Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

pomalý notebook

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
exltus
Návštěvník
Návštěvník
Příspěvky: 63
Registrován: 17 lis 2007 19:59

pomalý notebook

#1 Příspěvek od exltus »

Dobrý den,
poslední dobou jsem zaznamenal, ze muj notebook je extrémně pomalý a na spoustu věcí ani nereaguje. tady je log
Předem děkuji

Logfile of random's system information tool 1.10 (written by random/random)
Run by jana at 2014-11-16 19:17:15
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 67 GB (14%) free of 477 GB
Total RAM: 3959 MB (63% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:18:34, on 16.11.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17420)
Boot mode: Normal

Running processes:
C:\Windows\snuvcdsm.exe
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Users\jana\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.15.4\dsrlte.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\jana.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTer ... DF&PC=AV01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://rts.dsrlte.com?affID=na
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTer ... DF&PC=AV01
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: (no name) - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - (no file)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Yahoo! Search] C:\Users\jana\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.15.4\dsrlte.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: IePlugin Services (IePluginServices) - Cherished Technololgy LIMITED - C:\ProgramData\IePluginServices\PluginService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MaintainerSvc6.89.573444 - Unknown owner - C:\ProgramData\01e58235-010d-43b1-8340-277d43a75321\maintainer.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: WindowsMangerProtect Service (WindowsMangerProtect) - Fuyu LIMITED - C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 7905 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\system32\WLANExt.exe 3014000
\??\C:\Windows\system32\conhost.exe "-7086057936131908821351769327444430970-106509458393487736277268979-1836984644
atieclxx
C:\ProgramData\IePluginServices\PluginService.exe -service
C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe -service
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\ProgramData\01e58235-010d-43b1-8340-277d43a75321\maintainer.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Windows\snuvcdsm.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
HydraDM64.exe -h:65918 "Maximalizovat na celou plochu" "Maximalizovat k rohům okna" "Obnovit pracovní plochu"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
taskeng.exe {851DDB1C-BD8A-478B-AB5C-642D577B586A}
"C:\Users\jana\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.15.4\dsrlte.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3444.0.459778378\667111867" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,16 --gpu-vendor-id=0x1002 --gpu-device-id=0x68e4 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=14.200.1004.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/control/EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/Bootstrap/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-1-Percent/group_99/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --channel="3444.2.1450313597\1421321442" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/control/EmbeddedSearch/Group6 pct:10f stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/Bootstrap/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_04/UMA-Uniformity-Trial-1-Percent/group_99/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --channel="3444.4.1885916746\251329557" /prefetch:673131151
C:\Windows\system32\sppsvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Users\jana\Downloads\RSITx64.exe"
wmiadap.exe /F /T /R
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-07-28 612248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-07-29 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-07-28 457712]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-07-29 171944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2013-10-24 13662936]
"PLFSetL"=C:\Windows\PLFSetL.exe [2011-01-13 99712]
"SNUVCDSM"=C:\Windows\snuvcdsm.exe [2011-01-13 30080]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-04-22 2097960]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"HydraVisionDesktopManager"=C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [2014-04-17 1967616]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
"Yahoo! Search"=C:\Users\jana\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.15.4\dsrlte.exe [2014-11-13 533352]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-08-21 959176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-03-13 112512]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Programy\Skype\Phone\Skype.exe [2014-07-02 21644384]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-07-11 256896]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-08-01 4085896]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2014-08-11 767200]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.ffds"=ff_vfw.dll
"msacm.aacacm"=AACACM.acm
"msacm.ac3acm"=AC3ACM.acm
"msacm.lameacm"=LameACM.acm
"VIDC.LAGS"=lagarith.dll
"VIDC.MLCY"=mlc.dll
"VIDC.ULRA"=C:\Windows\system32\utv_vcm.dll
"VIDC.ULRG"=C:\Windows\system32\utv_vcm.dll
"VIDC.ULY0"=C:\Windows\system32\utv_vcm.dll
"VIDC.ULY2"=C:\Windows\system32\utv_vcm.dll
"VIDC.ULH0"=C:\Windows\system32\utv_vcm.dll
"VIDC.ULH2"=C:\Windows\system32\utv_vcm.dll
"vidc.x264"=C:\PROGRA~1\X264VF~1\X264VF~1.DLL
"vidc.XVID"=xvidvfw.dll
"VIDC.VP80"=vp8vfw.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-11-16 19:17:15 ----D---- C:\Program Files\trend micro
2014-11-16 19:17:14 ----D---- C:\rsit
2014-11-16 18:58:59 ----D---- C:\Program Files (x86)\GOG.com
2014-11-16 18:25:43 ----A---- C:\Windows\system32\drivers\{c0b542ce-0b43-4536-9ff3-886eaf9fb44c}Gw64.sys
2014-11-13 09:58:22 ----A---- C:\Windows\system32\drivers\{9642e31c-2703-4a31-ba45-9e8dfb693e38}Gw64.sys
2014-11-12 03:13:46 ----A---- C:\Windows\system32\generaltel.dll
2014-11-12 03:13:46 ----A---- C:\Windows\system32\aepdu.dll
2014-11-12 03:13:45 ----A---- C:\Windows\system32\aeinv.dll
2014-11-12 03:13:42 ----A---- C:\Windows\system32\termsrv.dll
2014-11-12 03:13:42 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2014-11-12 03:13:41 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2014-11-12 03:13:41 ----A---- C:\Windows\system32\lsasrv.dll
2014-11-12 03:13:41 ----A---- C:\Windows\system32\adtschema.dll
2014-11-12 03:13:39 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2014-11-12 03:13:39 ----A---- C:\Windows\SYSWOW64\secur32.dll
2014-11-12 03:13:39 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2014-11-12 03:13:39 ----A---- C:\Windows\system32\msaudite.dll
2014-11-12 03:13:33 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-11-12 03:13:33 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-11-12 03:13:33 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-11-12 03:13:33 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-11-12 03:13:33 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-11-12 03:13:32 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-11-12 03:13:32 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-11-12 03:13:32 ----A---- C:\Windows\system32\iernonce.dll
2014-11-12 03:13:32 ----A---- C:\Windows\system32\ie4uinit.exe
2014-11-12 03:13:31 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-11-12 03:13:31 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-11-12 03:13:31 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-11-12 03:13:30 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-11-12 03:13:30 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-11-12 03:13:28 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-11-12 03:13:28 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-11-12 03:13:28 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-11-12 03:13:28 ----A---- C:\Windows\system32\urlmon.dll
2014-11-12 03:13:28 ----A---- C:\Windows\system32\iedkcs32.dll
2014-11-12 03:13:27 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-11-12 03:13:27 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-11-12 03:13:27 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-11-12 03:13:27 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-11-12 03:13:26 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-11-12 03:13:26 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-11-12 03:13:26 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-11-12 03:13:26 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-11-12 03:13:26 ----A---- C:\Windows\system32\msfeeds.dll
2014-11-12 03:13:26 ----A---- C:\Windows\system32\dxtrans.dll
2014-11-12 03:13:25 ----A---- C:\Windows\system32\iesetup.dll
2014-11-12 03:13:25 ----A---- C:\Windows\system32\ieapfltr.dll
2014-11-12 03:13:23 ----A---- C:\Windows\system32\iertutil.dll
2014-11-12 03:13:22 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-11-12 03:13:22 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-11-12 03:13:21 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-11-12 03:13:21 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-11-12 03:13:21 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-11-12 03:13:21 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-11-12 03:13:21 ----A---- C:\Windows\system32\jsproxy.dll
2014-11-12 03:13:21 ----A---- C:\Windows\system32\ieUnatt.exe
2014-11-12 03:13:20 ----A---- C:\Windows\system32\ieui.dll
2014-11-12 03:13:20 ----A---- C:\Windows\system32\dxtmsft.dll
2014-11-12 03:13:19 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-11-12 03:13:19 ----A---- C:\Windows\system32\mshtmled.dll
2014-11-12 03:13:19 ----A---- C:\Windows\system32\ieframe.dll
2014-11-12 03:13:18 ----A---- C:\Windows\system32\vbscript.dll
2014-11-12 03:13:18 ----A---- C:\Windows\system32\jscript9diag.dll
2014-11-12 03:13:18 ----A---- C:\Windows\system32\jscript9.dll
2014-11-12 03:13:17 ----A---- C:\Windows\system32\wininet.dll
2014-11-12 03:13:16 ----A---- C:\Windows\system32\msrating.dll
2014-11-12 03:13:16 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-11-12 03:13:15 ----A---- C:\Windows\system32\mshtml.dll
2014-11-12 03:11:54 ----A---- C:\Windows\system32\msxml3.dll
2014-11-12 03:11:53 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2014-11-12 03:11:53 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2014-11-12 03:11:53 ----A---- C:\Windows\system32\msxml3r.dll
2014-11-12 03:11:51 ----A---- C:\Windows\SYSWOW64\IMJP10K.DLL
2014-11-12 03:11:51 ----A---- C:\Windows\system32\IMJP10K.DLL
2014-11-12 03:11:48 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll
2014-11-12 03:11:48 ----A---- C:\Windows\system32\AUDIOKSE.dll
2014-11-12 03:11:47 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2014-11-12 03:11:47 ----A---- C:\Windows\system32\EncDump.dll
2014-11-12 03:11:47 ----A---- C:\Windows\system32\audiosrv.dll
2014-11-12 03:11:47 ----A---- C:\Windows\system32\AudioSes.dll
2014-11-12 03:11:47 ----A---- C:\Windows\system32\AudioEng.dll
2014-11-12 03:11:46 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2014-11-12 03:11:43 ----A---- C:\Windows\system32\schannel.dll
2014-11-12 03:11:43 ----A---- C:\Windows\system32\ncrypt.dll
2014-11-12 03:11:42 ----A---- C:\Windows\SYSWOW64\schannel.dll
2014-11-12 03:11:42 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2014-11-12 03:11:42 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2014-11-12 03:11:41 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2014-11-12 03:11:41 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2014-11-12 03:11:41 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2014-11-12 03:11:41 ----A---- C:\Windows\system32\wdigest.dll
2014-11-12 03:11:41 ----A---- C:\Windows\system32\TSpkg.dll
2014-11-12 03:11:41 ----A---- C:\Windows\system32\msv1_0.dll
2014-11-12 03:11:41 ----A---- C:\Windows\system32\kerberos.dll
2014-11-12 03:11:40 ----A---- C:\Windows\SYSWOW64\credssp.dll
2014-11-12 03:11:40 ----A---- C:\Windows\system32\credssp.dll
2014-11-12 03:11:31 ----A---- C:\Windows\system32\win32k.sys
2014-11-12 03:11:30 ----A---- C:\Windows\SYSWOW64\packager.dll
2014-11-12 03:11:30 ----A---- C:\Windows\system32\packager.dll
2014-11-12 03:11:23 ----A---- C:\Windows\system32\msi.dll
2014-11-12 03:11:22 ----A---- C:\Windows\SYSWOW64\msi.dll
2014-11-12 03:11:15 ----A---- C:\Windows\system32\oleaut32.dll
2014-11-12 03:11:14 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2014-11-10 18:07:27 ----A---- C:\Windows\system32\drivers\{98e700ee-1d13-4cd6-97a6-d8d4d2f0a35b}Gw64.sys
2014-11-10 16:24:58 ----D---- C:\Users\jana\AppData\Roaming\EnglishGrammarinUseExtra
2014-11-10 16:24:58 ----D---- C:\Users\jana\AppData\Roaming\Cambridge
2014-11-10 16:18:14 ----HD---- C:\Program Files (x86)\Zero G Registry
2014-11-10 16:18:14 ----D---- C:\Program Files (x86)\Cambridge
2014-11-07 13:09:52 ----D---- C:\Users\jana\AppData\Roaming\Macromedia
2014-11-07 09:21:10 ----A---- C:\Windows\system32\drivers\{6b9234ab-d79f-41db-86f9-8be7a3e9ee74}Gw64.sys
2014-11-04 18:24:01 ----A---- C:\Windows\system32\drivers\{a2df9e48-ce26-4812-87d1-df6c5bed5ea9}Gw64.sys
2014-11-01 19:24:42 ----D---- C:\Nová složka
2014-11-01 13:04:41 ----D---- C:\mikro 1
2014-11-01 13:02:09 ----D---- C:\Program Files (x86)\GreenTree Applications
2014-11-01 13:01:10 ----D---- C:\ProgramData\YTD Video Downloader
2014-11-01 13:01:02 ----D---- C:\2-click run
2014-11-01 12:09:35 ----A---- C:\Windows\system32\drivers\{51d6aaf3-0bd7-47b0-8963-1c6f4d58b8fd}Gw64.sys
2014-10-29 10:02:47 ----A---- C:\Windows\system32\drivers\{d04f5c84-12ff-4486-8e31-240e7ca6e6d3}Gw64.sys
2014-10-28 10:34:19 ----D---- C:\ProgramData\01e58235-010d-43b1-8340-277d43a75321
2014-10-26 21:03:33 ----A---- C:\Windows\system32\drivers\{19b94dbb-e67e-43ec-827b-c943f0fc9c16}Gw64.sys
2014-10-23 01:40:04 ----A---- C:\Windows\system32\drivers\{972b8ad0-9d6f-4688-9227-759df6914df4}Gw64.sys
2014-10-22 19:05:15 ----D---- C:\Program Files (x86)\NVIDIA Corporation

======List of files/folders modified in the last 1 month======

2014-11-16 19:18:21 ----D---- C:\Windows\Temp
2014-11-16 19:17:15 ----RD---- C:\Program Files
2014-11-16 19:13:35 ----D---- C:\Windows\inf
2014-11-16 19:12:28 ----D---- C:\Windows\system32\config
2014-11-16 19:08:51 ----D---- C:\Users\jana\AppData\Roaming\uTorrent
2014-11-16 18:58:59 ----RD---- C:\Program Files (x86)
2014-11-16 18:58:08 ----AD---- C:\Windows\System32
2014-11-16 18:58:08 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-11-16 18:53:37 ----D---- C:\Windows
2014-11-16 18:44:45 ----AD---- C:\Windows\SysWOW64
2014-11-16 18:44:36 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-11-16 18:27:15 ----D---- C:\Users\jana\AppData\Roaming\DAEMON Tools Lite
2014-11-16 18:27:09 ----D---- C:\Windows\SoftwareDistribution
2014-11-16 18:27:03 ----D---- C:\Windows\debug
2014-11-16 18:25:43 ----D---- C:\Windows\system32\drivers
2014-11-16 18:25:42 ----A---- C:\Windows\win.ini
2014-11-14 12:36:42 ----D---- C:\Users\jana\AppData\Roaming\vlc
2014-11-13 22:29:21 ----D---- C:\Windows\system32\Tasks
2014-11-13 21:30:34 ----D---- C:\Windows\rescache
2014-11-13 20:02:21 ----D---- C:\Windows\Tasks
2014-11-13 03:37:33 ----D---- C:\Windows\Microsoft.NET
2014-11-13 03:36:52 ----RSD---- C:\Windows\assembly
2014-11-13 03:28:27 ----D---- C:\Windows\Prefetch
2014-11-13 03:28:03 ----D---- C:\Windows\winsxs
2014-11-13 03:24:57 ----SD---- C:\Windows\system32\CompatTel
2014-11-13 03:24:54 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-11-13 03:24:54 ----D---- C:\Windows\system32\cs-CZ
2014-11-13 03:24:54 ----D---- C:\Program Files\Internet Explorer
2014-11-13 03:24:53 ----D---- C:\Windows\SYSWOW64\en-US
2014-11-13 03:24:53 ----D---- C:\Windows\system32\en-US
2014-11-13 03:24:52 ----D---- C:\Program Files (x86)\Internet Explorer
2014-11-13 03:07:36 ----SHD---- C:\Windows\Installer
2014-11-13 03:06:40 ----D---- C:\Windows\system32\MRT
2014-11-13 03:02:30 ----A---- C:\Windows\system32\MRT.exe
2014-11-13 03:00:52 ----SHD---- C:\System Volume Information
2014-11-12 03:10:52 ----D---- C:\Windows\system32\catroot2
2014-11-10 16:24:09 ----D---- C:\Users\jana\AppData\Roaming\Adobe
2014-11-10 16:24:09 ----D---- C:\ProgramData\Adobe
2014-11-10 16:24:07 ----D---- C:\Program Files (x86)\Common Files
2014-11-10 16:24:07 ----D---- C:\Program Files (x86)\Adobe
2014-11-09 14:24:53 ----D---- C:\Windows\system32\NDF
2014-11-07 13:07:04 ----D---- C:\Hry
2014-11-03 00:21:20 ----D---- C:\Program Files (x86)\SupTab
2014-11-01 13:01:10 ----HD---- C:\ProgramData
2014-10-28 06:34:58 ----N---- C:\Windows\system32\MpSigStub.exe
2014-10-23 14:01:29 ----D---- C:\Windows\Logs

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2014-07-28 65776]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2014-07-28 224896]
R0 iaStorA;iaStorA; C:\Windows\system32\DRIVERS\iaStorA.sys [2013-09-20 630632]
R0 iaStorF;iaStorF; C:\Windows\system32\DRIVERS\iaStorF.sys [2013-09-20 28008]
R0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hcs.sys [2013-07-17 20464]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 {00c97d86-accb-4288-9972-6d929c1fe93a}Gw64;{00c97d86-accb-4288-9972-6d929c1fe93a}Gw64; C:\Windows\system32\drivers\{00c97d86-accb-4288-9972-6d929c1fe93a}Gw64.sys [2014-09-27 48720]
R1 {19b94dbb-e67e-43ec-827b-c943f0fc9c16}Gw64;{19b94dbb-e67e-43ec-827b-c943f0fc9c16}Gw64; C:\Windows\system32\drivers\{19b94dbb-e67e-43ec-827b-c943f0fc9c16}Gw64.sys [2014-10-26 48776]
R1 {51d6aaf3-0bd7-47b0-8963-1c6f4d58b8fd}Gw64;{51d6aaf3-0bd7-47b0-8963-1c6f4d58b8fd}Gw64; C:\Windows\system32\drivers\{51d6aaf3-0bd7-47b0-8963-1c6f4d58b8fd}Gw64.sys [2014-11-01 48776]
R1 {6b9234ab-d79f-41db-86f9-8be7a3e9ee74}Gw64;{6b9234ab-d79f-41db-86f9-8be7a3e9ee74}Gw64; C:\Windows\system32\drivers\{6b9234ab-d79f-41db-86f9-8be7a3e9ee74}Gw64.sys [2014-11-06 48776]
R1 {9642e31c-2703-4a31-ba45-9e8dfb693e38}Gw64;{9642e31c-2703-4a31-ba45-9e8dfb693e38}Gw64; C:\Windows\system32\drivers\{9642e31c-2703-4a31-ba45-9e8dfb693e38}Gw64.sys [2014-11-12 48776]
R1 {972b8ad0-9d6f-4688-9227-759df6914df4}Gw64;{972b8ad0-9d6f-4688-9227-759df6914df4}Gw64; C:\Windows\system32\drivers\{972b8ad0-9d6f-4688-9227-759df6914df4}Gw64.sys [2014-10-22 48776]
R1 {98e700ee-1d13-4cd6-97a6-d8d4d2f0a35b}Gw64;{98e700ee-1d13-4cd6-97a6-d8d4d2f0a35b}Gw64; C:\Windows\system32\drivers\{98e700ee-1d13-4cd6-97a6-d8d4d2f0a35b}Gw64.sys [2014-11-10 48776]
R1 {a2df9e48-ce26-4812-87d1-df6c5bed5ea9}Gw64;{a2df9e48-ce26-4812-87d1-df6c5bed5ea9}Gw64; C:\Windows\system32\drivers\{a2df9e48-ce26-4812-87d1-df6c5bed5ea9}Gw64.sys [2014-11-04 48776]
R1 {c0b542ce-0b43-4536-9ff3-886eaf9fb44c}Gw64;{c0b542ce-0b43-4536-9ff3-886eaf9fb44c}Gw64; C:\Windows\system32\drivers\{c0b542ce-0b43-4536-9ff3-886eaf9fb44c}Gw64.sys [2014-11-16 48776]
R1 {d04f5c84-12ff-4486-8e31-240e7ca6e6d3}Gw64;{d04f5c84-12ff-4486-8e31-240e7ca6e6d3}Gw64; C:\Windows\system32\drivers\{d04f5c84-12ff-4486-8e31-240e7ca6e6d3}Gw64.sys [2014-10-29 48776]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2014-07-28 93568]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2014-07-28 1041168]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2014-07-28 427360]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-09-27 283064]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2014-07-28 29208]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2014-07-28 79184]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2014-07-28 92008]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2014-08-12 15961088]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2014-08-12 557056]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2014-06-21 94720]
R3 BCM43XX;Ovladač síťového adaptéru Broadcom 802.11; C:\Windows\system32\DRIVERS\bcmwl664.sys [2013-11-05 9082576]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2013-02-19 57848]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2013-11-05 3707864]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\k57nd60a.sys [2013-07-26 458960]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2011-01-13 1806592]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-04-22 318000]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-09-12 64704]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2014-08-12 239616]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-07-28 50344]
R2 IePluginServices;IePlugin Services; C:\ProgramData\IePluginServices\PluginService.exe [2014-09-24 705416]
R2 MaintainerSvc6.89.573444;MaintainerSvc6.89.573444; C:\ProgramData\01e58235-010d-43b1-8340-277d43a75321\maintainer.exe [2014-11-16 123632]
R2 WindowsMangerProtect;WindowsMangerProtect Service; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [2014-09-27 528896]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-28 116648]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-16 267440]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-28 116648]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-11-06 114688]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-07-28 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119548
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: pomalý notebook

#2 Příspěvek od Rudy »

Zdravím!
Spusťte nejprve tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

exltus
Návštěvník
Návštěvník
Příspěvky: 63
Registrován: 17 lis 2007 19:59

Re: pomalý notebook

#3 Příspěvek od exltus »

# AdwCleaner v4.101 - Report created 16/11/2014 at 19:48:34
# Updated 09/11/2014 by Xplode
# Database : 2014-11-16.1 [Live]
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : jana - JANA-PC
# Running from : C:\Users\jana\Desktop\adwcleaner_4.101.exe
# Option : Clean

***** [ Services ] *****

Service Deleted : IePluginServices
Service Deleted : WindowsMangerProtect
Service Deleted : {00c97d86-accb-4288-9972-6d929c1fe93a}Gw64
Service Deleted : {19b94dbb-e67e-43ec-827b-c943f0fc9c16}Gw64
Service Deleted : {51d6aaf3-0bd7-47b0-8963-1c6f4d58b8fd}Gw64
Service Deleted : {6b9234ab-d79f-41db-86f9-8be7a3e9ee74}Gw64
Service Deleted : {9642e31c-2703-4a31-ba45-9e8dfb693e38}Gw64
Service Deleted : {972b8ad0-9d6f-4688-9227-759df6914df4}Gw64
Service Deleted : {98e700ee-1d13-4cd6-97a6-d8d4d2f0a35b}Gw64
Service Deleted : {a2df9e48-ce26-4812-87d1-df6c5bed5ea9}Gw64
Service Deleted : {c0b542ce-0b43-4536-9ff3-886eaf9fb44c}Gw64
Service Deleted : {d04f5c84-12ff-4486-8e31-240e7ca6e6d3}Gw64

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\IePluginServices
Folder Deleted : C:\ProgramData\WindowsMangerProtect
Folder Deleted : C:\ProgramData\ytd video downloader
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ytd video downloader
Folder Deleted : C:\Program Files (x86)\GreenTree Applications
Folder Deleted : C:\Program Files (x86)\SupTab
Folder Deleted : C:\Users\jana\AppData\Local\pay-by-ads
Folder Deleted : C:\Users\jana\AppData\Roaming\istartsurf
Folder Deleted : C:\Users\jana\AppData\Roaming\SupTab
File Deleted : C:\Windows\System32\\drivers\{00c97d86-accb-4288-9972-6d929c1fe93a}Gw64.sys
File Deleted : C:\Windows\System32\\drivers\{19b94dbb-e67e-43ec-827b-c943f0fc9c16}Gw64.sys
File Deleted : C:\Windows\System32\\drivers\{51d6aaf3-0bd7-47b0-8963-1c6f4d58b8fd}Gw64.sys
File Deleted : C:\Windows\System32\\drivers\{6b9234ab-d79f-41db-86f9-8be7a3e9ee74}Gw64.sys
File Deleted : C:\Windows\System32\\drivers\{9642e31c-2703-4a31-ba45-9e8dfb693e38}Gw64.sys
File Deleted : C:\Windows\System32\\drivers\{972b8ad0-9d6f-4688-9227-759df6914df4}Gw64.sys
File Deleted : C:\Windows\System32\\drivers\{98e700ee-1d13-4cd6-97a6-d8d4d2f0a35b}Gw64.sys
File Deleted : C:\Windows\System32\\drivers\{a2df9e48-ce26-4812-87d1-df6c5bed5ea9}Gw64.sys
File Deleted : C:\Windows\System32\\drivers\{c0b542ce-0b43-4536-9ff3-886eaf9fb44c}Gw64.sys
File Deleted : C:\Windows\System32\\drivers\{d04f5c84-12ff-4486-8e31-240e7ca6e6d3}Gw64.sys
File Deleted : C:\Users\jana\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx

***** [ Scheduled Tasks ] *****

Task Deleted : Yahoo! Search
Task Deleted : Yahoo! Search Updater

***** [ Shortcuts ] *****

Shortcut Disinfected : C:\Users\jana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Shortcut Disinfected : C:\Users\jana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Shortcut Disinfected : C:\Users\jana\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
Shortcut Disinfected : C:\Users\jana\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk

***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Key Deleted : HKCU\Software\Classes\keepmysearch
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKCU\Software\SupHpUISoft
Key Deleted : HKLM\SOFTWARE\istartsurfSoftware
Key Deleted : HKLM\SOFTWARE\SupDp
Key Deleted : HKLM\SOFTWARE\SupTab
Key Deleted : HKLM\SOFTWARE\supWindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\supWPM
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Search
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\istartsurf uninstall
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WindowsMangerProtect
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\464AA55239C100F32AF2D438EDDC0F47
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5652BA3D5FB98AE31B337BF0AF939856
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EB95E1AFCBABE3DB9ECCC669B99494

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17420

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]

-\\ Google Chrome v38.0.2125.122

[C:\Users\jana\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.istartsurf.com/web/?type=ds&ts=1411 ... earchTerms}

*************************

AdwCleaner[R0].txt - [7364 octets] - [16/11/2014 19:44:14]
AdwCleaner[S0].txt - [6898 octets] - [16/11/2014 19:48:34]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6958 octets] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119548
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: pomalý notebook

#4 Příspěvek od Rudy »

Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět