Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Pomaly start systemu Windows a plochy

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
CZDaywalker
Návštěvník
Návštěvník
Příspěvky: 191
Registrován: 25 úno 2008 07:58

Pomaly start systemu Windows a plochy

#1 Příspěvek od CZDaywalker »

Zdravim,

Mam tady notebook u ktereho je problem se spustenim = celkove zapnuti, najeti do systemu + moznost pracovat odhaduju tak na 10 minut.

Zde je log:
Logfile of random's system information tool 1.10 (written by random/random)
Run by uživatel at 2016-01-01 17:28:31
Microsoft® Windows Vista™ Home Basic Service Pack 2
System drive C: has 143 GB (63%) free of 228 GB
Total RAM: 2038 MB (35% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:32:33, on 1.1.2016
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16723)
Boot mode: Normal

Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\Dwm.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\PLFSetL.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files\BlueStacks\HD-Agent.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Labtec NumPad\Magickey.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Users\UIVATE~1\AppData\Local\Temp\RtkBtMnt.exe
C:\Users\uživatel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\uživatel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\uživatel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\RSIT.exe
C:\Program Files\trend micro\uživatel.exe
C:\Users\uživatel\AppData\Local\Google\Chrome\Application\chrome.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = localhost:21320
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [PLFSetL] C:\Windows\PLFSetL.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe"
O4 - HKLM\..\Run: [Printsrv] c:\Windows\System32\Printing_Admin_Scripts\en-US\driverupd.vbs
O4 - HKLM\..\Run: [BlueStacks Agent] C:\Program Files\BlueStacks\HD-Agent.exe
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [Google Update] "C:\Users\uživatel\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKCU\..\Run: [Spybot-S&D Cleaning] "C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean
O4 - HKCU\..\Run: [SpybotPostWindows10UpgradeReInstall] "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Enable Labtec NumPad.lnk = C:\Program Files\Labtec NumPad\Magickey.exe
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: BlueStacks Android Service (BstHdAndroidSvc) - BlueStack Systems, Inc. - C:\Program Files\BlueStacks\HD-Service.exe
O23 - Service: BlueStacks Log Rotator Service (BstHdLogRotatorSvc) - BlueStack Systems, Inc. - C:\Program Files\BlueStacks\HD-LogRotatorService.exe
O23 - Service: BlueStacks Updater Service (BstHdUpdaterSvc) - BlueStack Systems, Inc. - C:\Program Files\BlueStacks\HD-UpdaterService.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 7103 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\Check for updates (Spybot - Search & Destroy).job - C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe /autoupdate /silent /autoclose /background
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3381152194-3172404285-1880440078-1000Core.job - C:\Users\uživatel\AppData\Local\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3381152194-3172404285-1880440078-1000UA.job - C:\Users\uživatel\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\Refresh immunization (Spybot - Search & Destroy).job - C:\Program Files\Spybot - Search & Destroy 2\SDImmunize.exe /immunize /silent /autoclose
C:\Windows\tasks\Scan the system (Spybot - Search & Destroy).job - C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe /scan /cleanclose

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-02-15 460712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-15 172968]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-04-05 1008184]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2010-11-01 4853760]
"PLFSetL"=C:\Windows\PLFSetL.exe [2007-07-05 94208]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-02-11 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-02-11 166424]
"Persistence"=C:\Windows\system32\igfxpers.exe [2008-02-11 133656]
"SDTray"=C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [2013-05-16 3830224]
"Printsrv"=c:\Windows\System32\Printing_Admin_Scripts\en-US\driverupd.vbs [2013-12-04 559]
"BlueStacks Agent"=C:\Program Files\BlueStacks\HD-Agent.exe [2015-03-24 863960]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2015-04-29 981688]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\uživatel\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-30 144200]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2012-02-13 3481408]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2015-08-20 6490904]
"Spybot-S&D Cleaning"=C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe [2013-05-16 3642312]
"SpybotPostWindows10UpgradeReInstall"=C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [2015-07-28 1011200]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2015-12-17 50378880]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mncebxuSrv]
C:\Windows\system32\mncebxu.vbe [2014-03-05 7670]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mnceenlcSrv]
C:\Windows\system32\mnceenlc.vbe [2014-03-05 7670]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msbkvoyaSrv]
C:\Windows\system32\msbkvoya.vbe [2014-06-23 649]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msbwfuSrv]
C:\Windows\system32\msbwfu.vbe [2014-06-23 649]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mskoutSrv]
C:\Windows\inf\mskout.vbe [2013-08-27 1558]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msqnbuSrv]
C:\Windows\system32\msqnbu.vbe [2014-06-23 649]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSStp]
C:\Windows\inf\msstp.vbe [2014-03-05 1584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NtVdmSrv]
C:\Windows\inf\ntvdm.vbe [2013-06-20 1219]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
Enable Labtec NumPad.lnk - C:\Program Files\Labtec NumPad\Magickey.exe

C:\Users\uživatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OpenOffice.org 3.2.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2008-02-11 204800]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SDWinLogon]
SDWinLogon.dll []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe"="C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon"
"C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe"="C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service"
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe"="C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater"
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe"="C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.FPS1"=frapsvid.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-01-01 17:28:31 ----D---- C:\Program Files\trend micro
2016-01-01 17:28:30 ----D---- C:\rsit
2016-01-01 17:28:19 ----A---- C:\RSIT.exe
2016-01-01 09:45:34 ----D---- C:\Program Files\Common Files\Skype
2016-01-01 09:45:33 ----RD---- C:\Program Files\Skype
2016-01-01 09:45:20 ----SHD---- C:\Config.Msi
2015-12-25 15:02:10 ----D---- C:\Fraps
2015-12-17 14:03:25 ----D---- C:\Users\uživatel\AppData\Roaming\Mozilla
2015-12-10 12:56:45 ----D---- C:\7d5b56e9cba49c1900af45d25653
2015-12-10 12:37:44 ----A---- C:\Windows\system32\d3d10warp.dll
2015-12-10 12:37:44 ----A---- C:\Windows\system32\d3d10level9.dll
2015-12-10 12:37:44 ----A---- C:\Windows\system32\d3d10core.dll
2015-12-10 12:37:44 ----A---- C:\Windows\system32\d3d10_1core.dll
2015-12-10 12:37:44 ----A---- C:\Windows\system32\d3d10_1.dll
2015-12-10 12:37:44 ----A---- C:\Windows\system32\d2d1.dll
2015-12-10 12:37:43 ----A---- C:\Windows\system32\win32k.sys
2015-12-10 12:37:43 ----A---- C:\Windows\system32\user32.dll
2015-12-10 12:37:43 ----A---- C:\Windows\system32\d3d10.dll
2015-12-10 12:37:42 ----A---- C:\Windows\system32\FntCache.dll
2015-12-10 12:37:42 ----A---- C:\Windows\system32\DWrite.dll
2015-12-10 12:35:42 ----A---- C:\Windows\system32\els.dll
2015-12-10 12:33:22 ----A---- C:\Windows\system32\tzres.dll
2015-12-10 12:32:10 ----A---- C:\Windows\system32\comsvcs.dll
2015-12-10 12:32:07 ----A---- C:\Windows\system32\catsrvut.dll
2015-12-10 12:30:43 ----A---- C:\Windows\system32\drivers\rmcast.sys
2015-12-09 14:32:05 ----A---- C:\Windows\system32\mshta.exe
2015-12-09 14:32:04 ----A---- C:\Windows\system32\vbscript.dll
2015-12-09 14:32:04 ----A---- C:\Windows\system32\msfeedsbs.dll
2015-12-09 14:32:04 ----A---- C:\Windows\system32\jsproxy.dll
2015-12-09 14:32:04 ----A---- C:\Windows\system32\dxtmsft.dll
2015-12-09 14:32:03 ----A---- C:\Windows\system32\urlmon.dll
2015-12-09 14:32:03 ----A---- C:\Windows\system32\msfeedssync.exe
2015-12-09 14:32:02 ----A---- C:\Windows\system32\msfeeds.dll
2015-12-09 14:32:02 ----A---- C:\Windows\system32\jscript.dll
2015-12-09 14:32:01 ----A---- C:\Windows\system32\url.dll
2015-12-09 14:32:01 ----A---- C:\Windows\system32\ieUnatt.exe
2015-12-09 14:32:01 ----A---- C:\Windows\system32\iertutil.dll
2015-12-09 14:31:59 ----A---- C:\Windows\system32\wininet.dll
2015-12-09 14:31:59 ----A---- C:\Windows\system32\jscript9.dll
2015-12-09 14:31:58 ----A---- C:\Windows\system32\ieframe.dll
2015-12-09 14:31:57 ----A---- C:\Windows\system32\mshtmled.dll
2015-12-09 14:31:56 ----A---- C:\Windows\system32\ieui.dll
2015-12-09 14:31:56 ----A---- C:\Windows\system32\dxtrans.dll
2015-12-09 14:31:52 ----A---- C:\Windows\system32\mshtml.dll

======List of files/folders modified in the last 1 month======

2016-01-01 17:32:33 ----D---- C:\Windows\Temp
2016-01-01 17:28:31 ----RD---- C:\Program Files
2016-01-01 16:10:40 ----D---- C:\Users\uživatel\AppData\Roaming\Skype
2016-01-01 10:26:33 ----SHD---- C:\System Volume Information
2016-01-01 09:45:50 ----SHD---- C:\Windows\Installer
2016-01-01 09:45:34 ----D---- C:\Program Files\Common Files
2016-01-01 09:45:33 ----D---- C:\Windows\System32
2016-01-01 09:45:25 ----D---- C:\ProgramData\Skype
2015-12-29 13:52:37 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2015-12-28 10:58:39 ----D---- C:\Windows\system32\catroot2
2015-12-25 14:57:02 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-12-18 11:53:14 ----D---- C:\Windows\system32\MRT
2015-12-18 11:52:14 ----A---- C:\Windows\system32\mrt.exe
2015-12-13 13:49:22 ----D---- C:\Windows
2015-12-10 13:33:56 ----D---- C:\Windows\rescache
2015-12-10 13:21:28 ----D---- C:\Windows\Microsoft.NET
2015-12-10 13:19:01 ----RSD---- C:\Windows\assembly
2015-12-10 13:03:34 ----D---- C:\Program Files\Microsoft Silverlight
2015-12-10 12:56:48 ----D---- C:\Windows\system32\XPSViewer
2015-12-10 12:56:48 ----D---- C:\Windows\system32\migration
2015-12-10 12:56:48 ----D---- C:\Program Files\Internet Explorer
2015-12-10 12:56:46 ----D---- C:\Windows\system32\cs-CZ
2015-12-10 12:56:46 ----D---- C:\Windows\inf
2015-12-10 12:56:45 ----D---- C:\Windows\system32\drivers
2015-12-10 12:38:05 ----D---- C:\Windows\winsxs
2015-12-10 12:38:02 ----D---- C:\Windows\system32\catroot
2015-12-09 04:39:28 ----N---- C:\Windows\system32\MpSigStub.exe
2015-12-02 11:23:21 ----D---- C:\Windows\Tasks

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2015-03-04 245096]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2012-03-10 242240]
R2 BstHdDrv;BlueStacks Hypervisor; \??\C:\Program Files\BlueStacks\HD-Hypervisor-x86.sys [2015-03-24 130776]
R2 irda;IrDA Protocol; C:\Windows\system32\DRIVERS\irda.sys [2008-04-05 95744]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2010-11-01 12672]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2015-03-04 95408]
R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2010-11-01 8192]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2007-07-22 180736]
R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2010-11-01 985600]
R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2010-11-01 207360]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2010-11-01 2044896]
R3 NETw4v32;Ovladač adaptéru Intel(R) Wireless WiFi Link pro systém Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw4v32.sys [2007-09-26 2251776]
R3 NSCIRDA;NSC Infrared Device Driver; C:\Windows\system32\DRIVERS\nscirda.sys [2008-04-05 30720]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-04-11 89088]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2007-10-01 1769984]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2010-11-01 659968]
R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys [2012-07-26 66560]
S3 AF15BDA;AF9015 BDA Device; C:\Windows\system32\DRIVERS\AF15BDA.sys [2009-06-03 483200]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2008-04-05 92160]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2011-04-21 508416]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-06-17 30208]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2010-11-01 81448]
S3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\drivers\btwavdt.sys [2010-11-01 99880]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2010-11-01 28464]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2010-11-01 17448]
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\Windows\System32\Drivers\btwusb.sys [2007-03-23 67960]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-04-05 5632]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 HSFHWAZL;HSFHWAZL; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2008-04-05 200704]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-04-05 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-04-05 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-04-05 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-04-05 6016]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
S3 UIUSys;Conexant Setup API; C:\Windows\system32\DRIVERS\UIUSYS.SYS []
S3 USBNumPad;Numberpad USB Keyboard; C:\Windows\System32\Drivers\USBNumPad.sys [2007-03-19 9600]
S3 usbvideo;Zobrazovací zařízení USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-04-05 134016]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 155136]
S4 ErrDev;Ovladače chybového zařízení hardwaru Microsoft; C:\Windows\system32\drivers\errdev.sys [2008-04-05 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-04-05 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service; C:\Program Files\BlueStacks\HD-LogRotatorService.exe [2015-03-24 388824]
R2 BstHdUpdaterSvc;BlueStacks Updater Service; C:\Program Files\BlueStacks\HD-UpdaterService.exe [2015-03-24 798424]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-04-05 21504]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2007-11-01 794624]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-04-05 21504]
R2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2008-04-05 21504]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2015-04-30 22216]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2007-11-01 483328]
R2 SDScannerService;Spybot-S&D 2 Scanner Service; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [2013-05-16 1817560]
R2 SDUpdateService;Spybot-S&D 2 Updating Service; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2013-05-16 1033688]
R2 SDWSCService;Spybot-S&D 2 Security Center Service; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [2013-05-15 171928]
R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2010-11-01 386560]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2015-04-30 284504]
S2 BstHdAndroidSvc;BlueStacks Android Service; C:\Program Files\BlueStacks\HD-Service.exe [2015-03-24 433880]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2015-07-09 327296]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-12-29 269504]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2014-04-11 772296]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2014-04-11 45744]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-11 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-11 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-11 139944]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pomaly start systemu Windows a plochy

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

CZDaywalker
Návštěvník
Návštěvník
Příspěvky: 191
Registrován: 25 úno 2008 07:58

Re: Pomaly start systemu Windows a plochy

#3 Příspěvek od CZDaywalker »

Tak po startu se objevuje hlaska, ze expIorer.exe prestal pracovat a ukoncit program je jedina moznost jak se toho zbavit.

Tady je log:

# AdwCleaner v5.027 - Logfile created 01/01/2016 at 18:48:06
# Updated 30/12/2015 by Xplode
# Database : 2015-12-30.1 [Server]
# Operating system : Windows Vista (TM) Home Basic Service Pack 2 (x86)
# Username : uživatel - UŽIVATEL-PC
# Running from : C:\Users\uživatel\Desktop\adwcleaner_5.027.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****

[-] Folder Deleted : C:\ProgramData\Tarma Installer
[-] Folder Deleted : C:\ProgramData\Trymedia

***** [ Files ] *****


***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****

[-] Task Deleted : Express Files Updater

***** [ Registry ] *****

[-] Key Deleted : HKCU\Software\7b50789aece6c4d54a54c7f6ab7be366
[-] Key Deleted : HKCU\Software\c25bb4b46988f213a04e5145e3c057f0
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
[-] Key Deleted : HKCU\Software\Softonic
[-] Key Deleted : HKLM\SOFTWARE\Tarma Installer
[-] Key Deleted : HKLM\SOFTWARE\Trymedia Systems
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ExpressFiles

***** [ Web browsers ] *****


*************************

:: "Tracing" keys removed
:: Winsock settings cleared

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [1460 bytes] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pomaly start systemu Windows a plochy

#4 Příspěvek od Rudy »

Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

CZDaywalker
Návštěvník
Návštěvník
Příspěvky: 191
Registrován: 25 úno 2008 07:58

Re: Pomaly start systemu Windows a plochy

#5 Příspěvek od CZDaywalker »

Tady je:

Logfile of random's system information tool 1.10 (written by random/random)
Run by uživatel at 2016-01-01 20:00:01
Microsoft® Windows Vista™ Home Basic Service Pack 2
System drive C: has 142 GB (62%) free of 228 GB
Total RAM: 2038 MB (42% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:01:10, on 1.1.2016
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16723)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\PLFSetL.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\BlueStacks\HD-Agent.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Labtec NumPad\Magickey.exe
C:\Windows\system32\igfxsrvc.exe
C:\Users\UIVATE~1\AppData\Local\Temp\RtkBtMnt.exe
C:\Windows\system32\Taskmgr.exe
C:\Users\uživatel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\uživatel\Desktop\RSIT.exe
C:\Program Files\trend micro\uživatel.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_66\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_66\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [PLFSetL] C:\Windows\PLFSetL.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Printsrv] c:\Windows\System32\Printing_Admin_Scripts\en-US\driverupd.vbs
O4 - HKLM\..\Run: [BlueStacks Agent] C:\Program Files\BlueStacks\HD-Agent.exe
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\uživatel\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [SpybotPostWindows10UpgradeReInstall] "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Enable Labtec NumPad.lnk = C:\Program Files\Labtec NumPad\Magickey.exe
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: BlueStacks Android Service (BstHdAndroidSvc) - BlueStack Systems, Inc. - C:\Program Files\BlueStacks\HD-Service.exe
O23 - Service: BlueStacks Log Rotator Service (BstHdLogRotatorSvc) - BlueStack Systems, Inc. - C:\Program Files\BlueStacks\HD-LogRotatorService.exe
O23 - Service: BlueStacks Updater Service (BstHdUpdaterSvc) - BlueStack Systems, Inc. - C:\Program Files\BlueStacks\HD-UpdaterService.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 5929 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3381152194-3172404285-1880440078-1000Core.job - C:\Users\uživatel\AppData\Local\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3381152194-3172404285-1880440078-1000UA.job - C:\Users\uživatel\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_66\bin\ssv.dll [2016-01-01 460384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_66\bin\jp2ssv.dll [2016-01-01 172640]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-04-05 1008184]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2010-11-01 4853760]
"PLFSetL"=C:\Windows\PLFSetL.exe [2007-07-05 94208]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-02-11 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-02-11 166424]
"Persistence"=C:\Windows\system32\igfxpers.exe [2008-02-11 133656]
"Printsrv"=c:\Windows\System32\Printing_Admin_Scripts\en-US\driverupd.vbs [2013-12-04 559]
"BlueStacks Agent"=C:\Program Files\BlueStacks\HD-Agent.exe [2015-03-24 863960]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2015-04-29 981688]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2015-11-09 596528]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\uživatel\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-30 144200]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2012-02-13 3481408]
"SpybotPostWindows10UpgradeReInstall"=C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [2015-07-28 1011200]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2015-12-17 50378880]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mncebxuSrv]
C:\Windows\system32\mncebxu.vbe [2014-03-05 7670]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mnceenlcSrv]
C:\Windows\system32\mnceenlc.vbe [2014-03-05 7670]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msbkvoyaSrv]
C:\Windows\system32\msbkvoya.vbe [2014-06-23 649]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msbwfuSrv]
C:\Windows\system32\msbwfu.vbe [2014-06-23 649]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mskoutSrv]
C:\Windows\inf\mskout.vbe [2013-08-27 1558]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msqnbuSrv]
C:\Windows\system32\msqnbu.vbe [2014-06-23 649]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSStp]
C:\Windows\inf\msstp.vbe [2014-03-05 1584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NtVdmSrv]
C:\Windows\inf\ntvdm.vbe [2013-06-20 1219]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
Enable Labtec NumPad.lnk - C:\Program Files\Labtec NumPad\Magickey.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2008-02-11 204800]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.FPS1"=frapsvid.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-01-01 19:23:56 ----D---- C:\Program Files\Common Files\Java
2016-01-01 19:23:39 ----D---- C:\Users\uživatel\AppData\Roaming\Sun
2016-01-01 18:44:38 ----D---- C:\AdwCleaner
2016-01-01 18:20:20 ----A---- C:\Windows\system32\XAudio2_7.dll
2016-01-01 18:20:20 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2016-01-01 18:20:19 ----A---- C:\Windows\system32\xactengine3_7.dll
2016-01-01 18:20:18 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2016-01-01 18:20:17 ----A---- C:\Windows\system32\d3dcsx_43.dll
2016-01-01 18:20:16 ----A---- C:\Windows\system32\d3dx11_43.dll
2016-01-01 18:20:16 ----A---- C:\Windows\system32\d3dx10_43.dll
2016-01-01 18:20:15 ----A---- C:\Windows\system32\D3DX9_43.dll
2016-01-01 18:20:12 ----A---- C:\Windows\system32\XAudio2_6.dll
2016-01-01 18:20:12 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2016-01-01 18:20:10 ----A---- C:\Windows\system32\xactengine3_6.dll
2016-01-01 18:20:10 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2016-01-01 18:20:09 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2016-01-01 18:20:08 ----A---- C:\Windows\system32\XAudio2_5.dll
2016-01-01 18:20:07 ----A---- C:\Windows\system32\xactengine3_5.dll
2016-01-01 18:20:07 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2016-01-01 18:20:05 ----A---- C:\Windows\system32\d3dcsx_42.dll
2016-01-01 18:20:00 ----A---- C:\Windows\system32\d3dx11_42.dll
2016-01-01 18:19:59 ----A---- C:\Windows\system32\d3dx10_42.dll
2016-01-01 18:19:58 ----A---- C:\Windows\system32\d3dx10_41.dll
2016-01-01 18:19:58 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2016-01-01 18:19:57 ----A---- C:\Windows\system32\D3DX9_41.dll
2016-01-01 18:19:52 ----A---- C:\Windows\system32\XAudio2_4.dll
2016-01-01 18:19:51 ----A---- C:\Windows\system32\xactengine3_4.dll
2016-01-01 18:19:50 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2016-01-01 18:19:50 ----A---- C:\Windows\system32\d3dx10_40.dll
2016-01-01 18:19:50 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2016-01-01 18:19:49 ----A---- C:\Windows\system32\D3DX9_40.dll
2016-01-01 18:19:45 ----A---- C:\Windows\system32\XAudio2_3.dll
2016-01-01 18:19:45 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2016-01-01 18:19:39 ----A---- C:\Windows\system32\xactengine3_3.dll
2016-01-01 18:19:38 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2016-01-01 18:19:37 ----A---- C:\Windows\system32\XAudio2_2.dll
2016-01-01 18:19:37 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2016-01-01 18:19:36 ----A---- C:\Windows\system32\xactengine3_2.dll
2016-01-01 18:19:35 ----A---- C:\Windows\system32\d3dx10_39.dll
2016-01-01 18:19:35 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2016-01-01 18:19:31 ----A---- C:\Windows\system32\D3DX9_39.dll
2016-01-01 18:19:27 ----A---- C:\Windows\system32\XAudio2_1.dll
2016-01-01 18:19:27 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2016-01-01 18:19:26 ----A---- C:\Windows\system32\xactengine3_1.dll
2016-01-01 18:19:26 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2016-01-01 18:19:25 ----A---- C:\Windows\system32\d3dx10_38.dll
2016-01-01 18:19:25 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2016-01-01 18:19:24 ----A---- C:\Windows\system32\D3DX9_38.dll
2016-01-01 18:19:21 ----A---- C:\Windows\system32\XAudio2_0.dll
2016-01-01 18:19:20 ----A---- C:\Windows\system32\xactengine3_0.dll
2016-01-01 18:19:19 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2016-01-01 18:19:19 ----A---- C:\Windows\system32\d3dx10_37.dll
2016-01-01 18:19:19 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2016-01-01 18:19:16 ----A---- C:\Windows\system32\D3DX9_37.dll
2016-01-01 18:19:12 ----A---- C:\Windows\system32\xactengine2_10.dll
2016-01-01 18:19:11 ----A---- C:\Windows\system32\d3dx10_36.dll
2016-01-01 18:19:11 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2016-01-01 18:19:09 ----A---- C:\Windows\system32\d3dx9_36.dll
2016-01-01 18:19:04 ----A---- C:\Windows\system32\xactengine2_9.dll
2016-01-01 18:19:04 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2016-01-01 18:19:04 ----A---- C:\Windows\system32\d3dx10_35.dll
2016-01-01 18:19:04 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2016-01-01 18:19:01 ----A---- C:\Windows\system32\d3dx9_35.dll
2016-01-01 18:18:38 ----A---- C:\Windows\system32\xactengine2_8.dll
2016-01-01 18:18:38 ----A---- C:\Windows\system32\d3dx10_34.dll
2016-01-01 18:18:38 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2016-01-01 18:18:36 ----A---- C:\Windows\system32\d3dx9_34.dll
2016-01-01 18:18:30 ----A---- C:\Windows\system32\xinput1_3.dll
2016-01-01 18:18:28 ----A---- C:\Windows\system32\xactengine2_7.dll
2016-01-01 18:18:28 ----A---- C:\Windows\system32\d3dx10_33.dll
2016-01-01 18:18:27 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2016-01-01 18:18:25 ----A---- C:\Windows\system32\d3dx9_33.dll
2016-01-01 18:18:21 ----A---- C:\Windows\system32\xactengine2_6.dll
2016-01-01 18:18:14 ----A---- C:\Windows\system32\xactengine2_5.dll
2016-01-01 18:18:12 ----A---- C:\Windows\system32\d3dx9_32.dll
2016-01-01 18:18:12 ----A---- C:\Windows\system32\d3dx10.dll
2016-01-01 18:18:02 ----A---- C:\Windows\system32\xactengine2_4.dll
2016-01-01 18:18:01 ----A---- C:\Windows\system32\x3daudio1_1.dll
2016-01-01 18:17:59 ----A---- C:\Windows\system32\xactengine2_3.dll
2016-01-01 18:17:58 ----A---- C:\Windows\system32\xinput1_2.dll
2016-01-01 18:17:55 ----A---- C:\Windows\system32\xactengine2_2.dll
2016-01-01 18:17:54 ----A---- C:\Windows\system32\xinput1_1.dll
2016-01-01 18:17:53 ----A---- C:\Windows\system32\xactengine2_1.dll
2016-01-01 18:17:37 ----A---- C:\Windows\system32\d3dx9_30.dll
2016-01-01 18:17:31 ----A---- C:\Windows\system32\xactengine2_0.dll
2016-01-01 18:17:31 ----A---- C:\Windows\system32\x3daudio1_0.dll
2016-01-01 18:17:28 ----A---- C:\Windows\system32\d3dx9_29.dll
2016-01-01 18:17:23 ----A---- C:\Windows\system32\d3dx9_28.dll
2016-01-01 18:17:18 ----A---- C:\Windows\system32\d3dx9_27.dll
2016-01-01 18:17:14 ----A---- C:\Windows\system32\d3dx9_26.dll
2016-01-01 18:17:09 ----A---- C:\Windows\system32\d3dx9_25.dll
2016-01-01 18:17:00 ----A---- C:\Windows\system32\d3dx9_24.dll
2016-01-01 18:09:58 ----HD---- C:\Windows\msdownld.tmp
2016-01-01 18:09:51 ----D---- C:\Windows\system32\directx
2016-01-01 17:28:31 ----D---- C:\Program Files\trend micro
2016-01-01 17:28:30 ----D---- C:\rsit
2016-01-01 17:28:19 ----A---- C:\RSIT.exe
2016-01-01 09:45:34 ----D---- C:\Program Files\Common Files\Skype
2016-01-01 09:45:33 ----RD---- C:\Program Files\Skype
2015-12-25 15:02:10 ----D---- C:\Fraps
2015-12-17 14:03:25 ----D---- C:\Users\uživatel\AppData\Roaming\Mozilla
2015-12-10 12:56:45 ----D---- C:\7d5b56e9cba49c1900af45d25653
2015-12-10 12:37:44 ----A---- C:\Windows\system32\d3d10warp.dll
2015-12-10 12:37:44 ----A---- C:\Windows\system32\d3d10level9.dll
2015-12-10 12:37:44 ----A---- C:\Windows\system32\d3d10core.dll
2015-12-10 12:37:44 ----A---- C:\Windows\system32\d3d10_1core.dll
2015-12-10 12:37:44 ----A---- C:\Windows\system32\d3d10_1.dll
2015-12-10 12:37:44 ----A---- C:\Windows\system32\d2d1.dll
2015-12-10 12:37:43 ----A---- C:\Windows\system32\win32k.sys
2015-12-10 12:37:43 ----A---- C:\Windows\system32\user32.dll
2015-12-10 12:37:43 ----A---- C:\Windows\system32\d3d10.dll
2015-12-10 12:37:42 ----A---- C:\Windows\system32\FntCache.dll
2015-12-10 12:37:42 ----A---- C:\Windows\system32\DWrite.dll
2015-12-10 12:35:42 ----A---- C:\Windows\system32\els.dll
2015-12-10 12:33:22 ----A---- C:\Windows\system32\tzres.dll
2015-12-10 12:32:10 ----A---- C:\Windows\system32\comsvcs.dll
2015-12-10 12:32:07 ----A---- C:\Windows\system32\catsrvut.dll
2015-12-10 12:30:43 ----A---- C:\Windows\system32\drivers\rmcast.sys
2015-12-09 14:32:05 ----A---- C:\Windows\system32\mshta.exe
2015-12-09 14:32:04 ----A---- C:\Windows\system32\vbscript.dll
2015-12-09 14:32:04 ----A---- C:\Windows\system32\msfeedsbs.dll
2015-12-09 14:32:04 ----A---- C:\Windows\system32\jsproxy.dll
2015-12-09 14:32:04 ----A---- C:\Windows\system32\dxtmsft.dll
2015-12-09 14:32:03 ----A---- C:\Windows\system32\urlmon.dll
2015-12-09 14:32:03 ----A---- C:\Windows\system32\msfeedssync.exe
2015-12-09 14:32:02 ----A---- C:\Windows\system32\msfeeds.dll
2015-12-09 14:32:02 ----A---- C:\Windows\system32\jscript.dll
2015-12-09 14:32:01 ----A---- C:\Windows\system32\url.dll
2015-12-09 14:32:01 ----A---- C:\Windows\system32\ieUnatt.exe
2015-12-09 14:32:01 ----A---- C:\Windows\system32\iertutil.dll
2015-12-09 14:31:59 ----A---- C:\Windows\system32\wininet.dll
2015-12-09 14:31:59 ----A---- C:\Windows\system32\jscript9.dll
2015-12-09 14:31:58 ----A---- C:\Windows\system32\ieframe.dll
2015-12-09 14:31:57 ----A---- C:\Windows\system32\mshtmled.dll
2015-12-09 14:31:56 ----A---- C:\Windows\system32\ieui.dll
2015-12-09 14:31:56 ----A---- C:\Windows\system32\dxtrans.dll
2015-12-09 14:31:52 ----A---- C:\Windows\system32\mshtml.dll

======List of files/folders modified in the last 1 month======

2016-01-01 20:01:09 ----D---- C:\Windows\Temp
2016-01-01 19:28:15 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2016-01-01 19:26:58 ----D---- C:\Users\uživatel\AppData\Roaming\Skype
2016-01-01 19:24:37 ----D---- C:\Windows\System32
2016-01-01 19:24:30 ----D---- C:\ProgramData\Oracle
2016-01-01 19:24:24 ----SHD---- C:\Windows\Installer
2016-01-01 19:23:56 ----D---- C:\Program Files\Common Files
2016-01-01 19:22:59 ----A---- C:\Windows\system32\WindowsAccessBridge.dll
2016-01-01 19:22:23 ----D---- C:\Program Files\Java
2016-01-01 19:12:00 ----D---- C:\Windows
2016-01-01 19:12:00 ----D---- C:\Program Files\Spybot - Search & Destroy 2
2016-01-01 19:05:23 ----A---- C:\Windows\wininit.ini
2016-01-01 19:05:17 ----SD---- C:\ProgramData\Microsoft
2016-01-01 19:05:16 ----D---- C:\Windows\Tasks
2016-01-01 18:48:36 ----HD---- C:\ProgramData
2016-01-01 18:17:53 ----RSD---- C:\Windows\assembly
2016-01-01 18:16:09 ----D---- C:\Windows\Microsoft.NET
2016-01-01 18:12:59 ----SHD---- C:\System Volume Information
2016-01-01 18:09:48 ----D---- C:\Windows\Logs
2016-01-01 17:28:31 ----RD---- C:\Program Files
2016-01-01 09:45:45 ----D---- C:\ProgramData\Skype
2015-12-28 10:58:39 ----D---- C:\Windows\system32\catroot2
2015-12-25 14:57:02 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-12-18 12:14:06 ----D---- C:\Windows\system32\MRT
2015-12-18 11:52:14 ----A---- C:\Windows\system32\mrt.exe
2015-12-10 13:33:56 ----D---- C:\Windows\rescache
2015-12-10 13:03:34 ----D---- C:\Program Files\Microsoft Silverlight
2015-12-10 12:56:48 ----D---- C:\Windows\system32\XPSViewer
2015-12-10 12:56:48 ----D---- C:\Windows\system32\migration
2015-12-10 12:56:48 ----D---- C:\Program Files\Internet Explorer
2015-12-10 12:56:46 ----D---- C:\Windows\system32\cs-CZ
2015-12-10 12:56:46 ----D---- C:\Windows\inf
2015-12-10 12:56:45 ----D---- C:\Windows\system32\drivers
2015-12-10 12:38:05 ----D---- C:\Windows\winsxs
2015-12-10 12:38:02 ----D---- C:\Windows\system32\catroot
2015-12-09 04:39:28 ----N---- C:\Windows\system32\MpSigStub.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2015-03-04 245096]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2012-03-10 242240]
R2 BstHdDrv;BlueStacks Hypervisor; \??\C:\Program Files\BlueStacks\HD-Hypervisor-x86.sys [2015-03-24 130776]
R2 irda;IrDA Protocol; C:\Windows\system32\DRIVERS\irda.sys [2008-04-05 95744]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2010-11-01 12672]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2015-03-04 95408]
R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2010-11-01 8192]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2007-07-22 180736]
R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2010-11-01 985600]
R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2010-11-01 207360]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2010-11-01 2044896]
R3 NETw4v32;Ovladač adaptéru Intel(R) Wireless WiFi Link pro systém Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw4v32.sys [2007-09-26 2251776]
R3 NSCIRDA;NSC Infrared Device Driver; C:\Windows\system32\DRIVERS\nscirda.sys [2008-04-05 30720]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-04-11 89088]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2007-10-01 1769984]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2010-11-01 659968]
R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys [2012-07-26 66560]
S3 AF15BDA;AF9015 BDA Device; C:\Windows\system32\DRIVERS\AF15BDA.sys [2009-06-03 483200]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2008-04-05 92160]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2011-04-21 508416]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-06-17 30208]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2010-11-01 81448]
S3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\drivers\btwavdt.sys [2010-11-01 99880]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2010-11-01 28464]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2010-11-01 17448]
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\Windows\System32\Drivers\btwusb.sys [2007-03-23 67960]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-04-05 5632]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 HSFHWAZL;HSFHWAZL; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2008-04-05 200704]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-04-05 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-04-05 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-04-05 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-04-05 6016]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
S3 UIUSys;Conexant Setup API; C:\Windows\system32\DRIVERS\UIUSYS.SYS []
S3 USBNumPad;Numberpad USB Keyboard; C:\Windows\System32\Drivers\USBNumPad.sys [2007-03-19 9600]
S3 usbvideo;Zobrazovací zařízení USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-04-05 134016]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 155136]
S4 ErrDev;Ovladače chybového zařízení hardwaru Microsoft; C:\Windows\system32\drivers\errdev.sys [2008-04-05 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-04-05 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service; C:\Program Files\BlueStacks\HD-LogRotatorService.exe [2015-03-24 388824]
R2 BstHdUpdaterSvc;BlueStacks Updater Service; C:\Program Files\BlueStacks\HD-UpdaterService.exe [2015-03-24 798424]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-04-05 21504]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2007-11-01 794624]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-04-05 21504]
R2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2008-04-05 21504]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2015-04-30 22216]
R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2010-11-01 386560]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2015-04-30 284504]
S2 BstHdAndroidSvc;BlueStacks Android Service; C:\Program Files\BlueStacks\HD-Service.exe [2015-03-24 433880]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2007-11-01 483328]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2015-07-09 327296]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2016-01-01 269504]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2014-04-11 772296]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2014-04-11 45744]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-11 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-11 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-11 139944]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pomaly start systemu Windows a plochy

#6 Příspěvek od Rudy »

Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3381152194-3172404285-1880440078-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3381152194-3172404285-1880440078-1000UA.job
C:\Windows\system32\msbkvoya.vbe
C:\Windows\system32\mnceenlc.vbe
C:\Windows\system32\mncebxu.vbe
C:\Windows\system32\msbwfu.vbe
C:\Windows\inf\mskout.vbe
C:\Windows\system32\msqnbu.vbe
C:\Windows\inf\msstp.vbe
C:\Windows\inf\ntvdm.vbe

:reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mncebxuSrv]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mnceenlcSrv]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msbkvoyaSrv]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msbwfuSrv]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mskoutSrv]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msqnbuSrv]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSStp]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NtVdmSrv]

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

CZDaywalker
Návštěvník
Návštěvník
Příspěvky: 191
Registrován: 25 úno 2008 07:58

Re: Pomaly start systemu Windows a plochy

#7 Příspěvek od CZDaywalker »

log z OTM:

All processes killed
========== FILES ==========
File/Folder C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3381152194-3172404285-1880440078-1000Core.job not found.
File/Folder C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3381152194-3172404285-1880440078-1000UA.job not found.
File/Folder C:\Windows\system32\msbkvoya.vbe not found.
File/Folder C:\Windows\system32\mnceenlc.vbe not found.
File/Folder C:\Windows\system32\mncebxu.vbe not found.
File/Folder C:\Windows\system32\msbwfu.vbe not found.
File/Folder C:\Windows\inf\mskout.vbe not found.
File/Folder C:\Windows\system32\msqnbu.vbe not found.
File/Folder C:\Windows\inf\msstp.vbe not found.
File/Folder C:\Windows\inf\ntvdm.vbe not found.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mncebxuSrv\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mnceenlcSrv\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msbkvoyaSrv\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msbwfuSrv\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mskoutSrv\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msqnbuSrv\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSStp\ not found.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NtVdmSrv\ not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

User: uživatel
->Temp folder emptied: 31832 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 6690653 bytes
->Flash cache emptied: 1216 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 71068800 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 8708613 bytes
%systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 741 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 83,00 mb


[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Public

User: uživatel
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0,00 mb


OTM by OldTimer - Version 3.1.21.0 log created on 01012016_204957

Files moved on Reboot...
File C:\Users\uživatel\AppData\Local\Temp\etilqs_okuxoWz1Z22evJs not found!
File C:\Windows\temp\TMP0000004CBB846049065D8C5D not found!

Registry entries deleted on Reboot...

CZDaywalker
Návštěvník
Návštěvník
Příspěvky: 191
Registrován: 25 úno 2008 07:58

Re: Pomaly start systemu Windows a plochy

#8 Příspěvek od CZDaywalker »

RSIT log:

Logfile of random's system information tool 1.10 (written by random/random)
Run by uživatel at 2016-01-01 21:05:18
Microsoft® Windows Vista™ Home Basic Service Pack 2
System drive C: has 143 GB (62%) free of 228 GB
Total RAM: 2038 MB (44% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:08:06, on 1.1.2016
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16723)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\PLFSetL.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\BlueStacks\HD-Agent.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Users\uživatel\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Labtec NumPad\Magickey.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\mobsync.exe
C:\Users\UIVATE~1\AppData\Local\Temp\RtkBtMnt.exe
C:\Users\uživatel\Desktop\RSIT.exe
C:\Program Files\trend micro\uživatel.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_66\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_66\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [PLFSetL] C:\Windows\PLFSetL.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Printsrv] c:\Windows\System32\Printing_Admin_Scripts\en-US\driverupd.vbs
O4 - HKLM\..\Run: [BlueStacks Agent] C:\Program Files\BlueStacks\HD-Agent.exe
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [Google Update] "C:\Users\uživatel\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [SpybotPostWindows10UpgradeReInstall] "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Enable Labtec NumPad.lnk = C:\Program Files\Labtec NumPad\Magickey.exe
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: BlueStacks Android Service (BstHdAndroidSvc) - BlueStack Systems, Inc. - C:\Program Files\BlueStacks\HD-Service.exe
O23 - Service: BlueStacks Log Rotator Service (BstHdLogRotatorSvc) - BlueStack Systems, Inc. - C:\Program Files\BlueStacks\HD-LogRotatorService.exe
O23 - Service: BlueStacks Updater Service (BstHdUpdaterSvc) - BlueStack Systems, Inc. - C:\Program Files\BlueStacks\HD-UpdaterService.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 5864 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_66\bin\ssv.dll [2016-01-01 460384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_66\bin\jp2ssv.dll [2016-01-01 172640]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-04-05 1008184]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2010-11-01 4853760]
"PLFSetL"=C:\Windows\PLFSetL.exe [2007-07-05 94208]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-02-11 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-02-11 166424]
"Persistence"=C:\Windows\system32\igfxpers.exe [2008-02-11 133656]
"Printsrv"=c:\Windows\System32\Printing_Admin_Scripts\en-US\driverupd.vbs [2013-12-04 559]
"BlueStacks Agent"=C:\Program Files\BlueStacks\HD-Agent.exe [2015-03-24 863960]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2015-04-29 981688]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\uživatel\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-30 144200]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2012-02-13 3481408]
"SpybotPostWindows10UpgradeReInstall"=C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [2015-07-28 1011200]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2015-12-17 50378880]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
Enable Labtec NumPad.lnk - C:\Program Files\Labtec NumPad\Magickey.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2008-02-11 204800]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.FPS1"=frapsvid.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-01-01 20:44:17 ----D---- C:\_OTM
2016-01-01 20:25:23 ----A---- C:\Windows\system32\drivers\flash.sys
2016-01-01 19:23:56 ----D---- C:\Program Files\Common Files\Java
2016-01-01 19:23:39 ----D---- C:\Users\uživatel\AppData\Roaming\Sun
2016-01-01 18:44:38 ----D---- C:\AdwCleaner
2016-01-01 18:20:20 ----A---- C:\Windows\system32\XAudio2_7.dll
2016-01-01 18:20:20 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2016-01-01 18:20:19 ----A---- C:\Windows\system32\xactengine3_7.dll
2016-01-01 18:20:18 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2016-01-01 18:20:17 ----A---- C:\Windows\system32\d3dcsx_43.dll
2016-01-01 18:20:16 ----A---- C:\Windows\system32\d3dx11_43.dll
2016-01-01 18:20:16 ----A---- C:\Windows\system32\d3dx10_43.dll
2016-01-01 18:20:15 ----A---- C:\Windows\system32\D3DX9_43.dll
2016-01-01 18:20:12 ----A---- C:\Windows\system32\XAudio2_6.dll
2016-01-01 18:20:12 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2016-01-01 18:20:10 ----A---- C:\Windows\system32\xactengine3_6.dll
2016-01-01 18:20:10 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2016-01-01 18:20:09 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2016-01-01 18:20:08 ----A---- C:\Windows\system32\XAudio2_5.dll
2016-01-01 18:20:07 ----A---- C:\Windows\system32\xactengine3_5.dll
2016-01-01 18:20:07 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2016-01-01 18:20:05 ----A---- C:\Windows\system32\d3dcsx_42.dll
2016-01-01 18:20:00 ----A---- C:\Windows\system32\d3dx11_42.dll
2016-01-01 18:19:59 ----A---- C:\Windows\system32\d3dx10_42.dll
2016-01-01 18:19:58 ----A---- C:\Windows\system32\d3dx10_41.dll
2016-01-01 18:19:58 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2016-01-01 18:19:57 ----A---- C:\Windows\system32\D3DX9_41.dll
2016-01-01 18:19:52 ----A---- C:\Windows\system32\XAudio2_4.dll
2016-01-01 18:19:51 ----A---- C:\Windows\system32\xactengine3_4.dll
2016-01-01 18:19:50 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2016-01-01 18:19:50 ----A---- C:\Windows\system32\d3dx10_40.dll
2016-01-01 18:19:50 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2016-01-01 18:19:49 ----A---- C:\Windows\system32\D3DX9_40.dll
2016-01-01 18:19:45 ----A---- C:\Windows\system32\XAudio2_3.dll
2016-01-01 18:19:45 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2016-01-01 18:19:39 ----A---- C:\Windows\system32\xactengine3_3.dll
2016-01-01 18:19:38 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2016-01-01 18:19:37 ----A---- C:\Windows\system32\XAudio2_2.dll
2016-01-01 18:19:37 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2016-01-01 18:19:36 ----A---- C:\Windows\system32\xactengine3_2.dll
2016-01-01 18:19:35 ----A---- C:\Windows\system32\d3dx10_39.dll
2016-01-01 18:19:35 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2016-01-01 18:19:31 ----A---- C:\Windows\system32\D3DX9_39.dll
2016-01-01 18:19:27 ----A---- C:\Windows\system32\XAudio2_1.dll
2016-01-01 18:19:27 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2016-01-01 18:19:26 ----A---- C:\Windows\system32\xactengine3_1.dll
2016-01-01 18:19:26 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2016-01-01 18:19:25 ----A---- C:\Windows\system32\d3dx10_38.dll
2016-01-01 18:19:25 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2016-01-01 18:19:24 ----A---- C:\Windows\system32\D3DX9_38.dll
2016-01-01 18:19:21 ----A---- C:\Windows\system32\XAudio2_0.dll
2016-01-01 18:19:20 ----A---- C:\Windows\system32\xactengine3_0.dll
2016-01-01 18:19:19 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2016-01-01 18:19:19 ----A---- C:\Windows\system32\d3dx10_37.dll
2016-01-01 18:19:19 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2016-01-01 18:19:16 ----A---- C:\Windows\system32\D3DX9_37.dll
2016-01-01 18:19:12 ----A---- C:\Windows\system32\xactengine2_10.dll
2016-01-01 18:19:11 ----A---- C:\Windows\system32\d3dx10_36.dll
2016-01-01 18:19:11 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2016-01-01 18:19:09 ----A---- C:\Windows\system32\d3dx9_36.dll
2016-01-01 18:19:04 ----A---- C:\Windows\system32\xactengine2_9.dll
2016-01-01 18:19:04 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2016-01-01 18:19:04 ----A---- C:\Windows\system32\d3dx10_35.dll
2016-01-01 18:19:04 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2016-01-01 18:19:01 ----A---- C:\Windows\system32\d3dx9_35.dll
2016-01-01 18:18:38 ----A---- C:\Windows\system32\xactengine2_8.dll
2016-01-01 18:18:38 ----A---- C:\Windows\system32\d3dx10_34.dll
2016-01-01 18:18:38 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2016-01-01 18:18:36 ----A---- C:\Windows\system32\d3dx9_34.dll
2016-01-01 18:18:30 ----A---- C:\Windows\system32\xinput1_3.dll
2016-01-01 18:18:28 ----A---- C:\Windows\system32\xactengine2_7.dll
2016-01-01 18:18:28 ----A---- C:\Windows\system32\d3dx10_33.dll
2016-01-01 18:18:27 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2016-01-01 18:18:25 ----A---- C:\Windows\system32\d3dx9_33.dll
2016-01-01 18:18:21 ----A---- C:\Windows\system32\xactengine2_6.dll
2016-01-01 18:18:14 ----A---- C:\Windows\system32\xactengine2_5.dll
2016-01-01 18:18:12 ----A---- C:\Windows\system32\d3dx9_32.dll
2016-01-01 18:18:12 ----A---- C:\Windows\system32\d3dx10.dll
2016-01-01 18:18:02 ----A---- C:\Windows\system32\xactengine2_4.dll
2016-01-01 18:18:01 ----A---- C:\Windows\system32\x3daudio1_1.dll
2016-01-01 18:17:59 ----A---- C:\Windows\system32\xactengine2_3.dll
2016-01-01 18:17:58 ----A---- C:\Windows\system32\xinput1_2.dll
2016-01-01 18:17:55 ----A---- C:\Windows\system32\xactengine2_2.dll
2016-01-01 18:17:54 ----A---- C:\Windows\system32\xinput1_1.dll
2016-01-01 18:17:53 ----A---- C:\Windows\system32\xactengine2_1.dll
2016-01-01 18:17:37 ----A---- C:\Windows\system32\d3dx9_30.dll
2016-01-01 18:17:31 ----A---- C:\Windows\system32\xactengine2_0.dll
2016-01-01 18:17:31 ----A---- C:\Windows\system32\x3daudio1_0.dll
2016-01-01 18:17:28 ----A---- C:\Windows\system32\d3dx9_29.dll
2016-01-01 18:17:23 ----A---- C:\Windows\system32\d3dx9_28.dll
2016-01-01 18:17:18 ----A---- C:\Windows\system32\d3dx9_27.dll
2016-01-01 18:17:14 ----A---- C:\Windows\system32\d3dx9_26.dll
2016-01-01 18:17:09 ----A---- C:\Windows\system32\d3dx9_25.dll
2016-01-01 18:17:00 ----A---- C:\Windows\system32\d3dx9_24.dll
2016-01-01 18:09:51 ----D---- C:\Windows\system32\directx
2016-01-01 17:28:31 ----D---- C:\Program Files\trend micro
2016-01-01 17:28:30 ----D---- C:\rsit
2016-01-01 17:28:19 ----A---- C:\RSIT.exe
2016-01-01 09:45:34 ----D---- C:\Program Files\Common Files\Skype
2016-01-01 09:45:33 ----RD---- C:\Program Files\Skype
2015-12-25 15:02:10 ----D---- C:\Fraps
2015-12-17 14:03:25 ----D---- C:\Users\uživatel\AppData\Roaming\Mozilla
2015-12-10 12:56:45 ----D---- C:\7d5b56e9cba49c1900af45d25653
2015-12-10 12:37:44 ----A---- C:\Windows\system32\d3d10warp.dll
2015-12-10 12:37:44 ----A---- C:\Windows\system32\d3d10level9.dll
2015-12-10 12:37:44 ----A---- C:\Windows\system32\d3d10core.dll
2015-12-10 12:37:44 ----A---- C:\Windows\system32\d3d10_1core.dll
2015-12-10 12:37:44 ----A---- C:\Windows\system32\d3d10_1.dll
2015-12-10 12:37:44 ----A---- C:\Windows\system32\d2d1.dll
2015-12-10 12:37:43 ----A---- C:\Windows\system32\win32k.sys
2015-12-10 12:37:43 ----A---- C:\Windows\system32\user32.dll
2015-12-10 12:37:43 ----A---- C:\Windows\system32\d3d10.dll
2015-12-10 12:37:42 ----A---- C:\Windows\system32\FntCache.dll
2015-12-10 12:37:42 ----A---- C:\Windows\system32\DWrite.dll
2015-12-10 12:35:42 ----A---- C:\Windows\system32\els.dll
2015-12-10 12:33:22 ----A---- C:\Windows\system32\tzres.dll
2015-12-10 12:32:10 ----A---- C:\Windows\system32\comsvcs.dll
2015-12-10 12:32:07 ----A---- C:\Windows\system32\catsrvut.dll
2015-12-10 12:30:43 ----A---- C:\Windows\system32\drivers\rmcast.sys
2015-12-09 14:32:05 ----A---- C:\Windows\system32\mshta.exe
2015-12-09 14:32:04 ----A---- C:\Windows\system32\vbscript.dll
2015-12-09 14:32:04 ----A---- C:\Windows\system32\msfeedsbs.dll
2015-12-09 14:32:04 ----A---- C:\Windows\system32\jsproxy.dll
2015-12-09 14:32:04 ----A---- C:\Windows\system32\dxtmsft.dll
2015-12-09 14:32:03 ----A---- C:\Windows\system32\urlmon.dll
2015-12-09 14:32:03 ----A---- C:\Windows\system32\msfeedssync.exe
2015-12-09 14:32:02 ----A---- C:\Windows\system32\msfeeds.dll
2015-12-09 14:32:02 ----A---- C:\Windows\system32\jscript.dll
2015-12-09 14:32:01 ----A---- C:\Windows\system32\url.dll
2015-12-09 14:32:01 ----A---- C:\Windows\system32\ieUnatt.exe
2015-12-09 14:32:01 ----A---- C:\Windows\system32\iertutil.dll
2015-12-09 14:31:59 ----A---- C:\Windows\system32\wininet.dll
2015-12-09 14:31:59 ----A---- C:\Windows\system32\jscript9.dll
2015-12-09 14:31:58 ----A---- C:\Windows\system32\ieframe.dll
2015-12-09 14:31:57 ----A---- C:\Windows\system32\mshtmled.dll
2015-12-09 14:31:56 ----A---- C:\Windows\system32\ieui.dll
2015-12-09 14:31:56 ----A---- C:\Windows\system32\dxtrans.dll
2015-12-09 14:31:52 ----A---- C:\Windows\system32\mshtml.dll

======List of files/folders modified in the last 1 month======

2016-01-01 21:08:06 ----D---- C:\Windows\Temp
2016-01-01 21:06:33 ----D---- C:\Users\uživatel\AppData\Roaming\Skype
2016-01-01 20:49:59 ----D---- C:\Windows
2016-01-01 20:47:15 ----D---- C:\Windows\System32
2016-01-01 20:47:15 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-01-01 20:44:18 ----D---- C:\Windows\Tasks
2016-01-01 20:44:18 ----D---- C:\Windows\inf
2016-01-01 20:25:23 ----D---- C:\Windows\system32\drivers
2016-01-01 19:28:15 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2016-01-01 19:24:30 ----D---- C:\ProgramData\Oracle
2016-01-01 19:24:24 ----SHD---- C:\Windows\Installer
2016-01-01 19:23:56 ----D---- C:\Program Files\Common Files
2016-01-01 19:22:59 ----A---- C:\Windows\system32\WindowsAccessBridge.dll
2016-01-01 19:22:23 ----D---- C:\Program Files\Java
2016-01-01 19:12:00 ----D---- C:\Program Files\Spybot - Search & Destroy 2
2016-01-01 19:05:23 ----A---- C:\Windows\wininit.ini
2016-01-01 19:05:17 ----SD---- C:\ProgramData\Microsoft
2016-01-01 18:48:36 ----HD---- C:\ProgramData
2016-01-01 18:17:53 ----RSD---- C:\Windows\assembly
2016-01-01 18:16:09 ----D---- C:\Windows\Microsoft.NET
2016-01-01 18:12:59 ----SHD---- C:\System Volume Information
2016-01-01 18:09:48 ----D---- C:\Windows\Logs
2016-01-01 17:28:31 ----RD---- C:\Program Files
2016-01-01 09:45:45 ----D---- C:\ProgramData\Skype
2015-12-28 10:58:39 ----D---- C:\Windows\system32\catroot2
2015-12-18 12:14:06 ----D---- C:\Windows\system32\MRT
2015-12-18 11:52:14 ----A---- C:\Windows\system32\mrt.exe
2015-12-10 13:33:56 ----D---- C:\Windows\rescache
2015-12-10 13:03:34 ----D---- C:\Program Files\Microsoft Silverlight
2015-12-10 12:56:48 ----D---- C:\Windows\system32\XPSViewer
2015-12-10 12:56:48 ----D---- C:\Windows\system32\migration
2015-12-10 12:56:48 ----D---- C:\Program Files\Internet Explorer
2015-12-10 12:56:46 ----D---- C:\Windows\system32\cs-CZ
2015-12-10 12:38:05 ----D---- C:\Windows\winsxs
2015-12-10 12:38:02 ----D---- C:\Windows\system32\catroot
2015-12-09 04:39:28 ----N---- C:\Windows\system32\MpSigStub.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2015-03-04 245096]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2012-03-10 242240]
R2 BstHdDrv;BlueStacks Hypervisor; \??\C:\Program Files\BlueStacks\HD-Hypervisor-x86.sys [2015-03-24 130776]
R2 irda;IrDA Protocol; C:\Windows\system32\DRIVERS\irda.sys [2008-04-05 95744]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2010-11-01 12672]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2015-03-04 95408]
R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2010-11-01 8192]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2007-07-22 180736]
R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2010-11-01 985600]
R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2010-11-01 207360]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2010-11-01 2044896]
R3 NETw4v32;Ovladač adaptéru Intel(R) Wireless WiFi Link pro systém Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw4v32.sys [2007-09-26 2251776]
R3 NSCIRDA;NSC Infrared Device Driver; C:\Windows\system32\DRIVERS\nscirda.sys [2008-04-05 30720]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-04-11 89088]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2007-10-01 1769984]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2010-11-01 659968]
R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys [2012-07-26 66560]
S3 AF15BDA;AF9015 BDA Device; C:\Windows\system32\DRIVERS\AF15BDA.sys [2009-06-03 483200]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2008-04-05 92160]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2011-04-21 508416]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-06-17 30208]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2010-11-01 81448]
S3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\drivers\btwavdt.sys [2010-11-01 99880]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2010-11-01 28464]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2010-11-01 17448]
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\Windows\System32\Drivers\btwusb.sys [2007-03-23 67960]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-04-05 5632]
S3 flash;flash; \??\C:\Windows\system32\drivers\flash.sys [2016-01-01 8064]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 HSFHWAZL;HSFHWAZL; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2008-04-05 200704]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-04-05 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-04-05 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-04-05 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-04-05 6016]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
S3 UIUSys;Conexant Setup API; C:\Windows\system32\DRIVERS\UIUSYS.SYS []
S3 USBNumPad;Numberpad USB Keyboard; C:\Windows\System32\Drivers\USBNumPad.sys [2007-03-19 9600]
S3 usbvideo;Zobrazovací zařízení USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-04-05 134016]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 155136]
S4 ErrDev;Ovladače chybového zařízení hardwaru Microsoft; C:\Windows\system32\drivers\errdev.sys [2008-04-05 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-04-05 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service; C:\Program Files\BlueStacks\HD-LogRotatorService.exe [2015-03-24 388824]
R2 BstHdUpdaterSvc;BlueStacks Updater Service; C:\Program Files\BlueStacks\HD-UpdaterService.exe [2015-03-24 798424]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-04-05 21504]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-04-05 21504]
R2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2008-04-05 21504]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2015-04-30 22216]
R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2010-11-01 386560]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2015-04-30 284504]
S2 BstHdAndroidSvc;BlueStacks Android Service; C:\Program Files\BlueStacks\HD-Service.exe [2015-03-24 433880]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2007-11-01 794624]
S2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2007-11-01 483328]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2015-07-09 327296]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2016-01-01 269504]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2014-04-11 772296]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2014-04-11 45744]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-11 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-11 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-11 139944]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pomaly start systemu Windows a plochy

#9 Příspěvek od Rudy »

OK. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

CZDaywalker
Návštěvník
Návštěvník
Příspěvky: 191
Registrován: 25 úno 2008 07:58

Re: Pomaly start systemu Windows a plochy

#10 Příspěvek od CZDaywalker »

Bohuzel ne,
Zapnuti probiha asi takto:

Po nabehnuti BIOSu je cca minutu a pul jen black screen, pak se objevi loading screen Vist, kterz trva dalsi minutu a pul. Pak dalsi black screen asi 3 minuty a pak windows logo, uvitani a desktop. Nez se vubec da neco delat, to je tak na dalsi 3 minuty.

Nevim, jestli je to vada HDD, ale po celou dobu sviti kontrolka a disk hrabe...

CZDaywalker
Návštěvník
Návštěvník
Příspěvky: 191
Registrován: 25 úno 2008 07:58

Re: Pomaly start systemu Windows a plochy

#11 Příspěvek od CZDaywalker »

V priloze screen z CrystalDiskInfo a fragmentace disku je cca 45%
Přílohy
disk.jpg
disk.jpg (59.96 KiB) Zobrazeno 2475 x

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pomaly start systemu Windows a plochy

#12 Příspěvek od Rudy »

Disk má několik podezřelých sektorů. Zkuste ještě provést ErrorScan HDTune: http://www.stahuj.centrum.cz/utility_a_ ... -tune-pro/ . Pokud je disk v pořádku, budou všechny políčka zelená. U podezřelých nikdy nevíme, zda jsou opravdu jen podezřelé, nebo vadné.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

CZDaywalker
Návštěvník
Návštěvník
Příspěvky: 191
Registrován: 25 úno 2008 07:58

Re: Pomaly start systemu Windows a plochy

#13 Příspěvek od CZDaywalker »

2 špatné sektory:
Přílohy
disk.jpg
disk.jpg (51.65 KiB) Zobrazeno 2459 x

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pomaly start systemu Windows a plochy

#14 Příspěvek od Rudy »

Jj, je to chyba disku. Korektní řešení je jeho výměna, můžete se ale pokusit o jeho opravu pomocí utility HDAT, která je součástí Hirens´boot CD: http://www.hirensbootcd.org/ . Balík stáhněte, vypalte jako bootovatelné CD (vypalovací utilita je součástí balíku) a pomocí toho CD PC nastartujte. V menu pak zvolte Dos utils>HDD utils>HDAT a spusťte ho. Nechte proběhnout sken a pokud se oprava zdaří, kontrola pomocí HDTune by měla být v pořádku.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

CZDaywalker
Návštěvník
Návštěvník
Příspěvky: 191
Registrován: 25 úno 2008 07:58

Re: Pomaly start systemu Windows a plochy

#15 Příspěvek od CZDaywalker »

Tak scan pres tu utilitu neukazal zadne spatne sektory a cely notebook je ale najednou v dobre kondici = start systemu je za cca 3 minuty (do pouzitelneho stavu).
Prave jede HD PRO error kontrola...

Jeste tam zbyva tato hlaska:
Přílohy
hlaska.jpg
hlaska.jpg (19.05 KiB) Zobrazeno 2446 x

Zamčeno