﻿Additional scan result of Farbar Recovery Scan Tool (x64) Version:09-05-2016
Ran by MatLen (2016-05-10 17:16:24)
Running from C:\Users\MatLen\Desktop
Windows 10 Home Version 1511 (X64) (2015-12-06 11:18:39)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2712974650-3075997434-2261291459-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2712974650-3075997434-2261291459-503 - Limited - Disabled)
Guest (S-1-5-21-2712974650-3075997434-2261291459-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2712974650-3075997434-2261291459-1003 - Limited - Enabled)
MatLen (S-1-5-21-2712974650-3075997434-2261291459-1001 - Administrator - Enabled) => C:\Users\MatLen

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: AVG Internet Security (Disabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG Internet Security (Disabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}
FW: AVG Internet Security (Enabled) {757AB44A-78C2-7D1A-E37F-CA42A037B368}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

3DStudio In 16 INT (HKLM-x32\...\063FFFFFFF16FF00FF0701F00F02F000-R1) (Version: 16.0 - Graphisoft)
64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Accessories 16 INT (HKLM-x32\...\064FFFFFFF16FF00FF0701F00F02F000-R1) (Version: 16.0 - Graphisoft)
AIO_CDA_ProductContext (x32 Version: 140.0.425.000 - Hewlett-Packard) Hidden
AIO_CDA_Software (x32 Version: 140.0.428.000 - Hewlett-Packard) Hidden
AIO_Scan (x32 Version: 130.0.421.000 - Hewlett-Packard) Hidden
Alcor Micro USB Card Reader Driver  (HKLM-x32\...\AmUStor) (Version: 20.28.3317.04403 - Alcor Micro Corp.)
Alcor Micro USB Card Reader Driver  (x32 Version: 20.28.3317.04403 - Alcor Micro Corp.) Hidden
AMD Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD)
AMD Catalyst Install Manager (HKLM\...\{CF92700C-994C-4B90-026F-A9EE4EA52B38}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
ANT Drivers Installer x64 (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
Apple Application Support (HKLM-x32\...\{A83279FD-CA4B-4206-9535-90974DE76654}) (Version: 2.1.5 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ArchiCAD 16 CZE (HKLM\...\001FFF2FFF16FF00FF1101F01F02F000-R1) (Version: 16.0 - GRAPHISOFT)
ArchiGlazing for ArchiCAD 16 INT (HKLM-x32\...\007FFFFFFF16FF00FF0701F01F02F000-R1) (Version: 16.0 - GRAPHISOFT)
Ashampoo WinOptimizer 11 (HKLM-x32\...\{4209F371-8D72-8119-66FA-897D2D41E27F}_is1) (Version: 11.00.70 - Ashampoo GmbH & Co. KG)
AVG (HKLM\...\AvgZen) (Version: 1.51.2.3593 - AVG Technologies)
AVG (Version: 16.71.7596 - AVG Technologies) Hidden
AVG 2016 (Version: 16.0.4568 - AVG Technologies) Hidden
AVG Protection (HKLM\...\AVG) (Version: 2016.71.7596 - AVG Technologies)
AVG Zen (Version: 1.51.58 - AVG Technologies) Hidden
Balíček ovladače systému Windows - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Balíček ovladače systému Windows - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
Bing Bar (HKLM-x32\...\{16793295-2366-40F7-A045-A3E42A81365E}) (Version: 7.1.362.0 - Microsoft Corporation)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
BufferChm (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden
C4100 (x32 Version: 140.0.425.000 - Hewlett-Packard) Hidden
c4100_Help (x32 Version: 82.0.256.000 - Hewlett-Packard) Hidden
Cinema4D Add-On AC16 INT (HKLM-x32\...\045FFFFFFF16FF00FF0701F01F02F000-R1) (Version: 16.0 - GRAPHISOFT)
Construction Simulation 16 INT (HKLM-x32\...\066FFFFFFF16FF00FF0701F00F02F000-R1) (Version: 16.0 - Graphisoft)
Copy (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden
CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.6.3728 - CyberLink Corp.)
CyberLink MediaEspresso 6.7 (HKLM-x32\...\InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}) (Version: 6.7.1.4928 - CyberLink Corp.)
Cyberlink PhotoDirector (HKLM-x32\...\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.5.4824 - CyberLink Corp.)
CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.6.3702 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.6.3625 - CyberLink Corp.)
CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.3.3626 - CyberLink Corp.)
Cyklotrasy 2.36 (HKLM-x32\...\Cyklotrasy 2.36) (Version:  - )
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Destinations (x32 Version: 140.0.253.000 - Hewlett-Packard) Hidden
DeviceDiscovery (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden
DisableMSDefender (Version: 1.0.0 - Hewlett-Packard Company) Hidden
DocProc (x32 Version: 140.0.185.000 - Hewlett-Packard) Hidden
Dropbox (HKU\S-1-5-21-2712974650-3075997434-2261291459-1001\...\Dropbox) (Version: 3.18.1 - Dropbox, Inc.)
EA SPORTS™ FIFA 15 (HKLM-x32\...\{3D4ADA2B-F028-4307-ADF4-6F9AA44725DA}) (Version: 1.4.0.0 - Electronic Arts)
EGR-ShellExtension (HKLM-x32\...\EGR-ShellExtension) (Version: 1.2.0.101 - EasternGraphics)
Elevated Installer (x32 Version: 4.1.19.0 - Garmin Ltd or its subsidiaries) Hidden
Energy Star (HKLM-x32\...\{FC0ADA4D-8FA5-4452-8AFF-F0A0BAC97EF7}) (Version: 1.0.9 - Hewlett-Packard Company)
Euro Truck Simulator 2 (HKLM-x32\...\{1B705E8F-9893-4486-B5D7-4F7FEB9C871E}_is1) (Version: 1.14.2 - SCS Software)
Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
Fax (x32 Version: 140.0.307.000 - Hewlett-Packard) Hidden
Floor Plan Maker 7.9 (HKLM-x32\...\Floor Plan Maker_is1) (Version:  - EdrawSoft)
FMW 1 (Version: 1.73.2 - AVG Technologies) Hidden
Football Manager 2015 version 15.3.2 (HKLM-x32\...\{BD2F10CE-5561-4A0A-BD82-EB56E87D4FFB}_is1) (Version: 15.3.2 - SEGA)
Fotolab Fotosvet (HKLM-x32\...\Fotolab Fotosvet) (Version: 6.0.5 - CEWE Stiftung u Co. KGaA)
Garmin Express (HKLM-x32\...\{2639b4f0-83b4-4f3d-942f-e4ba22a40b9b}) (Version: 4.1.19.0 - Garmin Ltd or its subsidiaries)
Garmin Express (x32 Version: 4.1.19.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express Tray (x32 Version: 4.1.19.0 - Garmin Ltd or its subsidiaries) Hidden
Google Drive (HKLM-x32\...\{D7269C20-B3CE-4CD0-8E88-3D307D3BD41A}) (Version: 1.29.2074.1528 - Google, Inc.)
Google Earth Connections AC16 INT (HKLM-x32\...\039FFFFFFF16FF00FF0701F01F02F000-R1) (Version: 16.0 - GRAPHISOFT)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 50.0.2661.94 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
GPBaseService2 (x32 Version: 140.0.297.000 - Hewlett-Packard) Hidden
Grand Theft Auto V (HKLM-x32\...\Grand Theft Auto V_is1) (Version: 1.0.350.1 - Rockstar)
HeavyLoad V3.3 (64 bit) (HKLM\...\HeavyLoad_is1) (Version: 3.3 - JAM Software)
Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
High-Definition Video Playback 10 (x32 Version: 7.0.11400.29.0 - Nero AG) Hidden
HP Customer Participation Program 14.0 (HKLM\...\HPExtendedCapabilities) (Version: 14.0 - HP)
HP Documentation (HKLM-x32\...\{06600E94-1C34-40E2-AB09-D30AECF78172}) (Version: 1.1.0.0 - Hewlett-Packard)
HP Imaging Device Functions 14.0 (HKLM\...\HP Imaging Device Functions) (Version: 14.0 - HP)
HP Photosmart All-In-One Driver Software (HKLM\...\{4F6C1178-3FC0-44BB-8F9A-28D8516DFEE2}) (Version: 14.0 - HP)
HP Registration Service (HKLM\...\{D1E8F2D7-7794-4245-B286-87ED86C1893C}) (Version: 1.2.7493.4758 - Hewlett-Packard)
HP SimplePass (HKLM-x32\...\InstallShield_{314FAD12-F785-4471-BCE8-AB506642B9A1}) (Version: 8.01.06 - Hewlett-Packard)
HP Solution Center 14.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 14.0 - HP)
HP Support Assistant (HKLM-x32\...\{79C54A05-F146-4EA0-8A70-D4EFE6181E52}) (Version: 8.2.8.25 - Hewlett-Packard Company)
HP Support Information (HKLM-x32\...\{B2B7B1C8-7C8B-476C-BE2C-049731C55992}) (Version: 13.00.0000 - Hewlett-Packard)
HP Support Solutions Framework (HKLM-x32\...\{79CA8D8A-8371-4146-8920-C1405318E65E}) (Version: 12.2.8.17 - Hewlett-Packard Company)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPPhotoGadget (x32 Version: 140.0.524.000 - Hewlett-Packard) Hidden
HPProductAssistant (x32 Version: 140.0.298.000 - Hewlett-Packard) Hidden
HPSSupply (x32 Version: 140.0.297.000 - Hewlett-Packard) Hidden
HydraVision (x32 Version: 4.2.252.0 - Advanced Micro Devices, Inc.) Hidden
Check Duplicates Tool 16 INT (HKLM-x32\...\065FFFFFFF16FF00FF0701F00F02F000-R1) (Version: 16.0 - Graphisoft)
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6496.0 - IDT)
Inst5675 (Version: 8.01.06 - Softex Inc.) Hidden
Inst5676 (Version: 8.01.06 - Softex Inc.) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1158 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.5.0.1081 - Intel Corporation)
Intel® Chipset Device Software (x32 Version: 10.1.1.9 - Intel(R) Corporation) Hidden
Intel® Security Assist (HKLM-x32\...\{4B230374-6475-4A73-BA6E-41015E9C5013}) (Version: 1.0.0.532 - Intel Corporation)
Interior Wizard 16 INT (HKLM-x32\...\071FFFFFFF16FF00FF0701F00F02F000-R1) (Version: 16.0 - Graphisoft)
Intersections in Combos 16 INT (HKLM-x32\...\072FFFFFFF16FF00FF0701F00F02F000-R1) (Version: 16.0 - Graphisoft)
Java 8 Update 66 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218066F0}) (Version: 8.0.660.18 - Oracle Corporation)
Java(TM) 6 Update 32 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216032FF}) (Version: 6.0.320 - Oracle)
K-Lite Codec Pack 4.3.1 (Full) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 4.3.1 - )
MarketResearch (x32 Version: 140.0.299.000 - Hewlett-Packard) Hidden
Mesh to Roof Tool 16 INT (HKLM-x32\...\073FFFFFFF16FF00FF0701F00F02F000-R1) (Version: 16.0 - Graphisoft)
Microsoft Office 365 ProPlus - cs-cz (HKLM\...\O365ProPlusRetail - cs-cz) (Version:  - Microsoft Corporation)
Microsoft Primary Interoperability Assemblies 2005 (HKLM-x32\...\{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
MyPhoneExplorer (HKLM-x32\...\MPE) (Version: 1.8.6 - F.J. Wechselberger)
Nero BackItUp 10 (HKLM-x32\...\{68AB6930-5BFF-4FF6-923B-516A91984FE6}) (Version: 5.4.11600.19.100 - Nero AG)
Nero Burning ROM 10 (HKLM-x32\...\{7A5D731D-B4B3-490E-B339-75685712BAAB}) (Version: 10.0.11100.10.100 - Nero AG)
Nero BurnRights 10 (HKLM-x32\...\{943CFD7D-5336-47AF-9418-E02473A5A517}) (Version: 4.0.11000.12.100 - Nero AG)
Nero CoverDesigner 10 (HKLM-x32\...\{FCF00A6E-FB58-477A-ABE9-232907105521}) (Version: 5.0.10900.11.100 - Nero AG)
Nero DiscSpeed 10 (HKLM-x32\...\{34490F4E-48D0-492E-8249-B48BECF0537C}) (Version: 6.0.10800.7.100 - Nero AG)
Nero Express 10 (HKLM-x32\...\{70550193-1C22-445C-8FA4-564E155DB1A7}) (Version: 10.0.11000.10.100 - Nero AG)
Nero InfoTool 10 (HKLM-x32\...\{F412B4AF-388C-4FF5-9B2F-33DB1C536953}) (Version: 7.0.10800.8.100 - Nero AG)
Nero MediaHub 10 (HKLM-x32\...\{1F7FB68F-52F6-46A3-B42F-38CE46295AE5}) (Version: 1.0.13400.11.100 - Nero AG)
Nero Multimedia Suite 10 (HKLM-x32\...\{277C1559-4CF7-44FF-8D07-98AA9C13AABD}) (Version: 10.0.13100 - Nero AG)
Nero Recode 10 (HKLM-x32\...\{8ECEC853-5C3D-4B10-B5C7-FF11FF724807}) (Version: 4.6.10900.4.100 - Nero AG)
Nero RescueAgent 10 (HKLM-x32\...\{E337E787-CF61-4B7B-B84F-509202A54023}) (Version: 3.0.10900.9.100 - Nero AG)
Nero SoundTrax 10 (HKLM-x32\...\{E1EE5339-5D32-458F-BAAB-B19F6301BCE2}) (Version: 4.6.10600.2.100 - Nero AG)
Nero StartSmart 10 (HKLM-x32\...\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}) (Version: 10.0.11200.12.100 - Nero AG)
Nero Update (HKLM-x32\...\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: 1.0.0017 - Nero AG)
Nero Vision 10 (HKLM-x32\...\{9A4297F3-2A51-4ED9-92CA-4BCB8380947E}) (Version: 7.0.11100.8.100 - Nero AG)
Nero WaveEditor 10 (HKLM-x32\...\{EDCDFAD5-DF80-4600-A493-E9DAD6810230}) (Version: 5.6.10600.2.100 - Nero AG)
Network64 (Version: 140.0.306.000 - Hewlett-Packard) Hidden
NVIDIA PhysX (HKLM-x32\...\{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}) (Version: 9.10.0514 - NVIDIA Corporation)
OCR Software by I.R.I.S. 14.0 (HKLM\...\HPOCR) (Version: 14.0 - HP)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4815.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4815.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4815.1002 - Microsoft Corporation) Hidden
Ogg Codecs 0.81.15562 (HKLM-x32\...\Ogg Codecs) (Version: 0.81.15562 - Xiph.Org)
Philips Songbird (HKLM-x32\...\Philips Songbird) (Version: 6.1.2265 (2265) - Koninklijke Philips Electronics N.V.)
Polygon Counting Tool 16 INT (HKLM-x32\...\074FFFFFFF16FF00FF0701F00F02F000-R1) (Version: 16.0 - Graphisoft)
Profiler 16 INT (HKLM-x32\...\075FFFFFFF16FF00FF0701F00F02F000-R1) (Version: 16.0 - Graphisoft)
RAL Colour System 16 INT (HKLM-x32\...\076FFFFFFF16FF00FF0701F00F02F000-R1) (Version: 16.0 - Graphisoft)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.30164 - Realtek Semiconductor Corp.)
Recovery Manager (x32 Version: 5.5.0.7316 - CyberLink Corp.) Hidden
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.1.5.8 - Rockstar Games)
Scan (x32 Version: 140.0.253.000 - Hewlett-Packard) Hidden
Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 14.0 - HP)
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 8.1.0.9134 - Microsoft Corporation)
Skype™ 7.18 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.112 - Skype Technologies S.A.)
SolutionCenter (x32 Version: 140.0.299.000 - Hewlett-Packard) Hidden
Status (x32 Version: 140.0.342.000 - Hewlett-Packard) Hidden
Supertintin 1.2.0.4 (HKLM-x32\...\Supertintin Skype Video Call Recorder_is1) (Version: =1.2.0.4 - Imtiger Software Inc.)
Tekla BIMsight (HKLM\...\{8B2438C3-C1A6-488C-AF5D-740DE0613CCF}) (Version: 1.7.0 - Tekla Corporation)
Tekla Model Sharing Foundation, Clash Check 2.7 (HKLM-x32\...\{8DFA9AE5-A5BD-4976-952F-75E95E72D6BD}) (Version: 2.7.0 - Tekla Corporation)
Tekla Model Sharing Foundation, DGN import plugin 1.10 (HKLM-x32\...\{E676CB50-E1FD-436E-A269-76D0DC5E8A2B}) (Version: 1.10.0 - Tekla Corporation)
Tekla Model Sharing Foundation, DWG import plugin 1.14 (HKLM-x32\...\{62E2074A-7F70-4C58-931E-0D4DC66844F6}) (Version: 1.14.0 - Tekla Corporation)
Tekla Model Sharing Foundation, IFC import plugin 1.65 (HKLM-x32\...\{AF4B14BE-CBE7-452E-A1F7-C15EE9556C09}) (Version: 1.65.0 - Tekla Corporation)
Tekla Model Sharing Foundation, WebViewerXml plugin 1.9 (HKLM-x32\...\{4614B232-B595-4CF2-A4A6-DC6D29D11051}) (Version: 1.9.0 - Tekla Corporation)
Toolbox (x32 Version: 140.0.596.000 - Hewlett-Packard) Hidden
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.51a - Ghisler Software GmbH)
TrayApp (x32 Version: 140.0.297.000 - Hewlett-Packard) Hidden
Unity Web Player (HKU\S-1-5-21-2712974650-3075997434-2261291459-1001\...\UnityWebPlayer) (Version: 5.2.0f3 - Unity Technologies ApS)
Viber (HKU\S-1-5-21-2712974650-3075997434-2261291459-1001\...\Viber) (Version: 5.2.0.2546 - Viber Media Inc)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
WebReg (x32 Version: 140.0.297.017 - Hewlett-Packard) Hidden
WibuKey Setup (WibuKey Remove) (HKLM\...\{00060000-0000-1004-8002-0000C06B5161}) (Version: Version 6.00d of 2011-Sep-22 (Build 138) (Setup) - WIBU-SYSTEMS AG)
Winamp (HKLM-x32\...\Winamp) (Version: 5.666  - Nullsoft, Inc)
XnView 2.32 (HKLM-x32\...\XnView_is1) (Version: 2.32 - Gougelet Pierre-e)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-2712974650-3075997434-2261291459-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\MatLen\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2712974650-3075997434-2261291459-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\MatLen\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\FileCoAuth.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2712974650-3075997434-2261291459-1001_Classes\CLSID\{DEDBE4C9-9E87-40C5-B437-9AAB7EB9C667}\InprocServer32 -> C:\Program Files (x86)\EasternGraphics\EGR-ShellExtension\Win64\egr_se.dll (EasternGraphics)
CustomCLSID: HKU\S-1-5-21-2712974650-3075997434-2261291459-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\MatLen\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2712974650-3075997434-2261291459-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\MatLen\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2712974650-3075997434-2261291459-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\MatLen\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2712974650-3075997434-2261291459-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\MatLen\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2712974650-3075997434-2261291459-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\MatLen\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2712974650-3075997434-2261291459-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\MatLen\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2712974650-3075997434-2261291459-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\MatLen\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2712974650-3075997434-2261291459-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\MatLen\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2712974650-3075997434-2261291459-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\MatLen\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2712974650-3075997434-2261291459-1001_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\MatLen\AppData\Roaming\Dropbox\bin\DropboxExt64.30.dll (Dropbox, Inc.)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0171EFB7-38D0-419F-98B5-F03E886D7F62} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2016-04-06] (Hewlett-Packard)
Task: {0DF69934-F51E-46D4-ADDB-5D258DDB8B22} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {100F110F-8824-4F79-9DC8-AD3B1FADA563} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-10-28] (Microsoft Corporation)
Task: {12A6B3CE-89D8-4C1B-A990-65675183BAFB} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {28F9F569-1E0C-4F35-84D5-72451EDB2133} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {2AC76349-A7AD-4C37-AAEE-C6978A0BDF3F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater - Resources => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-03-07] (Hewlett-Packard)
Task: {3809B4E6-CF36-415C-B840-6CB219ECB594} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {3D72E124-F9CC-4472-8D62-7FC7F6D292F8} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {434A4794-4FDA-42FA-9837-95464EF739EE} - System32\Tasks\{E1331C18-3099-426B-86C0-18473A5E216D} => pcalua.exe -a F:\ppk.exe -d F:\
Task: {594F66EA-20FE-42D4-B19B-C920453F0F82} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-02-18] (Hewlett-Packard Company)
Task: {621B9870-CB9D-4EA2-BBAC-6966448AD1F0} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-02-09] (Microsoft Corporation)
Task: {6EA28A72-796E-460D-AEF2-C1FDD02C1110} - System32\Tasks\One-Click Optimizer WO11 => C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 11\WO11.exe [2015-07-09] (Ashampoo Development GmbH & Co. KG)
Task: {71C2C952-C2D7-42ED-B118-731BC6A4983E} - System32\Tasks\{515EA16A-3946-4662-989D-B840864625F9} => pcalua.exe -a K:\START.EXE -d K:\
Task: {83A12D96-FC8C-4AC5-95CC-6D8AA6C53B7F} - System32\Tasks\GoogleUpdateTaskMachineUA1cfffde88909800 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {85266CB0-CA00-4E40-8A51-53EFFBD82BE1} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {8B089397-55C5-4520-8824-AC82710D5063} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {9263F5F5-B5C5-4F28-A7B8-CA042396B91B} - System32\Tasks\HPCeeScheduleForMatLen => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2015-06-16] (Hewlett-Packard)
Task: {991A9359-1980-4BD5-B982-C6F860FFBE54} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-02-09] (Microsoft Corporation)
Task: {9B666AD4-CF64-4EEB-B3A3-963DB4B30B02} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {9F198619-14B8-4A24-9064-1E63C3726C30} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {9F83598D-01D3-4FD0-97DA-74577CCCED8A} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [2016-04-08] ()
Task: {9FBDCBDE-5FDE-46E6-BEDF-155FB29DA184} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-04-13] (Microsoft Corporation)
Task: {A0C90381-6DA5-4C9E-B9A1-4FD1989D56DD} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {A1115B4B-EF37-40EB-8FAE-F4256852E459} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-10-28] (Microsoft Corporation)
Task: {A3FC1C39-38B1-4005-B637-4ADCA6D69BFA} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Active Health Launcher => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2016-03-02] (Hewlett-Packard)
Task: {A608BA0D-732B-4164-AEF2-3B3AF1F186FE} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2712974650-3075997434-2261291459-1001Core => C:\Users\MatLen\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-18] (Dropbox, Inc.)
Task: {AE6260F7-7297-4A53-8B8E-370AD18DF168} - \CCleanerSkipUAC -> No File <==== ATTENTION
Task: {B24D3BFF-D599-45D1-957E-CCCEEABDE807} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {B48289D7-B1CF-4E8D-8DC3-4E047742EAD4} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2016-03-12] (Microsoft Corporation)
Task: {B9904B38-33F9-4D66-A6A8-FE254D496C8C} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2712974650-3075997434-2261291459-1001Core => C:\Users\MatLen\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-10-14] (Facebook Inc.)
Task: {C0715B6E-34B1-4FB7-B9B1-4B9D57227000} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {C1AFF952-D576-456F-B544-FC73A48B8C82} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2712974650-3075997434-2261291459-1001UA => C:\Users\MatLen\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-10-14] (Facebook Inc.)
Task: {CAB04B7C-0774-444D-8E1C-67194EC66629} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2712974650-3075997434-2261291459-1001UA => C:\Users\MatLen\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-18] (Dropbox, Inc.)
Task: {D1827D02-A77F-4872-94C7-3CD3491E5E93} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2016-03-02] (Hewlett-Packard)
Task: {D652B465-125A-4CA0-8817-15F86D869AC0} - System32\Tasks\{9875E999-DEF9-44A3-9A21-F02A4094947B} => pcalua.exe -a F:\ppk.exe -d F:\
Task: {E1ABC96B-AB8E-49B8-9EFC-E9FF7CA4C27D} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {EA15D7B2-57B6-405A-84E3-3A027F7C5E05} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-02-18] (Hewlett-Packard Company)
Task: {EC36F81B-6852-417E-90DB-1BEB76689959} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-03-07] (Hewlett-Packard)
Task: {F2A04DDA-C748-4D94-BAD3-3AAF6D1FD126} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {FC4C1BF3-5735-48F4-A4D0-E00D3A4BC381} - System32\Tasks\GoogleUpdateTaskMachineCore1d043cfbcc2e85d => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2712974650-3075997434-2261291459-1001Core.job => C:\Users\MatLen\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2712974650-3075997434-2261291459-1001UA.job => C:\Users\MatLen\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2712974650-3075997434-2261291459-1001Core.job => C:\Users\MatLen\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-2712974650-3075997434-2261291459-1001UA.job => C:\Users\MatLen\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d043cfbcc2e85d.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1cfffde88909800.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\HPCeeScheduleForMatLen.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2014-02-07 11:24 - 2014-02-07 11:24 - 02108928 _____ () C:\Program Files\Hewlett-Packard\SimplePass\autheng.dll
2014-02-07 11:21 - 2014-02-07 11:21 - 00035328 _____ () C:\Program Files\Hewlett-Packard\SimplePass\ssplogon.dll
2014-02-07 11:21 - 2014-02-07 11:21 - 00021504 _____ () C:\Program Files\Hewlett-Packard\SimplePass\cryptodll.dll
2014-02-07 11:21 - 2014-02-07 11:21 - 00055296 _____ () C:\Program Files\Hewlett-Packard\SimplePass\RandomPass.dll
2014-02-07 11:40 - 2014-02-07 11:40 - 00368528 _____ () C:\Program Files\Hewlett-Packard\SimplePass\mstrpwd.dll
2014-02-07 11:40 - 2014-02-07 11:40 - 00714128 _____ () C:\Program Files\Hewlett-Packard\SimplePass\GraphicalPwd.dll
2014-10-14 01:25 - 2015-10-13 05:34 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2016-04-13 10:29 - 2016-03-29 12:20 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-04-13 10:29 - 2016-03-29 12:20 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2016-04-26 12:09 - 2016-04-26 12:09 - 00959176 _____ () C:\Users\MatLen\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64\ClientTelemetry.dll
2015-12-18 01:54 - 2015-12-07 06:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-04-13 10:29 - 2016-04-02 05:25 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-04-13 10:29 - 2016-04-02 05:26 - 00674816 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\MtcUvc.dll
2016-04-13 10:29 - 2016-04-02 05:03 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-04-13 10:29 - 2016-04-02 04:58 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-04-13 10:29 - 2016-04-02 04:59 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-04-13 10:29 - 2016-04-02 05:02 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2014-02-07 11:28 - 2014-02-07 11:28 - 00065024 _____ () C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe
2012-03-19 12:23 - 2012-03-19 12:23 - 00380416 _____ () C:\Program Files (x86)\Philips\Philips Songbird Resources\Autolauncher\PhilipsDeviceListener.exe
2016-04-19 16:49 - 2016-04-19 16:50 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2016-04-26 12:09 - 2016-04-26 12:09 - 00679624 _____ () C:\Users\MatLen\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\ClientTelemetry.dll
2015-12-13 12:21 - 2016-03-21 23:50 - 00034768 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\_multiprocessing.pyd
2016-04-16 11:13 - 2016-03-21 23:51 - 00019408 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\faulthandler.pyd
2016-04-16 11:13 - 2016-03-21 23:50 - 00116688 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\pywintypes27.dll
2015-12-13 12:21 - 2016-03-21 23:50 - 00093640 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\_ctypes.pyd
2015-12-13 12:21 - 2016-03-21 23:50 - 00018376 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\select.pyd
2015-12-13 12:21 - 2016-04-08 20:20 - 00019760 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\tornado.speedups.pyd
2015-12-13 12:21 - 2016-03-21 23:52 - 00105928 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\win32api.pyd
2016-04-16 11:13 - 2016-03-21 23:50 - 00392144 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\pythoncom27.dll
2015-12-13 12:21 - 2016-04-08 20:20 - 00381752 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\win32com.shell.shell.pyd
2015-12-13 12:21 - 2016-03-21 23:50 - 00692688 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\unicodedata.pyd
2016-04-16 11:13 - 2016-04-08 20:19 - 00020816 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._constant_time.pyd
2015-12-13 12:21 - 2016-03-21 23:51 - 00112592 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\_cffi_backend.pyd
2016-04-16 11:13 - 2016-04-08 20:19 - 01682760 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._openssl.pyd
2016-04-16 11:13 - 2016-04-08 20:19 - 00020808 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._padding.pyd
2015-12-13 12:21 - 2016-04-08 20:20 - 00021840 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\_cffi_unicode_environ_win32_x8bf8e68bx9968e850.pyd
2016-04-16 11:13 - 2016-04-08 20:19 - 00038696 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\fastpath.pyd
2016-04-16 11:13 - 2016-03-21 23:52 - 00020936 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\mmapfile.pyd
2015-12-13 12:21 - 2016-03-21 23:52 - 00024528 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\win32event.pyd
2015-12-13 12:21 - 2016-03-21 23:52 - 00114640 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\win32security.pyd
2015-12-13 12:21 - 2016-03-21 23:52 - 00124880 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\win32file.pyd
2016-02-21 18:19 - 2016-04-08 20:20 - 00021832 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\_cffi_pywin_kernel32_x64d8f881xc8c369be.pyd
2015-12-13 12:21 - 2016-03-21 23:52 - 00024016 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\win32clipboard.pyd
2015-12-13 12:21 - 2016-03-21 23:52 - 00175560 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\win32gui.pyd
2015-12-13 12:21 - 2016-03-21 23:52 - 00030160 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\win32pipe.pyd
2015-12-13 12:21 - 2016-03-21 23:52 - 00043472 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\win32process.pyd
2015-12-13 12:21 - 2016-03-21 23:52 - 00028616 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\win32ts.pyd
2015-12-13 12:21 - 2016-03-21 23:52 - 00048592 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\win32service.pyd
2016-04-16 11:13 - 2016-04-08 20:19 - 00026456 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\dropbox.infinite.win.compiled._driverinstallation.pyd
2015-12-13 12:21 - 2016-03-21 23:52 - 00057808 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\win32evtlog.pyd
2015-12-13 12:21 - 2016-03-21 23:52 - 00024016 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\win32profile.pyd
2016-04-16 11:13 - 2016-04-08 20:19 - 00117056 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\breakpad.client.windows.handler.pyd
2015-12-13 12:21 - 2016-04-08 20:20 - 00023376 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\winscreenshot.compiled._CaptureScreenshot.pyd
2015-12-13 12:21 - 2016-03-21 23:50 - 00134608 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\_elementtree.pyd
2016-04-16 11:13 - 2016-03-21 23:50 - 00134088 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\pyexpat.pyd
2016-04-16 11:13 - 2016-03-21 23:51 - 00240584 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\jpegtran.pyd
2016-04-16 11:13 - 2016-04-08 20:19 - 00024392 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\librsyncffi.compiled._librsyncffi.pyd
2016-04-16 11:13 - 2016-03-21 23:52 - 00036296 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\librsync.dll
2016-04-16 11:13 - 2016-04-08 20:19 - 00031568 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\enterprise_data.compiled._enterprise_data.pyd
2016-04-16 11:13 - 2016-03-12 02:46 - 00293392 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\EnterpriseDataAdapter.dll
2016-04-16 11:13 - 2016-04-08 20:19 - 00052024 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\psutil._psutil_windows.pyd
2016-02-21 18:19 - 2016-04-08 20:20 - 00020800 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\winffi.iphlpapi._winffi_iphlpapi.pyd
2016-02-21 18:19 - 2016-04-08 20:20 - 00021824 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\winffi.kernel32._winffi_kernel32.pyd
2016-02-21 18:19 - 2016-04-08 20:20 - 00019776 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\winffi.winerror._winffi_winerror.pyd
2016-02-21 18:19 - 2016-04-08 20:20 - 00020800 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\winffi.wininet._winffi_wininet.pyd
2016-04-16 11:13 - 2016-04-08 20:19 - 00020280 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\cpuid.compiled._cpuid.pyd
2015-12-13 12:21 - 2016-03-21 23:52 - 00350152 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\winxpgui.pyd
2016-02-21 18:19 - 2016-04-08 20:20 - 00022352 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\winverifysignature.compiled._VerifySignature.pyd
2016-04-16 11:13 - 2016-04-08 20:19 - 00084280 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\dropbox_sqlite_ext.DLL
2016-04-16 11:13 - 2016-04-08 20:20 - 01826096 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\PyQt5.QtCore.pyd
2015-12-13 12:21 - 2016-03-21 23:51 - 00083912 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\sip.pyd
2016-04-16 11:13 - 2016-04-08 20:20 - 03928880 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\PyQt5.QtWidgets.pyd
2016-04-16 11:13 - 2016-04-08 20:20 - 01971504 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\PyQt5.QtGui.pyd
2016-04-16 11:13 - 2016-04-08 20:20 - 00531248 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\PyQt5.QtNetwork.pyd
2016-04-16 11:13 - 2016-04-08 20:20 - 00132912 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKit.pyd
2016-04-16 11:13 - 2016-04-08 20:20 - 00223544 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKitWidgets.pyd
2016-04-16 11:13 - 2016-04-08 20:20 - 00207672 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\PyQt5.QtPrintSupport.pyd
2016-04-16 11:13 - 2016-04-08 20:20 - 00158008 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\PyQt5.QtWebEngineWidgets.pyd
2016-04-16 11:13 - 2016-04-08 20:20 - 00042808 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\PyQt5.QtWebChannel.pyd
2016-04-16 11:13 - 2016-03-21 23:54 - 00017864 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\libEGL.dll
2016-04-16 11:13 - 2016-03-21 23:54 - 01631184 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\libGLESv2.dll
2016-04-16 11:13 - 2016-04-08 20:20 - 00025928 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\windisplaytoast.compiled._DisplayToast.pyd
2015-12-13 12:21 - 2016-04-08 20:20 - 00024904 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\_cffi_wpad_proxy_win_x752e3d61xdcfdcc84.pyd
2016-04-16 11:13 - 2016-04-08 20:20 - 00546096 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\PyQt5.QtQuick.pyd
2016-04-16 11:13 - 2016-04-08 20:20 - 00357680 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\PyQt5.QtQml.pyd
2015-03-04 23:45 - 2016-03-21 23:56 - 00697304 _____ () C:\Users\MatLen\AppData\Roaming\Dropbox\bin\QtQuick\Controls\qtquickcontrolsplugin.dll
2016-05-09 20:05 - 2016-05-09 20:05 - 40500224 _____ () C:\Program Files (x86)\AVG\UiDll\2171\libcef.dll
2015-07-11 00:37 - 2015-07-11 00:37 - 01243936 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2016-04-19 16:49 - 2016-04-19 16:50 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-04-19 16:49 - 2016-04-19 16:50 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2712974650-3075997434-2261291459-1001\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\theme1\img2.jpg
DNS Servers: 10.0.0.138
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2712974650-3075997434-2261291459-1001\...\StartupApproved\Run: => "Skype"
HKU\S-1-5-21-2712974650-3075997434-2261291459-1001\...\StartupApproved\Run: => "Viber"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [UDP Query User{5A5C84AC-748E-4B0C-8E9E-5D35E7D22092}E:\hry\grand theft auto vv\gta5.exe] => (Block) E:\hry\grand theft auto vv\gta5.exe
FirewallRules: [TCP Query User{AC050432-BA4B-449D-85FD-199BCBE66EFD}E:\hry\grand theft auto vv\gta5.exe] => (Block) E:\hry\grand theft auto vv\gta5.exe
FirewallRules: [{30ACCBE7-B985-4049-9D91-E279008C4786}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
FirewallRules: [{2C91ED57-9D1F-41A0-8674-4ABAB8B95E68}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
FirewallRules: [{78889D5D-CF78-4470-9351-5BA7022DA89F}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
FirewallRules: [{57E28164-384C-444E-97DE-4815417E5D2D}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
FirewallRules: [{FD0F48CE-3704-49FB-A9BC-8E73208CDC9C}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{3DC038FA-96B0-4D6C-A08B-6E0A0FCF1C46}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe
FirewallRules: [{8B73849E-9D6A-4095-90D7-C65CD453B2A4}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
FirewallRules: [{E1A98501-ADE3-4DA7-A473-0DE1189B8687}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe
FirewallRules: [{BE8405A6-F972-4ED3-A871-1C272A38D4B0}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe
FirewallRules: [{2ADB94F4-989D-4B08-A870-A0C4DC939766}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{EF43EE8A-A6F5-481B-8AD5-45D478D9856E}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{6DCC9E61-DF2B-4ADE-B459-10FF80A17762}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{BE290DEE-39A8-47DF-8604-47F8A8A9ABAD}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [TCP Query User{7D653BD3-2B1D-4660-B47E-DDC61CD8A316}C:\users\matlen\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\matlen\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [UDP Query User{4EF8FFB1-214B-4BD7-9393-0F699A76FA21}C:\users\matlen\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\matlen\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [{B984960A-AF1F-476F-877C-24A15C00F22B}] => (Allow) C:\Users\MatLen\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{A4BEF42A-EC37-4D29-82D3-79EF7BAFE3D2}] => (Allow) C:\Users\MatLen\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{53DD9F41-40C7-4450-89A0-53D10373067A}] => (Allow) C:\Users\MatLen\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe
FirewallRules: [{353684AF-B47C-4BBB-926D-A8120D0FB3FF}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{5C320B49-FA6A-44FD-9646-34A0528CBAC9}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{640D74B2-5960-4402-B92C-3EFB0878FCCD}] => (Allow) E:\hry\FIFA 15\fifasetup\fifaconfig.exe
FirewallRules: [{15FF38AF-CB9B-4BAD-B098-0EB2E25C5062}] => (Allow) E:\hry\FIFA 15\fifasetup\fifaconfig.exe
FirewallRules: [TCP Query User{950015C4-48EB-41BB-AC59-1D5718D11F61}E:\hry\fifa 15\fifa15.exe] => (Block) E:\hry\fifa 15\fifa15.exe
FirewallRules: [UDP Query User{74F89A9C-BA75-4AEB-A19B-C77FBA07FF7C}E:\hry\fifa 15\fifa15.exe] => (Block) E:\hry\fifa 15\fifa15.exe
FirewallRules: [TCP Query User{F0AE44EF-B455-426D-B7B8-20A083065987}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{A3F54045-AAD2-40F6-8373-20A36AD3E415}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{A6F0FF6C-9A9F-4450-BC9C-A62446FD75BF}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
FirewallRules: [TCP Query User{DBB72782-B86E-41E8-8ADD-858217776929}C:\users\matlen\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\matlen\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{E50BF1D2-2D5D-4704-9767-77BF8727BE0C}C:\users\matlen\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\matlen\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [{BE483253-D854-4F48-BB40-DDC518C4B81A}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
FirewallRules: [{AD44B3DE-B238-4C0E-8AE0-D057D3D87440}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
FirewallRules: [{061100A4-4AD7-4933-9A40-952582247232}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxm08.exe
FirewallRules: [{E83630A7-0DE3-4407-882D-78EBADC0F0F8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposfx08.exe
FirewallRules: [{396C6243-5B30-4CAA-AD1F-8F5F414D1A60}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe
FirewallRules: [{E39A3955-1AE2-4CE7-B966-DE6C662BE9E8}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe
FirewallRules: [{143D4390-D3DA-4CBF-8DDF-A69B27B1C2F5}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcopy2.exe
FirewallRules: [{54ADDBB1-6A06-411D-A763-F7660C390345}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe
FirewallRules: [{F4B10167-1BCB-4ECF-BE11-CCB0305D9536}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpzwiz01.exe
FirewallRules: [{9BF9F887-E7C0-4B8E-AB00-7C29EA7A6D04}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe
FirewallRules: [{CD0FB8CD-4B53-425F-8ADF-D042087F9CFC}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqnrs08.exe
FirewallRules: [{5717E319-F813-490A-93E3-2CCC60E6BE71}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe
FirewallRules: [{E2320520-66CD-43D0-8CB3-99E9DD7A0CA6}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxs08.exe
FirewallRules: [{E7EFE569-459F-4B44-80C0-0EFD96AB52FC}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqfxt08.exe
FirewallRules: [{D65AB1A5-22F3-4C61-A5F7-976A0B2CA37B}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe
FirewallRules: [{F2A0FE05-BBD9-4916-94C8-6CE8B24085C5}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
FirewallRules: [{874DDF6A-EABC-4D0D-A9DA-FF7C54EC5263}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe
FirewallRules: [{25771A2B-FB7B-4EAA-9261-CE20F7CA1FEC}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe
FirewallRules: [{FAF9910F-93AE-4533-B4FF-8487D7A484B1}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe
FirewallRules: [TCP Query User{23095BED-312B-4D4E-9117-754A35E743A7}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{2AFE3251-1D9C-4178-8E2F-59D17AF38987}C:\users\matlen\appdata\roaming\utorrent\utorrent.exe] => (Block) C:\users\matlen\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [UDP Query User{334C9456-56B6-4F5D-AC28-D9DFAD71734E}C:\users\matlen\appdata\roaming\utorrent\utorrent.exe] => (Block) C:\users\matlen\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [TCP Query User{4C1CBBA1-E879-44D4-B7DD-3C94F42A3019}E:\hry\fifa 15\fifa15.exe] => (Allow) E:\hry\fifa 15\fifa15.exe
FirewallRules: [UDP Query User{1DE63E32-2864-4ED6-B7F4-6695BA197544}E:\hry\fifa 15\fifa15.exe] => (Allow) E:\hry\fifa 15\fifa15.exe
FirewallRules: [{0BBB2BAB-9117-4F7D-A2A1-3532966A9D76}] => (Allow) C:\Program Files\GRAPHISOFT\ArchiCAD 16\ArchiCAD.exe
FirewallRules: [{28A6E1CD-E86E-4E9D-9B48-EABC0F6AC411}] => (Allow) C:\Program Files\GRAPHISOFT\ArchiCAD 16\ArchiCAD.exe
FirewallRules: [{EC24F1F0-1C78-4E50-8067-CDA30AA57D48}] => (Allow) C:\Program Files\GRAPHISOFT\ArchiCAD 16\GSQuickTimeServer\GSQTServer.exe
FirewallRules: [{946C6F40-850D-4115-9A5E-F7E6F67CE60F}] => (Allow) C:\Program Files\GRAPHISOFT\ArchiCAD 16\GSQuickTimeServer\GSQTServer.exe
FirewallRules: [{CFC42932-9D75-4917-A3E3-3887467CC580}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
FirewallRules: [{922C6041-C154-4AE0-944D-DB82A20F5CB7}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{9CB714A6-04D0-4B98-AD1B-BD525175E25C}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{9AFCB8AC-6934-487C-B4FF-98164174631D}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{70BAF8B5-5B7E-4D52-8977-066AF0987578}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{4FFD6891-583C-49E2-BB53-96123D94A924}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
FirewallRules: [{86B2BDD3-0D7B-4B30-BCDB-BAD5C15759E7}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{3498E819-6AA1-4818-8EC7-5EBA6C7253E1}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{C1DC7423-8DFC-4457-868D-227F2FE32AB7}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{C39FB367-BAE4-4266-8161-5AFDC658D554}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe

==================== Restore Points =========================

20-04-2016 20:06:19 Naplánovaný kontrolní bod
27-04-2016 17:47:42 Garmin Express
05-05-2016 17:12:04 Naplánovaný kontrolní bod
09-05-2016 20:20:51 Installed AVG 2016

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (05/10/2016 05:13:34 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: FRSTLauncher (3).exe, verze: 30.9.13.1, časové razítko: 0x2a425e19
Název chybujícího modulu: KERNELBASE.dll, verze: 10.0.10586.162, časové razítko: 0x56cd55ab
Kód výjimky: 0x0eedfade
Posun chyby: 0x000bdad8
ID chybujícího procesu: 0x25f8
Čas spuštění chybující aplikace: 0xFRSTLauncher (3).exe0
Cesta k chybující aplikaci: FRSTLauncher (3).exe1
Cesta k chybujícímu modulu: FRSTLauncher (3).exe2
ID zprávy: FRSTLauncher (3).exe3
Úplný název chybujícího balíčku: FRSTLauncher (3).exe4
ID aplikace související s chybujícím balíčkem: FRSTLauncher (3).exe5

Error: (05/10/2016 05:13:13 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: FRSTLauncher (2).exe, verze: 30.9.13.1, časové razítko: 0x2a425e19
Název chybujícího modulu: KERNELBASE.dll, verze: 10.0.10586.162, časové razítko: 0x56cd55ab
Kód výjimky: 0x0eedfade
Posun chyby: 0x000bdad8
ID chybujícího procesu: 0x239c
Čas spuštění chybující aplikace: 0xFRSTLauncher (2).exe0
Cesta k chybující aplikaci: FRSTLauncher (2).exe1
Cesta k chybujícímu modulu: FRSTLauncher (2).exe2
ID zprávy: FRSTLauncher (2).exe3
Úplný název chybujícího balíčku: FRSTLauncher (2).exe4
ID aplikace související s chybujícím balíčkem: FRSTLauncher (2).exe5

Error: (05/10/2016 05:13:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: FRSTLauncher (1).exe, verze: 30.9.13.1, časové razítko: 0x2a425e19
Název chybujícího modulu: KERNELBASE.dll, verze: 10.0.10586.162, časové razítko: 0x56cd55ab
Kód výjimky: 0x0eedfade
Posun chyby: 0x000bdad8
ID chybujícího procesu: 0x1ea4
Čas spuštění chybující aplikace: 0xFRSTLauncher (1).exe0
Cesta k chybující aplikaci: FRSTLauncher (1).exe1
Cesta k chybujícímu modulu: FRSTLauncher (1).exe2
ID zprávy: FRSTLauncher (1).exe3
Úplný název chybujícího balíčku: FRSTLauncher (1).exe4
ID aplikace související s chybujícím balíčkem: FRSTLauncher (1).exe5

Error: (05/09/2016 11:24:07 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe, verze: 10.0.10586.0, časové razítko: 0x5632d7ba
Název chybujícího modulu: ESENT.dll, verze: 10.0.10586.212, časové razítko: 0x56fa1686
Kód výjimky: 0xc0000602
Posun chyby: 0x000000000022885f
ID chybujícího procesu: 0x970
Čas spuštění chybující aplikace: 0xsvchost.exe0
Cesta k chybující aplikaci: svchost.exe1
Cesta k chybujícímu modulu: svchost.exe2
ID zprávy: svchost.exe3
Úplný název chybujícího balíčku: svchost.exe4
ID aplikace související s chybujícím balíčkem: svchost.exe5

Error: (05/09/2016 11:24:07 PM) (Source: ESENT) (EventID: 908) (User: )
Description: svchost (2416) Proces se ukončuje kvůli neopravitelnému selhání: PV: 10.0.10586.0 SV: 10.0.10586.0 GLE: 0 ERR: -1601(dir.cxx:753): dllentry.cxx(103) (ESENT[10.0.10586.0] RETAIL RTM MBCS).

Error: (05/09/2016 08:20:52 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Služba Šifrování selhala při volání OnIdentity() v objektu System Writer.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Protokol Microsoft LLDP (Link-Layer Discovery Protocol).

System Error:
Přístup byl odepřen.
.

Error: (05/08/2016 10:11:11 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe, verze: 10.0.10586.0, časové razítko: 0x5632d7ba
Název chybujícího modulu: ESENT.dll, verze: 10.0.10586.212, časové razítko: 0x56fa1686
Kód výjimky: 0xc0000602
Posun chyby: 0x000000000022885f
ID chybujícího procesu: 0x824
Čas spuštění chybující aplikace: 0xsvchost.exe0
Cesta k chybující aplikaci: svchost.exe1
Cesta k chybujícímu modulu: svchost.exe2
ID zprávy: svchost.exe3
Úplný název chybujícího balíčku: svchost.exe4
ID aplikace související s chybujícím balíčkem: svchost.exe5

Error: (05/08/2016 10:11:11 PM) (Source: ESENT) (EventID: 908) (User: )
Description: svchost (2084) Proces se ukončuje kvůli neopravitelnému selhání: PV: 10.0.10586.0 SV: 10.0.10586.0 GLE: 0 ERR: -1601(dir.cxx:753): dllentry.cxx(103) (ESENT[10.0.10586.0] RETAIL RTM MBCS).

Error: (05/08/2016 07:24:41 PM) (Source: Microsoft Office 15) (EventID: 2011) (User: )
Description: Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {482395BA-1B50-4D87-8F9B-0F0893625933}

Error: (05/08/2016 07:24:29 PM) (Source: Microsoft Office 15) (EventID: 2011) (User: )
Description: Office Subscription licensing exception: Error Code: 0x803D0010; CorrelationId: {482395BA-1B50-4D87-8F9B-0F0893625933}


System errors:
=============
Error: (05/10/2016 04:30:20 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: {784E29F4-5EBE-4279-9948-1E8FE941646D}

Error: (05/09/2016 11:24:07 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Služba State Repository byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 120000 milisekund: Restartovat službu.

Error: (05/09/2016 11:24:05 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Přístup k uživatelským datům_1178b8 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.

Error: (05/09/2016 11:24:05 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Úložiště uživatelských dat_1178b8 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.

Error: (05/09/2016 11:24:05 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Data kontaktů_1178b8 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.

Error: (05/09/2016 11:24:05 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Hostitel synchronizace_1178b8 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.

Error: (05/09/2016 11:24:05 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: specifické pro aplikaciMístníAktivace{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (pomocí LRPC)Není k dispoziciNení k dispozici

Error: (05/09/2016 08:17:32 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: {784E29F4-5EBE-4279-9948-1E8FE941646D}

Error: (05/09/2016 08:13:50 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Přístup k uživatelským datům_ada52 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.

Error: (05/09/2016 08:13:50 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Úložiště uživatelských dat_ada52 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.


CodeIntegrity:
===================================
  Date: 2016-05-10 17:14:07.890
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-05-10 17:14:07.879
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-05-10 17:13:56.984
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-05-10 17:13:56.975
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-05-10 17:13:35.754
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-05-10 17:13:35.737
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-05-10 17:13:34.938
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-05-10 17:13:34.926
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-05-10 17:13:13.979
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-05-10 17:13:13.961
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info =========================== 

Processor: Intel(R) Core(TM) i7-4790 CPU @ 3.60GHz
Percentage of memory in use: 18%
Total physical RAM: 16337.06 MB
Available physical RAM: 13251.26 MB
Total Virtual: 18769.06 MB
Available Virtual: 15544.14 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:225.91 GB) (Free:140.61 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (Recovery Image) (Fixed) (Total:10.65 GB) (Free:1.35 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive e: (DATADRIVE1) (Fixed) (Total:2794.39 GB) (Free:2232.07 GB) NTFS
Drive k: (20130715_0956) (CDROM) (Total:1.93 GB) (Free:0 GB) CDFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 238.5 GB) (Disk ID: 199AF529)

Partition: GPT.

========================================================
Disk: 1 (Size: 2794.5 GB) (Disk ID: D8F225FE)

Partition: GPT.

==================== End of Addition.txt ============================