Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

google chrome + baterie

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
smejky
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 10 dub 2016 16:16

google chrome + baterie

#1 Příspěvek od smejky »

Dobrý den.
Neznámá havěť mi smazala google chrome a nahradila podobně se tvářícím prohlížečem, avšak s ikonkou IE.
Po reinstalaci chrome problém vymizel.
Zároveň se mi do PC sama nainstalovala aplikace FREE VPN connection. Podařilo se mi ji smazat až CCleanerem. Standardním postupem v nastavení windows nešlo aplikaci odinstalovat.
No ale největší problém představuje nyní nenabíjení baterie notebooku. Ačkoli jsem připojen do sítě, baterie se nenabíjí - toto se objevilo zároveň s problémem s google chrome.
V příloze přikládám log z RSITu.
Info o PC:
Notebook Lenovo X201
WIN 10 32bit

Předem děkuji za pomoc.
Martin
Přílohy
log.pdf
(149.07 KiB) Staženo 35 x

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: google chrome + baterie

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

smejky
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 10 dub 2016 16:16

Re: google chrome + baterie

#3 Příspěvek od smejky »

také zdravím.
LOG v příloze.

Matin
Přílohy
log-adwcleaner.pdf
(55.7 KiB) Staženo 72 x

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: google chrome + baterie

#4 Příspěvek od Rudy »

Logy klidně můžete kopírovat přímo sem do fóra. Teď dejte log FRST: http://forum.viry.cz/viewtopic.php?f=13&t=133100 .
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

smejky
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 10 dub 2016 16:16

Re: google chrome + baterie

#5 Příspěvek od smejky »

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:05-03-2016 01
Ran by user (administrator) on MARTIN_PC (10-04-2016 21:24:29)
Running from C:\Users\user\Desktop
Loaded Profiles: user (Available Profiles: user & DefaultAppPool)
Platform: Microsoft Windows 10 Pro Version 1511 (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\iMController\Service\Lenovo.Modern.ImController.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
(AVG Technologies) C:\Program Files\AVG PC TuneUp\TuneUpUtilitiesService32.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
(AVG Technologies) C:\Program Files\AVG PC TuneUp\TuneUpUtilitiesApp32.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.29.5\GoogleCrashHandler.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\iMController\PluginHost\Lenovo.Modern.ImController.PluginHost.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Lenovo) C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Oracle Corporation) C:\Program Files\Java\jre1.8.0_73\bin\javaw.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_2016.29.13.0_x86__8wekyb3d8bbwe\WinStore.Mobile.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\user\Desktop\FRSTLauncher.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6111312 2015-11-09] (AVAST Software)
HKLM\...\Run: [SynLenovoHelper] => C:\Program Files\Synaptics\SynTP\SynLenovoHelper.exe [126120 2015-09-20] (Synaptics)
HKLM\...\Run: [SDTray] => C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [4127488 2015-06-16] (Safer-Networking Ltd.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3519656 2015-09-20] (Synaptics Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [594992 2016-01-29] (Oracle Corporation)
Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
HKU\S-1-5-21-506022658-3350514639-206302717-1000\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-506022658-3350514639-206302717-1000\...\Run: [Google Photos Backup] => C:\Users\user\AppData\Local\Programs\Google\Google Photos Backup\Google Photos Backup.exe [3791176 2015-12-11] (Google, Inc)
HKU\S-1-5-21-506022658-3350514639-206302717-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6667992 2016-03-11] (Piriform Ltd)
HKU\S-1-5-21-506022658-3350514639-206302717-1000\...\MountPoints2: {52dd5f98-a367-11e4-909f-f0def1050fde} - "E:\DTVP_Launcher.exe"
IFEO\AcroRd32.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\DATABASECOMPARE.EXE: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\effectextractor.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\excel.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\groove.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\infopath.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\lync.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\misc.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\msaccess.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\msoev.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\msotd.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\msoxmled.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\mspub.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\OcPubMgr.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\onenote.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\outlook.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\pdr13.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\powerpnt.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\powersuitestart.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\privacyiconclient.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\shareit.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\SPREADSHEETCOMPARE.EXE: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\Winword.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-08-14] (AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Digital Line Detect.lnk [2015-01-24]
ShortcutTarget: Digital Line Detect.lnk -> C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software )
BootExecute: autocheck autochk * sdnclean.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{abf42d39-3057-4014-a52b-690c12c6e361}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{c90fe104-8aba-4917-9257-1bde567aa1d4}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
HKU\S-1-5-21-506022658-3350514639-206302717-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
HKU\S-1-5-21-506022658-3350514639-206302717-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://stadsear.com/search5
HKU\S-1-5-21-506022658-3350514639-206302717-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/?trackid=sp-006
SearchScopes: HKLM -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKLM -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-506022658-3350514639-206302717-1000 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-506022658-3350514639-206302717-1000 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_73\bin\ssv.dll [2016-02-07] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-08-14] (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-02-07] (Oracle Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation)

FireFox:
========
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin: @java.com/DTPlugin,version=11.73.2 -> C:\Program Files\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll [2016-02-07] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-02-07] (Oracle Corporation)
FF Plugin: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2012-10-01] (Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-10] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-506022658-3350514639-206302717-1000: @tools.google.com/Google Update;version=3 -> C:\Users\user\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-08] (Google Inc.)
FF Plugin HKU\S-1-5-21-506022658-3350514639-206302717-1000: @tools.google.com/Google Update;version=9 -> C:\Users\user\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-08] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2012-10-01] (Microsoft Corporation)
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-11]

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/"
CHR Profile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-07]
CHR Extension: (Dokumenty Google) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-07]
CHR Extension: (Disk Google) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22]
CHR Extension: (YouTube) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-29]
CHR Extension: (Adblock Plus) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-03-11]
CHR Extension: (Vyhledávání Google) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-28]
CHR Extension: (Kami (formerly Notable PDF)) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecnphlgnajanjnkcmbpancdjoidceilk [2016-04-10]
CHR Extension: (Tabulky Google) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-07]
CHR Extension: (Dokumenty Google offline) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15]
CHR Extension: (AdBlock) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-03-21]
CHR Extension: (Avast Online Security) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-04-10]
CHR Extension: (FormApps Chrome Extension) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\ilfoopambfaclfjmpiaijnccgcmbeigi [2016-03-06]
CHR Extension: (Cisco WebEx Extension) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlhmfgmfgeifomenelglieieghnjghma [2016-02-07]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-09]
CHR Extension: (hxxp://www.seznam.cz/) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nphgeidmkmbmehnihdconhbclfgcdodn [2016-02-07]
CHR Extension: (Televize Online) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pcfeebemepipakkhapnhljbcdkagkloh [2016-02-07]
CHR Extension: (Gmail) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]
CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-03-24]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-03-24]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-08-14] (AVAST Software)
S3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [3218624 2015-08-14] (Avast Software)
R2 ImControllerService; C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [36808 2016-01-29] (Lenovo Group Limited)
S4 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [271328 2015-09-29] (Lenovo)
S4 RichVideo; C:\Program Files\CyberLink\Shared files\RichVideo.exe [253776 2014-10-03] (CyberLink)
R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1750712 2015-06-16] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2102496 2015-06-16] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [224712 2015-07-24] (Safer-Networking Ltd.)
S4 ShareItSvc; C:\Program Files\Lenovo\SHAREit\Shareit.Service.exe [31176 2016-01-20] (SHAREit Technologies Co.Ltd)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [208552 2015-09-20] (Synaptics Incorporated)
R2 TuneUp.UtilitiesSvc; C:\Program Files\AVG PC TuneUp\TuneUpUtilitiesService32.exe [2449624 2015-08-04] (AVG Technologies)
R2 UxTuneUp; C:\WINDOWS\System32\uxtuneup.dll [36568 2015-08-04] (AVG Technologies)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [280376 2015-10-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23256 2015-10-30] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [24016 2015-08-14] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [76000 2015-08-14] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [81728 2015-08-14] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49776 2015-08-14] (AVAST Software)
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [794952 2015-11-09] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [435464 2015-11-09] (AVAST Software)
S2 aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [113592 2015-08-14] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [208664 2015-08-14] (AVAST Software)
S3 BtHidBus; C:\WINDOWS\System32\Drivers\BtHidBus.sys [20616 2008-08-01] (IVT Corporation.)
S3 btnetBUs; C:\WINDOWS\System32\Drivers\btnetBus.sys [30088 2008-12-07] ()
R1 ElbyCDIO; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [30616 2013-03-04] (Elaborate Bytes AG)
R2 giveio; C:\WINDOWS\system32\giveio.sys [5248 1996-04-03] () [File not signed]
S3 IvtBtBUs; C:\WINDOWS\System32\Drivers\IvtBtBus.sys [26248 2008-07-02] (IVT Corporation.)
S3 LeadCore_57XX_AutoEjecDiskDrv; C:\WINDOWS\System32\drivers\LeadCore_57XX_AutoEjectCD.sys [14848 2010-04-03] () [File not signed]
R3 NETwNs32; C:\WINDOWS\System32\drivers\Netwsn00.sys [10372096 2015-10-30] (Intel Corporation)
R0 ngvss; C:\WINDOWS\system32\Drivers\ngvss.sys [95112 2015-08-14] (AVAST Software)
S3 PSI; C:\WINDOWS\System32\DRIVERS\psi_mf_x86.sys [16024 2016-02-02] (Secunia)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [26792 2015-09-20] (Synaptics Incorporated)
R2 speedfan; C:\WINDOWS\system32\speedfan.sys [24184 2012-12-29] (Almico Software)
R3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [35288 2013-08-22] (The OpenVPN Project)
R3 TuneUpUtilitiesDrv; C:\Program Files\AVG PC TuneUp\TuneUpUtilitiesDriver32.sys [30632 2015-06-25] (TuneUp Software)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [220752 2015-08-14] (Avast Software)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [37400 2015-10-30] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [246104 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [98648 2015-10-30] (Microsoft Corporation)
R3 WUDFWpdMtp; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [163328 2015-10-30] (Microsoft Corporation)
U3 idsvc; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-04-10 21:24 - 2016-04-10 21:25 - 00020340 _____ C:\Users\user\Desktop\FRST.txt
2016-04-10 21:24 - 2016-04-10 21:24 - 00000000 ____D C:\FRST
2016-04-10 21:22 - 2016-04-10 21:23 - 00112640 _____ (forum.viry.cz) C:\Users\user\Desktop\FRSTLauncher.exe
2016-04-10 21:22 - 2016-04-10 21:22 - 00112640 _____ (forum.viry.cz) C:\Users\user\Downloads\Nepotvrzeno 875602.crdownload
2016-04-10 21:16 - 2016-04-10 21:15 - 01725440 _____ (Farbar) C:\Users\user\Desktop\FRST.exe
2016-04-10 21:15 - 2016-04-10 21:15 - 01725440 _____ (Farbar) C:\Users\user\Downloads\FRST.exe
2016-04-10 18:58 - 2016-04-10 18:58 - 1116601811 _____ C:\Users\user\Downloads\Všichni-prezidentovi-muži-(1.-dabing,-Fiser,-Stepnicka,-Moravec,-1981).avi.4602015683546138624.part
2016-04-10 18:46 - 2016-04-10 18:46 - 00057039 ____T C:\Users\user\Desktop\log-adwcleaner.pdf
2016-04-10 18:30 - 2016-04-10 18:33 - 00000000 ____D C:\AdwCleaner
2016-04-10 18:29 - 2016-04-10 18:29 - 03119168 _____ C:\Users\user\Downloads\adwcleaner_5.109.exe
2016-04-10 17:33 - 2016-04-10 17:33 - 00152647 _____ C:\Users\user\Desktop\log.pdf
2016-04-10 17:11 - 2016-04-10 17:11 - 00022286 _____ C:\Users\user\Desktop\info.txt
2016-04-10 17:10 - 2016-04-10 17:10 - 00085028 _____ C:\Users\user\Desktop\cc_20160410_171037.reg
2016-04-10 17:07 - 2016-04-10 17:08 - 00000000 ____D C:\rsit
2016-04-10 17:07 - 2016-04-10 17:07 - 01107968 _____ C:\Users\user\Downloads\RSIT.exe
2016-04-10 17:07 - 2016-04-10 17:07 - 00000000 ____D C:\Program Files\trend micro
2016-04-10 17:06 - 2016-04-10 17:06 - 05658151 _____ (Swearware) C:\Users\user\Downloads\ComboFix.exe
2016-04-10 17:05 - 2016-04-10 17:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2016-04-10 17:05 - 2016-04-10 17:05 - 00000000 ____D C:\Program Files\CCleaner
2016-04-10 17:04 - 2016-04-10 17:04 - 06868672 _____ (Piriform Ltd) C:\Users\user\Downloads\ccsetup516.exe
2016-04-09 09:47 - 2016-04-09 09:47 - 00000000 ___HD C:\OneDriveTemp
2016-04-09 09:36 - 2016-04-09 09:36 - 02154872 _____ (Microsoft Corporation) C:\WINDOWS\system32\WudfUpdate_01011.dll
2016-04-09 09:30 - 2016-04-09 09:32 - 109262624 _____ (Lenovo ) C:\Users\user\Downloads\Nepotvrzeno 533360.exe
2016-04-09 02:57 - 2016-04-09 18:52 - 00000000 ____D C:\Users\user\Downloads\Concussion (2015) [1080p] [YTS.AG]
2016-04-09 02:56 - 2016-04-09 19:02 - 00000000 ____D C:\Users\user\Downloads\Star Wars Episode VII - The Force Awakens (2015) [1080p] [YTS.AG]
2016-04-09 02:56 - 2016-04-09 02:56 - 00039096 _____ C:\Users\user\Downloads\Concussion (2015) [1080p] [YTS.AG].torrent
2016-04-09 02:55 - 2016-04-09 02:55 - 00022338 _____ C:\Users\user\Downloads\Star Wars- Episode VII - The Force Awakens (2015) [1080p] [YTS.AG].torrent
2016-04-09 02:34 - 2016-04-09 02:34 - 00000258 __RSH C:\Users\user\ntuser.pol
2016-04-09 02:31 - 2016-04-09 02:31 - 00000640 __RSH C:\ProgramData\ntuser.pol
2016-04-09 02:30 - 2016-04-09 02:30 - 00001360 ___RS C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gооglе Сhrоme.lnk
2016-04-09 02:30 - 2016-04-09 02:30 - 00000000 ____D C:\Users\user\AppData\Roaming\SPI
2016-04-09 02:19 - 2016-04-09 02:19 - 00437643 _____ C:\Users\user\Downloads\21194.PDF
2016-03-24 22:03 - 2016-03-24 22:25 - 00000000 ____D C:\Users\user\Downloads\The Danish Girl 2015 1080p BluRay x264 DTS-JYK
2016-03-24 22:03 - 2016-03-24 22:03 - 00017566 _____ C:\Users\user\Downloads\[kat.cr]the.danish.girl.2015.1080p.bluray.x264.dts.jyk.torrent
2016-03-14 23:50 - 2016-03-14 23:50 - 00080719 _____ C:\Users\user\Downloads\0000001724892053_20160229_D_002_000_M_C.pdf
2016-03-14 23:50 - 2016-03-14 23:50 - 00080719 _____ C:\Users\user\Downloads\0000001724892053_20160229_D_002_000_M_C (1).pdf
2016-03-13 18:55 - 2016-03-13 18:55 - 00000000 ____D C:\Users\user\Documents\ProcAlyzer Dumps
2016-03-12 03:53 - 2016-03-12 03:53 - 00000020 ___SH C:\Users\DefaultAppPool\ntuser.ini

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-04-10 21:25 - 2016-02-08 23:15 - 00000978 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-506022658-3350514639-206302717-1000UA.job
2016-04-10 20:53 - 2015-01-18 19:27 - 00000958 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-04-10 20:39 - 2015-08-19 23:20 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-04-10 18:50 - 2016-01-23 15:27 - 00988244 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-04-10 18:50 - 2015-10-30 07:47 - 00000000 ____D C:\WINDOWS\INF
2016-04-10 18:45 - 2015-09-20 22:42 - 00000000 ___RD C:\Users\user\OneDrive
2016-04-10 18:45 - 2015-01-18 19:27 - 00000954 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-04-10 18:43 - 2016-01-23 15:41 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-04-10 18:43 - 2015-10-30 07:13 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2016-04-10 17:09 - 2015-10-30 07:48 - 00000000 ____D C:\WINDOWS\ModemLogs
2016-04-10 17:00 - 2015-09-23 19:35 - 00000000 ____D C:\Users\user\AppData\Roaming\uTorrent
2016-04-10 10:38 - 2015-10-30 07:48 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-04-09 22:25 - 2016-02-08 23:15 - 00000926 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-506022658-3350514639-206302717-1000Core.job
2016-04-09 09:36 - 2015-09-20 22:56 - 00217544 _____ (Lenovo Group Limited) C:\WINDOWS\system32\iMDriverHelper.dll
2016-04-09 09:35 - 2015-04-07 06:20 - 00000000 ____D C:\ProgramData\Package Cache
2016-04-09 03:17 - 2015-01-18 19:28 - 00002301 ____H C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-04-09 03:14 - 2015-10-30 07:48 - 00000000 ___HD C:\Program Files\WindowsApps
2016-04-09 03:14 - 2015-09-20 22:36 - 00000000 ____D C:\Users\user\AppData\Local\Packages
2016-04-09 03:03 - 2015-01-27 05:30 - 00000000 ____D C:\KMPlayer
2016-04-09 02:30 - 2009-07-14 04:37 - 00000000 ____D C:\WINDOWS\system32\GroupPolicy
2016-03-30 20:43 - 2016-02-07 13:40 - 00000000 ____D C:\Users\user\Documents\Priznani_za_2015
2016-03-23 19:51 - 2015-10-30 07:39 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-03-13 18:18 - 2015-11-29 23:41 - 00000000 ____D C:\ProgramData\tmp
2016-03-13 18:14 - 2016-01-23 15:22 - 00353184 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-03-12 23:40 - 2016-03-06 19:37 - 00000000 ____D C:\Users\user\Downloads\Vinyl_S01
2016-03-12 23:39 - 2015-11-09 19:06 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-03-12 03:53 - 2016-01-23 15:28 - 00000000 ____D C:\Users\DefaultAppPool
2016-03-12 03:30 - 2015-10-30 07:48 - 00000000 ____D C:\Program Files\Windows Portable Devices
2016-03-12 03:30 - 2015-10-30 07:48 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
2016-03-11 03:45 - 2015-09-20 22:42 - 00002411 _____ C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk

==================== Files in the root of some directories =======

2015-04-01 02:58 - 2015-04-01 02:58 - 0000000 _____ () C:\Users\user\AppData\Local\{3DE68A71-13F2-4F4B-8234-5E599221031B}
2015-02-25 00:35 - 2015-02-25 00:35 - 0000000 _____ () C:\Users\user\AppData\Local\{7047BA89-2137-4D1C-926E-7B055F428B96}
2015-07-03 08:22 - 2015-07-03 08:22 - 0004128 _____ () C:\ProgramData\bqeojehc.wbx

Some files in TEMP:
====================
C:\Users\user\AppData\Local\Temp\libeay32.dll
C:\Users\user\AppData\Local\Temp\msvcr120.dll
C:\Users\user\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-506022658-3350514639-206302717-1000Core.job => C:\Users\user\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-506022658-3350514639-206302717-1000UA.job => C:\Users\user\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Spybot - Search and Destroy (Enabled - Up to date) {A16C3F68-9280-E053-1818-342707FECF4D}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\user\Desktop" je 2 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\Spybot - Search & Destroy 2\\SDTray.exe"="C:\\Program Files\\Spybot - Search & Destroy 2\\SDTray.exe:*:Enabled:Spybot - Search & Destroy tray access"
"C:\\Program Files\\Spybot - Search & Destroy 2\\SDFSSvc.exe"="C:\\Program Files\\Spybot - Search & Destroy 2\\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service"
"C:\\Program Files\\Spybot - Search & Destroy 2\\SDUpdate.exe"="C:\\Program Files\\Spybot - Search & Destroy 2\\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater"
"C:\\Program Files\\Spybot - Search & Destroy 2\\SDUpdSvc.exe"="C:\\Program Files\\Spybot - Search & Destroy 2\\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]


==================== End Of Log ==============================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: google chrome + baterie

#6 Příspěvek od Rudy »

Otevřte poznámkový blok a zkopírujte do něj:
Start
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [594992 2016-01-29] (Oracle Corporation)
Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
HKU\S-1-5-21-506022658-3350514639-206302717-1000\...\MountPoints2: {52dd5f98-a367-11e4-909f-f0def1050fde} - "E:\DTVP_Launcher.exe"
IFEO\AcroRd32.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\DATABASECOMPARE.EXE: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\effectextractor.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\excel.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\groove.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\infopath.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\lync.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\misc.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\msaccess.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\msoev.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\msotd.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\msoxmled.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\mspub.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\OcPubMgr.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\onenote.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\outlook.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\pdr13.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\powerpnt.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\powersuitestart.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\privacyiconclient.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\shareit.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\SPREADSHEETCOMPARE.EXE: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\Winword.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
HKU\S-1-5-21-506022658-3350514639-206302717-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
HKU\S-1-5-21-506022658-3350514639-206302717-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://stadsear.com/search5
HKU\S-1-5-21-506022658-3350514639-206302717-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/?trackid=sp-006
SearchScopes: HKLM -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKLM -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-506022658-3350514639-206302717-1000 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-506022658-3350514639-206302717-1000 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
U3 idsvc; no ImagePath
C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-506022658-3350514639-206302717-1000UA.job
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-506022658-3350514639-206302717-1000Core.job
C:\ProgramData\bqeojehc.wbx
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

smejky
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 10 dub 2016 16:16

Re: google chrome + baterie

#7 Příspěvek od smejky »

Fix result of Farbar Recovery Scan Tool (x86) Version:05-03-2016 01
Ran by user (2016-04-10 22:43:45) Run:1
Running from C:\Users\user\Desktop
Loaded Profiles: user (Available Profiles: user & DefaultAppPool)
Boot Mode: Normal

==============================================

fixlist content:
*****************
Start
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [594992 2016-01-29] (Oracle Corporation)
Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
HKU\S-1-5-21-506022658-3350514639-206302717-1000\...\MountPoints2: {52dd5f98-a367-11e4-909f-f0def1050fde} - "E:\DTVP_Launcher.exe"
IFEO\AcroRd32.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\DATABASECOMPARE.EXE: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\effectextractor.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\excel.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\groove.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\infopath.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\lync.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\misc.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\msaccess.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\msoev.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\msotd.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\msoxmled.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\mspub.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\OcPubMgr.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\onenote.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\outlook.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\pdr13.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\powerpnt.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\powersuitestart.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\privacyiconclient.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\shareit.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\SPREADSHEETCOMPARE.EXE: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
IFEO\Winword.exe: [Debugger] "C:\Program Files\AVG PC TuneUp\TUAutoReactivator32.exe"
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
HKU\S-1-5-21-506022658-3350514639-206302717-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
HKU\S-1-5-21-506022658-3350514639-206302717-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://stadsear.com/search5
HKU\S-1-5-21-506022658-3350514639-206302717-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/?trackid=sp-006
SearchScopes: HKLM -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKLM -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-506022658-3350514639-206302717-1000 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-506022658-3350514639-206302717-1000 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
U3 idsvc; no ImagePath
C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-506022658-3350514639-206302717-1000UA.job
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-506022658-3350514639-206302717-1000Core.job
C:\ProgramData\bqeojehc.wbx
End
*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value removed successfully.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SDWinLogon" => key removed successfully.
"HKU\S-1-5-21-506022658-3350514639-206302717-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{52dd5f98-a367-11e4-909f-f0def1050fde}" => key removed successfully.
HKCR\CLSID\{52dd5f98-a367-11e4-909f-f0def1050fde} => key not found.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\AcroRd32.exe" => key removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\DATABASECOMPARE.EXE" => key removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\effectextractor.exe" => key removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\excel.exe" => key removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\groove.exe" => key removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\infopath.exe" => key removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\lync.exe" => key removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\misc.exe" => key removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\msaccess.exe" => key removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\msoev.exe" => key removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\msotd.exe" => key removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\msoxmled.exe" => key removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\mspub.exe" => key removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\OcPubMgr.exe" => key removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\onenote.exe" => key removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\outlook.exe" => key removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\pdr13.exe" => key removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\powerpnt.exe" => key removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\powersuitestart.exe" => key removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\privacyiconclient.exe" => key removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\shareit.exe" => key removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\SPREADSHEETCOMPARE.EXE" => key removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Winword.exe" => key removed successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKU\S-1-5-21-506022658-3350514639-206302717-1000\Software\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKU\S-1-5-21-506022658-3350514639-206302717-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKU\S-1-5-21-506022658-3350514639-206302717-1000\Software\Microsoft\Internet Explorer\Main\\Search Bar => value removed successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F}" => key removed successfully.
HKCR\CLSID\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F} => key not found.
HKU\S-1-5-21-506022658-3350514639-206302717-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
"HKU\S-1-5-21-506022658-3350514639-206302717-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F}" => key removed successfully.
HKCR\CLSID\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F} => key not found.
idsvc => service removed successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-506022658-3350514639-206302717-1000UA.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-506022658-3350514639-206302717-1000Core.job => moved successfully
C:\ProgramData\bqeojehc.wbx => moved successfully

==== End of Fixlog 22:43:46 ====

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: google chrome + baterie

#8 Příspěvek od Rudy »

Smazáno. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

smejky
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 10 dub 2016 16:16

Re: google chrome + baterie

#9 Příspěvek od smejky »

Bohužel nenastala. Stále nenabíjí baterie...

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: google chrome + baterie

#10 Příspěvek od Rudy »

Vypadá to na hw problém (vadná baterie - její elektronika, nebo nabíjecí obvody na zákl. desce). Ke zjištění budete ale potřebovat jinou, zaručeně zdravou baterii, stejného typu.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

smejky
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 10 dub 2016 16:16

Re: google chrome + baterie

#11 Příspěvek od smejky »

Děkuji moc za pomoc. Zkusím tedy HW kontolu.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: google chrome + baterie

#12 Příspěvek od Rudy »

OK.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět