Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24-05-2017
Ran by CZC (27-05-2017 14:46:52)
Running from C:\Users\CZC\Downloads
Windows 10 Home Version 1703 (X64) (2017-05-25 19:55:22)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3441746054-1229345982-1929768044-500 - Administrator - Disabled)
CZC (S-1-5-21-3441746054-1229345982-1929768044-1001 - Administrator - Enabled) => C:\Users\CZC
DefaultAccount (S-1-5-21-3441746054-1229345982-1929768044-503 - Limited - Disabled)
Guest (S-1-5-21-3441746054-1229345982-1929768044-501 - Limited - Disabled)
Ivanka (S-1-5-21-3441746054-1229345982-1929768044-1002 - Administrator - Enabled) => C:\Users\Ivanka

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avast Antivirus (Disabled - Out of date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Disabled - Out of date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

. . (Version: 7.1 - Intel) Hidden
. . . (x32 Version: 2.8.0.7 - Intel) Hidden
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 17.4.2294 - AVAST Software)
BitTorrent (HKU\S-1-5-21-3441746054-1229345982-1929768044-1001\...\BitTorrent) (Version: 7.10.0.43581 - BitTorrent Inc.)
Creative ALchemy (HKLM-x32\...\ALchemy) (Version: 1.43 - Creative Technology Limited)
Creative Audio Control Panel (HKLM-x32\...\AudioCS) (Version: 3.00 - Creative Technology Limited)
Creative Entertainment Console (HKLM-x32\...\Entertainment Console) (Version: 3.00 - Creative Technology Limited)
Creative Software AutoUpdate (HKLM-x32\...\Creative Software AutoUpdate) (Version: 1.40 - Creative Technology Limited)
Creative Sound Blaster Properties x64 Edition (HKLM-x32\...\Creative Sound Blaster Properties x64 Edition) (Version: 1.03 - Creative Technology Limited)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 58.0.3029.110 - Google Inc.)
Google Update Helper (x32 Version: 1.3.21.123 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.33.5 - Google Inc.) Hidden
Intel® Driver Update Utility (HKLM-x32\...\{b480f6cc-fa56-482b-b0a3-49d69a32db6d}) (Version: 2.8.0.7 - Intel)
KMPlayer (remove only) (HKLM-x32\...\The KMPlayer) (Version: 4.2.1.2 - PandoraTV)
Microsoft OneDrive (HKU\S-1-5-21-3441746054-1229345982-1929768044-1001\...\OneDriveSetup.exe) (Version: 17.3.6816.0313 - Microsoft Corporation)
Ovládací panel NVIDIA 378.78 (Version: 378.78 - NVIDIA Corporation) Hidden
SafeZone Stable 3.55.2393.596 (x32 Version: 3.55.2393.596 - Avast Software) Hidden
Transmission 2.92 (14714) (x64) (HKLM\...\{E2B281FA-6236-4F0D-B710-ECDB6B60EB5E}) (Version: 2.92.0 - Transmission Project)
Volume Panel (HKLM-x32\...\Creative Volume Panel) (Version: 2.21 - Creative Technology Limited)
WinRAR 5.40 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {14F7C753-72D4-406E-9EB4-D83370204BE2} - System32\Tasks\SafeZone scheduled Autoupdate 1495787694 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2017-03-22] (Avast Software)
Task: {5084BDD2-FEEB-4315-8AE6-63C497E31926} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => Wscript.exe //B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\task.vbs"
Task: {75163550-1358-451A-A13B-69916855E481} - System32\Tasks\Intel\Intel Telemetry 2 => C:\Program Files\Intel\Telemetry 2.0\lrio.exe [2016-03-17] (Intel Corporation)
Task: {9405D476-7868-4677-853E-2C612AFFA7A1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-05-26] (Google Inc.)
Task: {9CAED742-8B94-4028-97F3-A19B77188B6C} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-05-26] (AVAST Software)
Task: {FB32640E-7B07-48CE-9D41-A36A507EBA8F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-05-26] (Google Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2017-03-07 19:04 - 2017-03-07 19:04 - 00157456 _____ () C:\Program Files\Intel Driver Update Utility\SUR\SurSvc.exe
2017-05-25 21:46 - 2017-02-23 10:28 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2017-03-18 22:58 - 2017-03-18 22:58 - 00138000 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
2017-03-18 22:59 - 2017-03-20 06:45 - 01731072 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-05-26 06:21 - 2017-05-26 06:21 - 00074752 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.16.595.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2017-05-26 06:21 - 2017-05-26 06:21 - 00201728 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.16.595.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2017-05-26 06:21 - 2017-05-26 06:21 - 43202048 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.16.595.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2017-05-26 06:21 - 2017-05-26 06:21 - 02442752 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.16.595.0_x64__kzf8qxf38zg5c\skypert.dll
2017-05-26 10:31 - 2017-05-26 10:31 - 00170216 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2017-05-26 10:31 - 2017-05-26 10:31 - 00997896 _____ () C:\Program Files\AVAST Software\Avast\AvChrome.dll
2017-05-26 10:31 - 2017-05-26 10:31 - 67717632 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2017-05-26 10:31 - 2017-05-26 10:31 - 00176992 _____ () C:\Program Files\AVAST Software\Avast\event_routing_rpc.dll
2017-05-26 10:31 - 2017-05-26 10:31 - 00223224 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll
2017-05-26 10:31 - 2017-05-26 10:31 - 00291824 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll
2017-05-26 10:31 - 2017-05-26 10:31 - 00684656 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2017-05-26 10:34 - 2017-05-09 10:12 - 02864984 _____ () C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\libglesv2.dll
2017-05-26 10:34 - 2017-05-09 10:12 - 00087384 _____ () C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\libegl.dll
2016-01-29 10:04 - 2016-01-29 10:04 - 00151040 _____ () C:\KMPlayer\LibRealSenseKMP.dll
2017-04-18 06:47 - 2017-04-18 06:47 - 00274432 _____ () C:\KMPlayer\Core\libbluray.dll
2016-01-29 10:04 - 2016-01-29 10:04 - 00538112 _____ () C:\KMPlayer\libmplay.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2017-05-25 22:34 - 2017-05-25 22:31 - 00000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3441746054-1229345982-1929768044-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\CZC\Desktop\Karlos - záloha\Pictures\wallpapers ruzny\GraffitiWallpapers.jpg
DNS Servers: 109.202.72.93 - 109.202.73.93
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{00C5A152-003C-435E-8A94-BCD09E82871C}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{6C424F63-A5ED-4623-ACE7-F7396280B54B}] => (Allow) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.596\SZBrowser.exe
FirewallRules: [{3E0ED4F9-BF0A-4769-A7A5-E424F3A83CF4}] => (Allow) C:\Users\CZC\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{3A721C09-5541-4F56-83B9-FC26D18FAE7E}] => (Allow) C:\Users\CZC\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{D30593E0-FF6C-4102-A4D2-0D120ABFAF16}] => (Allow) C:\Users\CZC\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{25CC0F06-07D5-4A86-A7B9-CEE208237CCF}] => (Allow) C:\Users\CZC\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{366C2E66-0089-4A5D-BD30-3F011DC6F4AA}] => (Allow) C:\Users\CZC\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{81084F1F-B40B-4AB0-BB27-13CDB9953122}] => (Allow) C:\Users\CZC\AppData\Roaming\BitTorrent\BitTorrent.exe

==================== Restore Points =========================

26-05-2017 14:04:29 Windows Update
26-05-2017 14:04:55 Windows Update

==================== Faulty Device Manager Devices =============

Name: Intel(R) Management Engine Interface 
Description: Intel(R) Management Engine Interface 
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: Intel
Service: MEIx64
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (05/27/2017 06:24:30 AM) (Source: SideBySide) (EventID: 75) (User: )
Description: Selhalo generování kontextu aktivace pro: C:\Program Files (x86)\Creative\Audio Device Selection Unicode\CTAudSeu.exe. Chyba v souboru manifestu nebo zásad C:\Program Files (x86)\Creative\Audio Device Selection Unicode\CTAudSeu.exe na řádku 2.
V manifestu není povoleno více prvků requestedPrivileges.

Error: (05/26/2017 10:30:42 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: CoolerMaster)
Description: Aplikaci Microsoft.Windows.Photos_8wekyb3d8bbwe!App se nepovedlo aktivovat, protože došlo k chybě: -2147023170. Další informace najdete v protokolu Microsoft-Windows-TWinUI/Operational.

Error: (05/26/2017 10:03:20 PM) (Source: SideBySide) (EventID: 75) (User: )
Description: Selhalo generování kontextu aktivace pro: C:\Program Files (x86)\Creative\Audio Device Selection Unicode\CTAudSeu.exe. Chyba v souboru manifestu nebo zásad C:\Program Files (x86)\Creative\Audio Device Selection Unicode\CTAudSeu.exe na řádku 2.
V manifestu není povoleno více prvků requestedPrivileges.

Error: (05/26/2017 10:03:07 PM) (Source: SideBySide) (EventID: 75) (User: )
Description: Selhalo generování kontextu aktivace pro: C:\Program Files (x86)\Creative\Audio Device Selection Unicode\CTAudSeu.exe. Chyba v souboru manifestu nebo zásad C:\Program Files (x86)\Creative\Audio Device Selection Unicode\CTAudSeu.exe na řádku 2.
V manifestu není povoleno více prvků requestedPrivileges.

Error: (05/26/2017 02:50:38 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: CoolerMaster)
Description: Aplikaci Microsoft.BingWeather_8wekyb3d8bbwe!App se nepovedlo aktivovat, protože došlo k chybě: -2144927148. Další informace najdete v protokolu Microsoft-Windows-TWinUI/Operational.

Error: (05/26/2017 02:15:38 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: CoolerMaster)
Description: Aplikaci Microsoft.BingWeather_8wekyb3d8bbwe!App se nepovedlo aktivovat, protože došlo k chybě: -2144927148. Další informace najdete v protokolu Microsoft-Windows-TWinUI/Operational.

Error: (05/26/2017 11:31:32 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: CoolerMaster)
Description: Balíček Microsoft.MicrosoftEdge_40.15063.0.0_neutral__8wekyb3d8bbwe+ContentProcess#{00031401-0001-0000-b153-ea0200000000} se ukončil, protože jeho pozastavování trvalo moc dlouho.

Error: (05/26/2017 11:21:24 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: CoolerMaster)
Description: Aplikaci Microsoft.BingWeather_8wekyb3d8bbwe!App se nepovedlo aktivovat, protože došlo k chybě: -2144927148. Další informace najdete v protokolu Microsoft-Windows-TWinUI/Operational.

Error: (05/26/2017 10:56:24 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: CoolerMaster)
Description: Aplikaci Microsoft.BingWeather_8wekyb3d8bbwe!App se nepovedlo aktivovat, protože došlo k chybě: -2144927148. Další informace najdete v protokolu Microsoft-Windows-TWinUI/Operational.

Error: (05/26/2017 10:46:36 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny QueryFullProcessImageNameW došlo k neočekávané chybě. hr= 0x80070006, Neplatný popisovač.
.


Operace:
   Spouštění asynchronní operace

Kontext:
   Aktuální stav: DoSnapshotSet


System errors:
=============
Error: (05/27/2017 01:08:32 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 a APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (05/27/2017 10:12:09 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4

Error: (05/27/2017 09:35:03 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 a APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (05/27/2017 07:18:45 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4

Error: (05/26/2017 09:54:56 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba CldFlt neuspěla při spuštění v důsledku následující chyby: 
Požadavek není podporován.

Error: (05/26/2017 08:43:43 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 a APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (05/26/2017 08:43:04 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby Hostitel synchronizace_119214 bylo dosaženo časového limitu (30000 ms).

Error: (05/26/2017 08:43:03 PM) (Source: DCOM) (EventID: 10010) (User: CoolerMaster)
Description: Server {260EB9DE-5CBE-4BFF-A99A-3710AF55BF1E} se v daném časovém limitu neregistroval u služby DCOM.

Error: (05/26/2017 08:40:26 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba SystemUsageReportSvc_QUEENCREEK neuspěla při spuštění v důsledku následující chyby: 
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.

Error: (05/26/2017 08:40:26 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby SystemUsageReportSvc_QUEENCREEK bylo dosaženo časového limitu (30000 ms).


==================== Memory info =========================== 

Processor: Intel(R) Core(TM) i5-3350P CPU @ 3.10GHz
Percentage of memory in use: 68%
Total physical RAM: 4043.58 MB
Available physical RAM: 1268.65 MB
Total Virtual: 5451.58 MB
Available Virtual: 1609.92 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:930.73 GB) (Free:534.2 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 7E7A3354)
Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=930.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)

==================== End of Addition.txt ============================