Additional scan result of Farbar Recovery Scan Tool (x86) Version: 07-12-2016
Ran by Tomáš (13-12-2016 09:24:15)
Running from C:\Users\Tomáš\Desktop
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) (2008-06-28 13:08:21)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-401885020-672167872-4106706270-500 - Administrator - Disabled)
Guest (S-1-5-21-401885020-672167872-4106706270-501 - Limited - Disabled)
Tomáš (S-1-5-21-401885020-672167872-4106706270-1000 - Administrator - Enabled) => C:\Users\Tomáš

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avast Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-401885020-672167872-4106706270-1000\...\uTorrent) (Version: 3.4.9.42973 - BitTorrent Inc.)
7-Zip 15.14 (HKLM\...\{23170F69-40C1-2701-1514-000001000000}) (Version: 15.14.00.0 - Igor Pavlov)
Adobe Flash Player 19 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 19.0.0.226 - Adobe Systems Incorporated)
Adobe Flash Player 22 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 22.0.0.210 - Adobe Systems Incorporated)
Adobe Reader X (10.1.16) - Czech (HKLM\...\{AC76BA86-7AD7-1029-7B44-AA1000000001}) (Version: 10.1.16 - Adobe Systems Incorporated)
Aktualizace produktu Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISE_{0A1FAC46-B899-421D-B1A2-470896DC45DB}) (Version:  - Microsoft)
Aktualizace produktu Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISE_{5260BB53-C1F7-4A3B-9AEB-3EC9B37FF194}) (Version:  - Microsoft)
Aktualizace produktu Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISE_{E68DD413-B834-4923-8181-0A03B7555187}) (Version:  - Microsoft)
Avast Free Antivirus (HKLM\...\Avast) (Version: 12.3.2280 - AVAST Software)
FlexiBooks (HKU\S-1-5-21-401885020-672167872-4106706270-1000\...\eaadb22a7fda717f) (Version: 3.0.5.16 - Fraus Media spol. s r.o.)
Google Chrome (HKLM\...\Google Chrome) (Version: 49.0.2623.112 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.31.5 - Google Inc.) Hidden
MFC RunTime files (Version: 1.0.0 - Extensoft) Hidden
Microsoft .NET Framework 3.5 SP1 – jazyková sada – CSY (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - csy) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (čeština) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 2 (SP2) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}) (Version:  - Microsoft)
Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6425.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Online Games Manager v1.50 (HKLM\...\Online Games Manager) (Version: 1.50.1 - Real Networks, Inc.)
QCAD 3.15.3 (HKLM\...\QCAD) (Version: 3.15.3 - RibbonSoft GmbH)
Realtek 8139 and 8139C+ Ethernet Network Card Driver for Windows Vista (HKLM\...\{AE46ABD3-D625-467F-B5A7-8D3FFF077F0D}) (Version: 1.00.0000 - Realtek)
Revo Uninstaller 2.0.1 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.0.1 - VS Revo Group, Ltd.)
SafeZone Stable 1.48.2066.120 (Version: 1.48.2066.120 - Avast Software) Hidden
Skype™ 7.30 (HKLM\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.30.105 - Skype Technologies S.A.)
Sweet Home 3D version 5.2 (HKLM\...\Sweet Home 3D_is1) (Version: 5.2 - eTeks)
TOSHIBA Extended Tiles for Windows Mobility Center (HKLM\...\InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}) (Version: 1.01.00 - Toshiba)
Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.1 - VideoLAN)
Widevine Media Optimizer Chrome 6.0.0 (HKU\S-1-5-21-401885020-672167872-4106706270-1000\...\optimizer_chrome) (Version: 6.0.0.12757 - Widevine Technologies)
Windows Movie Maker 2.6 (HKLM\...\{B3DAF54F-DB25-4586-9EF1-96D24BB14088}) (Version: 2.6.4040.0 - Microsoft Corporation)
Wooky 2.0.0.0 (HKU\S-1-5-21-401885020-672167872-4106706270-1000\...\Wooky) (Version: 2.0.0.0 - Mobilbonus, s.r.o.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0C3AF200-FADC-49E5-880E-DEE192C8B79A} - System32\Tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask => C:\Windows\system32\RAServer.exe [2008-01-19] (Společnost Microsoft)
Task: {45E3B477-33B4-4A5E-B990-7E069A0C0FEB} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-09-14] (Adobe Systems Incorporated)
Task: {50A84039-A8AE-4401-8614-2AFB5FD38466} - System32\Tasks\{8AC47CF0-04A1-4D8B-977B-F7220D6E0400} => pcalua.exe -a "C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe" -c -uninstall
Task: {70D28111-48F8-47E5-B0B5-5EC306D4E27C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {8F6C3108-8BE0-4379-9EE6-CD328AA2A26C} - System32\Tasks\SafeZone scheduled Autoupdate 1460789744 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-08-12] (Avast Software)
Task: {971FF76C-B042-4CC1-931B-A9DA35F0CEF3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {A37D14E4-2523-4EC4-80E3-6D860CD5618F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2012-12-19] (Piriform Ltd)
Task: {B4D9BAAD-881B-41D6-AA0A-4E907BCB64E8} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-09-26] (AVAST Software)
Task: {ED0357DA-3669-43CE-8CEA-A53893EB00E7} - System32\Tasks\{C45B2238-C459-41C3-A631-31180011BA02} => Firefox.exe hxxp://ui.skype.com/ui/0/4.1.0.179/cs/abandoninstall?page=tsInstall&amp;installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:notoffered;ienotdefaultbrowser2
Task: {F4C03E4F-2995-4E57-8B58-72A055613441} - System32\Tasks\{57E9D930-435E-4525-9C64-7D375B6EC95B} => Firefox.exe hxxp://ui.skype.com/ui/0/4.2.0.169/cs/abandoninstall?page=tsDownload&amp;installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:notoffered;userlevelpresent

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2007-09-05 08:12 - 2007-02-05 17:13 - 00094208 _____ () C:\Program Files\ATK Hotkey\ASLDRSrv.exe
2016-09-26 12:20 - 2016-09-26 12:20 - 00169064 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-12-12 21:23 - 2016-12-12 21:23 - 03068416 _____ () C:\Program Files\AVAST Software\Avast\defs\16121201\algo.dll
2016-09-26 12:20 - 2016-09-26 12:20 - 00482928 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2010-11-21 15:54 - 2010-11-21 15:54 - 00094208 _____ () C:\Program Files\FileZilla FTP Client\fzshellext.dll
2007-09-05 08:12 - 2004-05-27 17:13 - 00057344 _____ () C:\Program Files\ATK Hotkey\CMSSC.dll
2007-09-05 08:12 - 2007-03-22 16:09 - 02420736 _____ () C:\Program Files\ATK Hotkey\ATKOSD.exe
2016-09-26 12:21 - 2016-09-26 12:21 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2016-09-10 17:18 - 2016-09-06 11:00 - 05197312 _____ () C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\SwiftShader\3.3.0.1\libglesv2.dll
2016-09-10 17:18 - 2016-09-06 11:00 - 00147456 _____ () C:\Users\Tomáš\AppData\Local\Google\Chrome\User Data\SwiftShader\3.3.0.1\libegl.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:66BB1E73 [171]
AlternateDataStreams: C:\ProgramData\TEMP:888AFB86 [110]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

HKLM\...\cmdfile\DefaultIcon: %SystemRoot%\System32\imageres.dll,-68 <===== ATTENTION

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com

There are 7736 more sites.

IE restricted site: HKU\S-1-5-21-401885020-672167872-4106706270-1000\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-401885020-672167872-4106706270-1000\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-401885020-672167872-4106706270-1000\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-401885020-672167872-4106706270-1000\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-401885020-672167872-4106706270-1000\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-401885020-672167872-4106706270-1000\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-401885020-672167872-4106706270-1000\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-401885020-672167872-4106706270-1000\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-401885020-672167872-4106706270-1000\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-401885020-672167872-4106706270-1000\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-401885020-672167872-4106706270-1000\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-401885020-672167872-4106706270-1000\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-401885020-672167872-4106706270-1000\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-401885020-672167872-4106706270-1000\...\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-401885020-672167872-4106706270-1000\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-401885020-672167872-4106706270-1000\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-401885020-672167872-4106706270-1000\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-401885020-672167872-4106706270-1000\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-401885020-672167872-4106706270-1000\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-401885020-672167872-4106706270-1000\...\123simsen.com -> www.123simsen.com

There are 7734 more sites.


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2006-11-02 11:23 - 2016-12-12 23:07 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts

127.0.0.1       localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-401885020-672167872-4106706270-1000\Control Panel\Desktop\\Wallpaper -> E:\Pictures\Cestování\Česko\Teplá 2012\P1030535.JPG
DNS Servers: 192.168.88.1 - 188.122.222.222
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 0) (EnableLUA: 0)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\Services: !SASCORE => 3
MSCONFIG\Services: 602XML Updater => 2
MSCONFIG\Services: a2AntiMalware => 2
MSCONFIG\Services: Apache2.2 => 2
MSCONFIG\Services: mysql => 2
MSCONFIG\Services: SkypeUpdate => 2
MSCONFIG\Services: XAMPP => 2
MSCONFIG\startupreg: ActivControl => C:\Program Files\Activ Software\ActivDriver\ActivControl2.exe
MSCONFIG\startupreg: RtHDVCpl => RtHDVCpl.exe
MSCONFIG\startupreg: ShowBatteryBar => "C:\Program Files\BatteryBar\ShowBatteryBar.exe" show
MSCONFIG\startupreg: Skytel => Skytel.exe

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [WinCollab-In-TCP] => %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-TCP] => %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-UDP] => %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-UDP] => %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [TCP Query User{ACB9E3CD-2A45-4C9C-9A95-1AFCFB20BF42}C:\program files\totalcmd\totalcmd.exe] => C:\program files\totalcmd\totalcmd.exe
FirewallRules: [UDP Query User{D0E627A0-E4FA-4365-98B0-3B02937E7AF0}C:\program files\totalcmd\totalcmd.exe] => C:\program files\totalcmd\totalcmd.exe
FirewallRules: [TCP Query User{4670BBFA-3A8B-464A-9F11-0A0FD3254690}C:\program files\zend\zendstudio-5.5.0\jre\bin\javaw.exe] => C:\program files\zend\zendstudio-5.5.0\jre\bin\javaw.exe
FirewallRules: [UDP Query User{64842079-BDA1-472D-88E5-5F0B7C83F8A6}C:\program files\zend\zendstudio-5.5.0\jre\bin\javaw.exe] => C:\program files\zend\zendstudio-5.5.0\jre\bin\javaw.exe
FirewallRules: [TCP Query User{8271DD5F-B510-45BA-9A6A-75E29E8221AA}C:\program files\zend\zendstudio-5.5.0\jre\bin\javaw.exe] => C:\program files\zend\zendstudio-5.5.0\jre\bin\javaw.exe
FirewallRules: [UDP Query User{225DDC6A-9001-4DFD-BDCE-40F1CE2F9988}C:\program files\zend\zendstudio-5.5.0\jre\bin\javaw.exe] => C:\program files\zend\zendstudio-5.5.0\jre\bin\javaw.exe
FirewallRules: [TCP Query User{B4539E49-A5CF-46E0-BBB8-6232AEB83A68}E:\apache\apache\bin\apache.exe] => E:\apache\apache\bin\apache.exe
FirewallRules: [UDP Query User{A8AF7DB8-BB1A-4452-8FD0-A4629E8C197E}E:\apache\apache\bin\apache.exe] => E:\apache\apache\bin\apache.exe
FirewallRules: [TCP Query User{6BDD1A8A-289F-49C5-85D4-17A950B059E3}E:\apache\mysql\bin\mysqld.exe] => E:\apache\mysql\bin\mysqld.exe
FirewallRules: [UDP Query User{2F435029-B20B-4AD3-839B-4FD3CE9C58EB}E:\apache\mysql\bin\mysqld.exe] => E:\apache\mysql\bin\mysqld.exe
FirewallRules: [TCP Query User{F90FC2F2-46AB-4648-BC7F-E5DDFDB19618}C:\program files\totalcmd\totalcmd.exe] => C:\program files\totalcmd\totalcmd.exe
FirewallRules: [UDP Query User{0FC6AF0B-AAA3-4C1D-8AFB-735E0FE996CA}C:\program files\totalcmd\totalcmd.exe] => C:\program files\totalcmd\totalcmd.exe
FirewallRules: [TCP Query User{FE45FCE1-3389-4968-B399-0596292E00B9}C:\program files\filezilla ftp client\filezilla.exe] => C:\program files\filezilla ftp client\filezilla.exe
FirewallRules: [UDP Query User{91F0D3B4-0989-4EE2-A39A-14AAE7E954FE}C:\program files\filezilla ftp client\filezilla.exe] => C:\program files\filezilla ftp client\filezilla.exe
FirewallRules: [TCP Query User{97A2F987-2E3F-4ED1-99CD-798BC68317CF}C:\program files\internet explorer\iexplore.exe] => C:\program files\internet explorer\iexplore.exe
FirewallRules: [UDP Query User{B379BA12-3669-4752-BC28-061C31737FE9}C:\program files\internet explorer\iexplore.exe] => C:\program files\internet explorer\iexplore.exe
FirewallRules: [TCP Query User{90EA19D7-87C4-4466-9F8C-610E2EE813E9}E:\apache\apache\bin\apache.exe] => E:\apache\apache\bin\apache.exe
FirewallRules: [UDP Query User{0A4BADF9-48B7-43A3-992A-42E66507B81A}E:\apache\apache\bin\apache.exe] => E:\apache\apache\bin\apache.exe
FirewallRules: [TCP Query User{CDAD98C8-01F8-4E05-97E4-11D82CAEE4D1}E:\apache\mysql\bin\mysqld.exe] => E:\apache\mysql\bin\mysqld.exe
FirewallRules: [UDP Query User{939C6270-5AE4-4129-97E2-E677080AFA70}E:\apache\mysql\bin\mysqld.exe] => E:\apache\mysql\bin\mysqld.exe
FirewallRules: [TCP Query User{4E74AEFB-4E0F-47C2-96E3-D2405C3CD84F}E:\apache\apache\bin\httpd.exe] => E:\apache\apache\bin\httpd.exe
FirewallRules: [UDP Query User{C743C5BE-BA3B-4E68-81C2-B7D0546B4BBB}E:\apache\apache\bin\httpd.exe] => E:\apache\apache\bin\httpd.exe
FirewallRules: [TCP Query User{62A7CC0A-54D1-4EA4-A3A1-6410519F7919}C:\program files\filezilla ftp client\filezilla.exe] => C:\program files\filezilla ftp client\filezilla.exe
FirewallRules: [UDP Query User{3B48D0CB-709E-47E6-A16D-4422323317E1}C:\program files\filezilla ftp client\filezilla.exe] => C:\program files\filezilla ftp client\filezilla.exe
FirewallRules: [TCP Query User{6B510C44-680A-4ABC-8B97-D5E6245CFBC8}C:\program files\activision\empires dawn of the modern world\empires_dmw.exe] => C:\program files\activision\empires dawn of the modern world\empires_dmw.exe
FirewallRules: [UDP Query User{F9B3386D-98D7-4BCF-A3DA-2076B017C8FD}C:\program files\activision\empires dawn of the modern world\empires_dmw.exe] => C:\program files\activision\empires dawn of the modern world\empires_dmw.exe
FirewallRules: [TCP Query User{C21D348E-B517-49D7-B88C-927F3967111B}C:\program files\activision\empires dawn of the modern world\empires_dmw.exe] => C:\program files\activision\empires dawn of the modern world\empires_dmw.exe
FirewallRules: [UDP Query User{2CDAC453-485E-46C5-B6B7-BDED8D2C92BE}C:\program files\activision\empires dawn of the modern world\empires_dmw.exe] => C:\program files\activision\empires dawn of the modern world\empires_dmw.exe
FirewallRules: [{3D444F81-F5BD-490F-9681-E2AB1432464B}] => LPort=80
FirewallRules: [{D0851A2D-7554-4FD6-A29C-9DF55A9A62B6}] => LPort=80
FirewallRules: [{E57F6A81-94D7-4D19-8195-05455008BCFF}] => LPort=80
FirewallRules: [{3BCAF1F4-5509-4CD9-8CA1-B3727892E02D}] => C:\Program Files\TeamViewer\Version6\TeamViewer.exe
FirewallRules: [{68DFB881-6B98-4C41-B352-30262129BE95}] => C:\Program Files\TeamViewer\Version6\TeamViewer.exe
FirewallRules: [{2B1A8A05-ABD9-4948-9503-A537E33A5291}] => C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
FirewallRules: [{A49E98D4-5851-4FCD-9646-081F2103463A}] => C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
FirewallRules: [{34D2EE4B-929D-421C-BE54-ED51A0EF5BB0}] => C:\Program Files\Common Files\soft602\langserv.exe
FirewallRules: [{DD445EFE-DB65-4439-9509-2DF0EEBCE82D}] => C:\Program Files\Common Files\soft602\langserv.exe
FirewallRules: [TCP Query User{B834BDF1-F39D-49F0-AF2F-160DBC917FFD}C:\program files\opera\opera.exe] => C:\program files\opera\opera.exe
FirewallRules: [UDP Query User{22DB06FE-823F-4A99-9132-AC3FCFA569B4}C:\program files\opera\opera.exe] => C:\program files\opera\opera.exe
FirewallRules: [TCP Query User{DBF93605-156F-4656-810B-0403276BFA32}E:\apache\apache\bin\httpd.exe] => E:\apache\apache\bin\httpd.exe
FirewallRules: [UDP Query User{A7477791-B2C4-45D1-97D6-3F3517E805D3}E:\apache\apache\bin\httpd.exe] => E:\apache\apache\bin\httpd.exe
FirewallRules: [TCP Query User{668D44FE-60C6-4339-892D-DAE2360474D3}C:\program files\activision2\empires dawn of the modern world\empires_dmw.exe] => C:\program files\activision2\empires dawn of the modern world\empires_dmw.exe
FirewallRules: [UDP Query User{55D67F7D-D47B-43D4-83E9-C68D45AED472}C:\program files\activision2\empires dawn of the modern world\empires_dmw.exe] => C:\program files\activision2\empires dawn of the modern world\empires_dmw.exe
FirewallRules: [{38163963-030C-4CE5-BAC8-50099534FF70}] => C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{6C859D93-F1AF-400B-9D9B-0978DFB492C3}] => C:\Program Files\Common Files\soft602\langserv.exe
FirewallRules: [{313B6013-088D-4981-B369-DFDDE38EA00C}] => C:\Program Files\Common Files\soft602\langserv.exe
FirewallRules: [{623B125F-68A3-4C22-A146-A4897485DF96}] => C:\Users\Tomáš\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{8447C9CA-228C-4000-B1B1-529A588DA0CF}] => C:\Users\Tomáš\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{8094EDEF-5D36-46BB-8AA6-7B3D011BFA43}] => C:\Users\Tomáš\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{0CF4EAC5-8780-44AF-A537-1DB3BCE2030F}] => C:\Users\Tomáš\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{7F4BD45B-DBD3-45CB-9540-0656B3BFA866}] => C:\Program Files\Skype\Phone\Skype.exe
FirewallRules: [{5812CDEB-CFD6-4828-A949-C91E02DFE47D}] => C:\Program Files\Google\Chrome\Application\chrome.exe

==================== Restore Points =========================

11-12-2016 16:43:03 ComboFix created restore point
12-12-2016 23:58:15 Revo Uninstaller's restore point - Microsoft Script Debugger
13-12-2016 00:04:53 Removed Zoner Callisto 5

==================== Faulty Device Manager Devices =============

Name: Microsoft ISATAP Adapter #3
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver

Name: TeamViewer VPN Adapter
Description: TeamViewer VPN Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: TeamViewer GmbH
Service: teamviewervpn
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows
Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: vpnva
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (12/12/2016 11:58:13 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Chyba služby Stínová kopie svazků: Při dotazu na rozhraní IVssWriterCallback došlo k neočekávané chybě. hr = 0x80070005.
To je často způsobeno nesprávným nastavením zabezpečení v modulu pro zápis nebo žadateli.


Operace:
   Shromažďování dat modulu pro zápis

Kontext:
   ID třídy modulu pro zápis: {e8132975-6f93-4464-a53e-1050253ae220}
   Název modulu pro zápis: System Writer
   ID instance modulu pro zápis: {77860f27-dd97-4293-9d5f-8465b047cdeb}

Error: (12/12/2016 10:43:03 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Vytvoření bodu obnovení na svazku se nezdařilo (Proces = C:\Windows\system32\wbem\wmiprvse.exe; Popis = ComboFix created restore point; Hr = 0x8007043c).

Error: (12/12/2016 10:43:03 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny CoCreateInstance došlo k neočekávané chybě. hr= 0x8007043c.


Operace:
   Vytvoření instance serveru VSS

Error: (12/12/2016 10:43:03 PM) (Source: VSS) (EventID: 18) (User: )
Description: Chyba služby Stínová kopie svazku: Server COM s identifikátorem CLSID {e579ab5f-1cc4-44b4-bed9-de0991ff0623} a názvem Coordinator nelze spustit v nouzovém režimu. 
Službu Stínová kopie svazku nelze spustit v nouzovém režimu. [0x8007043c]


Operace:
   Vytvoření instance serveru VSS

Error: (12/12/2016 10:41:08 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Vytvoření bodu obnovení na svazku se nezdařilo (Proces = C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exe Files\VS Revo Group\Revo Uninstaller\RevoUnin.exe" ; Popis = Revo Uninstaller's restore point - TogglDesktop; Hr = 0x8007043c).

Error: (12/12/2016 10:40:19 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Vytvoření bodu obnovení na svazku se nezdařilo (Proces = C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exe Files\VS Revo Group\Revo Uninstaller\RevoUnin.exe" ; Popis = Revo Uninstaller's restore point - TogglDesktop; Hr = 0x8007043c).

Error: (12/12/2016 10:38:52 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Vytvoření bodu obnovení na svazku se nezdařilo (Proces = C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exe Files\VS Revo Group\Revo Uninstaller\RevoUnin.exe" ; Popis = Revo Uninstaller's restore point - Malwarebytes verze 3.0.4.1269; Hr = 0x8007043c).

Error: (12/12/2016 10:38:04 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Vytvoření bodu obnovení na svazku se nezdařilo (Proces = C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exe Files\VS Revo Group\Revo Uninstaller\RevoUnin.exe" ; Popis = Revo Uninstaller's restore point - McAfee Security Scan Plus; Hr = 0x8007043c).

Error: (12/12/2016 10:36:28 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Vytvoření bodu obnovení na svazku se nezdařilo (Proces = C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exe Files\VS Revo Group\Revo Uninstaller\RevoUnin.exe" ; Popis = Revo Uninstaller's restore point - CrystalDiskInfo 7.0.4; Hr = 0x8007043c).

Error: (12/12/2016 10:34:39 PM) (Source: EventSystem) (EventID: 4609) (User: )
Description: Systém událostí modelu COM+ zjistil při vnitřním zpracování chybný návratový kód. Hodnota HRESULT byla 8007043c z řádku 45 z d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp. Obraťte se na podporu produktů společnosti Microsoft a informujte je o této chybě.


System errors:
=============
Error: (12/13/2016 09:04:01 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Zavedení následujícího ovladače pro spouštění počítače nebo systému se nezdařilo: 
ESProtectionDriver

Error: (12/13/2016 09:03:58 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Služba Hostitel zařízení UPnP závisí na službě SSDP Discovery, která neuspěla při spuštění v důsledku následující chyby: 
Zvolenou službu nelze spustit, protože není povolena nebo s ní není spojeno žádné povolené zařízení.

Error: (12/13/2016 09:03:58 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Ricoh xD-Picture Card Driver neuspěla při spuštění v důsledku následující chyby: 
Zvolenou službu nelze spustit, protože není povolena nebo s ní není spojeno žádné povolené zařízení.

Error: (12/13/2016 09:03:58 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba rimsptsk neuspěla při spuštění v důsledku následující chyby: 
Zvolenou službu nelze spustit, protože není povolena nebo s ní není spojeno žádné povolené zařízení.

Error: (12/13/2016 09:03:58 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba rimmptsk neuspěla při spuštění v důsledku následující chyby: 
Zvolenou službu nelze spustit, protože není povolena nebo s ní není spojeno žádné povolené zařízení.

Error: (12/12/2016 11:00:13 PM) (Source: Print) (EventID: 19) (User: NT AUTHORITY)
Description: Nasdílení tiskárny 10x15 glossy s názvem sdíleného prostředku 10x15 glossy se pomocí služby zařazování tisku nezdařilo. Chyba 2114. Danou tiskárnu nemohou používat další uživatelé v síti.

Error: (12/12/2016 11:00:13 PM) (Source: Print) (EventID: 19) (User: NT AUTHORITY)
Description: Nasdílení tiskárny 10x15 matt s názvem sdíleného prostředku 10x15 matt se pomocí služby zařazování tisku nezdařilo. Chyba 2114. Danou tiskárnu nemohou používat další uživatelé v síti.

Error: (12/12/2016 11:00:13 PM) (Source: Print) (EventID: 19) (User: NT AUTHORITY)
Description: Nasdílení tiskárny 13x18 glossy s názvem sdíleného prostředku 13x18 glossy se pomocí služby zařazování tisku nezdařilo. Chyba 2114. Danou tiskárnu nemohou používat další uživatelé v síti.

Error: (12/12/2016 11:00:13 PM) (Source: Print) (EventID: 19) (User: NT AUTHORITY)
Description: Nasdílení tiskárny 13x18 matt s názvem sdíleného prostředku 13x18 matt se pomocí služby zařazování tisku nezdařilo. Chyba 2114. Danou tiskárnu nemohou používat další uživatelé v síti.

Error: (12/12/2016 11:00:13 PM) (Source: Print) (EventID: 19) (User: NT AUTHORITY)
Description: Nasdílení tiskárny 15x23 glossy s názvem sdíleného prostředku 15x23 glossy se pomocí služby zařazování tisku nezdařilo. Chyba 2114. Danou tiskárnu nemohou používat další uživatelé v síti.


CodeIntegrity:
===================================
  Date: 2016-12-12 22:47:49.761
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

  Date: 2016-12-12 22:47:48.123
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

  Date: 2016-12-12 22:47:46.703
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

  Date: 2016-12-12 22:47:45.346
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

  Date: 2016-12-12 22:47:43.911
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\MBAMChameleon.sys because the set of per-page image hashes could not be found on the system.

  Date: 2016-12-12 22:47:42.507
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\MBAMChameleon.sys because the set of per-page image hashes could not be found on the system.

  Date: 2016-12-12 22:47:41.040
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\MBAMChameleon.sys because the set of per-page image hashes could not be found on the system.

  Date: 2016-12-12 22:47:39.402
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\MBAMChameleon.sys because the set of per-page image hashes could not be found on the system.

  Date: 2016-12-11 16:50:37.133
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

  Date: 2016-12-11 16:50:35.324
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.


==================== Memory info =========================== 

Processor: Intel(R) Pentium(R) Dual CPU T2370 @ 1.73GHz
Percentage of memory in use: 79%
Total physical RAM: 2038.48 MB
Available physical RAM: 414.24 MB
Total Virtual: 4979.52 MB
Available Virtual: 3185.7 MB

==================== Drives ================================

Drive c: (Vista) (Fixed) (Total:93.15 GB) (Free:14.45 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive e: (Data) (Fixed) (Total:91.69 GB) (Free:9.17 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 186.3 GB) (Disk ID: DE0D12FD)
Partition 1: (Not Active) - (Size=1.5 GB) - (Type=27)
Partition 2: (Active) - (Size=93.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=91.7 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================