﻿Additional scan result of Farbar Recovery Scan Tool (x86) Version:01-12-2015
Ran by Adam (2015-12-04 18:26:13)
Running from C:\Users\Adam\Desktop
Microsoft Windows 10 Home (X86) (2015-11-19 23:20:25)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Adam (S-1-5-21-3409903947-2537725115-4003705135-1000 - Administrator - Enabled) => C:\Users\Adam
Administrator (S-1-5-21-3409903947-2537725115-4003705135-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3409903947-2537725115-4003705135-503 - Limited - Disabled)
Guest (S-1-5-21-3409903947-2537725115-4003705135-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3409903947-2537725115-4003705135-1002 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: ESET Smart Security 9.0.318.22 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET Smart Security 9.0.318.22 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
FW: ESET Personálny firewall (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-3409903947-2537725115-4003705135-1000\...\uTorrent) (Version: 3.4.5.41202 - BitTorrent Inc.)
Adobe Acrobat Reader DC - Slovak (HKLM\...\{AC76BA86-7AD7-1051-7B44-AC0F074E4100}) (Version: 15.009.20079 - Adobe Systems Incorporated)
Adobe Flash Player 19 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 19.0.0.245 - Adobe Systems Incorporated)
AIDA64 Extreme v5.00 (HKLM\...\AIDA64 Extreme_is1) (Version: 5.00 - FinalWire Ltd.)
Aktualizácie NVIDIA 17.12.8 (Version: 17.12.8 - NVIDIA Corporation) Hidden
AviSynth (HKLM\...\AviSynth) (Version: 2.6.0 MT - )
CCleaner (HKLM\...\CCleaner) (Version: 5.12 - Piriform)
ESET Smart Security (HKLM\...\{EDD088BE-E6F8-40A6-9B79-BC40F70B03EB}) (Version: 9.0.318.22 - ESET, spol. s r.o.)
ffdshow v1.3.4530 [2014-02-09] (HKLM\...\ffdshow_is1) (Version: 1.3.4530.0 - )
Follow Virtual (HKU\S-1-5-21-3409903947-2537725115-4003705135-1000\...\{090FAB46-7C63-7F39-067F-E62AD4A8861B}) (Version: 1.4.6 - Web Kingdom corp)
Java 8 Update 66 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218066F0}) (Version: 8.0.660.18 - Oracle Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM\...\{650c9b4a-60ec-4e4e-8d8e-32d85ce3b7c5}) (Version: 11.0.61030.0 - Microsoft Corporation)
Mozilla Firefox 42.0 (x86 sk) (HKLM\...\Mozilla Firefox 42.0 (x86 sk)) (Version: 42.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 42.0.0.5780 - Mozilla)
NVIDIA 3D Vision radič ovládača 340.50 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 340.50 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.2.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.2.2 - NVIDIA Corporation)
NVIDIA Grafický ovládač 341.92 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 341.92 - NVIDIA Corporation)
NVIDIA Ovládač 3D Vision 341.92 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 341.92 - NVIDIA Corporation)
NVIDIA Ovládač zvuku HD 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation)
NVIDIA Softvér systému s podporou technológie PhysX 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
Ovládací panel NVIDIA 341.92 (Version: 341.92 - NVIDIA Corporation) Hidden
SHIELD Streaming (Version: 4.0.1000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 17.12.8 - NVIDIA Corporation) Hidden
TP-LINK TL-WN721N_TL-WN722N Driver (HKLM\...\{86A7EED0-02D0-4D91-8183-8D2F23F5E6AE}) (Version: 1.3.1 - TP-LINK)
TP-LINK Wireless Configuration Utility (HKLM\...\{319D91C6-3D44-436C-9F79-36C0D22372DC}) (Version: 1.3.1 - TP-LINK)
Universal Media Server (HKLM\...\Universal Media Server) (Version: 5.3.1 - Universal Media Server)
ViewRight Web PC (HKLM\...\{B62D5F4C-BEB2-4DCD-A8B4-EE21CCAEC28A}) (Version: 3.3.0.0 - Verimatrix, Inc.)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.1 - VideoLAN)
Winamp (HKLM\...\Winamp) (Version: 5.666  - Nullsoft, Inc)
WinRAR 5.11 (32-bitová verzia) (HKLM\...\WinRAR archiver) (Version: 5.11.0 - win.rar GmbH)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Restore Points =========================


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:04 - 2015-03-02 19:19 - 00000035 ____A C:\WINDOWS\system32\Drivers\etc\hosts


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {00DD308B-822F-4090-BAFB-EECB4A9FA7A1} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {0701E2B7-71DB-4AF2-A75E-86BC4D43B485} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {131C06B8-14F3-41A1-8CDD-A43328DB4ABC} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe
Task: {14E3DF6B-1C82-4C76-ADB7-2C9F6DA1C5D4} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {15F81952-00C0-4259-BF1F-07E339EE2A72} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {184A4656-2D65-44E5-8655-BFAFEB12CBBA} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {2223E858-70C4-4445-BB2E-4ADDF3883BA6} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {22F5437E-531D-4E79-9BD7-72E090728C0C} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {29F92B93-76C6-479D-8F8B-3E017DE689FA} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {2AFA9EDD-124B-4A5F-A034-295FD5B0B793} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {2CB4AC1A-B148-401F-BFBF-B54266DF14BE} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {35EC43FF-6459-4B09-8ACB-0E2B7BE5C070} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {39E767CB-5A54-46CC-B2EC-AD8238BFD7C7} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-11-16] (Piriform Ltd)
Task: {3E1764C9-A583-4DC6-93A0-903FC3F0EB10} - System32\Tasks\{F9103839-0420-4FD9-A678-532B012F9FEF} => pcalua.exe -a "C:\Program Files\SimpleFiles\Uninstall.exe"
Task: {3E9CB745-0B3A-4995-8690-1298281B37F1} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {41A1ED0C-C219-46A7-8F98-6C62A258DAD1} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {49B067E8-26A1-4AEC-B9F7-CB856D1A9292} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {56E05C1C-ECEC-4F53-8CA6-D0D7A947B60B} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
Task: {5BA47FED-C56E-4839-8D00-F76D492C5FB0} - System32\Tasks\Follow Virtual => Rundll32.exe "C:\Users\Adam\AppData\Local\Follow Virtual\{394B791F-EB11-26A8-F68C-E54F6B98AE87}\FollowVirtual.dll",#3
Task: {5E9FD623-05AF-4A7B-9AA7-0D850B65C456} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {5FF38D98-5D1A-474E-8AFB-4385B9194315} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe
Task: {67998E00-F2AA-43E1-81FB-7140B5BD5B23} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {73515558-37D5-4804-BA6F-5FE3D8318C46} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {79AC3F9A-D0F0-4185-8A91-7B2DF2C10EEB} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {86E97DE5-5B3D-44FB-B83D-F2DCE5CDD62E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-09-14] (Adobe Systems Incorporated)
Task: {87024A1D-AB7B-4309-B7FA-BB9C4F966693} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe
Task: {8E242192-9B79-4DBF-A6D6-F9A8D4B3645A} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {A4A4AD4B-F81A-4602-B8DC-F89B25FF2FBC} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {ABD77015-73EE-4578-9912-4B9E9FF0A79E} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {B08E76CD-48EC-48C4-BECE-D4DACA673DC5} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\WINDOWS\ehome\ehrec.exe
Task: {B09DFC11-653C-4EDC-8D67-92B6E83586CE} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {B2AF20BB-15DF-45FA-856A-CF8792B6CF64} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-11-11] (Microsoft Corporation)
Task: {BD07AF13-D52C-4ED1-AE87-75379991585A} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {C3F20F7E-25CC-4316-8D42-CE8E224D4235} - System32\Tasks\{6D0A16F6-7172-4C38-88C6-080AFACDA44F} => pcalua.exe -a C:\Users\Adam\Desktop\pms-1.90.1-setup-full-x64.exe -d C:\Users\Adam\Desktop
Task: {D561B8A9-F8ED-4B0A-8B81-A1DE6230467F} - System32\Tasks\SmartShare => C:\Program Files\LG Software\LG Smart Share\SmartShareStart.exe
Task: {D66A180E-674D-46FA-8B9F-7D643198B7D2} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {D696C286-63CB-4CC2-886B-B51234A395E5} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {D7168B37-8944-4887-91A2-BC687DA7A2B8} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {D823D09A-06A3-435B-B09A-AB9E0EF9E1C4} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {E0AC3ED3-BD3C-4FD4-A267-385A22279A37} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {E5776D4C-A8D0-4C80-B45E-B1AC922240B2} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {F4C84DBF-9043-4840-BB7F-0523CD9BBE43} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-11-11] (Adobe Systems Incorporated)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2015-10-30 06:44 - 2015-10-30 06:44 - 00149504 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2015-11-19 23:44 - 2015-10-13 17:47 - 00113840 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll
2015-12-03 17:11 - 2015-11-22 11:41 - 01859448 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2015-12-03 17:11 - 2015-11-22 11:41 - 01859448 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-10-30 06:44 - 2015-10-30 06:44 - 00070656 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2015-10-30 06:44 - 2015-10-30 06:44 - 00316416 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2015-10-30 06:44 - 2015-10-30 06:44 - 00428032 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\MtcUvc.dll
2015-12-03 17:10 - 2015-11-22 10:15 - 05352960 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2015-12-03 17:10 - 2015-11-22 10:11 - 00471552 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2015-12-03 17:11 - 2015-11-22 10:11 - 02366464 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2015-12-03 17:11 - 2015-11-22 10:14 - 02656768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-04-28 11:02 - 2013-10-21 10:00 - 00847360 _____ () C:\Program Files\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
2015-04-28 11:02 - 2013-06-28 13:50 - 01411072 _____ () C:\Program Files\TP-LINK\TP-LINK Wireless Configuration Utility\nicLan.dll
2015-04-28 11:02 - 2013-06-28 13:48 - 00193024 _____ () C:\Program Files\TP-LINK\TP-LINK Wireless Configuration Utility\DC_WFF.dll
2015-04-28 11:02 - 2013-06-28 13:48 - 00138752 _____ () C:\Program Files\TP-LINK\TP-LINK Wireless Configuration Utility\WJWF\WJWF.dll
2015-04-28 11:02 - 2013-06-28 13:48 - 00115712 _____ () C:\Program Files\TP-LINK\TP-LINK Wireless Configuration Utility\WJWF\WJWF_WPS_WIN7.DLL
2015-11-21 12:49 - 2015-11-21 12:49 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_1.11.19004.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2015-11-21 12:49 - 2015-11-21 12:49 - 00152064 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_1.11.19004.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2015-11-21 12:49 - 2015-11-21 12:49 - 18906624 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_1.11.19004.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2001-07-24 05:33 - 2001-07-24 05:33 - 00020480 _____ () C:\Program Files\Winamp\Plugins\out_null.dll
2001-07-24 05:33 - 2001-07-24 05:33 - 00020480 _____ () C:\Program Files\Winamp\Plugins\out_xf.dll
2013-12-13 03:47 - 2013-12-13 03:47 - 00333824 _____ () C:\Program Files\Winamp\Plugins\freeform\wacs\freetype\freetype.wac

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Program Files\CCleaner:Win32App_1
AlternateDataStreams: C:\Program Files\ffdshow:Win32App_1
AlternateDataStreams: C:\Program Files\Mozilla Firefox:Win32App_1
AlternateDataStreams: C:\Program Files\Verimatrix:Win32App_1
AlternateDataStreams: C:\Program Files\WinRAR:Win32App_1
AlternateDataStreams: C:\Program Files\Common Files\Adobe:Win32App_1

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3409903947-2537725115-4003705135-1000\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\theme1\img2.jpg
DNS Servers: 192.168.16.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^TVMOBiLiArtworkManager.lnk => C:\Windows\pss\TVMOBiLiArtworkManager.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Universal Media Server.lnk => C:\Windows\pss\Universal Media Server.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Adam^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^ConnectAir.lnk => C:\Windows\pss\ConnectAir.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: AirDroid 3 => C:\Program Files\AirDroid\AirDroid.exe /start
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
MSCONFIG\startupreg: NvBackend => "C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe"
MSCONFIG\startupreg: Plex Media Server => "C:\Program Files\Plex\Plex Media Server\Plex Media Server.exe"
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: uTorrent => "C:\Users\Adam\AppData\Roaming\uTorrent\uTorrent.exe"  /MINIMIZED
HKLM\...\StartupApproved\StartupFolder: => "Universal Media Server.lnk"
HKLM\...\StartupApproved\Run: => "RtHDVCpl"
HKLM\...\StartupApproved\Run: => "SunJavaUpdateSched"
HKU\S-1-5-21-3409903947-2537725115-4003705135-1000\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3409903947-2537725115-4003705135-1000\...\StartupApproved\Run: => "CCleaner Monitoring"
HKU\S-1-5-21-3409903947-2537725115-4003705135-1000\...\StartupApproved\Run: => "PC Remote Server"
HKU\S-1-5-21-3409903947-2537725115-4003705135-1000\...\StartupApproved\Run: => "SpybotPostWindows10UpgradeReInstall"
HKU\S-1-5-21-3409903947-2537725115-4003705135-1000\...\StartupApproved\Run: => "uTorrent"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-32bit] => (Allow) LPort=808
FirewallRules: [{3AE719DB-6544-4663-95B5-008590C05783}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{4BA65F7C-098F-4D59-B794-9D98EA283623}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{033DF0EC-EB51-48B0-8022-07CB3F956A26}] => (Allow) C:\Program Files\Winamp\winamp.exe
FirewallRules: [{6D5F103E-8F4D-4A54-A427-39DEFD895AD2}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{94EA4C3D-ED3A-4081-AB3E-74B8B9E0267E}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{7F625F99-65FA-4D6A-AEF1-1FAF8DCB6B8C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{3CDEFB05-184F-4228-90F8-D16D5335AC76}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{039D3FC5-8F28-45A8-8F90-7634E6A637AC}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{A004E952-5923-41EB-9C2E-3EA92E5DD4F7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{74A2ABED-9979-4EE0-B23D-EA0F4B4B3A48}] => (Allow) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{D6700C0A-E2AB-4E46-AF81-19D249C6FCE1}] => (Allow) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{0CD65270-4F0C-4F54-AF16-5096D96D5460}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{25686C2F-849A-4741-A569-2618AD30B814}] => (Allow) C:\Program Files\SimpleFiles\SimpleFiles.exe
FirewallRules: [{3B4E7F3B-1C14-4782-8373-3F913F0E346A}] => (Allow) C:\Program Files\SimpleFiles\SimpleFiles.exe
FirewallRules: [{83A0B5A6-46E0-46EE-9196-959CD4318D58}] => (Allow) C:\Program Files\SimpleFiles\downloader.exe
FirewallRules: [{32F79713-6F8D-47CB-B455-790017E1EF60}] => (Allow) C:\Program Files\SimpleFiles\downloader.exe
FirewallRules: [{040CED62-F86E-43EF-96EF-D478E0125583}] => (Allow) C:\Program Files\LuckyBrowse\app\LuckyBrowse.exe
FirewallRules: [{39749ED9-937F-40CA-B92B-BD355914F041}] => (Allow) C:\Program Files\LuckyBrowse\app\LuckyBrowse.exe
FirewallRules: [{2A25736D-369D-4AFC-95DD-48EF2B0C65C1}] => (Allow) C:\Users\Adam\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{32D00DE8-8BF2-4BDA-881F-86D372CDA28F}] => (Allow) C:\Users\Adam\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{D57BB156-2483-4231-A511-BD97B06C74A5}] => (Allow) C:\Users\Adam\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{D2D4042C-5726-4C8A-AA84-8F2CE9C6D9C4}] => (Allow) C:\Users\Adam\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{D960DD99-6767-4B4E-9BC9-C81A57C3062B}] => (Allow) C:\Users\Adam\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{3A5B4F2D-C8EB-4991-BFCA-48F046618004}] => (Allow) C:\Users\Adam\AppData\Roaming\uTorrent\uTorrent.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (12/04/2015 06:15:29 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: BITSC:\Windows\System32\bitsperf.dll4

Error: (12/02/2015 06:46:42 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: Adam-PC)
Description: Balík Microsoft.Windows.Photos_15.1120.13270.0_x86__8wekyb3d8bbwe+App sa ukončil, pretože jeho odstavenie trvalo príliš dlho.

Error: (11/25/2015 09:27:23 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program jp2launcher.exe version 11.66.2.18 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

Process ID: 3ac

Start Time: 01d127bee9743c2c

Termination Time: 52

Application Path: C:\Program Files\Java\jre1.8.0_66\bin\jp2launcher.exe

Report Id: d4463c79-93b2-11e5-93e7-bc5ff4731384

Faulting package full name: 

Faulting package-relative application ID:

Error: (11/25/2015 08:55:18 PM) (Source: MsiInstaller) (EventID: 1024) (User: Adam-PC)
Description: Produkt: Adobe Acrobat Reader DC - Slovak – Aktualizáciu {AC76BA86-7AD7-0000-2550-AC0F094E6F00} sa nepodarilo nainštalovať. Kód chyby je 1625. Inštalátor systému Windows umožňuje vytvárať denníky, ktoré vám môžu pomôcť pri odstraňovaní problémov s inštaláciou softvérových balíkov. Pokyny na zapnutie podpory zapisovania do denníka zobrazíte po kliknutí na nasledovné prepojenie: http://go.microsoft.com/fwlink/?LinkId=23127

Error: (11/25/2015 08:49:39 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: NT AUTHORITY)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.

Error: (11/25/2015 08:49:37 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: NT AUTHORITY)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.

Error: (11/25/2015 08:37:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Názov chybujúcej aplikácie: plugin-container.exe, verzia: 42.0.0.5780, časová značka: 0x5632d0a4
Názov chybujúceho modulu: NPSWF32_19_0_0_245.dll, verzia: 19.0.0.245, časová značka: 0x56311bb0
Kód výnimky: 0x80000003
Odstup chyby: 0x0036408d
Identifikácia chybujúceho procesu: 0x970
Čas spustenia chybujúcej aplikácie: 0xplugin-container.exe0
Cesta chybujúcej aplikácie: plugin-container.exe1
Cesta chybujúceho modulu: plugin-container.exe2
Identifikácia hlásenia: plugin-container.exe3
Celé meno chybujúceho balíka: plugin-container.exe4
Identifikácia chybujúcej aplikácie vzhľadom na balík: plugin-container.exe5

Error: (11/25/2015 07:11:48 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Microsoft.Photos.exe version 15.1120.13270.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

Process ID: 1324

Start Time: 01d127ac91d998da

Termination Time: 4294967295

Application Path: C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1120.13270.0_x86__8wekyb3d8bbwe\Microsoft.Photos.exe

Report Id: f412542e-939f-11e5-93e6-bc5ff4731384

Faulting package full name: Microsoft.Windows.Photos_15.1120.13270.0_x86__8wekyb3d8bbwe

Faulting package-relative application ID: App

Error: (11/25/2015 07:11:45 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Adam-PC)
Description: Aktivácia aplikácie Microsoft.Windows.Photos_8wekyb3d8bbwe!App zlyhala pre chybu: -2144927142 Ďalšie informácie nájdete v denníku Microsoft-Windows-TWinUI/Operational.

Error: (11/25/2015 05:30:52 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: NT AUTHORITY)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.


System errors:
=============
Error: (12/03/2015 11:03:56 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Počas čakania na pripojenie služby Sync Host_3f24a bol dosiahnutý časový limit (30000 ms).

Error: (12/03/2015 11:03:55 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Počas čakania na pripojenie služby Ukladací priestor používateľských údajov_3f24a bol dosiahnutý časový limit (30000 ms).

Error: (12/03/2015 11:03:55 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: Správca riadenia služieb sa po neočakávanom ukončení služby Ukladací priestor používateľských údajov_3f24a pokúsil vykonať opravnú akciu (Reštartovať službu), ale táto činnosť zlyhala s nasledujúcou chybou: 
%%1056

Error: (12/03/2015 11:03:45 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Prístup k používateľským údajom_3f24a sa neočakávane ukončila. Služba sa týmto spôsobom ukončila už 1 krát. O 10000 ms bude vykonaná nasledujúca opravná akcia: Reštartovať službu.

Error: (12/03/2015 11:03:45 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Ukladací priestor používateľských údajov_3f24a sa neočakávane ukončila. Služba sa týmto spôsobom ukončila už 1 krát. O 10000 ms bude vykonaná nasledujúca opravná akcia: Reštartovať službu.

Error: (12/03/2015 11:03:45 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Kontaktné údaje_3f24a sa neočakávane ukončila. Služba sa týmto spôsobom ukončila už 1 krát. O 10000 ms bude vykonaná nasledujúca opravná akcia: Reštartovať službu.

Error: (12/03/2015 11:03:45 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Sync Host_3f24a sa neočakávane ukončila. Služba sa týmto spôsobom ukončila už 1 krát. O 10000 ms bude vykonaná nasledujúca opravná akcia: Reštartovať službu.

Error: (12/03/2015 05:46:23 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Spustenie služby NetTcpPortSharing, od ktorej závisí služba NetTcpActivator, zlyhalo kvôli nasledujúcej chybe: 
%%1058

Error: (12/03/2015 05:45:58 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (EventID: 6) (User: NT AUTHORITY)
Description: Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware.

Error: (12/03/2015 05:43:44 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Sync Host_1fadd sa neočakávane ukončila. Služba sa týmto spôsobom ukončila už 1 krát. O 10000 ms bude vykonaná nasledujúca opravná akcia: Reštartovať službu.


CodeIntegrity:
===================================
  Date: 2015-12-03 17:47:04.690
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2015-11-29 21:41:42.773
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2015-11-25 22:08:45.560
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2015-11-25 17:27:08.876
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2015-11-21 13:12:44.969
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2015-11-20 00:10:17.402
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2015-11-20 00:10:13.946
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2015-11-19 23:43:07.899
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.


==================== Memory info =========================== 

Processor: AMD Athlon(tm) 64 Processor 3200+
Percentage of memory in use: 80%
Total physical RAM: 1023.24 MB
Available physical RAM: 202.57 MB
Total Virtual: 2751.24 MB
Available Virtual: 1167.4 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:49.48 GB) (Free:19.46 GB) NTFS
Drive d: (ARCHIV) (Fixed) (Total:139.89 GB) (Free:83.76 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 189.9 GB) (Disk ID: 19D719D7)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=49.5 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)
Partition 4: (Not Active) - (Size=139.9 GB) - (Type=OF Extended)

==================== End of Addition.txt ============================