
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosím o kontrolu PC
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Prosím o kontrolu PC
Dobrý den,
chtěla bych moc poprosit o preventivní kontrolu PC. Zdá se mi v poslední době pomalejší. Děkuji.
Vkládám log z RSIT:
Logfile of random's system information tool 1.10 (written by random/random)
Run by PC at 2015-10-09 15:49:43
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 157 GB (63%) free of 250 GB
Total RAM: 2047 MB (41% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:50:26, on 9.10.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18015)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\conhost32.exe
C:\Windows\system32\GWX\GWX.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Users\PC\AppData\Roaming\Microsoft\Networking\inet32upd.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\PC\Desktop\RSIT.exe
C:\Program Files\trend micro\PC.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll
O4 - HKLM\..\Run: [NvBackend] "C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe"
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O4 - Startup: conhost32.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{05A3DBCD-7CEE-4242-9D0A-C98322BA72DB}: NameServer = 84.16.121.1,84.16.120.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{05A3DBCD-7CEE-4242-9D0A-C98322BA72DB}: NameServer = 84.16.121.1,84.16.120.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{05A3DBCD-7CEE-4242-9D0A-C98322BA72DB}: NameServer = 84.16.121.1,84.16.120.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
--
End of file - 5511 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\DriverToolkit Autorun.job - C:\Program Files\DriverToolkit\DriverToolkit.exe --autorun
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\Norton Security Scan for PC.job - C:\PROGRA~1\NORTON~2\Engine\410~1.28\Nss.exe /scan-quick /scheduled
=========Mozilla firefox=========
ProfilePath - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\avfgrdd1.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe� Flash� Player 19.0.0.185 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_19_0_0_185.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\system32\Adobe\Director\np32dsw_1213153.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.31.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.31.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeExManDetect]
"Description"=
"Path"=C:\Program Files\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll
C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\avfgrdd1.default\searchplugins\
firmycz.xml
zbocz.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-01-22 460712]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01 1724032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-22 172968]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvBackend"=C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2014-03-20 1797064]
"HDAudDeck"=C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe [2009-12-04 1728512]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-09-23 926896]
"LogMeIn Hamachi Ui"=C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2015-08-03 5579624]
"AdobeAAMUpdater-1.0"=C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2015-08-05 508240]
"AdobeCS6ServiceManager"=C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2013-04-25 1075296]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2015-07-08 5089480]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"AdobeBridge"= []
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2015-08-07 53729824]
C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
conhost32.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SMPCHelper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\tvnserver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.FPS1"=frapsvid.dll
"vidc.mjpg"=bdmjpeg.dll
"vidc.mpeg"=bdmpegv.dll
"msacm.bdmpeg"=bdmpega.acm
"vidc.tscc"=C:\Windows\system32\tsccvid.dll
"vidc.tsc2"=C:\Windows\system32\tsc2_codec32.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-10-09 15:44:23 ----D---- C:\Program Files\trend micro
2015-10-09 15:44:22 ----D---- C:\rsit
2015-10-09 11:46:06 ----D---- C:\Program Files\CCleaner
2015-10-09 11:32:35 ----SHD---- C:\Config.Msi
2015-10-09 11:22:51 ----A---- C:\Windows\system32\drivers\rtl8187B.sys
2015-10-09 11:22:50 ----D---- C:\Windows\OPTIONS
2015-10-09 11:22:42 ----D---- C:\Program Files\Belkin
2015-10-09 11:22:42 ----A---- C:\Windows\system32\ISSRemoveSP.exe
2015-10-09 10:50:05 ----D---- C:\Users\PC\AppData\Roaming\InstallShield
2015-10-02 21:33:42 ----D---- C:\Program Files\Mozilla Firefox
2015-09-17 11:34:09 ----D---- C:\Program Files\Common Files\Skype
2015-09-10 12:16:53 ----D---- C:\ProgramData\ESET
======List of files/folders modified in the last 1 month======
2015-10-09 15:49:44 ----D---- C:\Windows\Temp
2015-10-09 15:44:23 ----RD---- C:\Program Files
2015-10-09 11:50:25 ----D---- C:\Users\PC\AppData\Roaming\TS3Client
2015-10-09 11:50:15 ----D---- C:\Windows\Panther
2015-10-09 11:50:15 ----D---- C:\Windows\inf
2015-10-09 11:50:14 ----D---- C:\Windows\Logs
2015-10-09 11:50:14 ----D---- C:\Windows\debug
2015-10-09 11:50:14 ----D---- C:\Windows
2015-10-09 11:46:10 ----D---- C:\Windows\system32\Tasks
2015-10-09 11:42:07 ----D---- C:\Windows\system32\config
2015-10-09 11:40:41 ----SHD---- C:\Windows\Installer
2015-10-09 11:40:39 ----HD---- C:\ProgramData
2015-10-09 11:39:21 ----D---- C:\Program Files\Euro Truck Simulator 2
2015-10-09 11:37:11 ----D---- C:\ProgramData\Microsoft Help
2015-10-09 11:37:09 ----RSD---- C:\Windows\assembly
2015-10-09 11:37:02 ----SD---- C:\ProgramData\Microsoft
2015-10-09 11:37:01 ----D---- C:\Program Files\Microsoft Office
2015-10-09 11:36:59 ----D---- C:\Windows\ShellNew
2015-10-09 11:35:36 ----D---- C:\Program Files\Common Files\microsoft shared
2015-10-09 11:35:35 ----D---- C:\Program Files\MSBuild
2015-10-09 11:35:04 ----RSD---- C:\Windows\Fonts
2015-10-09 11:32:28 ----D---- C:\Program Files\Common Files\System
2015-10-09 11:32:24 ----A---- C:\Windows\win.ini
2015-10-09 11:29:40 ----D---- C:\Users\PC\AppData\Roaming\Skype
2015-10-09 11:27:52 ----D---- C:\Windows\system32\NDF
2015-10-09 11:23:40 ----D---- C:\Windows\system32\catroot
2015-10-09 11:22:54 ----D---- C:\Windows\system32\DriverStore
2015-10-09 11:22:51 ----D---- C:\Windows\system32\drivers
2015-10-09 11:22:50 ----D---- C:\Windows\system
2015-10-09 11:22:42 ----D---- C:\Windows\System32
2015-10-09 11:22:40 ----HD---- C:\Program Files\InstallShield Installation Information
2015-10-09 11:22:36 ----SHD---- C:\System Volume Information
2015-10-09 11:19:09 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-10-09 11:11:48 ----D---- C:\ProgramData\NVIDIA
2015-10-09 11:10:53 ----D---- C:\Windows\Tasks
2015-10-09 09:50:20 ----SD---- C:\Windows\system32\GWX
2015-10-08 21:41:10 ----D---- C:\Windows\winsxs
2015-10-07 21:54:55 ----D---- C:\Users\PC\AppData\Roaming\vlc
2015-10-05 09:52:32 ----D---- C:\Windows\system32\catroot2
2015-10-03 19:16:58 ----D---- C:\Program Files\Mozilla Maintenance Service
2015-09-25 13:16:31 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2015-09-18 22:18:07 ----D---- C:\Users\PC\AppData\Roaming\dvdcss
2015-09-17 11:34:22 ----D---- C:\ProgramData\Skype
2015-09-17 11:34:10 ----RD---- C:\Program Files\Skype
2015-09-17 11:34:09 ----D---- C:\Program Files\Common Files
2015-09-13 11:25:37 ----D---- C:\Windows\Microsoft.NET
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2015-07-14 60552]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2015-07-14 202704]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [2014-09-20 378672]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2015-07-14 144536]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2015-07-14 46656]
R1 VWiFiFlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2015-07-14 185176]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2015-01-14 26176]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda32v.sys [2014-03-20 162592]
R3 NVNET;NVIDIA nForce 10/100 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmf6232.sys [2010-08-12 298216]
R3 RTL8187B;Belkin Wireless G USB Network Adapter; C:\Windows\system32\DRIVERS\rtl8187B.sys [2009-08-12 376320]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2009-11-25 1108480]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 14336]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 HPFXBULK;HPFXBULK; C:\Windows\system32\drivers\hpfxbulk.sys [2007-07-16 17432]
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x32.sys [2009-07-14 347264]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 14848]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-10-02 49152]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 36352]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-09-23 65192]
R2 AGSService;Adobe Genuine Software Integrity Service; C:\Program Files\Common Files\Adobe\AdobeGCClient\AGSService.exe [2015-09-29 2015936]
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2015-05-01 1394816]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2015-05-01 1772672]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2015-07-08 1353720]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2015-08-03 1883496]
R2 LMIGuardianSvc;LMIGuardianSvc; C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe [2015-08-03 411920]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2014-03-04 663896]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-03-04 411936]
R3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-28 144200]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2015-07-09 327296]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-09-25 269000]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-28 144200]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-08-15 102912]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2015-10-02 147624]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-05-12 1343400]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2013-09-11 46688]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
-----------------EOF-----------------
chtěla bych moc poprosit o preventivní kontrolu PC. Zdá se mi v poslední době pomalejší. Děkuji.
Vkládám log z RSIT:
Logfile of random's system information tool 1.10 (written by random/random)
Run by PC at 2015-10-09 15:49:43
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 157 GB (63%) free of 250 GB
Total RAM: 2047 MB (41% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:50:26, on 9.10.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18015)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\conhost32.exe
C:\Windows\system32\GWX\GWX.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Users\PC\AppData\Roaming\Microsoft\Networking\inet32upd.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\PC\Desktop\RSIT.exe
C:\Program Files\trend micro\PC.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll
O4 - HKLM\..\Run: [NvBackend] "C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe"
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O4 - Startup: conhost32.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{05A3DBCD-7CEE-4242-9D0A-C98322BA72DB}: NameServer = 84.16.121.1,84.16.120.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{05A3DBCD-7CEE-4242-9D0A-C98322BA72DB}: NameServer = 84.16.121.1,84.16.120.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{05A3DBCD-7CEE-4242-9D0A-C98322BA72DB}: NameServer = 84.16.121.1,84.16.120.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
--
End of file - 5511 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\DriverToolkit Autorun.job - C:\Program Files\DriverToolkit\DriverToolkit.exe --autorun
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\Norton Security Scan for PC.job - C:\PROGRA~1\NORTON~2\Engine\410~1.28\Nss.exe /scan-quick /scheduled
=========Mozilla firefox=========
ProfilePath - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\avfgrdd1.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe� Flash� Player 19.0.0.185 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_19_0_0_185.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\system32\Adobe\Director\np32dsw_1213153.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.31.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.31.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeExManDetect]
"Description"=
"Path"=C:\Program Files\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll
C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\avfgrdd1.default\searchplugins\
firmycz.xml
zbocz.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-01-22 460712]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01 1724032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-22 172968]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvBackend"=C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2014-03-20 1797064]
"HDAudDeck"=C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe [2009-12-04 1728512]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-09-23 926896]
"LogMeIn Hamachi Ui"=C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2015-08-03 5579624]
"AdobeAAMUpdater-1.0"=C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2015-08-05 508240]
"AdobeCS6ServiceManager"=C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2013-04-25 1075296]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2015-07-08 5089480]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"AdobeBridge"= []
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2015-08-07 53729824]
C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
conhost32.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SMPCHelper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\tvnserver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.FPS1"=frapsvid.dll
"vidc.mjpg"=bdmjpeg.dll
"vidc.mpeg"=bdmpegv.dll
"msacm.bdmpeg"=bdmpega.acm
"vidc.tscc"=C:\Windows\system32\tsccvid.dll
"vidc.tsc2"=C:\Windows\system32\tsc2_codec32.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-10-09 15:44:23 ----D---- C:\Program Files\trend micro
2015-10-09 15:44:22 ----D---- C:\rsit
2015-10-09 11:46:06 ----D---- C:\Program Files\CCleaner
2015-10-09 11:32:35 ----SHD---- C:\Config.Msi
2015-10-09 11:22:51 ----A---- C:\Windows\system32\drivers\rtl8187B.sys
2015-10-09 11:22:50 ----D---- C:\Windows\OPTIONS
2015-10-09 11:22:42 ----D---- C:\Program Files\Belkin
2015-10-09 11:22:42 ----A---- C:\Windows\system32\ISSRemoveSP.exe
2015-10-09 10:50:05 ----D---- C:\Users\PC\AppData\Roaming\InstallShield
2015-10-02 21:33:42 ----D---- C:\Program Files\Mozilla Firefox
2015-09-17 11:34:09 ----D---- C:\Program Files\Common Files\Skype
2015-09-10 12:16:53 ----D---- C:\ProgramData\ESET
======List of files/folders modified in the last 1 month======
2015-10-09 15:49:44 ----D---- C:\Windows\Temp
2015-10-09 15:44:23 ----RD---- C:\Program Files
2015-10-09 11:50:25 ----D---- C:\Users\PC\AppData\Roaming\TS3Client
2015-10-09 11:50:15 ----D---- C:\Windows\Panther
2015-10-09 11:50:15 ----D---- C:\Windows\inf
2015-10-09 11:50:14 ----D---- C:\Windows\Logs
2015-10-09 11:50:14 ----D---- C:\Windows\debug
2015-10-09 11:50:14 ----D---- C:\Windows
2015-10-09 11:46:10 ----D---- C:\Windows\system32\Tasks
2015-10-09 11:42:07 ----D---- C:\Windows\system32\config
2015-10-09 11:40:41 ----SHD---- C:\Windows\Installer
2015-10-09 11:40:39 ----HD---- C:\ProgramData
2015-10-09 11:39:21 ----D---- C:\Program Files\Euro Truck Simulator 2
2015-10-09 11:37:11 ----D---- C:\ProgramData\Microsoft Help
2015-10-09 11:37:09 ----RSD---- C:\Windows\assembly
2015-10-09 11:37:02 ----SD---- C:\ProgramData\Microsoft
2015-10-09 11:37:01 ----D---- C:\Program Files\Microsoft Office
2015-10-09 11:36:59 ----D---- C:\Windows\ShellNew
2015-10-09 11:35:36 ----D---- C:\Program Files\Common Files\microsoft shared
2015-10-09 11:35:35 ----D---- C:\Program Files\MSBuild
2015-10-09 11:35:04 ----RSD---- C:\Windows\Fonts
2015-10-09 11:32:28 ----D---- C:\Program Files\Common Files\System
2015-10-09 11:32:24 ----A---- C:\Windows\win.ini
2015-10-09 11:29:40 ----D---- C:\Users\PC\AppData\Roaming\Skype
2015-10-09 11:27:52 ----D---- C:\Windows\system32\NDF
2015-10-09 11:23:40 ----D---- C:\Windows\system32\catroot
2015-10-09 11:22:54 ----D---- C:\Windows\system32\DriverStore
2015-10-09 11:22:51 ----D---- C:\Windows\system32\drivers
2015-10-09 11:22:50 ----D---- C:\Windows\system
2015-10-09 11:22:42 ----D---- C:\Windows\System32
2015-10-09 11:22:40 ----HD---- C:\Program Files\InstallShield Installation Information
2015-10-09 11:22:36 ----SHD---- C:\System Volume Information
2015-10-09 11:19:09 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-10-09 11:11:48 ----D---- C:\ProgramData\NVIDIA
2015-10-09 11:10:53 ----D---- C:\Windows\Tasks
2015-10-09 09:50:20 ----SD---- C:\Windows\system32\GWX
2015-10-08 21:41:10 ----D---- C:\Windows\winsxs
2015-10-07 21:54:55 ----D---- C:\Users\PC\AppData\Roaming\vlc
2015-10-05 09:52:32 ----D---- C:\Windows\system32\catroot2
2015-10-03 19:16:58 ----D---- C:\Program Files\Mozilla Maintenance Service
2015-09-25 13:16:31 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2015-09-18 22:18:07 ----D---- C:\Users\PC\AppData\Roaming\dvdcss
2015-09-17 11:34:22 ----D---- C:\ProgramData\Skype
2015-09-17 11:34:10 ----RD---- C:\Program Files\Skype
2015-09-17 11:34:09 ----D---- C:\Program Files\Common Files
2015-09-13 11:25:37 ----D---- C:\Windows\Microsoft.NET
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2015-07-14 60552]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2015-07-14 202704]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [2014-09-20 378672]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2015-07-14 144536]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2015-07-14 46656]
R1 VWiFiFlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2015-07-14 185176]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2015-01-14 26176]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda32v.sys [2014-03-20 162592]
R3 NVNET;NVIDIA nForce 10/100 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmf6232.sys [2010-08-12 298216]
R3 RTL8187B;Belkin Wireless G USB Network Adapter; C:\Windows\system32\DRIVERS\rtl8187B.sys [2009-08-12 376320]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2009-11-25 1108480]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 14336]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 HPFXBULK;HPFXBULK; C:\Windows\system32\drivers\hpfxbulk.sys [2007-07-16 17432]
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x32.sys [2009-07-14 347264]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 14848]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-10-02 49152]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 36352]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-09-23 65192]
R2 AGSService;Adobe Genuine Software Integrity Service; C:\Program Files\Common Files\Adobe\AdobeGCClient\AGSService.exe [2015-09-29 2015936]
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2015-05-01 1394816]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2015-05-01 1772672]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2015-07-08 1353720]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2015-08-03 1883496]
R2 LMIGuardianSvc;LMIGuardianSvc; C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe [2015-08-03 411920]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2014-03-04 663896]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-03-04 411936]
R3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-28 144200]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2015-07-09 327296]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-09-25 269000]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-28 144200]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-08-15 102912]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2015-10-02 147624]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-05-12 1343400]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2013-09-11 46688]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
-----------------EOF-----------------
Re: Prosím o kontrolu PC
Zdravím, v Knihovně Plánovače úloh zakaž :
Driver Toolkit
GoogleUpdate - bude to tam vícekrát
Norton Security Scan for PC
Smaž nepotřebné soubory
pomocí CCleaneru
návod :
Čistič - tady vyčistíš PC od nepotřebných souborů a vysypeš Koš
Registry - tady vyčistíš registry (před použitím doporučuji udělat jejich zálohu kterou CCleaner nabízí)
čištění registru je třeba několikrát zopakovat !
Nástroje - tady lze odinstalovat programy, upravit co se spustí po Startu systému a obnovit systém
Stáhni a ulož na plochu AdwCleaner,
ukonči všechny programy včetně prohlížeče a dvojklikem jej spusť,
objeví se okno kde vlevo nahoře klikni na Scan.
Po dokončení skenu klikni na Clean,
proběhne restart PC kdy dojde ke smazání nepořádku.
Po té mi sem zkopíruj Report.
Driver Toolkit
GoogleUpdate - bude to tam vícekrát
Norton Security Scan for PC
Smaž nepotřebné soubory
pomocí CCleaneru
návod :
Čistič - tady vyčistíš PC od nepotřebných souborů a vysypeš Koš
Registry - tady vyčistíš registry (před použitím doporučuji udělat jejich zálohu kterou CCleaner nabízí)
čištění registru je třeba několikrát zopakovat !
Nástroje - tady lze odinstalovat programy, upravit co se spustí po Startu systému a obnovit systém
Stáhni a ulož na plochu AdwCleaner,
ukonči všechny programy včetně prohlížeče a dvojklikem jej spusť,
objeví se okno kde vlevo nahoře klikni na Scan.
Po dokončení skenu klikni na Clean,
proběhne restart PC kdy dojde ke smazání nepořádku.
Po té mi sem zkopíruj Report.
Re: Prosím o kontrolu PC
Zde je log z AdwCleaner:
# AdwCleaner v5.013 - Logfile created 09/10/2015 at 19:04:43
# Updated 09/10/2015 by Xplode
# Database : 2015-10-09.3 [Server]
# Operating system : Windows 7 Ultimate Service Pack 1 (x86)
# Username : PC - PC-PC
# Running from : C:\Users\PC\Desktop\adwcleaner_5.013.exe
# Option : Cleaning
# Support : http://toolslib.net/forum
***** [ Services ] *****
***** [ Folders ] *****
[-] Folder Deleted : C:\Program Files\ShowMyPCService
[-] Folder Deleted : C:\ProgramData\apn
[-] Folder Deleted : C:\Users\PC\AppData\Local\DriverToolkit
[-] Folder Deleted : C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafaimnnclfjfedmmabolbppcngeolgf
***** [ Files ] *****
[-] File Deleted : C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nafaimnnclfjfedmmabolbppcngeolgf_0.localstorage
***** [ DLLs ] *****
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
***** [ Registry ] *****
[-] Key Deleted : HKU\.DEFAULT\Software\AskPartnerNetwork
[-] Key Deleted : HKCU\Software\DriverToolkit
***** [ Web browsers ] *****
[-] [C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : bopakagnckmlgajfccecajhnimjiiedh
[-] [C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : nafaimnnclfjfedmmabolbppcngeolgf
*************************
:: Winsock settings cleared
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [1463 bytes] ##########
# AdwCleaner v5.013 - Logfile created 09/10/2015 at 19:04:43
# Updated 09/10/2015 by Xplode
# Database : 2015-10-09.3 [Server]
# Operating system : Windows 7 Ultimate Service Pack 1 (x86)
# Username : PC - PC-PC
# Running from : C:\Users\PC\Desktop\adwcleaner_5.013.exe
# Option : Cleaning
# Support : http://toolslib.net/forum
***** [ Services ] *****
***** [ Folders ] *****
[-] Folder Deleted : C:\Program Files\ShowMyPCService
[-] Folder Deleted : C:\ProgramData\apn
[-] Folder Deleted : C:\Users\PC\AppData\Local\DriverToolkit
[-] Folder Deleted : C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafaimnnclfjfedmmabolbppcngeolgf
***** [ Files ] *****
[-] File Deleted : C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nafaimnnclfjfedmmabolbppcngeolgf_0.localstorage
***** [ DLLs ] *****
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
***** [ Registry ] *****
[-] Key Deleted : HKU\.DEFAULT\Software\AskPartnerNetwork
[-] Key Deleted : HKCU\Software\DriverToolkit
***** [ Web browsers ] *****
[-] [C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : bopakagnckmlgajfccecajhnimjiiedh
[-] [C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : nafaimnnclfjfedmmabolbppcngeolgf
*************************
:: Winsock settings cleared
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [1463 bytes] ##########
Re: Prosím o kontrolu PC
Stáhni a ulož na plochu ComboFix,
spusť aplikaci jako Administrátor a povol instalaci Konzole pro zotavení - Recovery Console.
Poté se zobrazí okno s licenčními podmínkami které potvrdíš kliknutím na ANO,
pak ještě jednou klik na ANO a už to jede.
Celá akce trvá okolo 10 minut ale může i déle, během skenu se nepokoušej spouštět nic jiného.
Při skenovaní může být PC i restartováno nelekat se.
Upozornění: po dobu skenu vypni rezidentní štít Antiviru a AntiSpy programu,
protože Combofix se pokouší napadené soubory smazat a tyto programy mu můžou bránit.
Po dokončení skenu nebo následném restartu aplikace vytvoří log, uložený na C:/Combofix.txt
(při opakovaném použití jsou logy číslovány Combofix2.txt atd.), jeho obsah zkopíruj sem.
V případě nejasností je ZDE obrázkový návod.
spusť aplikaci jako Administrátor a povol instalaci Konzole pro zotavení - Recovery Console.
Poté se zobrazí okno s licenčními podmínkami které potvrdíš kliknutím na ANO,
pak ještě jednou klik na ANO a už to jede.
Celá akce trvá okolo 10 minut ale může i déle, během skenu se nepokoušej spouštět nic jiného.
Při skenovaní může být PC i restartováno nelekat se.
Upozornění: po dobu skenu vypni rezidentní štít Antiviru a AntiSpy programu,
protože Combofix se pokouší napadené soubory smazat a tyto programy mu můžou bránit.
Po dokončení skenu nebo následném restartu aplikace vytvoří log, uložený na C:/Combofix.txt
(při opakovaném použití jsou logy číslovány Combofix2.txt atd.), jeho obsah zkopíruj sem.
V případě nejasností je ZDE obrázkový návod.
Re: Prosím o kontrolu PC
Log z Combofixu:
ComboFix 15-10-09.01 - PC 10.10.2015 17:15:46.1.1 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.2047.1303 [GMT 2:00]
Spuštěný z: c:\users\PC\Desktop\ComboFix.exe
AV: ESET Smart Security 8.0 *Disabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289}
FW: ESET Personální firewall *Enabled* {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
SP: ESET Smart Security 8.0 *Disabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\conhost32.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2015-09-10 do 2015-10-10 )))))))))))))))))))))))))))))))
.
.
2015-10-10 15:23 . 2015-10-10 15:23 -------- d-----w- c:\users\PC\AppData\Local\temp
2015-10-10 15:23 . 2015-10-10 15:23 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-10-10 14:51 . 2015-10-10 14:51 -------- d-----w- C:\found.000
2015-10-09 17:03 . 2015-10-09 17:04 -------- d-----w- C:\AdwCleaner
2015-10-09 15:11 . 2015-08-31 23:05 8884144 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E34909DF-B6E2-4C20-96D7-C4F61F135073}\mpengine.dll
2015-10-09 13:44 . 2015-10-09 13:49 -------- d-----w- c:\program files\trend micro
2015-10-09 13:44 . 2015-10-09 13:44 -------- d-----w- C:\rsit
2015-10-09 09:46 . 2015-10-09 09:46 -------- d-----w- c:\program files\CCleaner
2015-10-09 09:22 . 2009-08-12 15:37 376320 ----a-w- c:\windows\system32\drivers\rtl8187B.sys
2015-10-09 09:22 . 2015-10-09 09:22 -------- d-----w- c:\windows\OPTIONS
2015-10-09 09:22 . 2009-08-12 15:37 376320 ----a-w- c:\windows\system\rtl8187B.sys
2015-10-09 09:22 . 2015-10-09 09:22 -------- d-----w- c:\program files\Belkin
2015-10-09 09:22 . 2009-02-05 00:49 451072 ----a-w- c:\windows\system32\ISSRemoveSP.exe
2015-10-09 08:50 . 2015-10-09 08:50 -------- d-----w- c:\users\PC\AppData\Roaming\InstallShield
2015-09-17 09:34 . 2015-09-17 09:34 -------- d-----w- c:\program files\Common Files\Skype
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-09-25 11:16 . 2014-05-12 19:57 780488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2015-09-25 11:16 . 2014-05-12 19:57 142536 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2015-09-02 02:48 . 2015-09-09 18:04 26624 ----a-w- c:\windows\system32\lpk.dll
2015-09-02 02:48 . 2015-09-09 18:04 70656 ----a-w- c:\windows\system32\fontsub.dll
2015-09-02 02:48 . 2015-09-09 18:04 10240 ----a-w- c:\windows\system32\dciman32.dll
2015-09-02 02:48 . 2015-09-09 18:04 34304 ----a-w- c:\windows\system32\atmlib.dll
2015-09-02 01:36 . 2015-09-09 18:04 2384896 ----a-w- c:\windows\system32\win32k.sys
2015-09-02 01:33 . 2015-09-09 18:04 299520 ----a-w- c:\windows\system32\atmfd.dll
2015-08-27 17:58 . 2015-09-09 18:05 1391104 ----a-w- c:\windows\system32\msxml6.dll
2015-08-27 17:58 . 2015-09-09 18:05 1241088 ----a-w- c:\windows\system32\msxml3.dll
2015-08-27 17:51 . 2015-09-09 18:05 2048 ----a-w- c:\windows\system32\msxml6r.dll
2015-08-27 17:51 . 2015-09-09 18:05 2048 ----a-w- c:\windows\system32\msxml3r.dll
2015-08-26 17:56 . 2015-09-09 18:02 93184 ----a-w- c:\windows\system32\wudriver.dll
2015-08-26 17:56 . 2015-09-09 18:02 35840 ----a-w- c:\windows\system32\wups2.dll
2015-08-26 17:56 . 2015-09-09 18:02 30208 ----a-w- c:\windows\system32\wups.dll
2015-08-26 17:56 . 2015-09-09 18:02 173056 ----a-w- c:\windows\system32\wuwebv.dll
2015-08-26 17:56 . 2015-09-09 18:02 566784 ----a-w- c:\windows\system32\wuapi.dll
2015-08-26 17:56 . 2015-09-09 18:02 2953728 ----a-w- c:\windows\system32\wucltux.dll
2015-08-26 17:56 . 2015-09-09 18:02 2061824 ----a-w- c:\windows\system32\wuaueng.dll
2015-08-26 17:55 . 2015-09-09 18:02 73728 ----a-w- c:\windows\system32\WinSetupUI.dll
2015-08-26 17:55 . 2015-09-09 18:02 11776 ----a-w- c:\windows\system32\wu.upgrade.ps.dll
2015-08-26 17:55 . 2015-09-09 18:02 34816 ----a-w- c:\windows\system32\wuapp.exe
2015-08-26 17:55 . 2015-09-09 18:02 135680 ----a-w- c:\windows\system32\wuauclt.exe
2015-08-15 05:53 . 2015-09-09 18:11 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2015-08-15 05:53 . 2015-09-09 18:11 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2015-08-15 05:40 . 2015-09-09 18:10 504832 ----a-w- c:\windows\system32\vbscript.dll
2015-08-15 05:40 . 2015-09-09 18:11 62464 ----a-w- c:\windows\system32\iesetup.dll
2015-08-15 05:39 . 2015-09-09 18:11 47616 ----a-w- c:\windows\system32\ieetwproxystub.dll
2015-08-15 05:39 . 2015-09-09 18:11 341504 ----a-w- c:\windows\system32\html.iec
2015-08-15 05:38 . 2015-09-09 18:10 64000 ----a-w- c:\windows\system32\MshtmlDac.dll
2015-08-15 05:29 . 2015-09-09 18:11 102912 ----a-w- c:\windows\system32\ieetwcollector.exe
2015-08-15 05:29 . 2015-09-09 18:11 115712 ----a-w- c:\windows\system32\ieUnatt.exe
2015-08-15 05:29 . 2015-09-09 18:11 620032 ----a-w- c:\windows\system32\jscript9diag.dll
2015-08-15 05:24 . 2015-09-09 18:11 667648 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2015-08-15 05:16 . 2015-09-09 18:11 60416 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2015-08-15 05:10 . 2015-09-09 18:10 4520448 ----a-w- c:\windows\system32\jscript9.dll
2015-08-15 05:01 . 2015-09-09 18:11 2052608 ----a-w- c:\windows\system32\inetcpl.cpl
2015-08-15 05:01 . 2015-09-09 18:11 1155072 ----a-w- c:\windows\system32\mshtmlmedia.dll
2015-08-15 04:43 . 2015-09-09 18:11 1951232 ----a-w- c:\windows\system32\wininet.dll
2015-08-05 17:41 . 2015-09-09 18:05 751104 ----a-w- c:\windows\system32\schedsvc.dll
2015-08-05 17:40 . 2015-09-09 18:05 216064 ----a-w- c:\windows\system32\InkEd.dll
2015-08-05 17:40 . 2015-09-09 18:05 22528 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\jnwppr.dll
2015-08-05 17:40 . 2015-09-09 18:05 19968 ----a-w- c:\windows\system32\jnwmon.dll
2015-08-04 17:48 . 2015-09-09 18:05 50176 ----a-w- c:\windows\system32\setbcdlocale.dll
2015-08-04 17:47 . 2015-09-09 18:05 50688 ----a-w- c:\windows\system32\appidapi.dll
2015-08-04 17:47 . 2015-09-09 18:05 28160 ----a-w- c:\windows\system32\appidsvc.dll
2015-08-04 17:46 . 2015-09-09 18:05 96768 ----a-w- c:\windows\system32\appidpolicyconverter.exe
2015-08-04 17:46 . 2015-09-09 18:05 16896 ----a-w- c:\windows\system32\appidcertstorecheck.exe
2015-08-04 16:53 . 2015-09-09 18:05 50176 ----a-w- c:\windows\system32\drivers\appid.sys
2015-08-03 10:12 . 2015-03-06 17:30 26176 ---ha-w- c:\windows\system32\hamachi.sys
2015-07-30 17:57 . 2015-08-12 10:54 909824 ----a-w- c:\windows\system32\FntCache.dll
2015-07-30 17:57 . 2015-08-12 10:54 1251328 ----a-w- c:\windows\system32\DWrite.dll
2015-07-30 17:57 . 2015-08-12 10:54 1987584 ----a-w- c:\windows\system32\d3d10warp.dll
2015-07-30 13:13 . 2015-08-12 11:37 103120 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-07-28 20:04 . 2015-08-12 10:56 15808 ----a-w- c:\windows\system32\CompatTelRunner.exe
2015-07-28 20:00 . 2015-08-12 10:56 635904 ----a-w- c:\windows\system32\invagent.dll
2015-07-28 20:00 . 2015-08-12 10:56 598528 ----a-w- c:\windows\system32\generaltel.dll
2015-07-28 20:00 . 2015-08-12 10:56 346112 ----a-w- c:\windows\system32\devinv.dll
2015-07-28 20:00 . 2015-08-12 10:56 952832 ----a-w- c:\windows\system32\appraiser.dll
2015-07-28 20:00 . 2015-08-12 10:56 60416 ----a-w- c:\windows\system32\acmigration.dll
2015-07-28 20:00 . 2015-08-12 10:56 202752 ----a-w- c:\windows\system32\aepdu.dll
2015-07-28 19:54 . 2015-08-12 10:56 934400 ----a-w- c:\windows\system32\aeinv.dll
2015-07-22 17:57 . 2015-09-09 18:04 3934656 ----a-w- c:\windows\system32\ntoskrnl.exe
2015-07-22 17:57 . 2015-09-09 18:04 3989952 ----a-w- c:\windows\system32\ntkrnlpa.exe
2015-07-22 17:57 . 2015-09-09 18:04 137664 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2015-07-22 17:57 . 2015-09-09 18:04 67520 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2015-07-22 17:54 . 2015-09-09 18:04 1308160 ----a-w- c:\windows\system32\ntdll.dll
2015-07-22 17:53 . 2015-09-09 18:04 172032 ----a-w- c:\windows\system32\wdigest.dll
2015-07-22 17:53 . 2015-09-09 18:04 937984 ----a-w- c:\windows\system32\diagtrack.dll
2015-07-22 17:53 . 2015-09-09 18:04 65536 ----a-w- c:\windows\system32\TSpkg.dll
2015-07-22 17:53 . 2015-09-09 18:04 635392 ----a-w- c:\windows\system32\tdh.dll
2015-07-22 17:53 . 2015-09-09 18:04 400896 ----a-w- c:\windows\system32\srcore.dll
2015-07-22 17:53 . 2015-09-09 18:04 43008 ----a-w- c:\windows\system32\srclient.dll
2015-07-22 17:53 . 2015-09-09 18:04 100352 ----a-w- c:\windows\system32\sspicli.dll
2015-07-22 17:53 . 2015-09-09 18:03 15872 ----a-w- c:\windows\system32\sspisrv.dll
2015-07-22 17:53 . 2015-09-09 18:04 655360 ----a-w- c:\windows\system32\rpcrt4.dll
2015-07-22 17:53 . 2015-09-09 18:04 248832 ----a-w- c:\windows\system32\schannel.dll
2015-07-22 17:53 . 2015-09-09 18:04 22016 ----a-w- c:\windows\system32\secur32.dll
2015-07-22 17:53 . 2015-09-09 18:04 221184 ----a-w- c:\windows\system32\ncrypt.dll
2015-07-22 17:53 . 2015-09-09 18:04 259584 ----a-w- c:\windows\system32\msv1_0.dll
2015-07-22 17:53 . 2015-09-09 18:04 1061376 ----a-w- c:\windows\system32\lsasrv.dll
2015-07-22 17:53 . 2015-09-09 18:04 552960 ----a-w- c:\windows\system32\kerberos.dll
2015-07-22 17:53 . 2015-09-09 18:04 38912 ----a-w- c:\windows\system32\csrsrv.dll
2015-07-22 17:53 . 2015-09-09 18:04 36864 ----a-w- c:\windows\system32\cryptbase.dll
2015-07-22 17:53 . 2015-09-09 18:03 17408 ----a-w- c:\windows\system32\credssp.dll
2015-07-22 17:53 . 2015-09-09 18:04 641536 ----a-w- c:\windows\system32\advapi32.dll
2015-07-22 17:52 . 2015-09-09 18:04 69632 ----a-w- c:\windows\system32\smss.exe
2015-07-22 17:52 . 2015-09-09 18:04 262656 ----a-w- c:\windows\system32\rstrui.exe
2015-07-22 17:52 . 2015-09-09 18:04 22528 ----a-w- c:\windows\system32\lsass.exe
2015-07-22 17:52 . 2015-09-09 18:04 50176 ----a-w- c:\windows\system32\auditpol.exe
2015-07-22 17:47 . 2015-09-09 18:03 60416 ----a-w- c:\windows\system32\msobjs.dll
2015-07-22 17:46 . 2015-09-09 18:03 146432 ----a-w- c:\windows\system32\msaudite.dll
2015-07-22 17:42 . 2015-09-09 18:03 6656 ----a-w- c:\windows\system32\apisetschema.dll
2015-07-22 17:42 . 2015-09-09 18:03 686080 ----a-w- c:\windows\system32\adtschema.dll
2015-07-22 16:38 . 2015-09-09 18:04 41984 ----a-w- c:\windows\system32\UtcResources.dll
2015-07-22 16:34 . 2015-09-09 18:03 225792 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2015-07-22 16:34 . 2015-09-09 18:03 98304 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2015-07-22 16:33 . 2015-09-09 18:03 124416 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2015-07-16 19:12 . 2015-08-12 10:54 856064 ----a-w- c:\windows\system32\rdvidcrl.dll
2015-07-16 19:12 . 2015-08-12 10:54 53248 ----a-w- c:\windows\system32\tsgqec.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2015-08-07 53729824]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvBackend"="c:\program files\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-03-20 1797064]
"HDAudDeck"="c:\program files\VIA\VIAudioi\VDeck\VDeck.exe" [2009-12-04 1728512]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-09-23 926896]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2015-08-03 5579624]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2015-08-05 508240]
"AdobeCS6ServiceManager"="c:\program files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2013-04-25 1075296]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2015-07-08 5089480]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SPReview"="c:\windows\System32\SPReview\SPReview.exe" [2014-05-09 280576]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2015-07-09 327296]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2015-08-15 102912]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2013-10-02 49152]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2014-05-12 1343400]
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2015-07-14 60552]
S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2015-07-14 202704]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2015-07-14 144536]
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys [2015-07-14 46656]
S2 AGSService;Adobe Genuine Software Integrity Service;c:\program files\Common Files\Adobe\AdobeGCClient\AGSService.exe [2015-09-29 2015936]
S2 c2cautoupdatesvc;Skype Click to Call Updater;c:\program files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2015-05-01 1394816]
S2 c2cpnrsvc;Skype Click to Call PNR Service;c:\program files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2015-05-01 1772672]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2015-07-08 1353720]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [2015-08-03 1883496]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn Hamachi\LMIGuardianSvc.exe [2015-08-03 411920]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-03-04 411936]
S3 RTL8187B;Belkin Wireless G USB Network Adapter;c:\windows\system32\DRIVERS\rtl8187B.sys [2009-08-12 376320]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2009-11-25 1108480]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
utcsvc REG_MULTI_SZ DiagTrack
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-09-28 18:05 997704 ----a-w- c:\program files\Google\Chrome\Application\45.0.2454.101\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2015-10-10 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-12 11:16]
.
2015-10-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2014-07-29 07:23]
.
2015-10-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2014-07-29 07:23]
.
2015-10-09 c:\windows\Tasks\Norton Security Scan for PC.job
- c:\progra~1\NORTON~2\Engine\410~1.28\Nss.exe [2014-09-20 06:04]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 84.16.121.1
TCP: Interfaces\{05A3DBCD-7CEE-4242-9D0A-C98322BA72DB}: NameServer = 84.16.121.1,84.16.120.1
FF - ProfilePath - c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\avfgrdd1.default\
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKCU-Run-AdobeBridge - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2015-10-10 17:25:41
ComboFix-quarantined-files.txt 2015-10-10 15:25
.
Před spuštěním: Volných bajtů: 163 115 278 336
Po spuštění: Volných bajtů: 162 778 009 600
.
- - End Of File - - 1EECAB966D10620AA541D2C30F7B976E
A36C5E4F47E84449FF07ED3517B43A31
ComboFix 15-10-09.01 - PC 10.10.2015 17:15:46.1.1 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.2047.1303 [GMT 2:00]
Spuštěný z: c:\users\PC\Desktop\ComboFix.exe
AV: ESET Smart Security 8.0 *Disabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289}
FW: ESET Personální firewall *Enabled* {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
SP: ESET Smart Security 8.0 *Disabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\conhost32.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2015-09-10 do 2015-10-10 )))))))))))))))))))))))))))))))
.
.
2015-10-10 15:23 . 2015-10-10 15:23 -------- d-----w- c:\users\PC\AppData\Local\temp
2015-10-10 15:23 . 2015-10-10 15:23 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-10-10 14:51 . 2015-10-10 14:51 -------- d-----w- C:\found.000
2015-10-09 17:03 . 2015-10-09 17:04 -------- d-----w- C:\AdwCleaner
2015-10-09 15:11 . 2015-08-31 23:05 8884144 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E34909DF-B6E2-4C20-96D7-C4F61F135073}\mpengine.dll
2015-10-09 13:44 . 2015-10-09 13:49 -------- d-----w- c:\program files\trend micro
2015-10-09 13:44 . 2015-10-09 13:44 -------- d-----w- C:\rsit
2015-10-09 09:46 . 2015-10-09 09:46 -------- d-----w- c:\program files\CCleaner
2015-10-09 09:22 . 2009-08-12 15:37 376320 ----a-w- c:\windows\system32\drivers\rtl8187B.sys
2015-10-09 09:22 . 2015-10-09 09:22 -------- d-----w- c:\windows\OPTIONS
2015-10-09 09:22 . 2009-08-12 15:37 376320 ----a-w- c:\windows\system\rtl8187B.sys
2015-10-09 09:22 . 2015-10-09 09:22 -------- d-----w- c:\program files\Belkin
2015-10-09 09:22 . 2009-02-05 00:49 451072 ----a-w- c:\windows\system32\ISSRemoveSP.exe
2015-10-09 08:50 . 2015-10-09 08:50 -------- d-----w- c:\users\PC\AppData\Roaming\InstallShield
2015-09-17 09:34 . 2015-09-17 09:34 -------- d-----w- c:\program files\Common Files\Skype
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-09-25 11:16 . 2014-05-12 19:57 780488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2015-09-25 11:16 . 2014-05-12 19:57 142536 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2015-09-02 02:48 . 2015-09-09 18:04 26624 ----a-w- c:\windows\system32\lpk.dll
2015-09-02 02:48 . 2015-09-09 18:04 70656 ----a-w- c:\windows\system32\fontsub.dll
2015-09-02 02:48 . 2015-09-09 18:04 10240 ----a-w- c:\windows\system32\dciman32.dll
2015-09-02 02:48 . 2015-09-09 18:04 34304 ----a-w- c:\windows\system32\atmlib.dll
2015-09-02 01:36 . 2015-09-09 18:04 2384896 ----a-w- c:\windows\system32\win32k.sys
2015-09-02 01:33 . 2015-09-09 18:04 299520 ----a-w- c:\windows\system32\atmfd.dll
2015-08-27 17:58 . 2015-09-09 18:05 1391104 ----a-w- c:\windows\system32\msxml6.dll
2015-08-27 17:58 . 2015-09-09 18:05 1241088 ----a-w- c:\windows\system32\msxml3.dll
2015-08-27 17:51 . 2015-09-09 18:05 2048 ----a-w- c:\windows\system32\msxml6r.dll
2015-08-27 17:51 . 2015-09-09 18:05 2048 ----a-w- c:\windows\system32\msxml3r.dll
2015-08-26 17:56 . 2015-09-09 18:02 93184 ----a-w- c:\windows\system32\wudriver.dll
2015-08-26 17:56 . 2015-09-09 18:02 35840 ----a-w- c:\windows\system32\wups2.dll
2015-08-26 17:56 . 2015-09-09 18:02 30208 ----a-w- c:\windows\system32\wups.dll
2015-08-26 17:56 . 2015-09-09 18:02 173056 ----a-w- c:\windows\system32\wuwebv.dll
2015-08-26 17:56 . 2015-09-09 18:02 566784 ----a-w- c:\windows\system32\wuapi.dll
2015-08-26 17:56 . 2015-09-09 18:02 2953728 ----a-w- c:\windows\system32\wucltux.dll
2015-08-26 17:56 . 2015-09-09 18:02 2061824 ----a-w- c:\windows\system32\wuaueng.dll
2015-08-26 17:55 . 2015-09-09 18:02 73728 ----a-w- c:\windows\system32\WinSetupUI.dll
2015-08-26 17:55 . 2015-09-09 18:02 11776 ----a-w- c:\windows\system32\wu.upgrade.ps.dll
2015-08-26 17:55 . 2015-09-09 18:02 34816 ----a-w- c:\windows\system32\wuapp.exe
2015-08-26 17:55 . 2015-09-09 18:02 135680 ----a-w- c:\windows\system32\wuauclt.exe
2015-08-15 05:53 . 2015-09-09 18:11 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2015-08-15 05:53 . 2015-09-09 18:11 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll
2015-08-15 05:40 . 2015-09-09 18:10 504832 ----a-w- c:\windows\system32\vbscript.dll
2015-08-15 05:40 . 2015-09-09 18:11 62464 ----a-w- c:\windows\system32\iesetup.dll
2015-08-15 05:39 . 2015-09-09 18:11 47616 ----a-w- c:\windows\system32\ieetwproxystub.dll
2015-08-15 05:39 . 2015-09-09 18:11 341504 ----a-w- c:\windows\system32\html.iec
2015-08-15 05:38 . 2015-09-09 18:10 64000 ----a-w- c:\windows\system32\MshtmlDac.dll
2015-08-15 05:29 . 2015-09-09 18:11 102912 ----a-w- c:\windows\system32\ieetwcollector.exe
2015-08-15 05:29 . 2015-09-09 18:11 115712 ----a-w- c:\windows\system32\ieUnatt.exe
2015-08-15 05:29 . 2015-09-09 18:11 620032 ----a-w- c:\windows\system32\jscript9diag.dll
2015-08-15 05:24 . 2015-09-09 18:11 667648 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2015-08-15 05:16 . 2015-09-09 18:11 60416 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2015-08-15 05:10 . 2015-09-09 18:10 4520448 ----a-w- c:\windows\system32\jscript9.dll
2015-08-15 05:01 . 2015-09-09 18:11 2052608 ----a-w- c:\windows\system32\inetcpl.cpl
2015-08-15 05:01 . 2015-09-09 18:11 1155072 ----a-w- c:\windows\system32\mshtmlmedia.dll
2015-08-15 04:43 . 2015-09-09 18:11 1951232 ----a-w- c:\windows\system32\wininet.dll
2015-08-05 17:41 . 2015-09-09 18:05 751104 ----a-w- c:\windows\system32\schedsvc.dll
2015-08-05 17:40 . 2015-09-09 18:05 216064 ----a-w- c:\windows\system32\InkEd.dll
2015-08-05 17:40 . 2015-09-09 18:05 22528 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\jnwppr.dll
2015-08-05 17:40 . 2015-09-09 18:05 19968 ----a-w- c:\windows\system32\jnwmon.dll
2015-08-04 17:48 . 2015-09-09 18:05 50176 ----a-w- c:\windows\system32\setbcdlocale.dll
2015-08-04 17:47 . 2015-09-09 18:05 50688 ----a-w- c:\windows\system32\appidapi.dll
2015-08-04 17:47 . 2015-09-09 18:05 28160 ----a-w- c:\windows\system32\appidsvc.dll
2015-08-04 17:46 . 2015-09-09 18:05 96768 ----a-w- c:\windows\system32\appidpolicyconverter.exe
2015-08-04 17:46 . 2015-09-09 18:05 16896 ----a-w- c:\windows\system32\appidcertstorecheck.exe
2015-08-04 16:53 . 2015-09-09 18:05 50176 ----a-w- c:\windows\system32\drivers\appid.sys
2015-08-03 10:12 . 2015-03-06 17:30 26176 ---ha-w- c:\windows\system32\hamachi.sys
2015-07-30 17:57 . 2015-08-12 10:54 909824 ----a-w- c:\windows\system32\FntCache.dll
2015-07-30 17:57 . 2015-08-12 10:54 1251328 ----a-w- c:\windows\system32\DWrite.dll
2015-07-30 17:57 . 2015-08-12 10:54 1987584 ----a-w- c:\windows\system32\d3d10warp.dll
2015-07-30 13:13 . 2015-08-12 11:37 103120 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-07-28 20:04 . 2015-08-12 10:56 15808 ----a-w- c:\windows\system32\CompatTelRunner.exe
2015-07-28 20:00 . 2015-08-12 10:56 635904 ----a-w- c:\windows\system32\invagent.dll
2015-07-28 20:00 . 2015-08-12 10:56 598528 ----a-w- c:\windows\system32\generaltel.dll
2015-07-28 20:00 . 2015-08-12 10:56 346112 ----a-w- c:\windows\system32\devinv.dll
2015-07-28 20:00 . 2015-08-12 10:56 952832 ----a-w- c:\windows\system32\appraiser.dll
2015-07-28 20:00 . 2015-08-12 10:56 60416 ----a-w- c:\windows\system32\acmigration.dll
2015-07-28 20:00 . 2015-08-12 10:56 202752 ----a-w- c:\windows\system32\aepdu.dll
2015-07-28 19:54 . 2015-08-12 10:56 934400 ----a-w- c:\windows\system32\aeinv.dll
2015-07-22 17:57 . 2015-09-09 18:04 3934656 ----a-w- c:\windows\system32\ntoskrnl.exe
2015-07-22 17:57 . 2015-09-09 18:04 3989952 ----a-w- c:\windows\system32\ntkrnlpa.exe
2015-07-22 17:57 . 2015-09-09 18:04 137664 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2015-07-22 17:57 . 2015-09-09 18:04 67520 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2015-07-22 17:54 . 2015-09-09 18:04 1308160 ----a-w- c:\windows\system32\ntdll.dll
2015-07-22 17:53 . 2015-09-09 18:04 172032 ----a-w- c:\windows\system32\wdigest.dll
2015-07-22 17:53 . 2015-09-09 18:04 937984 ----a-w- c:\windows\system32\diagtrack.dll
2015-07-22 17:53 . 2015-09-09 18:04 65536 ----a-w- c:\windows\system32\TSpkg.dll
2015-07-22 17:53 . 2015-09-09 18:04 635392 ----a-w- c:\windows\system32\tdh.dll
2015-07-22 17:53 . 2015-09-09 18:04 400896 ----a-w- c:\windows\system32\srcore.dll
2015-07-22 17:53 . 2015-09-09 18:04 43008 ----a-w- c:\windows\system32\srclient.dll
2015-07-22 17:53 . 2015-09-09 18:04 100352 ----a-w- c:\windows\system32\sspicli.dll
2015-07-22 17:53 . 2015-09-09 18:03 15872 ----a-w- c:\windows\system32\sspisrv.dll
2015-07-22 17:53 . 2015-09-09 18:04 655360 ----a-w- c:\windows\system32\rpcrt4.dll
2015-07-22 17:53 . 2015-09-09 18:04 248832 ----a-w- c:\windows\system32\schannel.dll
2015-07-22 17:53 . 2015-09-09 18:04 22016 ----a-w- c:\windows\system32\secur32.dll
2015-07-22 17:53 . 2015-09-09 18:04 221184 ----a-w- c:\windows\system32\ncrypt.dll
2015-07-22 17:53 . 2015-09-09 18:04 259584 ----a-w- c:\windows\system32\msv1_0.dll
2015-07-22 17:53 . 2015-09-09 18:04 1061376 ----a-w- c:\windows\system32\lsasrv.dll
2015-07-22 17:53 . 2015-09-09 18:04 552960 ----a-w- c:\windows\system32\kerberos.dll
2015-07-22 17:53 . 2015-09-09 18:04 38912 ----a-w- c:\windows\system32\csrsrv.dll
2015-07-22 17:53 . 2015-09-09 18:04 36864 ----a-w- c:\windows\system32\cryptbase.dll
2015-07-22 17:53 . 2015-09-09 18:03 17408 ----a-w- c:\windows\system32\credssp.dll
2015-07-22 17:53 . 2015-09-09 18:04 641536 ----a-w- c:\windows\system32\advapi32.dll
2015-07-22 17:52 . 2015-09-09 18:04 69632 ----a-w- c:\windows\system32\smss.exe
2015-07-22 17:52 . 2015-09-09 18:04 262656 ----a-w- c:\windows\system32\rstrui.exe
2015-07-22 17:52 . 2015-09-09 18:04 22528 ----a-w- c:\windows\system32\lsass.exe
2015-07-22 17:52 . 2015-09-09 18:04 50176 ----a-w- c:\windows\system32\auditpol.exe
2015-07-22 17:47 . 2015-09-09 18:03 60416 ----a-w- c:\windows\system32\msobjs.dll
2015-07-22 17:46 . 2015-09-09 18:03 146432 ----a-w- c:\windows\system32\msaudite.dll
2015-07-22 17:42 . 2015-09-09 18:03 6656 ----a-w- c:\windows\system32\apisetschema.dll
2015-07-22 17:42 . 2015-09-09 18:03 686080 ----a-w- c:\windows\system32\adtschema.dll
2015-07-22 16:38 . 2015-09-09 18:04 41984 ----a-w- c:\windows\system32\UtcResources.dll
2015-07-22 16:34 . 2015-09-09 18:03 225792 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2015-07-22 16:34 . 2015-09-09 18:03 98304 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2015-07-22 16:33 . 2015-09-09 18:03 124416 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2015-07-16 19:12 . 2015-08-12 10:54 856064 ----a-w- c:\windows\system32\rdvidcrl.dll
2015-07-16 19:12 . 2015-08-12 10:54 53248 ----a-w- c:\windows\system32\tsgqec.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2015-08-07 53729824]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvBackend"="c:\program files\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-03-20 1797064]
"HDAudDeck"="c:\program files\VIA\VIAudioi\VDeck\VDeck.exe" [2009-12-04 1728512]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-09-23 926896]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2015-08-03 5579624]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2015-08-05 508240]
"AdobeCS6ServiceManager"="c:\program files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2013-04-25 1075296]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2015-07-08 5089480]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SPReview"="c:\windows\System32\SPReview\SPReview.exe" [2014-05-09 280576]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2015-07-09 327296]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2015-08-15 102912]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2013-10-02 49152]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2014-05-12 1343400]
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2015-07-14 60552]
S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2015-07-14 202704]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2015-07-14 144536]
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys [2015-07-14 46656]
S2 AGSService;Adobe Genuine Software Integrity Service;c:\program files\Common Files\Adobe\AdobeGCClient\AGSService.exe [2015-09-29 2015936]
S2 c2cautoupdatesvc;Skype Click to Call Updater;c:\program files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2015-05-01 1394816]
S2 c2cpnrsvc;Skype Click to Call PNR Service;c:\program files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2015-05-01 1772672]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2015-07-08 1353720]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [2015-08-03 1883496]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn Hamachi\LMIGuardianSvc.exe [2015-08-03 411920]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-03-04 411936]
S3 RTL8187B;Belkin Wireless G USB Network Adapter;c:\windows\system32\DRIVERS\rtl8187B.sys [2009-08-12 376320]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2009-11-25 1108480]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
utcsvc REG_MULTI_SZ DiagTrack
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-09-28 18:05 997704 ----a-w- c:\program files\Google\Chrome\Application\45.0.2454.101\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2015-10-10 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-12 11:16]
.
2015-10-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2014-07-29 07:23]
.
2015-10-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2014-07-29 07:23]
.
2015-10-09 c:\windows\Tasks\Norton Security Scan for PC.job
- c:\progra~1\NORTON~2\Engine\410~1.28\Nss.exe [2014-09-20 06:04]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 84.16.121.1
TCP: Interfaces\{05A3DBCD-7CEE-4242-9D0A-C98322BA72DB}: NameServer = 84.16.121.1,84.16.120.1
FF - ProfilePath - c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\avfgrdd1.default\
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKCU-Run-AdobeBridge - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2015-10-10 17:25:41
ComboFix-quarantined-files.txt 2015-10-10 15:25
.
Před spuštěním: Volných bajtů: 163 115 278 336
Po spuštění: Volných bajtů: 162 778 009 600
.
- - End Of File - - 1EECAB966D10620AA541D2C30F7B976E
A36C5E4F47E84449FF07ED3517B43A31
Re: Prosím o kontrolu PC
Přes Start >> Spustit zkopíruj do okna:
ComboFix /Uninstall
a stiskni Enter
To odinstaluje ComboFix a smaže s ním související soubory a složky.
Použij T-Cleaner, který smaže případné zbytky po aplikacích které jsme použili.
Jen před jeho stažením a při použití stopni antivir, protože ho muže detekovat jako vir ale není tomu tak.
Pak dej vědět jak se PC chová.
ComboFix /Uninstall
a stiskni Enter
To odinstaluje ComboFix a smaže s ním související soubory a složky.
Použij T-Cleaner, který smaže případné zbytky po aplikacích které jsme použili.
Jen před jeho stažením a při použití stopni antivir, protože ho muže detekovat jako vir ale není tomu tak.
Pak dej vědět jak se PC chová.
Re: Prosím o kontrolu PC
Děkuji Vám moc za pomoc, počítač reaguje o poznání rychleji.
Na žádné jiné problémy jsem nenarazila.

Re: Prosím o kontrolu PC
Ještě ale koukám, že nám tam cosi zůstalo viset, tak to doladíme
Stáhni a spusť OTMoveIt
do levého okna aplikace pod Paste Instructions for Items to be Moved zkopíruj tento text:
klikni na MoveIt! a v pravém zeleném okně aplikace se Ti objeví info o provedene akci, obsah okna zkopíruj sem,
pokud aplikace bude požadovat restart, klikni na YES
v tom případě sem zkopíruj obsah logu uloženého na C:\_OTMoveIt\MovedFiles\

Stáhni a spusť OTMoveIt
do levého okna aplikace pod Paste Instructions for Items to be Moved zkopíruj tento text:
Kód: Vybrat vše
:processes
explorer.exe
:files
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
c:\windows\Tasks\Norton Security Scan for PC.job
:commands
[purity]
[emptytemp]
[start explorer]
pokud aplikace bude požadovat restart, klikni na YES
v tom případě sem zkopíruj obsah logu uloženého na C:\_OTMoveIt\MovedFiles\
Re: Prosím o kontrolu PC
Restart byl požadován, zde je log:
All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== FILES ==========
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job moved successfully.
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job moved successfully.
c:\windows\Tasks\Norton Security Scan for PC.job moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: PC
->Temp folder emptied: 56859 bytes
->Temporary Internet Files folder emptied: 38949644 bytes
->Java cache emptied: 12461793 bytes
->FireFox cache emptied: 13309973 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 753 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 591622 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 79331248 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 138,00 mb
OTM by OldTimer - Version 3.1.21.0 log created on 10122015_174717
All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== FILES ==========
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job moved successfully.
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job moved successfully.
c:\windows\Tasks\Norton Security Scan for PC.job moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: PC
->Temp folder emptied: 56859 bytes
->Temporary Internet Files folder emptied: 38949644 bytes
->Java cache emptied: 12461793 bytes
->FireFox cache emptied: 13309973 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 753 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 591622 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 79331248 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 138,00 mb
OTM by OldTimer - Version 3.1.21.0 log created on 10122015_174717
Re: Prosím o kontrolu PC
Teď už se mi to líbí
Znovu spusť OTMoveIt a nahoře v aplikaci klini na CleanUP!
tímto po sobě uklidí.
No a pokud s PC již není žádný problém je to z mé strany vše.

Znovu spusť OTMoveIt a nahoře v aplikaci klini na CleanUP!
tímto po sobě uklidí.
No a pokud s PC již není žádný problém je to z mé strany vše.
Re: Prosím o kontrolu PC
Ne, už žádný problém není. Ještě jednou moc děkuji za pomoc.
Mějte se hezky.
