﻿Additional scan result of Farbar Recovery Scan Tool (x64) Version:07-01-2015
Ran by Kosikovi (2016-01-07 22:32:49)
Running from C:\Users\Kosikovi\Desktop
Windows 10 Pro (X64) (2015-08-03 12:28:30)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1160693568-430831602-594197804-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1160693568-430831602-594197804-503 - Limited - Disabled)
Guest (S-1-5-21-1160693568-430831602-594197804-501 - Limited - Disabled)
Kosikovi (S-1-5-21-1160693568-430831602-594197804-1001 - Administrator - Enabled) => C:\Users\Kosikovi

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 15.009.20079 - Adobe Systems Incorporated)
Adobe Flash Player 20 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 20.0.0.267 - Adobe Systems Incorporated)
Akamai NetSession Interface (HKU\S-1-5-21-1160693568-430831602-594197804-1001\...\Akamai) (Version:  - Akamai Technologies, Inc)
Aktualizace NVIDIA 17.12.8 (Version: 17.12.8 - NVIDIA Corporation) Hidden
Aktualizace produktu Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISE_{0A1FAC46-B899-421D-B1A2-470896DC45DB}) (Version:  - Microsoft)
Aktualizace produktu Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISE_{5260BB53-C1F7-4A3B-9AEB-3EC9B37FF194}) (Version:  - Microsoft)
Aktualizace produktu Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISE_{E68DD413-B834-4923-8181-0A03B7555187}) (Version:  - Microsoft)
ASUS GameOSD Utility (x32 Version: 1.00.0000 - Your Company Name) Hidden
ASUS GPU TweakII (x32 Version: 1.0.5.7 - ASUSTek COMPUTER INC.) Hidden
AVG Web TuneUp (HKLM-x32\...\AVG Web TuneUp) (Version: 4.2.4.155 - AVG Technologies)
Camtasia Studio 8 (HKLM-x32\...\{A0FC961E-DC6D-4144-9277-ECDBB99D0AB9}) (Version: 8.5.1.1962 - TechSmith Corporation)
CCleaner (HKLM\...\CCleaner) (Version: 5.13 - Piriform)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
EA SPORTS™ FIFA 15 (HKLM-x32\...\{3D4ADA2B-F028-4307-ADF4-6F9AA44725DA}) (Version: 1.4.0.0 - Electronic Arts)
Fotogalerie (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 47.0.2526.106 - Google Inc.)
Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden
GTA San Andreas (HKLM-x32\...\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}) (Version: 1.00.00001 - Rockstar Games)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Java 8 Update 66 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218066F0}) (Version: 8.0.660.18 - Oracle Corporation)
Java(TM) SE Development Kit 6 Update 18 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0160180}) (Version: 1.6.0.180 - Sun Microsystems, Inc.)
jetAudio Basic (HKLM-x32\...\{DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A}) (Version: 8.1.0 - COWON)
Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 43.0.4 (x86 cs) (HKLM-x32\...\Mozilla Firefox 43.0.4 (x86 cs)) (Version: 43.0.4 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 43.0.4.5848 - Mozilla)
NVIDIA GeForce Experience 2.2.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.2.2 - NVIDIA Corporation)
NVIDIA Ovladač 3D Vision 341.92 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 341.92 - NVIDIA Corporation)
NVIDIA Ovladač řídící jednotky 3D Vision 340.50 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 340.50 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 341.92 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 341.92 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
Opera Stable 34.0.2036.25 (HKLM-x32\...\Opera 34.0.2036.25) (Version: 34.0.2036.25 - Opera Software)
Origin (HKLM-x32\...\Origin) (Version: 9.7.2.53208 - Electronic Arts, Inc.)
Ovládací panel NVIDIA 341.92 (Version: 341.92 - NVIDIA Corporation) Hidden
Paint.NET v3.5.10 (HKLM\...\{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}) (Version: 3.60.0 - dotPDN LLC)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.2.612.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
Seznam Software (HKU\S-1-5-21-1160693568-430831602-594197804-1001\...\SeznamInstall) (Version:  - Seznam.cz)
SHIELD Streaming (Version: 4.0.1000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 17.12.8 - NVIDIA Corporation) Hidden
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.5.0.9082 - Microsoft Corporation)
Skype™ 7.5 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.5.102 - Skype Technologies S.A.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Unity Web Player (HKU\S-1-5-21-1160693568-430831602-594197804-1001\...\UnityWebPlayer) (Version: 2.6.1f3_31223 - Unity Technologies ApS)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinRAR 5.21 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1160693568-430831602-594197804-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Kosikovi\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\FileCoAuth.exe (Microsoft Corporation)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {06188599-CAE0-4E3E-BE25-24549B77EBEF} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {0F3A202E-249A-4E1A-90FB-C3E0D6E256E8} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {1E8059DE-E0BB-46BE-A3B7-185AFB177336} - System32\Tasks\Opera scheduled Autoupdate 1440498617 => C:\Program Files (x86)\Opera\launcher.exe [2015-12-04] (Opera Software)
Task: {29732658-79BC-4813-B64E-7A32B2308F06} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {39B8C12E-E3BF-4F0B-A931-24ADF12E530D} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {4D3CDCA5-AF14-4613-8B26-84A4307F67BB} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2015-11-09] (Oracle Corporation)
Task: {503A1620-D9CA-401A-B581-BFA21E97BD12} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-16] (Google Inc.)
Task: {571FE50D-0DDC-4B1E-9E0D-9E6FEAA89B9A} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated)
Task: {59FC6E85-4DB6-4300-955A-35407DD62DFA} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-12-29] (Adobe Systems Incorporated)
Task: {5EC0C383-A4AC-4D42-83B7-25B19BC1BBFF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-16] (Google Inc.)
Task: {61397AEF-B961-4663-AA64-BB8E323D1A7D} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {621D0ECD-F33E-4912-AE0C-F17A3E336C79} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {943B820B-D0B1-4B04-8B51-0B3373D3B886} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {9BB52002-E20D-4ADC-9D2E-1E11B0AB657E} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {9F89CC30-CADD-4426-8CAD-D1145C61C4E5} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {A20B2CAE-96B0-4388-B8C9-A8AC43E1FEAA} - System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig => config upnphost start= auto
Task: {B42B9551-E478-48F7-9B98-0CC180A2BBB1} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {C8D32FDF-DB70-4E48-9B86-55A8ADDE7E0E} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\AVG\AVG PC TuneUp\OneClick.exe
Task: {CA1BE266-18C4-4226-A14B-B6EB34BF88B6} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe
Task: {D113E51C-6858-4351-87CF-1FE36D214834} - System32\Tasks\Open Chrome => Chrome.exe toolbar.avg.com/ch-uninstall?cid={E0292357-0B10-4A5D-B8DB-E55F03FCCDE3}&amp;mid=d5948c4f18e247cd9dc0c1f60e99b4f4-3e1724757f7bf6a441a70eb1e8bcc952a4b63c1f&amp;lang=cs&amp;ds=AVG&amp;coid=avgtbavg&amp;cmpid=1015tb&amp;pr=fr&amp;d=&amp;v=4.2.4.155&amp;pid=wtu&amp;sg=
Task: {E2A2B585-3D09-4282-9076-EA471BBDAF1A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-12-08] (Piriform Ltd)
Task: {F0542BA0-A37E-450A-AF8D-164596527F53} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2015-08-03 14:13 - 2015-07-15 03:04 - 00032768 _____ () C:\WINDOWS\SYSTEM32\licensemanagerapi.dll
2015-07-10 11:27 - 2015-12-16 16:22 - 01164688 _____ () C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe
2015-08-19 18:10 - 2015-08-11 10:14 - 00404480 _____ () C:\WINDOWS\System32\diagtrack_wininternal.dll
2015-05-28 19:28 - 2015-05-28 19:28 - 00048640 _____ () C:\Windows\SysWOW64\ASGT.exe
2015-10-01 13:51 - 2015-09-17 07:48 - 02494712 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2015-06-17 17:20 - 2015-05-26 12:35 - 00079872 _____ () C:\Users\Kosikovi\AppData\Roaming\Seznam.cz\bin\18551libfoxloader-x64.dll
2015-10-01 13:51 - 2015-09-17 07:48 - 02494712 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-10-01 13:50 - 2015-09-17 06:48 - 00429056 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2015-07-10 11:59 - 2015-07-10 11:59 - 00143360 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\XamlTileRendering.dll
2015-10-01 13:51 - 2015-09-17 06:44 - 06569472 _____ () C:\WINDOWS\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2015-10-01 13:50 - 2015-09-17 06:42 - 00471040 _____ () C:\WINDOWS\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2015-10-01 13:50 - 2015-09-17 06:42 - 01808384 _____ () C:\WINDOWS\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2015-10-01 13:51 - 2015-09-17 06:43 - 02274816 _____ () C:\WINDOWS\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-07-10 12:00 - 2015-07-10 17:05 - 00210432 _____ () C:\WINDOWS\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.ProxyStub.dll
2015-06-17 17:20 - 2015-05-26 12:38 - 00457384 _____ () C:\Users\Kosikovi\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
2015-06-17 17:20 - 2015-05-26 12:36 - 00073896 _____ () C:\Users\Kosikovi\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
2015-12-08 20:25 - 2015-12-08 20:25 - 00047616 _____ () C:\Program Files\CCleaner\lang\lang-1029.dll
2015-06-17 17:20 - 2015-05-26 12:37 - 00078504 _____ () C:\Users\Kosikovi\AppData\Roaming\Seznam.cz\bin\18548libfoxloader.dll
2015-06-17 17:20 - 2015-05-26 12:38 - 00862888 _____ () C:\Users\Kosikovi\AppData\Roaming\Seznam.cz\bin\lightspeed.dll
2015-06-17 17:20 - 2015-05-26 12:39 - 01778376 _____ () C:\Users\Kosikovi\AppData\Roaming\Seznam.cz\bin\libfoxcub.dll
2015-02-15 22:51 - 2012-06-25 10:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\WINDOWS\system32\Drivers\rglpaoaf.sys:changelist

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 14:25 - 2016-01-07 21:42 - 00000826 ____A C:\WINDOWS\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1160693568-430831602-594197804-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Kosikovi\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\{7bf108c7-b554-4d15-92cd-dbe135cc5045}.jpg
DNS Servers: 192.168.30.254 - 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is disabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

HKLM\...\StartupApproved\StartupFolder: => "McAfee Security Scan Plus.lnk"
HKLM\...\StartupApproved\Run32: => "seznam-listicka-distribuce"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKU\S-1-5-21-1160693568-430831602-594197804-1001\...\StartupApproved\Run: => "Skype"
HKU\S-1-5-21-1160693568-430831602-594197804-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-1160693568-430831602-594197804-1001\...\StartupApproved\Run: => "cz.seznam.software.autoupdate"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [UDP Query User{99906D40-E888-495C-A579-43964F605E59}C:\users\kosikovi\appdata\roaming\utorrent\utorrent.exe] => (Block) C:\users\kosikovi\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [TCP Query User{2E9863AF-7D6A-4BDE-88B3-924A8844CDB3}C:\users\kosikovi\appdata\roaming\utorrent\utorrent.exe] => (Block) C:\users\kosikovi\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [UDP Query User{66D34840-DF0F-448E-9999-42EBDC25D5AA}C:\users\kosikovi\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\kosikovi\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [TCP Query User{97B95668-D61F-491B-814B-7131E100B842}C:\users\kosikovi\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\kosikovi\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [{7D9CB52C-8EA5-4E35-83A9-0D9E4E7B9BBA}] => (Allow) LPort=1900
FirewallRules: [{EB25AA06-557B-4D81-8166-563E2046CBFE}] => (Allow) LPort=2869
FirewallRules: [{A2E62007-D5D0-4484-B1FD-A0DBFD0DAA7B}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{F2AEAB3F-6AC2-4FA5-A4B7-F6C174588D22}] => (Allow) LPort=8317
FirewallRules: [{8C67EBCD-A0E1-4798-9335-35EEBA44BD49}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C5C18635-925E-47BA-9C57-BC7221C25FFB}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [UDP Query User{1835ACEA-AEF8-47B0-9379-743287C2FBFD}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{3C9A736E-47E8-4E3E-A528-88B92C98E527}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{AD1D09BD-B263-481A-8913-CD8DF67D0C27}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{2C32E284-7B4F-4C8C-AFE2-8F32451FC2D2}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{B5FBD0E2-25DC-404A-A455-28696DC9C79F}C:\users\kosikovi\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\kosikovi\appdata\local\akamai\netsession_win.exe
FirewallRules: [TCP Query User{3DBDAC6D-F6E6-4867-9E28-1BEAE284A5ED}C:\users\kosikovi\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\kosikovi\appdata\local\akamai\netsession_win.exe
FirewallRules: [{F33E870D-012B-4843-925E-591FA89F0B68}] => (Allow) C:\ProgramData\NexonEU\NGM\NGM.exe
FirewallRules: [{B6F3F4FD-D655-405B-93F4-18389EB318DE}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{582F56C6-D650-4665-B0F1-9272EFC6F37A}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [TCP Query User{6A99F02C-551A-4A92-A00C-CD117032B32D}C:\users\kosikovi\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\kosikovi\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{A85F6601-F958-4429-88F2-2371168FE5DC}C:\users\kosikovi\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\kosikovi\appdata\local\akamai\netsession_win.exe
FirewallRules: [{1A67BC9B-9135-45B9-81EB-68BF81FEF903}] => (Allow) C:\Users\Kosikovi\AppData\Roaming\uTorrent\utorrent.exe
FirewallRules: [{9AAEAB8A-69F7-4D48-92D9-BCF687CFC36E}] => (Allow) C:\Users\Kosikovi\AppData\Roaming\uTorrent\utorrent.exe
FirewallRules: [{552C1922-160A-464B-8DED-8C27BFBECC9A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{0DB809D2-5120-423C-BAA5-AE214496C40B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{4464285B-370C-4E04-A2BC-43D016341D52}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [TCP Query User{B24D9ECB-6A82-4FC2-A807-927E30ABD819}C:\users\kosikovi\appdata\roaming\.minecraft\java\bin\javaw.exe] => (Block) C:\users\kosikovi\appdata\roaming\.minecraft\java\bin\javaw.exe
FirewallRules: [UDP Query User{07BA3531-53AB-48B3-8486-B0B076B46F6B}C:\users\kosikovi\appdata\roaming\.minecraft\java\bin\javaw.exe] => (Block) C:\users\kosikovi\appdata\roaming\.minecraft\java\bin\javaw.exe
FirewallRules: [{29EC438D-1963-4533-9BB1-553F0C5B70BD}] => (Allow) C:\hry\FIFA 15\fifasetup\fifaconfig.exe
FirewallRules: [{99E19898-C1BC-49B3-BCF2-CABCA0ED2D21}] => (Allow) C:\hry\FIFA 15\fifasetup\fifaconfig.exe
FirewallRules: [{83217225-A9F2-4087-83EA-1DD283D98F4A}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{32D3A414-8D2F-4297-9207-CE940E0D6B1E}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{B8D022E6-9B41-498A-86B8-FFAD58F814DF}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{1FFC12D3-BEE4-4675-AB6A-D06DD3AB1477}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{C2B488E0-D03D-4859-9D21-6D745D5593C5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{A32B14FF-E6BF-400A-AAA3-E81866442FF4}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe

==================== Restore Points =========================

ATTENTION: System Restore is disabled

==================== Faulty Device Manager Devices =============

Name: Enhanced Display Driver Helper Service
Description: Enhanced Display Driver Helper Service
Class Guid: {5458011f-08d4-4605-93a2-f03e61bedba3}
Manufacturer: ASUSTeK
Service: asuskbnt
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (01/07/2016 10:24:06 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Služba Šifrování selhala při volání OnIdentity() v objektu System Writer.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Protokol Microsoft LLDP (Link-Layer Discovery Protocol).

System Error:
Přístup byl odepřen.
.

Error: (01/07/2016 09:45:09 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcFailed continue stopping. [0]

Error: (01/07/2016 09:34:18 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: KosikPC)
Description: Aplikaci Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI se nepovedlo aktivovat, protože došlo k chybě: -2147023170. Další informace najdete v protokolu Microsoft-Windows-TWinUI/Operational.

Error: (01/07/2016 09:34:15 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: KosikPC)
Description: Aplikaci Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy!App se nepovedlo aktivovat, protože došlo k chybě: -2147023170. Další informace najdete v protokolu Microsoft-Windows-TWinUI/Operational.

Error: (01/07/2016 09:34:16 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: SearchUI.exe, verze: 10.0.10240.16515, časové razítko: 0x55fa5578
Název chybujícího modulu: Windows.UI.Xaml.dll, verze: 10.0.10240.16548, časové razítko: 0x56133a14
Kód výjimky: 0xc000027b
Posun chyby: 0x000000000044b4d8
ID chybujícího procesu: 0x900
Čas spuštění chybující aplikace: 0xSearchUI.exe0
Cesta k chybující aplikaci: SearchUI.exe1
Cesta k chybujícímu modulu: SearchUI.exe2
ID zprávy: SearchUI.exe3
Úplný název chybujícího balíčku: SearchUI.exe4
ID aplikace související s chybujícím balíčkem: SearchUI.exe5

Error: (01/07/2016 09:34:16 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: SearchUI.exe, verze: 10.0.10240.16515, časové razítko: 0x55fa5578
Název chybujícího modulu: atklumdispx.dll, verze: 7.14.10.304, časové razítko: 0x4bcc2d2c
Kód výjimky: 0xc0000005
Posun chyby: 0x00000000000079d5
ID chybujícího procesu: 0x900
Čas spuštění chybující aplikace: 0xSearchUI.exe0
Cesta k chybující aplikaci: SearchUI.exe1
Cesta k chybujícímu modulu: SearchUI.exe2
ID zprávy: SearchUI.exe3
Úplný název chybujícího balíčku: SearchUI.exe4
ID aplikace související s chybujícím balíčkem: SearchUI.exe5

Error: (01/07/2016 09:34:15 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: SearchUI.exe, verze: 10.0.10240.16515, časové razítko: 0x55fa5578
Název chybujícího modulu: atklumdispx.dll, verze: 7.14.10.304, časové razítko: 0x4bcc2d2c
Kód výjimky: 0xc0000005
Posun chyby: 0x00000000000079d5
ID chybujícího procesu: 0x900
Čas spuštění chybující aplikace: 0xSearchUI.exe0
Cesta k chybující aplikaci: SearchUI.exe1
Cesta k chybujícímu modulu: SearchUI.exe2
ID zprávy: SearchUI.exe3
Úplný název chybujícího balíčku: SearchUI.exe4
ID aplikace související s chybujícím balíčkem: SearchUI.exe5

Error: (01/07/2016 09:34:15 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: SearchUI.exe, verze: 10.0.10240.16515, časové razítko: 0x55fa5578
Název chybujícího modulu: atklumdispx.dll, verze: 7.14.10.304, časové razítko: 0x4bcc2d2c
Kód výjimky: 0xc0000005
Posun chyby: 0x00000000000079d5
ID chybujícího procesu: 0x900
Čas spuštění chybující aplikace: 0xSearchUI.exe0
Cesta k chybující aplikaci: SearchUI.exe1
Cesta k chybujícímu modulu: SearchUI.exe2
ID zprávy: SearchUI.exe3
Úplný název chybujícího balíčku: SearchUI.exe4
ID aplikace související s chybujícím balíčkem: SearchUI.exe5

Error: (01/07/2016 09:34:14 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: KosikPC)
Description: Aplikaci Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI se nepovedlo aktivovat, protože došlo k chybě: -2147023170. Další informace najdete v protokolu Microsoft-Windows-TWinUI/Operational.

Error: (01/07/2016 09:34:14 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: ShellExperienceHost.exe, verze: 10.0.10240.16515, časové razítko: 0x55fa599a
Název chybujícího modulu: Windows.UI.Xaml.dll, verze: 10.0.10240.16548, časové razítko: 0x56133a14
Kód výjimky: 0xc000027b
Posun chyby: 0x000000000044b4d8
ID chybujícího procesu: 0x340
Čas spuštění chybující aplikace: 0xShellExperienceHost.exe0
Cesta k chybující aplikaci: ShellExperienceHost.exe1
Cesta k chybujícímu modulu: ShellExperienceHost.exe2
ID zprávy: ShellExperienceHost.exe3
Úplný název chybujícího balíčku: ShellExperienceHost.exe4
ID aplikace související s chybujícím balíčkem: ShellExperienceHost.exe5


System errors:
=============
Error: (01/07/2016 10:17:48 PM) (Source: DCOM) (EventID: 10016) (User: KosikPC)
Description: výchozí pro počítačMístníAktivace{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}KosikPCKosikoviS-1-5-21-1160693568-430831602-594197804-1001LocalHost (pomocí LRPC)Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (01/07/2016 10:17:47 PM) (Source: DCOM) (EventID: 10016) (User: KosikPC)
Description: výchozí pro počítačMístníAktivace{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}KosikPCKosikoviS-1-5-21-1160693568-430831602-594197804-1001LocalHost (pomocí LRPC)Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (01/07/2016 10:17:47 PM) (Source: DCOM) (EventID: 10016) (User: KosikPC)
Description: výchozí pro počítačMístníAktivace{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}KosikPCKosikoviS-1-5-21-1160693568-430831602-594197804-1001LocalHost (pomocí LRPC)Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (01/07/2016 10:17:47 PM) (Source: DCOM) (EventID: 10016) (User: KosikPC)
Description: výchozí pro počítačMístníAktivace{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}KosikPCKosikoviS-1-5-21-1160693568-430831602-594197804-1001LocalHost (pomocí LRPC)Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (01/07/2016 10:13:07 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Služba Intel(R) Management and Security Application User Notification Service přestala během spouštění reagovat.

Error: (01/07/2016 10:01:08 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba EIO_XP neuspěla při spuštění v důsledku následující chyby: 
%%577

Error: (01/07/2016 09:52:14 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Hostitel synchronizace_Session1 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.

Error: (01/07/2016 09:30:38 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba EIO_XP neuspěla při spuštění v důsledku následující chyby: 
%%577

Error: (01/07/2016 09:28:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Hostitel synchronizace_Session1 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.

Error: (01/07/2016 09:28:39 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: Správce služeb se pokusil o opravnou akci (Restartovat službu) po nečekaném ukončení služby Windows Search, ale tato akce selhala kvůli následující chybě: 
%%1056


CodeIntegrity:
===================================
  Date: 2016-01-07 22:01:08.967
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\EIO64_XP.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2016-01-07 21:30:38.020
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\EIO64_XP.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2016-01-07 19:50:23.821
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-01-07 15:36:31.625
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\EIO64_XP.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2016-01-07 13:44:52.900
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\EIO64_XP.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2016-01-06 14:34:47.145
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-01-06 14:24:17.006
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\EIO64_XP.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2016-01-05 15:03:16.209
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-01-05 13:54:24.209
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-01-05 13:54:24.193
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info =========================== 

Processor: Intel(R) Core(TM) i3-3220 CPU @ 3.30GHz
Percentage of memory in use: 39%
Total physical RAM: 4063.14 MB
Available physical RAM: 2438.75 MB
Total Virtual: 4767.14 MB
Available Virtual: 2954.14 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:78.12 GB) (Free:20.75 GB) NTFS
Drive d: (Filmy a Seriály) (Fixed) (Total:214.84 GB) (Free:7.36 GB) NTFS
Drive e: (Hry) (Fixed) (Total:117.19 GB) (Free:11.33 GB) NTFS
Drive f: () (Removable) (Total:3.8 GB) (Free:1.21 GB) FAT32
Drive g: (Disk pro opravu Windows 10 64bit) (CDROM) (Total:0.33 GB) (Free:0 GB) UDF
Drive i: (Záloha) (Fixed) (Total:55.5 GB) (Free:7.79 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 2F112F10)
Partition 1: (Not Active) - (Size=993 KB) - (Type=42)
Partition 2: (Active) - (Size=100 MB) - (Type=42)
Partition 3: (Not Active) - (Size=78.1 GB) - (Type=42)
Partition 4: (Not Active) - (Size=387.5 GB) - (Type=42)

========================================================
Disk: 1 (Size: 3.8 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt ============================