Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu-mám zpomalený netbook

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Slimak07
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 15 zář 2009 20:12

Prosím o kontrolu-mám zpomalený netbook

#1 Příspěvek od Slimak07 »

Dobrý den,poslední dobou se mi stává,že například při prohlížení internetu,nebo vlastně i při čemkoli se nb zastaví a nějakou chvíli nereaguje.program neodpovídá,nebo jen zastaví při posunu stránek.Když už začne opět fungovat,párkrát zapípá :roll:
vkládám log z FRST pro kontrolu,případně prosím o rady.
Zatim díky.

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-01-2014 01
Ran by Acer (administrator) on ACER-PC on 11-01-2014 10:27:39
Running from C:\Users\Acer\Desktop
Microsoft Windows 7 Starter Service Pack 1 (X86) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\dsiwmis.exe
(Oceanis) C:\Program Files\Oceanis\SystemSetting\WallPaperAgent.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\LMworker.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\LMutilps32.exe
(Acer Incorporated) C:\Program Files\Acer\Registration\GREGsvc.exe
(Realsil Microelectronics Inc.) C:\Program Files\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Acer Incorporated) C:\Program Files\Acer\Acer VCM\RS_Service.exe
(Egis Technology Inc.) C:\Program Files\EgisTec MyWinLockerSuite\x86\SuiteTray.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\LManager.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Insyde Software Corp.) C:\Program Files\Acer\Android Manager\iSync.exe
(Insyde Software Corp.) C:\Program Files\Acer\Updater\iUpdate.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Acer Incorporated) C:\Program Files\Acer\Acer VCM\AcerVCM.exe
() C:\Program Files\Kooperativa\KoopPxBN\KoopPDFServerSA.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Acer\Desktop\FRSTLauncher.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [SuiteTray] - C:\Program Files\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [340848 2011-04-02] (Egis Technology Inc.)
HKLM\...\Run: [EgisTecPMMUpdate] - C:\Program Files\EgisTec IPS\PmmUpdate.exe [408432 2011-03-29] (Egis Technology Inc.)
HKLM\...\Run: [EgisUpdate] - C:\Program Files\EgisTec IPS\EgisUpdate.exe [202608 2011-03-29] (Egis Technology Inc.)
HKLM\...\Run: [LManager] - C:\Program Files\Launch Manager\LManager.exe [1103440 2011-07-01] (Dritek System Inc.)
HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [1812264 2010-11-12] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [10025576 2011-02-11] (Realtek Semiconductor)
HKLM\...\Run: [Power Management] - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [715368 2011-05-10] (Acer Incorporated)
HKLM\...\Run: [iSyncData] - C:\Program Files\Acer\Android Manager\iSync.exe [408128 2011-05-10] (Insyde Software Corp.)
HKLM\...\Run: [AndroidManager] - C:\Program Files\Acer\Android Manager\AML.exe [508992 2011-05-10] ()
HKLM\...\Run: [iPatchData] - C:\Program Files\Acer\Updater\iUpdate.exe [492096 2011-05-10] (Insyde Software Corp.)
HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [948440 2013-10-23] (Microsoft Corporation)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKCU\...\Run: [NextLive] - C:\Windows\system32\rundll32.exe "C:\Users\Acer\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
HKCU\...\Winlogon: [Shell] C:\Program Files\Oceanis\SystemSetting\WallPaperAgent.exe [115888 2009-12-10] (Oceanis) <==== ATTENTION
MountPoints2: {5a9c908d-9aaf-11e2-ac0f-e89a8fc67cf2} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {5a9c9095-9aaf-11e2-ac0f-e89a8fc67cf2} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {5a9c9098-9aaf-11e2-ac0f-e89a8fc67cf2} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {8717d3df-93c8-11e2-92d7-e89a8fc67cf2} - E:\autorun.exe
HKU\Default\...\RunOnce: [ScrSav] - C:\Program Files\Acer\Screensaver\run_Acer.exe [ 2010-07-29] ()
HKU\Default User\...\RunOnce: [ScrSav] - C:\Program Files\Acer\Screensaver\run_Acer.exe [ 2010-07-29] ()
Startup: C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Kooperativa - PDF Server.lnk
ShortcutTarget: Kooperativa - PDF Server.lnk -> C:\Program Files\Kooperativa\KoopPxBN\KoopPDFServerSA.exe ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {8A244612-A1F7-11E0-95C0-E71F4824019B} URL = http://badoo.com/startpage/?source=bsb&q={searchTerms}
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Windows 7 Starter Helper - {D381FF29-7CFB-4D4E-B92A-C4EDDC696614} - C:\Program Files\Oceanis\SystemSetting\StarterHelper.dll (Oceanis)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{5DDD03DD-0BE2-4043-9F41-F7C8DEDD9460}: [NameServer]217.77.165.81 217.77.161.131
Tcpip\..\Interfaces\{9D85903A-AD14-434E-8D20-C6B516FBCB0E}: [NameServer]217.77.165.81 217.77.161.131

Chrome:
=======
CHR HomePage: hxxp://www.seznam.cz/
CHR RestoreOnStartup: "hxxp://www.seznam.cz/"
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll ()
CHR Plugin: (McAfee SiteAdvisor) - C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.31.131.2_0\McChPlg.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.0.50401.0\npctrl.dll No File
CHR Extension: (Google Drive) - C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (avast! Online Security) - C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\8.0.8_0
CHR Extension: (Google Wallet) - C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0
CHR Extension: (Gmail) - C:\Users\Acer\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0

========================== Services (Whitelisted) =================

S3 EgisTec Ticket Service; C:\Program Files\Common Files\EgisTec\Services\EgisTicketService.exe [173424 2011-04-02] (Egis Technology Inc. )
R2 ePowerSvc; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [739944 2011-05-10] (Acer Incorporated)
R2 GREGService; C:\Program Files\Acer\Registration\GREGsvc.exe [29696 2011-05-26] (Acer Incorporated)
R2 IconMan_R; C:\Program Files\Realtek\Realtek PCIE Card Reader\RIconMan.exe [1755136 2011-03-07] (Realsil Microelectronics Inc.)
R2 Live Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [255376 2012-04-05] (Acer Incorporated)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-10-23] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280288 2013-10-23] (Microsoft Corporation)
R2 RS_Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [260640 2010-01-30] (Acer Incorporated)

==================== Drivers (Whitelisted) ====================

R3 ETD; C:\Windows\System32\DRIVERS\ETD.sys [116008 2010-11-12] (ELAN Microelectronics Corp.)
S3 huawei_cdcacm; C:\Windows\System32\DRIVERS\ew_jucdcacm.sys [89856 2011-07-12] (Huawei Technologies Co., Ltd.)
S3 huawei_ext_ctrl; C:\Windows\System32\DRIVERS\ew_juextctrl.sys [26624 2011-07-12] (Huawei Technologies Co., Ltd.)
S3 huawei_wwanecm; C:\Windows\System32\DRIVERS\ew_juwwanecm.sys [182272 2011-07-12] (Huawei Technologies Co., Ltd.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [214696 2013-09-27] (Microsoft Corporation)
R1 mwlPSDFilter; C:\Windows\System32\DRIVERS\mwlPSDFilter.sys [21600 2012-02-17] (Egis Technology Inc.)
R1 mwlPSDNServ; C:\Windows\System32\DRIVERS\mwlPSDNServ.sys [16936 2012-02-17] (Egis Technology Inc.)
R1 mwlPSDVDisk; C:\Windows\System32\DRIVERS\mwlPSDVDisk.sys [62240 2012-02-17] (Egis Technology Inc.)
R2 npf; C:\Windows\System32\drivers\npf.sys [50704 2010-01-27] (CACE Technologies, Inc.)
R3 RSPCIESTOR; C:\Windows\System32\DRIVERS\RtsPStor.sys [252520 2011-03-07] (Realtek Semiconductor Corp.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2013-03-23] ()
U3 aedexvnq; C:\Windows\System32\Drivers\aedexvnq.sys [0 ] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-01-11 10:27 - 2014-01-11 10:28 - 00012689 _____ C:\Users\Acer\Desktop\FRST.txt
2014-01-11 10:27 - 2014-01-11 10:27 - 00000000 ____D C:\FRST
2014-01-11 10:25 - 2014-01-11 10:26 - 00112640 _____ (forum.viry.cz) C:\Users\Acer\Desktop\FRSTLauncher.exe
2014-01-11 10:23 - 2014-01-11 10:23 - 01220096 _____ (Farbar) C:\Users\Acer\Desktop\FRST.exe
2014-01-08 10:42 - 2014-01-08 10:42 - 00000000 ____D C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google+ Auto Backup
2014-01-07 01:22 - 2014-01-07 01:22 - 00000000 ____D C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pojišťovna České spořitelny
2014-01-06 20:23 - 2014-01-06 20:23 - 04558848 _____ (Google Inc.) C:\Windows\system32\GPhotos.scr
2014-01-04 21:10 - 2014-01-09 01:13 - 00000000 ____D C:\Users\Acer\Desktop\50 shades of Grey
2014-01-03 20:39 - 2014-01-03 20:39 - 00000907 _____ C:\Users\Acer\Desktop\Plus500.lnk
2014-01-03 20:39 - 2014-01-03 20:39 - 00000000 ____D C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Plus500
2014-01-03 20:38 - 2014-01-03 20:39 - 00000000 ____D C:\Users\Acer\AppData\Local\Plus500
2014-01-03 20:38 - 2014-01-03 20:38 - 00000000 ____D C:\Program Files\Plus500
2014-01-03 14:53 - 2014-01-03 14:53 - 00000000 ____D C:\Users\Acer\AppData\Local\WinZip Courier
2014-01-03 14:52 - 2014-01-03 14:52 - 00000000 ____D C:\ProgramData\WinZipEC
2014-01-03 14:37 - 2014-01-10 23:26 - 00000000 ____D C:\Users\Acer\Documents\Soubory aplikace Outlook
2014-01-02 14:05 - 2014-01-02 14:05 - 00682496 _____ () C:\Users\Acer\AppData\Local\setup.exe
2014-01-02 14:05 - 2014-01-02 14:05 - 00000000 ____D C:\Users\Acer\AppData\Local\Help
2014-01-02 14:03 - 2014-01-02 14:03 - 00000000 ____D C:\Users\Acer\AppData\Local\CSC
2013-12-31 15:54 - 2011-06-21 11:24 - 00032768 _____ C:\Windows\system32\Drivers\sp_rsdrv2.sys
2013-12-31 15:53 - 2013-12-31 15:53 - 00000079 _____ C:\Windows\wininit.ini
2013-12-31 15:08 - 2013-12-31 15:53 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-12-30 19:31 - 2013-12-30 19:43 - 00000000 ____D C:\ProgramData\SecTaskMan
2013-12-28 09:17 - 2013-12-31 16:07 - 00003556 _____ C:\Windows\PFRO.log
2013-12-24 22:59 - 2013-12-24 23:05 - 00000000 ____D C:\ProgramData\AVG
2013-12-24 22:59 - 2013-12-24 22:59 - 00000000 __SHD C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2013-12-24 22:59 - 2013-12-24 22:59 - 00000000 ____D C:\Users\Acer\AppData\Roaming\AVG
2013-12-24 22:58 - 2013-12-24 22:58 - 00002037 _____ C:\Users\Public\Desktop\Free YouTube Downloader.lnk
2013-12-24 22:58 - 2013-12-24 22:58 - 00000000 ____D C:\Program Files\Free YouTube Downloader
2013-12-24 22:57 - 2014-01-11 05:40 - 00000000 ____D C:\Users\Acer\AppData\Roaming\newnext.me
2013-12-24 22:57 - 2013-12-24 23:01 - 00000000 ____D C:\Users\Acer\AppData\Local\Mobogenie
2013-12-24 22:57 - 2013-12-24 22:57 - 00000000 ____D C:\Users\Acer\AppData\Local\genienext
2013-12-24 22:57 - 2013-12-24 22:57 - 00000000 ____D C:\Users\Acer\AppData\Local\cache
2013-12-24 22:57 - 2013-12-24 22:57 - 00000000 ____D C:\Users\Acer\.android
2013-12-24 22:57 - 2013-12-24 22:57 - 00000000 _____ C:\Users\Acer\daemonprocess.txt
2013-12-24 22:55 - 2013-12-24 23:02 - 00000000 ____D C:\Program Files\MyPC Backup
2013-12-24 22:55 - 2013-12-24 23:01 - 00000000 ____D C:\Program Files\Mobogenie
2013-12-24 22:50 - 2013-12-24 22:50 - 00000000 ____D C:\ProgramData\Oracle
2013-12-24 22:50 - 2013-12-24 22:50 - 00000000 ____D C:\Program Files\Common Files\Java
2013-12-24 22:50 - 2013-12-24 22:49 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-12-24 22:49 - 2013-12-24 22:49 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-12-24 22:49 - 2013-12-24 22:49 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-12-24 22:49 - 2013-12-24 22:49 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-12-23 22:48 - 2009-03-24 11:52 - 00659264 _____ (Microsoft Corporation) C:\Windows\system32\mscomct2.ocx
2013-12-23 12:39 - 2014-01-02 17:58 - 00000000 ____D C:\Users\Acer\Desktop\prilohy_6527
2013-12-18 23:22 - 2014-01-09 09:52 - 00001288 _____ C:\Windows\setupact.log
2013-12-18 23:22 - 2013-12-18 23:22 - 00000000 _____ C:\Windows\setuperr.log
2013-12-17 13:04 - 2013-12-18 01:20 - 00000000 ____D C:\Users\Acer\Desktop\Videa telefon
2013-12-14 13:03 - 2013-12-14 13:28 - 00000000 ____D C:\Users\Acer\Desktop\Nová složka
2013-12-14 01:58 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-14 01:58 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-14 01:58 - 2013-11-26 10:22 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-12-14 01:58 - 2013-11-26 09:53 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-14 01:58 - 2013-11-26 09:52 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-12-14 01:58 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-14 01:58 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-14 01:58 - 2013-11-26 09:36 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-14 01:58 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-14 01:58 - 2013-11-26 09:29 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-14 01:58 - 2013-11-26 09:29 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-12-14 01:58 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-12-14 01:58 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-14 01:58 - 2013-11-26 09:13 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-14 01:58 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-14 01:58 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-14 01:58 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-12-14 01:58 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-14 01:58 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-14 01:47 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-14 01:47 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-13 22:46 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-13 22:46 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-13 22:46 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-13 22:46 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-13 22:46 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-13 22:46 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-13 22:46 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-13 22:46 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-13 22:45 - 2013-10-30 02:27 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-13 22:45 - 2013-10-04 02:49 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-13 22:45 - 2013-10-04 02:17 - 00177152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys

==================== One Month Modified Files and Folders =======

2014-01-11 10:28 - 2014-01-11 10:27 - 00012689 _____ C:\Users\Acer\Desktop\FRST.txt
2014-01-11 10:28 - 2013-03-15 14:23 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-11 10:27 - 2014-01-11 10:27 - 00000000 ____D C:\FRST
2014-01-11 10:27 - 2012-11-22 17:20 - 00000936 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-11 10:27 - 2012-11-20 12:23 - 01717524 _____ C:\Windows\WindowsUpdate.log
2014-01-11 10:26 - 2014-01-11 10:25 - 00112640 _____ (forum.viry.cz) C:\Users\Acer\Desktop\FRSTLauncher.exe
2014-01-11 10:23 - 2014-01-11 10:23 - 01220096 _____ (Farbar) C:\Users\Acer\Desktop\FRST.exe
2014-01-11 09:35 - 2013-03-16 14:32 - 00000924 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2876516928-2939531918-4130130541-1000UA.job
2014-01-11 05:40 - 2013-12-24 22:57 - 00000000 ____D C:\Users\Acer\AppData\Roaming\newnext.me
2014-01-11 00:52 - 2012-12-09 17:08 - 00000000 ____D C:\Users\Acer\AppData\Roaming\Skype
2014-01-10 23:26 - 2014-01-03 14:37 - 00000000 ____D C:\Users\Acer\Documents\Soubory aplikace Outlook
2014-01-10 23:10 - 2013-03-16 14:32 - 00000902 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2876516928-2939531918-4130130541-1000Core.job
2014-01-10 23:01 - 2013-11-16 13:54 - 00000000 ____D C:\Users\Acer\Desktop\Nová složka (2)
2014-01-10 16:02 - 2012-11-22 17:20 - 00000932 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-09 10:01 - 2009-07-14 05:34 - 00016160 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-09 10:01 - 2009-07-14 05:34 - 00016160 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-09 09:58 - 2010-11-20 22:01 - 01585078 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-09 09:52 - 2013-12-18 23:22 - 00001288 _____ C:\Windows\setupact.log
2014-01-09 09:52 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-09 01:13 - 2014-01-04 21:10 - 00000000 ____D C:\Users\Acer\Desktop\50 shades of Grey
2014-01-08 11:18 - 2013-03-27 19:04 - 00000000 ____D C:\Users\Acer\Desktop\Práce
2014-01-08 10:42 - 2014-01-08 10:42 - 00000000 ____D C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google+ Auto Backup
2014-01-08 10:40 - 2012-05-16 19:37 - 00000000 ___HD C:\Users\Acer\Desktop\.picasaoriginals
2014-01-07 01:27 - 2012-11-22 17:19 - 00000000 ____D C:\Users\Acer\AppData\Local\Deployment
2014-01-07 01:22 - 2014-01-07 01:22 - 00000000 ____D C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pojišťovna České spořitelny
2014-01-06 20:23 - 2014-01-06 20:23 - 04558848 _____ (Google Inc.) C:\Windows\system32\GPhotos.scr
2014-01-04 21:23 - 2012-11-23 17:35 - 00000000 ____D C:\ProgramData\Microsoft Help
2014-01-03 20:39 - 2014-01-03 20:39 - 00000907 _____ C:\Users\Acer\Desktop\Plus500.lnk
2014-01-03 20:39 - 2014-01-03 20:39 - 00000000 ____D C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Plus500
2014-01-03 20:39 - 2014-01-03 20:38 - 00000000 ____D C:\Users\Acer\AppData\Local\Plus500
2014-01-03 20:38 - 2014-01-03 20:38 - 00000000 ____D C:\Program Files\Plus500
2014-01-03 16:30 - 2013-12-04 17:57 - 00000000 ____D C:\Users\Acer\ING_eKalkulacka_ING_CZ
2014-01-03 15:59 - 2012-11-20 13:25 - 00000000 ____D C:\Users\Acer
2014-01-03 15:57 - 2013-12-04 18:08 - 00000086 _____ C:\Users\Acer\.java.policy
2014-01-03 14:53 - 2014-01-03 14:53 - 00000000 ____D C:\Users\Acer\AppData\Local\WinZip Courier
2014-01-03 14:52 - 2014-01-03 14:52 - 00000000 ____D C:\ProgramData\WinZipEC
2014-01-02 20:04 - 2013-03-27 19:07 - 00000000 ____D C:\ProgramData\firebird
2014-01-02 17:58 - 2013-12-23 12:39 - 00000000 ____D C:\Users\Acer\Desktop\prilohy_6527
2014-01-02 14:05 - 2014-01-02 14:05 - 00682496 _____ () C:\Users\Acer\AppData\Local\setup.exe
2014-01-02 14:05 - 2014-01-02 14:05 - 00000000 ____D C:\Users\Acer\AppData\Local\Help
2014-01-02 14:03 - 2014-01-02 14:03 - 00000000 ____D C:\Users\Acer\AppData\Local\CSC
2014-01-02 09:43 - 2012-04-11 07:03 - 00000000 ____D C:\Users\Acer\Desktop\Mp3
2013-12-31 16:07 - 2013-12-28 09:17 - 00003556 _____ C:\Windows\PFRO.log
2013-12-31 15:53 - 2013-12-31 15:53 - 00000079 _____ C:\Windows\wininit.ini
2013-12-31 15:53 - 2013-12-31 15:08 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-12-30 19:43 - 2013-12-30 19:31 - 00000000 ____D C:\ProgramData\SecTaskMan
2013-12-29 11:51 - 2013-11-20 15:45 - 00000000 _____ C:\Windows\system32\sinstall.log
2013-12-28 10:41 - 2012-12-08 10:42 - 00000000 ____D C:\Users\Acer\AppData\Local\Adobe
2013-12-28 09:17 - 2009-07-14 05:33 - 00411936 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-25 00:32 - 2012-11-20 13:26 - 00109672 _____ C:\Users\Acer\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-24 23:10 - 2013-03-28 18:02 - 00000000 ____D C:\Program Files\Kooperativa
2013-12-24 23:05 - 2013-12-24 22:59 - 00000000 ____D C:\ProgramData\AVG
2013-12-24 23:02 - 2013-12-24 22:55 - 00000000 ____D C:\Program Files\MyPC Backup
2013-12-24 23:01 - 2013-12-24 22:57 - 00000000 ____D C:\Users\Acer\AppData\Local\Mobogenie
2013-12-24 23:01 - 2013-12-24 22:55 - 00000000 ____D C:\Program Files\Mobogenie
2013-12-24 22:59 - 2013-12-24 22:59 - 00000000 __SHD C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2013-12-24 22:59 - 2013-12-24 22:59 - 00000000 ____D C:\Users\Acer\AppData\Roaming\AVG
2013-12-24 22:58 - 2013-12-24 22:58 - 00002037 _____ C:\Users\Public\Desktop\Free YouTube Downloader.lnk
2013-12-24 22:58 - 2013-12-24 22:58 - 00000000 ____D C:\Program Files\Free YouTube Downloader
2013-12-24 22:58 - 2012-12-27 11:15 - 00000000 ____D C:\Users\Acer\AppData\Roaming\OpenCandy
2013-12-24 22:57 - 2013-12-24 22:57 - 00000000 ____D C:\Users\Acer\AppData\Local\genienext
2013-12-24 22:57 - 2013-12-24 22:57 - 00000000 ____D C:\Users\Acer\AppData\Local\cache
2013-12-24 22:57 - 2013-12-24 22:57 - 00000000 ____D C:\Users\Acer\.android
2013-12-24 22:57 - 2013-12-24 22:57 - 00000000 _____ C:\Users\Acer\daemonprocess.txt
2013-12-24 22:50 - 2013-12-24 22:50 - 00000000 ____D C:\ProgramData\Oracle
2013-12-24 22:50 - 2013-12-24 22:50 - 00000000 ____D C:\Program Files\Common Files\Java
2013-12-24 22:49 - 2013-12-24 22:50 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-12-24 22:49 - 2013-12-24 22:49 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-12-24 22:49 - 2013-12-24 22:49 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-12-24 22:49 - 2013-12-24 22:49 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-12-24 22:48 - 2013-07-15 15:16 - 00000000 ____D C:\Program Files\Java
2013-12-23 22:16 - 2013-04-10 11:17 - 00001313 _____ C:\Users\Acer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kooperativa - Perspektiva 7BN Extern.lnk
2013-12-18 23:22 - 2013-12-18 23:22 - 00000000 _____ C:\Windows\setuperr.log
2013-12-18 12:21 - 2007-07-12 02:49 - 00000000 ____D C:\Windows\Panther
2013-12-18 12:19 - 2013-04-03 06:28 - 00000000 ____D C:\Windows\pss
2013-12-18 12:18 - 2012-11-23 21:05 - 00000973 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-12-18 12:18 - 2012-11-23 21:05 - 00000000 ____D C:\Program Files\CCleaner
2013-12-18 01:20 - 2013-12-17 13:04 - 00000000 ____D C:\Users\Acer\Desktop\Videa telefon
2013-12-15 22:55 - 2013-03-28 17:07 - 00001912 _____ C:\Windows\epplauncher.mif
2013-12-15 22:46 - 2013-03-28 17:07 - 00000000 ____D C:\Program Files\Microsoft Security Client
2013-12-14 13:28 - 2013-12-14 13:03 - 00000000 ____D C:\Users\Acer\Desktop\Nová složka
2013-12-14 11:52 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\rescache
2013-12-14 01:55 - 2013-07-31 14:47 - 00000000 ____D C:\Windows\system32\MRT
2013-12-14 01:49 - 2012-11-23 18:35 - 88123800 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe

Some content of TEMP:
====================
C:\Users\Acer\AppData\Local\Temp\BackupSetup.exe


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2876516928-2939531918-4130130541-1000Core.job => C:\Users\Acer\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2876516928-2939531918-4130130541-1000UA.job => C:\Users\Acer\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Acer\Desktop" je 5594 MB.


***** Startup Programs *****

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
"C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update
"C:\Users\Acer\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^ING eKalkula�ka.lnk
C:\Users\Acer\ING_EK~1\JETTYS~1.BAT

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Acer^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Kooperativa - PDF Server.lnk
C:\PROGRA~1\KOOPER~1\KoopPxBN\KOOPPD~1.EXE


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================
Přílohy
Addition.rar
Addition
(4.88 KiB) Staženo 14 x

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119506
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu-mám zpomalený netbook

#2 Příspěvek od Rudy »

Otevřte poznámkový blok a zkopírujte do něj:
Start
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
MountPoints2: {5a9c908d-9aaf-11e2-ac0f-e89a8fc67cf2} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {5a9c9095-9aaf-11e2-ac0f-e89a8fc67cf2} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {5a9c9098-9aaf-11e2-ac0f-e89a8fc67cf2} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {8717d3df-93c8-11e2-92d7-e89a8fc67cf2} - E:\autorun.exe
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {8A244612-A1F7-11E0-95C0-E71F4824019B} URL = http://badoo.com/startpage/?source=bsb&q={searchTerms}
U3 aedexvnq; C:\Windows\System32\Drivers\aedexvnq.sys [0 ] (Microsoft Corporation)
C:\Windows\System32\Drivers\aedexvnq.sys
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2876516928-2939531918-4130130541-1000UA.job
C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2876516928-2939531918-4130130541-1000Core.job
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
C:\Users\Acer\AppData\Local\Temp
End
Uložte na plochu jako fixlist.txt. Pak znovu spusťte FRST a klikněte na >Fix<. Zkopírujte sem pak log, který se na závěr vytvoří.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Slimak07
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 15 zář 2009 20:12

Re: Prosím o kontrolu-mám zpomalený netbook

#3 Příspěvek od Slimak07 »

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 11-01-2014 01
Ran by Acer at 2014-01-11 14:39:25 Run:1
Running from C:\Users\Acer\Desktop
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
Start
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
MountPoints2: {5a9c908d-9aaf-11e2-ac0f-e89a8fc67cf2} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {5a9c9095-9aaf-11e2-ac0f-e89a8fc67cf2} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {5a9c9098-9aaf-11e2-ac0f-e89a8fc67cf2} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {8717d3df-93c8-11e2-92d7-e89a8fc67cf2} - E:\autorun.exe
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {8A244612-A1F7-11E0-95C0-E71F4824019B} URL = http://badoo.com/startpage/?source=bsb&q={searchTerms}
U3 aedexvnq; C:\Windows\System32\Drivers\aedexvnq.sys [0 ] (Microsoft Corporation)
C:\Windows\System32\Drivers\aedexvnq.sys
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2876516928-2939531918-4130130541-1000UA.job
C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2876516928-2939531918-4130130541-1000Core.job
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
C:\Users\Acer\AppData\Local\Temp
End
*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5a9c908d-9aaf-11e2-ac0f-e89a8fc67cf2} => Key deleted successfully.
HKCR\CLSID\{5a9c908d-9aaf-11e2-ac0f-e89a8fc67cf2} => Key not found.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5a9c9095-9aaf-11e2-ac0f-e89a8fc67cf2} => Key deleted successfully.
HKCR\CLSID\{5a9c9095-9aaf-11e2-ac0f-e89a8fc67cf2} => Key not found.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5a9c9098-9aaf-11e2-ac0f-e89a8fc67cf2} => Key deleted successfully.
HKCR\CLSID\{5a9c9098-9aaf-11e2-ac0f-e89a8fc67cf2} => Key not found.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8717d3df-93c8-11e2-92d7-e89a8fc67cf2} => Key deleted successfully.
HKCR\CLSID\{8717d3df-93c8-11e2-92d7-e89a8fc67cf2} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8A244612-A1F7-11E0-95C0-E71F4824019B} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{8A244612-A1F7-11E0-95C0-E71F4824019B} => Key not found.
aedexvnq => Service deleted successfully.
Could not move "C:\Windows\System32\Drivers\aedexvnq.sys" => Scheduled to move on reboot.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2876516928-2939531918-4130130541-1000UA.job => Moved successfully.
C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2876516928-2939531918-4130130541-1000Core.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.

"C:\Users\Acer\AppData\Local\Temp" directory move:

C:\Users\Acer\AppData\Local\Temp\Acer.swf => Moved successfully.
C:\Users\Acer\AppData\Local\Temp\ads000 => Moved successfully.
Could not move "C:\Users\Acer\AppData\Local\Temp\aipflib.log" => Scheduled to move on reboot.
C:\Users\Acer\AppData\Local\Temp\ASPNETSetup_00000.log => Moved successfully.
C:\Users\Acer\AppData\Local\Temp\CVR80FB.tmp.cvr => Moved successfully.
C:\Users\Acer\AppData\Local\Temp\CVRE4F8.tmp.cvr => Moved successfully.
C:\Users\Acer\AppData\Local\Temp\CVRFF23.tmp.cvr => Moved successfully.
C:\Users\Acer\AppData\Local\Temp\dd_NDP451-KB2858725-x86-x64-ENU_decompression_log.txt => Moved successfully.
C:\Users\Acer\AppData\Local\Temp\dd_SetupUtility.txt => Moved successfully.
C:\Users\Acer\AppData\Local\Temp\dd_wcf_CA_smci_20140111_101640_141.txt => Moved successfully.
Could not move "C:\Users\Acer\AppData\Local\Temp\etilqs_ERMSKQyWwxQj3dj" => Scheduled to move on reboot.
Could not move "C:\Users\Acer\AppData\Local\Temp\etilqs_lmC1LmZEj1xCQiQ" => Scheduled to move on reboot.
Could not move "C:\Users\Acer\AppData\Local\Temp\etilqs_yot34pNMyIiiVIm" => Scheduled to move on reboot.
Could not move "C:\Users\Acer\AppData\Local\Temp\FXSAPIDebugLogFile.txt" => Scheduled to move on reboot.
Could not move "C:\Users\Acer\AppData\Local\Temp\LManager.log" => Scheduled to move on reboot.
Could not move "C:\Users\Acer\AppData\Local\Temp\LMworker.log" => Scheduled to move on reboot.
C:\Users\Acer\AppData\Local\Temp\Microsoft .NET Framework 4.5.1 Setup_20140111_110945642-MSI_netfx_Full_GDR_x86.msi.txt => Moved successfully.
C:\Users\Acer\AppData\Local\Temp\Microsoft .NET Framework 4.5.1 Setup_20140111_110945642.html => Moved successfully.
C:\Users\Acer\AppData\Local\Temp\modules00 => Moved successfully.
C:\Users\Acer\AppData\Local\Temp\modules11 => Moved successfully.
Could not move "C:\Users\Acer\AppData\Local\Temp\qtsingleapp-kooppd-d32-1-lockfile" => Scheduled to move on reboot.
C:\Users\Acer\AppData\Local\Temp\RGI1665.tmp => Moved successfully.
C:\Users\Acer\AppData\Local\Temp\RGI1665.tmp-tmp => Moved successfully.
C:\Users\Acer\AppData\Local\Temp\users00 => Moved successfully.
C:\Users\Acer\AppData\Local\Temp\wmplog00.sqm => Moved successfully.
C:\Users\Acer\AppData\Local\Temp\wmplog01.sqm => Moved successfully.
C:\Users\Acer\AppData\Local\Temp\~E49A.tmp => Moved successfully.
Could not move "C:\Users\Acer\AppData\Local\Temp" directory. => Scheduled to move on reboot.


=> Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-01-11 14:43:14)<=

C:\Windows\System32\Drivers\aedexvnq.sys => Is moved successfully.
"C:\Users\Acer\AppData\Local\Temp\aipflib.log" => File could not move.
C:\Users\Acer\AppData\Local\Temp\etilqs_ERMSKQyWwxQj3dj => Is moved successfully.
C:\Users\Acer\AppData\Local\Temp\etilqs_lmC1LmZEj1xCQiQ => Is moved successfully.
C:\Users\Acer\AppData\Local\Temp\etilqs_yot34pNMyIiiVIm => Is moved successfully.
"C:\Users\Acer\AppData\Local\Temp\FXSAPIDebugLogFile.txt" => File could not move.
"C:\Users\Acer\AppData\Local\Temp\LManager.log" => File could not move.
"C:\Users\Acer\AppData\Local\Temp\LMworker.log" => File could not move.
"C:\Users\Acer\AppData\Local\Temp\qtsingleapp-kooppd-d32-1-lockfile" => File could not move.
"C:\Users\Acer\AppData\Local\Temp" => Directory could not move.

==== End of Fixlog ====

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119506
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu-mám zpomalený netbook

#4 Příspěvek od Rudy »

Smazáno. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Slimak07
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 15 zář 2009 20:12

Re: Prosím o kontrolu-mám zpomalený netbook

#5 Příspěvek od Slimak07 »

Prozatím testuju,ale vypadá to,že je to lepší.Už teď ale děkuju.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119506
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu-mám zpomalený netbook

#6 Příspěvek od Rudy »

Nemáte zač! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Slimak07
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 15 zář 2009 20:12

Re: Prosím o kontrolu-mám zpomalený netbook

#7 Příspěvek od Slimak07 »

a ještě se rovnou zeptám...co to bylo?

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119506
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu-mám zpomalený netbook

#8 Příspěvek od Rudy »

Především tam byl rootkit. To ostatní byly jen zbytečnosti.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět