﻿Additional scan result of Farbar Recovery Scan Tool (x64) Version:03-10-2015
Ran by Kajušinka (2015-10-04 11:09:10)
Running from C:\Users\Kajušinka\Desktop
Windows 8.1 (X64) (2015-03-19 04:06:31)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2958726476-3350756913-3102298719-500 - Administrator - Disabled)
Guest (S-1-5-21-2958726476-3350756913-3102298719-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2958726476-3350756913-3102298719-1003 - Limited - Enabled)
Kajušinka (S-1-5-21-2958726476-3350756913-3102298719-1001 - Administrator - Enabled) => C:\Users\Kajušinka

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: ESET NOD32 Antivirus 9.0.318.10 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
AS: ESET NOD32 Antivirus 9.0.318.10 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Acer Care Center (HKLM\...\{A424844F-CDB3-45E2-BB77-1DDE4A091E76}) (Version: 1.00.3013 - Acer Incorporated)
Acer Power Management (HKLM\...\{91F52DE4-B789-42B0-9311-A349F10E5479}) (Version: 7.00.8105 - Acer Incorporated)
Acer Quick Access (HKLM\...\{C1FA525F-D701-4B31-9D32-504FC0CF0B98}) (Version: 1.01.3016.0 - Acer Incorporated)
Acer Recovery Management (HKLM\...\{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}) (Version: 6.00.8108 - Acer Incorporated)
Acer User Experience Improvement Program App Monitor Plugin (HKLM\...\{978724F6-1863-4DD5-9E66-FB77F5AB5613}) (Version: 1.02.3004 - Acer Incorporated)
Acer User Experience Improvement Program Framework (HKLM\...\{12A718F2-2357-4D41-9E1F-18583A4745F7}) (Version: 1.02.3004 - Acer Incorporated)
Acer Video Player (HKLM-x32\...\{B6846F20-4821-11E3-8F96-0800200C9A66}) (Version: 1.00.2005.0 - Acer Incorporated)
Aktualizace NVIDIA 2.4.5.28 (Version: 2.4.5.28 - NVIDIA Corporation) Hidden
Aloha TriPeaks (x32 Version: 2.2.0.98 - WildTangent) Hidden
Any Video Converter 5.7.7 (HKLM-x32\...\Any Video Converter_is1) (Version:  - Any-Video-Converter.com)
AOP Framework (HKLM-x32\...\{4A37A114-702F-4055-A4B6-16571D4A5353}) (Version: 3.01.2008.3 - Acer Incorporated)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.4.2233 - AVAST Software)
Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Broadcom NetLink Controller (HKLM\...\{7FBA83D7-D58E-4B70-9B9B-12E95B183B22}) (Version: 16.6.1.3 - Broadcom Corporation)
calibre (HKLM-x32\...\{CF0D492B-12F2-40B0-AF33-0F1BAA0BEF37}) (Version: 2.28.0 - Kovid Goyal)
CCleaner (HKLM\...\CCleaner) (Version: 5.10 - Piriform)
CyberLink PhotoDirector 3 (HKLM-x32\...\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.1.4917 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.4220 - CyberLink Corp.)
CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.4609.02 - CyberLink Corp.)
Dolby Digital Plus Home Theater (HKLM\...\{7E3D8FA1-6092-469A-955B-68FC4A2C67CA}) (Version: 7.6.3.1 - Dolby Laboratories Inc)
ESET NOD32 Antivirus (HKLM\...\{518C6E61-1A33-4BF9-8A02-1B4815A341FA}) (Version: 9.0.318.10 - ESET, spol. s r.o.)
Farm to Fork Collector's Edition (x32 Version: 3.0.2.59 - WildTangent) Hidden
Foxit PhantomPDF (HKLM-x32\...\{F74C595C-BEF2-4AF9-9C4E-68F3CD509C4D}) (Version: 6.0.120.609 - Foxit Corporation)
Game Explorer Categories - genres (HKLM-x32\...\WildTangentGameProvider-acer-genres) (Version: 11.0.0.7 - WildTangent, Inc.)
Game Explorer Categories - main (HKLM-x32\...\WildTangentGameProvider-acer-main) (Version: 11.0.0.7 - WildTangent, Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 45.0.2454.101 - Google Inc.)
Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden
Governor of Poker 2 Premium Edition (x32 Version: 3.0.2.59 - WildTangent) Hidden
HellSpy Klient verze 0.8.0 (HKLM-x32\...\{553E24F0-09FD-4BCB-9CF0-4FC0F6DB95D1}_is1) (Version: 0.8.0 - HellSpy.com)
Intel(R) Chipset Device Software (x32 Version: 10.0.20 - Intel(R) Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 10.0.0.1168 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3643 - Intel Corporation)
Intel(R) Update Manager (HKLM-x32\...\{12914061-EB9B-4AE7-AC7E-0B8A607C7DF4}) (Version: 2.3.1338 - Intel Corporation)
Jewel Match 3 (x32 Version: 3.0.2.59 - WildTangent) Hidden
King Oddball (x32 Version: 3.0.2.48 - WildTangent) Hidden
LUXOR Evolved (x32 Version: 2.2.0.98 - WildTangent) Hidden
Magic Academy (x32 Version: 2.2.0.98 - WildTangent) Hidden
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUSR) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{d491dd9d-2eda-4d75-b504-1a201436e7fd}) (Version: 11.0.61030.0 - Microsoft Corporation)
NVIDIA GeForce Experience 2.4.5.28 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.4.5.28 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 352.86 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 352.86 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
Ori and the Blind Forest (HKLM-x32\...\{XXXXXXXX-XXXX-XXXX-XXXX-BLACKBOX0039}) (Version: 6.0 - Black Box)
Ovládací panel NVIDIA 352.86 (Version: 352.86 - NVIDIA Corporation) Hidden
Peggle Nights (x32 Version: 2.2.0.98 - WildTangent) Hidden
Plants vs. Zombies - Game of the Year (x32 Version: 3.0.2.59 - WildTangent) Hidden
Polar Bowler 1st Frame (x32 Version: 3.0.2.59 - WildTangent) Hidden
Qualcomm Atheros 61x4 Wireless LAN&Bluetooth Installer (HKLM-x32\...\{3241744A-BA36-41F0-B4AA-EF3946D00632}) (Version: 11.0.0.619A - Qualcomm Atheros)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.39059 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7260 - Realtek Semiconductor Corp.)
SHIELD Streaming (Version: 4.1.2000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.4.5.28 - NVIDIA Corporation) Hidden
Skype™ 7.8 (HKLM-x32\...\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.8.102 - Skype Technologies S.A.)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version:  - )
Spotify (HKLM-x32\...\Spotify) (Version: 0.9.6.81.gd359a796 - Spotify AB)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
The Chronicles of Emerland Solitaire (x32 Version: 3.0.2.51 - WildTangent) Hidden
TP-LINK TL-WN721N_TL-WN722N Driver (HKLM-x32\...\{86A7EED0-02D0-4D91-8183-8D2F23F5E6AE}) (Version: 1.3.1 - TP-LINK)
TP-LINK Wireless Configuration Utility (HKLM-x32\...\{319D91C6-3D44-436C-9F79-36C0D22372DC}) (Version: 1.3.1 - TP-LINK)
Trinklit Supreme (x32 Version: 2.2.0.98 - WildTangent) Hidden
Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
WildTangent Games (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.4.0 - WildTangent)
WildTangent Games App (x32 Version: 4.0.11.13 - WildTangent) Hidden
Zuma's Revenge (x32 Version: 2.2.0.97 - WildTangent) Hidden

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Restore Points =========================


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0021BCA7-BFF6-474E-9BCE-F2798CF4A5C0} - System32\Tasks\Recovery Management\Notification => C:\Program Files\Acer\Acer Recovery Management\Notification\Notification.exe [2014-06-17] (Acer Incorporated)
Task: {371153E9-8DB8-4972-9E8C-CD010BD7D3C4} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-10-04] (AVAST Software)
Task: {4C9CEBED-C1A0-4FFE-BE22-A78DC019BF87} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-02-28] ()
Task: {4D9C81D5-D662-41FB-8FDA-24F327E89BF8} - System32\Tasks\Quick Access => C:\Program Files\Acer\Acer Quick Access\QALauncher.exe [2014-06-26] (Acer Incorporate)
Task: {52BA574C-593C-432D-AC0A-44128C23FD96} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-20] (Google Inc.)
Task: {5FAC24DB-0F6E-44A6-A34A-2428E64F2A05} - System32\Tasks\DolbySelectorTask => C:\Program Files\Dolby Digital Plus\ddp.exe [2014-04-07] (Dolby Laboratories Inc.)
Task: {705CA18D-97D7-4F82-8570-BB939E361021} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe invagent.dll,RunUpdate -noappraiser
Task: {739FE456-8BC6-49FD-9EAA-C0F03D158DB3} - System32\Tasks\ACCAgent => C:\Program Files (x86)\Acer\Care Center\LiveUpdateAgent.exe [2014-08-29] ()
Task: {7920C473-7218-4EA1-AF60-621D4F8A498E} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-09-16] (Piriform Ltd)
Task: {7A5F84DB-53D5-4820-8C28-C3BEEA05D05D} - System32\Tasks\{464509D3-E984-455F-95EC-62D4F19BEE7A} => Chrome.exe http://www.skype.com/go/downloading?source=lightinstaller&amp;ver=7.2.0.103&amp;LastError=12002
Task: {89A40BDD-B2C2-4AB3-B308-9990474CECB2} - System32\Tasks\{8736CB98-3253-4511-92A0-2C7E84590513} => Chrome.exe http://ui.skype.com/ui/0/7.2.0.103/cs/abandoninstall?source=lightinstaller&amp;page=tsInstall
Task: {9091F5F9-CDCA-4C00-898A-C81AD2A9B0BB} - System32\Tasks\UbtFrameworkService => C:\Program Files\Acer\User Experience Improvement Program\Framework\TriggerFramework.exe [2014-03-13] (TODO: <Company name>)
Task: {979DEE5F-C3F8-4264-9745-ED0B8CA35E5F} - System32\Tasks\Quick Access Quick Launcher => C:\Program Files\Acer\Acer Quick Access\QALauncher.exe [2014-06-26] (Acer Incorporate)
Task: {9BD10F92-4730-425B-83AC-89002D1F624A} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-02-28] ()
Task: {A0AF97C7-7B20-4ED7-BFBB-3FDE1DBB0C68} - System32\Tasks\WindowsUpda2ta => C:\Users\Kajušinka\AppData\Roaming\MICROSOFT\v.vbs
Task: {A824D7BC-4A88-4856-BBD3-8116CB1BA1A9} - System32\Tasks\Power Management => C:\Program Files\Acer\Acer Power Management\ePowerTrayLauncher.exe [2014-06-12] (Acer Incorporated)
Task: {C69E481D-CE6A-4264-8F28-6F7A5C9BF915} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-20] (Google Inc.)
Task: {D93ADDDD-4482-4001-901C-0DCA1E715ABF} - System32\Tasks\ACC => C:\Program Files (x86)\Acer\Care Center\LiveUpdateChecker.exe [2014-08-29] ()
Task: {E674ED56-1ADC-4B1B-ADE5-FE450F1147B6} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-08-26] (Microsoft Corporation)
Task: {EA319872-D93F-49C6-BB27-6B05DA12A884} - System32\Tasks\Software Update Application => C:\ProgramData\OEM\UpgradeTool\ListCheck.exe [2014-06-08] (Acer Incorporated)
Task: {F3B13C31-3553-45E5-A839-29121D994D0F} - \AutoKMS -> No File <==== ATTENTION

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2015-05-28 17:36 - 2015-05-12 05:30 - 00116368 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2014-08-22 08:48 - 2014-08-22 08:48 - 00139264 _____ () C:\Windows\system32\ihvmanager\AthIHVManager.dll
2010-01-30 02:40 - 2010-01-30 02:40 - 04254560 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2014-12-10 00:50 - 2012-04-24 12:43 - 00254512 _____ () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
2014-04-07 16:13 - 2014-04-07 16:13 - 00052096 _____ () C:\Program Files\Dolby Digital Plus\Dolby.DDP.Controls_Desktop.dll
2015-03-20 15:36 - 2013-10-21 12:00 - 00847360 _____ () C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
2015-09-16 21:33 - 2015-09-16 21:33 - 00047104 _____ () C:\Program Files\CCleaner\lang\lang-1029.dll
2015-05-17 13:19 - 2013-10-01 11:09 - 00078880 _____ () C:\Program Files\Realtek\Audio\HDA\FMAPP.exe
2015-10-04 09:41 - 2015-10-04 09:41 - 00103376 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2015-10-04 09:41 - 2015-10-04 09:41 - 00123976 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2015-10-04 09:41 - 2015-10-04 09:41 - 02966528 _____ () C:\Program Files\AVAST Software\Avast\defs\15100400\algo.dll
2015-05-28 17:20 - 2015-05-23 03:48 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2015-03-20 15:36 - 2013-06-28 15:50 - 01411072 _____ () C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\nicLan.dll
2015-03-20 15:36 - 2013-06-28 15:48 - 00193024 _____ () C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\DC_WFF.dll
2015-10-04 09:41 - 2015-10-04 09:41 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2015-09-30 16:49 - 2015-09-24 04:34 - 01501512 _____ () C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.101\libglesv2.dll
2015-09-30 16:49 - 2015-09-24 04:34 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.101\libegl.dll
2014-02-20 04:51 - 2014-02-20 04:51 - 01241560 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2015-09-30 16:49 - 2015-09-24 04:34 - 16487752 _____ () C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.101\PepperFlash\pepflashplayer.dll
2015-10-04 09:41 - 2015-10-04 09:41 - 00985600 _____ () C:\Program Files\AVAST Software\Avast\ffmpegsumo.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2958726476-3350756913-3102298719-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Kajušinka\AppData\Roaming\Microsoft\Windows Photo Viewer\Tapeta programu Windows Prohlížeč fotografií.jpg
DNS Servers: 10.0.8.1 - 8.8.8.8
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

HKLM\...\StartupApproved\Run: => "Andy"
HKU\S-1-5-21-2958726476-3350756913-3102298719-1001\...\StartupApproved\StartupFolder: => "crack serial keygen Microsoft Office 2010 .vbs"
HKU\S-1-5-21-2958726476-3350756913-3102298719-1001\...\StartupApproved\StartupFolder: => "conhost32.exe"
HKU\S-1-5-21-2958726476-3350756913-3102298719-1001\...\StartupApproved\StartupFolder: => "conhost64.exe"
HKU\S-1-5-21-2958726476-3350756913-3102298719-1001\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_82691DA48A5177D8997070697CF28EE3"
HKU\S-1-5-21-2958726476-3350756913-3102298719-1001\...\StartupApproved\Run: => "Skype"
HKU\S-1-5-21-2958726476-3350756913-3102298719-1001\...\StartupApproved\Run: => "Steam"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{F48A8DB5-C193-421E-B868-24BF8B505E56}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{6E93B7C9-9850-49F9-B516-B416BEB14321}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{E1C820BA-69DB-45F3-A46C-225A9853220D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{D473F969-4D63-4E5C-904B-102F880D1045}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{37AC2B09-743F-4503-ADD3-DBCABB5F2D7F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{07DBEE30-AAD6-4A96-9BC4-2A959DCF56EE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{9F274543-783E-4C49-86D5-3CE9D17D656E}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
FirewallRules: [{CC26F5DB-FBAE-4CDD-B0D0-972939D93192}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
FirewallRules: [{CADA0969-CA7E-4BBD-9B7F-18715E0FC504}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
FirewallRules: [{E2AEC2F9-6C85-4A9F-86D3-6604FA4E4D60}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
FirewallRules: [{7946F392-A1D7-48CA-B363-BDDCBE12F0C8}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{9529A959-E279-4920-8A5D-51AA8DF3CA36}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe
FirewallRules: [{2FE20441-54AE-4136-A427-10B3084C6C31}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe
FirewallRules: [{B317862F-3333-4D8F-B769-348E2A5A66FE}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe
FirewallRules: [TCP Query User{2E98325D-1A7B-4064-806B-0FBF57742A28}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
FirewallRules: [UDP Query User{930CB571-D168-416F-BDED-8A088FD890BA}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
FirewallRules: [TCP Query User{9FB4119E-AA11-462B-9290-BC0CADA70C11}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe
FirewallRules: [UDP Query User{FCE50A49-E71B-49BF-8746-3017E75C9358}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe
FirewallRules: [TCP Query User{8F021E00-E843-4D65-9F24-0560D1D30658}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{74C45445-8F2B-4026-9EE5-8E980FF9DFEA}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{1B634FB8-CC72-4217-AF66-0F25E51C214F}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{24CBCB96-5A34-4CCE-A145-E49F83343023}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{1DCCD570-6671-457D-A01F-F7DE907038BF}] => (Allow) D:\Programy\Steam\Steam.exe
FirewallRules: [{237CD197-DFFA-437E-99DD-0F54EB97D069}] => (Allow) D:\Programy\Steam\Steam.exe
FirewallRules: [{5C3BB085-45A8-4349-998E-608361B81BBA}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{011939A2-D0EE-4B94-BB2B-B92F21CEAB76}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{AF7E1D24-7DA8-4B74-BB08-8917E6EAE700}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{3F17B85A-3E3C-46CD-9742-DD3B350A62A5}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [TCP Query User{7098C1BA-48AD-497A-9FA2-FE59EC7B2DA5}C:\program files\andy\andy.exe] => (Allow) C:\program files\andy\andy.exe
FirewallRules: [UDP Query User{FC2C1562-BD53-4C5B-B799-470E5AEB268A}C:\program files\andy\andy.exe] => (Allow) C:\program files\andy\andy.exe
FirewallRules: [{F3F96396-CF4E-4D07-9FD4-77807B053377}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [TCP Query User{28F008D3-7983-43DA-A745-52EEE09A458F}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe
FirewallRules: [UDP Query User{0719A600-BE6E-4DA2-8600-2DB7B3B1B924}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe
FirewallRules: [{5E566E79-6D30-46F8-8257-C573AD4B852B}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{C95E5805-88D7-43EB-A371-A85B2B50D14E}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (10/04/2015 02:23:39 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program Explorer.EXE verze 6.3.9600.17667 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.

ID procesu: 7b8

Čas spuštění: 01d0fe3a5d3a6b13

Čas ukončení: 0

Cesta k aplikaci: C:\WINDOWS\Explorer.EXE

ID hlášení: f2b4dd6c-6a2d-11e5-827a-2c337a4e0522

Úplný název chybujícího balíčku: 

ID aplikace související s chybujícím balíčkem:

Error: (10/03/2015 11:12:05 PM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: )
Description: Svazek Recovery nebyl optimalizován, protože byla zjištěna chyba: Parametr není správný. (0x80070057).

Error: (10/03/2015 11:10:53 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: BITSC:\Windows\System32\bitsperf.dll8

Error: (10/03/2015 09:41:56 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: LocalNtaNlhJSQu.exe, verze: 8.1.9.1, časové razítko: 0x545fcb05
Název chybujícího modulu: KERNELBASE.dll, verze: 6.3.9600.17415, časové razítko: 0x54505737
Kód výjimky: 0xe0434352
Posun chyby: 0x0000000000008b9c
ID chybujícího procesu: 0x22f8
Čas spuštění chybující aplikace: 0xLocalNtaNlhJSQu.exe0
Cesta k chybující aplikaci: LocalNtaNlhJSQu.exe1
Cesta k chybujícímu modulu: LocalNtaNlhJSQu.exe2
ID zprávy: LocalNtaNlhJSQu.exe3
Úplný název chybujícího balíčku: LocalNtaNlhJSQu.exe4
ID aplikace související s chybujícím balíčkem: LocalNtaNlhJSQu.exe5

Error: (10/03/2015 09:41:56 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Aplikace: LocalNtaNlhJSQu.exe
Verze Framework: v4.0.30319
Popis: Proces byl ukončen z důvodu neošetřené výjimky.
Informace o výjimce: kód výjimky e0434352, adresa výjimky 00007FFA41358B9C
Zásobník:

Error: (10/03/2015 09:34:53 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: KMS-Activator-Windows-7-8-8.1-et-Office-2010-2013.exe, verze: 0.0.0.0, časové razítko: 0x545fd155
Název chybujícího modulu: KERNELBASE.dll, verze: 6.3.9600.17415, časové razítko: 0x54505737
Kód výjimky: 0xe0434352
Posun chyby: 0x0000000000008b9c
ID chybujícího procesu: 0x1dd0
Čas spuštění chybující aplikace: 0xKMS-Activator-Windows-7-8-8.1-et-Office-2010-2013.exe0
Cesta k chybující aplikaci: KMS-Activator-Windows-7-8-8.1-et-Office-2010-2013.exe1
Cesta k chybujícímu modulu: KMS-Activator-Windows-7-8-8.1-et-Office-2010-2013.exe2
ID zprávy: KMS-Activator-Windows-7-8-8.1-et-Office-2010-2013.exe3
Úplný název chybujícího balíčku: KMS-Activator-Windows-7-8-8.1-et-Office-2010-2013.exe4
ID aplikace související s chybujícím balíčkem: KMS-Activator-Windows-7-8-8.1-et-Office-2010-2013.exe5

Error: (10/03/2015 09:34:53 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Aplikace: KMS-Activator-Windows-7-8-8.1-et-Office-2010-2013.exe
Verze Framework: v4.0.30319
Popis: Proces byl ukončen z důvodu neošetřené výjimky.
Informace o výjimce: System.Exception
Zásobník:
   na Ⴈ.Ⴈ.Ⴅ(System.String[])

Error: (10/03/2015 09:20:04 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: KMS-Activator-Windows-7-8-8.1-et-Office-2010-2013.exe, verze: 0.0.0.0, časové razítko: 0x545fd155
Název chybujícího modulu: KERNELBASE.dll, verze: 6.3.9600.17415, časové razítko: 0x54505737
Kód výjimky: 0xe0434352
Posun chyby: 0x0000000000008b9c
ID chybujícího procesu: 0x598
Čas spuštění chybující aplikace: 0xKMS-Activator-Windows-7-8-8.1-et-Office-2010-2013.exe0
Cesta k chybující aplikaci: KMS-Activator-Windows-7-8-8.1-et-Office-2010-2013.exe1
Cesta k chybujícímu modulu: KMS-Activator-Windows-7-8-8.1-et-Office-2010-2013.exe2
ID zprávy: KMS-Activator-Windows-7-8-8.1-et-Office-2010-2013.exe3
Úplný název chybujícího balíčku: KMS-Activator-Windows-7-8-8.1-et-Office-2010-2013.exe4
ID aplikace související s chybujícím balíčkem: KMS-Activator-Windows-7-8-8.1-et-Office-2010-2013.exe5

Error: (10/03/2015 09:20:04 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Aplikace: KMS-Activator-Windows-7-8-8.1-et-Office-2010-2013.exe
Verze Framework: v4.0.30319
Popis: Proces byl ukončen z důvodu neošetřené výjimky.
Informace o výjimce: System.Exception
Zásobník:
   na Ⴈ.Ⴈ.Ⴅ(System.String[])

Error: (10/03/2015 09:19:49 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: KMS-Activator-Windows-7-8-8.1-et-Office-2010-2013.exe, verze: 0.0.0.0, časové razítko: 0x545fd155
Název chybujícího modulu: KERNELBASE.dll, verze: 6.3.9600.17415, časové razítko: 0x54505737
Kód výjimky: 0xe0434352
Posun chyby: 0x0000000000008b9c
ID chybujícího procesu: 0x23f0
Čas spuštění chybující aplikace: 0xKMS-Activator-Windows-7-8-8.1-et-Office-2010-2013.exe0
Cesta k chybující aplikaci: KMS-Activator-Windows-7-8-8.1-et-Office-2010-2013.exe1
Cesta k chybujícímu modulu: KMS-Activator-Windows-7-8-8.1-et-Office-2010-2013.exe2
ID zprávy: KMS-Activator-Windows-7-8-8.1-et-Office-2010-2013.exe3
Úplný název chybujícího balíčku: KMS-Activator-Windows-7-8-8.1-et-Office-2010-2013.exe4
ID aplikace související s chybujícím balíčkem: KMS-Activator-Windows-7-8-8.1-et-Office-2010-2013.exe5


System errors:
=============
Error: (10/04/2015 11:02:30 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: Výstraha o závažné chybě byla vygenerována a zaslána na vzdálený koncový bod. To může vést k ukončení připojení. Kód závažné chyby definovaný protokolem TLS: 20. Stav chyby Windows SChannel: 960

Error: (10/04/2015 11:02:10 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: Výstraha o závažné chybě byla vygenerována a zaslána na vzdálený koncový bod. To může vést k ukončení připojení. Kód závažné chyby definovaný protokolem TLS: 20. Stav chyby Windows SChannel: 960

Error: (10/04/2015 10:53:33 AM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba ESET Service je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (10/04/2015 08:41:37 AM) (Source: DCOM) (EventID: 10010) (User: Muffin)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}

Error: (10/04/2015 08:41:07 AM) (Source: DCOM) (EventID: 10010) (User: Muffin)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}

Error: (10/04/2015 02:45:37 AM) (Source: DCOM) (EventID: 10010) (User: Muffin)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}

Error: (10/04/2015 02:45:07 AM) (Source: DCOM) (EventID: 10010) (User: Muffin)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}

Error: (10/04/2015 02:40:17 AM) (Source: DCOM) (EventID: 10010) (User: Muffin)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}

Error: (10/04/2015 02:39:47 AM) (Source: DCOM) (EventID: 10010) (User: Muffin)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}

Error: (10/04/2015 02:28:44 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: {FDA74D11-C4A6-4577-9F73-D7CA8586E10D}


CodeIntegrity:
===================================
  Date: 2015-10-04 11:07:03.218
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-10-04 11:07:02.975
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-10-04 11:07:02.744
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-10-04 11:07:02.515
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-10-04 11:07:02.242
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-10-04 11:07:01.926
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-10-04 11:06:56.751
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-10-04 11:06:56.514
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-10-04 11:06:56.305
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-10-04 11:06:56.009
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info =========================== 

Processor: Intel(R) Core(TM) i7-4720HQ CPU @ 2.60GHz
Percentage of memory in use: 51%
Total physical RAM: 8115.27 MB
Available physical RAM: 3896.8 MB
Total Virtual: 10803.27 MB
Available Virtual: 6082.04 MB

==================== Drives ================================

Drive c: (Acer) (Fixed) (Total:118.43 GB) (Free:63.43 GB) NTFS
Drive d: (DATA) (Fixed) (Total:914.65 GB) (Free:608.55 GB) NTFS
Drive e: (Moje MP3 soubory) (CDROM) (Total:4.27 GB) (Free:0 GB) UDF

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 119.2 GB) (Disk ID: 1D9F1715)

Partition: GPT.

========================================================
Disk: 1 (Size: 931.5 GB) (Disk ID: 1D9F170A)

Partition: GPT.

==================== End of Addition.txt ============================