Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Procesor jde do špiček

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
catr
Návštěvník
Návštěvník
Příspěvky: 19
Registrován: 25 srp 2009 20:10

Procesor jde do špiček

#1 Příspěvek od catr »

Dobrý den, mám starý počítač (Pentium D), ale na něm nově přeinstalovaný systém.
Procesor se najednou zničeho nic vytíží a počítač se lagne. Nějaká služba chvost si bere hodně výkonu. Tak mi prosím poraďte co mám udělat? Není to tím že ty starý pentia tolik topí a že se jen přehřeje? Pastu pod chladičem mám novou.

Děkuji za jakoukoli pomoc. Martin



Logfile of random's system information tool 1.10 (written by random/random)
Run by admin at 2016-04-29 10:02:01
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 133 GB (87%) free of 153 GB
Total RAM: 3071 MB (35% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:02:16, on 29.4.2016
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Users\admin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\admin.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\admin\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EHttpSrv) - ESET - C:\Program Files\ESET\ESET Endpoint Antivirus\ehttpsrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Endpoint Antivirus\x86\ekrn.exe
O23 - Service: ESET SHA Service (eshasrv) - ESET - C:\Program Files\ESET\ESET Endpoint Antivirus\eshasrv.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 5293 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Windows\system32\Dwm.exe"
"taskhost.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Users\admin\AppData\Local\Google\Chrome\Application\chrome.exe"
C:\Users\admin\AppData\Local\Google\Chrome\Application\chrome.exe --type=crashpad-handler /prefetch:7 --no-rate-limit "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel=m --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=50.0.2661.87 --handshake-handle=0xcc
"C:\Users\admin\AppData\Local\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3056.0.1936712569\128040628" --disable-direct-composition --supports-dual-gpus=false --gpu-driver-bug-workarounds=4,12,24,53,64,71 --gpu-vendor-id=0x10de --gpu-device-id=0x0de1 --gpu-driver-vendor=NVIDIA --gpu-driver-version=10.18.13.6472 --ignored=" --type=renderer " /prefetch:2
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\ESET\ESET Endpoint Antivirus\x86\ekrn.exe"
"C:\Program Files\ESET\ESET Endpoint Antivirus\egui.exe" /hide
C:\Windows\SysWOW64\DllHost.exe /Processid:{B366DEBE-645B-43A5-B865-DDD82C345492}
"C:\Users\admin\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,IncidentReportingModuleLoadAnalysis<SafeBrowsingIncidentReportingServiceFeatures,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention --lang=cs --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/BrotliEncoding/Default/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/*CrossDevicePromo/14DaySingleProfile/*DataReductionProxyConfigService/Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StableNumTitleWords15_PostPeriod/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PreRead/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control50pct/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/*SafeBrowsingIncidentReportingServiceFeatures/WithModuleLoadAnalysis/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SafeBrowsingUpdateFrequency/Default/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_03/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*WebFontsIntervention/Enabled/WebRTC-LocalIPPermissionCheck/Enabled/WebRTC-PeerConnectionDTLS1.2/Enabled/ --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="3056.6.337557775\1949419035" /prefetch:1

"C:\Users\admin\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-320702765-1389370669-2285494104-1000Core.job - C:\Users\admin\AppData\Local\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-320702765-1389370669-2285494104-1000UA.job - C:\Users\admin\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2016-04-28 7982112]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\admin\AppData\Local\Google\Update\GoogleUpdate.exe [2016-04-26 154440]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-04-29 10:02:04 ----D---- C:\Program Files\trend micro
2016-04-29 10:02:01 ----D---- C:\rsit
2016-04-29 09:36:33 ----D---- C:\ProgramData\ESET
2016-04-29 09:36:33 ----D---- C:\Program Files\ESET
2016-04-29 08:00:59 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe
2016-04-29 07:20:39 ----D---- C:\Users\admin\AppData\Roaming\Ashampoo
2016-04-29 07:20:33 ----D---- C:\ProgramData\Ashampoo
2016-04-29 07:20:29 ----D---- C:\Program Files (x86)\Ashampoo
2016-04-28 17:31:32 ----D---- C:\ProgramData\NVIDIA
2016-04-28 17:30:15 ----A---- C:\Windows\SYSWOW64\vulkaninfo.exe
2016-04-28 17:30:15 ----A---- C:\Windows\SYSWOW64\vulkan-1.dll
2016-04-28 17:30:15 ----A---- C:\Windows\system32\vulkaninfo.exe
2016-04-28 17:30:15 ----A---- C:\Windows\system32\vulkan-1.dll
2016-04-28 17:29:38 ----D---- C:\Program Files (x86)\VulkanRT
2016-04-28 17:28:41 ----A---- C:\Windows\system32\nvvsvc.exe
2016-04-28 17:28:41 ----A---- C:\Windows\system32\nvsvcr.dll
2016-04-28 17:28:41 ----A---- C:\Windows\system32\nvsvc64.dll
2016-04-28 17:28:41 ----A---- C:\Windows\system32\nvshext.dll
2016-04-28 17:28:41 ----A---- C:\Windows\system32\nvmctray.dll
2016-04-28 17:28:41 ----A---- C:\Windows\system32\nvcpl.dll
2016-04-28 17:28:41 ----A---- C:\Windows\system32\nv3dappshextr.dll
2016-04-28 17:28:41 ----A---- C:\Windows\system32\nv3dappshext.dll
2016-04-28 17:27:53 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2016-04-28 17:27:53 ----A---- C:\Windows\system32\OpenCL.dll
2016-04-28 17:27:29 ----D---- C:\ProgramData\NVIDIA Corporation
2016-04-28 17:26:53 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2016-04-28 17:22:21 ----SHD---- C:\Windows\Installer
2016-04-28 17:22:17 ----D---- C:\ProgramData\Package Cache
2016-04-28 17:21:16 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2016-04-28 17:21:16 ----A---- C:\Windows\SYSWOW64\nvumdshim.dll
2016-04-28 17:21:16 ----A---- C:\Windows\system32\nvwgf2umx.dll
2016-04-28 17:21:16 ----A---- C:\Windows\system32\nvumdshimx.dll
2016-04-28 17:21:15 ----A---- C:\Windows\SYSWOW64\nvptxJitCompiler.dll
2016-04-28 17:21:15 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2016-04-28 17:21:15 ----A---- C:\Windows\system32\nvptxJitCompiler.dll
2016-04-28 17:21:15 ----A---- C:\Windows\system32\nvopencl.dll
2016-04-28 17:21:15 ----A---- C:\Windows\system32\nvoglv64.dll
2016-04-28 17:21:14 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2016-04-28 17:21:14 ----A---- C:\Windows\SYSWOW64\nvoglshim32.dll
2016-04-28 17:21:14 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2016-04-28 17:21:14 ----A---- C:\Windows\SYSWOW64\NvIFR.dll
2016-04-28 17:21:14 ----A---- C:\Windows\SYSWOW64\NvFBC.dll
2016-04-28 17:21:14 ----A---- C:\Windows\SYSWOW64\nvfatbinaryLoader.dll
2016-04-28 17:21:14 ----A---- C:\Windows\system32\nvoglshim64.dll
2016-04-28 17:21:14 ----A---- C:\Windows\system32\nvinitx.dll
2016-04-28 17:21:14 ----A---- C:\Windows\system32\NvIFR64.dll
2016-04-28 17:21:14 ----A---- C:\Windows\system32\NvFBC64.dll
2016-04-28 17:21:14 ----A---- C:\Windows\system32\nvfatbinaryLoader.dll
2016-04-28 17:21:14 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2016-04-28 17:21:13 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2016-04-28 17:21:13 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2016-04-28 17:21:13 ----A---- C:\Windows\system32\nvdispgenco6436472.dll
2016-04-28 17:21:13 ----A---- C:\Windows\system32\nvdispco6436472.dll
2016-04-28 17:21:13 ----A---- C:\Windows\system32\nvd3dumx.dll
2016-04-28 17:21:13 ----A---- C:\Windows\system32\nvcuvid.dll
2016-04-28 17:21:12 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2016-04-28 17:21:12 ----A---- C:\Windows\system32\nvcuda.dll
2016-04-28 17:21:09 ----A---- C:\Windows\system32\nvcompiler.dll
2016-04-28 17:21:08 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2016-04-28 17:21:08 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2016-04-28 17:21:08 ----A---- C:\Windows\system32\nvapi64.dll
2016-04-28 15:15:44 ----D---- C:\0c092e2ac2efce046350466cf1
2016-04-28 15:15:16 ----D---- C:\6db4e5a6cdcc2b26c54773afe839
2016-04-28 15:10:23 ----D---- C:\Program Files\NVIDIA Corporation
2016-04-28 15:09:23 ----D---- C:\NVIDIA
2016-04-28 14:40:22 ----D---- C:\Windows\SYSWOW64\RTCOM
2016-04-28 14:40:22 ----D---- C:\Program Files\Realtek
2016-04-28 14:39:59 ----A---- C:\Windows\system32\SRSWOW64.dll
2016-04-28 14:39:59 ----A---- C:\Windows\system32\SRSTSX64.dll
2016-04-28 14:39:59 ----A---- C:\Windows\system32\SRSTSH64.dll
2016-04-28 14:39:59 ----A---- C:\Windows\system32\SRSHP64.dll
2016-04-28 14:39:59 ----A---- C:\Windows\system32\RtPgEx64.dll
2016-04-28 14:39:59 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2016-04-28 14:39:58 ----A---- C:\Windows\system32\RtkCfg64.dll
2016-04-28 14:39:58 ----A---- C:\Windows\system32\RtkAPO64.dll
2016-04-28 14:39:58 ----A---- C:\Windows\system32\RtkApi64.dll
2016-04-28 14:39:58 ----A---- C:\Windows\system32\RTCOM64.dll
2016-04-28 14:39:58 ----A---- C:\Windows\system32\RP3DHT64.dll
2016-04-28 14:39:58 ----A---- C:\Windows\system32\RP3DAA64.dll
2016-04-28 14:39:58 ----A---- C:\Windows\system32\RCoInst64.dll
2016-04-28 14:39:58 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2016-04-28 14:39:58 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2016-04-28 14:39:57 ----D---- C:\Program Files (x86)\Realtek
2016-04-28 14:39:57 ----A---- C:\Windows\system32\FMAPO64.dll
2016-04-28 14:39:57 ----A---- C:\Windows\system32\AERTAR64.dll
2016-04-28 14:39:57 ----A---- C:\Windows\system32\AERTAC64.dll
2016-04-28 14:39:53 ----HD---- C:\Program Files (x86)\Temp
2016-04-28 14:39:52 ----A---- C:\Windows\RtlExUpd.dll
2016-04-28 14:39:43 ----A---- C:\Windows\Language_trs.ini
2016-04-28 14:37:16 ----A---- C:\Windows\SYSWOW64\CSVer.dll
2016-04-26 16:42:32 ----A---- C:\Windows\AS_Debug.txt
2016-04-26 16:18:38 ----D---- C:\Intel
2016-04-26 16:17:58 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2016-04-26 16:17:58 ----D---- C:\Program Files (x86)\Intel
2016-04-26 15:05:49 ----D---- C:\Windows\Panther
2016-04-26 15:05:37 ----RASH---- C:\BOOTSECT.BAK
2016-04-26 15:05:36 ----SHD---- C:\Boot
2016-04-26 14:21:31 ----A---- C:\Windows\system32\wups2.dll
2016-04-26 14:21:31 ----A---- C:\Windows\system32\wucltux.dll
2016-04-26 14:21:31 ----A---- C:\Windows\system32\wuaueng.dll
2016-04-26 14:21:31 ----A---- C:\Windows\system32\wuauclt.exe
2016-04-26 14:21:24 ----A---- C:\Windows\SYSWOW64\wups.dll
2016-04-26 14:21:24 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2016-04-26 14:21:24 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2016-04-26 14:21:24 ----A---- C:\Windows\system32\wups.dll
2016-04-26 14:21:24 ----A---- C:\Windows\system32\wudriver.dll
2016-04-26 14:21:24 ----A---- C:\Windows\system32\wuapi.dll
2016-04-26 14:21:16 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2016-04-26 14:21:16 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2016-04-26 14:21:16 ----A---- C:\Windows\system32\wuwebv.dll
2016-04-26 14:21:16 ----A---- C:\Windows\system32\wuapp.exe
2016-04-26 14:16:34 ----D---- C:\Users\admin\AppData\Roaming\Identities
2016-04-26 14:16:20 ----SD---- C:\Users\admin\AppData\Roaming\Microsoft
2016-04-26 14:16:20 ----D---- C:\Users\admin\AppData\Roaming\Media Center Programs
2016-04-26 14:16:14 ----SHD---- C:\Recovery
2016-04-26 14:16:14 ----SHD---- C:\ProgramData\Šablony
2016-04-26 14:16:14 ----SHD---- C:\ProgramData\Plocha
2016-04-26 14:16:14 ----SHD---- C:\ProgramData\Oblíbené položky
2016-04-26 14:16:14 ----SHD---- C:\ProgramData\Nabídka Start
2016-04-26 14:16:14 ----SHD---- C:\ProgramData\Dokumenty
2016-04-26 14:16:14 ----SHD---- C:\ProgramData\Data aplikací
2016-04-26 14:09:44 ----D---- C:\Windows\SoftwareDistribution
2016-04-26 14:07:33 ----D---- C:\Windows\Prefetch
2016-04-26 14:06:47 ----ASH---- C:\pagefile.sys
2016-04-26 14:06:46 ----SHD---- C:\System Volume Information
2016-04-26 14:06:46 ----ASH---- C:\hiberfil.sys

======List of files/folders modified in the last 1 month======

2016-04-29 10:02:13 ----D---- C:\Windows\Temp
2016-04-29 10:02:04 ----RD---- C:\Program Files
2016-04-29 09:40:28 ----D---- C:\Windows\inf
2016-04-29 09:39:28 ----D---- C:\Windows\system32\DriverStore
2016-04-29 09:39:28 ----D---- C:\Windows\system32\catroot
2016-04-29 09:39:26 ----D---- C:\Windows\system32\drivers
2016-04-29 09:37:52 ----D---- C:\Windows\system32\config
2016-04-29 09:36:33 ----HD---- C:\ProgramData
2016-04-29 09:30:09 ----D---- C:\Windows\System32
2016-04-29 09:30:09 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-04-29 09:21:37 ----D---- C:\Windows\debug
2016-04-29 08:03:38 ----D---- C:\Windows
2016-04-29 08:01:19 ----D---- C:\Windows\SysWOW64
2016-04-29 07:20:29 ----RD---- C:\Program Files (x86)
2016-04-28 17:28:33 ----D---- C:\Windows\Help
2016-04-28 17:26:32 ----D---- C:\Windows\system32\catroot2
2016-04-28 15:15:44 ----D---- C:\Windows\Logs
2016-04-28 15:08:23 ----D---- C:\Windows\winsxs
2016-04-28 11:12:34 ----SD---- C:\ProgramData\Microsoft
2016-04-26 16:44:10 ----D---- C:\Windows\SYSWOW64\cs-CZ
2016-04-26 16:44:10 ----D---- C:\Windows\system32\cs-CZ
2016-04-26 16:17:54 ----D---- C:\Program Files (x86)\Common Files
2016-04-26 16:06:08 ----D---- C:\Windows\Tasks
2016-04-26 16:06:08 ----D---- C:\Windows\system32\Tasks
2016-04-26 15:05:01 ----D---- C:\Windows\Microsoft.NET
2016-04-26 15:05:00 ----RSD---- C:\Windows\assembly
2016-04-26 15:00:02 ----D---- C:\Windows\system32\wdi
2016-04-26 14:21:47 ----D---- C:\Windows\system32\CodeIntegrity
2016-04-26 14:20:55 ----D---- C:\Windows\system32\restore
2016-04-26 14:16:32 ----SHD---- C:\$Recycle.Bin
2016-04-26 14:16:20 ----RD---- C:\Users
2016-04-26 14:16:14 ----D---- C:\Program Files\Windows NT
2016-04-26 14:15:49 ----D---- C:\Windows\rescache
2016-04-26 14:10:18 ----D---- C:\Windows\system32\sysprep
2016-04-26 14:07:28 ----D---- C:\Windows\CSC

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2015-11-11 186272]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2015-11-11 169744]
R3 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2015-11-11 253752]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2016-04-28 1966624]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2016-04-29 15680]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Endpoint Antivirus\x86\ekrn.exe [2015-11-27 1612000]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2016-03-22 1264064]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2016-03-22 426040]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 EHttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Endpoint Antivirus\ehttpsrv.exe [2015-11-27 43208]
S3 eshasrv;ESET SHA Service; C:\Program Files\ESET\ESET Endpoint Antivirus\eshasrv.exe [2015-11-27 185032]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Procesor jde do špiček

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

catr
Návštěvník
Návštěvník
Příspěvky: 19
Registrován: 25 srp 2009 20:10

Re: Procesor jde do špiček

#3 Příspěvek od catr »

# AdwCleaner v5.115 - Log soubor vytvořen 04/05/2016 o 01:41:57
# Aktualizováno 01/05/2016 by Xplode
# Databáze : 2016-05-04.2 [Server]
# Operační systém : Windows 7 Professional Service Pack 1 (X64)
# Jméno uživatele : admin - OLDMACHINE
# Spuštěno z : C:\Users\admin\Downloads\adwcleaner_5.115.exe
# Volba : Čištění
# Podpora : http://toolslib.net/forum

***** [ Služby ] *****


***** [ Složky ] *****


***** [ Soubory ] *****


***** [ DLLs ] *****


***** [ WMI ] *****


***** [ Zástupci ] *****


***** [ Naplánované úkoly ] *****


***** [ Registr ] *****


***** [ Webové prohlížeče ] *****


*************************

:: "Tracing" odstraněných kláves
:: Nastavení Winsock odstraněno

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [795 bytes] - [04/05/2016 01:41:57]
C:\AdwCleaner\AdwCleaner[S1].txt - [838 bytes] - [04/05/2016 01:39:57]

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [939 bytes] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Procesor jde do špiček

#4 Příspěvek od Rudy »

Toto je OK. Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-320702765-1389370669-2285494104-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-320702765-1389370669-2285494104-1000UA.job

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

catr
Návštěvník
Návštěvník
Příspěvky: 19
Registrován: 25 srp 2009 20:10

Re: Procesor jde do špiček

#5 Příspěvek od catr »

Logfile of random's system information tool 1.10 (written by random/random)
Run by admin at 2016-05-09 16:03:27
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 133 GB (87%) free of 153 GB
Total RAM: 3071 MB (32% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:03:34, on 9.5.2016
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Users\admin\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Users\admin\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Users\admin\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Users\admin\AppData\Local\Google\Update\Install\{29C79FEA-5285-4007-BB3F-4CA8D32CACA2}\50.0.2661.94_50.0.2661.87_chrome_updater.exe
C:\Users\admin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\admin\AppData\Local\Temp\CR_2096E.tmp\setup.exe
C:\Users\admin\AppData\Local\Temp\CR_2096E.tmp\setup.exe
C:\Users\admin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\admin.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\admin\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EHttpSrv) - ESET - C:\Program Files\ESET\ESET Endpoint Antivirus\ehttpsrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Endpoint Antivirus\x86\ekrn.exe
O23 - Service: ESET SHA Service (eshasrv) - ESET - C:\Program Files\ESET\ESET Endpoint Antivirus\eshasrv.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 5727 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files\ESET\ESET Endpoint Antivirus\x86\ekrn.exe"
"C:\Windows\system32\Dwm.exe"
"taskhost.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\ESET\ESET Endpoint Antivirus\egui.exe" /hide
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\notepad.exe" C:\_OTM\MovedFiles\05092016_155701.log
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe"
"C:\Users\admin\AppData\Local\Google\Update\GoogleUpdate.exe" /c
"C:\Users\admin\AppData\Local\Google\Update\GoogleUpdate.exe" /ua /installsource core
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Users\admin\AppData\Local\Google\Update\GoogleUpdate.exe" -Embedding
C:\Windows\system32\sppsvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Users\admin\AppData\Local\Google\Update\Install\{29C79FEA-5285-4007-BB3F-4CA8D32CACA2}\50.0.2661.94_50.0.2661.87_chrome_updater.exe" --multi-install --do-not-launch-chrome
"C:\Users\admin\AppData\Local\Google\Chrome\Application\chrome.exe"
C:\Users\admin\AppData\Local\Google\Chrome\Application\chrome.exe --type=crashpad-handler /prefetch:7 --no-rate-limit "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel=m --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=50.0.2661.87 --handshake-handle=0xcc
"C:\Users\admin\AppData\Local\Temp\CR_2096E.tmp\setup.exe" --install-archive="C:\Users\admin\AppData\Local\Temp\CR_2096E.tmp\CHROME_PATCH.PACKED.7Z" --previous-version="50.0.2661.87" --multi-install --do-not-launch-chrome
C:\Users\admin\AppData\Local\Temp\CR_2096E.tmp\setup.exe --type=crashpad-handler --no-rate-limit "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel=m --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=50.0.2661.94 --handshake-handle=0x10c
"C:\Users\admin\AppData\Local\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="2268.0.1877987041\1330306072" --disable-direct-composition --supports-dual-gpus=false --gpu-driver-bug-workarounds=4,12,24,53,64,71 --gpu-vendor-id=0x10de --gpu-device-id=0x0de1 --gpu-driver-vendor=NVIDIA --gpu-driver-version=10.18.13.6472 --ignored=" --type=renderer " /prefetch:2
"C:\Users\admin\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,IncidentReportingModuleLoadAnalysis<SafeBrowsingIncidentReportingServiceFeatures,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention --lang=cs --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/BrotliEncoding/Default/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/*CrossDevicePromo/14DaySingleProfile/*DataReductionProxyConfigService/Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StableNumTitleWords15_PostPeriod/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PreRead/Default/*QUIC/EnabledPreferAes/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Launch50pct_11011_1_1_10/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/Off/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/*SafeBrowsingIncidentReportingServiceFeatures/WithModuleLoadAnalysis/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_03/*UMA-Uniformity-Trial-10-Percent/group_04/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_06/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*WebFontsIntervention/Enabled/WebRTC-LocalIPPermissionCheck/Enabled/ --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=fetchDeferLateScripts=true,fetchIncreaseFontPriority=true,fetchIncreasePriorities=true --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="2268.2.245445937\488891262" /prefetch:1
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Users\admin\Desktop\RSITx64.exe"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"

======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2016-04-28 7982112]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\admin\AppData\Local\Google\Update\GoogleUpdate.exe [2016-04-26 154440]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-05-09 15:57:01 ----D---- C:\_OTM
2016-05-04 01:39:16 ----D---- C:\AdwCleaner
2016-04-29 10:02:04 ----D---- C:\Program Files\trend micro
2016-04-29 10:02:01 ----D---- C:\rsit
2016-04-29 09:36:33 ----D---- C:\ProgramData\ESET
2016-04-29 09:36:33 ----D---- C:\Program Files\ESET
2016-04-29 08:00:59 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe
2016-04-29 07:20:39 ----D---- C:\Users\admin\AppData\Roaming\Ashampoo
2016-04-29 07:20:33 ----D---- C:\ProgramData\Ashampoo
2016-04-29 07:20:29 ----D---- C:\Program Files (x86)\Ashampoo
2016-04-28 17:31:32 ----D---- C:\ProgramData\NVIDIA
2016-04-28 17:30:15 ----A---- C:\Windows\SYSWOW64\vulkaninfo.exe
2016-04-28 17:30:15 ----A---- C:\Windows\SYSWOW64\vulkan-1.dll
2016-04-28 17:30:15 ----A---- C:\Windows\system32\vulkaninfo.exe
2016-04-28 17:30:15 ----A---- C:\Windows\system32\vulkan-1.dll
2016-04-28 17:29:38 ----D---- C:\Program Files (x86)\VulkanRT
2016-04-28 17:28:41 ----A---- C:\Windows\system32\nvvsvc.exe
2016-04-28 17:28:41 ----A---- C:\Windows\system32\nvsvcr.dll
2016-04-28 17:28:41 ----A---- C:\Windows\system32\nvsvc64.dll
2016-04-28 17:28:41 ----A---- C:\Windows\system32\nvshext.dll
2016-04-28 17:28:41 ----A---- C:\Windows\system32\nvmctray.dll
2016-04-28 17:28:41 ----A---- C:\Windows\system32\nvcpl.dll
2016-04-28 17:28:41 ----A---- C:\Windows\system32\nv3dappshextr.dll
2016-04-28 17:28:41 ----A---- C:\Windows\system32\nv3dappshext.dll
2016-04-28 17:27:53 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2016-04-28 17:27:53 ----A---- C:\Windows\system32\OpenCL.dll
2016-04-28 17:27:29 ----D---- C:\ProgramData\NVIDIA Corporation
2016-04-28 17:26:53 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2016-04-28 17:22:21 ----SHD---- C:\Windows\Installer
2016-04-28 17:22:17 ----D---- C:\ProgramData\Package Cache
2016-04-28 17:21:16 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2016-04-28 17:21:16 ----A---- C:\Windows\SYSWOW64\nvumdshim.dll
2016-04-28 17:21:16 ----A---- C:\Windows\system32\nvwgf2umx.dll
2016-04-28 17:21:16 ----A---- C:\Windows\system32\nvumdshimx.dll
2016-04-28 17:21:15 ----A---- C:\Windows\SYSWOW64\nvptxJitCompiler.dll
2016-04-28 17:21:15 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2016-04-28 17:21:15 ----A---- C:\Windows\system32\nvptxJitCompiler.dll
2016-04-28 17:21:15 ----A---- C:\Windows\system32\nvopencl.dll
2016-04-28 17:21:15 ----A---- C:\Windows\system32\nvoglv64.dll
2016-04-28 17:21:14 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2016-04-28 17:21:14 ----A---- C:\Windows\SYSWOW64\nvoglshim32.dll
2016-04-28 17:21:14 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2016-04-28 17:21:14 ----A---- C:\Windows\SYSWOW64\NvIFR.dll
2016-04-28 17:21:14 ----A---- C:\Windows\SYSWOW64\NvFBC.dll
2016-04-28 17:21:14 ----A---- C:\Windows\SYSWOW64\nvfatbinaryLoader.dll
2016-04-28 17:21:14 ----A---- C:\Windows\system32\nvoglshim64.dll
2016-04-28 17:21:14 ----A---- C:\Windows\system32\nvinitx.dll
2016-04-28 17:21:14 ----A---- C:\Windows\system32\NvIFR64.dll
2016-04-28 17:21:14 ----A---- C:\Windows\system32\NvFBC64.dll
2016-04-28 17:21:14 ----A---- C:\Windows\system32\nvfatbinaryLoader.dll
2016-04-28 17:21:14 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2016-04-28 17:21:13 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2016-04-28 17:21:13 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2016-04-28 17:21:13 ----A---- C:\Windows\system32\nvdispgenco6436472.dll
2016-04-28 17:21:13 ----A---- C:\Windows\system32\nvdispco6436472.dll
2016-04-28 17:21:13 ----A---- C:\Windows\system32\nvd3dumx.dll
2016-04-28 17:21:13 ----A---- C:\Windows\system32\nvcuvid.dll
2016-04-28 17:21:12 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2016-04-28 17:21:12 ----A---- C:\Windows\system32\nvcuda.dll
2016-04-28 17:21:09 ----A---- C:\Windows\system32\nvcompiler.dll
2016-04-28 17:21:08 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2016-04-28 17:21:08 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2016-04-28 17:21:08 ----A---- C:\Windows\system32\nvapi64.dll
2016-04-28 15:15:44 ----D---- C:\0c092e2ac2efce046350466cf1
2016-04-28 15:15:16 ----D---- C:\6db4e5a6cdcc2b26c54773afe839
2016-04-28 15:10:23 ----D---- C:\Program Files\NVIDIA Corporation
2016-04-28 15:09:23 ----D---- C:\NVIDIA
2016-04-28 14:40:22 ----D---- C:\Windows\SYSWOW64\RTCOM
2016-04-28 14:40:22 ----D---- C:\Program Files\Realtek
2016-04-28 14:39:59 ----A---- C:\Windows\system32\SRSWOW64.dll
2016-04-28 14:39:59 ----A---- C:\Windows\system32\SRSTSX64.dll
2016-04-28 14:39:59 ----A---- C:\Windows\system32\SRSTSH64.dll
2016-04-28 14:39:59 ----A---- C:\Windows\system32\SRSHP64.dll
2016-04-28 14:39:59 ----A---- C:\Windows\system32\RtPgEx64.dll
2016-04-28 14:39:59 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2016-04-28 14:39:58 ----A---- C:\Windows\system32\RtkCfg64.dll
2016-04-28 14:39:58 ----A---- C:\Windows\system32\RtkAPO64.dll
2016-04-28 14:39:58 ----A---- C:\Windows\system32\RtkApi64.dll
2016-04-28 14:39:58 ----A---- C:\Windows\system32\RTCOM64.dll
2016-04-28 14:39:58 ----A---- C:\Windows\system32\RP3DHT64.dll
2016-04-28 14:39:58 ----A---- C:\Windows\system32\RP3DAA64.dll
2016-04-28 14:39:58 ----A---- C:\Windows\system32\RCoInst64.dll
2016-04-28 14:39:58 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2016-04-28 14:39:58 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2016-04-28 14:39:57 ----D---- C:\Program Files (x86)\Realtek
2016-04-28 14:39:57 ----A---- C:\Windows\system32\FMAPO64.dll
2016-04-28 14:39:57 ----A---- C:\Windows\system32\AERTAR64.dll
2016-04-28 14:39:57 ----A---- C:\Windows\system32\AERTAC64.dll
2016-04-28 14:39:53 ----HD---- C:\Program Files (x86)\Temp
2016-04-28 14:39:52 ----A---- C:\Windows\RtlExUpd.dll
2016-04-28 14:39:43 ----A---- C:\Windows\Language_trs.ini
2016-04-28 14:37:16 ----A---- C:\Windows\SYSWOW64\CSVer.dll
2016-04-26 16:42:32 ----A---- C:\Windows\AS_Debug.txt
2016-04-26 16:18:38 ----D---- C:\Intel
2016-04-26 16:17:58 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2016-04-26 16:17:58 ----D---- C:\Program Files (x86)\Intel
2016-04-26 15:05:49 ----D---- C:\Windows\Panther
2016-04-26 15:05:37 ----RASH---- C:\BOOTSECT.BAK
2016-04-26 15:05:36 ----SHD---- C:\Boot
2016-04-26 14:21:31 ----A---- C:\Windows\system32\wups2.dll
2016-04-26 14:21:31 ----A---- C:\Windows\system32\wucltux.dll
2016-04-26 14:21:31 ----A---- C:\Windows\system32\wuaueng.dll
2016-04-26 14:21:31 ----A---- C:\Windows\system32\wuauclt.exe
2016-04-26 14:21:24 ----A---- C:\Windows\SYSWOW64\wups.dll
2016-04-26 14:21:24 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2016-04-26 14:21:24 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2016-04-26 14:21:24 ----A---- C:\Windows\system32\wups.dll
2016-04-26 14:21:24 ----A---- C:\Windows\system32\wudriver.dll
2016-04-26 14:21:24 ----A---- C:\Windows\system32\wuapi.dll
2016-04-26 14:21:16 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2016-04-26 14:21:16 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2016-04-26 14:21:16 ----A---- C:\Windows\system32\wuwebv.dll
2016-04-26 14:21:16 ----A---- C:\Windows\system32\wuapp.exe
2016-04-26 14:16:34 ----D---- C:\Users\admin\AppData\Roaming\Identities
2016-04-26 14:16:20 ----SD---- C:\Users\admin\AppData\Roaming\Microsoft
2016-04-26 14:16:20 ----D---- C:\Users\admin\AppData\Roaming\Media Center Programs
2016-04-26 14:16:14 ----SHD---- C:\Recovery
2016-04-26 14:16:14 ----SHD---- C:\ProgramData\Šablony
2016-04-26 14:16:14 ----SHD---- C:\ProgramData\Plocha
2016-04-26 14:16:14 ----SHD---- C:\ProgramData\Oblíbené položky
2016-04-26 14:16:14 ----SHD---- C:\ProgramData\Nabídka Start
2016-04-26 14:16:14 ----SHD---- C:\ProgramData\Dokumenty
2016-04-26 14:16:14 ----SHD---- C:\ProgramData\Data aplikací
2016-04-26 14:09:44 ----D---- C:\Windows\SoftwareDistribution
2016-04-26 14:07:33 ----D---- C:\Windows\Prefetch
2016-04-26 14:06:47 ----ASH---- C:\pagefile.sys
2016-04-26 14:06:46 ----SHD---- C:\System Volume Information
2016-04-26 14:06:46 ----ASH---- C:\hiberfil.sys

======List of files/folders modified in the last 1 month======

2016-05-09 16:03:20 ----D---- C:\Windows\Temp
2016-05-09 15:57:04 ----D---- C:\Windows\Tasks
2016-05-09 15:56:53 ----D---- C:\Windows\System32
2016-05-09 15:56:53 ----D---- C:\Windows\inf
2016-05-09 15:56:53 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-05-09 15:53:18 ----D---- C:\Windows\system32\config
2016-04-29 10:02:04 ----RD---- C:\Program Files
2016-04-29 09:39:28 ----D---- C:\Windows\system32\DriverStore
2016-04-29 09:39:28 ----D---- C:\Windows\system32\catroot
2016-04-29 09:39:26 ----D---- C:\Windows\system32\drivers
2016-04-29 09:36:33 ----HD---- C:\ProgramData
2016-04-29 09:21:37 ----D---- C:\Windows\debug
2016-04-29 08:03:38 ----D---- C:\Windows
2016-04-29 08:01:19 ----D---- C:\Windows\SysWOW64
2016-04-29 07:20:29 ----RD---- C:\Program Files (x86)
2016-04-28 17:28:33 ----D---- C:\Windows\Help
2016-04-28 17:26:32 ----D---- C:\Windows\system32\catroot2
2016-04-28 15:15:44 ----D---- C:\Windows\Logs
2016-04-28 15:08:23 ----D---- C:\Windows\winsxs
2016-04-28 11:12:34 ----SD---- C:\ProgramData\Microsoft
2016-04-26 16:44:10 ----D---- C:\Windows\SYSWOW64\cs-CZ
2016-04-26 16:44:10 ----D---- C:\Windows\system32\cs-CZ
2016-04-26 16:17:54 ----D---- C:\Program Files (x86)\Common Files
2016-04-26 16:06:08 ----D---- C:\Windows\system32\Tasks
2016-04-26 15:05:01 ----D---- C:\Windows\Microsoft.NET
2016-04-26 15:05:00 ----RSD---- C:\Windows\assembly
2016-04-26 15:00:02 ----D---- C:\Windows\system32\wdi
2016-04-26 14:21:47 ----D---- C:\Windows\system32\CodeIntegrity
2016-04-26 14:20:55 ----D---- C:\Windows\system32\restore
2016-04-26 14:16:32 ----SHD---- C:\$Recycle.Bin
2016-04-26 14:16:20 ----RD---- C:\Users
2016-04-26 14:16:14 ----D---- C:\Windows\system32\Recovery
2016-04-26 14:16:14 ----D---- C:\Program Files\Windows NT
2016-04-26 14:15:49 ----D---- C:\Windows\rescache
2016-04-26 14:10:18 ----D---- C:\Windows\system32\sysprep
2016-04-26 14:07:28 ----D---- C:\Windows\CSC

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2015-11-11 186272]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2015-11-11 169744]
R3 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2015-11-11 253752]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2016-04-28 1966624]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2016-04-29 15680]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Endpoint Antivirus\x86\ekrn.exe [2015-11-27 1612000]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2016-03-22 1264064]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2016-03-22 426040]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 EHttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Endpoint Antivirus\ehttpsrv.exe [2015-11-27 43208]
S3 eshasrv;ESET SHA Service; C:\Program Files\ESET\ESET Endpoint Antivirus\eshasrv.exe [2015-11-27 185032]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Procesor jde do špiček

#6 Příspěvek od Rudy »

Smazáno. Znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

catr
Návštěvník
Návštěvník
Příspěvky: 19
Registrován: 25 srp 2009 20:10

Re: Procesor jde do špiček

#7 Příspěvek od catr »

Bohužel ne, ale děkuji za ochotu.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Procesor jde do špiček

#8 Příspěvek od Rudy »

Udělejte ještě kompletní sekn MBAM: http://www.malwarebytes.org/mbam.php a dejte log. Předem nic nemažte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět