAL\CALMAIN.exeC:\WINDOWS\SYSTEM32\MSVCRT.dll114909ae-4815-11e5-bee2-7054d262383d

Error: (08/21/2015 02:56:33 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: CALMAIN.exe8.2.0.1442b232eMSVCRT.dll7.0.9600.1741554504b2ec00000050000b3f2b8c01d0dc0782b8790bC:\Program Files (x86)\Canon\CAL\CALMAIN.exeC:\WINDOWS\SYSTEM32\MSVCRT.dll0bd8d6b7-4804-11e5-bee1-7054d262383d

Error: (08/21/2015 10:39:56 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: IntelMeFWService.exe8.1.0.12564feb6176unknown0.0.0.000000000c00000052e183560106401d0dbecf4ecc5b2C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exeunknown32f188f1-47e0-11e5-bedf-7054d262383d

Error: (08/19/2015 06:43:48 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: CALMAIN.exe8.2.0.1442b232eMSVCRT.dll7.0.9600.1741554504b2ec00000050000b3f2a4801d0da983043b7d7C:\Program Files (x86)\Canon\CAL\CALMAIN.exeC:\WINDOWS\SYSTEM32\MSVCRT.dll7665e04a-4691-11e5-bedd-7054d262383d

Error: (08/17/2015 04:29:22 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: CALMAIN.exe8.2.0.1442b232eMSVCRT.dll7.0.9600.1741554504b2ec00000050000b3f297c01d0d8f6e40ff3c0C:\Program Files (x86)\Canon\CAL\CALMAIN.exeC:\WINDOWS\SYSTEM32\MSVCRT.dll5a0e548d-44ec-11e5-bedc-7054d262383d

Error: (08/13/2015 05:48:30 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005

Error: (08/11/2015 04:41:26 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: CALMAIN.exe8.2.0.1442b232eMSVCRT.dll7.0.9600.1741554504b2ec00000050000b3f2d0c01d0d4409970bc20C:\Program Files (x86)\Canon\CAL\CALMAIN.exeC:\WINDOWS\SYSTEM32\MSVCRT.dll0b2fbf98-4037-11e5-bedb-7054d262383d

Error: (08/05/2015 11:27:05 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: CALMAIN.exe8.2.0.1442b232eMSVCRT.dll7.0.9600.1741554504b2ec00000050000b3f2d6401d0cfc26a3ea9e5C:\Program Files (x86)\Canon\CAL\CALMAIN.exeC:\WINDOWS\SYSTEM32\MSVCRT.dllb754832a-3bb8-11e5-beda-7054d262383d

Error: (08/05/2015 11:56:49 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005

Error: (08/04/2015 07:47:41 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Notebook)
Description: Microsoft.BingNews_8wekyb3d8bbwe!AppexNews-2144927142


==================== Memory info =========================== 

Processor: Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz
Percentage of memory in use: 42%
Total physical RAM: 4047.22 MB
Available physical RAM: 2321.71 MB
Total Virtual: 4751.22 MB
Available Virtual: 2675.58 MB

==================== Drives ================================

Drive c: (TI30983100B) (Fixed) (Total:585.28 GB) (Free:517.89 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 596.2 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of log ============================