Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Postupné zpomalování a sekání se PC

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
mlzd
Návštěvník
Návštěvník
Příspěvky: 130
Registrován: 02 led 2005 00:36
Bydliště: VDF

Postupné zpomalování a sekání se PC

#1 Příspěvek od mlzd »

Zdravím!
Po zhruba hodinovém spuštění se začne PC zpomalovat, trhavě načítat, všechno jde jako když se tomu nechce. Zjistil jsem, že se spouští duplicitně Firefox na pozadí. Musím jej ukončit ze Správce úloh, abych mohl vůbec dál něco dělat. Co to způsobuje nemám tušení... Díky předem za radu!

(Mně to připadá jako kdyby se zahlcovala RAM)


Logfile of random's system information tool 1.09 (written by random/random)
Run by Wow at 2014-02-14 12:34:38
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 223 GB (61%) free of 368 GB
Total RAM: 3056 MB (2% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:35:04, on 14.2.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16518)
Boot mode: Normal

Running processes:
C:\Windows\vsnpstd3.exe
C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Servant Salamander 2.0\salamand.exe
C:\Program Files\trend micro\Wow.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACA ... 5gf8k12w37
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchgol.com/?babsrc=HP_ss& ... 2&tsp=5022
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [Hotkey Utility] C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Poslat jako MMS - res://C:\Program Files (x86)\O2\SMSender\SMSender.E.182.dll/1003
O8 - Extra context menu item: Poslat jako SMS - res://C:\Program Files (x86)\O2\SMSender\SMSender.E.182.dll/1001
O8 - Extra context menu item: Poslat MMS na - res://C:\Program Files (x86)\O2\SMSender\SMSender.E.182.dll/1002
O8 - Extra context menu item: Poslat SMS na - res://C:\Program Files (x86)\O2\SMSender\SMSender.E.182.dll/1000
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 7 (AdvancedSystemCareService7) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GRegService (Greg_Service) - Acer Incorporated - C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MyWinLocker Service (MWLService) - Egis Technology Inc. - C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe
O23 - Service: NTI IScheduleSvc - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Updater Service - Acer - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: WDDMService - WDC - C:\Program Files\Western Digital\WD SmartWare\WDDMService.exe
O23 - Service: WDFME (WDFMEService) - Western Digital - C:\Program Files\Western Digital\WD SmartWare\WDFME.exe
O23 - Service: WDRules (WDRulesService) - Western Digital - C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9667 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe"
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\System32\svchost.exe -k yksvcs
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Acer\Registration\GregHSRW.exe"
"C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe"
"C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Acer\Acer Updater\UpdaterService.exe"
"C:\Program Files\Western Digital\WD SmartWare\WDDMService.exe"
"C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 2156
"C:\Program Files\Western Digital\WD SmartWare\WDFME.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-6ce00d8e-af5a-41b5-8aa3-19c3162fa47a -SystemEventPortName:HostProcess-3741e95d-9100-4158-9926-49b5329fa8cf -IoCancelEventPortName:HostProcess-4bb3dac4-3fe8-4ae5-85ca-18cc4f4f9b77 -NonStateChangingEventPortName:HostProcess-5dd2cbd5-0bb9-4135-a8b0-b1c0abb21015 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:c54aae53-c8ea-4af8-a4d6-6bca2b5471a1 -DeviceGroupId:WpdFsGroup
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe"
"C:\Windows\vsnpstd3.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Servant Salamander 2.0\salamand.exe"
"D:\Internet_safety\Viry_RSIT\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\HP Photo Creations Communicator.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Wow\AppData\Roaming\Mozilla\Firefox\Profiles\ve2ispyc.default-1368026474286

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 12.0.0.44 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.21.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Windows\SysWOW64\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5]
"Description"=A component of your photo software powered by RocketLife
"Path"=C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 12.0.0.43 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

C:\Program Files (x86)\Mozilla Firefox\extensions\
{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}

C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
nppdf32.dll
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

C:\Users\Wow\AppData\Roaming\Mozilla\Firefox\Profiles\ve2ispyc.default-1368026474286\extensions\
adsremoval@adsremoval.net

C:\Users\Wow\AppData\Roaming\Mozilla\Firefox\Profiles\ve2ispyc.default-1368026474286\searchplugins\
peklada-google.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-02-04 1390368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2013-05-08 77424]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-02-04 1143168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-02-04 1390368]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-02-04 1143168]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-07-20 7981088]
"snpstd3"=C:\Windows\vsnpstd3.exe [2006-09-18 843776]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe [2013-04-04 958576]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EgisTecLiveUpdate]
c:\program files (x86)\egistec egis software update\egisupdate.exe [2009-08-04 199464]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [2010-06-09 49208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mwlDaemon]
c:\program files (x86)\egistec\mywinlocker 3\x86\mwldaemon.exe [2009-09-10 349480]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nástroj WD Quick View]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tsnpstd3]
C:\Windows\tsnpstd3.exe [2007-03-30 262144]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WD Quick View]
[]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Hotkey Utility"=C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe [2009-08-18 629280]
"Microsoft Default Manager"=C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [2010-05-10 439568]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-02-04 3767096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\kEvP64.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=0x00000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=0
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll

======File associations======

.js - edit -
.js - open -
.txt - open - NotePad.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-02-14 09:13:20 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-02-13 23:54:23 ----SHD---- C:\Config.Msi
2014-02-13 23:51:53 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-02-13 23:51:53 ----A---- C:\Windows\system32\vbscript.dll
2014-02-13 23:50:52 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-02-13 23:50:52 ----A---- C:\Windows\system32\msrating.dll
2014-02-13 23:50:51 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-02-13 23:50:50 ----A---- C:\Windows\system32\ieui.dll
2014-02-13 23:50:49 ----A---- C:\Windows\system32\iernonce.dll
2014-02-13 23:50:49 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-02-13 23:50:49 ----A---- C:\Windows\system32\ie4uinit.exe
2014-02-13 23:50:48 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-02-13 23:50:48 ----A---- C:\Windows\system32\jsproxy.dll
2014-02-13 23:50:47 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-02-13 23:50:47 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-02-13 23:50:47 ----A---- C:\Windows\system32\msfeeds.dll
2014-02-13 23:50:46 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-02-13 23:50:46 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-02-13 23:50:46 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-02-13 23:50:46 ----A---- C:\Windows\system32\ieUnatt.exe
2014-02-13 23:50:46 ----A---- C:\Windows\system32\iesetup.dll
2014-02-13 23:50:45 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-02-13 23:50:45 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-02-13 23:50:44 ----A---- C:\Windows\system32\mshtml.dll
2014-02-13 23:50:43 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-02-13 23:50:43 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-02-13 23:50:43 ----A---- C:\Windows\system32\jscript9diag.dll
2014-02-13 23:50:42 ----A---- C:\Windows\system32\ieapfltr.dll
2014-02-13 23:50:41 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-02-13 23:50:41 ----A---- C:\Windows\system32\iertutil.dll
2014-02-13 23:50:40 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-02-13 23:50:40 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-02-13 23:50:40 ----A---- C:\Windows\system32\wininet.dll
2014-02-13 23:50:40 ----A---- C:\Windows\system32\urlmon.dll
2014-02-13 23:50:36 ----A---- C:\Windows\system32\ieframe.dll
2014-02-13 23:50:33 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-02-13 23:50:32 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-02-13 23:50:30 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-02-13 23:50:28 ----A---- C:\Windows\system32\jscript9.dll
2014-02-13 20:14:35 ----A---- C:\AdwCleaner[R38].txt
2014-02-13 19:50:02 ----D---- C:\rsit
2014-02-13 19:47:50 ----A---- C:\Windows\system32\msxml3.dll
2014-02-13 19:47:48 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2014-02-13 19:47:48 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2014-02-13 19:47:48 ----A---- C:\Windows\system32\msxml3r.dll
2014-02-13 19:47:43 ----A---- C:\Windows\system32\RMActivate_isv.exe
2014-02-13 19:47:42 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp_isv.exe
2014-02-13 19:47:42 ----A---- C:\Windows\SYSWOW64\RMActivate_isv.exe
2014-02-13 19:47:42 ----A---- C:\Windows\SYSWOW64\RMActivate.exe
2014-02-13 19:47:42 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2014-02-13 19:47:42 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2014-02-13 19:47:42 ----A---- C:\Windows\system32\RMActivate.exe
2014-02-13 19:47:41 ----A---- C:\Windows\SYSWOW64\secproc_isv.dll
2014-02-13 19:47:41 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp.exe
2014-02-13 19:47:41 ----A---- C:\Windows\system32\secproc_isv.dll
2014-02-13 19:47:41 ----A---- C:\Windows\system32\secproc.dll
2014-02-13 19:47:41 ----A---- C:\Windows\system32\msdrm.dll
2014-02-13 19:47:40 ----A---- C:\Windows\SYSWOW64\secproc_ssp_isv.dll
2014-02-13 19:47:40 ----A---- C:\Windows\SYSWOW64\secproc_ssp.dll
2014-02-13 19:47:40 ----A---- C:\Windows\SYSWOW64\secproc.dll
2014-02-13 19:47:40 ----A---- C:\Windows\SYSWOW64\msdrm.dll
2014-02-13 19:47:40 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2014-02-13 19:47:40 ----A---- C:\Windows\system32\secproc_ssp.dll
2014-02-13 19:47:25 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2014-02-13 19:47:25 ----A---- C:\Windows\system32\d3d10warp.dll
2014-02-13 19:47:24 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2014-02-13 19:47:24 ----A---- C:\Windows\system32\d2d1.dll
2014-02-12 22:58:38 ----A---- C:\AdwCleaner[R37].txt
2014-02-10 20:58:24 ----A---- C:\AdwCleaner[S23].txt
2014-02-10 20:57:23 ----A---- C:\AdwCleaner[R36].txt
2014-02-08 12:01:00 ----D---- C:\Users\Wow\AppData\Roaming\IrfanView
2014-02-05 23:13:56 ----A---- C:\AdwCleaner[S22].txt
2014-02-05 23:12:02 ----A---- C:\AdwCleaner[R35].txt
2014-02-04 23:42:43 ----D---- C:\Users\Wow\AppData\Roaming\Opera Software
2014-02-04 22:46:07 ----D---- C:\Users\Wow\AppData\Roaming\AVAST Software
2014-02-04 22:45:28 ----A---- C:\Windows\system32\drivers\aswVmm.sys
2014-02-04 22:45:28 ----A---- C:\Windows\system32\drivers\aswStm.sys
2014-02-04 22:45:25 ----A---- C:\Windows\system32\drivers\aswRvrt.sys
2014-02-04 22:45:22 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2014-02-04 22:45:21 ----A---- C:\Windows\system32\drivers\aswSP.sys
2014-02-04 22:45:19 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2014-02-04 22:45:17 ----A---- C:\Windows\system32\drivers\aswRdr2.sys
2014-02-04 22:45:13 ----A---- C:\Windows\system32\aswBoot.exe
2014-02-04 22:45:02 ----A---- C:\Windows\avastSS.scr
2014-02-04 22:44:39 ----D---- C:\Program Files\AVAST Software
2014-02-04 22:43:22 ----D---- C:\ProgramData\AVAST Software
2014-02-03 19:41:47 ----D---- C:\Users\Wow\AppData\Roaming\Malwarebytes
2014-02-03 19:41:34 ----D---- C:\ProgramData\Malwarebytes
2014-02-03 19:41:33 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-02-03 19:41:33 ----A---- C:\Windows\system32\drivers\mbam.sys
2014-01-29 20:38:04 ----A---- C:\autoexec.bat
2014-01-29 20:36:15 ----D---- C:\Program Files\Enigma Software Group
2014-01-29 14:52:32 ----D---- C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-01-17 08:53:44 ----D---- C:\Program Files (x86)\Dup Scout
2014-01-15 12:02:06 ----A---- C:\Windows\system32\drivers\netio.sys
2014-01-15 12:02:04 ----A---- C:\Windows\system32\win32k.sys
2014-01-15 12:02:03 ----A---- C:\Windows\system32\drivers\usbport.sys
2014-01-15 12:02:03 ----A---- C:\Windows\system32\drivers\usbehci.sys
2014-01-15 12:02:02 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2014-01-15 12:02:02 ----A---- C:\Windows\system32\drivers\usbohci.sys
2014-01-15 12:02:02 ----A---- C:\Windows\system32\drivers\usbhub.sys
2014-01-15 12:02:02 ----A---- C:\Windows\system32\drivers\usbd.sys
2014-01-15 12:02:02 ----A---- C:\Windows\system32\drivers\usbccgp.sys

======List of files/folders modified in the last 1 month======

2014-02-14 12:34:44 ----D---- C:\Program Files\trend micro
2014-02-14 12:21:06 ----D---- C:\Windows\Temp
2014-02-14 11:00:20 ----D---- C:\Windows\system32\config
2014-02-14 10:46:36 ----D---- C:\Users\Wow\AppData\Roaming\BitTorrent
2014-02-14 10:43:58 ----D---- C:\Windows\winsxs
2014-02-14 10:43:16 ----D---- C:\ProgramData\NVIDIA
2014-02-14 10:42:09 ----D---- C:\Windows\SysWOW64
2014-02-14 10:42:07 ----D---- C:\Windows\System32
2014-02-14 09:39:13 ----SHD---- C:\System Volume Information
2014-02-14 09:13:43 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-02-14 09:13:41 ----RD---- C:\Program Files (x86)
2014-02-14 08:59:45 ----D---- C:\Windows\Microsoft.NET
2014-02-14 08:59:44 ----RSD---- C:\Windows\assembly
2014-02-14 08:49:48 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-02-14 08:49:47 ----D---- C:\Windows\system32\cs-CZ
2014-02-14 08:49:47 ----D---- C:\Program Files (x86)\Internet Explorer
2014-02-14 08:49:46 ----D---- C:\Program Files\Internet Explorer
2014-02-14 00:15:46 ----SHD---- C:\Windows\Installer
2014-02-14 00:14:49 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2014-02-14 00:14:38 ----D---- C:\Windows\inf
2014-02-14 00:14:31 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-02-14 00:01:57 ----D---- C:\Windows\system32\catroot
2014-02-13 23:51:59 ----D---- C:\Windows\system32\catroot2
2014-02-13 23:18:47 ----D---- C:\Users\Wow\AppData\Roaming\Winamp
2014-02-13 20:13:59 ----D---- C:\Users\Wow\AppData\Roaming\Skype
2014-02-13 18:24:05 ----AD---- C:\Windows
2014-02-13 14:55:58 ----D---- C:\Program Files (x86)\Opera
2014-02-13 13:54:02 ----D---- C:\Windows\system32\Tasks
2014-02-12 22:01:15 ----HD---- C:\ProgramData
2014-02-11 22:25:08 ----D---- C:\Windows\Tasks
2014-02-11 21:16:05 ----A---- C:\Windows\wincmd.ini
2014-02-11 21:01:19 ----A---- C:\Windows\win.ini
2014-02-08 11:56:51 ----D---- C:\Program Files (x86)\Adobe
2014-02-07 14:36:10 ----D---- C:\ProgramData\ProductData
2014-02-06 14:32:14 ----D---- C:\Program Files (x86)\CCleaner
2014-02-05 19:59:16 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-02-05 13:23:41 ----D---- C:\Windows\SoftwareDistribution
2014-02-05 13:18:18 ----D---- C:\Windows\debug
2014-02-04 22:45:58 ----D---- C:\Program Files (x86)\Mozilla Thunderbird
2014-02-04 22:45:28 ----D---- C:\Windows\system32\drivers
2014-02-04 22:44:39 ----D---- C:\Program Files
2014-02-04 22:40:18 ----A---- C:\Windows\wininit.ini
2014-02-04 22:40:16 ----D---- C:\ProgramData\Spybot - Search & Destroy
2014-02-04 22:40:15 ----SD---- C:\ProgramData\Microsoft
2014-02-04 22:39:34 ----D---- C:\ProgramData\f-secure
2014-02-03 19:49:13 ----D---- C:\ProgramData\DSearchLink
2014-02-02 20:55:57 ----D---- C:\Program Files\SUPERAntiSpyware
2014-01-31 14:54:37 ----D---- C:\Windows\system32\NDF
2014-01-29 23:16:58 ----SD---- C:\Users\Wow\AppData\Roaming\Microsoft
2014-01-29 21:14:08 ----D---- C:\Users\Wow\AppData\Roaming\iPumper
2014-01-29 17:54:20 ----D---- C:\Windows\Prefetch
2014-01-27 22:34:13 ----D---- C:\Program Files (x86)\Common Files
2014-01-27 22:34:10 ----RSD---- C:\Windows\Fonts
2014-01-16 12:37:24 ----D---- C:\Windows\system32\DriverStore
2014-01-15 15:34:16 ----D---- C:\Windows\system32\MRT
2014-01-15 15:32:00 ----A---- C:\Windows\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2014-02-04 65776]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2014-02-04 207904]
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-04 16440]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 aswRdr;aswRdr; \??\C:\Windows\system32\drivers\aswRdr2.sys [2014-02-04 92544]
R1 aswSnx;aswSnx; \??\C:\Windows\system32\drivers\aswSnx.sys [2014-02-04 1038072]
R1 aswSP;aswSP; \??\C:\Windows\system32\drivers\aswSP.sys [2014-02-04 421704]
R1 mwlPSDFilter;mwlPSDFilter; C:\Windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-02 22576]
R1 mwlPSDNServ;mwlPSDNServ; C:\Windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-02 20016]
R1 mwlPSDVDisk;mwlPSDVDisk; C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-02 60464]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2014-02-04 78648]
R3 aswStm;aswStm; \??\C:\Windows\system32\drivers\aswStm.sys [2014-02-04 80184]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-07-20 1831968]
R3 NTIDrvr;NTIDrvr; \??\C:\Windows\system32\drivers\NTIDrvr.sys [2009-05-06 18432]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2009-06-26 83488]
R3 SNPSTD3;USB PC Camera (SNPSTD3); C:\Windows\system32\DRIVERS\snpstd3.sys [2007-04-03 10535040]
R3 UBHelper;UBHelper; \??\C:\Windows\system32\drivers\UBHelper.sys [2009-05-06 16896]
R3 WDC_SAM;WD SCSI Pass Thru driver; C:\Windows\system32\DRIVERS\wdcsam64.sys [2011-12-16 14464]
S3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\agrsm64.sys [2009-06-11 1208320]
S3 atikmdag;atikmdag; C:\Windows\system32\drivers\atikmdag.sys [2009-07-13 5020672]
S3 esgiguard;esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys []
S3 pcwe;pcwe; \??\D:\Programy_system\PC_Wizard\pcw86-64.sys [2004-12-04 7680]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2013-05-02 19456]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-05-02 57856]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdvancedSystemCareService7;Advanced SystemCare Service 7; C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe [2013-12-09 881440]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-02-04 50344]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 Greg_Service;GRegService; C:\Program Files (x86)\Acer\Registration\GregHSRW.exe [2009-08-28 1150496]
R2 MWLService;MyWinLocker Service; C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [2009-09-10 305448]
R2 NTI IScheduleSvc;NTI IScheduleSvc; C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-08-12 62208]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-01-18 884512]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-01-18 383264]
R2 Updater Service;Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2009-07-04 240160]
R2 WDDMService;WDDMService; C:\Program Files\Western Digital\WD SmartWare\WDDMService.exe [2011-12-15 319384]
R2 WDFMEService;WDFME; C:\Program Files\Western Digital\WD SmartWare\WDFME.exe [2011-12-15 1977224]
R2 WDRulesService;WDRules; C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe [2011-12-15 1338264]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 2292096]
R2 yksvc;Marvell Yukon Service; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-06-30 136176]
S2 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2013-12-03 2151200]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-02-25 1260320]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-05 257928]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-06-30 136176]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-10-12 182768]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-02-06 111616]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-02-14 118896]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-06-15 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Postupné zpomalování a sekání se PC

#2 Příspěvek od Márty84 »

Zdravim :)

:arrow: Odinstalujte Advanced SystemCare a pripadne vse od IObit. Dokze to nadelat vic skody nez uzitku.

:arrow: Udelejte !!!kompletni!!! kontrolu s MBAM http://forum.viry.cz/viewtopic.php?f=29&t=115222 a dejte sem vysledky. Predem nic nemazte, miva obcas falesne detekce
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

mlzd
Návštěvník
Návštěvník
Příspěvky: 130
Registrován: 02 led 2005 00:36
Bydliště: VDF

Re: Postupné zpomalování a sekání se PC

#3 Příspěvek od mlzd »

Pro zajímavost Kontrolu přs MBAM jsem si dělal včera. Zde protokol.
(Jinak nový sjedu, pak jej sem dám. ASC jsem již odinstaloval)

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Verze: v2014.02.13.09

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16476
Wow :: WOW-PC [administrátor]

13.2.2014 20:23:18
mbam-log-2014-02-13 (20-23-18).txt

Typ: Kompletní kontrola (C:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 158844
Uplynulý čas: 52 minut, 29 sekund [přerušeno]

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 1
C:\Users\Wow\AppData\Local\Google\Chrome\User Data\Default\File System\000\t\00\00000000 (PUP.Optional.OneClickDownloader.A) -> Přesun do karantény a smazání se zdařilo.

(konec)

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Postupné zpomalování a sekání se PC

#4 Příspěvek od Márty84 »

Jj, udelejte novou, jestli se nahodou neco neobjevilo. Pokud bude cisto, dejte sem hned log z ADWCleaneru.


:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner a ulozte ho na plochu.
Ukoncete vsechny programy, jinak to AdwCleaner udela za vas.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Kliknete na Scan a program zacne pracovat.
Az skonci, vyplivne na vas log (pokud ne, najdete ho zde C:\AdwCleaner\AdwCleaner[R?].txt ), ten mi sem zkopirujte.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

mlzd
Návštěvník
Návštěvník
Příspěvky: 130
Registrován: 02 led 2005 00:36
Bydliště: VDF

Re: Postupné zpomalování a sekání se PC

#5 Příspěvek od mlzd »

Malwarebytes Anti-Malware 1.75.0.1300
http://www.malwarebytes.org

Verze: v2014.02.13.09

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16518
Wow :: WOW-PC [administrátor]

14.2.2014 20:25:44
mbam-log-2014-02-14 (20-25-44).txt

Typ: Kompletní kontrola (C:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 460978
Uplynulý čas: 1 hodin, 13 minut, 11 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 1
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.StartPage.A) -> Špatný: (http://www.searchgol.com/?babsrc=HP_ss& ... 2&tsp=5022) Dobrý: (http://www.google.com) -> Přesun do karantény a opravení se zdařilo.

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)

(konec)
*******************************************************************

# AdwCleaner v2.007 - Logfile created 02/14/2014 at 21:43:42
# Updated 06/11/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Wow - WOW-PC
# Boot Mode : Normal
# Running from : D:\Internet_safety\adwcleaner.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****


***** [Registry] *****


***** [Internet Browsers] *****

-\\ Internet Explorer v9.11.9600.16518

[OK] Registry is clean.

-\\ Mozilla Firefox v27.0.1 (cs)

Profile name : default-1368026474286 [Profil par défaut]
File : C:\Users\Wow\AppData\Roaming\Mozilla\Firefox\Profiles\ve2ispyc.default-1368026474286\prefs.js

[OK] File is clean.

-\\ Google Chrome v32.0.1700.107

File : C:\Users\Wow\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

-\\ Opera v [Unable to get version]

File : C:\Users\Wow\AppData\Roaming\Opera\Opera\operaprefs.ini

[OK] File is clean.

*************************

AdwCleaner[R40].txt - [997 octets] - [14/02/2014 21:43:42]

########## EOF - C:\AdwCleaner[R40].txt - [1057 octets] ##########

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Postupné zpomalování a sekání se PC

#6 Příspěvek od Márty84 »

:!: Jestli bude Avast rvat, ze to chce otevrit v sandboxu, nedovolte to! Vyberte moznost Otevrit normalne
:arrow: Stahnete RogueKiller http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe , ulozte ho na plochu, kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Probehne kratoucky testik a pak se zpristupni vpravo nahore tlacitko Prohledat. Na to kliknete a probehne dalsi test.
Po dokonceni kliknete na napis Zprava a objevi se log. Ten mi sem vlozte
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

mlzd
Návštěvník
Návštěvník
Příspěvky: 130
Registrován: 02 led 2005 00:36
Bydliště: VDF

Re: Postupné zpomalování a sekání se PC

#7 Příspěvek od mlzd »

RogueKiller V8.8.7 [Feb 11 2014] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://forum.adlice.com
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno v : Normální režim
Uživatel : Wow [Práva správce]
Mód : Kontrola -- Datum : 02/14/2014 23:54:37
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 5 ¤¤¤
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> NALEZENO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> NALEZENO
[HJ SMENU][PUM] HKCU\[...]\Advanced : Start_TrackProgs (0) -> NALEZENO
[HJ DESK][PUM] HKCU\[...]\ClassicStartMenu : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK][PUM] HKCU\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Browser Addons : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ SCSI) WDC WD7501AALS-00J7B SCSI Disk Device +++++
--- User ---
[MBR] 435e26f908dfa6a50372973023b92aec
[BSP] 618b8c597363f168fa3864521bbdea84 : Acer MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 14000 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 28674048 | Size: 100 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 28878848 | Size: 368076 Mo
3 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 782698496 | Size: 333226 Mo
User = LL1 ... OK!
Error reading LL2 MBR! ([0x1] Nesprávná funkce. )

Dokončeno : << RKreport[0]_S_02142014_235437.txt >>

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Postupné zpomalování a sekání se PC

#8 Příspěvek od Márty84 »

:arrow: Znovu spustte RogueKiller jako spravce (pokud jste ho jeste nezavrel/a, rovnou kliknete na napis Smazat)
Probehne kratoucky testik a pak se zpristupni vpravo nahore tlacitko Prohledat. Na to kliknete a probehne dalsi test.
Po dokonceni kliknete na napis Smazat.
Pak kliknete na napis Zprava a objevi se log. Ten mi sem vlozte.
Pak kliknete na napis Oprava Host a Zprava.
Objevi se dalsi log. I ten mi sem vlozte.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

mlzd
Návštěvník
Návštěvník
Příspěvky: 130
Registrován: 02 led 2005 00:36
Bydliště: VDF

Re: Postupné zpomalování a sekání se PC

#9 Příspěvek od mlzd »

RogueKiller V8.8.7 [Feb 11 2014] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://forum.adlice.com
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno v : Normální režim
Uživatel : Wow [Práva správce]
Mód : Odebrat -- Datum : 02/15/2014 12:27:02
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 5 ¤¤¤
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> VYMAZÁNO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> VYMAZÁNO
[HJ SMENU][PUM] HKCU\[...]\Advanced : Start_TrackProgs (0) -> NAHRAZENO (1)
[HJ DESK][PUM] HKCU\[...]\ClassicStartMenu : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRAZENO (0)
[HJ DESK][PUM] HKCU\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRAZENO (0)

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Browser Addons : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ SCSI) WDC WD7501AALS-00J7B SCSI Disk Device +++++
--- User ---
[MBR] 435e26f908dfa6a50372973023b92aec
[BSP] 618b8c597363f168fa3864521bbdea84 : Acer MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 14000 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 28674048 | Size: 100 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 28878848 | Size: 368076 Mo
3 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 782698496 | Size: 333226 Mo
User = LL1 ... OK!
Error reading LL2 MBR! ([0x1] Nesprávná funkce. )

+++++ PhysicalDrive1: (\\.\PHYSICALDRIVE2 @ USB) USB DISK Pro USB Device +++++
--- User ---
[MBR] 8cd7cf884afd3a724bd33f94e6c1565d
[BSP] 33a07a59d299ab4ea9f4ab0156f9d86f : Windows XP MBR Code
Partition table:
0 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 8064 | Size: 7377 Mo
User = LL1 ... OK!
Error reading LL2 MBR! ([0x32] Po?adavek není podporován. )

Dokončeno : << RKreport[0]_D_02152014_122702.txt >>
RKreport[0]_S_02142014_235437.txt;RKreport[0]_S_02152014_122420.txt

______________________________________________________________________

RogueKiller V8.8.7 [Feb 11 2014] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://forum.adlice.com
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno v : Normální režim
Uživatel : Wow [Práva správce]
Mód : Oprava HOSTS -- Datum : 02/15/2014 12:28:29
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 0 ¤¤¤

¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ Resetovaný HOSTS: ¤¤¤
127.0.0.1 localhost


Dokončeno : << RKreport[0]_H_02152014_122829.txt >>
RKreport[0]_D_02152014_122702.txt;RKreport[0]_S_02142014_235437.txt;RKreport[0]_S_02152014_122420.txt

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Postupné zpomalování a sekání se PC

#10 Příspěvek od Márty84 »

:!: Pokud nemate, zazalohujte si radeji dulezita data (fotky, dokumenty, atd.) :!:

:!: Nepouzivejte ComboFix bez predchozi domluvy! Je to poruseni pravidel fora a ztratite tim narok na pomoc!

:arrow: Stahnete ComboFix http://download.bleepingcomputer.com/sUBs/ComboFix.exe a ulozte ho na plochu.
Vypnete antivir i dalsi pripadne zabezpeceni.
Kliknete na ComboFix pravym mysidlem a levym na Spustit jako spravce
Odsouhlaste licencni podminky a nechte program pracovat. Jestli vam nabidne instalaci Konzoly pro zotaveni, souhlaste.
Po dobu skenu nic nespoustejte, nikam neklikejte.
Po dokonceni skenovani (muze dojit i k restartu pc) by se mel vytvorit log, ktery bude umisteny zde C:\ComboFix.txt
Jeho obsah sem zkopirujte

:!: Kdyby po restartu nenabehl windows, restartujte znovu, mackejte klavesu F8 a zvolte - Posledni znama funkcni konfigurace
:!: Kdyz windows nabehne, ale pri spousteni ruznych programu bude hlasena chyba, staci restartovat pc a bude to v poradku
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

mlzd
Návštěvník
Návštěvník
Příspěvky: 130
Registrován: 02 led 2005 00:36
Bydliště: VDF

Re: Postupné zpomalování a sekání se PC

#11 Příspěvek od mlzd »

ComboFix 14-02-14.01 - Wow 16.02.2014 4:17.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3056.1372 [GMT 1:00]
Spuštěný z: c:\users\Wow\Videos\Tracing\Desktop\ComboFix.exe
AV: avast! Internet Security *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
FW: avast! Internet Security *Disabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
SP: avast! Internet Security *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Install.exe
c:\program files (x86)\Common Files\Acer GameZone online.ico
c:\programdata\311085A2B3.sys
c:\users\Public\AlexaNSISPlugin.3912.dll
c:\users\Wow\AppData\Local\._Revolution_
c:\users\Wow\AppData\Local\assembly\tmp
c:\users\Wow\AppData\Local\assembly\tmp\VO63XOZM\__AssemblyInfo__.ini
c:\users\Wow\AppData\Local\assembly\tmp\VO63XOZM\SMSender.182.DLL
c:\users\Wow\AppData\Roaming\.#
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\wininit.ini
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-01-16 do 2014-02-16 )))))))))))))))))))))))))))))))
.
.
2014-02-14 22:38 . 2014-02-14 22:38 28184 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2014-02-14 22:38 . 2014-02-14 22:38 440672 ----a-w- c:\windows\system32\drivers\aswNdisFlt.sys
2014-02-13 22:51 . 2013-12-21 09:53 548864 ----a-w- c:\windows\system32\vbscript.dll
2014-02-13 22:51 . 2013-12-21 08:56 454656 ----a-w- c:\windows\SysWow64\vbscript.dll
2014-02-13 18:50 . 2014-02-13 18:51 -------- d-----w- C:\rsit
2014-02-08 11:01 . 2014-02-08 11:01 -------- d-----w- c:\users\Wow\AppData\Roaming\IrfanView
2014-02-05 21:27 . 2014-02-05 22:19 -------- d-----w- c:\users\Wow\AppData\Local\MailRu
2014-02-05 21:26 . 2014-02-05 21:26 -------- d-----w- c:\users\Wow\AppData\Local\Mail.Ru
2014-02-04 22:42 . 2014-02-04 22:42 -------- d-----w- c:\users\Wow\AppData\Roaming\Opera Software
2014-02-04 22:42 . 2014-02-04 22:42 -------- d-----w- c:\users\Wow\AppData\Local\Opera Software
2014-02-04 21:46 . 2014-02-04 21:46 -------- d-----w- c:\users\Wow\AppData\Roaming\AVAST Software
2014-02-04 21:45 . 2014-02-04 21:45 80184 ----a-w- c:\windows\system32\drivers\aswStm.sys
2014-02-04 21:45 . 2014-02-04 21:45 207904 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-02-04 21:45 . 2014-02-04 21:45 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-02-04 21:45 . 2014-02-04 21:45 1038072 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2014-02-04 21:45 . 2014-02-04 21:45 421704 ----a-w- c:\windows\system32\drivers\aswSP.sys
2014-02-04 21:45 . 2014-02-04 21:45 78648 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-02-04 21:45 . 2014-02-04 21:45 92544 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-02-04 21:45 . 2014-02-04 21:45 334136 ----a-w- c:\windows\system32\aswBoot.exe
2014-02-04 21:45 . 2014-02-04 21:45 43152 ----a-w- c:\windows\avastSS.scr
2014-02-04 21:44 . 2014-02-04 21:44 -------- d-----w- c:\program files\AVAST Software
2014-02-04 21:43 . 2014-02-04 21:43 -------- d-----w- c:\programdata\AVAST Software
2014-02-03 18:41 . 2014-02-03 18:41 -------- d-----w- c:\users\Wow\AppData\Roaming\Malwarebytes
2014-02-03 18:41 . 2014-02-03 18:41 -------- d-----w- c:\programdata\Malwarebytes
2014-02-03 18:41 . 2014-02-03 18:41 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2014-02-03 18:41 . 2013-04-04 13:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-01-29 19:36 . 2014-01-29 19:36 -------- d-----w- c:\program files\Enigma Software Group
2014-01-29 13:52 . 2014-02-04 21:42 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy 2
2014-01-17 07:54 . 2014-01-17 07:54 -------- d-----w- c:\users\Wow\AppData\Local\Dup Scout
2014-01-17 07:53 . 2014-01-17 07:53 -------- d-----w- c:\program files (x86)\Dup Scout
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-02-05 18:59 . 2012-04-03 13:45 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-02-05 18:59 . 2011-09-05 13:23 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-01-15 14:32 . 2010-01-30 11:33 86054176 ----a-w- c:\windows\system32\MRT.exe
2013-12-03 12:45 . 2013-12-03 12:45 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-12-03 12:45 . 2013-12-03 12:45 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2013-12-03 12:44 . 2013-12-03 12:44 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2013-12-03 12:44 . 2013-12-03 12:44 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll
2013-12-03 12:44 . 2013-12-03 12:44 235008 ----a-w- c:\windows\system32\elshyph.dll
2013-12-03 12:44 . 2013-12-03 12:44 182272 ----a-w- c:\windows\SysWow64\msls31.dll
2013-12-03 12:44 . 2013-12-03 12:44 62464 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-12-03 12:44 . 2013-12-03 12:44 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2013-12-03 12:44 . 2013-12-03 12:44 337408 ----a-w- c:\windows\SysWow64\html.iec
2013-12-03 12:44 . 2013-12-03 12:44 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2013-12-03 12:44 . 2013-12-03 12:44 36352 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-12-03 12:44 . 2013-12-03 12:44 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-12-03 12:44 . 2013-12-03 12:44 151552 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-12-03 12:44 . 2013-12-03 12:44 139264 ----a-w- c:\windows\SysWow64\wextract.exe
2013-12-03 12:44 . 2013-12-03 12:44 13312 ----a-w- c:\windows\SysWow64\mshta.exe
2013-12-03 12:44 . 2013-12-03 12:44 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-12-03 12:44 . 2013-12-03 12:44 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll
2013-12-03 12:44 . 2013-12-03 12:44 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-12-03 12:44 . 2013-12-03 12:44 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-12-03 12:44 . 2013-12-03 12:44 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-12-03 12:44 . 2013-12-03 12:44 942592 ----a-w- c:\windows\system32\jsIntl.dll
2013-12-03 12:44 . 2013-12-03 12:44 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-12-03 12:44 . 2013-12-03 12:44 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-12-03 12:44 . 2013-12-03 12:44 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-12-03 12:44 . 2013-12-03 12:44 247808 ----a-w- c:\windows\system32\msls31.dll
2013-12-03 12:44 . 2013-12-03 12:44 13312 ----a-w- c:\windows\system32\msfeedssync.exe
2013-12-03 12:44 . 2013-12-03 12:44 131072 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-12-03 12:44 . 2013-12-03 12:44 84992 ----a-w- c:\windows\system32\mshtmled.dll
2013-12-03 12:44 . 2013-12-03 12:44 81408 ----a-w- c:\windows\system32\icardie.dll
2013-12-03 12:44 . 2013-12-03 12:44 77312 ----a-w- c:\windows\system32\tdc.ocx
2013-12-03 12:44 . 2013-12-03 12:44 616104 ----a-w- c:\windows\system32\ieapfltr.dat
2013-12-03 12:44 . 2013-12-03 12:44 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-12-03 12:44 . 2013-12-03 12:44 453120 ----a-w- c:\windows\system32\dxtmsft.dll
2013-12-03 12:44 . 2013-12-03 12:44 413696 ----a-w- c:\windows\system32\html.iec
2013-12-03 12:44 . 2013-12-03 12:44 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2013-12-03 12:44 . 2013-12-03 12:44 30208 ----a-w- c:\windows\system32\licmgr10.dll
2013-12-03 12:44 . 2013-12-03 12:44 296960 ----a-w- c:\windows\system32\dxtrans.dll
2013-12-03 12:44 . 2013-12-03 12:44 263376 ----a-w- c:\windows\system32\iedkcs32.dll
2013-12-03 12:44 . 2013-12-03 12:44 243200 ----a-w- c:\windows\system32\webcheck.dll
2013-12-03 12:44 . 2013-12-03 12:44 235520 ----a-w- c:\windows\system32\url.dll
2013-12-03 12:44 . 2013-12-03 12:44 167424 ----a-w- c:\windows\system32\iexpress.exe
2013-12-03 12:44 . 2013-12-03 12:44 143872 ----a-w- c:\windows\system32\wextract.exe
2013-12-03 12:44 . 2013-12-03 12:44 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-12-03 12:44 . 2013-12-03 12:44 105984 ----a-w- c:\windows\system32\iesysprep.dll
2013-12-03 12:44 . 2013-12-03 12:44 101376 ----a-w- c:\windows\system32\inseng.dll
2013-12-03 12:44 . 2013-12-03 12:44 83968 ----a-w- c:\windows\system32\MshtmlDac.dll
2013-12-03 12:44 . 2013-12-03 12:44 774144 ----a-w- c:\windows\system32\jscript.dll
2013-12-03 12:44 . 2013-12-03 12:44 62464 ----a-w- c:\windows\system32\pngfilt.dll
2013-12-03 12:44 . 2013-12-03 12:44 48128 ----a-w- c:\windows\system32\imgutil.dll
2013-12-03 12:44 . 2013-12-03 12:44 147968 ----a-w- c:\windows\system32\occache.dll
2013-12-03 12:44 . 2013-12-03 12:44 13824 ----a-w- c:\windows\system32\mshta.exe
2013-12-03 12:44 . 2013-12-03 12:44 135680 ----a-w- c:\windows\system32\iepeers.dll
2013-11-27 01:41 . 2014-01-15 11:02 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2013-11-27 01:41 . 2014-01-15 11:02 99840 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2013-11-27 01:41 . 2014-01-15 11:02 53248 ----a-w- c:\windows\system32\drivers\usbehci.sys
2013-11-27 01:41 . 2014-01-15 11:02 325120 ----a-w- c:\windows\system32\drivers\usbport.sys
2013-11-27 01:41 . 2014-01-15 11:02 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys
2013-11-27 01:41 . 2014-01-15 11:02 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2013-11-27 01:41 . 2014-01-15 11:02 7808 ----a-w- c:\windows\system32\drivers\usbd.sys
2013-11-26 11:40 . 2014-01-15 11:02 376768 ----a-w- c:\windows\system32\drivers\netio.sys
2013-11-26 10:32 . 2014-01-15 11:02 3156480 ----a-w- c:\windows\system32\win32k.sys
2013-11-23 18:26 . 2013-12-11 13:44 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll
2013-11-23 17:47 . 2013-12-11 13:44 465920 ----a-w- c:\windows\system32\WMPhoto.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2009-09-10 13:41 120104 ----a-w- c:\program files (x86)\EgisTec\MyWinLocker 3\x86\PSDProtect.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Hotkey Utility"="c:\program files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe" [2009-08-18 629280]
"Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-02-04 3767096]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0cnat
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"ArcadeDeluxeAgent"="c:\program files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"BackupManagerTray"="c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
"SDTray"="c:\program files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 LiveUpdateSvc;LiveUpdate;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 pcwe;pcwe;d:\programy_system\PC_Wizard\pcw86-64.sys;d:\programy_system\PC_Wizard\pcw86-64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys;c:\windows\SYSNATIVE\drivers\aswKbd.sys [x]
S1 aswNdisFlt;Avast! Firewall Driver;c:\windows\system32\DRIVERS\aswNdisFlt.sys;c:\windows\SYSNATIVE\DRIVERS\aswNdisFlt.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDFilter.sys [x]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDNServ.sys [x]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDVDisk.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe;c:\program files\AVAST Software\Avast\afwServ.exe [x]
S2 Greg_Service;GRegService;c:\program files (x86)\Acer\Registration\GregHSRW.exe;c:\program files (x86)\Acer\Registration\GregHSRW.exe [x]
S2 MWLService;MyWinLocker Service;c:\program files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe;c:\program files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [x]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe;c:\program files\Acer\Acer Updater\UpdaterService.exe [x]
S2 WDDMService;WDDMService;c:\program files\Western Digital\WD SmartWare\WDDMService.exe;c:\program files\Western Digital\WD SmartWare\WDDMService.exe [x]
S2 WDFMEService;WDFME;c:\program files\Western Digital\WD SmartWare\WDFME.exe;c:\program files\Western Digital\WD SmartWare\WDFME.exe [x]
S2 WDRulesService;WDRules;c:\program files\Western Digital\WD SmartWare\WDRulesEngine.exe;c:\program files\Western Digital\WD SmartWare\WDRulesEngine.exe [x]
S2 yksvc;Marvell Yukon Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S3 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys;c:\windows\SYSNATIVE\DRIVERS\wdcsam64.sys [x]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
Obsah adresáře 'Naplánované úlohy'
.
2014-02-12 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 18:59]
.
2013-09-21 c:\windows\Tasks\HP Photo Creations Communicator.job
- c:\programdata\HP Photo Creations\Communicator.exe [2013-05-29 22:49]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-02-04 21:45 287280 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2009-09-10 13:44 137512 ----a-w- c:\program files (x86)\EgisTec\MyWinLocker 3\x64\PSDProtect.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-07-20 7981088]
"snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-18 843776]
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Poslat jako MMS - c:\program files (x86)\O2\SMSender\SMSender.E.182.dll/1003
IE: Poslat jako SMS - c:\program files (x86)\O2\SMSender\SMSender.E.182.dll/1001
IE: Poslat MMS na - c:\program files (x86)\O2\SMSender\SMSender.E.182.dll/1002
IE: Poslat SMS na - c:\program files (x86)\O2\SMSender\SMSender.E.182.dll/1000
IE: WikiKomentáře Google... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Wow\AppData\Roaming\Mozilla\Firefox\Profiles\ve2ispyc.default-1368026474286\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: network.proxy.type - 4
.
.
------- Asociace souborů -------
.
txtfile=NotePad.exe "%1" %*
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
SafeBoot-kEvP64.sys
SafeBoot-mcmscsvc
SafeBoot-MCODS
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
.
**************************************************************************
.
Celkový čas: 2014-02-16 04:44:11 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-02-16 03:44
.
Před spuštěním: Volných bajtů: 234 470 412 288
Po spuštění: Volných bajtů: 234 913 759 232
.
- - End Of File - - 42B27CB4CB508CF35DFAC098C92024DB

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Postupné zpomalování a sekání se PC

#12 Příspěvek od Márty84 »

:arrow: Odinstalujte Spybota, program je zastaraly.

:!: Presunte ComboFix na plochu, pokud tam neni.
:arrow: Otevrete si poznamkovy blok a zkopirujte do nej tento skript

Kód: Vybrat vše

KillAll::

Registry::
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"=-

RegLock::
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]

Driver::
SkypeUpdate

Reboot::
Vlevo nahore kliknete na napis Soubor
Kliknete na napis Ulozit jako...
Napiste spravne ten cerveny nazev CFScript a ulozte na plochu.
Vypnete antivir i dalsi pripadne zabezpeceni.
Pretahntete mysi tento vytvoreny textovy dokument nad ikonu ComboFix a pustte.
ComboFix by se mel spustit a vykonat prikazy.
Az skonci (muze dojit k restartu pc), mel by se objevit novy log, ten mi sem zase zkopirujte.

:!: Kdyby po restartu nenabehl windows, restartujte znovu, mackejte klavesu F8 a zvolte - Posledni znama funkcni konfigurace
:!: Kdyz windows nabehne, ale pri spousteni ruznych programu bude hlasena chyba, staci restartovat pc a bude to v poradku
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

mlzd
Návštěvník
Návštěvník
Příspěvky: 130
Registrován: 02 led 2005 00:36
Bydliště: VDF

Re: Postupné zpomalování a sekání se PC

#13 Příspěvek od mlzd »

ComboFix 14-02-14.01 - Wow 16.02.2014 13:01:35.2.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3056.921 [GMT 1:00]
Spuštěný z: c:\users\Wow\Videos\Tracing\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Wow\Videos\Tracing\Desktop\CFScript.txt
AV: avast! Internet Security *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
FW: avast! Internet Security *Disabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
SP: avast! Internet Security *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_SkypeUpdate
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-01-16 do 2014-02-16 )))))))))))))))))))))))))))))))
.
.
2014-02-16 12:20 . 2014-02-16 12:20 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-02-16 12:20 . 2014-02-16 12:20 -------- d-----w- c:\users\Guest\AppData\Local\temp
2014-02-14 22:38 . 2014-02-14 22:38 28184 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2014-02-14 22:38 . 2014-02-14 22:38 440672 ----a-w- c:\windows\system32\drivers\aswNdisFlt.sys
2014-02-13 22:51 . 2013-12-21 09:53 548864 ----a-w- c:\windows\system32\vbscript.dll
2014-02-13 22:51 . 2013-12-21 08:56 454656 ----a-w- c:\windows\SysWow64\vbscript.dll
2014-02-13 18:50 . 2014-02-13 18:51 -------- d-----w- C:\rsit
2014-02-08 11:01 . 2014-02-08 11:01 -------- d-----w- c:\users\Wow\AppData\Roaming\IrfanView
2014-02-05 21:27 . 2014-02-05 22:19 -------- d-----w- c:\users\Wow\AppData\Local\MailRu
2014-02-05 21:26 . 2014-02-05 21:26 -------- d-----w- c:\users\Wow\AppData\Local\Mail.Ru
2014-02-04 22:42 . 2014-02-04 22:42 -------- d-----w- c:\users\Wow\AppData\Roaming\Opera Software
2014-02-04 22:42 . 2014-02-04 22:42 -------- d-----w- c:\users\Wow\AppData\Local\Opera Software
2014-02-04 21:46 . 2014-02-04 21:46 -------- d-----w- c:\users\Wow\AppData\Roaming\AVAST Software
2014-02-04 21:45 . 2014-02-04 21:45 80184 ----a-w- c:\windows\system32\drivers\aswStm.sys
2014-02-04 21:45 . 2014-02-04 21:45 207904 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-02-04 21:45 . 2014-02-04 21:45 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-02-04 21:45 . 2014-02-04 21:45 1038072 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2014-02-04 21:45 . 2014-02-04 21:45 421704 ----a-w- c:\windows\system32\drivers\aswSP.sys
2014-02-04 21:45 . 2014-02-04 21:45 78648 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-02-04 21:45 . 2014-02-04 21:45 92544 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-02-04 21:45 . 2014-02-04 21:45 334136 ----a-w- c:\windows\system32\aswBoot.exe
2014-02-04 21:45 . 2014-02-04 21:45 43152 ----a-w- c:\windows\avastSS.scr
2014-02-04 21:44 . 2014-02-04 21:44 -------- d-----w- c:\program files\AVAST Software
2014-02-04 21:43 . 2014-02-04 21:43 -------- d-----w- c:\programdata\AVAST Software
2014-02-03 18:41 . 2014-02-03 18:41 -------- d-----w- c:\users\Wow\AppData\Roaming\Malwarebytes
2014-02-03 18:41 . 2014-02-03 18:41 -------- d-----w- c:\programdata\Malwarebytes
2014-02-03 18:41 . 2014-02-03 18:41 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2014-02-03 18:41 . 2013-04-04 13:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-01-29 19:36 . 2014-01-29 19:36 -------- d-----w- c:\program files\Enigma Software Group
2014-01-29 13:52 . 2014-02-04 21:42 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy 2
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-02-05 18:59 . 2012-04-03 13:45 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-02-05 18:59 . 2011-09-05 13:23 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-01-15 14:32 . 2010-01-30 11:33 86054176 ----a-w- c:\windows\system32\MRT.exe
2013-12-03 12:45 . 2013-12-03 12:45 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-12-03 12:45 . 2013-12-03 12:45 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2013-12-03 12:44 . 2013-12-03 12:44 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2013-12-03 12:44 . 2013-12-03 12:44 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll
2013-12-03 12:44 . 2013-12-03 12:44 235008 ----a-w- c:\windows\system32\elshyph.dll
2013-12-03 12:44 . 2013-12-03 12:44 182272 ----a-w- c:\windows\SysWow64\msls31.dll
2013-12-03 12:44 . 2013-12-03 12:44 62464 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-12-03 12:44 . 2013-12-03 12:44 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2013-12-03 12:44 . 2013-12-03 12:44 337408 ----a-w- c:\windows\SysWow64\html.iec
2013-12-03 12:44 . 2013-12-03 12:44 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2013-12-03 12:44 . 2013-12-03 12:44 36352 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-12-03 12:44 . 2013-12-03 12:44 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-12-03 12:44 . 2013-12-03 12:44 151552 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-12-03 12:44 . 2013-12-03 12:44 139264 ----a-w- c:\windows\SysWow64\wextract.exe
2013-12-03 12:44 . 2013-12-03 12:44 13312 ----a-w- c:\windows\SysWow64\mshta.exe
2013-12-03 12:44 . 2013-12-03 12:44 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-12-03 12:44 . 2013-12-03 12:44 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll
2013-12-03 12:44 . 2013-12-03 12:44 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-12-03 12:44 . 2013-12-03 12:44 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-12-03 12:44 . 2013-12-03 12:44 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-12-03 12:44 . 2013-12-03 12:44 942592 ----a-w- c:\windows\system32\jsIntl.dll
2013-12-03 12:44 . 2013-12-03 12:44 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-12-03 12:44 . 2013-12-03 12:44 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-12-03 12:44 . 2013-12-03 12:44 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-12-03 12:44 . 2013-12-03 12:44 247808 ----a-w- c:\windows\system32\msls31.dll
2013-12-03 12:44 . 2013-12-03 12:44 13312 ----a-w- c:\windows\system32\msfeedssync.exe
2013-12-03 12:44 . 2013-12-03 12:44 131072 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-12-03 12:44 . 2013-12-03 12:44 84992 ----a-w- c:\windows\system32\mshtmled.dll
2013-12-03 12:44 . 2013-12-03 12:44 81408 ----a-w- c:\windows\system32\icardie.dll
2013-12-03 12:44 . 2013-12-03 12:44 77312 ----a-w- c:\windows\system32\tdc.ocx
2013-12-03 12:44 . 2013-12-03 12:44 616104 ----a-w- c:\windows\system32\ieapfltr.dat
2013-12-03 12:44 . 2013-12-03 12:44 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-12-03 12:44 . 2013-12-03 12:44 453120 ----a-w- c:\windows\system32\dxtmsft.dll
2013-12-03 12:44 . 2013-12-03 12:44 413696 ----a-w- c:\windows\system32\html.iec
2013-12-03 12:44 . 2013-12-03 12:44 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2013-12-03 12:44 . 2013-12-03 12:44 30208 ----a-w- c:\windows\system32\licmgr10.dll
2013-12-03 12:44 . 2013-12-03 12:44 296960 ----a-w- c:\windows\system32\dxtrans.dll
2013-12-03 12:44 . 2013-12-03 12:44 263376 ----a-w- c:\windows\system32\iedkcs32.dll
2013-12-03 12:44 . 2013-12-03 12:44 243200 ----a-w- c:\windows\system32\webcheck.dll
2013-12-03 12:44 . 2013-12-03 12:44 235520 ----a-w- c:\windows\system32\url.dll
2013-12-03 12:44 . 2013-12-03 12:44 167424 ----a-w- c:\windows\system32\iexpress.exe
2013-12-03 12:44 . 2013-12-03 12:44 143872 ----a-w- c:\windows\system32\wextract.exe
2013-12-03 12:44 . 2013-12-03 12:44 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-12-03 12:44 . 2013-12-03 12:44 105984 ----a-w- c:\windows\system32\iesysprep.dll
2013-12-03 12:44 . 2013-12-03 12:44 101376 ----a-w- c:\windows\system32\inseng.dll
2013-12-03 12:44 . 2013-12-03 12:44 83968 ----a-w- c:\windows\system32\MshtmlDac.dll
2013-12-03 12:44 . 2013-12-03 12:44 774144 ----a-w- c:\windows\system32\jscript.dll
2013-12-03 12:44 . 2013-12-03 12:44 62464 ----a-w- c:\windows\system32\pngfilt.dll
2013-12-03 12:44 . 2013-12-03 12:44 48128 ----a-w- c:\windows\system32\imgutil.dll
2013-12-03 12:44 . 2013-12-03 12:44 147968 ----a-w- c:\windows\system32\occache.dll
2013-12-03 12:44 . 2013-12-03 12:44 13824 ----a-w- c:\windows\system32\mshta.exe
2013-12-03 12:44 . 2013-12-03 12:44 135680 ----a-w- c:\windows\system32\iepeers.dll
2013-11-27 01:41 . 2014-01-15 11:02 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2013-11-27 01:41 . 2014-01-15 11:02 99840 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2013-11-27 01:41 . 2014-01-15 11:02 53248 ----a-w- c:\windows\system32\drivers\usbehci.sys
2013-11-27 01:41 . 2014-01-15 11:02 325120 ----a-w- c:\windows\system32\drivers\usbport.sys
2013-11-27 01:41 . 2014-01-15 11:02 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys
2013-11-27 01:41 . 2014-01-15 11:02 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2013-11-27 01:41 . 2014-01-15 11:02 7808 ----a-w- c:\windows\system32\drivers\usbd.sys
2013-11-26 11:40 . 2014-01-15 11:02 376768 ----a-w- c:\windows\system32\drivers\netio.sys
2013-11-26 10:32 . 2014-01-15 11:02 3156480 ----a-w- c:\windows\system32\win32k.sys
2013-11-23 18:26 . 2013-12-11 13:44 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll
2013-11-23 17:47 . 2013-12-11 13:44 465920 ----a-w- c:\windows\system32\WMPhoto.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2009-09-10 13:41 120104 ----a-w- c:\program files (x86)\EgisTec\MyWinLocker 3\x86\PSDProtect.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Hotkey Utility"="c:\program files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe" [2009-08-18 629280]
"Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-02-04 3767096]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0cnat
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"ArcadeDeluxeAgent"="c:\program files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
"BackupManagerTray"="c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
"SDTray"="c:\program files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 LiveUpdateSvc;LiveUpdate;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe [x]
R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 pcwe;pcwe;d:\programy_system\PC_Wizard\pcw86-64.sys;d:\programy_system\PC_Wizard\pcw86-64.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys;c:\windows\SYSNATIVE\drivers\aswKbd.sys [x]
S1 aswNdisFlt;Avast! Firewall Driver;c:\windows\system32\DRIVERS\aswNdisFlt.sys;c:\windows\SYSNATIVE\DRIVERS\aswNdisFlt.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDFilter.sys [x]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDNServ.sys [x]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDVDisk.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe;c:\program files\AVAST Software\Avast\afwServ.exe [x]
S2 Greg_Service;GRegService;c:\program files (x86)\Acer\Registration\GregHSRW.exe;c:\program files (x86)\Acer\Registration\GregHSRW.exe [x]
S2 MWLService;MyWinLocker Service;c:\program files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe;c:\program files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [x]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe;c:\program files\Acer\Acer Updater\UpdaterService.exe [x]
S2 WDDMService;WDDMService;c:\program files\Western Digital\WD SmartWare\WDDMService.exe;c:\program files\Western Digital\WD SmartWare\WDDMService.exe [x]
S2 WDFMEService;WDFME;c:\program files\Western Digital\WD SmartWare\WDFME.exe;c:\program files\Western Digital\WD SmartWare\WDFME.exe [x]
S2 WDRulesService;WDRules;c:\program files\Western Digital\WD SmartWare\WDRulesEngine.exe;c:\program files\Western Digital\WD SmartWare\WDRulesEngine.exe [x]
S2 yksvc;Marvell Yukon Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S3 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys;c:\windows\SYSNATIVE\DRIVERS\wdcsam64.sys [x]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2014-02-12 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 18:59]
.
2013-09-21 c:\windows\Tasks\HP Photo Creations Communicator.job
- c:\programdata\HP Photo Creations\Communicator.exe [2013-05-29 22:49]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-02-04 21:45 287280 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2009-09-10 13:44 137512 ----a-w- c:\program files (x86)\EgisTec\MyWinLocker 3\x64\PSDProtect.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-07-20 7981088]
"snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-18 843776]
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Poslat jako MMS - c:\program files (x86)\O2\SMSender\SMSender.E.182.dll/1003
IE: Poslat jako SMS - c:\program files (x86)\O2\SMSender\SMSender.E.182.dll/1001
IE: Poslat MMS na - c:\program files (x86)\O2\SMSender\SMSender.E.182.dll/1002
IE: Poslat SMS na - c:\program files (x86)\O2\SMSender\SMSender.E.182.dll/1000
IE: WikiKomentáře Google... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Wow\AppData\Roaming\Mozilla\Firefox\Profiles\ve2ispyc.default-1368026474286\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: network.proxy.type - 4
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
.
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
.
**************************************************************************
.
Celkový čas: 2014-02-16 13:27:33 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-02-16 12:27
ComboFix2.txt 2014-02-16 03:44
.
Před spuštěním: Volných bajtů: 234 977 611 776
Po spuštění: Volných bajtů: 234 502 623 232
.
- - End Of File - - 1F03ADD6894856673E9558F12512B643



SpyBot už mám delší dobu odinstalovaný..

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Postupné zpomalování a sekání se PC

#14 Příspěvek od Márty84 »

mlzd píše:SpyBot už mám delší dobu odinstalovaný..
V tom pripade se odinstalace nezdarila, protoze stale visi v registrech. Odpalim ho tedy silou.


:arrow: Dejte novy log z RSIT
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

mlzd
Návštěvník
Návštěvník
Příspěvky: 130
Registrován: 02 led 2005 00:36
Bydliště: VDF

Re: Postupné zpomalování a sekání se PC

#15 Příspěvek od mlzd »

Logfile of random's system information tool 1.09 (written by random/random)
Run by Wow at 2014-02-17 12:54:22
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 223 GB (61%) free of 368 GB
Total RAM: 3056 MB (15% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:54:33, on 17.2.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16518)
Boot mode: Normal

Running processes:
C:\Windows\vsnpstd3.exe
C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Servant Salamander 2.0\salamand.exe
C:\Program Files\trend micro\Wow.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [Hotkey Utility] C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Poslat jako MMS - res://C:\Program Files (x86)\O2\SMSender\SMSender.E.182.dll/1003
O8 - Extra context menu item: Poslat jako SMS - res://C:\Program Files (x86)\O2\SMSender\SMSender.E.182.dll/1001
O8 - Extra context menu item: Poslat MMS na - res://C:\Program Files (x86)\O2\SMSender\SMSender.E.182.dll/1002
O8 - Extra context menu item: Poslat SMS na - res://C:\Program Files (x86)\O2\SMSender\SMSender.E.182.dll/1000
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GRegService (Greg_Service) - Acer Incorporated - C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MyWinLocker Service (MWLService) - Egis Technology Inc. - C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe
O23 - Service: NTI IScheduleSvc - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Updater Service - Acer - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: WDDMService - WDC - C:\Program Files\Western Digital\WD SmartWare\WDDMService.exe
O23 - Service: WDFME (WDFMEService) - Western Digital - C:\Program Files\Western Digital\WD SmartWare\WDFME.exe
O23 - Service: WDRules (WDRulesService) - Western Digital - C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8597 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\System32\svchost.exe -k yksvcs
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Program Files\AVAST Software\Avast\afwServ.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Acer\Registration\GregHSRW.exe"
"C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe"
"C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Acer\Acer Updater\UpdaterService.exe"
"C:\Program Files\Western Digital\WD SmartWare\WDDMService.exe"
"C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 2320
"C:\Program Files\Western Digital\WD SmartWare\WDFME.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-22d6be4a-1472-4450-a076-daf0bd3dd6e8 -SystemEventPortName:HostProcess-fd8cc107-fed0-4751-90ff-1b9d6f5bf4dc -IoCancelEventPortName:HostProcess-10b18e54-c5e1-4d11-8501-427bc1d1686b -NonStateChangingEventPortName:HostProcess-ad549611-5540-45e8-b8b4-5fc4f9acf2b2 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:0bef3bc8-f785-4be0-bdba-133e7bfd4eb1 -DeviceGroupId:WpdFsGroup
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Windows\vsnpstd3.exe"
"C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Servant Salamander 2.0\salamand.exe"
"D:\Internet_safety\Viry_RSIT\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\HP Photo Creations Communicator.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Wow\AppData\Roaming\Mozilla\Firefox\Profiles\ve2ispyc.default-1368026474286

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 12.0.0.44 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.21.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Windows\SysWOW64\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5]
"Description"=A component of your photo software powered by RocketLife
"Path"=C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 12.0.0.43 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

C:\Program Files (x86)\Mozilla Firefox\extensions\
{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}

C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
nppdf32.dll
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

C:\Users\Wow\AppData\Roaming\Mozilla\Firefox\Profiles\ve2ispyc.default-1368026474286\extensions\
adsremoval@adsremoval.net

C:\Users\Wow\AppData\Roaming\Mozilla\Firefox\Profiles\ve2ispyc.default-1368026474286\searchplugins\
peklada-google.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-02-04 1390368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2013-05-08 77424]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-02-04 1143168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-02-04 1390368]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-02-04 1143168]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-07-20 7981088]
"snpstd3"=C:\Windows\vsnpstd3.exe [2006-09-18 843776]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe [2013-04-04 958576]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EgisTecLiveUpdate]
c:\program files (x86)\egistec egis software update\egisupdate.exe [2009-08-04 199464]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [2010-06-09 49208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mwlDaemon]
c:\program files (x86)\egistec\mywinlocker 3\x86\mwldaemon.exe [2009-09-10 349480]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nástroj WD Quick View]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tsnpstd3]
C:\Windows\tsnpstd3.exe [2007-03-30 262144]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WD Quick View]
[]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Hotkey Utility"=C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe [2009-08-18 629280]
"Microsoft Default Manager"=C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [2010-05-10 439568]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-02-04 3767096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=0x00000000
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll

======File associations======

.js - edit -
.txt - open - NotePad.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-02-16 13:27:41 ----SHD---- C:\$RECYCLE.BIN
2014-02-16 13:27:34 ----A---- C:\ComboFix.txt
2014-02-16 04:14:27 ----A---- C:\Windows\zip.exe
2014-02-16 04:14:27 ----A---- C:\Windows\SWSC.exe
2014-02-16 04:14:27 ----A---- C:\Windows\SWREG.exe
2014-02-16 04:14:27 ----A---- C:\Windows\sed.exe
2014-02-16 04:14:27 ----A---- C:\Windows\PEV.exe
2014-02-16 04:14:27 ----A---- C:\Windows\NIRCMD.exe
2014-02-16 04:14:27 ----A---- C:\Windows\MBR.exe
2014-02-16 04:14:27 ----A---- C:\Windows\grep.exe
2014-02-16 04:14:19 ----D---- C:\Qoobox
2014-02-16 04:14:06 ----D---- C:\Windows\erdnt
2014-02-14 23:38:22 ----A---- C:\Windows\system32\drivers\aswKbd.sys
2014-02-14 23:38:05 ----A---- C:\Windows\system32\drivers\aswNdisFlt.sys
2014-02-14 21:43:42 ----A---- C:\AdwCleaner[R40].txt
2014-02-14 09:13:20 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-02-13 23:54:23 ----D---- C:\Config.Msi
2014-02-13 23:51:53 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-02-13 23:51:53 ----A---- C:\Windows\system32\vbscript.dll
2014-02-13 23:50:52 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-02-13 23:50:52 ----A---- C:\Windows\system32\msrating.dll
2014-02-13 23:50:51 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-02-13 23:50:50 ----A---- C:\Windows\system32\ieui.dll
2014-02-13 23:50:49 ----A---- C:\Windows\system32\iernonce.dll
2014-02-13 23:50:49 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-02-13 23:50:49 ----A---- C:\Windows\system32\ie4uinit.exe
2014-02-13 23:50:48 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-02-13 23:50:48 ----A---- C:\Windows\system32\jsproxy.dll
2014-02-13 23:50:47 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-02-13 23:50:47 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-02-13 23:50:47 ----A---- C:\Windows\system32\msfeeds.dll
2014-02-13 23:50:46 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-02-13 23:50:46 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-02-13 23:50:46 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-02-13 23:50:46 ----A---- C:\Windows\system32\ieUnatt.exe
2014-02-13 23:50:46 ----A---- C:\Windows\system32\iesetup.dll
2014-02-13 23:50:45 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-02-13 23:50:45 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-02-13 23:50:44 ----A---- C:\Windows\system32\mshtml.dll
2014-02-13 23:50:43 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-02-13 23:50:43 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-02-13 23:50:43 ----A---- C:\Windows\system32\jscript9diag.dll
2014-02-13 23:50:42 ----A---- C:\Windows\system32\ieapfltr.dll
2014-02-13 23:50:41 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-02-13 23:50:41 ----A---- C:\Windows\system32\iertutil.dll
2014-02-13 23:50:40 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-02-13 23:50:40 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-02-13 23:50:40 ----A---- C:\Windows\system32\wininet.dll
2014-02-13 23:50:40 ----A---- C:\Windows\system32\urlmon.dll
2014-02-13 23:50:36 ----A---- C:\Windows\system32\ieframe.dll
2014-02-13 23:50:33 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-02-13 23:50:32 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-02-13 23:50:30 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-02-13 23:50:28 ----A---- C:\Windows\system32\jscript9.dll
2014-02-13 19:50:02 ----D---- C:\rsit
2014-02-13 19:47:50 ----A---- C:\Windows\system32\msxml3.dll
2014-02-13 19:47:48 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2014-02-13 19:47:48 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2014-02-13 19:47:48 ----A---- C:\Windows\system32\msxml3r.dll
2014-02-13 19:47:43 ----A---- C:\Windows\system32\RMActivate_isv.exe
2014-02-13 19:47:42 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp_isv.exe
2014-02-13 19:47:42 ----A---- C:\Windows\SYSWOW64\RMActivate_isv.exe
2014-02-13 19:47:42 ----A---- C:\Windows\SYSWOW64\RMActivate.exe
2014-02-13 19:47:42 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2014-02-13 19:47:42 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2014-02-13 19:47:42 ----A---- C:\Windows\system32\RMActivate.exe
2014-02-13 19:47:41 ----A---- C:\Windows\SYSWOW64\secproc_isv.dll
2014-02-13 19:47:41 ----A---- C:\Windows\SYSWOW64\RMActivate_ssp.exe
2014-02-13 19:47:41 ----A---- C:\Windows\system32\secproc_isv.dll
2014-02-13 19:47:41 ----A---- C:\Windows\system32\secproc.dll
2014-02-13 19:47:41 ----A---- C:\Windows\system32\msdrm.dll
2014-02-13 19:47:40 ----A---- C:\Windows\SYSWOW64\secproc_ssp_isv.dll
2014-02-13 19:47:40 ----A---- C:\Windows\SYSWOW64\secproc_ssp.dll
2014-02-13 19:47:40 ----A---- C:\Windows\SYSWOW64\secproc.dll
2014-02-13 19:47:40 ----A---- C:\Windows\SYSWOW64\msdrm.dll
2014-02-13 19:47:40 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2014-02-13 19:47:40 ----A---- C:\Windows\system32\secproc_ssp.dll
2014-02-13 19:47:25 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2014-02-13 19:47:25 ----A---- C:\Windows\system32\d3d10warp.dll
2014-02-13 19:47:24 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2014-02-13 19:47:24 ----A---- C:\Windows\system32\d2d1.dll
2014-02-08 12:01:00 ----D---- C:\Users\Wow\AppData\Roaming\IrfanView
2014-02-04 23:42:43 ----D---- C:\Users\Wow\AppData\Roaming\Opera Software
2014-02-04 22:46:07 ----D---- C:\Users\Wow\AppData\Roaming\AVAST Software
2014-02-04 22:45:28 ----A---- C:\Windows\system32\drivers\aswVmm.sys
2014-02-04 22:45:28 ----A---- C:\Windows\system32\drivers\aswStm.sys
2014-02-04 22:45:25 ----A---- C:\Windows\system32\drivers\aswRvrt.sys
2014-02-04 22:45:22 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2014-02-04 22:45:21 ----A---- C:\Windows\system32\drivers\aswSP.sys
2014-02-04 22:45:19 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2014-02-04 22:45:17 ----A---- C:\Windows\system32\drivers\aswRdr2.sys
2014-02-04 22:45:13 ----A---- C:\Windows\system32\aswBoot.exe
2014-02-04 22:45:02 ----A---- C:\Windows\avastSS.scr
2014-02-04 22:44:39 ----D---- C:\Program Files\AVAST Software
2014-02-04 22:43:22 ----D---- C:\ProgramData\AVAST Software
2014-02-03 19:41:47 ----D---- C:\Users\Wow\AppData\Roaming\Malwarebytes
2014-02-03 19:41:34 ----D---- C:\ProgramData\Malwarebytes
2014-02-03 19:41:33 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-02-03 19:41:33 ----A---- C:\Windows\system32\drivers\mbam.sys
2014-01-29 20:38:04 ----A---- C:\autoexec.bat
2014-01-29 20:36:15 ----D---- C:\Program Files\Enigma Software Group
2014-01-29 14:52:32 ----D---- C:\Program Files (x86)\Spybot - Search & Destroy 2

======List of files/folders modified in the last 1 month======

2014-02-17 12:54:23 ----D---- C:\Program Files\trend micro
2014-02-17 12:50:02 ----D---- C:\Windows\Temp
2014-02-17 12:26:38 ----D---- C:\Windows\system32\config
2014-02-17 12:10:11 ----D---- C:\ProgramData\NVIDIA
2014-02-17 05:54:06 ----D---- C:\Windows\system32\MRT
2014-02-17 05:51:43 ----D---- C:\Windows\debug
2014-02-17 05:51:32 ----A---- C:\Windows\system32\MRT.exe
2014-02-17 05:49:55 ----SHD---- C:\System Volume Information
2014-02-16 15:33:24 ----D---- C:\ProgramData\ChessBase
2014-02-16 13:35:47 ----D---- C:\ProgramData
2014-02-16 13:27:38 ----D---- C:\Windows\system32\drivers
2014-02-16 13:22:52 ----AD---- C:\Windows
2014-02-16 13:22:52 ----A---- C:\Windows\system.ini
2014-02-16 13:22:42 ----D---- C:\Windows\system32\drivers\etc
2014-02-16 13:10:46 ----D---- C:\Windows\SYSWOW64\drivers
2014-02-16 13:10:46 ----D---- C:\Windows\SysWOW64
2014-02-16 13:10:46 ----D---- C:\Windows\AppPatch
2014-02-16 13:10:45 ----D---- C:\Program Files (x86)\Common Files
2014-02-15 11:56:05 ----RSD---- C:\Windows\assembly
2014-02-15 11:56:05 ----D---- C:\Windows\Microsoft.NET
2014-02-14 23:39:04 ----D---- C:\Windows\inf
2014-02-14 23:39:02 ----D---- C:\Windows\system32\catroot
2014-02-14 23:39:01 ----D---- C:\Windows\system32\DriverStore
2014-02-14 23:38:24 ----D---- C:\Windows\system32\Tasks
2014-02-14 19:21:35 ----D---- C:\Users\Wow\AppData\Roaming\Skype
2014-02-14 17:44:21 ----D---- C:\ProgramData\ProductData
2014-02-14 16:37:40 ----D---- C:\Program Files (x86)\IObit
2014-02-14 10:46:36 ----D---- C:\Users\Wow\AppData\Roaming\BitTorrent
2014-02-14 10:43:58 ----D---- C:\Windows\winsxs
2014-02-14 10:42:07 ----D---- C:\Windows\System32
2014-02-14 09:13:43 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-02-14 09:13:41 ----RD---- C:\Program Files (x86)
2014-02-14 08:49:48 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-02-14 08:49:47 ----D---- C:\Windows\system32\cs-CZ
2014-02-14 08:49:47 ----D---- C:\Program Files (x86)\Internet Explorer
2014-02-14 08:49:46 ----D---- C:\Program Files\Internet Explorer
2014-02-14 00:15:46 ----SHD---- C:\Windows\Installer
2014-02-14 00:14:49 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2014-02-14 00:14:31 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-02-13 23:51:59 ----D---- C:\Windows\system32\catroot2
2014-02-13 23:18:47 ----D---- C:\Users\Wow\AppData\Roaming\Winamp
2014-02-13 14:55:58 ----D---- C:\Program Files (x86)\Opera
2014-02-11 22:25:08 ----D---- C:\Windows\Tasks
2014-02-11 21:16:05 ----A---- C:\Windows\wincmd.ini
2014-02-11 21:01:19 ----A---- C:\Windows\win.ini
2014-02-08 11:56:51 ----D---- C:\Program Files (x86)\Adobe
2014-02-06 14:32:14 ----D---- C:\Program Files (x86)\CCleaner
2014-02-05 19:59:16 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-02-05 13:23:41 ----D---- C:\Windows\SoftwareDistribution
2014-02-04 22:45:58 ----D---- C:\Program Files (x86)\Mozilla Thunderbird
2014-02-04 22:44:39 ----D---- C:\Program Files
2014-02-04 22:40:16 ----D---- C:\ProgramData\Spybot - Search & Destroy
2014-02-04 22:40:15 ----SD---- C:\ProgramData\Microsoft
2014-02-04 22:39:34 ----D---- C:\ProgramData\f-secure
2014-02-03 19:49:13 ----D---- C:\ProgramData\DSearchLink
2014-02-02 20:55:57 ----D---- C:\Program Files\SUPERAntiSpyware
2014-01-31 14:54:37 ----D---- C:\Windows\system32\NDF
2014-01-29 23:16:58 ----SD---- C:\Users\Wow\AppData\Roaming\Microsoft
2014-01-29 21:14:08 ----D---- C:\Users\Wow\AppData\Roaming\iPumper
2014-01-29 17:54:20 ----D---- C:\Windows\Prefetch
2014-01-27 22:34:10 ----RSD---- C:\Windows\Fonts

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2014-02-04 65776]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2014-02-04 207904]
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-04 16440]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 aswKbd;aswKbd; \??\C:\Windows\system32\drivers\aswKbd.sys [2014-02-14 28184]
R1 aswNdisFlt;Avast! Firewall Driver; C:\Windows\system32\DRIVERS\aswNdisFlt.sys [2014-02-14 440672]
R1 aswRdr;aswRdr; \??\C:\Windows\system32\drivers\aswRdr2.sys [2014-02-04 92544]
R1 aswSnx;aswSnx; \??\C:\Windows\system32\drivers\aswSnx.sys [2014-02-04 1038072]
R1 aswSP;aswSP; \??\C:\Windows\system32\drivers\aswSP.sys [2014-02-04 421704]
R1 mwlPSDFilter;mwlPSDFilter; C:\Windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-02 22576]
R1 mwlPSDNServ;mwlPSDNServ; C:\Windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-02 20016]
R1 mwlPSDVDisk;mwlPSDVDisk; C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-02 60464]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2014-02-04 78648]
R3 aswStm;aswStm; \??\C:\Windows\system32\drivers\aswStm.sys [2014-02-04 80184]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-07-20 1831968]
R3 NTIDrvr;NTIDrvr; \??\C:\Windows\system32\drivers\NTIDrvr.sys [2009-05-06 18432]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2009-06-26 83488]
R3 SNPSTD3;USB PC Camera (SNPSTD3); C:\Windows\system32\DRIVERS\snpstd3.sys [2007-04-03 10535040]
R3 UBHelper;UBHelper; \??\C:\Windows\system32\drivers\UBHelper.sys [2009-05-06 16896]
R3 WDC_SAM;WD SCSI Pass Thru driver; C:\Windows\system32\DRIVERS\wdcsam64.sys [2011-12-16 14464]
S3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\agrsm64.sys [2009-06-11 1208320]
S3 atikmdag;atikmdag; C:\Windows\system32\drivers\atikmdag.sys [2009-07-13 5020672]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 esgiguard;esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys []
S3 pcwe;pcwe; \??\D:\Programy_system\PC_Wizard\pcw86-64.sys [2004-12-04 7680]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2013-05-02 19456]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-05-02 57856]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-02-04 50344]
R2 avast! Firewall;avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [2014-02-14 113704]
R2 Greg_Service;GRegService; C:\Program Files (x86)\Acer\Registration\GregHSRW.exe [2009-08-28 1150496]
R2 MWLService;MyWinLocker Service; C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [2009-09-10 305448]
R2 NTI IScheduleSvc;NTI IScheduleSvc; C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-08-12 62208]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-01-18 884512]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-01-18 383264]
R2 Updater Service;Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2009-07-04 240160]
R2 WDDMService;WDDMService; C:\Program Files\Western Digital\WD SmartWare\WDDMService.exe [2011-12-15 319384]
R2 WDFMEService;WDFME; C:\Program Files\Western Digital\WD SmartWare\WDFME.exe [2011-12-15 1977224]
R2 WDRulesService;WDRules; C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe [2011-12-15 1338264]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 2292096]
R2 yksvc;Marvell Yukon Service; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-06-30 136176]
S2 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2013-12-03 2151200]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-02-25 1260320]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-05 257928]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-06-30 136176]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-10-12 182768]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-02-06 111616]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-02-14 118896]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-06-15 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Zamčeno