﻿Additional scan result of Farbar Recovery Scan Tool (x64) Version:06-09-2015 01
Ran by pc (2015-09-07 10:25:19)
Running from C:\Users\pc\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2010-05-31 17:27:27)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1426072499-1494131920-3719141132-500 - Administrator - Disabled)
Guest (S-1-5-21-1426072499-1494131920-3719141132-501 - Limited - Disabled)
pc (S-1-5-21-1426072499-1494131920-3719141132-1000 - Administrator - Enabled) => C:\Users\pc

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Disabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-1426072499-1494131920-3719141132-1000\...\uTorrent) (Version: 3.4.1.30740 - BitTorrent Inc.)
Adobe Flash Player 18 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 18.0.0.203 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.12) - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated)
AnyBurn (HKLM-x32\...\AnyBurn) (Version: 2.7 - Power Software Ltd)
Avast Internet Security (HKLM-x32\...\Avast) (Version: 10.3.2225 - AVAST Software)
Balíček ovladače systému Windows - Google, Inc (androidusb) USB  (12/11/2012 1.0.0009.00000) (HKLM\...\8E3B176889FB79CA6FE02DF2D2D6DE38BD9FC9F6) (Version: 12/11/2012 1.0.0009.00000 - Google, Inc)
Balíček ovladače systému Windows - Nokia Modem  (06/09/2010 4.5) (HKLM\...\34EA302E7F4CBD17A19E33BBCB72363234956D7E) (Version: 06/09/2010 4.5 - Nokia)
Balíček ovladače systému Windows - Nokia Modem  (06/09/2010 7.01.0.7) (HKLM\...\EEEE705096F837B7907659F100C9FE6DA001970F) (Version: 06/09/2010 7.01.0.7 - Nokia)
Balíček ovladače systému Windows - Nokia pccsmcfd LegacyDriver  (05/31/2012 7.1.2.0) (HKLM\...\62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F) (Version: 05/31/2012 7.1.2.0 - Nokia)
Balíček ovladače systému Windows - Qualcomm (qcusbnet) Net  (10/16/2012 1.0.7.9) (HKLM\...\C03E573DE1B7F7DE10352D707DF6C7E88C0FAA03) (Version: 10/16/2012 1.0.7.9 - Qualcomm)
Balíček ovladače systému Windows - Qualcomm Incorporated (qcusbser) Modem  (10/26/2012 2.1.0.3) (HKLM\...\19E621CD1BB015A1069EB53B72E2877DC34F038C) (Version: 10/26/2012 2.1.0.3 - Qualcomm Incorporated)
Balíček ovladače systému Windows - Qualcomm Incorporated (qcusbser) Ports  (10/26/2012 2.1.0.3) (HKLM\...\521149B020D2896EF887ED07E9FC74DD0C29C17A) (Version: 10/26/2012 2.1.0.3 - Qualcomm Incorporated)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 45.0.2454.85 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.13 - Google Inc.) Hidden
Malwarebytes Anti-Malware verze 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (čeština) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Language Pack 2013  - Czech/čeština (HKLM\...\Office15.OMUI.cs-cz) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Train Simulator (HKLM-x32\...\Train Simulator 1.0) (Version:  - )
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Works (HKLM-x32\...\{99D7DE4C-2775-4B16-B155-7F09AE939E8E}) (Version: 9.7.0621 - Microsoft Corporation)
Nástroje kontroly pravopisu pro Microsoft Office 2013 – čeština (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Nástroje korektúry balíka Microsoft Office 2013 - slovenčina (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Ovládací prvek ActiveX platformy Windows Live Mesh pro vzdálená připojení (HKLM-x32\...\{B6190387-0036-4BEB-8D74-A0AFC5F14706}) (Version: 15.4.5722.2 - Microsoft Corporation)
RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version:  - Microsoft)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-0100-0405-1000-0000000FF1CE}_Office15.OMUI.cs-cz_{010BF41A-4D78-40C3-90BA-117DF64A0AE2}) (Version:  - Microsoft)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (Version:  - Microsoft) Hidden
Tweaking.com - Windows Repair (HKLM-x32\...\Tweaking.com - Windows Repair) (Version: 3.1.3 - Tweaking.com)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
Windows Driver Package - Broadcom Bluetooth  (07/30/2009 6.2.0.9405) (HKLM\...\6B6B5E96843E55CF5CF8C7E45FB457F1FE642FF1) (Version: 07/30/2009 6.2.0.9405 - Broadcom)
Windows Driver Package - Broadcom Bluetooth  (09/11/2009 6.2.0.9407) (HKLM\...\3932CA781A7894D20116FDF60F878301800EA8AB) (Version: 09/11/2009 6.2.0.9407 - Broadcom)
Windows Driver Package - Broadcom HIDClass  (07/28/2009 6.2.0.9800) (HKLM\...\3BA80AB4C7E9F8497C115C844953A3D4BEB84D21) (Version: 07/28/2009 6.2.0.9800 - Broadcom)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\...\{068B46A0-8858-4CEB-80BC-A4AE787A05FC}) (Version: 14.0.8089.726 - Microsoft Corporation)
Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Restore Points =========================


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2015-07-12 12:36 - 00000855 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {00313FFA-AADF-4E6B-ADB2-9FD767CD2B29} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-1426072499-1494131920-3719141132-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2014-03-15] (RealNetworks, Inc.)
Task: {0103F906-0551-4118-8D05-086EC6ACE47F} - System32\Tasks\{6793CEAC-A2E0-4DC5-AB70-A054DFE20650} => C:\Program Files (x86)\J A Formoso\Train Store\TrainStore.exe [2006-05-07] (J.A. Formoso (tfmsts@btconnect.com))
Task: {046D652F-D7DF-4666-AE0F-8369AA545A01} - System32\Tasks\RealCreateProcessScheduledTask2136949026S-1-5-21-1426072499-1494131920-3719141132-1000 => c:\program files (x86)\real\realplayer\update\realsched.exe [2014-04-06] (RealNetworks, Inc.)
Task: {0B9715FE-9E3C-47A3-B76E-4D6B7201BBD7} - System32\Tasks\{4B382DE6-74CA-4DEC-80AB-B74B09FA9D2C} => D:\Viewer\ppview32.exe
Task: {2BB17421-9C52-416A-A37D-904CA3A8997F} - System32\Tasks\{748CEED2-10B4-4065-99AE-F8F5042AECD0} => pcalua.exe -a "C:\Program Files (x86)\android_driver_install\android_driver_install.exe" -d "C:\Program Files (x86)\android_driver_install"
Task: {2FB3C663-6D98-49B9-A197-F77F3E4AEA04} - System32\Tasks\RealCreateProcessScheduledTask442797761S-1-5-21-1426072499-1494131920-3719141132-1000 => c:\program files (x86)\real\realplayer\update\realsched.exe [2014-04-06] (RealNetworks, Inc.)
Task: {34F3ECF4-B15B-44AF-BA43-4C81818B1315} - System32\Tasks\{524E147D-82C2-4F90-85B8-EA02D00211A0} => C:\Program Files (x86)\AVG\AVG PC TuneUp\Integrator.exe
Task: {391FFD58-D147-4258-858E-63E3C317703A} - System32\Tasks\Microsoft Office 15 Sync Maintenance for pc-PC-pc pc-PC => C:\Program Files\Microsoft Office\Office15\MsoSync.exe [2014-11-12] (Microsoft Corporation)
Task: {3A716FD1-73AB-479E-8DC0-8EE10810D504} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-1426072499-1494131920-3719141132-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-03-20] (RealNetworks, Inc.)
Task: {427694C2-1D27-4BDA-BDC2-131FDF488BB9} - System32\Tasks\{A8432A50-836A-49DD-916B-E34B9A6B64B9} => D:\Doplnkove_programy\trainstore32\TRNST3CS\TrainStore Setup CSY.exe
Task: {428041D9-4835-4DE8-9CC0-214E104627FB} - System32\Tasks\avast! Emergency Update => C:\Program Files\Alwil Software\Avast5\AvastEmUpdate.exe [2015-08-18] (AVAST Software)
Task: {5084C39B-1B39-445D-BCC9-7C80EA78FB91} - System32\Tasks\{B858C03A-285F-4D76-A322-48A1395B77EE} => C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe [2010-05-14] (Nokia)
Task: {514E49A4-6B00-401C-8A00-66592FE8371F} - System32\Tasks\Tweaking.com - Windows Repair Tray Icon => C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe [2015-03-12] (Tweaking.com)
Task: {528857C7-41DD-4019-BB06-F20B90E0FA94} - System32\Tasks\{EE70D181-A035-4613-A444-C60EB12AEE5E} => D:\83\setup.exe
Task: {566650DA-841B-48C8-BEE2-16C7D1BF948C} - System32\Tasks\RealCreateProcessScheduledTask2124940615S-1-5-21-1426072499-1494131920-3719141132-1000 => c:\program files (x86)\real\realplayer\update\realsched.exe [2014-04-06] (RealNetworks, Inc.)
Task: {578B8F9C-7C92-4504-9C90-24E124AA9767} - System32\Tasks\{0078A2C3-690B-4593-82B4-D432C2E93959} => C:\Program Files (x86)\PasswdFinder\PasswdFinder.exe
Task: {61BA7EFC-8B42-490E-9A0E-62D814A5B2E5} - System32\Tasks\{B096CD4E-FB8C-4658-A621-A86A79BFD40C} => C:\Program Files (x86)\Makayama Interactive\Easy WiFi Radar\Easy WIFI Radar.exe
Task: {704C2432-6B9B-4D63-80A0-AE76C1D0950C} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1426072499-1494131920-3719141132-1000UA => C:\Users\pc\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-02-27] (Facebook Inc.)
Task: {7380789C-17C2-412E-9537-39057F0C8F9F} - System32\Tasks\{B044D693-9755-4A93-B177-A5945FBC0115} => pcalua.exe -a D:\82.1\setup.exe -d D:\82.1
Task: {7738042A-CE3A-463C-8529-81ECFEC4BEC2} - System32\Tasks\{7F673F77-50CC-489B-9893-82683527644C} => C:\Users\pc\Desktop\Easy WIFI Radar 1.0.5v Installer.exe
Task: {7BBA99EF-0AF6-49B4-8B2F-14D9C8C33690} - System32\Tasks\{01EC8CB1-496C-42C7-934B-A4CDAE054F59} => C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe [2010-05-14] (Nokia)
Task: {7EB50B92-A95F-4659-9B51-34EFFE41D818} - System32\Tasks\{D2B2ED1E-E9A6-4631-A780-A859C509B227} => C:\Program Files (x86)\PasswdFinder\PasswdFinder.exe
Task: {7FC3B348-EC10-4098-93CB-3483C2B003A6} - System32\Tasks\{05397978-82F6-4DA5-A8F8-83618F348427} => msiexec.exe /package "C:\Users\pc\Documents\MSTS\Trať-BP\Doplnkove_programy\Shape_Viewer_15\SView15.msi"
Task: {883667F4-AA6F-45F1-886B-68EF6F6D81DA} - System32\Tasks\{E5465151-EB15-4A56-B101-7538E6F7411E} => pcalua.exe -a C:\Users\pc\Documents\setup_pc_navigator.exe -d C:\Users\pc\Documents
Task: {894148F5-7F49-401D-B40D-7118CDF17422} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation)
Task: {8C8EA645-4230-4C12-AC62-48B6DA4F29EB} - System32\Tasks\{FDE4770E-88B8-45A7-BD74-688EDEF7381D} => D:\82.1\setup.exe
Task: {8D446617-12B2-42A9-8C0E-0EE4D5689E69} - System32\Tasks\{B78DFE9D-57F7-4635-BEE5-8EDA7F94A005} => msiexec.exe /package "C:\Users\pc\Documents\MSTS\Trať-BP\Doplnkove_programy\Shape_Viewer_15\SView15.msi"
Task: {90052DD2-0E9A-4422-A423-BBE69FB71A80} - System32\Tasks\RealCreateProcessScheduledTask2211642211S-1-5-21-1426072499-1494131920-3719141132-1000 => c:\program files (x86)\real\realplayer\update\realsched.exe [2014-04-06] (RealNetworks, Inc.)
Task: {92417898-25E7-4F14-BD70-8E9A0FF315DC} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-12] (Adobe Systems Incorporated)
Task: {97662764-0969-4676-B2C5-1473AFECB434} - System32\Tasks\RealCreateProcessScheduledTask389363207S-1-5-21-1426072499-1494131920-3719141132-1000 => c:\program files (x86)\real\realplayer\update\realsched.exe [2014-04-06] (RealNetworks, Inc.)
Task: {A1520C48-1208-408A-A1DA-60BDFDB0E4B4} - System32\Tasks\{B65F7DFC-3105-4A4F-AE81-520A818646B5} => C:\Program Files (x86)\J A Formoso\Train Store\TrainStore.exe [2006-05-07] (J.A. Formoso (tfmsts@btconnect.com))
Task: {A1937C93-3535-4D26-B9C8-BD4B87245EA5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {A2956356-4E6F-4956-81E7-E810555C9C30} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {A9A10503-E1C2-4512-A465-034515FE7F8A} - System32\Tasks\{1FD1895F-8E94-443F-9CB2-2227893BC621} => pcalua.exe -a D:\Setup\setup.exe -d D:\Setup
Task: {AE87C4AE-8481-468A-9F7B-D4F5DDB9FB25} - System32\Tasks\{391B9558-C1F4-44C1-98C6-E9A9304FA6E2} => D:\Doplnkove_programy\trainstore32\TRNST3CS\TrainStore Setup CSY.exe
Task: {B0B0C27A-21ED-46C6-8DAA-4BD3C5779D94} - System32\Tasks\{B4E5CDA8-DB44-4AC9-B75E-8A2F38E79E92} => C:\Program Files (x86)\J A Formoso\Train Store\TrainStore.exe [2006-05-07] (J.A. Formoso (tfmsts@btconnect.com))
Task: {B7D3E827-BAC9-4CF1-91C4-378532CFA5C7} - System32\Tasks\{9C242A46-95CC-47AB-BE69-FDBBC16D4957} => pcalua.exe -a "C:\Program Files (x86)\Microsoft Games\Train Simulator\global.exe" -d "C:\Program Files (x86)\Microsoft Games\Train Simulator"
Task: {C14D16BD-932A-4BAE-BAF3-4E58170881D9} - System32\Tasks\RealCreateProcessScheduledTask240033013S-1-5-21-1426072499-1494131920-3719141132-1000 => c:\program files (x86)\real\realplayer\update\realsched.exe [2014-04-06] (RealNetworks, Inc.)
Task: {C32BA217-2D27-4118-B108-B8222FD20F54} - System32\Tasks\{72401DE0-23E0-4464-8DD9-D06E26F70A31} => C:\Program Files (x86)\Makayama Interactive\Easy WiFi Radar\Easy WIFI Radar.exe
Task: {C56DA889-AE8D-4733-B545-87A14985A45B} - System32\Tasks\{709F6356-40C5-4266-B5D2-A7DBF2D06A39} => C:\Program Files (x86)\J A Formoso\Train Store\TrainStore.exe [2006-05-07] (J.A. Formoso (tfmsts@btconnect.com))
Task: {C81779FF-AECD-4B42-9387-CF9A83917CA1} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {CA0380B4-9FAF-4BB8-A05D-FA15177137A7} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-1426072499-1494131920-3719141132-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2014-03-15] (RealNetworks, Inc.)
Task: {CDC116E2-5D7B-44A9-8EB4-4DF082F2A1DA} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {CF5BF137-81B8-40AC-BD70-A68E23B529A0} - System32\Tasks\{AD6B66BA-E144-42D8-B8A0-12E952F59AB4} => pcalua.exe -a "D:\PC Navigátor 9 Truck\setup_ocx.exe" -d "D:\PC Navigátor 9 Truck"
Task: {D4AD257E-0C96-4761-81FA-806C4946B3D4} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-1426072499-1494131920-3719141132-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-03-20] (RealNetworks, Inc.)
Task: {D6DCE6F6-BDBD-4AA5-9B56-07054E617BBE} - System32\Tasks\{A1FA0075-C062-405E-8F53-4C1CB86B1865} => C:\Program Files (x86)\Gothic III\Gothic3.exe [2006-12-13] (Pluto 13 GmbH)
Task: {D9167CCA-52B7-4C3C-9A49-5D5CF0184DEA} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-02-20] (Piriform Ltd)
Task: {DE36EA2E-A611-4171-B63F-F9B336AE7522} - System32\Tasks\{7D364CE4-1948-4104-8818-D03D39B0C256} => C:\Program Files (x86)\AVG\AVG PC TuneUp\Integrator.exe
Task: {DFDAC8EB-10CC-4346-9439-5D2615B9A595} - System32\Tasks\{512DFD97-0338-4DB7-B873-F70E1AD00F98} => D:\Doplnkove_programy\trainstore32\TRNST3CS\TrainStore Setup CSY.exe
Task: {EC868BE3-39D4-452A-A2C8-1B140690D667} - System32\Tasks\{FF3C5C32-F260-477D-B7F0-7834B5457F3D} => C:\Program Files (x86)\PasswdFinder\PasswdFinder.exe
Task: {EF40FEC5-EBAE-4826-A05E-BCC08F10C233} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1426072499-1494131920-3719141132-1000Core => C:\Users\pc\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-02-27] (Facebook Inc.)
Task: {F0A8AD8E-1BA1-458D-B106-1A20EC2D5F96} - System32\Tasks\{76E576D9-1889-4DB6-98DE-03B876FFA87F} => C:\Program Files (x86)\Makayama Interactive\Easy WiFi Radar\Easy WIFI Radar.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2014-03-15 03:18 - 2014-03-15 03:18 - 00039568 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
2014-03-20 21:13 - 2014-03-20 21:13 - 00023552 _____ () C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe
2015-08-18 10:07 - 2015-08-18 10:07 - 00102864 _____ () C:\Program Files\Alwil Software\Avast5\log.dll
2015-08-18 10:07 - 2015-08-18 10:07 - 00123976 _____ () C:\Program Files\Alwil Software\Avast5\JsonRpcServer.dll
2015-08-31 20:09 - 2015-08-31 20:09 - 02961920 _____ () C:\Program Files\Alwil Software\Avast5\defs\15083101\algo.dll
2015-09-07 09:37 - 2015-09-07 09:37 - 02964480 _____ () C:\Program Files\Alwil Software\Avast5\defs\15090601\algo.dll
2009-02-03 02:33 - 2009-02-03 02:33 - 00460199 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\sqlite3.dll
2008-09-29 02:55 - 2008-09-29 02:55 - 01076224 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\ACE.dll
2015-05-31 06:12 - 2015-05-31 06:12 - 40540672 _____ () C:\Program Files\Alwil Software\Avast5\libcef.dll
2014-04-06 13:50 - 2014-04-06 13:50 - 00869976 _____ () c:\program files (x86)\real\realplayer\RPDS\Plugins\cldplin.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\Temp:0B9176C0
AlternateDataStreams: C:\ProgramData\Temp:5D7E5A8F
AlternateDataStreams: C:\ProgramData\Temp:93DE1838
AlternateDataStreams: C:\ProgramData\Temp:AB689DEA
AlternateDataStreams: C:\ProgramData\Temp:ABE89FFE
AlternateDataStreams: C:\ProgramData\Temp:E3C56885
AlternateDataStreams: C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Seznam.cz.website:DESTICON_email1229235768
AlternateDataStreams: C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Seznam.cz.website:DESTICON_firmy-216282473
AlternateDataStreams: C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Seznam.cz.website:DESTICON_novinky-1609642764
AlternateDataStreams: C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Seznam.cz.website:DESTICON_prozeny771666966
AlternateDataStreams: C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Seznam.cz.website:DESTICON_sport6476750
AlternateDataStreams: C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Seznam.cz.website:DESTICON_stream1444311432
AlternateDataStreams: C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Seznam.cz.website:DESTICON_super-41222104

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1426072499-1494131920-3719141132-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\pc\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 10.0.0.138
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{F7D2772F-0B81-426F-8578-141D6C46D434}] => (Allow) C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
FirewallRules: [{21794B7D-038C-46C3-ABB2-BA02D7D5331A}] => (Allow) C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
FirewallRules: [{D44B1660-1054-4F94-B4A6-92F0CC1C08FC}] => (Allow) C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
FirewallRules: [{0584C4F0-F225-4D4C-9E47-0253EFDA52EA}] => (Allow) C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
FirewallRules: [{2B913525-08F2-4BAE-AB7F-84C86E1CE16A}] => (Allow) C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\Acer Arcade Deluxe.exe
FirewallRules: [{B4CA0941-1C2B-41C9-AA74-EA5080158739}] => (Allow) C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\PlayMovie.exe
FirewallRules: [{9DF68020-5133-4EF2-BB84-1D1E7F89114F}] => (Allow) C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\PMVService.exe
FirewallRules: [{E53E3CA8-0DFA-4461-A73F-CB93BE8BD705}] => (Allow) C:\Program Files (x86)\Acer Arcade Deluxe\HomeMedia\HomeMedia.exe
FirewallRules: [{49D9A51A-8CDF-469D-A694-1565EA9C5C49}] => (Allow) C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe
FirewallRules: [{6E6D84FB-B878-4F55-9F4E-843B5F0BD471}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{BBBCEE9F-8093-47F6-9028-C8D512ADCB6D}] => (Allow) LPort=2869
FirewallRules: [{78506298-8314-4B06-B894-C63AD41FAC2D}] => (Allow) LPort=1900
FirewallRules: [{0DA50B95-4E01-466E-AD31-38169D6982FA}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [TCP Query User{99ADB0B3-B0AB-45C3-8B13-650A5EE9FCB6}C:\program files (x86)\mozilla firefox\plugin-container.exe] => (Allow) C:\program files (x86)\mozilla firefox\plugin-container.exe
FirewallRules: [UDP Query User{4B7DFF5E-8AF8-4CDF-8C7A-CFD82FF915C7}C:\program files (x86)\mozilla firefox\plugin-container.exe] => (Allow) C:\program files (x86)\mozilla firefox\plugin-container.exe
FirewallRules: [{C35BF9A0-3CBA-42D5-B4F8-17782BA06CD9}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{5086AF13-9A21-4BB6-BC4A-E55E8887F462}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{26B89D60-6CCA-461E-BC81-4DD37A6652EA}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{0DA8E1C2-B8D5-4047-A375-6B4E484275CF}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{DA4C8A93-73B5-4C6D-BE47-AF3EED4AA511}] => (Allow) C:\Program Files (x86)\nokia\nokia suite\nokiasuite.exe
FirewallRules: [{D194F861-9468-4AD0-96E2-6C7530386669}] => (Allow) C:\Users\pc\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe
FirewallRules: [{7BFECDB0-3BD2-424B-B10B-ABEA3F10C570}] => (Allow) C:\Users\pc\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{CF1314D4-CF6F-49BE-A219-0811EA842C25}] => (Allow) C:\Users\pc\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{1C430A68-51E4-440F-9749-F89EA792BA3D}] => (Allow) c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe
FirewallRules: [{C1E40247-2B67-4C57-A3E3-5C72DFD12B09}] => (Allow) C:\Users\pc\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{5F6FB2C8-A473-43B8-9E1A-BFDBF902264E}] => (Allow) C:\Users\pc\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{0C166FF8-D8F9-4FBB-A646-CF3A2C8390ED}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (09/07/2015 09:38:16 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418225

Error: (09/06/2015 05:54:17 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Generování kontextu aktivace pro rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"1 se nezdařilo.
Závislé sestavení rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0" nelze najít.
Podrobnější diagnostické údaje získáte pomocí programu sxstrace.exe.

Error: (09/06/2015 03:35:17 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Generování kontextu aktivace pro rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"1 se nezdařilo.
Závislé sestavení rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0" nelze najít.
Podrobnější diagnostické údaje získáte pomocí programu sxstrace.exe.

Error: (09/06/2015 11:55:11 AM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
Description: Failed to schedule Software Protection service for re-start at 2015-09-06T17:02:03Z. Error Code: 0x80041321.

Error: (09/06/2015 11:49:58 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418225

Error: (09/06/2015 11:46:05 AM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
Description: Failed to schedule Software Protection service for re-start at 2015-09-06T17:02:05Z. Error Code: 0x80041321.

Error: (09/06/2015 11:41:05 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418225

Error: (09/04/2015 12:11:02 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
Description: Failed to schedule Software Protection service for re-start at 2015-09-06T17:02:02Z. Error Code: 0x80041321.

Error: (09/04/2015 12:06:02 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418225

Error: (09/03/2015 04:47:32 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Generování kontextu aktivace pro rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"1 se nezdařilo.
Závislé sestavení rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0" nelze najít.
Podrobnější diagnostické údaje získáte pomocí programu sxstrace.exe.


System errors:
=============
Error: (09/07/2015 10:12:14 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Při čekání na odezvu transakce služby avast! Firewall bylo dosaženo časového limitu (30000 ms).

Error: (09/06/2015 11:39:51 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Při čekání na odezvu transakce služby ShellHWDetection bylo dosaženo časového limitu (30000 ms).

Error: (09/03/2015 08:14:37 PM) (Source: volsnap) (EventID: 35) (User: )
Description: Stínové kopie svazku C: byly přerušeny, protože se nepodařilo zvětšit úložiště stínové kopie.

Error: (09/02/2015 04:48:26 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {752073A1-23F2-4396-85F0-8FDB879ED0ED}

Error: (09/02/2015 04:41:52 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Služba Windows Update přestala během spouštění reagovat.

Error: (09/02/2015 04:38:06 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Úložná technologie Intel(R) Rapid neuspěla při spuštění v důsledku následující chyby: 
%%1053

Error: (09/02/2015 04:38:06 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby Úložná technologie Intel(R) Rapid bylo dosaženo časového limitu (30000 ms).

Error: (09/02/2015 04:34:31 PM) (Source: NETLOGON) (EventID: 3095) (User: )
Description: Tento počítač je nakonfigurován jako člen pracovní skupiny, nikoliv jako
člen domény. Přihlašovací služba Netlogon nepotřebuje být spuštěna v této
konfiguraci.

Error: (09/02/2015 04:34:21 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Předchozí vypnutí systému (22:06:52, ‎31.‎8.‎2015) bylo neočekávané.

Error: (08/30/2015 08:56:25 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Při čekání na odezvu transakce služby avast! Firewall bylo dosaženo časového limitu (30000 ms).


Microsoft Office:
=========================
Error: (09/07/2015 09:38:16 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418225

Error: (09/06/2015 05:54:17 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"C:\Windows\Installer\{DE431304-8040-43D4-8419-A58E210A3894}\recordingmanager.exe

Error: (09/06/2015 03:35:17 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"C:\Windows\Installer\{DE431304-8040-43D4-8419-A58E210A3894}\recordingmanager.exe

Error: (09/06/2015 11:55:11 AM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
Description: 0x800413212015-09-06T17:02:03Z

Error: (09/06/2015 11:49:58 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418225

Error: (09/06/2015 11:46:05 AM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
Description: 0x800413212015-09-06T17:02:05Z

Error: (09/06/2015 11:41:05 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418225

Error: (09/04/2015 12:11:02 PM) (Source: Office Software Protection Platform Service) (EventID: 16385) (User: )
Description: 0x800413212015-09-06T17:02:02Z

Error: (09/04/2015 12:06:02 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418225

Error: (09/03/2015 04:47:32 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"C:\Windows\Installer\{DE431304-8040-43D4-8419-A58E210A3894}\recordingmanager.exe


CodeIntegrity:
===================================
  Date: 2015-03-01 20:57:50.693
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-03-01 20:57:50.085
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-03-01 20:57:49.477
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-03-01 20:57:48.868
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-03-01 20:38:44.138
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-03-01 20:38:43.514
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-03-01 20:38:42.875
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-03-01 20:38:42.266
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-03-01 19:46:35.296
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-03-01 19:46:34.687
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info =========================== 

Processor: Pentium(R) Dual-Core CPU T4400 @ 2.20GHz
Percentage of memory in use: 64%
Total physical RAM: 3066.93 MB
Available physical RAM: 1095.54 MB
Total Virtual: 7664.11 MB
Available Virtual: 3517.42 MB

==================== Drives ================================

Drive c: (ACER) (Fixed) (Total:285.3 GB) (Free:35.62 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 298.1 GB) (Disk ID: 5C795C79)
Partition 1: (Not Active) - (Size=12.7 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=285.3 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================