﻿Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-07-2016
Ran by Pavel (2016-07-30 21:24:45)
Running from C:\Users\Pavel\Desktop
Windows 10 Pro Version 1511 (X64) (2015-12-11 14:23:11)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-380585536-327012264-1297929140-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-380585536-327012264-1297929140-503 - Limited - Disabled)
Guest (S-1-5-21-380585536-327012264-1297929140-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-380585536-327012264-1297929140-1005 - Limited - Enabled)
Pavel (S-1-5-21-380585536-327012264-1297929140-1000 - Administrator - Enabled) => C:\Users\Pavel

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 15.14 (x64 edition) (HKLM\...\{23170F69-40C1-2702-1514-000001000000}) (Version: 15.14.00.0 - Igor Pavlov)
8GadgetPack (HKLM-x32\...\{D0BD6EC7-ADBC-4127-815A-77E2336873EA}) (Version: 17.0.0 - Helmut Buhler)
ABBYY FineReader 10 Professional Edition (HKLM-x32\...\{F1000000-0001-0000-0000-074957833700}) (Version: 10.501.128.70010 - ABBYY)
Acronis Disk Director Suite (HKLM-x32\...\{2300EE96-0A41-4FAB-BD03-989EC44577A0}) (Version: 10.0.2161 - Acronis)
Acronis Disk Director Home (HKLM-x32\...\{9CCC78EF-027E-40E0-9B61-39932C65E3FE}) (Version: 11.0.216 - Acronis)
Adobe Acrobat 8 Professional - Czech, Greek, Hungarian, Polish, Slovak (HKLM-x32\...\Adobe Acrobat 8 Professional - Czech, Greek, Hungarian, Polish, Slovak) (Version: 8.0.0 - Adobe Systems)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 21.0.0.198 - Adobe Systems Incorporated)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 2.6.0.393 - Adobe Systems Incorporated)
Adobe Flash Player 22 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 22.0.0.209 - Adobe Systems Incorporated)
Adobe Photoshop Lightroom 4.4 64-bit (HKLM\...\{11A955CD-4398-405A-886D-E464C3618FBF}) (Version: 4.4.1 - Adobe)
AMD Catalyst Install Manager (HKLM\...\{3FAEEEBE-48F4-84C1-2B49-96AE73E67E3E}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
Anti-Twin (Installation 19.6.2015) (HKLM-x32\...\Anti-Twin 2015-06-19 17.03.39) (Version:  - Joerg Rosenthal, Germany)
AOMEI Backupper Standard (HKLM-x32\...\{A83692F5-3E9B-4E95-9E7E-B5DF5536C09F}_is1) (Version:  - AOMEI Technology Co., Ltd.)
Artopedia 3 (instalace na disk) (HKLM-x32\...\Artopedia 3 (instalace na disk)) (Version:  - )
Ashampoo Burning Studio 2010 (HKLM-x32\...\Ashampoo Burning Studio 2010_is1) (Version: 9.1.0 - ashampoo GmbH & Co. KG)
Aspell Czech Dictionary-0.50-2 (HKLM-x32\...\Aspell Czech Dictionary_is1) (Version:  - GNU)
Auto Gordian Knot 2.55 (HKLM-x32\...\AutoGK) (Version: 2.55 - len0x)
Avidemux 2.6 - 64 bits (HKLM-x32\...\Avidemux 2.6 - 64 bits (64-bit)) (Version: 2.6.911.151222 - )
AviSynth 2.5 (HKLM-x32\...\AviSynth) (Version:  - )
BibleWorks 8 (HKLM-x32\...\{B038A58E-EAF0-44CB-ADCA-3895ECD0812D}) (Version: 1.00.000 - BibleWorks)
Bit Che (HKLM-x32\...\{D9DA5C41-964F-455F-B5E7-3664519440E8}_is1) (Version: 3.5 build 26 - Convivea Inc.)
Blobby Volley 2 Version 1.0 (HKLM-x32\...\Blobby Volley 2 Version 1.0_is1) (Version:  - )
Box Sync (x32 Version: 4.0.7100.0 - Box Inc.) Hidden
BS.Player FREE (HKLM-x32\...\BSPlayerf) (Version: 2.69.1079 - AB Team, d.o.o.)
C:\Program Files\Adobe\Adobe Photoshop Lightroom 4.4\LRcestina_uninstall.exe (HKLM-x32\...\CZ Lokalizace pro Lightroom 4.x_is1) (Version: 1.0 - )
Canon Utilities Digital Photo Professional 3.9 (HKLM-x32\...\DPP) (Version: 3.9.4.0 - Canon Inc.)
Canon Utilities EOS Utility (HKLM-x32\...\EOS Utility) (Version: 2.9.0.0 - Canon Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.20 - Piriform)
Clavia USB Driver v3.02 (HKLM-x32\...\Clavia USB Driver v3.02) (Version:  - )
DirTree 1.02 (HKLM-x32\...\DirTree_is1) (Version:  - Petr Ambrož)
DisplayFusion 6.1.2 (HKLM-x32\...\B076073A-5527-4f4f-B46B-B10692277DA2_is1) (Version: 6.1.2.0 - Binary Fortress Software)
DriveTheLife (HKLM-x32\...\{29FE44D7-BC89-4188-8B0E-F6BA073C15A5}_is1) (Version: 6.2.0.2 - 深圳市驱动人生软件技术有限公司)
Dropbox (HKLM-x32\...\Dropbox) (Version: 6.4.14 - Dropbox, Inc.)
Dropbox Update Helper (x32 Version: 1.3.27.35 - Dropbox, Inc.) Hidden
Evernote v. 6.1.2 (HKLM-x32\...\{A46ABD1E-2837-11E6-9E7C-005056951CAD}) (Version: 6.1.2.2292 - Evernote Corp.)
FairStars CD Ripper 1.51 (HKLM-x32\...\FairStars CD Ripper_is1) (Version:  - FairStars Soft)
FastStone Image Viewer 5.3 (HKLM-x32\...\FastStone Image Viewer) (Version: 5.3 - FastStone Soft)
Firebird 2.5.5.26952 (Win32) (HKLM-x32\...\FBDBServer_2_5_is1) (Version: 2.5.5.26952 - Firebird Project)
FocusWriter (HKLM-x32\...\FocusWriter) (Version: 1.5.3 - Graeme Gott)
FreeFileSync 8.3 (HKLM-x32\...\FreeFileSync) (Version: 8.3 - www.FreeFileSync.org)
GNU Aspell 0.50-3 (HKLM-x32\...\GNU Aspell_is1) (Version:  - GNU)
Google Drive (HKLM-x32\...\{709316AD-161C-4D5C-9AE7-0B3A822DA271}) (Version: 1.30.2170.0459 - Google, Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 51.0.2704.103 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
HandBrake 0.10.2 (HKLM-x32\...\HandBrake) (Version: 0.10.2 - )
Hesla JB 2013 (HKLM-x32\...\Hesla JB_is1) (Version:  - )
Hesla Jednoty bratrské 2.1 (HKLM-x32\...\Hesla Jednoty bratrské_is1) (Version:  - )
IcoFX 1.6.4 (HKLM-x32\...\IcoFX_is1) (Version:  - )
Java 8 Update 91 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.14 - Oracle Corporation)
jetToolBar (HKLM-x32\...\{5F6AA55D-5E83-438B-A208-AC63FF013966}) (Version: 3.8 - )
jetToolBar 3.8.x Czech Language Pack (HKLM-x32\...\jetToolBar 3.8.x Czech Language Pack) (Version:  - )
JPG To PDF 2.2.1 (HKLM-x32\...\JPG To PDF_is1) (Version:  - JPG To PDF Developer Team)
Junction Link Magic 2.0 (HKLM\...\Junction Link Magic_is1) (Version:  - )
KeePass Password Safe 2.34 (HKLM-x32\...\KeePassPasswordSafe2_is1) (Version: 2.34 - Dominik Reichl)
LADSPA_plugins-win-0.4.15 (HKLM-x32\...\LADSPA_plugins-win_is1) (Version:  - Audacity Team)
Lenovo Phone Manager (HKLM-x32\...\{5E794B10-7A71-4B45-BFD7-41FFF3C20E49}) (Version: 1.4.1.10098 - Lenovo)
LenovoUsbDriver 1.0.13 (HKLM-x32\...\LenovoUsbDriver) (Version: 1.0.13 - Lenovo)
Lingea Lexicon 2002 (HKLM-x32\...\Lexicon 4.0) (Version:  - )
MailStore Home 9.7.1.11637 (HKLM-x32\...\MailStore Home_universal1) (Version: 9.7.1.11637 - MailStore Software GmbH)
Malwarebytes Anti-Malware verze 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
MEGAsync (HKLM-x32\...\MEGAsync) (Version:  - Mega Limited)
Metric Collection SDK 35 (x32 Version: 1.2.0010.00 - Lenovo Group Limited) Hidden
Microsoft Office Professional Plus 2013 (HKLM-x32\...\Office15.PROPLUS) (Version: 15.0.4420.1017 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{4FFA2088-8317-3B14-93CD-4C699DB37843}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Works 6-9 Converter (HKLM-x32\...\{95140000-0137-0405-0000-0000000FF1CE}) (Version: 14.0.6120.5002 - Microsoft Corporation)
Mozilla Firefox 47.0.1 (x64 cs) (HKLM\...\Mozilla Firefox 47.0.1 (x64 cs)) (Version: 47.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 47.0.1 - Mozilla)
MSI to redistribute MS VS2005 CRT libraries (HKLM-x32\...\{A8D93648-9F7F-407D-915C-62044644C3DA}) (Version: 8.0.50727.42 - The Firebird Project)
Nástroje kontroly pravopisu pro Microsoft Office 2013 – čeština (x32 Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Nástroje korektúry balíka Microsoft Office 2013 - slovenčina (x32 Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Network ScanGear Ver.2.0 (HKLM-x32\...\InstallShield_{EC4A65D2-AF2D-44B7-B90A-17CED4A1E661}) (Version: 2.00.0000 - Canon Inc.)
Network ScanGear Ver.2.0 (x32 Version: 2.00.0000 - Canon Inc.) Hidden
NexusFont 2.5 (ver 2.5.8.1582) (HKLM-x32\...\{EFEDD205-43FE-4208-B682-0937E803E19E}_is1) (Version:  - xiles)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.9.2 - Notepad++ Team)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version:  - )
PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.316.1 - Tracker Software Products Ltd)
Potplayer-64 Bits (HKLM\...\PotPlayer64) (Version:  - Kakao Corp.)
PRE11 STI 64Installer (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
PSPad editor (HKLM-x32\...\PSPad editor_is1) (Version: 4.5.7.2450 - Jan Fiala)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7530 - Realtek Semiconductor Corp.)
Recuva (HKLM\...\Recuva) (Version: 1.52 - Piriform)
Sada Compatibility Pack pro systém Office 2007 (HKLM-x32\...\{90120000-0020-0405-0000-0000000FF1CE}) (Version: 12.0.6514.5001 - Microsoft Corporation)
SHAREit (HKLM-x32\...\SHAREit_is1) (Version: 2.5.1.1 - Lenovo Group Limited)
Simplenote (HKLM-x32\...\Simplenote) (Version:  - Automattic, Inc.)
Skype™ 7.23 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.23.105 - Skype Technologies S.A.)
SSDlife Pro (HKLM-x32\...\{274A0362-DB46-4C5F-9D03-B1EEE404ED2B}) (Version: 2.5.76 - BinarySense Inc.)
Tajpi 2.97 (HKLM-x32\...\Tajpi_is1) (Version:  - )
Toolwiz Time Freeze 2016 (HKLM-x32\...\{3A74D01E-3AEF-4DF4-8404-0056150C97A3}) (Version: 3.2.0.2000 - Toolwiz)
Total Commander (Remove or Repair) (HKLM-x32\...\Totalcmd) (Version: 8.51 RC1 - Ghisler Software GmbH)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.51a - Ghisler Software GmbH)
UFR II Printer Driver Uninstaller (HKLM\...\Canon UFR II Printer Driver) (Version: 5, 4, 0, 0 - Canon Inc.)
Unlocker 1.9.2 (HKLM\...\Unlocker) (Version: 1.9.2 - Cedrick Collomb)
Wunderlist - Wunderlist (HKLM-x32\...\Wunderlist Wunderlist) (Version: 3.4.1 - Wunderlist)
XviD MPEG4 Video Codec (remove only) (HKLM-x32\...\XviD MPEG4 Video Codec) (Version:  - )
Zoner Photo Studio 16 (HKLM\...\ZonerPhotoStudio16_CZ_is1) (Version: 16.0.1.7 - ZONER software)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-380585536-327012264-1297929140-1000_Classes\CLSID\{0B7AD8D3-094A-44DE-A348-83C6C3FA347C}\InprocServer32 -> C:\Users\Pavel\AppData\Local\Microsoft\Windows Sidebar\Gadgets\Clipboarder.gadget\Release\Clipboarder64.dll (Helmut Buhler)
CustomCLSID: HKU\S-1-5-21-380585536-327012264-1297929140-1000_Classes\CLSID\{0E7BE950-4ACC-47CB-834B-41A8B96BBFF9}\InprocServer32 -> C:\Users\Pavel\AppData\Local\Microsoft\Windows Sidebar\Gadgets\Sidebar7.gadget\Release\Sidebar7.64.dll (Helmut Buhler)
CustomCLSID: HKU\S-1-5-21-380585536-327012264-1297929140-1000_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Pavel\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\FileCoAuth.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-380585536-327012264-1297929140-1000_Classes\CLSID\{A4FEF2CE-E494-419e-ABCC-B2E993FB6BC0}\InprocServer32 -> C:\Users\Pavel\AppData\Local\Microsoft\Windows Sidebar\Gadgets\GlassyNetworkMonitor.gadget\Release\ProcessMonitor64.dll (TODO: <Firmenname>)
CustomCLSID: HKU\S-1-5-21-380585536-327012264-1297929140-1000_Classes\CLSID\{BCAFD618-3FAE-4EFE-BF4E-4C43A7E1320B}\InprocServer32 -> C:\Program Files\Zoner\Photo Studio 16\Program64\SHELLEXT.DLL (ZONER software)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {037E6402-50A6-4DCE-8BBB-AF298B183A05} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
Task: {0EAE6307-BCA5-4CEB-9142-89C034B4161C} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-08-20] (Dropbox, Inc.)
Task: {12C1416E-50BC-4CA2-A45B-53620D1CE7ED} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {13ACB83A-A323-413E-968F-1C3940461B8F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
Task: {185AAFC1-3C11-4B59-BC18-ADD301ED4362} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {19FCA2C6-5998-48C2-8950-8B5B26068FB0} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {1DA9958A-CDD9-4390-9BC7-763E91A8786E} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {20F063C0-0BF1-4847-A49D-FCBA5541FC34} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-07-13] (Piriform Ltd)
Task: {26336086-2500-4C0F-B140-7112025FA327} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {2A80F537-9E1E-4B90-A4A5-3B8559301F09} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {352D7F5E-D1C3-4B9E-835D-4A1E47B27776} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {36E157BB-7063-4416-B5B1-E9241C954FB5} - System32\Tasks\Záloha nastavení => C:\Utility\FreeFileSync\FreeFileSync.exe
Task: {3E2DCD37-FC24-49CC-8436-182DB0A84503} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {43542039-ACA6-4C98-AB82-154B38F8AAC4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {4ACC5285-5DA2-4947-A29C-D11D72DD1773} - System32\Tasks\GoogleUpdateTaskMachineCore1d0aa9d56318e20 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {4E79C20E-87D9-486D-A92C-47BBCBC1D7F0} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {4F315A57-E62D-4495-8E52-60650AB6E613} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: {53BBCDDE-FF70-481B-A43A-DA795856752A} - System32\Tasks\SafeZone scheduled Autoupdate 1462315076 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe
Task: {5B592E1E-1339-48D5-999A-C3EC38C2F1B8} - System32\Tasks\{0F326C14-CB1A-4AE0-9F41-14F6BC6B56B6} => pcalua.exe -a "C:\Program Files (x86)\NexusFont\FontInstaller.exe" -d C:\Windows\system32 -c uninstall NexusFontMappedFile_2208693 "-" "Odinstalování písem..." "Zrušit" "-8,1,1296,1001"
Task: {663AEB05-3734-4034-9D2F-1750DAE1BFC7} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {66B9F0F9-E55C-440B-B74A-FAC223542F8A} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {697F4AF6-51B9-40A4-AB21-1FA98973D4D5} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-08-20] (Dropbox, Inc.)
Task: {6A750EEB-DE7F-44C6-883C-B5741708C8B4} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {7A85878D-4B38-4D76-AD85-6232E3A9577F} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {7AFC44F4-CDAA-42CA-96E0-D1A7A95C2D8B} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {7BA03871-2039-4B88-AF95-36DCECDA8017} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-07-29] (Microsoft Corporation)
Task: {7BE84CEB-D11F-48B8-ACE2-C418F267E067} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {7C8A535C-26E2-4366-B3F7-2FAA1FCC6F6A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-07-26] (Adobe Systems Incorporated)
Task: {7DFBFD88-164B-4C4C-A137-487A2F2FB582} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {7FB719EF-0079-4315-90B8-2E41A58124FE} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {80D284B5-FD79-4C37-B69B-9B3DBCED517F} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {834DCDB9-0072-479F-94DB-2E0F264EE5B8} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {83E9EB8F-338B-4A3E-8979-11EAC69E488A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {902289FD-EE97-46A5-A041-8E98B312BEF3} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {99C0F495-D917-4450-97EA-B7EC9A584851} - System32\Tasks\AdobeAAMUpdater-1.0-Dual-stůl-Pavel => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2015-08-05] (Adobe Systems Incorporated)
Task: {9F240A8B-D909-49FD-8CAB-518D66645DA3} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe [2015-07-06] (Lenovo)
Task: {A5C35452-0028-441F-A3A5-3FD80DC342C5} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {A8E6C9B4-821C-4D39-AA0D-44AE21E6CE3E} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {AC3F5452-6B7B-4DDD-B0DA-6331BD0CB73D} - System32\Tasks\Driver Booster SkipUAC (Pavel) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe
Task: {ADD5F6E9-14BA-4F64-AA18-6CB31F50C7EB} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {AFAB0EC5-AC70-488E-845B-3F7EE4E51D1A} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {B036C29F-D762-463D-AA1B-5F651E758FBB} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe
Task: {B4EC811F-8584-47DD-A562-44308B39ABE6} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {BF0AA6F1-FA7E-4A3E-86E7-22512101C0B3} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {BF2F7D33-DBCD-4187-86CB-6EFB5AA6E16E} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
Task: {C30B2C9C-5BB0-4822-953E-01F6DD23D209} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {D3CFC3B6-DA13-4D2C-8DDD-2303DB6EE98B} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {D4B8C704-5004-44F3-91D2-A387168E0010} - System32\Tasks\Logon Screen SkipUAC => C:\Program Files\Logon Screen\Logon Screen.exe
Task: {D51328D6-4BCE-4925-82F3-9FF7DC115C68} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe
Task: {DCF8B838-C2E5-4220-BAA9-FE395A17E669} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {ECE4D0FD-4783-4C56-903F-D4AB6B843740} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {F0DF4510-969A-4D5F-9E44-2445FFD40A52} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {F4C99F5F-A0FF-409D-85D8-9E98BEF16EE3} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d0aa9d56318e20.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

Shortcut: C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NET_Acer_VYP.lnk -> C:\Bat\Sit\NET_Acer_VYP.bat ()
Shortcut: C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NET_Acer_ZAP.lnk -> C:\Bat\Sit\NET_Acer_ZAP.bat ()
Shortcut: C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NET_ALL_VYP.lnk -> C:\Bat\Sit\NET_ALL_VYP.bat ()
Shortcut: C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NET_Sbor1_VYP.lnk -> C:\Bat\Sit\NET_Sbor1_VYP.bat ()
Shortcut: C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NET_Sbor1_ZAP.lnk -> C:\Bat\Sit\NET_Sbor1_ZAP.bat ()

ShortcutWithArgument: C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Spouštěč aplikací Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --show-app-list
ShortcutWithArgument: C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_pjkljhegncpnkpknbcohdijeoejaedia\Gmail.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=pjkljhegncpnkpknbcohdijeoejaedia
ShortcutWithArgument: C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_jlncjaehedpdoinepaejmlpbmdkgmpog\Journey (Diary, Journal).lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=jlncjaehedpdoinepaejmlpbmdkgmpog
ShortcutWithArgument: C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_ejjicmeblgpmajnghnpcppodonldlgfn\Kalendář Google.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=ejjicmeblgpmajnghnpcppodonldlgfn
ShortcutWithArgument: C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_coobgpohoikkiipiblmjeljniedjpjpf\Vyhledávání Google.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=coobgpohoikkiipiblmjeljniedjpjpf
ShortcutWithArgument: C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_cggdfndeldjmhfganiokikkgpnmdjgim\Úkoly.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=cggdfndeldjmhfganiokikkgpnmdjgim
ShortcutWithArgument: C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Spouštěč aplikací Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --show-app-list
ShortcutWithArgument: C:\Users\Pavel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Spouštěč aplikací Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --show-app-list

==================== Loaded Modules (Whitelisted) ==============

2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2016-07-26 11:47 - 2016-07-01 06:48 - 02656408 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-07-26 11:47 - 2016-07-01 06:48 - 02656408 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2014-05-23 02:10 - 2014-05-23 02:10 - 00671904 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
2010-07-15 06:44 - 2010-07-15 06:44 - 00020032 _____ () C:\Program Files\Unlocker\UnlockerCOM.dll
2016-05-18 00:42 - 2016-05-18 00:42 - 00230064 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll
2014-05-01 16:13 - 2016-07-26 11:04 - 00592384 _____ () C:\ProgramData\MEGAsync\ShellExtX64.dll
2016-07-26 11:47 - 2016-07-01 05:21 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-04-19 08:30 - 2016-04-19 08:31 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2015-12-18 09:22 - 2015-12-07 06:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-07-26 11:50 - 2016-07-01 05:48 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-07-26 11:47 - 2016-07-01 05:27 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-07-26 11:47 - 2016-07-01 05:22 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-07-26 11:47 - 2016-07-01 05:24 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-09-18 18:14 - 2013-08-17 09:16 - 00253952 _____ () C:\Utility\caps-unlocker\CapsUnlocker.exe
2015-03-17 18:10 - 2014-11-25 04:32 - 00254824 _____ () C:\Program Files (x86)\DTLSoft\DriveTheLife\DTLUpdater\CheckUpdate.dll
2015-03-17 18:10 - 2014-11-25 04:32 - 00163704 _____ () C:\Program Files (x86)\DTLSoft\DriveTheLife\substat.dll
2016-01-16 17:08 - 2015-09-15 18:56 - 00306904 _____ () C:\Program Files (x86)\AOMEI Backupper\UiLogic.dll
2016-01-16 17:08 - 2015-09-15 18:56 - 00241368 _____ () C:\Program Files (x86)\AOMEI Backupper\diskmgr.dll
2016-01-16 17:08 - 2015-09-15 18:56 - 00290520 _____ () C:\Program Files (x86)\AOMEI Backupper\Comn.dll
2016-01-16 17:08 - 2015-09-15 18:56 - 00122584 _____ () C:\Program Files (x86)\AOMEI Backupper\FuncLogic.dll
2016-01-16 17:08 - 2015-09-15 18:56 - 00347864 _____ () C:\Program Files (x86)\AOMEI Backupper\ImgFile.dll
2016-01-16 17:08 - 2015-09-15 18:56 - 00028376 _____ () C:\Program Files (x86)\AOMEI Backupper\Encrypt.dll
2016-01-16 17:08 - 2015-09-15 18:56 - 00483032 _____ () C:\Program Files (x86)\AOMEI Backupper\EnumFolder.dll
2016-01-16 17:08 - 2015-09-15 18:56 - 00069336 _____ () C:\Program Files (x86)\AOMEI Backupper\Compress.dll
2016-01-16 17:08 - 2015-09-15 18:56 - 00102104 _____ () C:\Program Files (x86)\AOMEI Backupper\BrLog.dll
2016-01-16 17:08 - 2015-09-15 18:56 - 00691928 _____ () C:\Program Files (x86)\AOMEI Backupper\Sync.dll
2016-01-16 17:08 - 2015-09-15 18:56 - 00077528 _____ () C:\Program Files (x86)\AOMEI Backupper\Ldm.dll
2016-01-16 17:08 - 2015-09-15 18:56 - 00061144 _____ () C:\Program Files (x86)\AOMEI Backupper\Device.dll
2016-01-16 17:08 - 2015-09-15 18:56 - 00282328 _____ () C:\Program Files (x86)\AOMEI Backupper\BrFat.dll
2016-01-16 17:08 - 2015-09-15 18:56 - 00962264 _____ () C:\Program Files (x86)\AOMEI Backupper\BrNtfs.dll
2016-01-16 17:08 - 2015-09-15 18:56 - 00282328 _____ () C:\Program Files (x86)\AOMEI Backupper\Clone.dll
2016-01-16 17:08 - 2015-09-15 18:56 - 00118488 _____ () C:\Program Files (x86)\AOMEI Backupper\Backup.dll
2016-01-16 17:08 - 2015-09-15 18:56 - 00155352 _____ () C:\Program Files (x86)\AOMEI Backupper\FlBackup.dll
2016-01-16 17:08 - 2015-02-26 01:00 - 02403504 _____ () C:\Program Files (x86)\AOMEI Backupper\QtCore4.dll
2016-01-16 17:08 - 2015-09-15 18:56 - 00102104 _____ () C:\Program Files (x86)\AOMEI Backupper\BrVol.dll
2016-01-16 17:08 - 2015-09-15 18:56 - 00253656 _____ () C:\Program Files (x86)\AOMEI Backupper\GptBcd.dll
2016-01-16 17:08 - 2015-09-15 18:56 - 00175832 _____ () C:\Program Files (x86)\AOMEI Backupper\DeviceMgr.dll
2015-07-30 17:53 - 2015-08-27 07:45 - 00144736 _____ () c:\program files (x86)\dtlsoft\drivethelife\ldrvsvc.dll
2015-03-17 18:10 - 2014-11-25 04:32 - 00254824 _____ () c:\program files (x86)\dtlsoft\drivethelife\dtlupdater\checkupdate.dll
2015-03-17 18:10 - 2014-11-25 04:32 - 00163704 _____ () c:\program files (x86)\dtlsoft\drivethelife\substat.dll
2016-04-19 08:30 - 2016-04-19 08:31 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-04-19 08:30 - 2016-04-19 08:31 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2016-07-30 14:51 - 2016-07-30 14:51 - 00098816 ____R () d:\Temp\Temp1\_MEI58162\win32api.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00110080 ____R () d:\Temp\Temp1\_MEI58162\pywintypes27.dll
2016-07-30 14:51 - 2016-07-30 14:51 - 00364544 ____R () d:\Temp\Temp1\_MEI58162\pythoncom27.dll
2016-07-30 14:51 - 2016-07-30 14:51 - 00320512 ____R () d:\Temp\Temp1\_MEI58162\win32com.shell.shell.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00776704 ____R () d:\Temp\Temp1\_MEI58162\_hashlib.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 01176576 ____R () d:\Temp\Temp1\_MEI58162\wx._core_.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00806400 ____R () d:\Temp\Temp1\_MEI58162\wx._gdi_.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00816128 ____R () d:\Temp\Temp1\_MEI58162\wx._windows_.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 01067008 ____R () d:\Temp\Temp1\_MEI58162\wx._controls_.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00733184 ____R () d:\Temp\Temp1\_MEI58162\wx._misc_.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00682496 ____R () d:\Temp\Temp1\_MEI58162\pysqlite2._sqlite.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00088064 ____R () d:\Temp\Temp1\_MEI58162\_ctypes.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00119808 ____R () d:\Temp\Temp1\_MEI58162\win32file.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00108544 ____R () d:\Temp\Temp1\_MEI58162\win32security.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00007168 ____R () d:\Temp\Temp1\_MEI58162\hashobjs_ext.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00017920 ____R () d:\Temp\Temp1\_MEI58162\thumbnails_ext.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00088064 ____R () d:\Temp\Temp1\_MEI58162\usb_ext.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00012288 ____R () d:\Temp\Temp1\_MEI58162\common.time34.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00018432 ____R () d:\Temp\Temp1\_MEI58162\win32event.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00167936 ____R () d:\Temp\Temp1\_MEI58162\win32gui.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00046080 ____R () d:\Temp\Temp1\_MEI58162\_socket.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 01208320 ____R () d:\Temp\Temp1\_MEI58162\_ssl.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00128512 ____R () d:\Temp\Temp1\_MEI58162\_elementtree.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00127488 ____R () d:\Temp\Temp1\_MEI58162\pyexpat.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00038912 ____R () d:\Temp\Temp1\_MEI58162\win32inet.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00036864 ____R () d:\Temp\Temp1\_MEI58162\_psutil_windows.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00525208 ____R () d:\Temp\Temp1\_MEI58162\windows._lib_cacheinvalidation.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00011264 ____R () d:\Temp\Temp1\_MEI58162\win32crypt.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00077312 ____R () d:\Temp\Temp1\_MEI58162\wx._html2.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00027136 ____R () d:\Temp\Temp1\_MEI58162\_multiprocessing.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00020480 ____R () d:\Temp\Temp1\_MEI58162\_yappi.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00035840 ____R () d:\Temp\Temp1\_MEI58162\win32process.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00686080 ____R () d:\Temp\Temp1\_MEI58162\unicodedata.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00078848 ____R () d:\Temp\Temp1\_MEI58162\wx._animate.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00123392 ____R () d:\Temp\Temp1\_MEI58162\wx._wizard.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00024064 ____R () d:\Temp\Temp1\_MEI58162\win32pipe.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00010240 ____R () d:\Temp\Temp1\_MEI58162\select.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00025600 ____R () d:\Temp\Temp1\_MEI58162\win32pdh.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00017408 ____R () d:\Temp\Temp1\_MEI58162\win32profile.pyd
2016-07-30 14:51 - 2016-07-30 14:51 - 00022528 ____R () d:\Temp\Temp1\_MEI58162\win32ts.pyd
2015-09-18 18:14 - 2012-02-24 10:20 - 00053248 _____ () C:\Utility\caps-unlocker\CapsUnlocker.dll
2016-06-01 14:39 - 2016-06-01 14:39 - 00439480 _____ () C:\Program Files (x86)\Evernote\Evernote\libxml2.dll
2016-06-01 14:39 - 2016-06-01 14:39 - 00321208 _____ () C:\Program Files (x86)\Evernote\Evernote\libtidy.dll
2016-07-26 11:04 - 2016-07-26 11:04 - 00482304 _____ () C:\ProgramData\MEGAsync\libsodium.dll
2016-06-18 09:03 - 2016-06-15 11:15 - 01745560 _____ () C:\Program Files (x86)\Google\Chrome\Application\51.0.2704.103\libglesv2.dll
2016-06-18 09:03 - 2016-06-15 11:15 - 00091288 _____ () C:\Program Files (x86)\Google\Chrome\Application\51.0.2704.103\libegl.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:4FC01C57 [286]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-380585536-327012264-1297929140-1000\...\amazon.com -> hxxps://amazon.com

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-380585536-327012264-1297929140-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Pavel\AppData\Local\DisplayFusion\Wallpaper_2.png
DNS Servers: 213.46.172.36 - 213.46.172.37
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: Acrobat Assistant 8.0 => "C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
MSCONFIG\startupreg: Adobe Creative Cloud => "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
MSCONFIG\startupreg: Bitcasa => C:\Program Files\Bitcasa\BitcasaBoot.exe "C:\Program Files\Bitcasa\Bitcasa.exe" /startup
MSCONFIG\startupreg: Bonus.SSR.FR10 => "C:\Program Files (x86)\ABBYY FineReader 10\Bonus.ScreenshotReader.exe" /autorun
MSCONFIG\startupreg: CAHeadless => C:\Program Files (x86)\Adobe\Elements 11 Organizer\CAHeadless\ElementsAutoAnalyzer.exe
MSCONFIG\startupreg: KeePass 2 PreLoad => "C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe" --preload
MSCONFIG\startupreg: ToolwizTimeFreeze => "C:\Program Files\Toolwiz Time Freeze 2014\ToolwizTimeFreeze.exe" -autorun
MSCONFIG\startupreg: Zoner Photo Studio Service 16 => "C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXEC:\Program Files\Zoner\Photo Studio 16\Program32\ZPSService.exe"
HKLM\...\StartupApproved\StartupFolder: => "jetToolBar.lnk"
HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run32: => "KeePass 2 PreLoad"
HKLM\...\StartupApproved\Run32: => "MagicPlusHelper"
HKU\S-1-5-21-380585536-327012264-1297929140-1000\...\StartupApproved\Run: => "RocketDock"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [PotPlayer(PotPlayerMini64.exe)] => (Allow) C:\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe
FirewallRules: [{F681CB9D-4C50-418C-AED4-FCED38FCFC6F}] => (Allow) C:\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe
FirewallRules: [{ADDEB599-351C-4D75-AB63-1F86C1940CE2}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{878CB251-B494-4BB1-ADFD-A1A6784DE1C2}] => (Allow) C:\Program Files\AXON klient Snapshot\AXON.klient.exe
FirewallRules: [{3EA4D12B-3D0F-4C77-945E-7C61BB86FC4C}] => (Allow) C:\Program Files\AXON klient Snapshot\AXON.klient.exe
FirewallRules: [{D3BF550F-7A62-4084-AE0E-BC71C319B9F4}] => (Allow) C:\Program Files\AXON klient Snapshot\AXON.klient.exe
FirewallRules: [{EE3A5A85-E866-4414-99DE-A5190443EEB4}] => (Allow) C:\Program Files\AXON klient Snapshot\AXON.klient.exe
FirewallRules: [TCP Query User{56D6CC77-C3E2-4833-9CE5-1DEC83E82973}C:\program files (x86)\canon\network scangear\sgtool.exe] => (Allow) C:\program files (x86)\canon\network scangear\sgtool.exe
FirewallRules: [UDP Query User{70C3F4BA-066D-469C-9AC7-2105924E0B41}C:\program files (x86)\canon\network scangear\sgtool.exe] => (Allow) C:\program files (x86)\canon\network scangear\sgtool.exe
FirewallRules: [TCP Query User{DC697E90-2D2D-4626-B51F-1FE1E557BFA9}C:\utility\radiosure\radiosure.exe] => (Allow) C:\utility\radiosure\radiosure.exe
FirewallRules: [UDP Query User{B5F27EA8-F94C-464D-BBF1-0525AA60BB20}C:\utility\radiosure\radiosure.exe] => (Allow) C:\utility\radiosure\radiosure.exe
FirewallRules: [TCP Query User{B4FA640C-1DA0-4A09-AD2B-A473E3F16229}C:\program files\onone software\perfect effects 8\perfect effects 8.exe] => (Allow) C:\program files\onone software\perfect effects 8\perfect effects 8.exe
FirewallRules: [UDP Query User{5F7E03FF-E250-4DB9-BC43-A60B35BCB053}C:\program files\onone software\perfect effects 8\perfect effects 8.exe] => (Allow) C:\program files\onone software\perfect effects 8\perfect effects 8.exe
FirewallRules: [TCP Query User{9E5FC62A-1D3E-4DF8-BA28-96EA79B9AF66}C:\program files (x86)\java\jre1.8.0_40\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_40\launch4j-tmp\frd.exe
FirewallRules: [UDP Query User{3156C305-9084-480A-938D-C11AEC86623F}C:\program files (x86)\java\jre1.8.0_40\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_40\launch4j-tmp\frd.exe
FirewallRules: [TCP Query User{801BDAF8-C28F-4DCD-9BFE-83187168F71D}C:\program files (x86)\blobby volley 2 version 1.0\blobby.exe] => (Allow) C:\program files (x86)\blobby volley 2 version 1.0\blobby.exe
FirewallRules: [UDP Query User{92714BA9-3F72-439A-AFEF-72D201E2BACC}C:\program files (x86)\blobby volley 2 version 1.0\blobby.exe] => (Allow) C:\program files (x86)\blobby volley 2 version 1.0\blobby.exe
FirewallRules: [{5DC1B072-BF07-46CC-B325-567E62250A16}] => (Allow) C:\Program Files (x86)\DTLSoft\DriveTheLife\DriveTheLife.exe
FirewallRules: [{7EB7C9D3-1FA2-412A-A299-DB09C2A42C52}] => (Allow) C:\Program Files (x86)\DTLSoft\DriveTheLife\DTLService.exe
FirewallRules: [{9B218FB9-2B10-42CC-AA9C-C53F4ACEC37F}] => (Allow) C:\Program Files (x86)\DTLSoft\DriveTheLife\download\MiniThunderPlatform.exe
FirewallRules: [{8A066A18-0EA0-4C09-9AAD-A9B9595B307A}] => (Allow) C:\Users\Pavel\AppData\Local\Microsoft\OneDrive\OneDrive.exe
FirewallRules: [{38422FE7-2692-4B0A-8D76-B0ED2EA12869}] => (Allow) C:\Utility\uTorrent\utorrent.exe
FirewallRules: [{CFC43E86-A4AD-48E1-951C-39F02858DF6B}] => (Allow) C:\Utility\uTorrent\utorrent.exe
FirewallRules: [{16C78ACC-C971-4CB0-A94C-57D6149AE28F}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe
FirewallRules: [{4CABCEE2-1DC1-45A3-B821-7AC226E31E28}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe
FirewallRules: [TCP Query User{899F6DD4-2353-43B1-8EB2-FADCB4BF9F09}C:\program files (x86)\magicplus\magicplus.exe] => (Allow) C:\program files (x86)\magicplus\magicplus.exe
FirewallRules: [UDP Query User{6E7FCAD3-E85D-4948-86AB-D670303DFC45}C:\program files (x86)\magicplus\magicplus.exe] => (Allow) C:\program files (x86)\magicplus\magicplus.exe
FirewallRules: [{D776388B-FC59-4431-B585-45D4B74DBF2D}] => (Allow) C:\Program Files\Farpr\Farpr.exe
FirewallRules: [{59EF3078-4B7B-443C-A5B7-1F87E6D0F06D}] => (Allow) C:\Program Files\Farpr\Farpr.exe
FirewallRules: [{7BD55F2C-698A-4F46-80BF-380EBA9C995A}] => (Allow) C:\Program Files\Farpr\Farpr.exe
FirewallRules: [{177CA20F-801D-4101-B689-E52D3B792636}] => (Allow) C:\Program Files\Farpr\Farpr.exe
FirewallRules: [{FA46201A-D575-46E5-8A53-B25DB15E98CB}] => (Allow) C:\Program Files\Farpr\fbguard.exe
FirewallRules: [{6887CE3F-0E2D-4C89-B58C-C00DA9FA9C67}] => (Allow) C:\Program Files\Farpr\fbguard.exe
FirewallRules: [{E723133F-8DDA-446C-899F-7C6BE614B80A}] => (Allow) C:\Program Files\Farpr\fbguard.exe
FirewallRules: [{FA8C5A2C-0304-4B54-ADC7-5270C9C60FAD}] => (Allow) C:\Program Files\Farpr\fbguard.exe
FirewallRules: [{90D56D71-5FCE-4481-8C61-38ACA055E557}] => (Allow) C:\Program Files\Farpr\Firebird.exe
FirewallRules: [{749DDA90-2242-4FEB-82B6-C1B5CABD9E0A}] => (Allow) C:\Program Files\Farpr\Firebird.exe
FirewallRules: [{EEDE8272-0287-4474-90E0-F77495D9E9EA}] => (Allow) C:\Program Files\Farpr\Firebird.exe
FirewallRules: [{A77840D1-5C43-4D75-A532-72CE0F1A485F}] => (Allow) C:\Program Files\Farpr\Firebird.exe
FirewallRules: [{E82DFDD8-9F79-4895-9FAB-D8DB95708BEA}] => (Allow) C:\Program Files\Farpr\aktualizuj.exe
FirewallRules: [{E8EFDE04-97F4-424B-B696-2ACBFF62DFC0}] => (Allow) C:\Program Files\Farpr\aktualizuj.exe
FirewallRules: [{B561EFB4-1113-4957-A156-7B5C48444620}] => (Allow) C:\Program Files\Farpr\aktualizuj.exe
FirewallRules: [{FC5B6878-A38B-4FB7-B22B-E71071D5F198}] => (Allow) C:\Program Files\Farpr\aktualizuj.exe
FirewallRules: [{9AD84EE6-28DF-4F90-9333-F1FC26A8C318}] => (Allow) C:\Program Files\FreeFileSync\FreeFileSync.exe
FirewallRules: [{4007C93A-0DE6-412E-BC25-8AE402036164}] => (Allow) C:\Program Files\FreeFileSync\FreeFileSync.exe
FirewallRules: [{82057C07-6460-4B8D-BCEC-413E1247A4E4}] => (Allow) C:\Program Files\FreeFileSync\FreeFileSync.exe
FirewallRules: [{40FBF779-6FDD-4D5A-80F2-C92A03B1FE31}] => (Allow) C:\Program Files\FreeFileSync\FreeFileSync.exe
FirewallRules: [{D3AA60F3-962C-46F5-956A-A1285B3AF93A}] => (Allow) C:\totalcmd64\TOTALCMD64.EXE
FirewallRules: [{95AA8E54-2926-4D92-BD61-D0E17B2024AC}] => (Allow) C:\totalcmd64\TOTALCMD64.EXE
FirewallRules: [{6C872B64-C641-48B0-8596-96FEB3F7325B}] => (Allow) C:\totalcmd64\TOTALCMD64.EXE
FirewallRules: [{21892E93-04DE-48B9-A67B-7DAF6B70AB6F}] => (Allow) C:\totalcmd64\TOTALCMD64.EXE
FirewallRules: [{EB0C6E3E-60AC-403C-94A1-796814A79984}] => (Allow) C:\totalcmd64\TCMADM64.EXE
FirewallRules: [{B9D69345-517A-4D85-98BE-88BD48F849C2}] => (Allow) C:\totalcmd64\TCMADM64.EXE
FirewallRules: [{2B77D777-2B6F-44AE-8A19-DE80D8B9155A}] => (Allow) C:\totalcmd64\TCMADM64.EXE
FirewallRules: [{F59BD6F2-4DAA-49A9-996E-A655E146C7BD}] => (Allow) C:\totalcmd64\TCMADM64.EXE
FirewallRules: [{2DC7DFAD-9F70-4AF1-B2F7-3330454D416E}] => (Allow) C:\Program Files (x86)\AOMEI Backupper\PxeUi.exe
FirewallRules: [{E1AC7C81-4535-4454-B14F-1AEE8233A470}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{6750E419-6B96-4F07-B042-05FCE13D8DBA}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
FirewallRules: [{40D69677-D65C-4E3F-8297-C8F9A051AF9E}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{49966E61-A321-40CC-BB7E-B2A73DAB1C98}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe

==================== Restore Points =========================

ATTENTION: System Restore is disabled

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (07/30/2016 04:08:01 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

Error: (07/30/2016 04:08:01 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

Error: (07/30/2016 04:08:01 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

Error: (07/30/2016 02:56:04 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

Error: (07/30/2016 02:56:04 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

Error: (07/30/2016 02:56:04 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

Error: (07/30/2016 02:54:38 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Generování kontextu aktivace pro C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.494_none_a2d8b04ea53e3145.manifest1 se nezdařilo. Chyba v souboru manifestu nebo zásad C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.494_none_a2d8b04ea53e3145.manifest2 na řádku C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.494_none_a2d8b04ea53e3145.manifest3.
Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní.
Konfliktní součásti:
Součást 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.494_none_a2d8b04ea53e3145.manifest.
Součást 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.494_none_ea85e725b9ba5a4b.manifest.

Error: (07/30/2016 02:54:38 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Generování kontextu aktivace pro C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.494_none_a2d8b04ea53e3145.manifest1 se nezdařilo. Chyba v souboru manifestu nebo zásad C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.494_none_a2d8b04ea53e3145.manifest2 na řádku C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.494_none_a2d8b04ea53e3145.manifest3.
Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní.
Konfliktní součásti:
Součást 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.494_none_a2d8b04ea53e3145.manifest.
Součást 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.494_none_ea85e725b9ba5a4b.manifest.

Error: (07/30/2016 01:33:57 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

Error: (07/30/2016 01:33:57 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.


System errors:
=============
Error: (07/30/2016 07:54:39 PM) (Source: DCOM) (EventID: 10016) (User: Dual-stůl)
Description: specifické pro aplikaciMístníAktivace{9E175B6D-F52A-11D8-B9A5-505054503030}{9E175B9C-F52A-11D8-B9A5-505054503030}Dual-stůlPavelS-1-5-21-380585536-327012264-1297929140-1000LocalHost (pomocí LRPC)Není k dispoziciNení k dispozici

Error: (07/30/2016 07:54:39 PM) (Source: DCOM) (EventID: 10016) (User: Dual-stůl)
Description: specifické pro aplikaciMístníAktivace{9E175B6D-F52A-11D8-B9A5-505054503030}{9E175B9C-F52A-11D8-B9A5-505054503030}Dual-stůlPavelS-1-5-21-380585536-327012264-1297929140-1000LocalHost (pomocí LRPC)Není k dispoziciNení k dispozici

Error: (07/30/2016 07:54:39 PM) (Source: DCOM) (EventID: 10016) (User: Dual-stůl)
Description: specifické pro aplikaciMístníAktivace{9E175B6D-F52A-11D8-B9A5-505054503030}{9E175B9C-F52A-11D8-B9A5-505054503030}Dual-stůlPavelS-1-5-21-380585536-327012264-1297929140-1000LocalHost (pomocí LRPC)Není k dispoziciNení k dispozici

Error: (07/30/2016 04:08:20 PM) (Source: Microsoft-Windows-HAL) (EventID: 12) (User: )
Description: Firmware platformy při předchozím přechodu systémového napájení poškodil paměť. Zkontrolujte dostupnost aktualizovaného firmwaru pro váš systém.

Error: (07/30/2016 02:49:43 PM) (Source: Service Control Manager) (EventID: 7003) (User: )
Description: Služba Správce výběru OS závisí na následující službě: ProtectedStorage. Tato služba pravděpodobně není nainstalována.

Error: (07/30/2016 02:49:43 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Služba NetTcpActivator závisí na službě NetTcpPortSharing, která neuspěla při spuštění v důsledku následující chyby: 
%%1058 = Zvolenou službu nelze spustit, protože není povolena nebo s ní není spojeno žádné povolené zařízení.


Error: (07/30/2016 02:49:37 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Předchozí vypnutí systému (13:40:43, ‎30.‎07.‎2016) bylo neočekávané.

Error: (07/30/2016 01:40:47 PM) (Source: Service Control Manager) (EventID: 7003) (User: )
Description: Služba Správce výběru OS závisí na následující službě: ProtectedStorage. Tato služba pravděpodobně není nainstalována.

Error: (07/30/2016 01:40:47 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Služba NetTcpActivator závisí na službě NetTcpPortSharing, která neuspěla při spuštění v důsledku následující chyby: 
%%1058 = Zvolenou službu nelze spustit, protože není povolena nebo s ní není spojeno žádné povolené zařízení.


Error: (07/30/2016 01:36:47 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Přístup k uživatelským datům_3b8e1 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.


CodeIntegrity:
===================================
  Date: 2016-07-30 08:09:16.024
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-07-29 15:05:57.643
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-07-29 13:09:50.515
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-06-26 13:50:20.713
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-06-24 19:22:03.717
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-06-20 08:11:45.032
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-06-18 12:58:37.525
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-06-18 12:02:33.960
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-06-18 08:48:20.362
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-06-17 09:03:08.338
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.


==================== Memory info =========================== 

Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 3800+
Percentage of memory in use: 29%
Total physical RAM: 8191.55 MB
Available physical RAM: 5778.44 MB
Total Virtual: 13191.55 MB
Available Virtual: 10517 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:118.26 GB) (Free:75.96 GB) NTFS
Drive d: (LETISTE) (Fixed) (Total:445.75 GB) (Free:102.06 GB) NTFS
Drive e: (DATA) (Fixed) (Total:20 GB) (Free:4.69 GB) NTFS
Drive f: (ZALOHA) (Fixed) (Total:149.05 GB) (Free:55.4 GB) NTFS
Drive h: (2T) (Fixed) (Total:1862.98 GB) (Free:1406 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 119.2 GB) (Disk ID: 47F6CBE6)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=118.3 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)

========================================================
Disk: 1 (Size: 465.8 GB) (Disk ID: AF1B6DA9)
Partition 1: (Not Active) - (Size=20 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=445.8 GB) - (Type=07 NTFS)

========================================================
Disk: 2 (Size: 149 GB) (Disk ID: FAD4FAD4)
Partition 1: (Active) - (Size=149 GB) - (Type=07 NTFS)

========================================================
Disk: 3 (MBR Code: Windows XP) (Size: 1863 GB) (Disk ID: DB8B27FC)
Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================