Stránka 1 z 1

Prosím o kontrolu

Napsal: 23 kvě 2015 09:14
od georgdj
Dobrý den,
prosím o kontrolu. Přes mbam jsem spustil kontrolu. nalezen Trojan Bitcoinminer C:\Windows\Temp\svchost.exe.
Využívá procesor na 100%. I po odstranění a restartu opět ve správci souboru prázdný proces, který využívá 100% proces.
Neumím se toho žebráka zbavit. Moc děkuji za pomoc.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:11:45, on 23. 5. 2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.16442)
Boot mode: Normal

Running processes:
C:\Windows\system32\PrintDisp.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\RocketDock\RocketDock.exe
C:\Program Files (x86)\Software602\Print2PDF\Print2PDF.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Jirka\Desktop\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll
O3 - Toolbar: Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O4 - HKLM\..\Run: [BigDog305] C:\Windows\VM305_STI.EXE A4 TECH PC Camera V
O4 - HKLM\..\Run: [Print2PDF Print Monitor] "C:\Program Files (x86)\Software602\Print2PDF\Print2PDF.exe" /server
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [iSkysoft Helper Compact.exe] C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe
O4 - HKLM\..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files (x86)\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Jirka\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-21-626980440-2269883898-3179777769-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [RocketDock] "C:\Program Files (x86)\RocketDock\RocketDock.exe" (User '?')
O4 - HKUS\S-1-5-21-626980440-2269883898-3179777769-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [Google Update] "C:\Users\Jirka\AppData\Local\Google\Update\GoogleUpdate.exe" /c (User '?')
O4 - S-1-5-21-626980440-2269883898-3179777769-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 Startup: Sidebar.lnk = C:\Program Files\Windows Sidebar\sidebar.exe (User '?')
O4 - Startup: Sidebar.lnk = C:\Program Files\Windows Sidebar\sidebar.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe
O9 - Extra 'Tools' menuitem: Classic IE Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: 602Updater (602XML Updater) - Software602 a.s. - C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: Printer Control - Unknown owner - C:\Windows\system32\PrintCtrl.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TeamViewer 10 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

Re: Prosím o kontrolu

Napsal: 23 kvě 2015 09:31
od georgdj
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-05-2015 01
Ran by Jirka at 2015-05-23 10:29:52
Running from C:\Users\Jirka\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-626980440-2269883898-3179777769-500 - Administrator - Disabled)
Guest (S-1-5-21-626980440-2269883898-3179777769-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-626980440-2269883898-3179777769-1003 - Limited - Enabled)
Jirka (S-1-5-21-626980440-2269883898-3179777769-1001 - Administrator - Enabled) => C:\Users\Jirka

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

«Need for Speed - Most Wanted» 1.5 (HKLM-x32\...\{FB0127F3-985B-44CE-AE29-378CAF60B361}_is1) (Version: 1.5 - Electronic Arts)
µTorrent (HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\uTorrent) (Version: 3.4.2.35702 - BitTorrent Inc.)
7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - )
8GadgetPack (HKLM-x32\...\{F7EF899D-0339-4279-8FB1-96801D829A3F}) (Version: 8.0.1 - Helmut Buhler)
A4 TECH PC Camera V (HKLM-x32\...\{8AD824A5-1CCC-4BB7-82C9-E6FB25CC0479}) (Version: 2007.07.30 - A4)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.7.0.1530 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.188 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.08) - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated)
Age Of Empires II HD v2.5 [LAN Edition] (HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\Age Of Empires II HD v2.5 [LAN Edition]) (Version: - )
Aktualizace NVIDIA 15.3.33 (Version: 15.3.33 - NVIDIA Corporation) Hidden
AVI to 3GP (HKLM-x32\...\{AE4E8D53-2D05-4EB4-A1E7-FF48B8E76DDE}_is1) (Version: - www.avito3gp.com)
BS.Player FREE (HKLM-x32\...\BSPlayerf) (Version: 2.66.1075 - AB Team, d.o.o.)
CCleaner (HKLM\...\CCleaner) (Version: 4.17 - Piriform)
CDex - Open Source Digital Audio CD Extractor (HKLM-x32\...\CDex) (Version: 1.70.4.2009 - Georgy Berdyshev)
Classic Shell (HKLM\...\{840C85B7-D3D6-4143-9AF9-DAE80FD54CFC}) (Version: 4.1.0 - IvoSoft)
Čeština pro GTA IV v1.0.7.0 1.0.7.0 (HKLM-x32\...\Čeština pro GTA IV v1.0.7.0 1.0.7.0) (Version: - )
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.47.1.0333 - Disc Soft Ltd)
Google Earth (HKLM-x32\...\{96AD3B61-EAE2-11E2-9E72-B8AC6F98CCE3}) (Version: 7.1.1.1888 - Google)
Google Chrome (HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\Google Chrome) (Version: 42.0.2311.152 - Google Inc.)
Grand Theft Auto IV (HKLM-x32\...\{579BA58C-F33D-4970-9953-B94B43768AC3}) (Version: 1.00.0000 - Rockstar Games)
Grand Theft Auto IV (x32 Version: 1.0.0013.131 - Rockstar Games Inc.) Hidden
HTC BMP USB Driver (HKLM-x32\...\{31A559C1-9E4D-423B-9DD3-34A6C5398752}) (Version: 1.0.5375 - HTC)
HTC Driver Installer (HKLM-x32\...\{4CEEE5D0-F905-4688-B9F9-ECC710507796}) (Version: 4.1.0.001 - HTC Corporation)
HTC Sync (HKLM-x32\...\{C4494248-6D52-4674-B8CF-9177EA3F92F8}) (Version: 3.3.53 - HTC Corporation)
Infix PDF Editor verze 6.1.9.0 (HKLM-x32\...\83FFB914-6FA7-4F1F-807E-E0FFBA2E49E1_is1) (Version: 6.1.9.0 - Iceni Technology)
Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217040FF}) (Version: 7.0.510 - Oracle)
K-Lite Mega Codec Pack 10.4.0 (HKLM-x32\...\KLiteCodecPack_is1) (Version: 10.4.0 - )
Malwarebytes Anti-Malware verze 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
MegaTrainer eXperience V1.1.5.3 (HKLM-x32\...\MegaTrainer eXperience_is1) (Version: - )
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x64 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
MiniTool Partition Wizard Home Edition 8.1.1 (HKLM-x32\...\{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1) (Version: - MiniTool Solution Ltd.)
Mozilla Firefox 37.0.2 (x86 cs) (HKLM-x32\...\Mozilla Firefox 37.0.2 (x86 cs)) (Version: 37.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 35.0.1 - Mozilla)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
Nero 8 (HKLM-x32\...\{6D45EF03-E8EE-4355-81C3-F918CBCF1029}) (Version: 8.3.309 - Nero AG)
NVIDIA GeForce Experience 2.1.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.1 - NVIDIA Corporation)
NVIDIA Ovladač 3D Vision 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 340.52 - NVIDIA Corporation)
NVIDIA Ovladač řídící jednotky 3D Vision 340.50 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 340.50 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 340.52 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.4.11.2806 - Electronic Arts, Inc.)
Ovládací panel NVIDIA 340.52 (Version: 340.52 - NVIDIA Corporation) Hidden
Ovladače videa společnosti Pinnacle (HKLM\...\{6DE721A5-5E89-4D74-994C-652BB3C0672E}) (Version: 12.1.0.030 - Pinnacle Systems)
Pinnacle Studio 15 (HKLM-x32\...\{1362E602-9625-42D3-B57F-CDA9D26F9DA8}) (Version: 15.0.0.7593 - Pinnacle Systems)
Pinnacle Studio 15 Ultimate Plugins (HKLM-x32\...\{EB5DF19E-75D5-4FF1-AE23-2A9A2E0F2BDD}) (Version: 15.0.0.7593 - Pinnacle Systems)
Pinnacle Studio Bonus Content (HKLM-x32\...\{FC030CB5-46A6-4229-AD6E-0AC869F509C8}) (Version: 15.0.0.51 - Pinnacle Systems)
ProgDVB (HKLM-x32\...\ProgDVB) (Version: 6.9x - Prog)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0024 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5694 - Realtek Semiconductor Corp.)
RocketDock 1.3.5 (HKLM-x32\...\RocketDock_is1) (Version: - Punk Software)
Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.3.14044_17 - Samsung Electronics Co., Ltd.)
Samsung Kies (x32 Version: 2.6.3.14044_17 - Samsung Electronics Co., Ltd.) Hidden
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.14083.17 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (x32 Version: 3.2.14083.17 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.45.0 - SAMSUNG Electronics Co., Ltd.)
SHIELD Streaming (Version: 3.1.100 - NVIDIA Corporation) Hidden
Sim Aquarium 3 (HKLM-x32\...\Sim Aquarium 3_is1) (Version: 3 - Ladislav Vojnic)
SimCity™ (HKLM-x32\...\{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}) (Version: 1.0.0.0 - Electronic Arts)
Skype™ 6.22 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.22.107 - Skype Technologies S.A.)
Software602 Print2PDF (HKLM-x32\...\{32C74893-0243-4235-A6F3-201F0E5D2C03}) (Version: 9.1.11.0421 - Software602 a.s.)
Subtitle Workshop 2.51 (HKLM-x32\...\SubtitleWorkshop) (Version: - )
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.36897 - TeamViewer)
The Settlers 7 - Paths to a Kingdom (HKLM-x32\...\{63860309-DA8A-4BAE-9EAE-CE1D6D79340C}) (Version: 1.12.1396 - Ubisoft)
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
USB PC Camera VC305 (HKLM-x32\...\{ADE16A9D-FBDC-4ECC-B6BD-9C31E51D0305}) (Version: - )
VCRedistSetup (x32 Version: 1.0.0 - Nero AG) Hidden
VirtualDJ 8 (HKLM-x32\...\{9ADBBA93-4625-4898-BB0D-BCE7EA9F8B4A}) (Version: 8.0.0 - Atomix Productions)
VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN)
Winamp (HKLM-x32\...\Winamp) (Version: 5.65 - Nullsoft, Inc)
Winamp Detector Plug-in (HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc)
WinRAR (HKLM-x32\...\WinRAR archiver) (Version: - )
World of Tanks (HKLM-x32\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812EU}_is1) (Version: - Wargaming.net)
Yawcam 0.4.1 (HKLM-x32\...\{8FE96B14-E1F9-47BF-8BA1-A81467CD259B}_is1) (Version: - )
Základní software zařízení HP Photosmart 5510 series (HKLM\...\{22E8B03A-9094-45AC-910A-CB491A16A593}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
Zoo Tycoon 2 (HKLM-x32\...\Zoo Tycoon 2) (Version: 1.0 - Microsoft)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-626980440-2269883898-3179777769-1001_Classes\CLSID\{0E7BE950-4ACC-47CB-834B-41A8B96BBFF9}\InprocServer32 -> C:\Users\Jirka\AppData\Local\Microsoft\Windows Sidebar\Gadgets\Sidebar7.gadget\Release\Sidebar7.64.dll (Helmut Buhler)
CustomCLSID: HKU\S-1-5-21-626980440-2269883898-3179777769-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Jirka\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-626980440-2269883898-3179777769-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Jirka\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-626980440-2269883898-3179777769-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Jirka\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-626980440-2269883898-3179777769-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Jirka\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-626980440-2269883898-3179777769-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Jirka\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll (Google Inc.)

==================== Restore Points =========================


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2012-07-26 07:26 - 2014-03-16 09:58 - 00001487 ___RA C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 csc3-2010-crl.verisign.com
127.0.0.1 ocsp.verisign.com
127.0.0.1 crl.verisign.com
127.0.0.1 download.dm.origin.com
127.0.0.1 secure.download.dm.origin.com
127.0.0.1 loginregistration.dm.origin.com
127.0.0.1 achievements.gameservices.ea.com
127.0.0.1 friends.dm.origin.com
127.0.0.1 avatar.dm.origin.com
127.0.0.1 ecommerce.dm.origin.com
127.0.0.1 static.cdn.ea.com
127.0.0.1 tealium.hs.llnwd.net
127.0.0.1 heartbeat.dm.origin.com
127.0.0.1 web.dm.origin.com
127.0.0.1 store.origin.com
127.0.0.1 ec2-54-243-231-82.compute-1.amazonaws.com
127.0.0.1 eaassets-a.akamaihd.net
127.0.0.1 ssl.resources.ea.com
127.0.0.1 akamai.cdn.ea.com
127.0.0.1 novafusion.ea.com
127.0.0.1 proxy.novafusion.ea.com
127.0.0.1 ec2-23-23-167-200.compute-1.amazonaws.com
127.0.0.1 dirtybits.dm.origin.com
127.0.0.1 chat.dm.origin.com
127.0.0.1 easo.ea.com
127.0.0.1 ea.com
127.0.0.1 telemetry.simcity.com
127.0.0.1 ec2-54-228-227-181.eu-west-1.compute.amazonaws.com
127.0.0.1 ec2-46-137-177-16.eu-west-1.compute.amazonaws.com

There are 11 more lines.


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {274C4ACC-4C68-4B79-96FB-DBC72939416B} - System32\Tasks\{07B84F4C-CD57-43A9-973D-C2ECF6F666EE} => pcalua.exe -a C:\Total\TOTALCMD.EXE -d C:\Total
Task: {582EED7A-8124-4EE3-BACE-0A2CABF192F3} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-626980440-2269883898-3179777769-1001UA => C:\Users\Jirka\AppData\Local\Google\Update\GoogleUpdate.exe [2014-01-12] (Google Inc.)
Task: {84CB3F3D-DFE3-46FC-A95F-118799FBE939} - System32\Tasks\Origin => C:\Windows\system32\config\systemprofile\AppData\Roaming\Origin\update.vbe [2014-09-09] () <==== ATTENTION
Task: {AC9CFF55-378D-4935-96CE-5983BEC13C54} - System32\Tasks\Launch HTC Sync Loader => C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe [2013-05-13] ()
Task: {BBE1F1A9-799E-49EE-963A-4449E032F8FB} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-08-21] (Piriform Ltd)
Task: {D42C0BE9-E143-4EDA-98FD-1FACA0B1026B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-05-23] (Adobe Systems Incorporated)
Task: {ECF4923D-604E-4481-859F-8294B4DA71F9} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\WatTask => C:\Windows Activation Technologies\wat.exe [2006-04-21] ()
Task: {FBB5091E-F657-4CF5-A162-B10C1302A352} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-626980440-2269883898-3179777769-1001Core => C:\Users\Jirka\AppData\Local\Google\Update\GoogleUpdate.exe [2014-01-12] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-626980440-2269883898-3179777769-1001Core.job => C:\Users\Jirka\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-626980440-2269883898-3179777769-1001UA.job => C:\Users\Jirka\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2013-09-16 17:36 - 2014-07-02 20:55 - 00116568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2014-06-02 20:14 - 2010-12-02 02:13 - 00216576 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\Software602.dll
2013-09-16 18:30 - 2007-09-02 13:58 - 00495616 _____ () C:\Program Files (x86)\RocketDock\RocketDock.exe
2015-05-23 10:08 - 2015-05-23 10:08 - 01563136 _____ () C:\Windows\Temp\svchost.exe
2015-05-23 10:25 - 2015-05-23 10:25 - 02223104 _____ () C:\Users\Jirka\Desktop\adwcleaner_4.205.exe
2013-09-16 18:30 - 2007-09-02 13:57 - 00069632 _____ () C:\Program Files (x86)\RocketDock\RocketDock.dll
2014-06-02 20:00 - 2008-09-29 13:09 - 00073728 _____ () C:\Program Files (x86)\Software602\Print2PDF\wcs.dll
2014-06-02 20:00 - 2008-09-29 13:09 - 00532480 _____ () C:\Program Files (x86)\Software602\Print2PDF\wc.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-626980440-2269883898-3179777769-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 109.231.191.1 - 109.231.191.3

==================== MSCONFIG/TASK MANAGER Error getting ==

(Currently there is no automatic fix for this section.)

HKLM\...\StartupApproved\Run: => "PrintDisp"
HKLM\...\StartupApproved\Run: => "ShadowPlay"
HKLM\...\StartupApproved\Run32: => "KiesTrayAgent"
HKLM\...\StartupApproved\Run32: => "BigDog305"
HKLM\...\StartupApproved\Run32: => "NBKeyScan"
HKLM\...\StartupApproved\Run32: => "Adobe ARM"
HKLM\...\StartupApproved\Run32: => "iSkysoft Helper Compact.exe"
HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\StartupApproved\Run: => "KiesPreload"
HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\StartupApproved\Run: => ""
HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\StartupApproved\Run: => "KiesAirMessage"
HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\StartupApproved\Run: => "RGSC"
HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\StartupApproved\Run: => "EADM"
HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\StartupApproved\Run: => "Google Update"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppextcomobj.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppextcomobj.exe
FirewallRules: [{C650D07D-01B2-4E26-9901-E4D9C3EFE038}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{9D7711BD-AC92-4088-B379-217C028E043A}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{F5FE90EF-A115-423B-AE84-C8368966C6DA}] => (Allow) C:\Program Files\HP\HP Photosmart 5510 series\Bin\DeviceSetup.exe
FirewallRules: [{92C0380E-7952-4D49-8A61-3A81883E139B}] => (Allow) C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{0F790692-5876-42BB-8282-D9E936BC3FB4}] => (Allow) C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{E7E8E5E7-7431-4E72-AB6A-90D8F2E76544}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [TCP Query User{6094047A-9F05-4FAF-A2F8-F0957FD7883B}E:\torrenty\simcity\start.exe] => (Allow) E:\torrenty\simcity\start.exe
FirewallRules: [UDP Query User{6084B9EB-54DD-429E-9D9A-F2433DEBD753}E:\torrenty\simcity\start.exe] => (Allow) E:\torrenty\simcity\start.exe
FirewallRules: [TCP Query User{992F9C28-DC10-4C01-AA75-1F40E16A61F0}E:\torrenty\simcity\apache\httpd.exe] => (Allow) E:\torrenty\simcity\apache\httpd.exe
FirewallRules: [UDP Query User{37B559C1-B5A1-4DF4-859C-5057C4595DD1}E:\torrenty\simcity\apache\httpd.exe] => (Allow) E:\torrenty\simcity\apache\httpd.exe
FirewallRules: [TCP Query User{7FA4D68A-CE4E-45F4-9FCC-359EC1AB05E2}D:\games\world of tanks\wotlauncher.exe] => (Allow) D:\games\world of tanks\wotlauncher.exe
FirewallRules: [UDP Query User{EF6FE8AB-FF60-499B-886B-4FE62AB9F165}D:\games\world of tanks\wotlauncher.exe] => (Allow) D:\games\world of tanks\wotlauncher.exe
FirewallRules: [TCP Query User{78BB2AE3-FFC8-4AC3-9F50-75DD779799C5}D:\games\world of tanks\worldoftanks.exe] => (Allow) D:\games\world of tanks\worldoftanks.exe
FirewallRules: [UDP Query User{58B8E915-BE5A-4F96-B616-A7D1657BB294}D:\games\world of tanks\worldoftanks.exe] => (Allow) D:\games\world of tanks\worldoftanks.exe
FirewallRules: [{48CD59E3-084E-4DE8-8C35-871394650FA6}] => (Allow) C:\Users\Jirka\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{EBF964D7-DC5F-417E-B2B1-C9E695D968D2}] => (Allow) C:\Users\Jirka\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [TCP Query User{1F9B9B21-50D0-4B23-BD1F-5D5576BE72BE}D:\games\age of empires\game.dat] => (Allow) D:\games\age of empires\game.dat
FirewallRules: [UDP Query User{87EB7865-64C5-4185-9B84-456DD5902D36}D:\games\age of empires\game.dat] => (Allow) D:\games\age of empires\game.dat
FirewallRules: [TCP Query User{010C12F4-07F5-4B03-8F06-7EA9F81629E0}C:\program files (x86)\virtualdj\virtualdj_pro.exe] => (Block) C:\program files (x86)\virtualdj\virtualdj_pro.exe
FirewallRules: [UDP Query User{AB8E0E09-B00E-46F4-AD4E-C1E942B2CD56}C:\program files (x86)\virtualdj\virtualdj_pro.exe] => (Block) C:\program files (x86)\virtualdj\virtualdj_pro.exe
FirewallRules: [{8DC7E677-2880-430F-87E9-05E9144232F1}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 15\Programs\RM.exe
FirewallRules: [{15F6194E-D1E6-46A8-837D-9BF35352D18B}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 15\Programs\RM.exe
FirewallRules: [{AF7655DA-A122-4A75-86CB-C2A7A333AAE5}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 15\Programs\Studio.exe
FirewallRules: [{67DCED7B-6167-4F6C-8BD7-4246665101E5}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 15\Programs\Studio.exe
FirewallRules: [{7D3C3CF4-0EF9-41A5-A914-C1D9C3D66C90}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 15\Programs\umi.exe
FirewallRules: [{5B82AB0C-8FC1-4F21-B50C-57E6251E6C1D}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 15\Programs\umi.exe
FirewallRules: [{2324CF8B-0BCB-43F4-81BB-45F398E60A1B}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{1F1D04F2-CDE6-48F8-A503-82A79248D351}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{852AC0AC-3985-4807-A18B-0732DBDDA667}] => (Allow) D:\Games\Settlers 7 Gold\Data\Base\_Dbg\Bin\Release\Settlers7R.exe
FirewallRules: [{1A970232-011F-450A-87CB-BC15634C091D}] => (Allow) D:\Games\Settlers 7 Gold\Data\Base\_Dbg\Bin\Release\Settlers7R.exe
FirewallRules: [{3DE4E709-AC82-45FB-850B-1D2DACBF6E16}] => (Allow) D:\Games\RockstarGames\Grand Theft Auto IV\LaunchGTAIV.exe
FirewallRules: [{B12824A7-36AB-45D5-8DB2-DDA4B5A59B8F}] => (Allow) D:\Games\RockstarGames\Grand Theft Auto IV\LaunchGTAIV.exe
FirewallRules: [TCP Query User{D6437164-482B-44F1-81FC-08A4C2A5BECE}E:\torrenty\simcity\stunnel\tstunnel.exe] => (Allow) E:\torrenty\simcity\stunnel\tstunnel.exe
FirewallRules: [UDP Query User{D17086A0-3CC5-4A03-A95D-CED55EB3B8EA}E:\torrenty\simcity\stunnel\tstunnel.exe] => (Allow) E:\torrenty\simcity\stunnel\tstunnel.exe
FirewallRules: [TCP Query User{D38E13AF-482D-4052-BC06-0C5ACD47CDD2}D:\games\need for speed - most wanted\nfs13.exe] => (Allow) D:\games\need for speed - most wanted\nfs13.exe
FirewallRules: [UDP Query User{2EB2EDBD-0954-4899-A464-2370DD55F782}D:\games\need for speed - most wanted\nfs13.exe] => (Allow) D:\games\need for speed - most wanted\nfs13.exe
FirewallRules: [TCP Query User{68FA666B-32D2-4220-B518-FDEB68BFA435}C:\windows\syswow64\javaw.exe] => (Allow) C:\windows\syswow64\javaw.exe
FirewallRules: [UDP Query User{B877F6DB-711F-4813-9FB3-8169C0814B36}C:\windows\syswow64\javaw.exe] => (Allow) C:\windows\syswow64\javaw.exe
FirewallRules: [{CDCA330E-0B8D-4F75-8532-E89A8282E0DE}] => (Allow) C:\Users\Jirka\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{35E46C75-E4B0-4598-9F03-E72FA1952981}] => (Allow) C:\Users\Jirka\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{D64F10BC-E310-46F0-8735-E6C748827830}] => (Allow) D:\Games\SimCity\SimCity\SimCity.exe
FirewallRules: [{CB9C5667-70DB-40E6-92CA-3E3CBAED0B56}] => (Allow) D:\Games\SimCity\SimCity\SimCity.exe
FirewallRules: [{3474882F-9F33-4BE9-A96D-2159885B5C5A}] => (Allow) D:\Games\zoo\zt.exe
FirewallRules: [{7FCDFC98-1793-4D24-8332-66CC5D8F5EA1}] => (Allow) D:\Games\zoo\zt.exe
FirewallRules: [{FBDBC211-ABB6-4C40-976B-D0879F21DFBA}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{146BEFE2-604D-41AF-96DC-379D2AA494E4}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{763DFDCB-3F90-42F5-A853-F1171F701645}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{EB6CDE93-6E51-4679-B15C-A0B29AE35F46}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{D5B039B4-1AC0-40AC-9106-A4483A06C128}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{52EB6BA8-36D0-4F73-A91F-AE23D59497F0}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{C8A43C12-DB73-4713-A0AF-526A78EF9DDE}] => (Allow) C:\Windows\SysWOW64\muzapp.exe
FirewallRules: [{9C0B71B5-F09E-4E93-931F-B52B4D37DB2A}] => (Allow) C:\Windows\SysWOW64\muzapp.exe
FirewallRules: [{80515C18-0F7C-4E0F-9CD4-58EB56647478}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{1699D350-3F51-4258-8BE8-D4B9057D57B2}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{1DCFD896-C464-4F02-9343-2E49DCDC1424}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{FAB4D8C8-A988-4A96-B3E1-4587EF537B72}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{5F34963E-7B21-4055-B43D-3290702ABC7E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{FC2540AA-DF70-4E60-800B-1588C363F4FC}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{F086802F-BCFF-4B55-B93A-5216725614B0}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{5DBAE308-0237-4D59-ABF3-ADDA7B683F59}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (05/23/2015 09:19:37 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Název chybujícího modulu: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Kód výjimky: 0xc0000094
Posun chyby: 0x000000000002814d
ID chybujícího procesu: 0x1fe4
Čas spuštění chybující aplikace: 0xsvchost.exe0
Cesta k chybující aplikaci: svchost.exe1
Cesta k chybujícímu modulu: svchost.exe2
ID zprávy: svchost.exe3
Úplný název chybujícího balíčku: svchost.exe4
ID aplikace související s chybujícím balíčkem: svchost.exe5

Error: (05/23/2015 08:59:39 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Název chybujícího modulu: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Kód výjimky: 0xc0000094
Posun chyby: 0x000000000002814d
ID chybujícího procesu: 0x10c8
Čas spuštění chybující aplikace: 0xsvchost.exe0
Cesta k chybující aplikaci: svchost.exe1
Cesta k chybujícímu modulu: svchost.exe2
ID zprávy: svchost.exe3
Úplný název chybujícího balíčku: svchost.exe4
ID aplikace související s chybujícím balíčkem: svchost.exe5

Error: (05/23/2015 08:59:26 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Název chybujícího modulu: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Kód výjimky: 0xc0000094
Posun chyby: 0x000000000002814d
ID chybujícího procesu: 0x1b1c
Čas spuštění chybující aplikace: 0xsvchost.exe0
Cesta k chybující aplikaci: svchost.exe1
Cesta k chybujícímu modulu: svchost.exe2
ID zprávy: svchost.exe3
Úplný název chybujícího balíčku: svchost.exe4
ID aplikace související s chybujícím balíčkem: svchost.exe5

Error: (05/23/2015 08:59:25 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Název chybujícího modulu: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Kód výjimky: 0xc0000094
Posun chyby: 0x000000000002814d
ID chybujícího procesu: 0xe18
Čas spuštění chybující aplikace: 0xsvchost.exe0
Cesta k chybující aplikaci: svchost.exe1
Cesta k chybujícímu modulu: svchost.exe2
ID zprávy: svchost.exe3
Úplný název chybujícího balíčku: svchost.exe4
ID aplikace související s chybujícím balíčkem: svchost.exe5

Error: (05/16/2015 02:56:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Název chybujícího modulu: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Kód výjimky: 0xc0000094
Posun chyby: 0x000000000002814d
ID chybujícího procesu: 0x1ac8
Čas spuštění chybující aplikace: 0xsvchost.exe0
Cesta k chybující aplikaci: svchost.exe1
Cesta k chybujícímu modulu: svchost.exe2
ID zprávy: svchost.exe3
Úplný název chybujícího balíčku: svchost.exe4
ID aplikace související s chybujícím balíčkem: svchost.exe5

Error: (05/16/2015 02:32:11 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Název chybujícího modulu: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Kód výjimky: 0xc0000094
Posun chyby: 0x000000000002814d
ID chybujícího procesu: 0xa7c
Čas spuštění chybující aplikace: 0xsvchost.exe0
Cesta k chybující aplikaci: svchost.exe1
Cesta k chybujícímu modulu: svchost.exe2
ID zprávy: svchost.exe3
Úplný název chybujícího balíčku: svchost.exe4
ID aplikace související s chybujícím balíčkem: svchost.exe5

Error: (05/14/2015 08:03:35 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Název chybujícího modulu: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Kód výjimky: 0xc0000094
Posun chyby: 0x000000000002814d
ID chybujícího procesu: 0xcb8
Čas spuštění chybující aplikace: 0xsvchost.exe0
Cesta k chybující aplikaci: svchost.exe1
Cesta k chybujícímu modulu: svchost.exe2
ID zprávy: svchost.exe3
Úplný název chybujícího balíčku: svchost.exe4
ID aplikace související s chybujícím balíčkem: svchost.exe5

Error: (05/14/2015 08:02:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Název chybujícího modulu: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Kód výjimky: 0xc0000094
Posun chyby: 0x000000000002814d
ID chybujícího procesu: 0x82c
Čas spuštění chybující aplikace: 0xsvchost.exe0
Cesta k chybující aplikaci: svchost.exe1
Cesta k chybujícímu modulu: svchost.exe2
ID zprávy: svchost.exe3
Úplný název chybujícího balíčku: svchost.exe4
ID aplikace související s chybujícím balíčkem: svchost.exe5

Error: (05/14/2015 08:01:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Název chybujícího modulu: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Kód výjimky: 0xc0000094
Posun chyby: 0x000000000002814d
ID chybujícího procesu: 0x1560
Čas spuštění chybující aplikace: 0xsvchost.exe0
Cesta k chybující aplikaci: svchost.exe1
Cesta k chybujícímu modulu: svchost.exe2
ID zprávy: svchost.exe3
Úplný název chybujícího balíčku: svchost.exe4
ID aplikace související s chybujícím balíčkem: svchost.exe5

Error: (05/14/2015 08:00:42 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Název chybujícího modulu: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Kód výjimky: 0xc0000094
Posun chyby: 0x000000000002814d
ID chybujícího procesu: 0x18fc
Čas spuštění chybující aplikace: 0xsvchost.exe0
Cesta k chybující aplikaci: svchost.exe1
Cesta k chybujícímu modulu: svchost.exe2
ID zprávy: svchost.exe3
Úplný název chybujícího balíčku: svchost.exe4
ID aplikace související s chybujícím balíčkem: svchost.exe5


System errors:
=============
Error: (05/14/2015 07:49:25 PM) (Source: volsnap) (EventID: 36) (User: )
Description: Stínové kopie svazku C: byly přerušeny, protože z důvodu limitu stanoveného uživatelem se nepodařilo zvětšit úložiště stínové kopie.

Error: (04/19/2015 10:33:17 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4

Error: (04/19/2015 09:16:37 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4

Error: (03/03/2015 08:05:55 PM) (Source: volsnap) (EventID: 36) (User: )
Description: Stínové kopie svazku C: byly přerušeny, protože z důvodu limitu stanoveného uživatelem se nepodařilo zvětšit úložiště stínové kopie.

Error: (02/07/2015 08:00:24 PM) (Source: volsnap) (EventID: 36) (User: )
Description: Stínové kopie svazku C: byly přerušeny, protože z důvodu limitu stanoveného uživatelem se nepodařilo zvětšit úložiště stínové kopie.

Error: (01/24/2015 06:31:16 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4

Error: (01/11/2015 05:05:13 PM) (Source: bowser) (EventID: 8003) (User: )
Description: Hlavní prohledávač přijal oznámení serveru od počítače NOTEBOOK,
který se považuje za hlavní prohledávač domény pro přenos NetBT_Tcpip_{2B4AD9C4-68FB-4A3C-8CFE-ED975104B6AE}.
Hlavní prohledávač bude ukončen nebo bude vyvolána volba.

Error: (01/11/2015 00:23:37 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4

Error: (01/10/2015 04:38:31 PM) (Source: bowser) (EventID: 8003) (User: )
Description: Hlavní prohledávač přijal oznámení serveru od počítače NOTEBOOK,
který se považuje za hlavní prohledávač domény pro přenos NetBT_Tcpip_{2B4AD9C4-68FB-4A3C-8CFE-ED975104B6AE}.
Hlavní prohledávač bude ukončen nebo bude vyvolána volba.

Error: (01/01/2015 07:35:43 PM) (Source: volsnap) (EventID: 36) (User: )
Description: Stínové kopie svazku C: byly přerušeny, protože z důvodu limitu stanoveného uživatelem se nepodařilo zvětšit úložiště stínové kopie.


Microsoft Office:
=========================

CodeIntegrity Errors:
===================================
Date: 2014-01-30 19:18:05.061
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Moborobo\MoboroboAssDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info ===========================

Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 6000+
Percentage of memory in use: 34%
Total physical RAM: 4087.06 MB
Available physical RAM: 2658.28 MB
Total Pagefile: 4791.06 MB
Available Pagefile: 3222.47 MB
Total Virtual: 8192 MB
Available Virtual: 8191.78 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:58.5 GB) (Free:22.57 GB) NTFS
Drive d: (Download) (Fixed) (Total:407.16 GB) (Free:253.44 GB) NTFS
Drive e: (Hudba) (Fixed) (Total:931.51 GB) (Free:353.29 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 2B072B06)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=58.5 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=407.2 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 931.5 GB) (Disk ID: C5365980)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=42)

==================== End of log ============================

Re: Prosím o kontrolu

Napsal: 23 kvě 2015 09:32
od georgdj
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22-05-2015 01
Ran by Jirka (administrator) on PC-JIRKA on 23-05-2015 10:28:03
Running from C:\Users\Jirka\Desktop
Loaded Profiles: Jirka (Available Profiles: Jirka)
Platform: Windows 8 Enterprise (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 10 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Software602 a.s.) C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) C:\Windows\System32\PrintCtrl.exe
(ActMask Co.,Ltd - http://www.all2pdf.com) C:\Windows\System32\PrintDisp.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Realtek Semiconductor) C:\Windows\RAVCpl64.exe
() C:\Program Files (x86)\RocketDock\RocketDock.exe
(Software602) C:\Program Files (x86)\Software602\Print2PDF\Print2PDF.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Windows\System32\schtasks.exe
() C:\Windows\Temp\svchost.exe
(Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
() C:\Users\Jirka\Desktop\adwcleaner_4.205.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\Run: [RtHDVCpl] => C:\Windows\RAVCpl64.exe [6471200 2008-08-27] (Realtek Semiconductor)
HKLM-x32\...\Run: [Skytel] => C:\Windows\Skytel.exe [1833504 2008-08-27] (Realtek Semiconductor Corp.)
HKLM-x32\...\Run: [PrintDisp] => C:\Windows\system32\PrintDisp.exe [870400 2012-10-29] (ActMask Co.,Ltd - http://www.all2pdf.com)
HKLM-x32\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161984 2014-04-20] (IvoSoft)
HKLM-x32\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2403104 2014-07-25] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [BigDog305] => C:\Windows\VM305_STI.EXE [57344 2007-04-09] (VM305SNAP)
HKLM-x32\...\Run: [Print2PDF Print Monitor] => C:\Program Files (x86)\Software602\Print2PDF\Print2PDF.exe [222776 2011-04-12] (Software602)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [iSkysoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe [2000896 2014-04-04] (iSkySoft)
HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [310064 2014-06-14] (Samsung Electronics Co., Ltd.)
HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\Run: [RocketDock] => C:\Program Files (x86)\RocketDock\RocketDock.exe [495616 2007-09-02] ()
HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\Run: [Google Update] => C:\Users\Jirka\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2014-01-12] (Google Inc.)
HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\MountPoints2: {c40e06aa-1ef7-11e3-be69-001fd0ddbfca} - "G:\autorun.exe"
Startup: C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sidebar.lnk [2013-09-16]
ShortcutTarget: Sidebar.lnk -> C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-04-20] (IvoSoft)
ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20] (IvoSoft)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-626980440-2269883898-3179777769-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
SearchScopes: HKU\S-1-5-21-626980440-2269883898-3179777769-1001 -> {3D5FD8A2-6B52-45D9-8C35-0F13256F4292} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_13415
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-04-20] (IvoSoft)
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2014-04-20] (IvoSoft)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20] (IvoSoft)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-12-18] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-12-18] (Oracle Corporation)
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2014-04-20] (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-04-20] (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20] (IvoSoft)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 109.231.191.1 109.231.191.3

FireFox:
========
FF ProfilePath: C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\m8es3xti.default
FF Homepage: www.seznam.cz
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_188.dll [2015-05-23] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_188.dll [2015-05-23] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-07-12] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2013-12-18] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2013-12-18] (Oracle Corporation)
FF Plugin-x32: @nullsoft.com/winampDetector;version=1 -> C:\Program Files (x86)\Winamp Detect\npwachk.dll [2013-07-24] (Nullsoft, Inc.)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2014-07-02] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2014-07-02] (NVIDIA Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll No File
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll No File
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-626980440-2269883898-3179777769-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Jirka\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-04-28] (Google Inc.)
FF Plugin HKU\S-1-5-21-626980440-2269883898-3179777769-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Jirka\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-04-28] (Google Inc.)
FF Plugin HKU\S-1-5-21-626980440-2269883898-3179777769-1001: ubisoft.com/uplaypc -> D:\Games\Settlers 7 Gold\Data\Base\_Dbg\Bin\Release\orbit\npuplaypc.dll [2013-02-26] (Ubisoft)
FF Extension: Forecastfox - C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\m8es3xti.default\Extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3} [2013-09-16]
FF Extension: 1-Click Dailymotion Video Downloader - C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\m8es3xti.default\Extensions\DailymotionVideoDownloader@PeterOlayev.com.xpi [2013-12-14]
FF Extension: Download YouTube Videos as MP4 - C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\m8es3xti.default\Extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi [2013-12-27]

Chrome:
=======
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/"
CHR Profile: C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-09-18]
CHR Extension: (Google Drive) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-09-18]
CHR Extension: (YouTube) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-09-18]
CHR Extension: (Google Search) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-09-18]
CHR Extension: (Google Wallet) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-29]
CHR Extension: (Gmail) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-09-18]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 602XML Updater; C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe [73728 2010-04-14] (Software602 a.s.) []
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [537896 2008-06-24] (Nero AG)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1720608 2014-07-25] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18956064 2014-07-25] (NVIDIA Corporation)
R2 Printer Control; C:\Windows\system32\PrintCtrl.exe [121856 2012-10-21] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) []
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5426448 2014-12-15] (TeamViewer GmbH)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 61883; C:\Windows\System32\drivers\61883.sys [61440 2012-07-26] (Microsoft Corporation)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283200 2013-09-17] (DT Soft Ltd)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-05-23] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-04-14] (Malwarebytes Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-07-25] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19152 2013-09-30] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] ()
S3 Rockusb; C:\Windows\System32\drivers\rockusb.sys [65688 2013-03-11] (Fuzhou Rockchip Electronics Co,Ltd.)
R3 vvftav; C:\Windows\system32\drivers\vvftav.sys [300800 2007-06-23] (Vimicro Corporation)
R3 ZSMC0305; C:\Windows\System32\Drivers\usbVM305.sys [1541120 2007-03-08] (Vimicro Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-05-23 10:28 - 2015-05-23 10:28 - 00013823 _____ () C:\Users\Jirka\Desktop\FRST.txt
2015-05-23 10:27 - 2015-05-23 10:28 - 00000000 ____D () C:\FRST
2015-05-23 10:27 - 2015-05-23 10:27 - 02108416 _____ (Farbar) C:\Users\Jirka\Desktop\FRST64.exe
2015-05-23 10:25 - 2015-05-23 10:26 - 00000000 ____D () C:\AdwCleaner
2015-05-23 10:25 - 2015-05-23 10:25 - 02223104 _____ () C:\Users\Jirka\Desktop\adwcleaner_4.205.exe
2015-05-23 10:11 - 2015-05-23 10:11 - 00008471 _____ () C:\Users\Jirka\Desktop\hijackthis.log
2015-05-23 10:03 - 2015-05-23 10:03 - 00388608 _____ (Trend Micro Inc.) C:\Users\Jirka\Desktop\hijackthis.exe
2015-05-23 09:56 - 2015-05-23 09:59 - 00000042 _____ () C:\Users\Jirka\Desktop\Skylink.txt

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-05-23 10:17 - 2014-02-16 15:35 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\ClassicShell
2015-05-23 10:14 - 2012-07-26 12:01 - 00726246 _____ () C:\Windows\system32\perfh005.dat
2015-05-23 10:14 - 2012-07-26 12:01 - 00147800 _____ () C:\Windows\system32\perfc005.dat
2015-05-23 10:14 - 2012-07-26 09:28 - 01714430 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-23 10:11 - 2014-08-01 19:17 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-05-23 10:06 - 2014-09-29 18:15 - 00012292 _____ () C:\Windows\PFRO.log
2015-05-23 10:06 - 2013-09-16 20:04 - 00000000 ____D () C:\Windows\EffectResources
2015-05-23 10:06 - 2013-09-16 17:36 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-05-23 10:06 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-23 10:02 - 2013-09-16 19:10 - 00001903 _____ () C:\Windows\WINCMD.INI
2015-05-23 10:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2015-05-23 09:50 - 2013-09-16 18:22 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-05-23 09:47 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2015-05-23 09:38 - 2014-09-29 18:16 - 00429648 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-05-23 09:38 - 2014-01-12 16:58 - 00000928 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-626980440-2269883898-3179777769-1001Core.job
2015-05-23 09:38 - 2013-09-16 18:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-05-23 09:38 - 2012-07-26 10:18 - 00000000 ____D () C:\Windows\DigitalLocker
2015-05-23 09:37 - 2014-01-12 16:58 - 00000980 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-626980440-2269883898-3179777769-1001UA.job
2015-05-23 09:36 - 2013-11-17 18:03 - 00000000 ____D () C:\Program Files (x86)\MOBILedit! Forensic
2015-05-23 09:22 - 2014-08-01 19:17 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-05-23 09:22 - 2014-08-01 19:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-05-23 09:22 - 2014-08-01 19:17 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-05-23 09:21 - 2014-09-01 16:33 - 00000000 ____D () C:\Users\Jirka\AppData\Local\Adobe
2015-05-23 09:20 - 2013-09-16 18:22 - 00003802 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-05-23 09:12 - 2014-09-14 08:41 - 01103642 _____ () C:\Windows\WindowsUpdate.log
2015-05-14 18:22 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent
2015-05-14 18:20 - 2013-09-16 18:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-04-28 03:33 - 2014-01-12 16:58 - 00003926 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-626980440-2269883898-3179777769-1001UA
2015-04-28 03:32 - 2014-01-12 16:58 - 00003546 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-626980440-2269883898-3179777769-1001Core

==================== Files in the root of some directories =======

2013-10-20 19:36 - 2014-05-04 12:18 - 0008192 _____ () C:\Users\Jirka\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-07-08 17:51 - 2014-07-08 17:51 - 0000001 _____ () C:\Users\Jirka\AppData\Local\RawCopy.1.01.agreement
2014-07-08 17:52 - 2014-07-08 17:52 - 0000003 _____ () C:\Users\Jirka\AppData\Local\RawCopy.savedialog.dir
2014-07-08 17:52 - 2014-07-08 17:52 - 0000001 _____ () C:\Users\Jirka\AppData\Local\RawCopy.savedialog.filterindex
2014-07-08 17:51 - 2014-07-08 17:51 - 0000001 _____ () C:\Users\Jirka\AppData\Local\RawCopy.sourcedisk.index
2014-08-31 17:05 - 2014-08-31 17:05 - 0000017 _____ () C:\Users\Jirka\AppData\Local\resmon.resmoncfg
2013-10-31 21:26 - 2013-10-31 22:39 - 0024431 _____ () C:\Users\Jirka\AppData\Local\SRDownloader.err
2013-09-17 17:13 - 2014-01-29 18:40 - 0001136 _____ () C:\Users\Jirka\AppData\Local\SRDownloader.nast
2013-09-16 19:51 - 2013-09-16 19:51 - 0000057 _____ () C:\ProgramData\Ament.ini

Files to move or delete:
====================
C:\Users\Jirka\Workaround.vbs
C:\Users\Jirka\AppData\Roaming\Origin\update.vbe


Some files in TEMP:
====================
C:\Users\Jirka\AppData\Local\Temp\Quarantine.exe
C:\Users\Jirka\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-05-11 20:55

==================== End of log ============================

Re: Prosím o kontrolu

Napsal: 23 kvě 2015 09:52
od georgdj

Re: Prosím o kontrolu

Napsal: 23 kvě 2015 09:54
od georgdj
Jako tako... vyhledat v něm umím i odmazat

Re: Prosím o kontrolu

Napsal: 23 kvě 2015 10:03
od georgdj
Posílám exeport

Re: Prosím o kontrolu

Napsal: 23 kvě 2015 10:42
od georgdj
Takl problém bohužel neodstraněn....


Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22-05-2015 01
Ran by Jirka (administrator) on PC-JIRKA on 23-05-2015 11:26:13
Running from C:\Users\Jirka\Desktop
Loaded Profiles: Jirka (Available Profiles: Jirka)
Platform: Windows 8 Enterprise (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 10 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\wscript.exe
() C:\Windows Activation Technologies\wat.exe
(Software602 a.s.) C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) C:\Windows\System32\PrintCtrl.exe
(ActMask Co.,Ltd - http://www.all2pdf.com) C:\Windows\System32\PrintDisp.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Realtek Semiconductor) C:\Windows\RAVCpl64.exe
() C:\Program Files (x86)\RocketDock\RocketDock.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Software602) C:\Program Files (x86)\Software602\Print2PDF\Print2PDF.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\Run: [RtHDVCpl] => C:\Windows\RAVCpl64.exe [6471200 2008-08-27] (Realtek Semiconductor)
HKLM-x32\...\Run: [Skytel] => C:\Windows\Skytel.exe [1833504 2008-08-27] (Realtek Semiconductor Corp.)
HKLM-x32\...\Run: [PrintDisp] => C:\Windows\system32\PrintDisp.exe [870400 2012-10-29] (ActMask Co.,Ltd - http://www.all2pdf.com)
HKLM-x32\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161984 2014-04-20] (IvoSoft)
HKLM-x32\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2403104 2014-07-25] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [BigDog305] => C:\Windows\VM305_STI.EXE [57344 2007-04-09] (VM305SNAP)
HKLM-x32\...\Run: [Print2PDF Print Monitor] => C:\Program Files (x86)\Software602\Print2PDF\Print2PDF.exe [222776 2011-04-12] (Software602)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [iSkysoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe [2000896 2014-04-04] (iSkySoft)
HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [310064 2014-06-14] (Samsung Electronics Co., Ltd.)
HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\Run: [RocketDock] => C:\Program Files (x86)\RocketDock\RocketDock.exe [495616 2007-09-02] ()
HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\Run: [Google Update] => C:\Users\Jirka\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2014-01-12] (Google Inc.)
HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\MountPoints2: {c40e06aa-1ef7-11e3-be69-001fd0ddbfca} - "G:\autorun.exe"
Startup: C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sidebar.lnk [2013-09-16]
ShortcutTarget: Sidebar.lnk -> C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-04-20] (IvoSoft)
ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20] (IvoSoft)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-626980440-2269883898-3179777769-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-626980440-2269883898-3179777769-1001 -> {3D5FD8A2-6B52-45D9-8C35-0F13256F4292} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_13415
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-04-20] (IvoSoft)
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2014-04-20] (IvoSoft)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20] (IvoSoft)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-12-18] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-12-18] (Oracle Corporation)
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2014-04-20] (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-04-20] (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20] (IvoSoft)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 109.231.191.1 109.231.191.3

FireFox:
========
FF ProfilePath: C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\m8es3xti.default
FF Homepage: www.seznam.cz
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_188.dll [2015-05-23] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_188.dll [2015-05-23] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-07-12] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2013-12-18] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2013-12-18] (Oracle Corporation)
FF Plugin-x32: @nullsoft.com/winampDetector;version=1 -> C:\Program Files (x86)\Winamp Detect\npwachk.dll [2013-07-24] (Nullsoft, Inc.)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2014-07-02] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2014-07-02] (NVIDIA Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll No File
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll No File
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-626980440-2269883898-3179777769-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Jirka\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-04-28] (Google Inc.)
FF Plugin HKU\S-1-5-21-626980440-2269883898-3179777769-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Jirka\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-04-28] (Google Inc.)
FF Plugin HKU\S-1-5-21-626980440-2269883898-3179777769-1001: ubisoft.com/uplaypc -> D:\Games\Settlers 7 Gold\Data\Base\_Dbg\Bin\Release\orbit\npuplaypc.dll [2013-02-26] (Ubisoft)
FF Extension: Forecastfox - C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\m8es3xti.default\Extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3} [2013-09-16]
FF Extension: 1-Click Dailymotion Video Downloader - C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\m8es3xti.default\Extensions\DailymotionVideoDownloader@PeterOlayev.com.xpi [2013-12-14]
FF Extension: Download YouTube Videos as MP4 - C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\m8es3xti.default\Extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi [2013-12-27]

Chrome:
=======
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/"
CHR Profile: C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-09-18]
CHR Extension: (Google Drive) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-09-18]
CHR Extension: (YouTube) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-09-18]
CHR Extension: (Google Search) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-09-18]
CHR Extension: (Google Wallet) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-29]
CHR Extension: (Gmail) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-09-18]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 602XML Updater; C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe [73728 2010-04-14] (Software602 a.s.) []
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [537896 2008-06-24] (Nero AG)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1720608 2014-07-25] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18956064 2014-07-25] (NVIDIA Corporation)
R2 Printer Control; C:\Windows\system32\PrintCtrl.exe [121856 2012-10-21] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) []
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5426448 2014-12-15] (TeamViewer GmbH)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 61883; C:\Windows\System32\drivers\61883.sys [61440 2012-07-26] (Microsoft Corporation)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283200 2013-09-17] (DT Soft Ltd)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-05-23] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-04-14] (Malwarebytes Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-07-25] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19152 2013-09-30] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] ()
S3 Rockusb; C:\Windows\System32\drivers\rockusb.sys [65688 2013-03-11] (Fuzhou Rockchip Electronics Co,Ltd.)
R3 vvftav; C:\Windows\system32\drivers\vvftav.sys [300800 2007-06-23] (Vimicro Corporation)
R3 ZSMC0305; C:\Windows\System32\Drivers\usbVM305.sys [1541120 2007-03-08] (Vimicro Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-05-23 11:26 - 2015-05-23 11:26 - 00014072 _____ () C:\Users\Jirka\Desktop\FRST.txt
2015-05-23 11:26 - 2015-05-23 11:26 - 00003174 _____ () C:\Windows\System32\Tasks\Origin
2015-05-23 11:15 - 2015-05-23 11:20 - 00000000 ____D () C:\Archivace
2015-05-23 11:02 - 2015-05-23 11:02 - 00000235 _____ () C:\Users\Jirka\Documents\export.rar
2015-05-23 11:01 - 2015-05-23 11:01 - 00000348 _____ () C:\Users\Jirka\Documents\export.reg
2015-05-23 10:27 - 2015-05-23 11:26 - 00000000 ____D () C:\FRST
2015-05-23 10:27 - 2015-05-23 10:27 - 02108416 _____ (Farbar) C:\Users\Jirka\Desktop\FRST64.exe
2015-05-23 10:25 - 2015-05-23 10:40 - 00000000 ____D () C:\AdwCleaner
2015-05-23 10:25 - 2015-05-23 10:25 - 02223104 _____ () C:\Users\Jirka\Desktop\adwcleaner_4.205.exe
2015-05-23 10:11 - 2015-05-23 10:11 - 00008471 _____ () C:\Users\Jirka\Desktop\hijackthis.log
2015-05-23 10:03 - 2015-05-23 10:03 - 00388608 _____ (Trend Micro Inc.) C:\Users\Jirka\Desktop\hijackthis.exe
2015-05-23 09:56 - 2015-05-23 09:59 - 00000042 _____ () C:\Users\Jirka\Desktop\Skylink.txt

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-05-23 11:26 - 2013-09-16 19:10 - 00001919 _____ () C:\Windows\WINCMD.INI
2015-05-23 11:25 - 2013-09-16 17:36 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-05-23 11:25 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-23 11:23 - 2014-01-12 16:58 - 00000980 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-626980440-2269883898-3179777769-1001UA.job
2015-05-23 11:19 - 2014-02-16 15:35 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\ClassicShell
2015-05-23 11:17 - 2013-09-17 18:30 - 00000000 ___HD () C:\Users\Jirka\AppData\Roaming\Origin
2015-05-23 11:16 - 2013-09-16 17:25 - 00000000 ____D () C:\Users\Jirka
2015-05-23 11:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2015-05-23 10:50 - 2013-09-16 18:22 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-05-23 10:41 - 2012-07-26 12:01 - 00726246 _____ () C:\Windows\system32\perfh005.dat
2015-05-23 10:41 - 2012-07-26 12:01 - 00147800 _____ () C:\Windows\system32\perfc005.dat
2015-05-23 10:41 - 2012-07-26 09:28 - 01714430 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-23 10:34 - 2014-09-29 18:15 - 00012646 _____ () C:\Windows\PFRO.log
2015-05-23 10:11 - 2014-08-01 19:17 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-05-23 10:06 - 2013-09-16 20:04 - 00000000 ____D () C:\Windows\EffectResources
2015-05-23 09:47 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2015-05-23 09:38 - 2014-09-29 18:16 - 00429648 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-05-23 09:38 - 2014-01-12 16:58 - 00000928 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-626980440-2269883898-3179777769-1001Core.job
2015-05-23 09:38 - 2013-09-16 18:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-05-23 09:38 - 2012-07-26 10:18 - 00000000 ____D () C:\Windows\DigitalLocker
2015-05-23 09:36 - 2013-11-17 18:03 - 00000000 ____D () C:\Program Files (x86)\MOBILedit! Forensic
2015-05-23 09:22 - 2014-08-01 19:17 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-05-23 09:22 - 2014-08-01 19:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-05-23 09:22 - 2014-08-01 19:17 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-05-23 09:21 - 2014-09-01 16:33 - 00000000 ____D () C:\Users\Jirka\AppData\Local\Adobe
2015-05-23 09:20 - 2013-09-16 18:22 - 00003802 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-05-23 09:12 - 2014-09-14 08:41 - 01103642 _____ () C:\Windows\WindowsUpdate.log
2015-05-14 18:22 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent
2015-05-14 18:20 - 2013-09-16 18:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-04-28 03:33 - 2014-01-12 16:58 - 00003926 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-626980440-2269883898-3179777769-1001UA
2015-04-28 03:32 - 2014-01-12 16:58 - 00003546 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-626980440-2269883898-3179777769-1001Core

==================== Files in the root of some directories =======

2013-10-20 19:36 - 2014-05-04 12:18 - 0008192 _____ () C:\Users\Jirka\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-07-08 17:51 - 2014-07-08 17:51 - 0000001 _____ () C:\Users\Jirka\AppData\Local\RawCopy.1.01.agreement
2014-07-08 17:52 - 2014-07-08 17:52 - 0000003 _____ () C:\Users\Jirka\AppData\Local\RawCopy.savedialog.dir
2014-07-08 17:52 - 2014-07-08 17:52 - 0000001 _____ () C:\Users\Jirka\AppData\Local\RawCopy.savedialog.filterindex
2014-07-08 17:51 - 2014-07-08 17:51 - 0000001 _____ () C:\Users\Jirka\AppData\Local\RawCopy.sourcedisk.index
2014-08-31 17:05 - 2014-08-31 17:05 - 0000017 _____ () C:\Users\Jirka\AppData\Local\resmon.resmoncfg
2013-10-31 21:26 - 2013-10-31 22:39 - 0024431 _____ () C:\Users\Jirka\AppData\Local\SRDownloader.err
2013-09-17 17:13 - 2014-01-29 18:40 - 0001136 _____ () C:\Users\Jirka\AppData\Local\SRDownloader.nast
2013-09-16 19:51 - 2013-09-16 19:51 - 0000057 _____ () C:\ProgramData\Ament.ini

Some files in TEMP:
====================
C:\Users\Jirka\AppData\Local\Temp\svchost.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-05-11 20:55

==================== End of log ============================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-05-2015 01
Ran by Jirka at 2015-05-23 11:27:23
Running from C:\Users\Jirka\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-626980440-2269883898-3179777769-500 - Administrator - Disabled)
Guest (S-1-5-21-626980440-2269883898-3179777769-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-626980440-2269883898-3179777769-1003 - Limited - Enabled)
Jirka (S-1-5-21-626980440-2269883898-3179777769-1001 - Administrator - Enabled) => C:\Users\Jirka

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

«Need for Speed - Most Wanted» 1.5 (HKLM-x32\...\{FB0127F3-985B-44CE-AE29-378CAF60B361}_is1) (Version: 1.5 - Electronic Arts)
µTorrent (HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\uTorrent) (Version: 3.4.2.35702 - BitTorrent Inc.)
7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - )
8GadgetPack (HKLM-x32\...\{F7EF899D-0339-4279-8FB1-96801D829A3F}) (Version: 8.0.1 - Helmut Buhler)
A4 TECH PC Camera V (HKLM-x32\...\{8AD824A5-1CCC-4BB7-82C9-E6FB25CC0479}) (Version: 2007.07.30 - A4)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.7.0.1530 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.188 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.08) - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated)
Age Of Empires II HD v2.5 [LAN Edition] (HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\Age Of Empires II HD v2.5 [LAN Edition]) (Version: - )
Aktualizace NVIDIA 15.3.33 (Version: 15.3.33 - NVIDIA Corporation) Hidden
AVI to 3GP (HKLM-x32\...\{AE4E8D53-2D05-4EB4-A1E7-FF48B8E76DDE}_is1) (Version: - www.avito3gp.com)
BS.Player FREE (HKLM-x32\...\BSPlayerf) (Version: 2.66.1075 - AB Team, d.o.o.)
CCleaner (HKLM\...\CCleaner) (Version: 4.17 - Piriform)
CDex - Open Source Digital Audio CD Extractor (HKLM-x32\...\CDex) (Version: 1.70.4.2009 - Georgy Berdyshev)
Classic Shell (HKLM\...\{840C85B7-D3D6-4143-9AF9-DAE80FD54CFC}) (Version: 4.1.0 - IvoSoft)
Čeština pro GTA IV v1.0.7.0 1.0.7.0 (HKLM-x32\...\Čeština pro GTA IV v1.0.7.0 1.0.7.0) (Version: - )
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.47.1.0333 - Disc Soft Ltd)
Google Earth (HKLM-x32\...\{96AD3B61-EAE2-11E2-9E72-B8AC6F98CCE3}) (Version: 7.1.1.1888 - Google)
Google Chrome (HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\Google Chrome) (Version: 42.0.2311.152 - Google Inc.)
Grand Theft Auto IV (HKLM-x32\...\{579BA58C-F33D-4970-9953-B94B43768AC3}) (Version: 1.00.0000 - Rockstar Games)
Grand Theft Auto IV (x32 Version: 1.0.0013.131 - Rockstar Games Inc.) Hidden
HTC BMP USB Driver (HKLM-x32\...\{31A559C1-9E4D-423B-9DD3-34A6C5398752}) (Version: 1.0.5375 - HTC)
HTC Driver Installer (HKLM-x32\...\{4CEEE5D0-F905-4688-B9F9-ECC710507796}) (Version: 4.1.0.001 - HTC Corporation)
HTC Sync (HKLM-x32\...\{C4494248-6D52-4674-B8CF-9177EA3F92F8}) (Version: 3.3.53 - HTC Corporation)
Infix PDF Editor verze 6.1.9.0 (HKLM-x32\...\83FFB914-6FA7-4F1F-807E-E0FFBA2E49E1_is1) (Version: 6.1.9.0 - Iceni Technology)
Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217040FF}) (Version: 7.0.510 - Oracle)
K-Lite Mega Codec Pack 10.4.0 (HKLM-x32\...\KLiteCodecPack_is1) (Version: 10.4.0 - )
Malwarebytes Anti-Malware verze 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
MegaTrainer eXperience V1.1.5.3 (HKLM-x32\...\MegaTrainer eXperience_is1) (Version: - )
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x64 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
MiniTool Partition Wizard Home Edition 8.1.1 (HKLM-x32\...\{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1) (Version: - MiniTool Solution Ltd.)
Mozilla Firefox 37.0.2 (x86 cs) (HKLM-x32\...\Mozilla Firefox 37.0.2 (x86 cs)) (Version: 37.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 35.0.1 - Mozilla)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
Nero 8 (HKLM-x32\...\{6D45EF03-E8EE-4355-81C3-F918CBCF1029}) (Version: 8.3.309 - Nero AG)
NVIDIA GeForce Experience 2.1.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.1 - NVIDIA Corporation)
NVIDIA Ovladač 3D Vision 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 340.52 - NVIDIA Corporation)
NVIDIA Ovladač řídící jednotky 3D Vision 340.50 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 340.50 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 340.52 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.4.11.2806 - Electronic Arts, Inc.)
Ovládací panel NVIDIA 340.52 (Version: 340.52 - NVIDIA Corporation) Hidden
Ovladače videa společnosti Pinnacle (HKLM\...\{6DE721A5-5E89-4D74-994C-652BB3C0672E}) (Version: 12.1.0.030 - Pinnacle Systems)
Pinnacle Studio 15 (HKLM-x32\...\{1362E602-9625-42D3-B57F-CDA9D26F9DA8}) (Version: 15.0.0.7593 - Pinnacle Systems)
Pinnacle Studio 15 Ultimate Plugins (HKLM-x32\...\{EB5DF19E-75D5-4FF1-AE23-2A9A2E0F2BDD}) (Version: 15.0.0.7593 - Pinnacle Systems)
Pinnacle Studio Bonus Content (HKLM-x32\...\{FC030CB5-46A6-4229-AD6E-0AC869F509C8}) (Version: 15.0.0.51 - Pinnacle Systems)
ProgDVB (HKLM-x32\...\ProgDVB) (Version: 6.9x - Prog)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0024 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5694 - Realtek Semiconductor Corp.)
RocketDock 1.3.5 (HKLM-x32\...\RocketDock_is1) (Version: - Punk Software)
Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.3.14044_17 - Samsung Electronics Co., Ltd.)
Samsung Kies (x32 Version: 2.6.3.14044_17 - Samsung Electronics Co., Ltd.) Hidden
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.14083.17 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (x32 Version: 3.2.14083.17 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.45.0 - SAMSUNG Electronics Co., Ltd.)
SHIELD Streaming (Version: 3.1.100 - NVIDIA Corporation) Hidden
Sim Aquarium 3 (HKLM-x32\...\Sim Aquarium 3_is1) (Version: 3 - Ladislav Vojnic)
SimCity™ (HKLM-x32\...\{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}) (Version: 1.0.0.0 - Electronic Arts)
Skype™ 6.22 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.22.107 - Skype Technologies S.A.)
Software602 Print2PDF (HKLM-x32\...\{32C74893-0243-4235-A6F3-201F0E5D2C03}) (Version: 9.1.11.0421 - Software602 a.s.)
Subtitle Workshop 2.51 (HKLM-x32\...\SubtitleWorkshop) (Version: - )
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.36897 - TeamViewer)
The Settlers 7 - Paths to a Kingdom (HKLM-x32\...\{63860309-DA8A-4BAE-9EAE-CE1D6D79340C}) (Version: 1.12.1396 - Ubisoft)
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
USB PC Camera VC305 (HKLM-x32\...\{ADE16A9D-FBDC-4ECC-B6BD-9C31E51D0305}) (Version: - )
VCRedistSetup (x32 Version: 1.0.0 - Nero AG) Hidden
VirtualDJ 8 (HKLM-x32\...\{9ADBBA93-4625-4898-BB0D-BCE7EA9F8B4A}) (Version: 8.0.0 - Atomix Productions)
VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN)
Winamp (HKLM-x32\...\Winamp) (Version: 5.65 - Nullsoft, Inc)
Winamp Detector Plug-in (HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc)
WinRAR (HKLM-x32\...\WinRAR archiver) (Version: - )
World of Tanks (HKLM-x32\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812EU}_is1) (Version: - Wargaming.net)
Yawcam 0.4.1 (HKLM-x32\...\{8FE96B14-E1F9-47BF-8BA1-A81467CD259B}_is1) (Version: - )
Základní software zařízení HP Photosmart 5510 series (HKLM\...\{22E8B03A-9094-45AC-910A-CB491A16A593}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
Zoo Tycoon 2 (HKLM-x32\...\Zoo Tycoon 2) (Version: 1.0 - Microsoft)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-626980440-2269883898-3179777769-1001_Classes\CLSID\{0E7BE950-4ACC-47CB-834B-41A8B96BBFF9}\InprocServer32 -> C:\Users\Jirka\AppData\Local\Microsoft\Windows Sidebar\Gadgets\Sidebar7.gadget\Release\Sidebar7.64.dll (Helmut Buhler)
CustomCLSID: HKU\S-1-5-21-626980440-2269883898-3179777769-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Jirka\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-626980440-2269883898-3179777769-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Jirka\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-626980440-2269883898-3179777769-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Jirka\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-626980440-2269883898-3179777769-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Jirka\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-626980440-2269883898-3179777769-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Jirka\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll (Google Inc.)

==================== Restore Points =========================


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2012-07-26 07:26 - 2014-03-16 09:58 - 00001487 ___RA C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 csc3-2010-crl.verisign.com
127.0.0.1 ocsp.verisign.com
127.0.0.1 crl.verisign.com
127.0.0.1 download.dm.origin.com
127.0.0.1 secure.download.dm.origin.com
127.0.0.1 loginregistration.dm.origin.com
127.0.0.1 achievements.gameservices.ea.com
127.0.0.1 friends.dm.origin.com
127.0.0.1 avatar.dm.origin.com
127.0.0.1 ecommerce.dm.origin.com
127.0.0.1 static.cdn.ea.com
127.0.0.1 tealium.hs.llnwd.net
127.0.0.1 heartbeat.dm.origin.com
127.0.0.1 web.dm.origin.com
127.0.0.1 store.origin.com
127.0.0.1 ec2-54-243-231-82.compute-1.amazonaws.com
127.0.0.1 eaassets-a.akamaihd.net
127.0.0.1 ssl.resources.ea.com
127.0.0.1 akamai.cdn.ea.com
127.0.0.1 novafusion.ea.com
127.0.0.1 proxy.novafusion.ea.com
127.0.0.1 ec2-23-23-167-200.compute-1.amazonaws.com
127.0.0.1 dirtybits.dm.origin.com
127.0.0.1 chat.dm.origin.com
127.0.0.1 easo.ea.com
127.0.0.1 ea.com
127.0.0.1 telemetry.simcity.com
127.0.0.1 ec2-54-228-227-181.eu-west-1.compute.amazonaws.com
127.0.0.1 ec2-46-137-177-16.eu-west-1.compute.amazonaws.com

There are 11 more lines.


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {274C4ACC-4C68-4B79-96FB-DBC72939416B} - System32\Tasks\{07B84F4C-CD57-43A9-973D-C2ECF6F666EE} => pcalua.exe -a C:\Total\TOTALCMD.EXE -d C:\Total
Task: {582EED7A-8124-4EE3-BACE-0A2CABF192F3} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-626980440-2269883898-3179777769-1001UA => C:\Users\Jirka\AppData\Local\Google\Update\GoogleUpdate.exe [2014-01-12] (Google Inc.)
Task: {A9609594-C831-4AB5-8932-E689788EC2C3} - System32\Tasks\Origin => C:\Windows\system32\config\systemprofile\AppData\Roaming\Origin\update.vbe [2014-09-09] () <==== ATTENTION
Task: {AC9CFF55-378D-4935-96CE-5983BEC13C54} - System32\Tasks\Launch HTC Sync Loader => C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe [2013-05-13] ()
Task: {BBE1F1A9-799E-49EE-963A-4449E032F8FB} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-08-21] (Piriform Ltd)
Task: {D42C0BE9-E143-4EDA-98FD-1FACA0B1026B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-05-23] (Adobe Systems Incorporated)
Task: {ECF4923D-604E-4481-859F-8294B4DA71F9} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\WatTask => C:\Windows Activation Technologies\wat.exe [2006-04-21] ()
Task: {FBB5091E-F657-4CF5-A162-B10C1302A352} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-626980440-2269883898-3179777769-1001Core => C:\Users\Jirka\AppData\Local\Google\Update\GoogleUpdate.exe [2014-01-12] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-626980440-2269883898-3179777769-1001Core.job => C:\Users\Jirka\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-626980440-2269883898-3179777769-1001UA.job => C:\Users\Jirka\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2013-09-16 17:36 - 2014-07-02 20:55 - 00116568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2014-06-02 20:14 - 2010-12-02 02:13 - 00216576 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\Software602.dll
2014-09-09 19:11 - 2006-04-21 07:42 - 00022016 _____ () C:\Windows Activation Technologies\wat.exe
2013-09-16 18:30 - 2007-09-02 13:58 - 00495616 _____ () C:\Program Files (x86)\RocketDock\RocketDock.exe
2013-09-16 18:30 - 2007-09-02 13:57 - 00069632 _____ () C:\Program Files (x86)\RocketDock\RocketDock.dll
2014-06-02 20:00 - 2008-09-29 13:09 - 00073728 _____ () C:\Program Files (x86)\Software602\Print2PDF\wcs.dll
2014-06-02 20:00 - 2008-09-29 13:09 - 00532480 _____ () C:\Program Files (x86)\Software602\Print2PDF\wc.dll
2013-09-16 17:30 - 2006-09-14 00:20 - 00126464 _____ () C:\Program Files (x86)\WinRAR\rarext.dll
2013-09-16 17:30 - 2006-09-14 17:29 - 00315392 _____ () C:\Program Files (x86)\WinRAR\rarlng.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-626980440-2269883898-3179777769-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 109.231.191.1 - 109.231.191.3

==================== MSCONFIG/TASK MANAGER Error getting ==

(Currently there is no automatic fix for this section.)

HKLM\...\StartupApproved\Run: => "PrintDisp"
HKLM\...\StartupApproved\Run: => "ShadowPlay"
HKLM\...\StartupApproved\Run32: => "KiesTrayAgent"
HKLM\...\StartupApproved\Run32: => "BigDog305"
HKLM\...\StartupApproved\Run32: => "NBKeyScan"
HKLM\...\StartupApproved\Run32: => "Adobe ARM"
HKLM\...\StartupApproved\Run32: => "iSkysoft Helper Compact.exe"
HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\StartupApproved\Run: => "KiesPreload"
HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\StartupApproved\Run: => ""
HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\StartupApproved\Run: => "KiesAirMessage"
HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\StartupApproved\Run: => "RGSC"
HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\StartupApproved\Run: => "EADM"
HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\StartupApproved\Run: => "Google Update"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppextcomobj.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppextcomobj.exe
FirewallRules: [{C650D07D-01B2-4E26-9901-E4D9C3EFE038}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{9D7711BD-AC92-4088-B379-217C028E043A}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{F5FE90EF-A115-423B-AE84-C8368966C6DA}] => (Allow) C:\Program Files\HP\HP Photosmart 5510 series\Bin\DeviceSetup.exe
FirewallRules: [{92C0380E-7952-4D49-8A61-3A81883E139B}] => (Allow) C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{0F790692-5876-42BB-8282-D9E936BC3FB4}] => (Allow) C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{E7E8E5E7-7431-4E72-AB6A-90D8F2E76544}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [TCP Query User{6094047A-9F05-4FAF-A2F8-F0957FD7883B}E:\torrenty\simcity\start.exe] => (Allow) E:\torrenty\simcity\start.exe
FirewallRules: [UDP Query User{6084B9EB-54DD-429E-9D9A-F2433DEBD753}E:\torrenty\simcity\start.exe] => (Allow) E:\torrenty\simcity\start.exe
FirewallRules: [TCP Query User{992F9C28-DC10-4C01-AA75-1F40E16A61F0}E:\torrenty\simcity\apache\httpd.exe] => (Allow) E:\torrenty\simcity\apache\httpd.exe
FirewallRules: [UDP Query User{37B559C1-B5A1-4DF4-859C-5057C4595DD1}E:\torrenty\simcity\apache\httpd.exe] => (Allow) E:\torrenty\simcity\apache\httpd.exe
FirewallRules: [TCP Query User{7FA4D68A-CE4E-45F4-9FCC-359EC1AB05E2}D:\games\world of tanks\wotlauncher.exe] => (Allow) D:\games\world of tanks\wotlauncher.exe
FirewallRules: [UDP Query User{EF6FE8AB-FF60-499B-886B-4FE62AB9F165}D:\games\world of tanks\wotlauncher.exe] => (Allow) D:\games\world of tanks\wotlauncher.exe
FirewallRules: [TCP Query User{78BB2AE3-FFC8-4AC3-9F50-75DD779799C5}D:\games\world of tanks\worldoftanks.exe] => (Allow) D:\games\world of tanks\worldoftanks.exe
FirewallRules: [UDP Query User{58B8E915-BE5A-4F96-B616-A7D1657BB294}D:\games\world of tanks\worldoftanks.exe] => (Allow) D:\games\world of tanks\worldoftanks.exe
FirewallRules: [{48CD59E3-084E-4DE8-8C35-871394650FA6}] => (Allow) C:\Users\Jirka\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{EBF964D7-DC5F-417E-B2B1-C9E695D968D2}] => (Allow) C:\Users\Jirka\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [TCP Query User{1F9B9B21-50D0-4B23-BD1F-5D5576BE72BE}D:\games\age of empires\game.dat] => (Allow) D:\games\age of empires\game.dat
FirewallRules: [UDP Query User{87EB7865-64C5-4185-9B84-456DD5902D36}D:\games\age of empires\game.dat] => (Allow) D:\games\age of empires\game.dat
FirewallRules: [TCP Query User{010C12F4-07F5-4B03-8F06-7EA9F81629E0}C:\program files (x86)\virtualdj\virtualdj_pro.exe] => (Block) C:\program files (x86)\virtualdj\virtualdj_pro.exe
FirewallRules: [UDP Query User{AB8E0E09-B00E-46F4-AD4E-C1E942B2CD56}C:\program files (x86)\virtualdj\virtualdj_pro.exe] => (Block) C:\program files (x86)\virtualdj\virtualdj_pro.exe
FirewallRules: [{8DC7E677-2880-430F-87E9-05E9144232F1}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 15\Programs\RM.exe
FirewallRules: [{15F6194E-D1E6-46A8-837D-9BF35352D18B}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 15\Programs\RM.exe
FirewallRules: [{AF7655DA-A122-4A75-86CB-C2A7A333AAE5}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 15\Programs\Studio.exe
FirewallRules: [{67DCED7B-6167-4F6C-8BD7-4246665101E5}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 15\Programs\Studio.exe
FirewallRules: [{7D3C3CF4-0EF9-41A5-A914-C1D9C3D66C90}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 15\Programs\umi.exe
FirewallRules: [{5B82AB0C-8FC1-4F21-B50C-57E6251E6C1D}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 15\Programs\umi.exe
FirewallRules: [{2324CF8B-0BCB-43F4-81BB-45F398E60A1B}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{1F1D04F2-CDE6-48F8-A503-82A79248D351}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{852AC0AC-3985-4807-A18B-0732DBDDA667}] => (Allow) D:\Games\Settlers 7 Gold\Data\Base\_Dbg\Bin\Release\Settlers7R.exe
FirewallRules: [{1A970232-011F-450A-87CB-BC15634C091D}] => (Allow) D:\Games\Settlers 7 Gold\Data\Base\_Dbg\Bin\Release\Settlers7R.exe
FirewallRules: [{3DE4E709-AC82-45FB-850B-1D2DACBF6E16}] => (Allow) D:\Games\RockstarGames\Grand Theft Auto IV\LaunchGTAIV.exe
FirewallRules: [{B12824A7-36AB-45D5-8DB2-DDA4B5A59B8F}] => (Allow) D:\Games\RockstarGames\Grand Theft Auto IV\LaunchGTAIV.exe
FirewallRules: [TCP Query User{D6437164-482B-44F1-81FC-08A4C2A5BECE}E:\torrenty\simcity\stunnel\tstunnel.exe] => (Allow) E:\torrenty\simcity\stunnel\tstunnel.exe
FirewallRules: [UDP Query User{D17086A0-3CC5-4A03-A95D-CED55EB3B8EA}E:\torrenty\simcity\stunnel\tstunnel.exe] => (Allow) E:\torrenty\simcity\stunnel\tstunnel.exe
FirewallRules: [TCP Query User{D38E13AF-482D-4052-BC06-0C5ACD47CDD2}D:\games\need for speed - most wanted\nfs13.exe] => (Allow) D:\games\need for speed - most wanted\nfs13.exe
FirewallRules: [UDP Query User{2EB2EDBD-0954-4899-A464-2370DD55F782}D:\games\need for speed - most wanted\nfs13.exe] => (Allow) D:\games\need for speed - most wanted\nfs13.exe
FirewallRules: [TCP Query User{68FA666B-32D2-4220-B518-FDEB68BFA435}C:\windows\syswow64\javaw.exe] => (Allow) C:\windows\syswow64\javaw.exe
FirewallRules: [UDP Query User{B877F6DB-711F-4813-9FB3-8169C0814B36}C:\windows\syswow64\javaw.exe] => (Allow) C:\windows\syswow64\javaw.exe
FirewallRules: [{CDCA330E-0B8D-4F75-8532-E89A8282E0DE}] => (Allow) C:\Users\Jirka\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{35E46C75-E4B0-4598-9F03-E72FA1952981}] => (Allow) C:\Users\Jirka\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{D64F10BC-E310-46F0-8735-E6C748827830}] => (Allow) D:\Games\SimCity\SimCity\SimCity.exe
FirewallRules: [{CB9C5667-70DB-40E6-92CA-3E3CBAED0B56}] => (Allow) D:\Games\SimCity\SimCity\SimCity.exe
FirewallRules: [{3474882F-9F33-4BE9-A96D-2159885B5C5A}] => (Allow) D:\Games\zoo\zt.exe
FirewallRules: [{7FCDFC98-1793-4D24-8332-66CC5D8F5EA1}] => (Allow) D:\Games\zoo\zt.exe
FirewallRules: [{FBDBC211-ABB6-4C40-976B-D0879F21DFBA}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{146BEFE2-604D-41AF-96DC-379D2AA494E4}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{763DFDCB-3F90-42F5-A853-F1171F701645}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{EB6CDE93-6E51-4679-B15C-A0B29AE35F46}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{D5B039B4-1AC0-40AC-9106-A4483A06C128}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{52EB6BA8-36D0-4F73-A91F-AE23D59497F0}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{C8A43C12-DB73-4713-A0AF-526A78EF9DDE}] => (Allow) C:\Windows\SysWOW64\muzapp.exe
FirewallRules: [{9C0B71B5-F09E-4E93-931F-B52B4D37DB2A}] => (Allow) C:\Windows\SysWOW64\muzapp.exe
FirewallRules: [{80515C18-0F7C-4E0F-9CD4-58EB56647478}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{1699D350-3F51-4258-8BE8-D4B9057D57B2}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{1DCFD896-C464-4F02-9343-2E49DCDC1424}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{FAB4D8C8-A988-4A96-B3E1-4587EF537B72}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{5F34963E-7B21-4055-B43D-3290702ABC7E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{FC2540AA-DF70-4E60-800B-1588C363F4FC}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{F086802F-BCFF-4B55-B93A-5216725614B0}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{5DBAE308-0237-4D59-ABF3-ADDA7B683F59}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (05/23/2015 11:03:45 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe, verze: 0.0.0.0, časové razítko: 0x53cfa27e
Název chybujícího modulu: svchost.exe, verze: 0.0.0.0, časové razítko: 0x53cfa27e
Kód výjimky: 0xc0000094
Posun chyby: 0x000000000002573a
ID chybujícího procesu: 0x11d0
Čas spuštění chybující aplikace: 0xsvchost.exe0
Cesta k chybující aplikaci: svchost.exe1
Cesta k chybujícímu modulu: svchost.exe2
ID zprávy: svchost.exe3
Úplný název chybujícího balíčku: svchost.exe4
ID aplikace související s chybujícím balíčkem: svchost.exe5

Error: (05/23/2015 11:01:29 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe, verze: 0.0.0.0, časové razítko: 0x53cfa27e
Název chybujícího modulu: svchost.exe, verze: 0.0.0.0, časové razítko: 0x53cfa27e
Kód výjimky: 0xc0000094
Posun chyby: 0x000000000002573a
ID chybujícího procesu: 0x848
Čas spuštění chybující aplikace: 0xsvchost.exe0
Cesta k chybující aplikaci: svchost.exe1
Cesta k chybujícímu modulu: svchost.exe2
ID zprávy: svchost.exe3
Úplný název chybujícího balíčku: svchost.exe4
ID aplikace související s chybujícím balíčkem: svchost.exe5

Error: (05/23/2015 09:19:37 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Název chybujícího modulu: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Kód výjimky: 0xc0000094
Posun chyby: 0x000000000002814d
ID chybujícího procesu: 0x1fe4
Čas spuštění chybující aplikace: 0xsvchost.exe0
Cesta k chybující aplikaci: svchost.exe1
Cesta k chybujícímu modulu: svchost.exe2
ID zprávy: svchost.exe3
Úplný název chybujícího balíčku: svchost.exe4
ID aplikace související s chybujícím balíčkem: svchost.exe5

Error: (05/23/2015 08:59:39 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Název chybujícího modulu: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Kód výjimky: 0xc0000094
Posun chyby: 0x000000000002814d
ID chybujícího procesu: 0x10c8
Čas spuštění chybující aplikace: 0xsvchost.exe0
Cesta k chybující aplikaci: svchost.exe1
Cesta k chybujícímu modulu: svchost.exe2
ID zprávy: svchost.exe3
Úplný název chybujícího balíčku: svchost.exe4
ID aplikace související s chybujícím balíčkem: svchost.exe5

Error: (05/23/2015 08:59:26 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Název chybujícího modulu: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Kód výjimky: 0xc0000094
Posun chyby: 0x000000000002814d
ID chybujícího procesu: 0x1b1c
Čas spuštění chybující aplikace: 0xsvchost.exe0
Cesta k chybující aplikaci: svchost.exe1
Cesta k chybujícímu modulu: svchost.exe2
ID zprávy: svchost.exe3
Úplný název chybujícího balíčku: svchost.exe4
ID aplikace související s chybujícím balíčkem: svchost.exe5

Error: (05/23/2015 08:59:25 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Název chybujícího modulu: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Kód výjimky: 0xc0000094
Posun chyby: 0x000000000002814d
ID chybujícího procesu: 0xe18
Čas spuštění chybující aplikace: 0xsvchost.exe0
Cesta k chybující aplikaci: svchost.exe1
Cesta k chybujícímu modulu: svchost.exe2
ID zprávy: svchost.exe3
Úplný název chybujícího balíčku: svchost.exe4
ID aplikace související s chybujícím balíčkem: svchost.exe5

Error: (05/16/2015 02:56:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Název chybujícího modulu: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Kód výjimky: 0xc0000094
Posun chyby: 0x000000000002814d
ID chybujícího procesu: 0x1ac8
Čas spuštění chybující aplikace: 0xsvchost.exe0
Cesta k chybující aplikaci: svchost.exe1
Cesta k chybujícímu modulu: svchost.exe2
ID zprávy: svchost.exe3
Úplný název chybujícího balíčku: svchost.exe4
ID aplikace související s chybujícím balíčkem: svchost.exe5

Error: (05/16/2015 02:32:11 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Název chybujícího modulu: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Kód výjimky: 0xc0000094
Posun chyby: 0x000000000002814d
ID chybujícího procesu: 0xa7c
Čas spuštění chybující aplikace: 0xsvchost.exe0
Cesta k chybující aplikaci: svchost.exe1
Cesta k chybujícímu modulu: svchost.exe2
ID zprávy: svchost.exe3
Úplný název chybujícího balíčku: svchost.exe4
ID aplikace související s chybujícím balíčkem: svchost.exe5

Error: (05/14/2015 08:03:35 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Název chybujícího modulu: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Kód výjimky: 0xc0000094
Posun chyby: 0x000000000002814d
ID chybujícího procesu: 0xcb8
Čas spuštění chybující aplikace: 0xsvchost.exe0
Cesta k chybující aplikaci: svchost.exe1
Cesta k chybujícímu modulu: svchost.exe2
ID zprávy: svchost.exe3
Úplný název chybujícího balíčku: svchost.exe4
ID aplikace související s chybujícím balíčkem: svchost.exe5

Error: (05/14/2015 08:02:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Název chybujícího modulu: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Kód výjimky: 0xc0000094
Posun chyby: 0x000000000002814d
ID chybujícího procesu: 0x82c
Čas spuštění chybující aplikace: 0xsvchost.exe0
Cesta k chybující aplikaci: svchost.exe1
Cesta k chybujícímu modulu: svchost.exe2
ID zprávy: svchost.exe3
Úplný název chybujícího balíčku: svchost.exe4
ID aplikace související s chybujícím balíčkem: svchost.exe5


System errors:
=============
Error: (05/23/2015 10:35:17 AM) (Source: DCOM) (EventID: 10016) (User: PC-Jirka)
Description: specifické pro aplikaciMístníSpuštění{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}PC-JirkaJirkaS-1-5-21-626980440-2269883898-3179777769-1001LocalHost (pomocí LRPC)Není k dispoziciNení k dispozici

Error: (05/23/2015 10:33:36 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Služba Služba Windows Media Player Network Sharing závisí na službě Windows Search, která neuspěla při spuštění v důsledku následující chyby:
%%1069

Error: (05/23/2015 10:33:36 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Windows Search neuspěla při spuštění v důsledku následující chyby:
%%1069

Error: (05/23/2015 10:33:36 AM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Služba WSearch se nemohla přihlásit jako NT AUTHORITY\SYSTEM s aktuálně konfigurovaným heslem z důvodu následující chyby:
%%50

Chcete-li zajistit správnou konfiguraci služby, použijte modul snap-in Služby konzoly Microsoft Management Console (MMC).

Error: (05/23/2015 10:33:35 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Windows Search neuspěla při spuštění v důsledku následující chyby:
%%1069

Error: (05/23/2015 10:33:35 AM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Služba WSearch se nemohla přihlásit jako NT AUTHORITY\SYSTEM s aktuálně konfigurovaným heslem z důvodu následující chyby:
%%50

Chcete-li zajistit správnou konfiguraci služby, použijte modul snap-in Služby konzoly Microsoft Management Console (MMC).

Error: (05/23/2015 10:33:06 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Služba Windows Media Player Network Sharing byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 30000 milisekund: Restartovat službu.

Error: (05/23/2015 10:33:05 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Windows Search byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 30000 milisekund: Restartovat službu.

Error: (05/23/2015 10:33:05 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Printer Control byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (05/23/2015 10:33:05 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba NVIDIA Streamer Service byla neočekávaně ukončena. Tento stav nastal již 1krát.


Microsoft Office:
=========================

CodeIntegrity Errors:
===================================
Date: 2014-01-30 19:18:05.061
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Moborobo\MoboroboAssDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info ===========================

Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 6000+
Percentage of memory in use: 25%
Total physical RAM: 4087.06 MB
Available physical RAM: 3038.14 MB
Total Pagefile: 4791.06 MB
Available Pagefile: 3667.04 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:58.5 GB) (Free:22.53 GB) NTFS
Drive d: (Download) (Fixed) (Total:407.16 GB) (Free:253.44 GB) NTFS
Drive e: (Hudba) (Fixed) (Total:931.51 GB) (Free:353.29 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 2B072B06)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=58.5 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=407.2 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 931.5 GB) (Disk ID: C5365980)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=42)

==================== End of log ============================

Re: Prosím o kontrolu

Napsal: 23 kvě 2015 11:22
od georgdj
Takže vypadá to, že to svinstvo je pryč. Mockrát děkuju za pomoc. Jsi vážně machr. Ještě jednou díky.
Posílám ještě pro jistotu log a v příloze ty archivované soubory.
:) :| :happy:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22-05-2015 01
Ran by Jirka (administrator) on PC-JIRKA on 23-05-2015 12:18:00
Running from C:\Users\Jirka\Desktop
Loaded Profiles: Jirka (Available Profiles: Jirka)
Platform: Windows 8 Enterprise (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 10 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Software602 a.s.) C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe
(Microsoft Corporation) C:\Windows\System32\wscript.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) C:\Windows\System32\PrintCtrl.exe
(ActMask Co.,Ltd - http://www.all2pdf.com) C:\Windows\System32\PrintDisp.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Realtek Semiconductor) C:\Windows\RAVCpl64.exe
() C:\Program Files (x86)\RocketDock\RocketDock.exe
(Software602) C:\Program Files (x86)\Software602\Print2PDF\Print2PDF.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Software602 a.s.) C:\Program Files (x86)\Software602\Print2PDF\Installer.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\Run: [RtHDVCpl] => C:\Windows\RAVCpl64.exe [6471200 2008-08-27] (Realtek Semiconductor)
HKLM-x32\...\Run: [Skytel] => C:\Windows\Skytel.exe [1833504 2008-08-27] (Realtek Semiconductor Corp.)
HKLM-x32\...\Run: [PrintDisp] => C:\Windows\system32\PrintDisp.exe [870400 2012-10-29] (ActMask Co.,Ltd - http://www.all2pdf.com)
HKLM-x32\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161984 2014-04-20] (IvoSoft)
HKLM-x32\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2403104 2014-07-25] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [BigDog305] => C:\Windows\VM305_STI.EXE [57344 2007-04-09] (VM305SNAP)
HKLM-x32\...\Run: [Print2PDF Print Monitor] => C:\Program Files (x86)\Software602\Print2PDF\Print2PDF.exe [222776 2011-04-12] (Software602)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [iSkysoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe [2000896 2014-04-04] (iSkySoft)
HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [310064 2014-06-14] (Samsung Electronics Co., Ltd.)
HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\Run: [RocketDock] => C:\Program Files (x86)\RocketDock\RocketDock.exe [495616 2007-09-02] ()
HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\Run: [Google Update] => C:\Users\Jirka\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2014-01-12] (Google Inc.)
HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\MountPoints2: {c40e06aa-1ef7-11e3-be69-001fd0ddbfca} - "G:\autorun.exe"
Startup: C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sidebar.lnk [2013-09-16]
ShortcutTarget: Sidebar.lnk -> C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-04-20] (IvoSoft)
ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20] (IvoSoft)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-626980440-2269883898-3179777769-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-626980440-2269883898-3179777769-1001 -> {3D5FD8A2-6B52-45D9-8C35-0F13256F4292} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_13415
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-04-20] (IvoSoft)
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2014-04-20] (IvoSoft)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20] (IvoSoft)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-12-18] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-12-18] (Oracle Corporation)
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2014-04-20] (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-04-20] (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20] (IvoSoft)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 109.231.191.1 109.231.191.3

FireFox:
========
FF ProfilePath: C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\m8es3xti.default
FF Homepage: www.seznam.cz
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_188.dll [2015-05-23] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_188.dll [2015-05-23] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-07-12] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2013-12-18] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2013-12-18] (Oracle Corporation)
FF Plugin-x32: @nullsoft.com/winampDetector;version=1 -> C:\Program Files (x86)\Winamp Detect\npwachk.dll [2013-07-24] (Nullsoft, Inc.)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2014-07-02] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2014-07-02] (NVIDIA Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll No File
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll No File
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-626980440-2269883898-3179777769-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Jirka\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-04-28] (Google Inc.)
FF Plugin HKU\S-1-5-21-626980440-2269883898-3179777769-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Jirka\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-04-28] (Google Inc.)
FF Plugin HKU\S-1-5-21-626980440-2269883898-3179777769-1001: ubisoft.com/uplaypc -> D:\Games\Settlers 7 Gold\Data\Base\_Dbg\Bin\Release\orbit\npuplaypc.dll [2013-02-26] (Ubisoft)
FF Extension: Forecastfox - C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\m8es3xti.default\Extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3} [2013-09-16]
FF Extension: 1-Click Dailymotion Video Downloader - C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\m8es3xti.default\Extensions\DailymotionVideoDownloader@PeterOlayev.com.xpi [2013-12-14]
FF Extension: Download YouTube Videos as MP4 - C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\m8es3xti.default\Extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi [2013-12-27]

Chrome:
=======
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/"
CHR Profile: C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-09-18]
CHR Extension: (Google Drive) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-09-18]
CHR Extension: (YouTube) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-09-18]
CHR Extension: (Google Search) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-09-18]
CHR Extension: (Google Wallet) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-29]
CHR Extension: (Gmail) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-09-18]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 602XML Updater; C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe [73728 2010-04-14] (Software602 a.s.) []
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [537896 2008-06-24] (Nero AG)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1720608 2014-07-25] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18956064 2014-07-25] (NVIDIA Corporation)
R2 Printer Control; C:\Windows\system32\PrintCtrl.exe [121856 2012-10-21] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) []
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5426448 2014-12-15] (TeamViewer GmbH)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 61883; C:\Windows\System32\drivers\61883.sys [61440 2012-07-26] (Microsoft Corporation)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283200 2013-09-17] (DT Soft Ltd)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-05-23] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-04-14] (Malwarebytes Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-07-25] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19152 2013-09-30] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] ()
S3 Rockusb; C:\Windows\System32\drivers\rockusb.sys [65688 2013-03-11] (Fuzhou Rockchip Electronics Co,Ltd.)
R3 vvftav; C:\Windows\system32\drivers\vvftav.sys [300800 2007-06-23] (Vimicro Corporation)
R3 ZSMC0305; C:\Windows\System32\Drivers\usbVM305.sys [1541120 2007-03-08] (Vimicro Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-05-23 12:18 - 2015-05-23 12:18 - 00014086 _____ () C:\Users\Jirka\Desktop\FRST.txt
2015-05-23 11:26 - 2015-05-23 11:26 - 00046304 _____ () C:\Archivace.rar
2015-05-23 11:15 - 2015-05-23 11:20 - 00000000 ____D () C:\Archivace
2015-05-23 11:02 - 2015-05-23 11:02 - 00000235 _____ () C:\Users\Jirka\Documents\export.rar
2015-05-23 11:01 - 2015-05-23 11:01 - 00000348 _____ () C:\Users\Jirka\Documents\export.reg
2015-05-23 10:27 - 2015-05-23 12:18 - 00000000 ____D () C:\FRST
2015-05-23 10:27 - 2015-05-23 10:27 - 02108416 _____ (Farbar) C:\Users\Jirka\Desktop\FRST64.exe
2015-05-23 10:25 - 2015-05-23 10:40 - 00000000 ____D () C:\AdwCleaner
2015-05-23 10:25 - 2015-05-23 10:25 - 02223104 _____ () C:\Users\Jirka\Desktop\adwcleaner_4.205.exe
2015-05-23 10:11 - 2015-05-23 10:11 - 00008471 _____ () C:\Users\Jirka\Desktop\hijackthis.log
2015-05-23 10:03 - 2015-05-23 10:03 - 00388608 _____ (Trend Micro Inc.) C:\Users\Jirka\Desktop\hijackthis.exe
2015-05-23 09:56 - 2015-05-23 09:59 - 00000042 _____ () C:\Users\Jirka\Desktop\Skylink.txt

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-05-23 12:15 - 2014-09-29 18:15 - 00013748 _____ () C:\Windows\PFRO.log
2015-05-23 12:15 - 2013-09-16 17:36 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-05-23 12:15 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-23 12:14 - 2014-02-16 15:35 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\ClassicShell
2015-05-23 12:14 - 2013-09-16 19:10 - 00001940 _____ () C:\Windows\WINCMD.INI
2015-05-23 12:11 - 2013-09-17 18:39 - 00000000 ____D () C:\ProgramData\Electronic Arts
2015-05-23 12:11 - 2013-09-17 18:29 - 00000000 ____D () C:\ProgramData\Origin
2015-05-23 12:09 - 2012-07-26 12:01 - 00726246 _____ () C:\Windows\system32\perfh005.dat
2015-05-23 12:09 - 2012-07-26 12:01 - 00147800 _____ () C:\Windows\system32\perfc005.dat
2015-05-23 12:09 - 2012-07-26 09:28 - 01714430 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-23 12:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2015-05-23 11:50 - 2013-09-16 18:22 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-05-23 11:37 - 2014-01-12 16:58 - 00000980 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-626980440-2269883898-3179777769-1001UA.job
2015-05-23 11:17 - 2013-09-17 18:30 - 00000000 ___HD () C:\Users\Jirka\AppData\Roaming\Origin
2015-05-23 11:16 - 2013-09-16 17:25 - 00000000 ____D () C:\Users\Jirka
2015-05-23 10:11 - 2014-08-01 19:17 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-05-23 10:06 - 2013-09-16 20:04 - 00000000 ____D () C:\Windows\EffectResources
2015-05-23 09:47 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2015-05-23 09:38 - 2014-09-29 18:16 - 00429648 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-05-23 09:38 - 2014-01-12 16:58 - 00000928 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-626980440-2269883898-3179777769-1001Core.job
2015-05-23 09:38 - 2013-09-16 18:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-05-23 09:38 - 2012-07-26 10:18 - 00000000 ____D () C:\Windows\DigitalLocker
2015-05-23 09:36 - 2013-11-17 18:03 - 00000000 ____D () C:\Program Files (x86)\MOBILedit! Forensic
2015-05-23 09:22 - 2014-08-01 19:17 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-05-23 09:22 - 2014-08-01 19:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-05-23 09:22 - 2014-08-01 19:17 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-05-23 09:21 - 2014-09-01 16:33 - 00000000 ____D () C:\Users\Jirka\AppData\Local\Adobe
2015-05-23 09:12 - 2014-09-14 08:41 - 01103642 _____ () C:\Windows\WindowsUpdate.log
2015-05-14 18:22 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent
2015-05-14 18:20 - 2013-09-16 18:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox

==================== Files in the root of some directories =======

2013-10-20 19:36 - 2014-05-04 12:18 - 0008192 _____ () C:\Users\Jirka\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-07-08 17:51 - 2014-07-08 17:51 - 0000001 _____ () C:\Users\Jirka\AppData\Local\RawCopy.1.01.agreement
2014-07-08 17:52 - 2014-07-08 17:52 - 0000003 _____ () C:\Users\Jirka\AppData\Local\RawCopy.savedialog.dir
2014-07-08 17:52 - 2014-07-08 17:52 - 0000001 _____ () C:\Users\Jirka\AppData\Local\RawCopy.savedialog.filterindex
2014-07-08 17:51 - 2014-07-08 17:51 - 0000001 _____ () C:\Users\Jirka\AppData\Local\RawCopy.sourcedisk.index
2014-08-31 17:05 - 2014-08-31 17:05 - 0000017 _____ () C:\Users\Jirka\AppData\Local\resmon.resmoncfg
2013-10-31 21:26 - 2013-10-31 22:39 - 0024431 _____ () C:\Users\Jirka\AppData\Local\SRDownloader.err
2013-09-17 17:13 - 2014-01-29 18:40 - 0001136 _____ () C:\Users\Jirka\AppData\Local\SRDownloader.nast
2013-09-16 19:51 - 2013-09-16 19:51 - 0000057 _____ () C:\ProgramData\Ament.ini

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-05-11 20:55

==================== End of log ============================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-05-2015 01
Ran by Jirka at 2015-05-23 12:19:01
Running from C:\Users\Jirka\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-626980440-2269883898-3179777769-500 - Administrator - Disabled)
Guest (S-1-5-21-626980440-2269883898-3179777769-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-626980440-2269883898-3179777769-1003 - Limited - Enabled)
Jirka (S-1-5-21-626980440-2269883898-3179777769-1001 - Administrator - Enabled) => C:\Users\Jirka

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

«Need for Speed - Most Wanted» 1.5 (HKLM-x32\...\{FB0127F3-985B-44CE-AE29-378CAF60B361}_is1) (Version: 1.5 - Electronic Arts)
µTorrent (HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\uTorrent) (Version: 3.4.2.35702 - BitTorrent Inc.)
7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - )
8GadgetPack (HKLM-x32\...\{F7EF899D-0339-4279-8FB1-96801D829A3F}) (Version: 8.0.1 - Helmut Buhler)
A4 TECH PC Camera V (HKLM-x32\...\{8AD824A5-1CCC-4BB7-82C9-E6FB25CC0479}) (Version: 2007.07.30 - A4)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.7.0.1530 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.188 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.08) - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated)
Age Of Empires II HD v2.5 [LAN Edition] (HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\Age Of Empires II HD v2.5 [LAN Edition]) (Version: - )
Aktualizace NVIDIA 15.3.33 (Version: 15.3.33 - NVIDIA Corporation) Hidden
AVI to 3GP (HKLM-x32\...\{AE4E8D53-2D05-4EB4-A1E7-FF48B8E76DDE}_is1) (Version: - www.avito3gp.com)
BS.Player FREE (HKLM-x32\...\BSPlayerf) (Version: 2.66.1075 - AB Team, d.o.o.)
CCleaner (HKLM\...\CCleaner) (Version: 4.17 - Piriform)
CDex - Open Source Digital Audio CD Extractor (HKLM-x32\...\CDex) (Version: 1.70.4.2009 - Georgy Berdyshev)
Classic Shell (HKLM\...\{840C85B7-D3D6-4143-9AF9-DAE80FD54CFC}) (Version: 4.1.0 - IvoSoft)
Čeština pro GTA IV v1.0.7.0 1.0.7.0 (HKLM-x32\...\Čeština pro GTA IV v1.0.7.0 1.0.7.0) (Version: - )
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.47.1.0333 - Disc Soft Ltd)
Google Earth (HKLM-x32\...\{96AD3B61-EAE2-11E2-9E72-B8AC6F98CCE3}) (Version: 7.1.1.1888 - Google)
Google Chrome (HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\Google Chrome) (Version: 42.0.2311.152 - Google Inc.)
Grand Theft Auto IV (HKLM-x32\...\{579BA58C-F33D-4970-9953-B94B43768AC3}) (Version: 1.00.0000 - Rockstar Games)
Grand Theft Auto IV (x32 Version: 1.0.0013.131 - Rockstar Games Inc.) Hidden
HTC BMP USB Driver (HKLM-x32\...\{31A559C1-9E4D-423B-9DD3-34A6C5398752}) (Version: 1.0.5375 - HTC)
HTC Driver Installer (HKLM-x32\...\{4CEEE5D0-F905-4688-B9F9-ECC710507796}) (Version: 4.1.0.001 - HTC Corporation)
HTC Sync (HKLM-x32\...\{C4494248-6D52-4674-B8CF-9177EA3F92F8}) (Version: 3.3.53 - HTC Corporation)
Infix PDF Editor verze 6.1.9.0 (HKLM-x32\...\83FFB914-6FA7-4F1F-807E-E0FFBA2E49E1_is1) (Version: 6.1.9.0 - Iceni Technology)
Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217040FF}) (Version: 7.0.510 - Oracle)
K-Lite Mega Codec Pack 10.4.0 (HKLM-x32\...\KLiteCodecPack_is1) (Version: 10.4.0 - )
Malwarebytes Anti-Malware verze 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
MegaTrainer eXperience V1.1.5.3 (HKLM-x32\...\MegaTrainer eXperience_is1) (Version: - )
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x64 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
MiniTool Partition Wizard Home Edition 8.1.1 (HKLM-x32\...\{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1) (Version: - MiniTool Solution Ltd.)
Mozilla Firefox 37.0.2 (x86 cs) (HKLM-x32\...\Mozilla Firefox 37.0.2 (x86 cs)) (Version: 37.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 35.0.1 - Mozilla)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
Nero 8 (HKLM-x32\...\{6D45EF03-E8EE-4355-81C3-F918CBCF1029}) (Version: 8.3.309 - Nero AG)
NVIDIA GeForce Experience 2.1.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.1 - NVIDIA Corporation)
NVIDIA Ovladač 3D Vision 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 340.52 - NVIDIA Corporation)
NVIDIA Ovladač řídící jednotky 3D Vision 340.50 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 340.50 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 340.52 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
Ovládací panel NVIDIA 340.52 (Version: 340.52 - NVIDIA Corporation) Hidden
Ovladače videa společnosti Pinnacle (HKLM\...\{6DE721A5-5E89-4D74-994C-652BB3C0672E}) (Version: 12.1.0.030 - Pinnacle Systems)
Pinnacle Studio 15 (HKLM-x32\...\{1362E602-9625-42D3-B57F-CDA9D26F9DA8}) (Version: 15.0.0.7593 - Pinnacle Systems)
Pinnacle Studio 15 Ultimate Plugins (HKLM-x32\...\{EB5DF19E-75D5-4FF1-AE23-2A9A2E0F2BDD}) (Version: 15.0.0.7593 - Pinnacle Systems)
Pinnacle Studio Bonus Content (HKLM-x32\...\{FC030CB5-46A6-4229-AD6E-0AC869F509C8}) (Version: 15.0.0.51 - Pinnacle Systems)
ProgDVB (HKLM-x32\...\ProgDVB) (Version: 6.9x - Prog)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0024 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5694 - Realtek Semiconductor Corp.)
RocketDock 1.3.5 (HKLM-x32\...\RocketDock_is1) (Version: - Punk Software)
Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.3.14044_17 - Samsung Electronics Co., Ltd.)
Samsung Kies (x32 Version: 2.6.3.14044_17 - Samsung Electronics Co., Ltd.) Hidden
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.14083.17 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (x32 Version: 3.2.14083.17 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.45.0 - SAMSUNG Electronics Co., Ltd.)
SHIELD Streaming (Version: 3.1.100 - NVIDIA Corporation) Hidden
Sim Aquarium 3 (HKLM-x32\...\Sim Aquarium 3_is1) (Version: 3 - Ladislav Vojnic)
SimCity™ (HKLM-x32\...\{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}) (Version: 1.0.0.0 - Electronic Arts)
Skype™ 6.22 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.22.107 - Skype Technologies S.A.)
Software602 Print2PDF (HKLM-x32\...\{32C74893-0243-4235-A6F3-201F0E5D2C03}) (Version: 9.1.11.0421 - Software602 a.s.)
Subtitle Workshop 2.51 (HKLM-x32\...\SubtitleWorkshop) (Version: - )
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.36897 - TeamViewer)
The Settlers 7 - Paths to a Kingdom (HKLM-x32\...\{63860309-DA8A-4BAE-9EAE-CE1D6D79340C}) (Version: 1.12.1396 - Ubisoft)
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
USB PC Camera VC305 (HKLM-x32\...\{ADE16A9D-FBDC-4ECC-B6BD-9C31E51D0305}) (Version: - )
VCRedistSetup (x32 Version: 1.0.0 - Nero AG) Hidden
VirtualDJ 8 (HKLM-x32\...\{9ADBBA93-4625-4898-BB0D-BCE7EA9F8B4A}) (Version: 8.0.0 - Atomix Productions)
VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN)
Winamp (HKLM-x32\...\Winamp) (Version: 5.65 - Nullsoft, Inc)
Winamp Detector Plug-in (HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc)
WinRAR (HKLM-x32\...\WinRAR archiver) (Version: - )
World of Tanks (HKLM-x32\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812EU}_is1) (Version: - Wargaming.net)
Yawcam 0.4.1 (HKLM-x32\...\{8FE96B14-E1F9-47BF-8BA1-A81467CD259B}_is1) (Version: - )
Základní software zařízení HP Photosmart 5510 series (HKLM\...\{22E8B03A-9094-45AC-910A-CB491A16A593}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
Zoo Tycoon 2 (HKLM-x32\...\Zoo Tycoon 2) (Version: 1.0 - Microsoft)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-626980440-2269883898-3179777769-1001_Classes\CLSID\{0E7BE950-4ACC-47CB-834B-41A8B96BBFF9}\InprocServer32 -> C:\Users\Jirka\AppData\Local\Microsoft\Windows Sidebar\Gadgets\Sidebar7.gadget\Release\Sidebar7.64.dll (Helmut Buhler)
CustomCLSID: HKU\S-1-5-21-626980440-2269883898-3179777769-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Jirka\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-626980440-2269883898-3179777769-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Jirka\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-626980440-2269883898-3179777769-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Jirka\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-626980440-2269883898-3179777769-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Jirka\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-626980440-2269883898-3179777769-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Jirka\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll (Google Inc.)

==================== Restore Points =========================


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2012-07-26 07:26 - 2015-05-23 12:13 - 00000000 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {274C4ACC-4C68-4B79-96FB-DBC72939416B} - \{07B84F4C-CD57-43A9-973D-C2ECF6F666EE} No Task File <==== ATTENTION
Task: {582EED7A-8124-4EE3-BACE-0A2CABF192F3} - \GoogleUpdateTaskUserS-1-5-21-626980440-2269883898-3179777769-1001UA No Task File <==== ATTENTION
Task: {A9609594-C831-4AB5-8932-E689788EC2C3} - \Origin No Task File <==== ATTENTION
Task: {AC9CFF55-378D-4935-96CE-5983BEC13C54} - \Launch HTC Sync Loader No Task File <==== ATTENTION
Task: {BBE1F1A9-799E-49EE-963A-4449E032F8FB} - \CCleanerSkipUAC No Task File <==== ATTENTION
Task: {D42C0BE9-E143-4EDA-98FD-1FACA0B1026B} - \Adobe Flash Player Updater No Task File <==== ATTENTION
Task: {ECF4923D-604E-4481-859F-8294B4DA71F9} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\WatTask => C:\Windows Activation Technologies\wat.exe [2006-04-21] ()
Task: {FBB5091E-F657-4CF5-A162-B10C1302A352} - \GoogleUpdateTaskUserS-1-5-21-626980440-2269883898-3179777769-1001Core No Task File <==== ATTENTION
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-626980440-2269883898-3179777769-1001Core.job => C:\Users\Jirka\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-626980440-2269883898-3179777769-1001UA.job => C:\Users\Jirka\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2013-09-16 17:36 - 2014-07-02 20:55 - 00116568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2014-06-02 20:14 - 2010-12-02 02:13 - 00216576 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\Software602.dll
2013-09-16 18:30 - 2007-09-02 13:58 - 00495616 _____ () C:\Program Files (x86)\RocketDock\RocketDock.exe
2013-09-16 18:30 - 2007-09-02 13:57 - 00069632 _____ () C:\Program Files (x86)\RocketDock\RocketDock.dll
2014-06-02 20:00 - 2008-09-29 13:09 - 00073728 _____ () C:\Program Files (x86)\Software602\Print2PDF\wcs.dll
2014-06-02 20:00 - 2008-09-29 13:09 - 00532480 _____ () C:\Program Files (x86)\Software602\Print2PDF\wc.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-626980440-2269883898-3179777769-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 109.231.191.1 - 109.231.191.3

==================== MSCONFIG/TASK MANAGER Error getting ==

(Currently there is no automatic fix for this section.)

HKLM\...\StartupApproved\Run: => "PrintDisp"
HKLM\...\StartupApproved\Run: => "ShadowPlay"
HKLM\...\StartupApproved\Run32: => "KiesTrayAgent"
HKLM\...\StartupApproved\Run32: => "BigDog305"
HKLM\...\StartupApproved\Run32: => "NBKeyScan"
HKLM\...\StartupApproved\Run32: => "Adobe ARM"
HKLM\...\StartupApproved\Run32: => "iSkysoft Helper Compact.exe"
HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\StartupApproved\Run: => "KiesPreload"
HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\StartupApproved\Run: => ""
HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\StartupApproved\Run: => "KiesAirMessage"
HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\StartupApproved\Run: => "RGSC"
HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\StartupApproved\Run: => "EADM"
HKU\S-1-5-21-626980440-2269883898-3179777769-1001\...\StartupApproved\Run: => "Google Update"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppextcomobj.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppextcomobj.exe
FirewallRules: [{C650D07D-01B2-4E26-9901-E4D9C3EFE038}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{9D7711BD-AC92-4088-B379-217C028E043A}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{F5FE90EF-A115-423B-AE84-C8368966C6DA}] => (Allow) C:\Program Files\HP\HP Photosmart 5510 series\Bin\DeviceSetup.exe
FirewallRules: [{92C0380E-7952-4D49-8A61-3A81883E139B}] => (Allow) C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{0F790692-5876-42BB-8282-D9E936BC3FB4}] => (Allow) C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{E7E8E5E7-7431-4E72-AB6A-90D8F2E76544}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [TCP Query User{6094047A-9F05-4FAF-A2F8-F0957FD7883B}E:\torrenty\simcity\start.exe] => (Allow) E:\torrenty\simcity\start.exe
FirewallRules: [UDP Query User{6084B9EB-54DD-429E-9D9A-F2433DEBD753}E:\torrenty\simcity\start.exe] => (Allow) E:\torrenty\simcity\start.exe
FirewallRules: [TCP Query User{992F9C28-DC10-4C01-AA75-1F40E16A61F0}E:\torrenty\simcity\apache\httpd.exe] => (Allow) E:\torrenty\simcity\apache\httpd.exe
FirewallRules: [UDP Query User{37B559C1-B5A1-4DF4-859C-5057C4595DD1}E:\torrenty\simcity\apache\httpd.exe] => (Allow) E:\torrenty\simcity\apache\httpd.exe
FirewallRules: [TCP Query User{7FA4D68A-CE4E-45F4-9FCC-359EC1AB05E2}D:\games\world of tanks\wotlauncher.exe] => (Allow) D:\games\world of tanks\wotlauncher.exe
FirewallRules: [UDP Query User{EF6FE8AB-FF60-499B-886B-4FE62AB9F165}D:\games\world of tanks\wotlauncher.exe] => (Allow) D:\games\world of tanks\wotlauncher.exe
FirewallRules: [TCP Query User{78BB2AE3-FFC8-4AC3-9F50-75DD779799C5}D:\games\world of tanks\worldoftanks.exe] => (Allow) D:\games\world of tanks\worldoftanks.exe
FirewallRules: [UDP Query User{58B8E915-BE5A-4F96-B616-A7D1657BB294}D:\games\world of tanks\worldoftanks.exe] => (Allow) D:\games\world of tanks\worldoftanks.exe
FirewallRules: [{48CD59E3-084E-4DE8-8C35-871394650FA6}] => (Allow) C:\Users\Jirka\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{EBF964D7-DC5F-417E-B2B1-C9E695D968D2}] => (Allow) C:\Users\Jirka\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [TCP Query User{1F9B9B21-50D0-4B23-BD1F-5D5576BE72BE}D:\games\age of empires\game.dat] => (Allow) D:\games\age of empires\game.dat
FirewallRules: [UDP Query User{87EB7865-64C5-4185-9B84-456DD5902D36}D:\games\age of empires\game.dat] => (Allow) D:\games\age of empires\game.dat
FirewallRules: [TCP Query User{010C12F4-07F5-4B03-8F06-7EA9F81629E0}C:\program files (x86)\virtualdj\virtualdj_pro.exe] => (Block) C:\program files (x86)\virtualdj\virtualdj_pro.exe
FirewallRules: [UDP Query User{AB8E0E09-B00E-46F4-AD4E-C1E942B2CD56}C:\program files (x86)\virtualdj\virtualdj_pro.exe] => (Block) C:\program files (x86)\virtualdj\virtualdj_pro.exe
FirewallRules: [{8DC7E677-2880-430F-87E9-05E9144232F1}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 15\Programs\RM.exe
FirewallRules: [{15F6194E-D1E6-46A8-837D-9BF35352D18B}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 15\Programs\RM.exe
FirewallRules: [{AF7655DA-A122-4A75-86CB-C2A7A333AAE5}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 15\Programs\Studio.exe
FirewallRules: [{67DCED7B-6167-4F6C-8BD7-4246665101E5}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 15\Programs\Studio.exe
FirewallRules: [{7D3C3CF4-0EF9-41A5-A914-C1D9C3D66C90}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 15\Programs\umi.exe
FirewallRules: [{5B82AB0C-8FC1-4F21-B50C-57E6251E6C1D}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 15\Programs\umi.exe
FirewallRules: [{2324CF8B-0BCB-43F4-81BB-45F398E60A1B}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{1F1D04F2-CDE6-48F8-A503-82A79248D351}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{852AC0AC-3985-4807-A18B-0732DBDDA667}] => (Allow) D:\Games\Settlers 7 Gold\Data\Base\_Dbg\Bin\Release\Settlers7R.exe
FirewallRules: [{1A970232-011F-450A-87CB-BC15634C091D}] => (Allow) D:\Games\Settlers 7 Gold\Data\Base\_Dbg\Bin\Release\Settlers7R.exe
FirewallRules: [{3DE4E709-AC82-45FB-850B-1D2DACBF6E16}] => (Allow) D:\Games\RockstarGames\Grand Theft Auto IV\LaunchGTAIV.exe
FirewallRules: [{B12824A7-36AB-45D5-8DB2-DDA4B5A59B8F}] => (Allow) D:\Games\RockstarGames\Grand Theft Auto IV\LaunchGTAIV.exe
FirewallRules: [TCP Query User{D6437164-482B-44F1-81FC-08A4C2A5BECE}E:\torrenty\simcity\stunnel\tstunnel.exe] => (Allow) E:\torrenty\simcity\stunnel\tstunnel.exe
FirewallRules: [UDP Query User{D17086A0-3CC5-4A03-A95D-CED55EB3B8EA}E:\torrenty\simcity\stunnel\tstunnel.exe] => (Allow) E:\torrenty\simcity\stunnel\tstunnel.exe
FirewallRules: [TCP Query User{D38E13AF-482D-4052-BC06-0C5ACD47CDD2}D:\games\need for speed - most wanted\nfs13.exe] => (Allow) D:\games\need for speed - most wanted\nfs13.exe
FirewallRules: [UDP Query User{2EB2EDBD-0954-4899-A464-2370DD55F782}D:\games\need for speed - most wanted\nfs13.exe] => (Allow) D:\games\need for speed - most wanted\nfs13.exe
FirewallRules: [TCP Query User{68FA666B-32D2-4220-B518-FDEB68BFA435}C:\windows\syswow64\javaw.exe] => (Allow) C:\windows\syswow64\javaw.exe
FirewallRules: [UDP Query User{B877F6DB-711F-4813-9FB3-8169C0814B36}C:\windows\syswow64\javaw.exe] => (Allow) C:\windows\syswow64\javaw.exe
FirewallRules: [{CDCA330E-0B8D-4F75-8532-E89A8282E0DE}] => (Allow) C:\Users\Jirka\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{35E46C75-E4B0-4598-9F03-E72FA1952981}] => (Allow) C:\Users\Jirka\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{D64F10BC-E310-46F0-8735-E6C748827830}] => (Allow) D:\Games\SimCity\SimCity\SimCity.exe
FirewallRules: [{CB9C5667-70DB-40E6-92CA-3E3CBAED0B56}] => (Allow) D:\Games\SimCity\SimCity\SimCity.exe
FirewallRules: [{3474882F-9F33-4BE9-A96D-2159885B5C5A}] => (Allow) D:\Games\zoo\zt.exe
FirewallRules: [{7FCDFC98-1793-4D24-8332-66CC5D8F5EA1}] => (Allow) D:\Games\zoo\zt.exe
FirewallRules: [{FBDBC211-ABB6-4C40-976B-D0879F21DFBA}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{146BEFE2-604D-41AF-96DC-379D2AA494E4}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{763DFDCB-3F90-42F5-A853-F1171F701645}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{EB6CDE93-6E51-4679-B15C-A0B29AE35F46}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{D5B039B4-1AC0-40AC-9106-A4483A06C128}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{52EB6BA8-36D0-4F73-A91F-AE23D59497F0}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{C8A43C12-DB73-4713-A0AF-526A78EF9DDE}] => (Allow) C:\Windows\SysWOW64\muzapp.exe
FirewallRules: [{9C0B71B5-F09E-4E93-931F-B52B4D37DB2A}] => (Allow) C:\Windows\SysWOW64\muzapp.exe
FirewallRules: [{80515C18-0F7C-4E0F-9CD4-58EB56647478}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{1699D350-3F51-4258-8BE8-D4B9057D57B2}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{1DCFD896-C464-4F02-9343-2E49DCDC1424}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{FAB4D8C8-A988-4A96-B3E1-4587EF537B72}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{5F34963E-7B21-4055-B43D-3290702ABC7E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{FC2540AA-DF70-4E60-800B-1588C363F4FC}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{F086802F-BCFF-4B55-B93A-5216725614B0}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{5DBAE308-0237-4D59-ABF3-ADDA7B683F59}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (05/23/2015 00:15:59 PM) (Source: SideBySide) (EventID: 72) (User: )
Description: Generování kontextu aktivace pro security1 se nezdařilo. Chyba v souboru manifestu nebo zásady security2 na řádku security3.
Prvek security je zřejmě podřízeným prvku urn:schemas-microsoft-com:asm.v1^assembly, což tato verze systému Windows nepodporuje.

Error: (05/23/2015 00:05:07 PM) (Source: SideBySide) (EventID: 72) (User: )
Description: Generování kontextu aktivace pro security1 se nezdařilo. Chyba v souboru manifestu nebo zásady security2 na řádku security3.
Prvek security je zřejmě podřízeným prvku urn:schemas-microsoft-com:asm.v1^assembly, což tato verze systému Windows nepodporuje.

Error: (05/23/2015 00:05:03 PM) (Source: SideBySide) (EventID: 72) (User: )
Description: Generování kontextu aktivace pro security1 se nezdařilo. Chyba v souboru manifestu nebo zásady security2 na řádku security3.
Prvek security je zřejmě podřízeným prvku urn:schemas-microsoft-com:asm.v1^assembly, což tato verze systému Windows nepodporuje.

Error: (05/23/2015 11:37:48 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Generování kontextu aktivace pro C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest1 se nezdařilo. Chyba v souboru manifestu nebo zásad C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest2 na řádku C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest3.
Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní.
Konfliktní součásti:
Součást 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.
Součást 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.

Error: (05/23/2015 11:37:47 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Generování kontextu aktivace pro C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest1 se nezdařilo. Chyba v souboru manifestu nebo zásad C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest2 na řádku C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest3.
Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní.
Konfliktní součásti:
Součást 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.
Součást 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.

Error: (05/23/2015 11:37:47 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Generování kontextu aktivace pro C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest1 se nezdařilo. Chyba v souboru manifestu nebo zásad C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest2 na řádku C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest3.
Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní.
Konfliktní součásti:
Součást 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Součást 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.

Error: (05/23/2015 11:36:35 AM) (Source: SideBySide) (EventID: 72) (User: )
Description: Generování kontextu aktivace pro security1 se nezdařilo. Chyba v souboru manifestu nebo zásady security2 na řádku security3.
Prvek security je zřejmě podřízeným prvku urn:schemas-microsoft-com:asm.v1^assembly, což tato verze systému Windows nepodporuje.

Error: (05/23/2015 11:03:45 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe, verze: 0.0.0.0, časové razítko: 0x53cfa27e
Název chybujícího modulu: svchost.exe, verze: 0.0.0.0, časové razítko: 0x53cfa27e
Kód výjimky: 0xc0000094
Posun chyby: 0x000000000002573a
ID chybujícího procesu: 0x11d0
Čas spuštění chybující aplikace: 0xsvchost.exe0
Cesta k chybující aplikaci: svchost.exe1
Cesta k chybujícímu modulu: svchost.exe2
ID zprávy: svchost.exe3
Úplný název chybujícího balíčku: svchost.exe4
ID aplikace související s chybujícím balíčkem: svchost.exe5

Error: (05/23/2015 11:01:29 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe, verze: 0.0.0.0, časové razítko: 0x53cfa27e
Název chybujícího modulu: svchost.exe, verze: 0.0.0.0, časové razítko: 0x53cfa27e
Kód výjimky: 0xc0000094
Posun chyby: 0x000000000002573a
ID chybujícího procesu: 0x848
Čas spuštění chybující aplikace: 0xsvchost.exe0
Cesta k chybující aplikaci: svchost.exe1
Cesta k chybujícímu modulu: svchost.exe2
ID zprávy: svchost.exe3
Úplný název chybujícího balíčku: svchost.exe4
ID aplikace související s chybujícím balíčkem: svchost.exe5

Error: (05/23/2015 09:19:37 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Název chybujícího modulu: svchost.exe, verze: 0.0.0.0, časové razítko: 0x543cdb10
Kód výjimky: 0xc0000094
Posun chyby: 0x000000000002814d
ID chybujícího procesu: 0x1fe4
Čas spuštění chybující aplikace: 0xsvchost.exe0
Cesta k chybující aplikaci: svchost.exe1
Cesta k chybujícímu modulu: svchost.exe2
ID zprávy: svchost.exe3
Úplný název chybujícího balíčku: svchost.exe4
ID aplikace související s chybujícím balíčkem: svchost.exe5


System errors:
=============
Error: (05/23/2015 00:15:47 PM) (Source: DCOM) (EventID: 10016) (User: PC-Jirka)
Description: specifické pro aplikaciMístníSpuštění{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}PC-JirkaJirkaS-1-5-21-626980440-2269883898-3179777769-1001LocalHost (pomocí LRPC)Není k dispoziciNení k dispozici

Error: (05/23/2015 00:14:12 PM) (Source: DCOM) (EventID: 10005) (User: PC-Jirka)
Description: 1084ShellHWDetectionNení k dispozici{DD522ACC-F821-461A-A407-50B198B896DC}

Error: (05/23/2015 00:14:07 PM) (Source: DCOM) (EventID: 10005) (User: PC-Jirka)
Description: 1084ShellHWDetectionNení k dispozici{DD522ACC-F821-461A-A407-50B198B896DC}

Error: (05/23/2015 00:13:57 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Služba Prohledávání počítačů závisí na službě Server, která neuspěla při spuštění v důsledku následující chyby:
%%1068

Error: (05/23/2015 00:13:57 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Služba Prohledávání počítačů závisí na službě Server, která neuspěla při spuštění v důsledku následující chyby:
%%1068

Error: (05/23/2015 00:13:57 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Služba Prohledávání počítačů závisí na službě Server, která neuspěla při spuštění v důsledku následující chyby:
%%1068

Error: (05/23/2015 00:13:33 PM) (Source: DCOM) (EventID: 10005) (User: PC-Jirka)
Description: 1084ShellHWDetectionNení k dispozici{DD522ACC-F821-461A-A407-50B198B896DC}

Error: (05/23/2015 00:13:28 PM) (Source: DCOM) (EventID: 10005) (User: PC-Jirka)
Description: 1084ShellHWDetectionNení k dispozici{DD522ACC-F821-461A-A407-50B198B896DC}

Error: (05/23/2015 00:13:24 PM) (Source: DCOM) (EventID: 10005) (User: PC-Jirka)
Description: 1084WSearchNení k dispozici{9E175B6D-F52A-11D8-B9A5-505054503030}

Error: (05/23/2015 00:13:22 PM) (Source: DCOM) (EventID: 10005) (User: PC-Jirka)
Description: 1084ShellHWDetectionNení k dispozici{DD522ACC-F821-461A-A407-50B198B896DC}


Microsoft Office:
=========================

CodeIntegrity Errors:
===================================
Date: 2014-01-30 19:18:05.061
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Moborobo\MoboroboAssDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info ===========================

Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 6000+
Percentage of memory in use: 29%
Total physical RAM: 4087.06 MB
Available physical RAM: 2883.4 MB
Total Pagefile: 4791.06 MB
Available Pagefile: 3439.04 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:58.5 GB) (Free:22.79 GB) NTFS
Drive d: (Download) (Fixed) (Total:407.16 GB) (Free:253.44 GB) NTFS
Drive e: (Hudba) (Fixed) (Total:931.51 GB) (Free:353.29 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 2B072B06)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=58.5 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=407.2 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 931.5 GB) (Disk ID: C5365980)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=42)

==================== End of log ============================