﻿Additional scan result of Farbar Recovery Scan Tool (x64) Version:25-08-2015 02
Ran by Jaruna (2015-08-26 00:18:02)
Running from C:\Users\Jaruna\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-725886734-121766909-2824906017-500 - Administrator - Disabled)
Guest (S-1-5-21-725886734-121766909-2824906017-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-725886734-121766909-2824906017-1003 - Limited - Enabled)
Jaruna (S-1-5-21-725886734-121766909-2824906017-1001 - Administrator - Enabled) => C:\Users\Jaruna

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

4G Hostless Modem (HKLM-x32\...\{AEFF9E60-3E93-41EE-9895-311F7D1C5FFD}) (Version: 1.0.0.2 - ZTE Corporation)
A9CAD (HKLM-x32\...\{C8E104FE-D57E-4082-9524-6C3A1C8DBDD7}) (Version: 2.2.0 - A9Tech)
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 15.008.20082 - Adobe Systems Incorporated)
Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated)
AllyFreeware 3.6 (HKLM-x32\...\AllyFreeware36_is1) (Version: 3.60.1.3 - Knowledge Base Software (Pty) Ltd)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.2.2218 - AVAST Software)
Canon MG5200 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5200_series) (Version:  - )
FelixCAD 5 LT (HKLM-x32\...\{12047811-D8BF-4F7B-976B-8CE70726CD1D}) (Version:  - )
Google Update Helper (x32 Version: 1.3.21.169 - Google Inc.) Hidden
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4176 - Intel Corporation)
KMPlayer (remove only) (HKLM-x32\...\The KMPlayer) (Version: 3.9.1.136 - PandoraTV)
Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Mozilla Firefox 40.0.2 (x86 cs) (HKLM-x32\...\Mozilla Firefox 40.0.2 (x86 cs)) (Version: 40.0.2 - Mozilla)
Nástroje kontroly pravopisu pro Microsoft Office 2013 – čeština (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Nástroje korektúry balíka Microsoft Office 2013 - slovenčina (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Opera Stable 31.0.1889.174 (HKLM-x32\...\Opera 31.0.1889.174) (Version: 31.0.1889.174 - Opera Software)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7503 - Realtek Semiconductor Corp.)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.51 - Ghisler Software GmbH)
VirtualCloneDrive (HKLM-x32\...\VirtualCloneDrive) (Version: 5.4.7.0 - Elaborate Bytes)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-725886734-121766909-2824906017-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation)

==================== Restore Points =========================

12-08-2015 10:40:17 Windows Update
22-08-2015 18:13:36 Windows Update

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 15:25 - 2015-08-25 16:58 - 00000826 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0C78D603-01D5-42B8-BB37-DBF1B09AA4C1} - System32\Tasks\Uninstaller_SkipUac_Jaruna => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe
Task: {12299756-6D14-4C0D-B8B8-96970A99F7C4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
Task: {1D6F2AE2-49AC-46C5-B904-EFEF231FBFDB} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation)
Task: {321CF279-673D-4FB2-84C9-BF77D39C8909} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-06-22] (Avast Software s.r.o.)
Task: {3AB7E022-A77C-4BA5-992C-B1EBBD556982} - System32\Tasks\Opera scheduled Autoupdate 1434107314 => C:\Program Files (x86)\Opera\launcher.exe [2015-08-17] (Opera Software)
Task: {3B9BA489-140B-499D-9DFA-C28777E7B064} - System32\Tasks\Driver Booster SkipUAC (Jaruna) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [2015-03-20] (IObit)
Task: {3DAC43F8-5683-4412-BA78-780BA252C2AE} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {6B9D9456-98E0-478D-89D7-71066554444F} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-08-12] (Microsoft Corporation)
Task: {75ED0F21-F713-4172-9089-02B0B7E6DC8A} - System32\Tasks\Trigger KMS Activation => C:\Program Files\KMSnano Final\TriggerKMS.exe
Task: {7CA0F523-A0FE-4443-ABF2-01675F2E76CD} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {A0C84C87-7E8F-4CAC-8677-927F1198858B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-12] (Adobe Systems Incorporated)
Task: {C0866E4E-6EEA-4043-BA0A-13863C6566C7} - System32\Tasks\RtHDVBg => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2015-06-04] (Realtek Semiconductor)
Task: {DA732526-13FE-4829-A484-294A1512AEC0} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe invagent.dll,RunUpdate -noappraiser
Task: {E0B38616-5B72-4553-99FD-4E161B4B229C} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2015-06-04] (Realtek Semiconductor)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\Uninstaller_SkipUac_Jaruna.job => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe

==================== Loaded Modules (Whitelisted) ==============

2015-06-05 19:58 - 2015-06-05 19:58 - 00104400 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2015-06-05 19:58 - 2015-06-05 19:58 - 00081728 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2015-08-25 20:57 - 2015-08-25 20:57 - 02961408 _____ () C:\Program Files\AVAST Software\Avast\defs\15082501\algo.dll
2015-06-05 19:58 - 2015-06-05 19:58 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-725886734-121766909-2824906017-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Jaruna\Documents\Dovolená 2015\104_PANA\P1040060.JPG
DNS Servers: 192.168.2.10
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

HKLM\...\StartupApproved\Run32: => "CancelAutoPlay_df"
HKLM\...\StartupApproved\Run32: => "CheckNDISPortF0ac74"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppextcomobj.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppextcomobj.exe
FirewallRules: [{95B07C9F-1EE8-4BD8-B811-040105117D37}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{2F3569C5-7143-4552-991B-9258F33B946C}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{B1F8FAD1-D258-437F-9DC3-52F7440D3447}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{C5C8CEC1-F642-4CF1-ACAA-A12574A9431C}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{C89C25E9-D54B-4E48-BCDD-1CF6794D4867}] => (Allow) C:\Users\Jaruna\AppData\Local\Temp\KMSnano\qemu-system-i386.exe
FirewallRules: [{E4ADC047-30EF-43D4-A997-5AB1D445B8E0}] => (Allow) C:\Users\Jaruna\AppData\Local\Temp\KMSnano\qemu-system-i386.exe
FirewallRules: [{A4A06890-D8D6-41A9-9523-13555FE6A788}] => (Allow) C:\Users\Jaruna\AppData\Local\Temp\KMSnano\qemu-system-i386.exe
FirewallRules: [{A01D6B80-4716-4D1F-A045-6DB4A1CC597D}] => (Allow) C:\Users\Jaruna\AppData\Local\Temp\KMSnano\qemu-system-i386.exe
FirewallRules: [{72FFF049-8BD3-411E-A259-EFF0EA267E0C}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe
FirewallRules: [{7EB6D6E0-C31E-47A7-9646-59EB4223F1F2}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe
FirewallRules: [{586EC201-CBD9-4EDA-8061-A6BE748F881E}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe
FirewallRules: [{6AEB4010-55B4-4120-B45C-AEDD61EEB947}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe
FirewallRules: [{65A4D14E-8346-4AEE-8693-DD6176ACB33A}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe
FirewallRules: [{04E4272F-F758-4F21-8E24-AB89BA28335F}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe
FirewallRules: [{667CB19C-9CD9-4C0F-9DB7-4DDB3C11BC85}] => (Allow) C:\Users\Jaruna\AppData\Roaming\svchost.exe
FirewallRules: [{EBB59507-4BAD-4464-BE3C-3E7F3E0E26FC}] => (Allow) C:\Users\Jaruna\AppData\Roaming\svchost.exe
FirewallRules: [{15662441-CF62-4FBB-9250-9AD037DEB0B9}] => (Allow) LPort=1688
FirewallRules: [{BBB794C1-07C4-418A-AD9C-A4CBC87635A9}] => (Allow) LPort=1689
FirewallRules: [{883CF220-B8FE-41CC-B7C4-39B6668ABEB7}] => (Allow) C:\Users\Jaruna\AppData\Local\TNT2\2.0.0.1983\TNT2User.exe
FirewallRules: [{4DB076BB-7ED8-432A-9E33-BB5AEFE9CB43}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe
FirewallRules: [{9F0624F9-0145-4F3E-856E-C7F8A9646601}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe
FirewallRules: [{87D85E8F-BCC1-49F0-98FC-D89262FFAC74}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{B968880C-4100-4373-97EF-7A3BCCA7FF85}] => (Allow) C:\Users\Jaruna\AppData\Local\Temp\nsj670D.tmp\Installer-10296835.exe
FirewallRules: [{8A5129D8-DEB7-4F25-940B-4A66EE2E8953}] => (Allow) C:\Users\Jaruna\AppData\Local\Temp\nsj670D.tmp\Installer-10296835.exe
FirewallRules: [{528AE3A6-1AAA-4760-8C66-9CACFA1905DB}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe
FirewallRules: [{7BACAF98-A654-4CF3-832D-0C146402572C}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe
FirewallRules: [{2E1BC1ED-B5C1-4553-AFCD-DDE9C34BEA43}] => (Allow) LPort=1689
FirewallRules: [{7FA7EDE1-EEA3-4E2E-AB00-0F587D94437D}] => (Allow) LPort=1688

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (08/25/2015 05:55:35 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: Service_KMS.exe, verze: 13.2.0.0, časové razítko: 0x53a73868
Název chybujícího modulu: unknown, verze: 0.0.0.0, časové razítko: 0x00000000
Kód výjimky: 0x00000000
Posun chyby: 0x00007ff7eb3c0399
ID chybujícího procesu: 0x9ac
Čas spuštění chybující aplikace: 0xService_KMS.exe0
Cesta k chybující aplikaci: Service_KMS.exe1
Cesta k chybujícímu modulu: Service_KMS.exe2
ID zprávy: Service_KMS.exe3
Úplný název chybujícího balíčku: Service_KMS.exe4
ID aplikace související s chybujícím balíčkem: Service_KMS.exe5

Error: (08/25/2015 05:55:24 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Aplikace: Service_KMS.exe
Verze Framework: v4.0.30319
Popis: Proces byl ukončen z důvodu neošetřené výjimky.
Informace o výjimce: System.IO.IOException
Zásobník:
   na System.Net.Sockets.NetworkStream.EndRead(System.IAsyncResult)
   na Service_KMS.KMSEmulator.TCPServer.ReadCallback(System.IAsyncResult)
   na System.Net.LazyAsyncResult.Complete(IntPtr)
   na System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   na System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   na System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
   na System.Net.ContextAwareResult.Complete(IntPtr)
   na System.Net.Sockets.BaseOverlappedAsyncResult.CompletionPortCallback(UInt32, UInt32, System.Threading.NativeOverlapped*)
   na System.Threading._IOCompletionCallback.PerformIOCompletionCallback(UInt32, UInt32, System.Threading.NativeOverlapped*)

Error: (08/25/2015 05:43:23 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: Service_KMS.exe, verze: 13.2.0.0, časové razítko: 0x53a73868
Název chybujícího modulu: KERNELBASE.dll, verze: 6.3.9600.17415, časové razítko: 0x54505737
Kód výjimky: 0xe0434352
Posun chyby: 0x0000000000008b9c
ID chybujícího procesu: 0x968
Čas spuštění chybující aplikace: 0xService_KMS.exe0
Cesta k chybující aplikaci: Service_KMS.exe1
Cesta k chybujícímu modulu: Service_KMS.exe2
ID zprávy: Service_KMS.exe3
Úplný název chybujícího balíčku: Service_KMS.exe4
ID aplikace související s chybujícím balíčkem: Service_KMS.exe5

Error: (08/25/2015 05:43:20 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Aplikace: Service_KMS.exe
Verze Framework: v4.0.30319
Popis: Proces byl ukončen z důvodu neošetřené výjimky.
Informace o výjimce: System.IO.IOException
Zásobník:
   na System.Net.Sockets.NetworkStream.EndRead(System.IAsyncResult)
   na Service_KMS.KMSEmulator.TCPServer.ReadCallback(System.IAsyncResult)
   na System.Net.LazyAsyncResult.Complete(IntPtr)
   na System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   na System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   na System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
   na System.Net.ContextAwareResult.Complete(IntPtr)
   na System.Net.Sockets.BaseOverlappedAsyncResult.CompletionPortCallback(UInt32, UInt32, System.Threading.NativeOverlapped*)
   na System.Threading._IOCompletionCallback.PerformIOCompletionCallback(UInt32, UInt32, System.Threading.NativeOverlapped*)

Error: (08/25/2015 05:38:14 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: Service_KMS.exe, verze: 13.2.0.0, časové razítko: 0x53a73868
Název chybujícího modulu: unknown, verze: 0.0.0.0, časové razítko: 0x00000000
Kód výjimky: 0x00000000
Posun chyby: 0x00007fff0d260399
ID chybujícího procesu: 0x83c
Čas spuštění chybující aplikace: 0xService_KMS.exe0
Cesta k chybující aplikaci: Service_KMS.exe1
Cesta k chybujícímu modulu: Service_KMS.exe2
ID zprávy: Service_KMS.exe3
Úplný název chybujícího balíčku: Service_KMS.exe4
ID aplikace související s chybujícím balíčkem: Service_KMS.exe5

Error: (08/25/2015 05:38:10 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Aplikace: Service_KMS.exe
Verze Framework: v4.0.30319
Popis: Proces byl ukončen z důvodu neošetřené výjimky.
Informace o výjimce: System.IO.IOException
Zásobník:
   na System.Net.Sockets.NetworkStream.EndRead(System.IAsyncResult)
   na Service_KMS.KMSEmulator.TCPServer.ReadCallback(System.IAsyncResult)
   na System.Net.LazyAsyncResult.Complete(IntPtr)
   na System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   na System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   na System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
   na System.Net.ContextAwareResult.Complete(IntPtr)
   na System.Net.Sockets.BaseOverlappedAsyncResult.CompletionPortCallback(UInt32, UInt32, System.Threading.NativeOverlapped*)
   na System.Threading._IOCompletionCallback.PerformIOCompletionCallback(UInt32, UInt32, System.Threading.NativeOverlapped*)

Error: (08/25/2015 05:36:33 PM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT AUTHORITY)
Description: Filtr událostí s dotazem select * from __InstanceModificationEvent where targetinstance isa '__ArbitratorConfiguration' nebylo možné znovu aktivovat v oboru názvů //./root, protože došlo k chybě 0x80041033. Dokud nebude problém odstraněn, nebude možné události prostřednictvím tohoto filtru doručovat.

Error: (08/25/2015 05:36:33 PM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: Zprostředkovatel událostí $Core se pokusil zaregistrovat dotaz select * from __TimerEvent, jehož cílová třída __TimerEvent v oboru názvů //./root neexistuje. Dotaz bude ignorován.

Error: (08/25/2015 05:36:33 PM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: Zprostředkovatel událostí $Core se pokusil zaregistrovat dotaz select * from __TimerEvent, jehož cílová třída __TimerEvent v oboru názvů //./ROOT/SecurityCenter neexistuje. Dotaz bude ignorován.

Error: (08/25/2015 05:36:33 PM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: Zprostředkovatel událostí $Core se pokusil zaregistrovat dotaz select * from __SystemEvent, jehož cílová třída __SystemEvent v oboru názvů //./root neexistuje. Dotaz bude ignorován.


System errors:
=============
Error: (08/26/2015 12:06:36 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: Rozšiřující modul sítě WLAN byl neočekávaně ukončen.

Cesta k modulu: C:\Windows\System32\bcmihvsrv64.dll

Error: (08/26/2015 12:06:36 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: Rozšiřující modul sítě WLAN byl neočekávaně ukončen.

Cesta k modulu: C:\Windows\System32\bcmihvsrv64.dll

Error: (08/26/2015 12:06:34 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: Rozšiřující modul sítě WLAN byl neočekávaně ukončen.

Cesta k modulu: C:\Windows\System32\bcmihvsrv64.dll

Error: (08/26/2015 12:06:23 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Služba Windows Media Player Network Sharing byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 30000 milisekund: Restartovat službu.

Error: (08/26/2015 12:06:23 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Update Mgr RecordPage byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 60000 milisekund: Restartovat službu.

Error: (08/26/2015 12:06:23 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Windows Search byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 30000 milisekund: Restartovat službu.

Error: (08/26/2015 12:06:23 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Windows Presentation Foundation Font Cache 3.0.0.0 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 0 milisekund: Restartovat službu.

Error: (08/26/2015 12:06:23 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Service Mgr RecordPage byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 60000 milisekund: Restartovat službu.

Error: (08/26/2015 12:06:23 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Reimage Real Time Protector byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (08/26/2015 12:06:22 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Adobe Acrobat Update Service byla neočekávaně ukončena. Tento stav nastal již 1krát.


Microsoft Office:
=========================
Error: (08/25/2015 05:55:35 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Service_KMS.exe13.2.0.053a73868unknown0.0.0.0000000000000000000007ff7eb3c03999ac01d0df4e682f05ccC:\Program Files\KMSpico\Service_KMS.exeunknownb84a18ac-4b41-11e5-826b-acb57dab2ad3

Error: (08/25/2015 05:55:24 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Aplikace: Service_KMS.exe
Verze Framework: v4.0.30319
Popis: Proces byl ukončen z důvodu neošetřené výjimky.
Informace o výjimce: System.IO.IOException
Zásobník:
   na System.Net.Sockets.NetworkStream.EndRead(System.IAsyncResult)
   na Service_KMS.KMSEmulator.TCPServer.ReadCallback(System.IAsyncResult)
   na System.Net.LazyAsyncResult.Complete(IntPtr)
   na System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   na System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   na System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
   na System.Net.ContextAwareResult.Complete(IntPtr)
   na System.Net.Sockets.BaseOverlappedAsyncResult.CompletionPortCallback(UInt32, UInt32, System.Threading.NativeOverlapped*)
   na System.Threading._IOCompletionCallback.PerformIOCompletionCallback(UInt32, UInt32, System.Threading.NativeOverlapped*)

Error: (08/25/2015 05:43:23 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Service_KMS.exe13.2.0.053a73868KERNELBASE.dll6.3.9600.1741554505737e04343520000000000008b9c96801d0df4cb06d8f46C:\Program Files\KMSpico\Service_KMS.exeC:\Windows\system32\KERNELBASE.dll044ae4f3-4b40-11e5-826a-acb57dab2ad3

Error: (08/25/2015 05:43:20 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Aplikace: Service_KMS.exe
Verze Framework: v4.0.30319
Popis: Proces byl ukončen z důvodu neošetřené výjimky.
Informace o výjimce: System.IO.IOException
Zásobník:
   na System.Net.Sockets.NetworkStream.EndRead(System.IAsyncResult)
   na Service_KMS.KMSEmulator.TCPServer.ReadCallback(System.IAsyncResult)
   na System.Net.LazyAsyncResult.Complete(IntPtr)
   na System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   na System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   na System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
   na System.Net.ContextAwareResult.Complete(IntPtr)
   na System.Net.Sockets.BaseOverlappedAsyncResult.CompletionPortCallback(UInt32, UInt32, System.Threading.NativeOverlapped*)
   na System.Threading._IOCompletionCallback.PerformIOCompletionCallback(UInt32, UInt32, System.Threading.NativeOverlapped*)

Error: (08/25/2015 05:38:14 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Service_KMS.exe13.2.0.053a73868unknown0.0.0.0000000000000000000007fff0d26039983c01d0df4bf8436adcC:\Program Files\KMSpico\Service_KMS.exeunknown4c29524b-4b3f-11e5-8269-acb57dab2ad3

Error: (08/25/2015 05:38:10 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Aplikace: Service_KMS.exe
Verze Framework: v4.0.30319
Popis: Proces byl ukončen z důvodu neošetřené výjimky.
Informace o výjimce: System.IO.IOException
Zásobník:
   na System.Net.Sockets.NetworkStream.EndRead(System.IAsyncResult)
   na Service_KMS.KMSEmulator.TCPServer.ReadCallback(System.IAsyncResult)
   na System.Net.LazyAsyncResult.Complete(IntPtr)
   na System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   na System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   na System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
   na System.Net.ContextAwareResult.Complete(IntPtr)
   na System.Net.Sockets.BaseOverlappedAsyncResult.CompletionPortCallback(UInt32, UInt32, System.Threading.NativeOverlapped*)
   na System.Threading._IOCompletionCallback.PerformIOCompletionCallback(UInt32, UInt32, System.Threading.NativeOverlapped*)

Error: (08/25/2015 05:36:33 PM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT AUTHORITY)
Description: //./rootselect * from __InstanceModificationEvent where targetinstance isa '__ArbitratorConfiguration'0x80041033

Error: (08/25/2015 05:36:33 PM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: $Coreselect * from __TimerEvent__TimerEvent//./root

Error: (08/25/2015 05:36:33 PM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: $Coreselect * from __TimerEvent__TimerEvent//./ROOT/SecurityCenter

Error: (08/25/2015 05:36:33 PM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: $Coreselect * from __SystemEvent__SystemEvent//./root


==================== Memory info =========================== 

Processor: Intel(R) Pentium(R) CPU N3540 @ 2.16GHz
Percentage of memory in use: 26%
Total physical RAM: 3982.48 MB
Available physical RAM: 2916.53 MB
Total Virtual: 4686.48 MB
Available Virtual: 3582.84 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:97.66 GB) (Free:29.5 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (Data) (Fixed) (Total:368.1 GB) (Free:367.5 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: FD490E17)
Partition 1: (Active) - (Size=97.7 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=368.1 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================