Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

preventivní kontrola logu---zpomalení počítače

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
tepan
Návštěvník
Návštěvník
Příspěvky: 248
Registrován: 22 pro 2006 21:11
Bydliště: Sumperk

preventivní kontrola logu---zpomalení počítače

#1 Příspěvek od tepan »

dobrý den,prosím o kontrolu logu...můj procesor čím dál častěji jede na 50 procent aniž by bylo něco spuštěno.

log z FRST.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:15-09-2015
Ran by Tepan (administrator) on TEPAN-PC (18-09-2015 10:33:31)
Running from C:\Users\Tepan\Desktop
Loaded Profiles: Tepan (Available Profiles: Tepan)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AMD) C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe
(AMD) C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpert.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe
(AMD) C:\Windows\SysWOW64\WinMsgBalloonServer.exe
(AMD) C:\Windows\SysWOW64\WinMsgBalloonClient.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(forum.viry.cz) C:\Users\Tepan\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6111824 2015-08-28] (AVAST Software)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [998104 2015-07-07] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-07-28] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8418584 2015-07-17] (Piriform Ltd)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-08-06] (AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2014-08-02]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 213.46.172.37 213.46.172.36
Tcpip\..\Interfaces\{224703BF-4E2B-4984-BECA-D22BB644A342}: [DhcpNameServer] 213.46.172.37 213.46.172.36
Tcpip\..\Interfaces\{B7B4C87E-1BE6-4F4F-A6C5-702CD234D949}: [DhcpNameServer] 8.8.8.8 192.168.91.2

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.seznam.cz/
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.seznam.cz/?clid=22668
SearchScopes: HKLM-x32 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1029120089-3632672932-3177029402-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1029120089-3632672932-3177029402-1001 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-08-06] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2015-02-25] (Eyeo GmbH)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll [2015-09-02] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-08-06] (AVAST Software)
BHO-x32: Pomocná služba pro přihlášení k účtu Microsoft -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-09-02] (Oracle Corporation)
BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-02-25] (Eyeo GmbH)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

FireFox:
========
FF ProfilePath: C:\Users\Tepan\AppData\Roaming\Mozilla\Firefox\Profiles\sdckyap9.default-1405284649585
FF DefaultSearchEngine: Google
FF SearchEngineOrder.3: Bing
FF SelectedSearchEngine: Поиск@Mail.Ru
FF Homepage: hxxps://www.seznam.cz/
FF Keyword.URL: hxxp://go.mail.ru/search?fr=ntg&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll [2015-08-15] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40620.0\npctrl.dll [2015-06-20] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-16] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-15] ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2014-11-21] (DivX, LLC)
FF Plugin-x32: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-09-02] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-09-02] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40620.0\npctrl.dll [2015-06-19] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll [2011-02-21] (RocketLife, LLP)
FF Plugin-x32: @videolan.org/vlc,version=2.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1029120089-3632672932-3177029402-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Tepan\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-20] (Google Inc.)
FF Plugin HKU\S-1-5-21-1029120089-3632672932-3177029402-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Tepan\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-20] (Google Inc.)
FF Plugin HKU\S-1-5-21-1029120089-3632672932-3177029402-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2014-06-22] ()
FF SearchPlugin: C:\Users\Tepan\AppData\Roaming\Mozilla\Firefox\Profiles\sdckyap9.default-1405284649585\searchplugins\anglicko-esk-slovnk.xml [2015-08-10]
FF SearchPlugin: C:\Users\Tepan\AppData\Roaming\Mozilla\Firefox\Profiles\sdckyap9.default-1405284649585\searchplugins\bing-.xml [2015-07-04]
FF Extension: Adblock Plus - C:\Users\Tepan\AppData\Roaming\Mozilla\Firefox\Profiles\sdckyap9.default-1405284649585\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-07-16]
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2014-07-28]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-03-15]
FF HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR HomePage: Default -> hxxps://mail.ru/cnt/11956636
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/"
CHR DefaultSearchURL: Default -> hxxp://go.mail.ru/search?q={searchTerms}&fr=xtn9
CHR DefaultSearchKeyword: Default -> mail.ru
CHR DefaultSuggestURL: Default -> hxxp://suggests.go.mail.ru/chrome?q={searchTerms}
CHR Profile: C:\Users\Tepan\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Avast Online Security) - C:\Users\Tepan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-07-20]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Tepan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-09]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-03-15]
CHR HKLM-x32\...\Chrome\Extension: [ilamgbdaebkbpkkmfmmfbnaamkhijdek] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ofdgafmdegfkhfdfkmllfefmcmcjllec] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [pnooffjhclkocplopffdbcdghmiffhji] - hxxps://clients2.google.com/service/update2/crx
StartMenuInternet: Google Chrome.XFTHEVSGWAYNGGKTIHVB3OUHNE - C:\Users\Tepan\AppData\Local\Google\Chrome\Application\chrome.exe

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-08-06] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4047768 2015-07-21] (Avast Software)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
S4 PLFlash DeviceIoControl Service; C:\Windows\SysWOW64\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-04-15] ()
R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [187048 2015-07-22] ()
R2 RzKLService; C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe [129168 2015-07-30] (Razer Inc.)
S4 SystemExplorerHelpService; C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe [820960 2014-12-20] (Mister Group)
S4 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5447952 2015-03-25] (TeamViewer GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 wsaudio; C:\Windows\SysWOW64\wsaudio.dll [367104 2015-05-25] () [File not signed]
S2 HPSLPSVC; C:\Users\Tepan\AppData\Local\Temp\7zS3FA8\hpslpsvc64.dll [X]
S2 Prime95 Service; C:\Program Files (x86)\Prime95\prime95.exe [X]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-08-06] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-08-06] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-08-06] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-08-06] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1048344 2015-08-18] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [447944 2015-08-06] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [150672 2015-08-06] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-08-06] (AVAST Software)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [88480 2014-08-14] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-10-01] (Disc Soft Ltd)
S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 ENTECH64; C:\Windows\system32\DRIVERS\ENTECH64.sys [12744 2008-09-17] (EnTech Taiwan)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [46400 2014-08-14] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-09-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
R0 ngvss; C:\Windows\System32\Drivers\ngvss.sys [115152 2015-08-06] (AVAST Software)
S3 NTIOLib_1_0_6; C:\Program Files (x86)\Setup Files\Ms7529v470\NTIOLib_X64.sys [11888 2011-01-06] (MSI) [File not signed]
R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [37184 2015-06-12] (Razer, Inc.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [386680 2014-10-01] (Duplex Secure Ltd.)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [273824 2015-07-21] (Avast Software)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-09-18 10:33 - 2015-09-18 10:33 - 00018653 _____ C:\Users\Tepan\Desktop\FRST.txt
2015-09-18 10:31 - 2015-09-18 10:31 - 00112640 _____ (forum.viry.cz) C:\Users\Tepan\Desktop\FRSTLauncher.exe
2015-09-18 10:30 - 2015-09-18 10:30 - 02191360 _____ (Farbar) C:\Users\Tepan\Desktop\FRST64.exe
2015-09-15 09:59 - 2015-09-15 09:59 - 00000833 _____ C:\Users\Tepan\Desktop\Nový textový dokument (2).txt
2015-09-10 07:18 - 2015-09-10 18:07 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\204D3F81.sys
2015-09-05 15:42 - 2015-09-18 10:10 - 00000784 _____ C:\Windows\setupact.log
2015-09-05 15:42 - 2015-09-05 15:42 - 00000000 _____ C:\Windows\setuperr.log
2015-09-02 14:41 - 2015-09-02 14:41 - 00000000 ____D C:\Users\Tepan\AppData\Roaming\Sun
2015-09-02 14:41 - 2015-09-02 14:41 - 00000000 ____D C:\Users\Tepan\.oracle_jre_usage
2015-08-29 07:23 - 2015-08-29 07:23 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\12881974.sys
2015-08-23 19:09 - 2015-08-23 19:09 - 00000000 _____ C:\Users\Tepan\Desktop\Nový textový dokument.txt
2015-08-23 14:35 - 2015-08-23 14:35 - 00001976 _____ C:\Users\Tepan\Desktop\888casino.lnk
2015-08-23 14:35 - 2015-08-23 14:35 - 00000000 ____D C:\Users\Tepan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\888casino
2015-08-23 14:35 - 2015-08-23 14:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\888casino
2015-08-23 14:34 - 2015-08-23 14:35 - 00000000 ____D C:\Users\Tepan\AppData\Roaming\CasinoOnNet
2015-08-23 14:34 - 2015-08-23 14:35 - 00000000 ____D C:\Program Files (x86)\CasinoOnNet
2015-08-23 09:35 - 2015-08-23 09:35 - 01605632 _____ C:\Users\Tepan\Desktop\adwcleaner_5.003.exe

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-09-18 10:33 - 2015-06-23 16:50 - 00000000 ____D C:\FRST
2015-09-18 10:32 - 2013-01-16 14:36 - 01967454 _____ C:\Windows\WindowsUpdate.log
2015-09-18 10:18 - 2009-07-14 06:45 - 00023024 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-09-18 10:18 - 2009-07-14 06:45 - 00023024 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-09-18 10:10 - 2015-07-22 12:37 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-09-18 10:08 - 2015-01-28 08:31 - 00000000 ____D C:\AdwCleaner
2015-09-17 08:13 - 2013-01-16 20:32 - 00000000 ____D C:\Users\Tepan\AppData\Roaming\vlc
2015-09-16 12:55 - 2013-01-16 17:21 - 00000000 ____D C:\Users\Tepan\AppData\Roaming\uTorrent
2015-09-15 08:34 - 2009-07-14 17:18 - 00668866 _____ C:\Windows\system32\perfh005.dat
2015-09-15 08:34 - 2009-07-14 17:18 - 00141526 _____ C:\Windows\system32\perfc005.dat
2015-09-15 08:34 - 2009-07-14 07:13 - 01584554 _____ C:\Windows\system32\PerfStringBackup.INI
2015-09-15 07:03 - 2014-01-26 11:59 - 00000000 ____D C:\Users\Tepan\Documents\888poker
2015-09-15 06:43 - 2015-02-06 15:24 - 00000000 ____D C:\Program Files (x86)\Full Tilt Poker.Eu
2015-09-15 06:37 - 2015-07-10 20:17 - 00000000 ____D C:\Users\Tepan\AppData\Roaming\PacificPoker
2015-09-15 06:37 - 2015-02-06 17:26 - 00000000 ____D C:\Users\Tepan\AppData\Local\FullTiltPoker.eu
2015-09-15 06:23 - 2014-02-22 15:18 - 00000000 ____D C:\Users\Tepan\Documents\Add-in Express
2015-09-08 20:38 - 2014-02-25 12:58 - 00000000 ____D C:\Users\Tepan\AppData\Local\CrashDumps
2015-09-02 15:38 - 2015-01-09 20:06 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-09-02 15:38 - 2013-01-16 15:40 - 00778440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-09-02 15:38 - 2013-01-16 15:40 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-09-02 14:43 - 2013-06-25 01:23 - 00000000 ____D C:\Program Files (x86)\Java
2015-09-02 14:42 - 2015-03-10 19:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-09-02 14:41 - 2015-05-14 06:31 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-09-02 14:41 - 2013-01-16 14:48 - 00000000 ____D C:\Users\Tepan
2015-08-23 14:20 - 2015-08-02 12:30 - 00000000 ____D C:\Program Files\Adblock Plus for IE

==================== Files in the root of some directories =======

2014-04-20 23:40 - 2014-04-20 23:43 - 0003750 _____ () C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml
2015-03-19 13:16 - 2015-07-06 19:48 - 0159200 ____T () C:\Users\Tepan\AppData\Roaming\CrashRpt1402.dll
2002-08-29 19:33 - 2002-08-29 19:33 - 0319488 ____R () C:\Users\Tepan\AppData\Roaming\MafiaSetup.exe
2015-04-17 13:51 - 2015-04-17 13:51 - 0000407 _____ () C:\Users\Tepan\AppData\Roaming\wameu_state.xml
2015-04-16 06:31 - 2015-04-16 06:56 - 0001000 _____ () C:\Users\Tepan\AppData\Roaming\__AvidCloudManager.log
2014-01-01 07:22 - 2015-04-16 06:34 - 0004608 _____ () C:\Users\Tepan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-12-10 22:00 - 2014-12-10 22:00 - 0000124 _____ () C:\Users\Tepan\AppData\Local\NetBetCoach_SettingsPath.txt
2014-12-26 01:52 - 2014-12-26 01:52 - 0007664 _____ () C:\Users\Tepan\AppData\Local\Resmon.ResmonCfg
2015-02-06 15:24 - 2015-02-06 15:28 - 53683536 _____ () C:\Users\Tepan\AppData\Local\TempFullTiltPokerEuSetup.exe
2015-07-05 19:13 - 2015-07-05 19:13 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2014-07-28 11:32 - 2014-12-28 22:03 - 0002240 _____ () C:\ProgramData\hpzinstall.log

Some files in TEMP:
====================
C:\Users\Tepan\AppData\Local\Temp\jre-8u60-windows-au.exe
C:\Users\Tepan\AppData\Local\Temp\Quarantine.exe
C:\Users\Tepan\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Acrobat Update Task.job => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\avast! Emergency Update.job => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
Task: C:\Windows\Tasks\DriverDocRunAtStartup.job => C:\Program Files (x86)\DriverDoc\Solvusoftdd.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1029120089-3632672932-3177029402-1001UA.job => C:\Users\Tepan\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HPCeeScheduleForTepan.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
Task: C:\Windows\Tasks\SmartRecharge.job => c:\programdata\{bac6e063-c6ce-6047-bac6-6e063c6c818f}\malwarebytes anti-malware premium 2.1.8 keygen is here ! [latest].exe <==== ATTENTION

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Disabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Tepan\Desktop" je 81 MB.


***** Startup Programs *****

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\amd_dc_opt
C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BingSvc
C:\Users\Tepan\AppData\Local\Microsoft\BingSvc\BingSvc.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring
"C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXMediaServer
C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FAHConsole
C:\Program Files\File Association Helper\FAHConsole.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update
"C:\Users\Tepan\AppData\Local\Google\Update\GoogleUpdate.exe" /c [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Raptr
C:\PROGRA~2\Raptr\raptrstub.exe --startup [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDVCPL
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC
"C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent
"C:\Users\Tepan\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Tepan^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^hpqtra08.exe
C:\Users\Tepan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hpqtra08.exe [x]


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================

altrok
Moderátor
Moderátor
Příspěvky: 7322
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: preventivní kontrola logu---zpomalení počítače

#2 Příspěvek od altrok »

Krasny den Vam preju :bye:


:arrow: Ktery proces vytezuje procesor nejvic?

:arrow: Co je tohle? c:\programdata\{bac6e063-c6ce-6047-bac6-6e063c6c818f}\malwarebytes anti-malware premium 2.1.8 keygen is here ! [latest].exe

:arrow: V ramci cisteni Vam budou vyprazdneny docasne adresare (vcetne Kose).

:arrow: Ulozte na plochu AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/ (nebo http://www.bleepingcomputer.com/download/adwcleaner/ )
  • ukoncete vsechny programy
  • kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
  • kliknete na Scan, pote na Cleaning
  • po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\AdwCleaner[Cx].txt), jehoz obsah mi zkopirujte do pristi odpovedi
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

tepan
Návštěvník
Návštěvník
Příspěvky: 248
Registrován: 22 pro 2006 21:11
Bydliště: Sumperk

Re: preventivní kontrola logu---zpomalení počítače

#3 Příspěvek od tepan »

nejvíce svchost.exe a DismHost.exe TrustedInstaller.exe (ale každý pokaždé méně či více)

Malwares bytes jsem odinstaloval

log z Adwcleaner je:

# AdwCleaner v5.008 - Logfile created 18/09/2015 at 23:29:26
# Updated 18/09/2015 by Xplode
# Database : 2015-09-17.3 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Tepan - TEPAN-PC
# Running from : C:\Users\Tepan\Desktop\adwcleaner_5.008.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****

[-] Folder Deleted : C:\ProgramData\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
[-] Folder Deleted : C:\ProgramData\{D76294E6-03B8-4971-AF2E-3F846161A690}
[-] Folder Deleted : C:\ProgramData\{E1ED556E-3EA0-4F44-8BE7-CC5FB0F4B424}

***** [ Files ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

[-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Control\Class\{0014298C-A9BA-440D-AAA8-AD12C7010EE5}
[-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Control\Class\{181A06EA-B82C-47DE-B851-E20FD0E1CC7D}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{210cd309-dc9f-4dcd-89a8-8a7b0003ffca}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{39c4e459-68e4-49c9-a331-9ebf4960d45a}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{210cd309-dc9f-4dcd-89a8-8a7b0003ffca}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{39c4e459-68e4-49c9-a331-9ebf4960d45a}

***** [ Web browsers ] *****

[-] [C:\Users\Tepan\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : ooebklgpfnbcnpokahmdidgbmlcdepkm

*************************

:: Winsock settings cleared

########## EOF - C:\AdwCleaner\AdwCleaner[C10].txt - [1713 bytes] ##########

tepan
Návštěvník
Návštěvník
Příspěvky: 248
Registrován: 22 pro 2006 21:11
Bydliště: Sumperk

Re: preventivní kontrola logu---zpomalení počítače

#4 Příspěvek od tepan »

a občas něco bere ještě :

jusched.exe a samozřejmě něco awast a WmiPrvSE.exe

přikládám obrázek,jak to vypadá,kdyžnic nedělám
Přílohy
Bez názvu.png
Bez názvu.png (57.75 KiB) Zobrazeno 2043 x

altrok
Moderátor
Moderátor
Příspěvky: 7322
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: preventivní kontrola logu---zpomalení počítače

#5 Příspěvek od altrok »

:arrow: Ulozte na plochu ESET Online Scanner kliknutim na esetsmartinstaller_csy.exe
  • ulozeny esetsmartinstaller_csy.exe dvojklikem spustte
  • zaskrtnete Ano, souhlasim s podminkami uziti a kliknete na Spustit
  • vyberte moznost Povolit detekci nechtenych aplikaci
  • rozkliknete moznost Rozsirene nastaveni a
    • zruste zatrzitko u volby Odstranit nalezene infiltrace
    • ponechte zatrhnutou moznost Pouzit technologii Anti-Stealth
  • kliknete na Kontrola, cimz se spusti az nekolikahodinovy sken
  • po dokonceni skenu kliknete na Seznam nalezenych infiltraci (v pripade zadneho nalezu log nevytvorite)
  • kliknete na Ulozit do textoveho souboru, log pojmenujte jako ESETlog a ulozte na plochu
  • obsah logu vlozte do pristi odpovedi
  • kliknete na << Zpet a zatrhnete moznost Odinstalovat
  • klikem na Dokoncit ESET Online Scanner zavrete.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

tepan
Návštěvník
Návštěvník
Příspěvky: 248
Registrován: 22 pro 2006 21:11
Bydliště: Sumperk

Re: preventivní kontrola logu---zpomalení počítače

#6 Příspěvek od tepan »

C:\FRST\Quarantine\C\Users\Tepan\AppData\Local\Temp\ICReinstall_adobe-flash-player-activex.exe varianta infiltrace Win32/InstallCore.ACQ.gen potenciálně nechtěná aplikace
C:\FRST\Quarantine\C\Users\Tepan\AppData\Local\Temp\is1128754588\344EECBB_stp\CreateShortcut.dll varianta infiltrace Win32/InstallCore.ACL potenciálně nechtěná aplikace
C:\FRST\Quarantine\C\Users\Tepan\AppData\Local\Temp\is1128754588\4DE27217_stp\TaskScheduler.dll varianta infiltrace Win32/InstallCore.ACL potenciálně nechtěná aplikace
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSS.exe varianta infiltrace Win32/Systweak.L potenciálně nechtěná aplikace
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSHelper.dll varianta infiltrace Win32/Systweak.N potenciálně nechtěná aplikace
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSPrivacyProtector.exe varianta infiltrace Win32/Systweak.L potenciálně nechtěná aplikace
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSRegClean.exe varianta infiltrace Win32/Systweak potenciálně nechtěná aplikace
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSRegistryOptimizer.exe varianta infiltrace Win32/Systweak.L potenciálně nechtěná aplikace
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSSystemCleaner.exe varianta infiltrace Win32/Systweak.L potenciálně nechtěná aplikace
C:\Users\Tepan\Desktop\Ochrana pocitace\dffsetup.exe varianta infiltrace Win32/Systweak potenciálně nechtěná aplikace
H:\$RECYCLE.BIN\S-1-5-21-4148227877-3223660242-267646093-1000\$RUNXU84.exe Win32/CentrumDownloader.A potenciálně nechtěná aplikace

tepan
Návštěvník
Návštěvník
Příspěvky: 248
Registrován: 22 pro 2006 21:11
Bydliště: Sumperk

Re: preventivní kontrola logu---zpomalení počítače

#7 Příspěvek od tepan »

jen chci ještě dodat,že na ploše mi stále zůstává FRSTLauncher a FRST64

altrok
Moderátor
Moderátor
Příspěvky: 7322
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: preventivní kontrola logu---zpomalení počítače

#8 Příspěvek od altrok »

:arrow: Nebojte, jeste je budeme potrebovat.


:arrow: Dejte log FRST.txt, prilozte i Addition.txt - http://forum.viry.cz/viewtopic.php?f=30&t=133101
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

tepan
Návštěvník
Návštěvník
Příspěvky: 248
Registrován: 22 pro 2006 21:11
Bydliště: Sumperk

Re: preventivní kontrola logu---zpomalení počítače

#9 Příspěvek od tepan »

ty logy uz nemam,zmizely(nevím přesně kdy--myslím,že po projetí Adwcleanerem nebo odinstalování Mbam

mám dát nový?

altrok
Moderátor
Moderátor
Příspěvky: 7322
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: preventivní kontrola logu---zpomalení počítače

#10 Příspěvek od altrok »

Ano, potrebuju logy o aktualnim stavu pocitace, takze udelejte nove :)
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

tepan
Návštěvník
Návštěvník
Příspěvky: 248
Registrován: 22 pro 2006 21:11
Bydliště: Sumperk

Re: preventivní kontrola logu---zpomalení počítače

#11 Příspěvek od tepan »

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:15-09-2015
Ran by Tepan (administrator) on TEPAN-PC (20-09-2015 20:55:37)
Running from C:\Users\Tepan\Desktop
Loaded Profiles: Tepan (Available Profiles: Tepan)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AMD) C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe
(AMD) C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpert.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe
(AMD) C:\Windows\SysWOW64\WinMsgBalloonServer.exe
(AMD) C:\Windows\SysWOW64\WinMsgBalloonClient.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6111824 2015-08-28] (AVAST Software)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [998104 2015-07-07] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-07-28] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\Run: [Google Update] => C:\Users\Tepan\AppData\Local\Google\Update\GoogleUpdate.exe [107848 2015-06-20] (Google Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-08-06] (AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2014-08-02]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 213.46.172.37 213.46.172.36
Tcpip\..\Interfaces\{224703BF-4E2B-4984-BECA-D22BB644A342}: [DhcpNameServer] 213.46.172.37 213.46.172.36
Tcpip\..\Interfaces\{B7B4C87E-1BE6-4F4F-A6C5-702CD234D949}: [DhcpNameServer] 8.8.8.8 192.168.91.2

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.seznam.cz/
HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.seznam.cz/?clid=22668
SearchScopes: HKLM-x32 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1029120089-3632672932-3177029402-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1029120089-3632672932-3177029402-1001 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-08-06] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2015-02-25] (Eyeo GmbH)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll [2015-09-02] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-08-06] (AVAST Software)
BHO-x32: Pomocná služba pro přihlášení k účtu Microsoft -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-09-02] (Oracle Corporation)
BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-02-25] (Eyeo GmbH)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

FireFox:
========
FF ProfilePath: C:\Users\Tepan\AppData\Roaming\Mozilla\Firefox\Profiles\sdckyap9.default-1405284649585
FF DefaultSearchEngine: Google
FF SearchEngineOrder.3: Bing
FF SelectedSearchEngine: Поиск@Mail.Ru
FF Homepage: hxxps://www.seznam.cz/
FF Keyword.URL: hxxp://go.mail.ru/search?fr=ntg&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll [2015-08-15] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40620.0\npctrl.dll [2015-06-20] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-16] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-15] ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2014-11-21] (DivX, LLC)
FF Plugin-x32: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-09-02] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-09-02] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40620.0\npctrl.dll [2015-06-19] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll [2011-02-21] (RocketLife, LLP)
FF Plugin-x32: @videolan.org/vlc,version=2.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1029120089-3632672932-3177029402-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Tepan\AppData\Local\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-18] (Google Inc.)
FF Plugin HKU\S-1-5-21-1029120089-3632672932-3177029402-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Tepan\AppData\Local\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-18] (Google Inc.)
FF Plugin HKU\S-1-5-21-1029120089-3632672932-3177029402-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2014-06-22] ()
FF SearchPlugin: C:\Users\Tepan\AppData\Roaming\Mozilla\Firefox\Profiles\sdckyap9.default-1405284649585\searchplugins\anglicko-esk-slovnk.xml [2015-08-10]
FF SearchPlugin: C:\Users\Tepan\AppData\Roaming\Mozilla\Firefox\Profiles\sdckyap9.default-1405284649585\searchplugins\bing-.xml [2015-07-04]
FF Extension: Adblock Plus - C:\Users\Tepan\AppData\Roaming\Mozilla\Firefox\Profiles\sdckyap9.default-1405284649585\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-07-16]
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2014-07-28]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-03-15]
FF HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR HomePage: Default -> hxxps://mail.ru/cnt/11956636
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/"
CHR DefaultSearchURL: Default -> hxxp://go.mail.ru/search?q={searchTerms}&fr=xtn9
CHR DefaultSearchKeyword: Default -> mail.ru
CHR DefaultSuggestURL: Default -> hxxp://suggests.go.mail.ru/chrome?q={searchTerms}
CHR Profile: C:\Users\Tepan\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Avast Online Security) - C:\Users\Tepan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-07-20]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Tepan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-09]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-03-15]
CHR HKLM-x32\...\Chrome\Extension: [ilamgbdaebkbpkkmfmmfbnaamkhijdek] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ofdgafmdegfkhfdfkmllfefmcmcjllec] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [pnooffjhclkocplopffdbcdghmiffhji] - hxxps://clients2.google.com/service/update2/crx
StartMenuInternet: Google Chrome.XFTHEVSGWAYNGGKTIHVB3OUHNE - C:\Users\Tepan\AppData\Local\Google\Chrome\Application\chrome.exe

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-08-06] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4047768 2015-07-21] (Avast Software)
S2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
S4 PLFlash DeviceIoControl Service; C:\Windows\SysWOW64\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed]
S2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-04-15] ()
R4 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [187048 2015-07-22] ()
R4 RzKLService; C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe [129168 2015-07-30] (Razer Inc.)
S4 SystemExplorerHelpService; C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe [820960 2014-12-20] (Mister Group)
S4 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5447952 2015-03-25] (TeamViewer GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 wsaudio; C:\Windows\SysWOW64\wsaudio.dll [367104 2015-05-25] () [File not signed]
S2 HPSLPSVC; C:\Users\Tepan\AppData\Local\Temp\7zS3FA8\hpslpsvc64.dll [X]
S2 Prime95 Service; C:\Program Files (x86)\Prime95\prime95.exe [X]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-08-06] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-08-06] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-08-06] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-08-06] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1048344 2015-08-18] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [447944 2015-08-06] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [150672 2015-08-06] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-08-06] (AVAST Software)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [88480 2014-08-14] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-10-01] (Disc Soft Ltd)
S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 ENTECH64; C:\Windows\system32\DRIVERS\ENTECH64.sys [12744 2008-09-17] (EnTech Taiwan)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [46400 2014-08-14] ()
R0 ngvss; C:\Windows\System32\Drivers\ngvss.sys [115152 2015-08-06] (AVAST Software)
S3 NTIOLib_1_0_6; C:\Program Files (x86)\Setup Files\Ms7529v470\NTIOLib_X64.sys [11888 2011-01-06] (MSI) [File not signed]
R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [37184 2015-06-12] (Razer, Inc.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [386680 2014-10-01] (Duplex Secure Ltd.)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [273824 2015-07-21] (Avast Software)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-09-20 20:55 - 2015-09-20 20:56 - 00017689 _____ C:\Users\Tepan\Desktop\FRST.txt
2015-09-20 10:34 - 2015-09-20 10:34 - 02870984 _____ (ESET) C:\Users\Tepan\Desktop\esetsmartinstaller_csy.exe
2015-09-18 23:42 - 2015-09-20 01:23 - 00000910 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1029120089-3632672932-3177029402-1001Core.job
2015-09-18 23:42 - 2015-09-18 23:42 - 00003932 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1029120089-3632672932-3177029402-1001UA
2015-09-18 23:42 - 2015-09-18 23:42 - 00003536 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1029120089-3632672932-3177029402-1001Core
2015-09-18 10:31 - 2015-09-18 10:31 - 00112640 _____ (forum.viry.cz) C:\Users\Tepan\Desktop\FRSTLauncher.exe
2015-09-18 10:30 - 2015-09-18 10:30 - 02191360 _____ (Farbar) C:\Users\Tepan\Desktop\FRST64.exe
2015-09-10 07:18 - 2015-09-10 18:07 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\204D3F81.sys
2015-09-02 14:41 - 2015-09-02 14:41 - 00000000 ____D C:\Users\Tepan\AppData\Roaming\Sun
2015-09-02 14:41 - 2015-09-02 14:41 - 00000000 ____D C:\Users\Tepan\.oracle_jre_usage
2015-08-29 07:23 - 2015-08-29 07:23 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\12881974.sys
2015-08-23 14:34 - 2015-09-18 23:28 - 00000000 ____D C:\Users\Tepan\AppData\Roaming\CasinoOnNet

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-09-20 20:56 - 2014-02-25 12:58 - 00000000 ____D C:\Users\Tepan\AppData\Local\CrashDumps
2015-09-20 20:55 - 2015-06-23 16:50 - 00000000 ____D C:\FRST
2015-09-20 20:54 - 2015-06-20 11:35 - 00000962 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1029120089-3632672932-3177029402-1001UA.job
2015-09-20 20:53 - 2015-01-09 20:06 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-09-20 19:10 - 2015-02-06 15:24 - 00000000 ____D C:\Program Files (x86)\Full Tilt Poker.Eu
2015-09-20 19:02 - 2009-07-14 06:45 - 00023024 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-09-20 19:02 - 2009-07-14 06:45 - 00023024 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-09-20 18:57 - 2013-01-16 14:36 - 02049049 _____ C:\Windows\WindowsUpdate.log
2015-09-20 16:13 - 2013-03-12 04:07 - 00003970 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{2A515284-680A-45EA-B4C4-72FAA57CC791}
2015-09-20 12:07 - 2015-01-19 02:51 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-09-20 11:00 - 2015-03-15 16:49 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2015-09-20 10:58 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-09-20 02:14 - 2013-01-16 20:32 - 00000000 ____D C:\Users\Tepan\AppData\Roaming\vlc
2015-09-18 23:52 - 2014-07-29 01:18 - 00000000 ____D C:\Users\Tepan\Desktop\Ochrana pocitace
2015-09-18 23:52 - 2014-07-29 01:17 - 00000000 ____D C:\Users\Tepan\Desktop\Hry
2015-09-18 23:30 - 2013-01-16 15:40 - 00003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-09-18 23:29 - 2015-01-28 08:31 - 00000000 ____D C:\AdwCleaner
2015-09-16 12:55 - 2013-01-16 17:21 - 00000000 ____D C:\Users\Tepan\AppData\Roaming\uTorrent
2015-09-15 08:34 - 2009-07-14 17:18 - 00668866 _____ C:\Windows\system32\perfh005.dat
2015-09-15 08:34 - 2009-07-14 17:18 - 00141526 _____ C:\Windows\system32\perfc005.dat
2015-09-15 08:34 - 2009-07-14 07:13 - 01584554 _____ C:\Windows\system32\PerfStringBackup.INI
2015-09-15 07:03 - 2014-01-26 11:59 - 00000000 ____D C:\Users\Tepan\Documents\888poker
2015-09-15 06:37 - 2015-07-10 20:17 - 00000000 ____D C:\Users\Tepan\AppData\Roaming\PacificPoker
2015-09-15 06:37 - 2015-02-06 17:26 - 00000000 ____D C:\Users\Tepan\AppData\Local\FullTiltPoker.eu
2015-09-15 06:23 - 2014-02-22 15:18 - 00000000 ____D C:\Users\Tepan\Documents\Add-in Express
2015-09-02 15:38 - 2013-01-16 15:40 - 00778440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-09-02 15:38 - 2013-01-16 15:40 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-09-02 14:43 - 2013-06-25 01:23 - 00000000 ____D C:\Program Files (x86)\Java
2015-09-02 14:42 - 2015-03-10 19:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-09-02 14:41 - 2015-05-14 06:31 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-09-02 14:41 - 2013-01-16 14:48 - 00000000 ____D C:\Users\Tepan
2015-08-23 14:20 - 2015-08-02 12:30 - 00000000 ____D C:\Program Files\Adblock Plus for IE

==================== Files in the root of some directories =======

2014-04-20 23:40 - 2014-04-20 23:43 - 0003750 _____ () C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml
2015-03-19 13:16 - 2015-07-06 19:48 - 0159200 ____T () C:\Users\Tepan\AppData\Roaming\CrashRpt1402.dll
2002-08-29 19:33 - 2002-08-29 19:33 - 0319488 ____R () C:\Users\Tepan\AppData\Roaming\MafiaSetup.exe
2015-04-17 13:51 - 2015-04-17 13:51 - 0000407 _____ () C:\Users\Tepan\AppData\Roaming\wameu_state.xml
2015-04-16 06:31 - 2015-04-16 06:56 - 0001000 _____ () C:\Users\Tepan\AppData\Roaming\__AvidCloudManager.log
2014-01-01 07:22 - 2015-04-16 06:34 - 0004608 _____ () C:\Users\Tepan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-12-10 22:00 - 2014-12-10 22:00 - 0000124 _____ () C:\Users\Tepan\AppData\Local\NetBetCoach_SettingsPath.txt
2014-12-26 01:52 - 2014-12-26 01:52 - 0007664 _____ () C:\Users\Tepan\AppData\Local\Resmon.ResmonCfg
2015-02-06 15:24 - 2015-02-06 15:28 - 53683536 _____ () C:\Users\Tepan\AppData\Local\TempFullTiltPokerEuSetup.exe
2015-07-05 19:13 - 2015-07-05 19:13 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2014-07-28 11:32 - 2014-12-28 22:03 - 0002240 _____ () C:\ProgramData\hpzinstall.log

Some files in TEMP:
====================
C:\Users\Tepan\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-07-04 23:53

==================== End of FRST.txt ============================

tepan
Návštěvník
Návštěvník
Příspěvky: 248
Registrován: 22 pro 2006 21:11
Bydliště: Sumperk

Re: preventivní kontrola logu---zpomalení počítače

#12 Příspěvek od tepan »

Additional scan result of Farbar Recovery Scan Tool (x64) Version:15-09-2015
Ran by Tepan (2015-09-20 20:56:37)
Running from C:\Users\Tepan\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2013-01-16 12:48:09)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1029120089-3632672932-3177029402-500 - Administrator - Disabled)
Guest (S-1-5-21-1029120089-3632672932-3177029402-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1029120089-3632672932-3177029402-1002 - Limited - Enabled)
Tepan (S-1-5-21-1029120089-3632672932-3177029402-1001 - Administrator - Enabled) => C:\Users\Tepan

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Disabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKLM-x32\...\uTorrent) (Version: 2.2.1.25534 - emc, uTorrent.CZ)
32Red Poker Room (HKLM-x32\...\32red (Poker)) (Version: 16.6.2.11243 - )
64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden
7-Zip 9.22beta (HKLM-x32\...\7-Zip) (Version: - )
888poker (HKLM-x32\...\888poker) (Version: - )
Adblock Plus for IE (32-bit and 64-bit) (HKLM\...\{26D488C3-89E9-455C-B96A-1ADF65A26C54}) (Version: 1.4 - Eyeo GmbH)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 18.0.0.199 - Adobe Systems Incorporated)
Adobe Flash Player 18 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 18.0.0.232 - Adobe Systems Incorporated)
Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.12) - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\...\{F37078EA-4B6A-1D6F-6FED-3EDF2117B42C}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
Assassin's Creed Brotherhood (HKLM-x32\...\{BE4BA698-8533-4F77-9559-C7F3F78C0B05}) (Version: 1.03 - Ubisoft)
Astroburn Lite (HKLM-x32\...\Astroburn Lite) (Version: 1.8.0.0182 - Disc Soft Ltd)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.3.2225 - AVAST Software)
AVG PC TuneUp Language Pack (en-US) (x32 Version: 12.0.4000.108 - AVG Technologies) Hidden
Balíček ovladače systému Windows - u-blox AG (ubloxusb) Ports (09/12/2008 1.2.0.1) (HKLM\...\38C9A50B4FB83FBC3B6B66EAC2E4A7B2930F8D10) (Version: 09/12/2008 1.2.0.1 - u-blox AG)
Betsson Poker by Microgaming (HKLM-x32\...\betssonpoker (Poker)) (Version: 16.6.2.11243 - )
BufferChm (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden
Call of Duty 4 - Modern Warfare verze 1.7 (HKLM-x32\...\{826D7727-6105-4C5D-A049-E4BADBC8BAAB}_is1) (Version: 1.7 - tomi2k9)
Call of Juarez - Bound in Blood (HKLM-x32\...\InstallShield_{019908AA-79E9-4389-A1AD-8BBEED63CFBA}) (Version: 1.01.0000 - Ubisoft)
Call of Juarez - Bound in Blood (x32 Version: 1.01.0000 - Ubisoft) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.08 - Piriform)
Copy (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Defraggler (HKLM\...\Defraggler) (Version: 2.18 - Piriform)
Destinations (x32 Version: 140.0.77.000 - Hewlett-Packard) Hidden
DeviceDiscovery (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden
DivX Setup (HKLM-x32\...\DivX Setup) (Version: 2.7.0.31 - DivX, LLC)
DJ_AIO_06_F2400_SW_Min (x32 Version: 140.0.690.000 - Hewlett-Packard) Hidden
Dual-Core Optimizer (HKLM-x32\...\{9FD6F1A8-5550-46AF-8509-271DF0E768B5}) (Version: 1.1.4.0169 - AMD)
DualCoreCenter (HKLM-x32\...\DualCoreCenter_is1) (Version: - MSI, Inc.)
EAX Unified (HKLM-x32\...\EAX Unified) (Version: - )
EVEREST Ultimate Edition v5.50 (HKLM-x32\...\EVEREST Ultimate Edition_is1) (Version: 5.50 - Lavalys, Inc.)
F2400 (x32 Version: 140.0.690.000 - Hewlett-Packard) Hidden
ffdshow v1.2.4422 [2012-04-09] (HKLM-x32\...\ffdshow_is1) (Version: 1.2.4422.0 - )
Fotogalerie (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Free Download Manager Language pack (HKLM-x32\...\Free Download Manager_is1) (Version: - )
Frontlines: Fuel of War (HKLM-x32\...\{C711E88C-9DC2-4254-A989-D6E017844DDF}) (Version: 1.0.1 - THQ)
Full Tilt Poker.Eu (HKLM-x32\...\{127BEFB3-24B2-4B44-8E99-AD22C2A5A8ED}) (Version: 5.28.1.WIN.FullTilt.EU - )
Futuremark SystemInfo (HKLM-x32\...\{BEE64C14-BEF1-4610-8A68-A16EAA47B882}) (Version: 3.21.2.1 - Futuremark Corporation)
Google Chrome (HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\Google Chrome) (Version: 45.0.2454.93 - Google Inc.)
GPBaseService2 (x32 Version: 140.0.211.000 - Hewlett-Packard) Hidden
Grand Theft Auto V (HKLM-x32\...\Grand Theft Auto V_is1) (Version: 1.0.350.1 - Rockstar)
Heroes of Might and Magic® IV Big World Barbarian (HKLM-x32\...\Heroes of Might and Magic® IV Big World Barbarian) (Version: - )
HP Customer Participation Program 14.0 (HKLM\...\HPExtendedCapabilities) (Version: 14.0 - HP)
HP Deskjet F2400 All-in-One Driver Software 14.0 Rel. 6 (HKLM\...\{819CA3BC-2FF8-4811-B42F-421F7BFD3559}) (Version: 14.0 - HP)
HP Imaging Device Functions 14.0 (HKLM\...\HP Imaging Device Functions) (Version: 14.0 - HP)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.12992 - HP)
HP Smart Web Printing 4.60 (HKLM\...\HP Smart Web Printing) (Version: 4.60 - HP)
HP Solution Center 14.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 14.0 - HP)
HPPhotoGadget (x32 Version: 140.0.524.000 - Hewlett-Packard) Hidden
HPProductAssistant (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden
IcoFX 1.6.4 (HKLM-x32\...\IcoFX_is1) (Version: - )
Java 8 Update 60 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218060F0}) (Version: 8.0.600.27 - Oracle Corporation)
L.A. Noire verzia 1.3.2617 (HKLM-x32\...\L.A. Noire_is1) (Version: 1.3.2617 - CzTorrent.net)
Mafia Game (HKLM-x32\...\Mafia Game) (Version: - )
MarketResearch (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden
Microsoft .NET Framework 4.5.2 (čeština) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40620.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
MozBackup 1.5.1 (HKLM-x32\...\MozBackup) (Version: - Pavel Cvrcek)
Mozilla Firefox 40.0.3 (x86 cs) (HKLM-x32\...\Mozilla Firefox 40.0.3 (x86 cs)) (Version: 40.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 31.5.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nero 8 Essentials (HKLM-x32\...\{470C8EFE-AEB0-402E-B05A-91E08C201029}) (Version: 8.3.416 - Nero AG)
NetBet Poker (HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\Netbet Poker) (Version: - )
Nexus 11.10 (HKLM-x32\...\Winstep Xtreme_is1) (Version: - )
NVIDIA PhysX (HKLM-x32\...\{64467D47-FFE4-4FBC-ABBA-A0DB829A17EB}) (Version: 9.12.0613 - NVIDIA Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
Origin (HKLM-x32\...\Origin) (Version: 9.1.15.109 - Electronic Arts, Inc.)
Poker MIRA (HKLM-x32\...\Poker MIRA 0) (Version: - )
PokerStars (HKLM-x32\...\PokerStars) (Version: - PokerStars)
RAIDXpert (HKLM-x32\...\InstallShield_{8A4A80C2-87B1-44FB-BC24-9168930EB150}) (Version: 3.3.1540.19 - AMD)
RAIDXpert (x32 Version: 3.3.1540.19 - AMD) Hidden
Razer Cortex (HKLM-x32\...\Razer Cortex_is1) (Version: 6.1.7.0 - Razer Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.89.716.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7503 - Realtek Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
RocketDock 1.3.5 (HKLM-x32\...\RocketDock_is1) (Version: - Punk Software)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.1.6.1 - Rockstar Games)
Scan (x32 Version: 140.0.80.000 - Hewlett-Packard) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft) Hidden
SevenZip (HKLM-x32\...\SevenZip) (Version: 9.20 - SevenZip)
SIW Pro Edition (Trial Version) (HKLM-x32\...\{3B9704C8-1286-4a17-9EA8-F63004FC74A1}_is1) (Version: 2015.03.12 - Topala Software Solutions)
Skype™ 7.7 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.7.102 - Skype Technologies S.A.)
SlimDrivers (HKLM-x32\...\{5AD12E7A-D739-4451-9BD1-3610EC56D8F5}) (Version: 2.2.45206 - SlimWare Utilities, Inc.)
SmartWebPrinting (x32 Version: 140.0.186.000 - Hewlett-Packard) Hidden
SolutionCenter (x32 Version: 140.0.213.000 - Hewlett-Packard) Hidden
Speccy (HKLM\...\Speccy) (Version: 1.28 - Piriform)
Status (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
System Explorer 6.2.0 (HKLM-x32\...\{40F485F7-6478-4896-B0D5-F94BE677EB78}_is1) (Version: - Mister Group)
System Requirements Lab (HKLM-x32\...\{F89CDED6-B1F1-489F-BA44-698BF6A737C2}) (Version: 6.1.6.0 - Husdawg, LLC)
System Requirements Lab Detection (HKLM-x32\...\{A407FC22-36BF-4C82-A516-59D94BC505A9}) (Version: 1.0.5.0 - Husdawg, LLC)
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.40642 - TeamViewer)
The Saboteur version 1.03 (HKLM-x32\...\The Saboteur_is1) (Version: 1.03 - )
Toolbox (x32 Version: 140.0.428.000 - Hewlett-Packard) Hidden
Total Commander (Remove or Repair) (HKLM-x32\...\Totalcmd) (Version: 7.56a - Ghisler Software GmbH)
TrayApp (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
Visual Studio 2010 x64 Redistributables (HKLM\...\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.1 - VideoLAN)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
WebReg (x32 Version: 140.0.212.017 - Hewlett-Packard) Hidden
William Hill Poker (HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\William Hill Poker) (Version: - )
Winamax (HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\Winamax 3.8.1) (Version: 3.8.1 - Winamax)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
Winner Poker (HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\winnerpoker) (Version: - )
WinPcap 4.1.2 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies)
WinRAR 5.21 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
WinZip 19.5 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240ED}) (Version: 19.5.11532 - WinZip Computing, S.L. )

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1029120089-3632672932-3177029402-1001_Classes\CLSID\{CB2B673F-D441-4CD4-AFBE-DC4037CA4220}\InprocServer32 -> C:\Program Files\WinZip\adxloader64.dll ()
CustomCLSID: HKU\S-1-5-21-1029120089-3632672932-3177029402-1001_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\Tepan\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1029120089-3632672932-3177029402-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Tepan\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll (Google Inc.)

==================== Restore Points =========================


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2015-01-09 12:37 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {040684E2-746B-4AC4-9B31-F3FA271305A8} - System32\Tasks\{A5924B5D-8DB4-4C60-BCB5-A5EADE420759} => pcalua.exe -a H:\SETUP.EXE -d H:\
Task: {0703CF5A-8013-468F-A5F4-5D44C9DA8935} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {19E6CE5F-CF3E-4413-A2FC-0CAA682A8F13} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-07-17] (Piriform Ltd)
Task: {1F6D8B6F-A098-4B66-ABF3-46E9F2870256} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2013\OneClick.exe
Task: {306EF145-F9B4-4D95-9812-303C88101FB3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-09-02] (Adobe Systems Incorporated)
Task: {30769E10-E67C-485F-A31D-721A1775331C} - System32\Tasks\{702AD2F2-E751-4E1C-845F-44FD9612CE84} => C:\Diablo II\Diablo II.exe
Task: {511092FD-B1C7-43C0-A870-A54419C69CFE} - System32\Tasks\HP online update program => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
Task: {6090461B-C567-4DF9-A452-B6BEFBC066ED} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2015-08-04] (Oracle Corporation)
Task: {6ECDFA05-FB6D-496D-B6D5-A89FFB99765A} - System32\Tasks\{66698E77-C66E-40C4-8C7C-3A397B7787CB} => pcalua.exe -a H:\SETUP.EXE -d H:\
Task: {81A1FA8A-9850-4FBA-AE76-A2325FA8AC84} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {832ABCD8-5C18-4C48-AD30-4A65CA2FFA51} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-08-06] (AVAST Software)
Task: {96073FA8-FFE0-4116-9778-58C141C7CFDC} - System32\Tasks\{FAD530BE-DABB-4A35-898F-C241A00668FC} => C:\Diablo II\Diablo II.exe
Task: {A2907E3D-3A70-47E4-990F-1FF7A5D0F8D6} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
Task: {A5B116A8-B590-4161-AAC9-BB9F6998B901} - System32\Tasks\HP Photo Creations Communicator => C:\ProgramData\HP Photo Creations\Communicator.exe [2011-02-21] ()
Task: {AEA0DEA5-F29F-4B4B-ACB4-B97BD347AD40} - System32\Tasks\{FF156A7F-B168-47A5-9FFC-2ACD88E0EF68} => pcalua.exe -a D:\Programy\Torrenty\uTorrent\lista_centrum.exe -d d:\Programy\Torrenty\uTorrent
Task: {BCE5B47B-9AB6-4650-A815-39677F46F1A2} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1029120089-3632672932-3177029402-1001UA => C:\Users\Tepan\AppData\Local\Google\Update\GoogleUpdate.exe [2015-06-20] (Google Inc.)
Task: {BD3D0611-1455-4171-A87C-7386CD2DFAF3} - System32\Tasks\{25C6D153-DFD3-4C33-B3B0-4161153DFAAC} => pcalua.exe -a C:\Windows\DIIUnin.exe -c C:\Windows\DIIUnin.dat
Task: {BE599165-223F-4809-9E9C-A712556793CA} - System32\Tasks\{C0DF86F4-0923-4C31-B17E-898DF0E55CE3} => C:\Diablo II\Diablo II.exe
Task: {CA650AE5-3A96-4B7B-8916-6932B2AACCA9} - System32\Tasks\Adobe online aktualizační program => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
Task: {D56872A3-2905-4A89-90A5-0C5222AF9BE1} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1029120089-3632672932-3177029402-1001Core => C:\Users\Tepan\AppData\Local\Google\Update\GoogleUpdate.exe [2015-06-20] (Google Inc.)
Task: {F20F4214-3B4F-4747-A7B2-F12BBD678A64} - System32\Tasks\Google Updater and Installer => C:\Users\Tepan\AppData\Local\Google\Update\GoogleUpdate.exe [2015-06-20] (Google Inc.)
Task: {F38ADF1F-FF55-4786-9411-B757136AA54B} - System32\Tasks\{3559EB80-0C68-40A4-98DF-A26E945BC2B7} => C:\Program Files (x86)\L.A. Noire\LANLauncher.exe [2012-11-16] (Rockstar Games)
Task: {FC8FD362-B9DF-427B-8BD4-15C1E091F9E6} - System32\Tasks\{DF2A06B5-02CE-43BA-9124-365E2BDF7438} => C:\Program Files (x86)\L.A. Noire\LANLauncher.exe [2012-11-16] (Rockstar Games)
Task: {FEC1C32C-9F24-4811-A16B-E02101FCB4A3} - System32\Tasks\{05B2A4A4-A4BB-4C53-96E1-786E630B5985} => C:\Diablo II\Diablo II.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Acrobat Update Task.job => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\DriverDocRunAtStartup.job => C:\Program Files (x86)\DriverDoc\Solvusoftdd.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1029120089-3632672932-3177029402-1001Core.job => C:\Users\Tepan\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1029120089-3632672932-3177029402-1001UA.job => C:\Users\Tepan\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HPCeeScheduleForTepan.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
Task: C:\Windows\Tasks\SmartRecharge.job => c:\programdata\{bac6e063-c6ce-6047-bac6-6e063c6c818f}\malwarebytes anti-malware premium 2.1.8 keygen is here ! [latest].exe <==== ATTENTION

==================== Loaded Modules (Whitelisted) ==============

2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2013-04-01 11:14 - 2013-04-15 16:26 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2015-07-22 23:30 - 2015-07-22 23:30 - 00187048 _____ () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
2015-08-06 10:46 - 2015-08-06 10:46 - 00102864 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2015-08-06 10:46 - 2015-08-06 10:46 - 00123976 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2015-09-20 01:16 - 2015-09-20 01:16 - 02965504 _____ () C:\Program Files\AVAST Software\Avast\defs\15091901\algo.dll
2015-09-20 11:01 - 2015-09-20 11:01 - 02965504 _____ () C:\Program Files\AVAST Software\Avast\defs\15092000\algo.dll
2011-07-22 14:48 - 2011-07-22 14:48 - 00516096 _____ () C:\Program Files (x86)\AMD\RAIDXpert\bin\libxml2.dll
2015-03-15 16:48 - 2015-03-15 16:48 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MSIServer => ""="Service"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE restricted site: HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\1001movie.com -> 1001movie.com
IE restricted site: HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\1001night.biz -> 1001night.biz
IE restricted site: HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\100gal.net -> 100gal.net
IE restricted site: HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\100sexlinks.com -> 100sexlinks.com

There are 4788 more restricted sites.

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Tepan\AppData\Roaming\Mozilla\Firefox\Pozadí plochy.bmp
DNS Servers: 213.46.172.37 - 213.46.172.36
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
MSCONFIG\Services: AMD External Events Utility => 2
MSCONFIG\Services: AVGIDSAgent => 2
MSCONFIG\Services: avgwd => 2
MSCONFIG\Services: eventlog => 2
MSCONFIG\Services: FreemakeVideoCapture => 2
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: NetBetCoach => 2
MSCONFIG\Services: PLFlash DeviceIoControl Service => 2
MSCONFIG\Services: Razer Game Scanner Service => 2
MSCONFIG\Services: RzKLService => 2
MSCONFIG\Services: SkypeUpdate => 2
MSCONFIG\Services: Steam Client Service => 3
MSCONFIG\Services: SystemExplorerHelpService => 3
MSCONFIG\Services: TeamViewer => 2
MSCONFIG\startupfolder: C:^Users^Tepan^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^hpqtra08.exe => C:\Windows\pss\hpqtra08.exe.Startup
MSCONFIG\startupreg: amd_dc_opt => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
MSCONFIG\startupreg: BingSvc => C:\Users\Tepan\AppData\Local\Microsoft\BingSvc\BingSvc.exe
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: DivXMediaServer => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
MSCONFIG\startupreg: FAHConsole => C:\Program Files\File Association Helper\FAHConsole.exe
MSCONFIG\startupreg: Google Update => "C:\Users\Tepan\AppData\Local\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: Raptr => C:\PROGRA~2\Raptr\raptrstub.exe --startup
MSCONFIG\startupreg: RTHDVCPL => "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
MSCONFIG\startupreg: uTorrent => "C:\Users\Tepan\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [TCP Query User{F5AACE19-C1BB-484E-8735-E553170A9994}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{88AA513B-93D6-41C7-B38C-92CC9D010437}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{E2C8EA70-BC4D-474C-9DA8-EE8396B79004}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{A9533CF2-7EF8-4006-98DF-61B78FC72BB9}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed Brotherhood\ACBSP.exe
FirewallRules: [{4AFB2756-281E-4A9A-A3C6-53D342CF7A16}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed Brotherhood\ACBSP.exe
FirewallRules: [{76D59E5A-6E43-45A2-B669-3B919DDD1FC8}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed Brotherhood\ACBMP.exe
FirewallRules: [{95B40537-652A-499E-BF36-399CC42F1F18}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed Brotherhood\ACBMP.exe
FirewallRules: [{51DBCD8D-0C8C-4D10-9FD6-02696DF5D62D}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed Brotherhood\AssassinsCreedBrotherhood.exe
FirewallRules: [{7F7A6765-8917-4C85-94E9-15C5ED0AC193}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed Brotherhood\AssassinsCreedBrotherhood.exe
FirewallRules: [{675CE0A6-34E9-43E9-897F-9CAC3D640482}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed Brotherhood\UPlayBrowser.exe
FirewallRules: [{937626A0-11FF-429F-A9FC-BE0449EA7311}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed Brotherhood\UPlayBrowser.exe
FirewallRules: [{9F3178B2-628B-47DE-901D-384D3F1752F1}] => (Allow) C:\Program Files (x86)\ICQ7M\ICQ.exe
FirewallRules: [{BC603AB3-723A-4981-BAD6-E89F7F3F1257}] => (Allow) C:\Program Files (x86)\ICQ7M\ICQ.exe
FirewallRules: [{83F96732-6E30-41DD-8C85-B1C0EA2A9626}] => (Allow) C:\Program Files (x86)\ICQ7M\ICQ.exe
FirewallRules: [{DC9157F3-5E08-407A-B8BE-AF11AB387D92}] => (Allow) C:\Program Files (x86)\ICQ7M\ICQ.exe
FirewallRules: [{9E392439-E6D9-4B41-BE4C-FD957EDE646A}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{3B8DDE69-F278-4CB1-AB1A-59A0BE8A7EC8}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{36F82312-8C7E-4036-9EEE-F65ACE783453}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{B09226B6-3EA2-4F13-AB8A-AB9A83797D84}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [TCP Query User{F9B7D28E-70BA-42E6-BF65-1D423BF8C194}C:\program files (x86)\mozilla firefox\plugin-container.exe] => (Allow) C:\program files (x86)\mozilla firefox\plugin-container.exe
FirewallRules: [UDP Query User{7B36B7EC-6440-420A-835F-0C1D31DF5C37}C:\program files (x86)\mozilla firefox\plugin-container.exe] => (Allow) C:\program files (x86)\mozilla firefox\plugin-container.exe
FirewallRules: [{49506D05-466D-4DCE-ABD8-D8A8591176C9}] => (Allow) LPort=9091
FirewallRules: [{A2CDC8CB-05FA-4132-84E4-EF01789FB623}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{1BE8EE6C-F80F-4175-B421-F76B4CA2D582}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{FDBB8AA6-96AD-4452-8BF7-282C5BEA864E}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{DF2B1D65-4293-40D5-956F-CF967AD51ED0}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{A22693E0-1197-4984-8814-7FBB07F48B75}] => (Allow) C:\Program Files (x86)\Ubisoft\Techland\Call of Juarez - Bound in Blood\CoJBiBGame_x86.exe
FirewallRules: [{383251CB-65EA-4DA2-B65F-73505FCA9BC8}] => (Allow) C:\Program Files (x86)\Ubisoft\Techland\Call of Juarez - Bound in Blood\CoJBiBGame_x86.exe
FirewallRules: [{5317532F-19A8-4925-8ECE-B063534407F5}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{C065C741-A9AD-4687-8234-A891C2E514D5}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [TCP Query User{4F275540-4C86-4946-8083-B6A73F2C5D1A}C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe
FirewallRules: [UDP Query User{967B0178-3D26-4CD7-9E98-3D3434C07B50}C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe
FirewallRules: [{6FC018B0-6333-4062-A0D6-B6A36FC53FC7}] => (Allow) LPort=9091
FirewallRules: [{2CB75DB2-1193-4FB8-BD71-DDE8E42307AA}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
FirewallRules: [{3354B97F-488A-493C-BA0A-2D7E105F0DDB}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
FirewallRules: [{CB21AC0C-18AD-4D23-A8B9-84708C2E6877}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe
FirewallRules: [{258A72F8-68C0-40C9-A22B-9F4EEE13FF25}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe
FirewallRules: [{29EA81F8-4777-41F0-9577-E318F71DC6CC}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcopy2.exe
FirewallRules: [{A3AA2648-30CE-449D-B17A-9F25BAA0BCF1}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe
FirewallRules: [{1B8C1CC1-B17D-4EDD-867A-D02544835C14}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe
FirewallRules: [{DFAE16F5-3FA2-4A75-93B3-3CAA263A3BE6}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe
FirewallRules: [{4C872100-D12B-42F1-8BB7-2C67B01BA2D0}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe
FirewallRules: [{1B0A6AB7-35C2-42BE-B00A-06B303BF0BD7}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
FirewallRules: [{66DADE87-7E55-48CE-8069-8D9003972BFD}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe
FirewallRules: [{6DC13435-2488-419E-950A-5D38313E9842}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe
FirewallRules: [{D50A170B-DEF9-4DB7-BFA5-0EFF26378381}] => (Allow) C:\Program Files (x86)\HP\digital imaging\smart web printing\smartwebprintexe.exe
FirewallRules: [{A7CB0C0C-5CE1-482E-BDE9-9D28FA093E45}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{87080D7D-F192-4AD6-8F82-8FE00C323721}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{184D59AE-C19A-4FF6-90F3-A691F97D203D}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{46258EB1-9ADD-48E7-AD0E-1F72BA6B8C21}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{F350B505-F65E-465B-A9BE-B07B855A4AF3}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{85524F2C-53A7-411A-9770-41253C633132}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{B78E414E-1505-498A-A1BA-6B3A403EFC85}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{64C9339E-F92D-46FC-87D9-EB5E12A528FA}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{BCCF6FE4-D778-47E1-8107-4E858E5308E6}] => (Allow) C:\Users\Tepan\AppData\Local\Google\Chrome\Application\chrome.exe
FirewallRules: [{3FDCDAC9-91AD-43F4-BF7C-1D6BCB332710}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{39FF30CA-1AED-4D62-918D-9BD738F8BE4F}] => (Allow) LPort=2869
FirewallRules: [{05DDA838-2DA4-4CBA-8140-13259F447BFB}] => (Allow) LPort=1900
FirewallRules: [{85E24832-40B4-45B3-B2CB-89B78BB90D24}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{CFF1FE4B-FF75-4B56-854A-A82EFB6F74FF}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [TCP Query User{F91C1020-45B1-41AA-A63C-18667CEBD935}C:\users\tepan\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\tepan\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [UDP Query User{ED682182-DBBC-419A-A2B7-B40D79523F87}C:\users\tepan\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\tepan\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [TCP Query User{A47BF579-C8E8-43FF-91DD-A1D59DE4DB6A}C:\program files\ubisoft\tom clancy's rainbow six vegas 2\binaries\r6vegas2_game.exe] => (Allow) C:\program files\ubisoft\tom clancy's rainbow six vegas 2\binaries\r6vegas2_game.exe
FirewallRules: [UDP Query User{9814E84E-8F75-467A-8596-FB377DB51674}C:\program files\ubisoft\tom clancy's rainbow six vegas 2\binaries\r6vegas2_game.exe] => (Allow) C:\program files\ubisoft\tom clancy's rainbow six vegas 2\binaries\r6vegas2_game.exe
FirewallRules: [{B4407EF5-0701-49B8-8711-2ADBC35D93DD}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{7A1DEB47-4C25-4367-9221-95A353F26DAD}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [TCP Query User{1055FEE0-3CA4-41CE-BE68-41C5D31C765F}D:\instalovane hry\grand theft auto v\gta5.exe] => (Allow) D:\instalovane hry\grand theft auto v\gta5.exe
FirewallRules: [UDP Query User{FF66E418-FFCF-46BD-80CC-CB27DB5B7AA3}D:\instalovane hry\grand theft auto v\gta5.exe] => (Allow) D:\instalovane hry\grand theft auto v\gta5.exe
FirewallRules: [{96749CEE-7138-4504-973E-7EBABDA0A5C0}] => (Allow) C:\Users\Tepan\AppData\Roaming\uTorrent\utorrent.exe
FirewallRules: [{3F482726-4C2C-4BB2-B84A-A5FBAE212671}] => (Allow) C:\Users\Tepan\AppData\Roaming\uTorrent\utorrent.exe

==================== Faulty Device Manager Devices =============

Name: Adaptér tunelového režimu Microsoft Teredo
Description: Adaptér tunelového režimu Microsoft Teredo
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (09/20/2015 08:56:00 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: Communicator.exe, verze: 0.0.0.0, časové razítko: 0x5303dd50
Název chybujícího modulu: Communicator.exe, verze: 0.0.0.0, časové razítko: 0x5303dd50
Kód výjimky: 0xc0000005
Posun chyby: 0x0000ee4d
ID chybujícího procesu: 0x1460
Čas spuštění chybující aplikace: 0xCommunicator.exe0
Cesta k chybující aplikaci: Communicator.exe1
Cesta k chybujícímu modulu: Communicator.exe2
ID zprávy: Communicator.exe3

Error: (09/20/2015 08:53:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: Communicator.exe, verze: 0.0.0.0, časové razítko: 0x5303dd50
Název chybujícího modulu: Communicator.exe, verze: 0.0.0.0, časové razítko: 0x5303dd50
Kód výjimky: 0xc0000005
Posun chyby: 0x0000ee4d
ID chybujícího procesu: 0x66c
Čas spuštění chybující aplikace: 0xCommunicator.exe0
Cesta k chybující aplikaci: Communicator.exe1
Cesta k chybujícímu modulu: Communicator.exe2
ID zprávy: Communicator.exe3

Error: (09/20/2015 06:57:40 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: Communicator.exe, verze: 0.0.0.0, časové razítko: 0x5303dd50
Název chybujícího modulu: Communicator.exe, verze: 0.0.0.0, časové razítko: 0x5303dd50
Kód výjimky: 0xc0000005
Posun chyby: 0x0000ee4d
ID chybujícího procesu: 0x414
Čas spuštění chybující aplikace: 0xCommunicator.exe0
Cesta k chybující aplikaci: Communicator.exe1
Cesta k chybujícímu modulu: Communicator.exe2
ID zprávy: Communicator.exe3

Error: (09/20/2015 04:56:00 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: Communicator.exe, verze: 0.0.0.0, časové razítko: 0x5303dd50
Název chybujícího modulu: Communicator.exe, verze: 0.0.0.0, časové razítko: 0x5303dd50
Kód výjimky: 0xc0000005
Posun chyby: 0x0000ee4d
ID chybujícího procesu: 0x7f4
Čas spuštění chybující aplikace: 0xCommunicator.exe0
Cesta k chybující aplikaci: Communicator.exe1
Cesta k chybujícímu modulu: Communicator.exe2
ID zprávy: Communicator.exe3

Error: (09/20/2015 03:56:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: Communicator.exe, verze: 0.0.0.0, časové razítko: 0x5303dd50
Název chybujícího modulu: Communicator.exe, verze: 0.0.0.0, časové razítko: 0x5303dd50
Kód výjimky: 0xc0000005
Posun chyby: 0x0000ee4d
ID chybujícího procesu: 0x13d0
Čas spuštění chybující aplikace: 0xCommunicator.exe0
Cesta k chybující aplikaci: Communicator.exe1
Cesta k chybujícímu modulu: Communicator.exe2
ID zprávy: Communicator.exe3

Error: (09/20/2015 02:56:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: Communicator.exe, verze: 0.0.0.0, časové razítko: 0x5303dd50
Název chybujícího modulu: Communicator.exe, verze: 0.0.0.0, časové razítko: 0x5303dd50
Kód výjimky: 0xc0000005
Posun chyby: 0x0000ee4d
ID chybujícího procesu: 0xd1c
Čas spuštění chybující aplikace: 0xCommunicator.exe0
Cesta k chybující aplikaci: Communicator.exe1
Cesta k chybujícímu modulu: Communicator.exe2
ID zprávy: Communicator.exe3

Error: (09/20/2015 01:56:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: Communicator.exe, verze: 0.0.0.0, časové razítko: 0x5303dd50
Název chybujícího modulu: Communicator.exe, verze: 0.0.0.0, časové razítko: 0x5303dd50
Kód výjimky: 0xc0000005
Posun chyby: 0x0000ee4d
ID chybujícího procesu: 0x1314
Čas spuštění chybující aplikace: 0xCommunicator.exe0
Cesta k chybující aplikaci: Communicator.exe1
Cesta k chybujícímu modulu: Communicator.exe2
ID zprávy: Communicator.exe3

Error: (09/20/2015 12:56:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: Communicator.exe, verze: 0.0.0.0, časové razítko: 0x5303dd50
Název chybujícího modulu: Communicator.exe, verze: 0.0.0.0, časové razítko: 0x5303dd50
Kód výjimky: 0xc0000005
Posun chyby: 0x0000ee4d
ID chybujícího procesu: 0x1248
Čas spuštění chybující aplikace: 0xCommunicator.exe0
Cesta k chybující aplikaci: Communicator.exe1
Cesta k chybujícímu modulu: Communicator.exe2
ID zprávy: Communicator.exe3

Error: (09/20/2015 11:56:02 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: Communicator.exe, verze: 0.0.0.0, časové razítko: 0x5303dd50
Název chybujícího modulu: Communicator.exe, verze: 0.0.0.0, časové razítko: 0x5303dd50
Kód výjimky: 0xc0000005
Posun chyby: 0x0000ee4d
ID chybujícího procesu: 0x10ec
Čas spuštění chybující aplikace: 0xCommunicator.exe0
Cesta k chybující aplikaci: Communicator.exe1
Cesta k chybujícímu modulu: Communicator.exe2
ID zprávy: Communicator.exe3

Error: (09/20/2015 11:47:26 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Generování kontextu aktivace pro C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest1 se nezdařilo. Chyba v souboru manifestu nebo zásad C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest2 na řádku C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest3.
Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní.
Konfliktní součásti:
Součást 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Součást 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.


System errors:
=============
Error: (09/20/2015 11:47:55 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba eapihdrv neuspěla při spuštění v důsledku následující chyby:
%%1275

Error: (09/20/2015 11:47:55 AM) (Source: Application Popup) (EventID: 1060) (User: )
Description: Načtení \??\C:\Users\Tepan\AppData\Local\Temp\ehdrv.sys bylo zablokováno kvůli nekompatibilitě s tímto systémem. Požádejte dodavatele softwaru
o kompatibilní verzi ovladače.

Error: (09/20/2015 11:47:54 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba eapihdrv neuspěla při spuštění v důsledku následující chyby:
%%1275

Error: (09/20/2015 11:47:54 AM) (Source: Application Popup) (EventID: 1060) (User: )
Description: Načtení \??\C:\Users\Tepan\AppData\Local\Temp\ehdrv.sys bylo zablokováno kvůli nekompatibilitě s tímto systémem. Požádejte dodavatele softwaru
o kompatibilní verzi ovladače.

Error: (09/20/2015 11:47:54 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba eapihdrv neuspěla při spuštění v důsledku následující chyby:
%%1275

Error: (09/20/2015 11:47:54 AM) (Source: Application Popup) (EventID: 1060) (User: )
Description: Načtení \??\C:\Users\Tepan\AppData\Local\Temp\ehdrv.sys bylo zablokováno kvůli nekompatibilitě s tímto systémem. Požádejte dodavatele softwaru
o kompatibilní verzi ovladače.

Error: (09/20/2015 11:47:53 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba eapihdrv neuspěla při spuštění v důsledku následující chyby:
%%1275

Error: (09/20/2015 11:47:53 AM) (Source: Application Popup) (EventID: 1060) (User: )
Description: Načtení \??\C:\Users\Tepan\AppData\Local\Temp\ehdrv.sys bylo zablokováno kvůli nekompatibilitě s tímto systémem. Požádejte dodavatele softwaru
o kompatibilní verzi ovladače.

Error: (09/20/2015 11:47:53 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba eapihdrv neuspěla při spuštění v důsledku následující chyby:
%%1275

Error: (09/20/2015 11:47:53 AM) (Source: Application Popup) (EventID: 1060) (User: )
Description: Načtení \??\C:\Users\Tepan\AppData\Local\Temp\ehdrv.sys bylo zablokováno kvůli nekompatibilitě s tímto systémem. Požádejte dodavatele softwaru
o kompatibilní verzi ovladače.


CodeIntegrity:
===================================
Date: 2015-01-09 21:59:11.287
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\Tepan\AppData\Local\Temp\EverestDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2015-01-09 21:59:11.052
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Users\Tepan\AppData\Local\Temp\EverestDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2015-01-09 21:59:10.319
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64 because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2015-01-09 21:59:10.085
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64 because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2015-01-08 22:48:17.564
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2015-01-08 22:48:17.346
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2015-01-08 22:48:17.081
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2015-01-08 22:48:16.831
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2015-01-08 17:10:05.023
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2015-01-08 17:10:04.571
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info ===========================

Processor: Pentium(R) Dual-Core CPU E5300 @ 2.60GHz
Percentage of memory in use: 38%
Total physical RAM: 4095.24 MB
Available physical RAM: 2501.82 MB
Total Virtual: 8188.69 MB
Available Virtual: 6393.12 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:170.9 GB) (Free:6.3 GB) NTFS
Drive d: () (Fixed) (Total:127 GB) (Free:1.44 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 0F29FC2D)
Partition 1: (Active) - (Size=200 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=170.9 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=127 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

altrok
Moderátor
Moderátor
Příspěvky: 7322
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: preventivní kontrola logu---zpomalení počítače

#13 Příspěvek od altrok »

  • Do Poznamkoveho bloku (Start -> spustit -> notepad) zkopirujte obsah bileho pole
  • ulozte na plochu jako fixlist (Typ souboru: Textovy dokument)
  • znovu spustte FRST a kliknete na Fix
  • po restartu bude na plose ulozen fixlog, jehoz obsah mi vlozte do pristi odpovedi

    Kód: Vybrat vše

    Start
    CloseProcesses:
    File: C:\Windows\system32\Drivers\204D3F81.sys
    File: C:\Windows\system32\Drivers\12881974.sys
    Folder: C:\Users\Tepan\AppData\Roaming\CasinoOnNet
    Folder: c:\programdata\{bac6e063-c6ce-6047-bac6-6e063c6c818f}
    c:\programdata\{bac6e063-c6ce-6047-bac6-6e063c6c818f}
    HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [998104 2015-07-07] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
    HKU\S-1-5-21-1029120089-3632672932-3177029402-1001\...\Run: [Google Update] => C:\Users\Tepan\AppData\Local\Google\Update\GoogleUpdate.exe [107848 2015-06-20] (Google Inc.)
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = 
    SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    FF SelectedSearchEngine: Поиск@Mail.Ru
    FF Keyword.URL: hxxp://go.mail.ru/search?fr=ntg&q=
    CHR DefaultSearchURL: Default -> hxxp://go.mail.ru/search?q={searchTerms}&fr=xtn9
    CHR DefaultSearchKeyword: Default -> mail.ru
    CHR DefaultSuggestURL: Default -> hxxp://suggests.go.mail.ru/chrome?q={searchTerms}
    S2 Prime95 Service; C:\Program Files (x86)\Prime95\prime95.exe [X]
    S3 catchme; \??\C:\ComboFix\catchme.sys [X]
    2015-09-20 20:55 - 2015-09-20 20:56 - 00017689 _____ C:\Users\Tepan\Desktop\FRST.txt
    2015-09-20 10:34 - 2015-09-20 10:34 - 02870984 _____ (ESET) C:\Users\Tepan\Desktop\esetsmartinstaller_csy.exe
    2015-09-18 10:31 - 2015-09-18 10:31 - 00112640 _____ (forum.viry.cz) C:\Users\Tepan\Desktop\FRSTLauncher.exe
    Task: {040684E2-746B-4AC4-9B31-F3FA271305A8} - System32\Tasks\{A5924B5D-8DB4-4C60-BCB5-A5EADE420759} => pcalua.exe -a H:\SETUP.EXE -d H:\
    Task: {6ECDFA05-FB6D-496D-B6D5-A89FFB99765A} - System32\Tasks\{66698E77-C66E-40C4-8C7C-3A397B7787CB} => pcalua.exe -a H:\SETUP.EXE -d H:\
    Task: {AEA0DEA5-F29F-4B4B-ACB4-B97BD347AD40} - System32\Tasks\{FF156A7F-B168-47A5-9FFC-2ACD88E0EF68} => pcalua.exe -a D:\Programy\Torrenty\uTorrent\lista_centrum.exe -d d:\Programy\Torrenty\uTorrent
    Task: C:\Windows\Tasks\Adobe Acrobat Update Task.job => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    Task: C:\Windows\Tasks\DriverDocRunAtStartup.job => C:\Program Files (x86)\DriverDoc\Solvusoftdd.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1029120089-3632672932-3177029402-1001Core.job => C:\Users\Tepan\AppData\Local\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1029120089-3632672932-3177029402-1001UA.job => C:\Users\Tepan\AppData\Local\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\SmartRecharge.job => c:\programdata\{bac6e063-c6ce-6047-bac6-6e063c6c818f}\malwarebytes anti-malware premium 2.1.8 keygen is here ! [latest].exe <==== ATTENTION
    C:\Users\Tepan\Desktop\Ochrana pocitace\dffsetup.exe
    Hosts:
    EmptyTemp:
    End
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Odpovědět