Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Vytížený procesor - kontrola logu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Rhonnyn
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 25 kvě 2016 18:40

Vytížený procesor - kontrola logu

#1 Příspěvek od Rhonnyn »

Dobrý den,
mám problém s obrovským vytížením procesoru. Měl bych mít třeba vytížení 5%, ale místo toho mám 70%. Proto bych rád poprosil, jestli byste mi nemohli zkontrolovat log nebo poradit, co s tím mám dělat. Nerad bych celý disk formátoval.

Zde přikládám log, kdyby bylo potřeba:

ComboFix 16-05-18.01 - E a D . 05. 2016 19:14:50.2.4 - x64
Microsoft Windows 8 Pro 6.2.9200.0.1250.420.1029.18.8108.5947 [GMT 2:00]
Spuštěný z: c:\users\E a D\Downloads\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Adobe\adobe_flash_player.exe
c:\programdata\Roaming
c:\windows\wininit.ini
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2016-04-25 do 2016-05-25 )))))))))))))))))))))))))))))))
.
.
2016-05-25 17:23 . 2016-05-25 17:23 -------- d-----w- c:\users\Default\AppData\Local\temp
2016-05-25 16:00 . 2016-05-25 16:00 119808 ----a-r- c:\users\E a D\AppData\Roaming\Microsoft\Installer\{CCF298AF-9CE1-4B26-B251-486E98A34789}\icons.exe
2016-05-25 16:00 . 2016-05-25 16:00 -------- d-----w- c:\users\E a D\AppData\Local\Apps
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-02-27 08:30 . 2014-11-16 09:20 97888 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2016-02-27 08:29 . 2016-02-27 08:29 1721576 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll
2016-02-27 08:29 . 2016-02-27 08:29 111336 ----a-w- c:\windows\system32\drivers\GeneStor.sys
2016-02-27 08:29 . 2016-02-27 08:29 1448248 ----a-w- c:\windows\system32\drivers\btmhsf.sys
2016-02-27 08:28 . 2016-02-27 08:28 548568 ----a-w- c:\windows\system32\RtCamX64.dll
2016-02-27 08:28 . 2016-02-27 08:28 5371608 ----a-w- c:\windows\RTFTrack.exe
2016-02-27 08:28 . 2016-02-27 08:28 486616 ----a-w- c:\windows\SysWow64\RtCamX.dll
2016-02-27 08:28 . 2016-02-27 08:28 3040472 ----a-w- c:\windows\system32\drivers\rtsuvc.sys
2016-02-27 08:28 . 2016-02-27 08:28 2627288 ----a-w- c:\windows\RtCamU64.exe
2016-02-27 08:28 . 2016-02-27 08:28 1971928 ----a-w- c:\windows\SysWow64\RsDecode.dll
2016-02-27 08:28 . 2016-02-27 08:28 1462720 ----a-w- c:\windows\system32\drivers\iaStorA.sys
2016-02-27 08:27 . 2016-02-27 08:27 185088 ----a-w- c:\windows\system32\drivers\TeeDriverW8x64.sys
2016-02-27 08:26 . 2016-02-27 08:26 532384 ----a-w- c:\windows\system32\SRSTSX64.dll
2016-02-27 08:26 . 2016-02-27 08:26 221976 ----a-w- c:\windows\system32\SRSTSH64.dll
2016-02-27 08:26 . 2016-02-27 08:26 209544 ----a-w- c:\windows\system32\SRSHP64.dll
2016-02-27 08:26 . 2016-02-27 08:26 166208 ----a-w- c:\windows\system32\SRSWOW64.dll
2016-02-27 08:26 . 2016-02-27 08:26 965032 ----a-w- c:\windows\system32\SFSS_APO.dll
2016-02-27 08:26 . 2016-02-27 08:26 90920 ----a-w- c:\windows\system32\SFCOM64.dll
2016-02-27 08:26 . 2016-02-27 08:26 88352 ----a-w- c:\windows\system32\RTEEG64A.dll
2016-02-27 08:26 . 2016-02-27 08:26 88328 ----a-w- c:\windows\system32\SFAPO64.dll
2016-02-27 08:26 . 2016-02-27 08:26 84616 ----a-w- c:\windows\system32\R4EEG64A.dll
2016-02-27 08:26 . 2016-02-27 08:26 83632 ----a-w- c:\windows\SysWow64\SFCOM.dll
2016-02-27 08:26 . 2016-02-27 08:26 72203792 ----a-w- c:\windows\system32\RCoRes64.dat
2016-02-27 08:26 . 2016-02-27 08:26 7172920 ----a-w- c:\windows\system32\R4EEP64A.dll
2016-02-27 08:26 . 2016-02-27 08:26 689888 ----a-w- c:\windows\system32\RtDataProc64.dll
2016-02-27 08:26 . 2016-02-27 08:26 4705536 ----a-w- c:\windows\system32\drivers\RTKVHD64.sys
2016-02-27 08:26 . 2016-02-27 08:26 447728 ----a-w- c:\windows\system32\R4EED64A.dll
2016-02-27 08:26 . 2016-02-27 08:26 387320 ----a-w- c:\windows\system32\RTEEP64A.dll
2016-02-27 08:26 . 2016-02-27 08:26 343712 ----a-w- c:\windows\system32\RtlCPAPI64.dll
2016-02-27 08:26 . 2016-02-27 08:26 3271912 ----a-w- c:\windows\system32\RtkApi64.dll
2016-02-27 08:26 . 2016-02-27 08:26 321720 ----a-w- c:\windows\system32\RP3DHT64.dll
2016-02-27 08:26 . 2016-02-27 08:26 321720 ----a-w- c:\windows\system32\RP3DAA64.dll
2016-02-27 08:26 . 2016-02-27 08:26 3195648 ----a-w- c:\windows\system32\RtPgEx64.dll
2016-02-27 08:26 . 2016-02-27 08:26 3052880 ----a-w- c:\windows\system32\RltkAPO64.dll
2016-02-27 08:26 . 2016-02-27 08:26 2893568 ----a-w- c:\windows\system32\RTSnMg64.cpl
2016-02-27 08:26 . 2016-02-27 08:26 23696 ----a-w- c:\windows\system32\RtkCoLDR64.dll
2016-02-27 08:26 . 2016-02-27 08:26 231920 ----a-w- c:\windows\system32\SFNHK64.dll
2016-02-27 08:26 . 2016-02-27 08:26 214840 ----a-w- c:\windows\system32\RTEED64A.dll
2016-02-27 08:26 . 2016-02-27 08:26 2030208 ----a-w- c:\windows\system32\RCoInstII64.dll
2016-02-27 08:26 . 2016-02-27 08:26 192992 ----a-w- c:\windows\system32\RtkCfg64.dll
2016-02-27 08:26 . 2016-02-27 08:26 151792 ----a-w- c:\windows\system32\R4EEL64A.dll
2016-02-27 08:26 . 2016-02-27 08:26 1356512 ----a-w- c:\windows\system32\RTCOM64.dll
2016-02-27 08:26 . 2016-02-27 08:26 134208 ----a-w- c:\windows\system32\R4EEA64A.dll
2016-02-27 08:26 . 2016-02-27 08:26 110992 ----a-w- c:\windows\system32\RTEEL64A.dll
2016-02-27 08:26 . 2016-02-27 08:26 708320 ----a-w- c:\windows\system32\DTSVoiceClarityDLL64.dll
2016-02-27 08:26 . 2016-02-27 08:26 678192 ----a-w- c:\windows\system32\MaxxAudioAPO30.dll
2016-02-27 08:26 . 2016-02-27 08:26 677680 ----a-w- c:\windows\system32\MaxxVolumeSDAPO.dll
2016-02-27 08:26 . 2016-02-27 08:26 369304 ----a-w- c:\windows\system32\HiFiDAX2API.dll
2016-02-27 08:26 . 2016-02-27 08:26 330568 ----a-w- c:\windows\system32\MaxxAudioAPO20.dll
2016-02-27 08:26 . 2016-02-27 08:26 3282032 ----a-w- c:\windows\system32\FMAPO64.dll
2016-02-27 08:26 . 2016-02-27 08:26 2050184 ----a-w- c:\windows\system32\MaxxAudioEQ64.dll
2016-02-27 08:26 . 2016-02-27 08:26 727440 ----a-w- c:\windows\system32\DTSSymmetryDLL64.dll
2016-02-27 08:26 . 2016-02-27 08:26 952984 ----a-w- c:\windows\system32\DolbyDAX2APOProp.dll
2016-02-27 08:26 . 2016-02-27 08:26 743968 ----a-w- c:\windows\system32\DTSBassEnhancementDLL64.dll
2016-02-27 08:26 . 2016-02-27 08:26 7096192 ----a-w- c:\windows\system32\DDPP64A.dll
2016-02-27 08:26 . 2016-02-27 08:26 6264640 ----a-w- c:\windows\system32\DDPP64AF3.dll
2016-02-27 08:26 . 2016-02-27 08:26 574760 ----a-w- c:\windows\system32\AERTAC64.dll
2016-02-27 08:26 . 2016-02-27 08:26 5338936 ----a-w- c:\windows\system32\DolbyDAX2APOv211.dll
2016-02-27 08:26 . 2016-02-27 08:26 504312 ----a-w- c:\windows\system32\DTSNeoPCDLL64.dll
2016-02-27 08:26 . 2016-02-27 08:26 445408 ----a-w- c:\windows\system32\DTSLimiterDLL64.dll
2016-02-27 08:26 . 2016-02-27 08:26 441272 ----a-w- c:\windows\system32\DTSGainCompensatorDLL64.dll
2016-02-27 08:26 . 2016-02-27 08:26 362056 ----a-w- c:\windows\system32\DDPO64AF3.dll
2016-02-27 08:26 . 2016-02-27 08:26 327464 ----a-w- c:\windows\system32\DDPO64A.dll
2016-02-27 08:26 . 2016-02-27 08:26 310424 ----a-w- c:\windows\system32\DDPA64F3.dll
2016-02-27 08:26 . 2016-02-27 08:26 272720 ----a-w- c:\windows\system32\DDPA64.dll
2016-02-27 08:26 . 2016-02-27 08:26 253904 ----a-w- c:\windows\system32\DTSGFXAPO64.dll
2016-02-27 08:26 . 2016-02-27 08:26 253872 ----a-w- c:\windows\system32\DTSLFXAPO64.dll
2016-02-27 08:26 . 2016-02-27 08:26 252880 ----a-w- c:\windows\system32\DTSGFXAPONS64.dll
2016-02-27 08:26 . 2016-02-27 08:26 1965816 ----a-w- c:\windows\system32\DDPD64A.dll
2016-02-27 08:26 . 2016-02-27 08:26 1959608 ----a-w- c:\windows\system32\DDPD64AF3.dll
2016-02-27 08:26 . 2016-02-27 08:26 1780624 ----a-w- c:\windows\system32\DTSS2SpeakerDLL64.dll
2016-02-27 08:26 . 2016-02-27 08:26 1591064 ----a-w- c:\windows\system32\DTSS2HeadphoneDLL64.dll
2016-02-27 08:26 . 2016-02-27 08:26 1508936 ----a-w- c:\windows\system32\DTSBoostDLL64.dll
2016-02-27 08:26 . 2016-02-27 08:26 122328 ----a-w- c:\windows\system32\CONEQMSAPOGUILibrary.dll
2016-02-27 08:26 . 2016-02-27 08:26 118600 ----a-w- c:\windows\system32\AERTAR64.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2012-10-01 19:38 1720976 ----a-w- c:\progra~2\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2012-10-01 19:38 1720976 ----a-w- c:\progra~2\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2012-10-01 19:38 1720976 ----a-w- c:\progra~2\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2014-03-04 3696912]
"Steam"="c:\program files (x86)\Steam\Steam.exe" [2016-03-31 3077712]
"cz.seznam.software.autoupdate"="c:\users\E a D\AppData\Roaming\Seznam.cz\szninstall.exe" [2013-05-16 1062472]
"cz.seznam.software.szndesktop"="c:\users\E a D\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" [2015-05-26 103080]
"MK LOL"="c:\program files (x86)\MKJogo\MK IM\Bin\MKIM.exe" [2016-02-21 821752]
"Innkeeper"="c:\users\E a D\AppData\Local\Innkeeper\Update.exe" [2015-11-05 1888136]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2015-11-07 6133520]
"seznam-listicka-distribuce"="c:\program files (x86)\Seznam.cz\distribution\szninstall.exe" [2013-05-16 1062472]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2016-01-29 595504]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\StartUp\
LOLRecorder.lnk - c:\program files (x86)\LOLReplay\LOLRecorder.exe -minimize [2014-5-23 504832]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"PromptOnSecureDesktop"= 0 (0x0)
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableCursorSuppression"= 1 (0x1)
"ConsentPromptBehaviorUser"= 3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R2 VBoxAswDrv;VBoxAsw Support Driver;c:\program files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys;c:\program files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [x]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\System32\Drivers\ssadadb.sys;c:\windows\SYSNATIVE\Drivers\ssadadb.sys [x]
R3 AvastVBoxSvc;AvastVBox COM Service;c:\program files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe;c:\program files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [x]
R3 BthLEEnum;Ovladač úspory energie technologie Bluetooth;c:\windows\system32\DRIVERS\BthLEEnum.sys;c:\windows\SYSNATIVE\DRIVERS\BthLEEnum.sys [x]
R3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys;c:\windows\SYSNATIVE\DRIVERS\btmaux.sys [x]
R3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys;c:\windows\SYSNATIVE\DRIVERS\btmhsf.sys [x]
R3 ETDSMBus;ETDSMBus;c:\windows\system32\DRIVERS\ETDSMBus.sys;c:\windows\SYSNATIVE\DRIVERS\ETDSMBus.sys [x]
R3 GeneStor;Genesys Logic Storage Driver;c:\windows\System32\drivers\GeneStor.sys;c:\windows\SYSNATIVE\drivers\GeneStor.sys [x]
R3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys;c:\windows\SYSNATIVE\DRIVERS\iBtFltCoex.sys [x]
R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys;c:\windows\SYSNATIVE\drivers\intelaud.sys [x]
R3 iumsvc;Intel(R) Update Manager;c:\program files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe;c:\program files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [x]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x]
R3 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 SmbDrvI;SmbDrvI;c:\windows\system32\DRIVERS\Smb_driver_Intel.sys;c:\windows\SYSNATIVE\DRIVERS\Smb_driver_Intel.sys [x]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\System32\drivers\ssadbus.sys;c:\windows\SYSNATIVE\drivers\ssadbus.sys [x]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdfl.sys [x]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdm.sys [x]
R3 vmicheartbeat;Služba prezenčního signálu technologie Hyper-V;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys;c:\windows\SYSNATIVE\DRIVERS\wsvd.sys [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 iaStorA;iaStorA;c:\windows\System32\drivers\iaStorA.sys;c:\windows\SYSNATIVE\drivers\iaStorA.sys [x]
S0 LHDmgr;LHDmgr;c:\windows\System32\DRIVERS\LhdX64.sys;c:\windows\SYSNATIVE\DRIVERS\LhdX64.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\System32\drivers\dtsoftbus01.sys;c:\windows\SYSNATIVE\drivers\dtsoftbus01.sys [x]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [x]
S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [x]
S2 BrcmSetSecurity;BrcmSetSecurity;c:\program files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe;c:\program files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe [x]
S2 ETDService;Elan Service;c:\program files\Elantech\ETDService.exe;c:\program files\Elantech\ETDService.exe [x]
S2 GfExperienceService;NVIDIA GeForce Experience Service;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [x]
S2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management;Intel(R) Wireless Bluetooth(R) 4.0 Radio Management;c:\program files (x86)\Intel\Bluetooth\ibtrksrv.exe;c:\program files (x86)\Intel\Bluetooth\ibtrksrv.exe [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [x]
S2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [x]
S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\System32\drivers\AcpiVpc.sys;c:\windows\SYSNATIVE\drivers\AcpiVpc.sys [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 iwdbus;IWD Bus Enumerator;c:\windows\System32\drivers\iwdbus.sys;c:\windows\SYSNATIVE\drivers\iwdbus.sys [x]
S3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C63x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C63x64.sys [x]
S3 NETwNe64;@oem156.inf,___ %NIC_Service_DispName_WIN8_64%;___ Ovladač adaptéru řady Intel(R) Wireless WiFi Link 5000 pro systém Windows 8 64 Bit;c:\windows\system32\DRIVERS\NETwew01.sys;c:\windows\SYSNATIVE\DRIVERS\NETwew01.sys [x]
S3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 rtsuvc;Lenovo EasyCamera;c:\windows\system32\DRIVERS\rtsuvc.sys;c:\windows\SYSNATIVE\DRIVERS\rtsuvc.sys [x]
S3 usb3Hub;UoIP Hub;c:\windows\System32\drivers\usb3Hub.sys;c:\windows\SYSNATIVE\drivers\usb3Hub.sys [x]
S3 WUDFWpdMtp;WUDFWpdMtp;c:\windows\system32\DRIVERS\WUDFRd.sys;c:\windows\SYSNATIVE\DRIVERS\WUDFRd.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2016-05-13 13:44 1186968 ----a-w- c:\program files (x86)\Google\Chrome\Application\50.0.2661.102\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2016-05-21 c:\windows\Tasks\Adobe Flash Player PPAPI Notifier.job
- c:\windows\SysWOW64\Macromed\Flash\FlashUtil32_21_0_0_242_pepper.exe [2016-05-13 15:53]
.
2016-05-25 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-16 15:53]
.
2016-05-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-10-26 12:05]
.
2016-05-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-10-26 12:05]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2012-10-01 19:37 2322576 ----a-w- c:\progra~1\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2012-10-01 19:37 2322576 ----a-w- c:\progra~1\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2012-10-01 19:37 2322576 ----a-w- c:\progra~1\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2015-09-30 12:34 780616 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2013-05-20 165872]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2013-05-20 407536]
"Persistence"="c:\windows\system32\igfxpers.exe" [2013-05-20 444400]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2016-02-27 16408320]
"RtHDVBg_Dolby"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2016-02-27 1407104]
"RtsFT"="RTFTrack.exe" [2016-02-27 5371608]
"UMonit64"="c:\windows\SysWOW64\UMonit64.exe" [2013-04-09 40960]
"BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshellex.dll" [2013-10-09 7818040]
"Energy Management"="c:\program files (x86)\Lenovo\Energy Management\Energy Management.exe" [2014-02-28 17080376]
"EnergyUtility"="c:\program files (x86)\Lenovo\Energy Management\Utility.exe" [2014-02-28 191544]
"RtHDVBg_LENOVO_DOLBYDRAGON"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2016-02-27 1407104]
"RtHDVBg_LENOVO_MICPKEY"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2016-02-27 1407104]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2015-08-27 2634872]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2015-08-27 1710568]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.seznam.cz/?clid=16194
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office15\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~1\Office15\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.10.1 192.168.1.1
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
c:\users\E a D\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DesktopWeatherAlerts.lnk - c:\users\E a D\AppData\Local\WeatherAlerts\DesktopWeatherAlertsApp.exe
HKLM-Run-ETDCtrl - c:\program files (x86)\Elantech\ETDCtrl.exe
AddRemove-Dark Souls 3_is1 - d:\games\Dark Souls 3\unins000.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
@SACL=(02 0000)
.
Celkový čas: 2016-05-25 19:33:10
ComboFix-quarantined-files.txt 2016-05-25 17:33
.
Před spuštěním: 140 987 260 928 bytes free
Po spuštění: 143 564 591 104 bytes free
.
- - End Of File - - 49E3C616016CFE26528EF1FB4362AE34
A36C5E4F47E84449FF07ED3517B43A31

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Vytížený procesor - kontrola logu

#2 Příspěvek od Rudy »

Zdravím!
Proč spouštíte ComboFix, utilitu určenou pouze profesionálům? Hodláte si nabořit systém, nebo některou aplikaci? Dejte log FRST: http://forum.viry.cz/viewtopic.php?f=13&t=133100 .
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Rhonnyn
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 25 kvě 2016 18:40

Re: Vytížený procesor - kontrola logu

#3 Příspěvek od Rhonnyn »

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:25-05-2016 01
Ran by E a D (administrator) on RHONNYN (26-05-2016 08:58:24)
Running from C:\Users\E a D\Desktop
Loaded Profiles: E a D (Available Profiles: E a D)
Platform: Windows 8 Pro (X64) Language: Čeština (Česká republika)
Internet Explorer Version 10 (Default browser: Opera)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel Corporation) C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(IObit) C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(LOL Replay) C:\Program Files (x86)\LOLReplay\LOLRecorder.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Opera Software) C:\Program Files (x86)\Opera\37.0.2178.43\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\37.0.2178.43\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\37.0.2178.43\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\37.0.2178.43\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\37.0.2178.43\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\37.0.2178.43\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\37.0.2178.43\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\37.0.2178.43\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\37.0.2178.43\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\37.0.2178.43\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\37.0.2178.43\opera.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16408320 2016-02-27] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407104 2016-02-27] (Realtek Semiconductor)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2888352 2013-04-25] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtsFT] => C:\Windows\RTFTrack.exe [5371608 2016-02-27] (Realtek semiconductor)
HKLM\...\Run: [UMonit64] => C:\Windows\SysWOW64\UMonit64.exe [40960 2013-04-09] ()
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17080376 2014-02-28] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [191544 2014-02-28] (Lenovo(beijing) Limited)
HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407104 2016-02-27] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407104 2016-02-27] (Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2634872 2015-08-27] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6133520 2015-11-07] (AVAST Software)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [595504 2016-01-29] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3236442656-2299666597-949595860-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-3236442656-2299666597-949595860-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [3077712 2016-03-31] (Valve Corporation)
HKU\S-1-5-21-3236442656-2299666597-949595860-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\E a D\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-3236442656-2299666597-949595860-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\E a D\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
HKU\S-1-5-21-3236442656-2299666597-949595860-1001\...\Run: [MK LOL] => C:\Program Files (x86)\MKJogo\MK IM\Bin\MKIM.exe [821752 2016-02-21] (MKGame)
HKU\S-1-5-21-3236442656-2299666597-949595860-1001\...\Run: [Innkeeper] => C:\Users\E a D\AppData\Local\Innkeeper\Update.exe --processStart Innkeeper.exe --process-start-args="-startup"
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [178512 2015-03-13] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [164568 2015-03-13] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-09-30] (AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\LOLRecorder.lnk [2014-06-29]
ShortcutTarget: LOLRecorder.lnk -> C:\Program Files (x86)\LOLReplay\LOLRecorder.exe (LOL Replay)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.10.1 192.168.1.1
Tcpip\..\Interfaces\{2033D7EF-6A66-4120-9844-C274D7AE86BF}: [DhcpNameServer] 192.168.10.1 192.168.1.1
Tcpip\..\Interfaces\{68CFBE00-4EAE-4100-9476-1F66BCAEF288}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-3236442656-2299666597-949595860-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3236442656-2299666597-949595860-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-3236442656-2299666597-949595860-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.seznam.cz/?clid=16194
SearchScopes: HKU\S-1-5-21-3236442656-2299666597-949595860-1001 -> {09A616F3-91BA-49F4-8145-A234F7753661} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-3236442656-2299666597-949595860-1001 -> {37D3B895-B70D-48D7-8722-72539F99B17C} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-3236442656-2299666597-949595860-1001 -> {6D26D0A1-6F71-44ED-8C91-1E695B32CC31} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-3236442656-2299666597-949595860-1001 -> {7FC795F6-E4C4-4BDA-BC91-E3BD8D6F25C8} URL = hxxp://www.mapy.cz/?query={searchTerms}&source ... arch_16194
SearchScopes: HKU\S-1-5-21-3236442656-2299666597-949595860-1001 -> {9813B808-F56A-46B4-8328-811F594B5784} URL = hxxp://www.firmy.cz/?q={searchTerms}&sourceid= ... arch_16194
SearchScopes: HKU\S-1-5-21-3236442656-2299666597-949595860-1001 -> {B70AF4F9-DAD7-48EF-A5D7-10CCD8DB7E4F} URL = hxxp://search.seznam.cz/?q={searchTerms}&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-3236442656-2299666597-949595860-1001 -> {BD6493A2-04F6-4C28-B8B1-991CF3925502} URL = hxxp://www.novinky.cz/hledej?w={searchTerms}&s ... arch_16194
SearchScopes: HKU\S-1-5-21-3236442656-2299666597-949595860-1001 -> {D49CD6D3-A965-4785-AB3F-1DE9151B924B} URL = hxxp://www.zbozi.cz/?q={searchTerms}&r=campmoz ... arch_16194
SearchScopes: HKU\S-1-5-21-3236442656-2299666597-949595860-1001 -> {E457F1CF-E5AE-4263-99BD-17275DD70786} URL = hxxp://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_16194
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-09-30] (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_74\bin\ssv.dll [2016-02-27] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-09-30] (AVAST Software)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_74\bin\jp2ssv.dll [2016-02-27] (Oracle Corporation)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2016-02-01] (Skype Technologies)

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_242.dll [2016-05-13] ()
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_242.dll [2016-05-13] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.74.2 -> C:\Program Files (x86)\Java\jre1.8.0_74\bin\dtplugin\npDeployJava1.dll [2016-02-27] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.74.2 -> C:\Program Files (x86)\Java\jre1.8.0_74\bin\plugin2\npjp2.dll [2016-02-27] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-11] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-11] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-05-03] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2012-10-01] (Microsoft Corporation)
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-10]

Chrome:
=======
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\E a D\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.8.824\_platform_specific\win_x86\widevinecdmadapter.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\50.0.2661.102\PepperFlash\pepflashplayer.dll ()
CHR Profile: C:\Users\E a D\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Dokumenty Google) - C:\Users\E a D\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-04]
CHR Extension: (Disk Google) - C:\Users\E a D\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (YouTube) - C:\Users\E a D\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Vyhledávání Google) - C:\Users\E a D\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-03]
CHR Extension: (Dokumenty Google offline) - C:\Users\E a D\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-05-20]
CHR Extension: (Local SWF Player) - C:\Users\E a D\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdmbckedabpbgjagmkgcejooabcdnone [2016-01-21]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\E a D\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-05-20]
CHR Extension: (Gmail) - C:\Users\E a D\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-07-03]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-09-30] (AVAST Software)
R2 BrcmSetSecurity; C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe [283296 2013-11-11] (Intel Corporation)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [99184 2013-04-12] (ELAN Microelectronics Corp.)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1155192 2015-08-27] (NVIDIA Corporation)
R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-10-18] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [178312 2015-09-25] (Intel Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [284912 2013-11-20] ()
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1872504 2015-08-27] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5544568 2015-08-27] (NVIDIA Corporation)
S2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3674864 2013-11-20] (Intel® Corporation)
S3 AvastVBoxSvc; "C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe" [X]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-09-30] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-09-30] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-09-30] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-09-30] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1059656 2015-11-07] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [449992 2015-11-07] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [153744 2015-09-30] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-09-30] (AVAST Software)
S3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2013-07-22] (Motorola Solutions, Inc.)
S3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1448248 2016-02-27] (Motorola Solutions, Inc.)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-10-12] (Disc Soft Ltd)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3295984 2012-07-26] (Broadcom Corporation)
S3 ETDSMBus; C:\Windows\system32\DRIVERS\ETDSMBus.sys [21840 2013-03-25] (ELAN Microelectronic Corp.)
S3 GeneStor; C:\Windows\System32\drivers\GeneStor.sys [111336 2016-02-27] (GenesysLogic)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2015-01-01] (REALiX(tm))
R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [185088 2016-02-27] (Intel Corporation)
R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew01.sys [3354384 2015-09-09] (Intel Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19576 2015-08-27] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [50472 2015-08-11] (NVIDIA Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [3040472 2016-02-27] (Realtek Semiconductor Corp.)
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [198656 2012-07-26] (Microsoft Corporation)
S3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2014-11-26] (Synaptics Incorporated)
R3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [206744 2013-06-20] (Windows (R) Win 7 DDK provider)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [36288 2013-07-02] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [247216 2013-07-02] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink)
U3 catchme; \??\C:\ComboFix\catchme.sys [X]
S2 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-05-26 08:58 - 2016-05-26 08:58 - 00021603 _____ C:\Users\E a D\Desktop\FRST.txt
2016-05-26 08:40 - 2016-05-26 08:58 - 00000000 ____D C:\FRST
2016-05-26 08:40 - 2016-05-26 08:40 - 02383360 _____ (Farbar) C:\Users\E a D\Desktop\FRST64.exe
2016-05-25 23:04 - 2016-05-25 23:04 - 00003903 _____ C:\Users\E a D\Downloads\xmen.apocalypse.(2016).eng.1cd.(6636209).zip
2016-05-25 22:13 - 2016-05-25 22:13 - 00998616 _____ (Fatecabi ) C:\Users\E a D\Downloads\x-men-apocalypse-cze-6636089.exe
2016-05-25 22:13 - 2016-05-25 22:13 - 00037702 _____ C:\Users\E a D\Downloads\xmen.apocalypse.(2016).cze.1cd.(6636089).zip
2016-05-25 22:12 - 2016-05-25 22:30 - 1292311862 _____ C:\Users\E a D\Downloads\X-Men-Apocalypse-2016-720p-HDCAM-x264-HQMic-Exclusive.mkv
2016-05-25 19:33 - 2016-05-25 19:33 - 00024377 _____ C:\ComboFix.txt
2016-05-25 19:14 - 2016-05-25 19:33 - 00000000 ____D C:\ComboFix
2016-05-25 19:12 - 2016-05-25 19:12 - 00001116 _____ C:\Users\E a D\Desktop\ComboFix – zástupce.lnk
2016-05-25 19:11 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2016-05-25 19:11 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2016-05-25 19:11 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2016-05-25 19:11 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2016-05-25 19:11 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2016-05-25 19:11 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe
2016-05-25 19:11 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2016-05-25 19:11 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2016-05-25 19:11 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2016-05-25 19:10 - 2016-05-25 19:33 - 00000000 ____D C:\Qoobox
2016-05-25 19:10 - 2016-05-25 19:29 - 00000000 ____D C:\Windows\erdnt
2016-05-25 19:09 - 2016-05-25 19:09 - 05659526 ____N (Swearware) C:\Users\E a D\Downloads\ComboFix.exe
2016-05-25 19:06 - 2016-05-25 19:06 - 00102476 _____ C:\Users\E a D\Downloads\The.Flash_.S02E23.LOL_.CZ_.srt
2016-05-25 18:17 - 2016-05-25 18:17 - 04713984 _____ (Geza Kovacs) C:\Users\E a D\Downloads\unetbootin-windows-625.exe
2016-05-25 18:01 - 2016-05-25 18:01 - 01473404 _____ C:\Users\E a D\Downloads\BootableUSB.zip
2016-05-25 18:00 - 2016-05-25 18:04 - 00000000 ____D C:\Users\E a D\AppData\Local\Apps\Windows 7 USB DVD Download Tool
2016-05-25 18:00 - 2016-05-25 18:00 - 00002480 _____ C:\Users\E a D\Desktop\Windows 7 USB DVD Download Tool.lnk
2016-05-25 18:00 - 2016-05-25 18:00 - 00000000 ____D C:\Users\E a D\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 USB DVD Download Tool
2016-05-25 17:29 - 2016-05-25 17:29 - 02721168 _____ (Microsoft Corporation) C:\Users\E a D\Downloads\Windows7-USB-DVD-tool.exe
2016-05-25 16:59 - 2016-05-25 16:59 - 00000869 _____ C:\Users\E a D\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\A Bootable USB.lnk
2016-05-25 15:43 - 2016-05-25 16:12 - 2460942336 _____ C:\Users\E a D\Downloads\Windows-7-Home-Premium---32bit---cz--aktivator.iso
2016-05-23 18:58 - 2016-05-24 13:00 - 00000000 ____D C:\Users\E a D\AppData\LocalLow\uTorrent

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-05-26 08:53 - 2014-11-16 11:21 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-05-26 08:43 - 2015-10-26 14:05 - 00000976 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-05-25 23:07 - 2014-02-27 22:40 - 00000000 ____D C:\The KMPlayer
2016-05-25 22:46 - 2015-06-16 19:06 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-05-25 20:03 - 2012-07-26 12:01 - 00727488 _____ C:\Windows\system32\perfh005.dat
2016-05-25 20:03 - 2012-07-26 12:01 - 00148006 _____ C:\Windows\system32\perfc005.dat
2016-05-25 20:03 - 2012-07-26 09:28 - 01714430 _____ C:\Windows\system32\PerfStringBackup.INI
2016-05-25 20:03 - 2012-07-26 07:37 - 00000000 ____D C:\Windows\Inf
2016-05-25 19:49 - 2014-02-23 23:19 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3236442656-2299666597-949595860-1001
2016-05-25 19:23 - 2012-07-26 07:26 - 00000215 _____ C:\Windows\system.ini
2016-05-25 19:20 - 2015-06-16 19:06 - 00000000 ____D C:\ProgramData\Adobe
2016-05-25 19:09 - 2014-12-27 15:03 - 00000000 ____D C:\Users\E a D\AppData\Roaming\Seznam.cz
2016-05-25 19:06 - 2016-02-14 10:32 - 00000000 ____D C:\Users\E a D\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Innkeeper
2016-05-25 19:06 - 2016-02-14 10:31 - 00000000 ____D C:\Users\E a D\AppData\Local\SquirrelTemp
2016-05-25 19:06 - 2016-02-14 10:31 - 00000000 ____D C:\Users\E a D\AppData\Local\Innkeeper
2016-05-25 19:04 - 2014-10-13 18:35 - 00000000 ____D C:\Program Files (x86)\Steam
2016-05-25 19:04 - 2014-08-20 09:49 - 00002872 _____ C:\Windows\System32\Tasks\Driver Booster SkipUAC (E a D)
2016-05-25 19:04 - 2014-02-28 15:21 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-05-25 19:03 - 2015-10-26 14:05 - 00000972 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-05-25 19:03 - 2012-07-26 09:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-05-25 18:14 - 2014-02-23 22:10 - 00002566 _____ C:\Windows\diagwrn.xml
2016-05-25 18:14 - 2014-02-23 22:10 - 00001908 _____ C:\Windows\diagerr.xml
2016-05-25 07:52 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent
2016-05-25 07:45 - 2012-07-26 10:12 - 00000000 ___HD C:\Program Files\WindowsApps
2016-05-24 13:00 - 2014-03-05 15:35 - 00000000 ____D C:\Users\E a D\AppData\Roaming\uTorrent
2016-05-22 20:37 - 2014-02-25 10:10 - 00000000 ____D C:\Users\E a D\AppData\Roaming\Skype
2016-05-21 23:19 - 2015-10-31 21:54 - 00000958 _____ C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job
2016-05-18 18:19 - 2015-05-29 11:25 - 00000000 ____D C:\Users\E a D\AppData\Local\Battle.net
2016-05-18 17:19 - 2015-05-29 11:25 - 00000000 ____D C:\Program Files (x86)\Battle.net
2016-05-13 21:46 - 2015-06-16 19:06 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2016-05-13 17:53 - 2015-10-31 21:54 - 00003920 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2016-05-13 17:53 - 2014-11-16 11:21 - 00003802 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-05-13 15:46 - 2015-10-26 14:17 - 00002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-05-12 19:41 - 2015-10-26 21:06 - 00003844 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1445886387
2016-05-12 19:41 - 2015-10-26 21:06 - 00001051 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2016-05-12 19:41 - 2015-01-06 21:39 - 00000000 ____D C:\Program Files (x86)\Opera
2016-05-11 14:38 - 2015-10-26 14:05 - 00003948 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-05-11 14:38 - 2015-10-26 14:05 - 00003712 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-05-02 16:30 - 2015-12-10 21:14 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-05-02 16:30 - 2014-02-25 10:10 - 00000000 ____D C:\ProgramData\Skype
2016-04-26 11:32 - 2015-06-22 07:31 - 00000000 ____D C:\Program Files (x86)\Hearthstone

==================== Files in the root of some directories =======

2014-02-25 18:51 - 2014-02-25 19:02 - 0098192 _____ () C:\Users\E a D\AppData\Local\WiDiLog.20140225.175136.wdl
2014-02-28 12:25 - 2014-02-28 12:26 - 0088237 _____ () C:\Users\E a D\AppData\Local\WiDiLog.20140228.112548.wdl
2014-02-28 16:38 - 2014-02-28 16:48 - 0113826 _____ () C:\Users\E a D\AppData\Local\WiDiLog.20140228.153829.wdl
2014-11-16 13:15 - 2014-11-16 13:17 - 0088963 _____ () C:\Users\E a D\AppData\Local\WiDiLog.20141116.121548.wdl
2014-11-16 13:17 - 2014-11-16 13:20 - 0093821 _____ () C:\Users\E a D\AppData\Local\WiDiLog.20141116.121731.wdl
2014-11-16 13:20 - 2014-11-16 13:22 - 0088856 _____ () C:\Users\E a D\AppData\Local\WiDiLog.20141116.122034.wdl
2014-02-25 10:21 - 2014-02-25 10:21 - 0012080 _____ () C:\Users\E a D\AppData\Local\WiDiSetupLog.20140225.092104.wdl
2014-02-25 10:28 - 2014-02-25 10:28 - 0012561 _____ () C:\Users\E a D\AppData\Local\WiDiSetupLog.20140225.092800.wdl
2014-02-25 10:31 - 2014-02-25 10:31 - 0012667 _____ () C:\Users\E a D\AppData\Local\WiDiSetupLog.20140225.093115.wdl
2014-02-25 10:35 - 2014-02-25 10:35 - 0014794 _____ () C:\Users\E a D\AppData\Local\WiDiSetupLog.20140225.093520.wdl
2014-02-25 10:46 - 2014-02-25 10:47 - 0033880 _____ () C:\Users\E a D\AppData\Local\WiDiSetupLog.20140225.094617.wdl
2014-02-25 18:49 - 2014-02-25 18:50 - 0034108 _____ () C:\Users\E a D\AppData\Local\WiDiSetupLog.20140225.174929.wdl
2014-02-25 18:44 - 2014-02-25 18:44 - 0010183 _____ () C:\Users\E a D\AppData\Local\WiDiUtilsLog.20140225.174402.wdl
2014-02-25 10:22 - 2014-02-25 10:22 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-05-26 07:26

==================== End of FRST.txt ============================

posilam ten log, no spoustel sem to protoze sem si tady nasel podobny topic a tam se to pouzilo, asi to byla chyba...
Přílohy
Addition.rar
(11.23 KiB) Staženo 33 x

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Vytížený procesor - kontrola logu

#4 Příspěvek od Rudy »

Teď spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Rhonnyn
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 25 kvě 2016 18:40

Re: Vytížený procesor - kontrola logu

#5 Příspěvek od Rhonnyn »

# AdwCleaner v5.118 - Log vytvořen 26/05/2016 v 18:30:16
# Aktualizováno 23/05/2016 by Xplode
# Databáze : 2016-05-26.2 [Server]
# Operační system : Windows 8 Pro (X64)
# Uživatelské jméno : E a D - RHONNYN
# Spuštěno z : C:\Users\E a D\Desktop\adwcleaner_5.118.exe
# Nastavení : Sken
# Podpora : http://toolslib.net/forum

***** [ Služby ] *****


***** [ Složky ] *****

Složka Nalezeno : C:\ProgramData\simplitec
Složka Nalezeno : C:\ProgramData\ytd video downloader
Složka Nalezeno : C:\ProgramData\Application Data\simplitec
Složka Nalezeno : C:\ProgramData\Application Data\ytd video downloader
Složka Nalezeno : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\simplitec
Složka Nalezeno : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ytd video downloader

***** [ Soubory ] *****

Soubor Nalezeno : C:\Windows\SysNative\roboot64.exe

***** [ DLL ] *****


***** [ WMI ] *****


***** [ Zástupci ] *****


***** [ Naplánované úlohy ] *****


***** [ Registry ] *****

Klíč Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{8BF0126F-A5B7-4720-ABB2-2414A0AF5474}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\TypeLib\{157B1AA6-3E5C-404A-9118-C1D91F537040}
Klíč Nalezeno : HKCU\Software\WEBAPP
Klíč Nalezeno : HKCU\Software\GreenTree Applications\YTD
Klíč Nalezeno : HKLM\SOFTWARE\simplitec
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Your Software Deals_is1
Klíč Nalezeno : HKU\S-1-5-21-3236442656-2299666597-949595860-1001\Software\WEBAPP
Klíč Nalezeno : HKU\S-1-5-21-3236442656-2299666597-949595860-1001\Software\GreenTree Applications\YTD

***** [ Prohlížeče ] *****


*************************

C:\AdwCleaner\AdwCleaner[S1].txt - [1812 bytů] - [26/05/2016 18:30:16]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1885 bytů] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Vytížený procesor - kontrola logu

#6 Příspěvek od Rudy »

Dejte nový log FRST.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Rhonnyn
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 25 kvě 2016 18:40

Re: Vytížený procesor - kontrola logu

#7 Příspěvek od Rhonnyn »

tohle je log po restartu...ten predtim sem asi poslal spatne...# AdwCleaner v5.118 - Log vytvořen 26/05/2016 v 18:31:50
# Aktualizováno 23/05/2016 by Xplode
# Databáze : 2016-05-26.2 [Server]
# Operační system : Windows 8 Pro (X64)
# Uživatelské jméno : E a D - RHONNYN
# Spuštěno z : C:\Users\E a D\Desktop\adwcleaner_5.118.exe
# Nastavení : Čištění
# Podpora : http://toolslib.net/forum

***** [ Služby ] *****


***** [ Složky ] *****

[-] Složka Smazáno : C:\ProgramData\simplitec
[-] Složka Smazáno : C:\ProgramData\ytd video downloader
[#] Složka Smazáno : C:\ProgramData\Application Data\simplitec
[#] Složka Smazáno : C:\ProgramData\Application Data\ytd video downloader
[-] Složka Smazáno : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\simplitec
[-] Složka Smazáno : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ytd video downloader

***** [ Soubory ] *****

[-] Soubor Smazáno : C:\Windows\SysNative\roboot64.exe

***** [ DLLs ] *****


***** [ WMI ] *****


***** [ Zástupci ] *****


***** [ Naplánované úlohy ] *****


***** [ Registry ] *****

[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{8BF0126F-A5B7-4720-ABB2-2414A0AF5474}
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{157B1AA6-3E5C-404A-9118-C1D91F537040}
[-] Klíč Smazáno : HKCU\Software\WEBAPP
[-] Klíč Smazáno : HKCU\Software\GreenTree Applications\YTD
[-] Klíč Smazáno : HKLM\SOFTWARE\simplitec
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Your Software Deals_is1

***** [ Prohlížeče ] *****


*************************

:: "Tracing" klíče smazány
:: Nastavení Winsock vyčištěno

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [1784 bytů] - [26/05/2016 18:31:50]
C:\AdwCleaner\AdwCleaner[S1].txt - [1964 bytů] - [26/05/2016 18:30:16]

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [1930 bytů] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Vytížený procesor - kontrola logu

#8 Příspěvek od Rudy »

Dejte nový log FRST.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Rhonnyn
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 25 kvě 2016 18:40

Re: Vytížený procesor - kontrola logu

#9 Příspěvek od Rhonnyn »

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:25-05-2016 01
Ran by E a D (administrator) on RHONNYN (26-05-2016 18:49:59)
Running from C:\Users\E a D\Desktop
Loaded Profiles: E a D (Available Profiles: E a D)
Platform: Windows 8 Pro (X64) Language: Čeština (Česká republika)
Internet Explorer Version 10 (Default browser: Opera)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel Corporation) C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
() C:\Windows\SysWOW64\UMonit64.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Opera Software) C:\Program Files (x86)\Opera\37.0.2178.43\opera.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Opera Software) C:\Program Files (x86)\Opera\37.0.2178.43\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\37.0.2178.43\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\37.0.2178.43\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\37.0.2178.43\opera.exe
() C:\Users\E a D\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\E a D\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(LOL Replay) C:\Program Files (x86)\LOLReplay\LOLRecorder.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Innkeeper) C:\Users\E a D\AppData\Local\Innkeeper\app-0.2.9\Innkeeper.exe
(Opera Software) C:\Program Files (x86)\Opera\37.0.2178.43\opera.exe
(Curse Inc.) C:\Users\E a D\AppData\Local\Innkeeper\app-0.2.9\Electron\bin\InnkeeperUI-win32-ia32\InnkeeperUI.exe
(Curse Inc.) C:\Users\E a D\AppData\Local\Innkeeper\app-0.2.9\Electron\bin\InnkeeperUI-win32-ia32\InnkeeperUI.exe
(Curse Inc.) C:\Users\E a D\AppData\Local\Innkeeper\app-0.2.9\Electron\bin\InnkeeperUI-win32-ia32\InnkeeperUI.exe
(Curse Inc.) C:\Users\E a D\AppData\Local\Innkeeper\app-0.2.9\Electron\bin\InnkeeperUI-win32-ia32\InnkeeperUI.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16418560 2016-05-26] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1419008 2016-05-26] (Realtek Semiconductor)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2888352 2013-04-25] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtsFT] => C:\Windows\RTFTrack.exe [5371608 2016-02-27] (Realtek semiconductor)
HKLM\...\Run: [UMonit64] => C:\Windows\SysWOW64\UMonit64.exe [40960 2013-04-09] ()
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17080376 2014-02-28] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [191544 2014-02-28] (Lenovo(beijing) Limited)
HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1419008 2016-05-26] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1419008 2016-05-26] (Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2634872 2015-08-27] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6133520 2015-11-07] (AVAST Software)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [595504 2016-01-29] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3236442656-2299666597-949595860-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-3236442656-2299666597-949595860-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [3077712 2016-03-31] (Valve Corporation)
HKU\S-1-5-21-3236442656-2299666597-949595860-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\E a D\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-3236442656-2299666597-949595860-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\E a D\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
HKU\S-1-5-21-3236442656-2299666597-949595860-1001\...\Run: [MK LOL] => C:\Program Files (x86)\MKJogo\MK IM\Bin\MKIM.exe [821752 2016-02-21] (MKGame)
HKU\S-1-5-21-3236442656-2299666597-949595860-1001\...\Run: [Innkeeper] => C:\Users\E a D\AppData\Local\Innkeeper\Update.exe --processStart Innkeeper.exe --process-start-args="-startup"
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [178512 2015-03-13] (NVIDIA Corporation)
AppInit_DLLs: ,C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [178512 2015-03-13] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [164568 2015-03-13] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-09-30] (AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\LOLRecorder.lnk [2014-06-29]
ShortcutTarget: LOLRecorder.lnk -> C:\Program Files (x86)\LOLReplay\LOLRecorder.exe (LOL Replay)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.10.1 192.168.1.1
Tcpip\..\Interfaces\{2033D7EF-6A66-4120-9844-C274D7AE86BF}: [DhcpNameServer] 192.168.10.1 192.168.1.1
Tcpip\..\Interfaces\{68CFBE00-4EAE-4100-9476-1F66BCAEF288}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-3236442656-2299666597-949595860-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3236442656-2299666597-949595860-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-3236442656-2299666597-949595860-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.seznam.cz/?clid=16194
SearchScopes: HKU\S-1-5-21-3236442656-2299666597-949595860-1001 -> {09A616F3-91BA-49F4-8145-A234F7753661} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-3236442656-2299666597-949595860-1001 -> {37D3B895-B70D-48D7-8722-72539F99B17C} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-3236442656-2299666597-949595860-1001 -> {6D26D0A1-6F71-44ED-8C91-1E695B32CC31} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-3236442656-2299666597-949595860-1001 -> {7FC795F6-E4C4-4BDA-BC91-E3BD8D6F25C8} URL = hxxp://www.mapy.cz/?query={searchTerms}&source ... arch_16194
SearchScopes: HKU\S-1-5-21-3236442656-2299666597-949595860-1001 -> {9813B808-F56A-46B4-8328-811F594B5784} URL = hxxp://www.firmy.cz/?q={searchTerms}&sourceid= ... arch_16194
SearchScopes: HKU\S-1-5-21-3236442656-2299666597-949595860-1001 -> {B70AF4F9-DAD7-48EF-A5D7-10CCD8DB7E4F} URL = hxxp://search.seznam.cz/?q={searchTerms}&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-3236442656-2299666597-949595860-1001 -> {BD6493A2-04F6-4C28-B8B1-991CF3925502} URL = hxxp://www.novinky.cz/hledej?w={searchTerms}&s ... arch_16194
SearchScopes: HKU\S-1-5-21-3236442656-2299666597-949595860-1001 -> {D49CD6D3-A965-4785-AB3F-1DE9151B924B} URL = hxxp://www.zbozi.cz/?q={searchTerms}&r=campmoz ... arch_16194
SearchScopes: HKU\S-1-5-21-3236442656-2299666597-949595860-1001 -> {E457F1CF-E5AE-4263-99BD-17275DD70786} URL = hxxp://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_16194
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-09-30] (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_74\bin\ssv.dll [2016-02-27] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-09-30] (AVAST Software)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_74\bin\jp2ssv.dll [2016-02-27] (Oracle Corporation)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2016-02-01] (Skype Technologies)

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_242.dll [2016-05-13] ()
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_242.dll [2016-05-13] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.74.2 -> C:\Program Files (x86)\Java\jre1.8.0_74\bin\dtplugin\npDeployJava1.dll [2016-02-27] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.74.2 -> C:\Program Files (x86)\Java\jre1.8.0_74\bin\plugin2\npjp2.dll [2016-02-27] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-11] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-11] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-05-03] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2012-10-01] (Microsoft Corporation)
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-10]

Chrome:
=======
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\E a D\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.8.824\_platform_specific\win_x86\widevinecdmadapter.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\50.0.2661.102\PepperFlash\pepflashplayer.dll ()
CHR Profile: C:\Users\E a D\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Dokumenty Google) - C:\Users\E a D\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-04]
CHR Extension: (Disk Google) - C:\Users\E a D\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (YouTube) - C:\Users\E a D\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Vyhledávání Google) - C:\Users\E a D\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-03]
CHR Extension: (Dokumenty Google offline) - C:\Users\E a D\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-05-20]
CHR Extension: (Local SWF Player) - C:\Users\E a D\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdmbckedabpbgjagmkgcejooabcdnone [2016-01-21]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\E a D\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-05-20]
CHR Extension: (Gmail) - C:\Users\E a D\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-07-03]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-09-30] (AVAST Software)
R2 BrcmSetSecurity; C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe [283296 2013-11-11] (Intel Corporation)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [99184 2013-04-12] (ELAN Microelectronics Corp.)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1155192 2015-08-27] (NVIDIA Corporation)
R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-10-18] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [178312 2015-09-25] (Intel Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [284912 2013-11-20] ()
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1872504 2015-08-27] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5544568 2015-08-27] (NVIDIA Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3674864 2013-11-20] (Intel® Corporation)
S3 AvastVBoxSvc; "C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe" [X]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-09-30] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-09-30] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-09-30] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-09-30] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1059656 2015-11-07] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [449992 2015-11-07] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [153744 2015-09-30] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-09-30] (AVAST Software)
S3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2013-07-22] (Motorola Solutions, Inc.)
S3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1448248 2016-02-27] (Motorola Solutions, Inc.)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-10-12] (Disc Soft Ltd)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3295984 2012-07-26] (Broadcom Corporation)
S3 ETDSMBus; C:\Windows\system32\DRIVERS\ETDSMBus.sys [21840 2013-03-25] (ELAN Microelectronic Corp.)
S3 GeneStor; C:\Windows\System32\drivers\GeneStor.sys [111336 2016-02-27] (GenesysLogic)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2015-01-01] (REALiX(tm))
R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [185600 2016-05-26] (Intel Corporation)
R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew01.sys [3354384 2015-09-09] (Intel Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19576 2015-08-27] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [50472 2015-08-11] (NVIDIA Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [3040472 2016-02-27] (Realtek Semiconductor Corp.)
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [198656 2012-07-26] (Microsoft Corporation)
S3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2014-11-26] (Synaptics Incorporated)
R3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [206744 2013-06-20] (Windows (R) Win 7 DDK provider)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [36288 2013-07-02] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [247216 2013-07-02] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S2 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-05-26 18:29 - 2016-05-26 18:31 - 00000000 ____D C:\AdwCleaner
2016-05-26 18:29 - 2016-05-26 18:29 - 03678272 _____ C:\Users\E a D\Desktop\adwcleaner_5.118.exe
2016-05-26 17:21 - 2016-05-26 17:21 - 72203792 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes64.dat
2016-05-26 17:21 - 2016-05-26 17:21 - 07172920 _____ (Dolby Laboratories) C:\Windows\system32\R4EEP64A.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 07096192 _____ (Dolby Laboratories) C:\Windows\system32\DDPP64A.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 06264640 _____ (Dolby Laboratories) C:\Windows\system32\DDPP64AF3.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 05681859 _____ C:\Windows\system32\Drivers\RTAIODAT.DAT
2016-05-26 17:21 - 2016-05-26 17:21 - 05338936 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOv211.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 04805376 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys
2016-05-26 17:21 - 2016-05-26 17:21 - 03283248 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 03282032 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 03198720 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 03082320 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RltkAPO64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 02894976 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl
2016-05-26 17:21 - 2016-05-26 17:21 - 02050184 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 02048256 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 01965816 _____ (Dolby Laboratories) C:\Windows\system32\DDPD64A.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 01959608 _____ (Dolby Laboratories) C:\Windows\system32\DDPD64AF3.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 01780624 _____ (DTS) C:\Windows\system32\DTSS2SpeakerDLL64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 01591064 _____ (DTS) C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 01508936 _____ (DTS) C:\Windows\system32\DTSBoostDLL64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 01356512 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 01060504 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOProp.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00965032 _____ (Sony Corporation) C:\Windows\system32\SFSS_APO.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00743968 _____ (DTS) C:\Windows\system32\DTSBassEnhancementDLL64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00727440 _____ (DTS) C:\Windows\system32\DTSSymmetryDLL64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00708312 _____ (DTS) C:\Windows\system32\DTSVoiceClarityDLL64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00689888 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00678184 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO30.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00677672 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVolumeSDAPO.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00574760 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00532384 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00504312 _____ (DTS) C:\Windows\system32\DTSNeoPCDLL64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00474376 _____ (Intel(R) Corporation) C:\Windows\system32\Drivers\IntcDAud.sys
2016-05-26 17:21 - 2016-05-26 17:21 - 00447720 _____ (Dolby Laboratories) C:\Windows\system32\R4EED64A.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00445400 _____ (DTS) C:\Windows\system32\DTSLimiterDLL64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00441272 _____ (DTS) C:\Windows\system32\DTSGainCompensatorDLL64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00387320 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00370840 _____ (Dolby Laboratories) C:\Windows\system32\HiFiDAX2API.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00362064 _____ (Dolby Laboratories) C:\Windows\system32\DDPO64AF3.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00343712 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00330560 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00327464 _____ (Dolby Laboratories) C:\Windows\system32\DDPO64A.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00321720 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00321720 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00310424 _____ (Dolby Laboratories) C:\Windows\system32\DDPA64F3.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00272720 _____ (Dolby Laboratories) C:\Windows\system32\DDPA64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00253904 _____ (DTS) C:\Windows\system32\DTSGFXAPO64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00253864 _____ (DTS) C:\Windows\system32\DTSLFXAPO64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00252880 _____ (DTS) C:\Windows\system32\DTSGFXAPONS64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00231920 _____ (Synopsys, Inc.) C:\Windows\system32\SFNHK64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00221976 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSH64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00214840 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00209544 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00192992 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00185600 _____ (Intel Corporation) C:\Windows\system32\Drivers\TeeDriverW8x64.sys
2016-05-26 17:21 - 2016-05-26 17:21 - 00166208 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00151792 _____ (Dolby Laboratories) C:\Windows\system32\R4EEL64A.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00134208 _____ (Dolby Laboratories) C:\Windows\system32\R4EEA64A.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00122320 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00118600 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00110992 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00090920 _____ (Synopsys, Inc.) C:\Windows\system32\SFCOM64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00088352 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00088328 _____ (Synopsys, Inc.) C:\Windows\system32\SFAPO64.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00084616 _____ (Dolby Laboratories) C:\Windows\system32\R4EEG64A.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00083632 _____ (Virage Logic Corporation / Sonic Focus) C:\Windows\SysWOW64\SFCOM.dll
2016-05-26 17:21 - 2016-05-26 17:21 - 00023704 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll
2016-05-26 17:17 - 2016-05-26 18:37 - 00003240 _____ C:\Windows\System32\Tasks\Driver Booster Scheduler
2016-05-26 17:17 - 2016-05-26 17:23 - 00002150 _____ C:\Users\Public\Desktop\Driver Booster 3.lnk
2016-05-26 17:17 - 2016-05-26 17:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 3
2016-05-26 15:18 - 2016-05-26 15:18 - 00000000 ____D C:\Users\E a D\AppData\Roaming\Ashampoo
2016-05-26 15:17 - 2016-05-26 15:17 - 00001861 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Your Software Deals.lnk
2016-05-26 15:17 - 2016-05-26 15:17 - 00001317 _____ C:\Users\Public\Desktop\Ashampoo Burning Studio 6 FREE.lnk
2016-05-26 15:17 - 2016-05-26 15:17 - 00000000 ____D C:\Users\E a D\AppData\Local\ashampoo
2016-05-26 15:17 - 2016-05-26 15:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo
2016-05-26 15:17 - 2016-05-26 15:17 - 00000000 ____D C:\ProgramData\Ashampoo
2016-05-26 15:17 - 2016-05-26 15:17 - 00000000 ____D C:\Program Files (x86)\Ashampoo
2016-05-26 15:16 - 2016-05-26 15:16 - 12891208 _____ (Ashampoo GmbH & Co. KG ) C:\Users\E a D\Downloads\ashampoo_burning_studio_6_free_6.84_13471.exe
2016-05-26 14:55 - 2016-05-26 15:04 - 00000412 __RSH C:\ProgramData\ntuser.pol
2016-05-26 14:55 - 2016-05-26 14:55 - 00640424 _____ (Akeo Consulting (hxxp://akeo.ie)) C:\Users\E a D\Downloads\rufus-1.4.12.exe
2016-05-26 13:55 - 2016-05-26 13:55 - 00038379 _____ C:\Users\E a D\Downloads\x-men-apocalypse-english-958813.zip
2016-05-26 13:31 - 2016-05-26 13:31 - 00035698 _____ C:\Users\E a D\Downloads\x-men-apocalypse-english-958811.zip
2016-05-26 09:04 - 2016-05-26 09:23 - 1682282992 _____ C:\Users\E a D\Downloads\Arrow.S04E23.720p.HDTV.X264-DIMENSION.mkv
2016-05-26 09:01 - 2016-05-26 09:01 - 00011502 _____ C:\Users\E a D\Desktop\Addition.rar
2016-05-26 08:58 - 2016-05-26 18:50 - 00021932 _____ C:\Users\E a D\Desktop\FRST.txt
2016-05-26 08:58 - 2016-05-26 08:59 - 00040097 _____ C:\Users\E a D\Desktop\Addition.txt
2016-05-26 08:40 - 2016-05-26 18:49 - 00000000 ____D C:\FRST
2016-05-26 08:40 - 2016-05-26 08:40 - 02383360 _____ (Farbar) C:\Users\E a D\Desktop\FRST64.exe
2016-05-25 23:04 - 2016-05-25 23:04 - 00003903 _____ C:\Users\E a D\Downloads\xmen.apocalypse.(2016).eng.1cd.(6636209).zip
2016-05-25 22:13 - 2016-05-25 22:13 - 00998616 _____ (Fatecabi ) C:\Users\E a D\Downloads\x-men-apocalypse-cze-6636089.exe
2016-05-25 22:13 - 2016-05-25 22:13 - 00037702 _____ C:\Users\E a D\Downloads\xmen.apocalypse.(2016).cze.1cd.(6636089).zip
2016-05-25 22:12 - 2016-05-25 22:30 - 1292311862 _____ C:\Users\E a D\Downloads\X-Men-Apocalypse-2016-720p-HDCAM-x264-HQMic-Exclusive.mkv
2016-05-25 19:33 - 2016-05-25 19:33 - 00024377 _____ C:\ComboFix.txt
2016-05-25 19:14 - 2016-05-25 19:33 - 00000000 ____D C:\ComboFix
2016-05-25 19:12 - 2016-05-25 19:12 - 00001116 _____ C:\Users\E a D\Desktop\ComboFix – zástupce.lnk
2016-05-25 19:11 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2016-05-25 19:11 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2016-05-25 19:11 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2016-05-25 19:11 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2016-05-25 19:11 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2016-05-25 19:11 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe
2016-05-25 19:11 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2016-05-25 19:11 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2016-05-25 19:11 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2016-05-25 19:10 - 2016-05-25 19:33 - 00000000 ____D C:\Qoobox
2016-05-25 19:10 - 2016-05-25 19:29 - 00000000 ____D C:\Windows\erdnt
2016-05-25 19:09 - 2016-05-25 19:09 - 05659526 ____N (Swearware) C:\Users\E a D\Downloads\ComboFix.exe
2016-05-25 19:06 - 2016-05-25 19:06 - 00102476 _____ C:\Users\E a D\Downloads\The.Flash_.S02E23.LOL_.CZ_.srt
2016-05-25 18:17 - 2016-05-25 18:17 - 04713984 _____ (Geza Kovacs) C:\Users\E a D\Downloads\unetbootin-windows-625.exe
2016-05-25 18:01 - 2016-05-25 18:01 - 01473404 _____ C:\Users\E a D\Downloads\BootableUSB.zip
2016-05-25 18:00 - 2016-05-25 18:04 - 00000000 ____D C:\Users\E a D\AppData\Local\Apps\Windows 7 USB DVD Download Tool
2016-05-25 18:00 - 2016-05-25 18:00 - 00002480 _____ C:\Users\E a D\Desktop\Windows 7 USB DVD Download Tool.lnk
2016-05-25 18:00 - 2016-05-25 18:00 - 00000000 ____D C:\Users\E a D\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 USB DVD Download Tool
2016-05-25 17:29 - 2016-05-25 17:29 - 02721168 _____ (Microsoft Corporation) C:\Users\E a D\Downloads\Windows7-USB-DVD-tool.exe
2016-05-25 16:59 - 2016-05-25 16:59 - 00000869 _____ C:\Users\E a D\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\A Bootable USB.lnk
2016-05-25 15:43 - 2016-05-25 16:12 - 2460942336 _____ C:\Users\E a D\Downloads\Windows-7-Home-Premium---32bit---cz--aktivator.iso
2016-05-23 18:58 - 2016-05-24 13:00 - 00000000 ____D C:\Users\E a D\AppData\LocalLow\uTorrent

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-05-26 18:43 - 2015-10-26 14:05 - 00000976 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-05-26 18:39 - 2012-07-26 12:01 - 00727488 _____ C:\Windows\system32\perfh005.dat
2016-05-26 18:39 - 2012-07-26 12:01 - 00148006 _____ C:\Windows\system32\perfc005.dat
2016-05-26 18:39 - 2012-07-26 09:28 - 01714430 _____ C:\Windows\system32\PerfStringBackup.INI
2016-05-26 18:39 - 2012-07-26 07:37 - 00000000 ____D C:\Windows\Inf
2016-05-26 18:38 - 2014-12-27 15:03 - 00000000 ____D C:\Users\E a D\AppData\Roaming\Seznam.cz
2016-05-26 18:37 - 2014-08-20 09:49 - 00002872 _____ C:\Windows\System32\Tasks\Driver Booster SkipUAC (E a D)
2016-05-26 18:34 - 2015-10-26 14:05 - 00000972 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-05-26 18:33 - 2014-10-13 18:35 - 00000000 ____D C:\Program Files (x86)\Steam
2016-05-26 18:33 - 2012-07-26 09:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-05-26 18:32 - 2012-07-26 07:26 - 00262144 ___SH C:\Windows\system32\config\BBI
2016-05-26 17:53 - 2014-11-16 11:21 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-05-26 17:22 - 2015-08-25 12:40 - 00000000 ____D C:\Windows\system32\DAX2
2016-05-26 17:22 - 2014-02-25 10:22 - 00000000 ____D C:\Windows\SysWOW64\RTCOM
2016-05-26 17:17 - 2014-11-16 11:04 - 00000000 ____D C:\ProgramData\ProductData
2016-05-26 14:55 - 2012-07-26 10:12 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2016-05-26 14:55 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\SysWOW64\GroupPolicy
2016-05-26 13:55 - 2014-02-27 22:40 - 00000000 ____D C:\The KMPlayer
2016-05-25 22:46 - 2015-06-16 19:06 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-05-25 19:49 - 2014-02-23 23:19 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3236442656-2299666597-949595860-1001
2016-05-25 19:23 - 2012-07-26 07:26 - 00000215 _____ C:\Windows\system.ini
2016-05-25 19:20 - 2015-06-16 19:06 - 00000000 ____D C:\ProgramData\Adobe
2016-05-25 19:06 - 2016-02-14 10:32 - 00000000 ____D C:\Users\E a D\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Innkeeper
2016-05-25 19:06 - 2016-02-14 10:31 - 00000000 ____D C:\Users\E a D\AppData\Local\SquirrelTemp
2016-05-25 19:06 - 2016-02-14 10:31 - 00000000 ____D C:\Users\E a D\AppData\Local\Innkeeper
2016-05-25 19:04 - 2014-02-28 15:21 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-05-25 18:14 - 2014-02-23 22:10 - 00002566 _____ C:\Windows\diagwrn.xml
2016-05-25 18:14 - 2014-02-23 22:10 - 00001908 _____ C:\Windows\diagerr.xml
2016-05-25 07:52 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent
2016-05-25 07:45 - 2012-07-26 10:12 - 00000000 ___HD C:\Program Files\WindowsApps
2016-05-24 13:00 - 2014-03-05 15:35 - 00000000 ____D C:\Users\E a D\AppData\Roaming\uTorrent
2016-05-22 20:37 - 2014-02-25 10:10 - 00000000 ____D C:\Users\E a D\AppData\Roaming\Skype
2016-05-21 23:19 - 2015-10-31 21:54 - 00000958 _____ C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job
2016-05-18 18:19 - 2015-05-29 11:25 - 00000000 ____D C:\Users\E a D\AppData\Local\Battle.net
2016-05-18 17:19 - 2015-05-29 11:25 - 00000000 ____D C:\Program Files (x86)\Battle.net
2016-05-13 21:46 - 2015-06-16 19:06 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2016-05-13 17:53 - 2015-10-31 21:54 - 00003920 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2016-05-13 17:53 - 2014-11-16 11:21 - 00003802 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-05-13 15:46 - 2015-10-26 14:17 - 00002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-05-12 19:41 - 2015-10-26 21:06 - 00003844 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1445886387
2016-05-12 19:41 - 2015-10-26 21:06 - 00001051 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2016-05-12 19:41 - 2015-01-06 21:39 - 00000000 ____D C:\Program Files (x86)\Opera
2016-05-11 14:38 - 2015-10-26 14:05 - 00003948 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-05-11 14:38 - 2015-10-26 14:05 - 00003712 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-05-02 16:30 - 2015-12-10 21:14 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-05-02 16:30 - 2014-02-25 10:10 - 00000000 ____D C:\ProgramData\Skype
2016-04-26 11:32 - 2015-06-22 07:31 - 00000000 ____D C:\Program Files (x86)\Hearthstone

==================== Files in the root of some directories =======

2014-02-25 18:51 - 2014-02-25 19:02 - 0098192 _____ () C:\Users\E a D\AppData\Local\WiDiLog.20140225.175136.wdl
2014-02-28 12:25 - 2014-02-28 12:26 - 0088237 _____ () C:\Users\E a D\AppData\Local\WiDiLog.20140228.112548.wdl
2014-02-28 16:38 - 2014-02-28 16:48 - 0113826 _____ () C:\Users\E a D\AppData\Local\WiDiLog.20140228.153829.wdl
2014-11-16 13:15 - 2014-11-16 13:17 - 0088963 _____ () C:\Users\E a D\AppData\Local\WiDiLog.20141116.121548.wdl
2014-11-16 13:17 - 2014-11-16 13:20 - 0093821 _____ () C:\Users\E a D\AppData\Local\WiDiLog.20141116.121731.wdl
2014-11-16 13:20 - 2014-11-16 13:22 - 0088856 _____ () C:\Users\E a D\AppData\Local\WiDiLog.20141116.122034.wdl
2014-02-25 10:21 - 2014-02-25 10:21 - 0012080 _____ () C:\Users\E a D\AppData\Local\WiDiSetupLog.20140225.092104.wdl
2014-02-25 10:28 - 2014-02-25 10:28 - 0012561 _____ () C:\Users\E a D\AppData\Local\WiDiSetupLog.20140225.092800.wdl
2014-02-25 10:31 - 2014-02-25 10:31 - 0012667 _____ () C:\Users\E a D\AppData\Local\WiDiSetupLog.20140225.093115.wdl
2014-02-25 10:35 - 2014-02-25 10:35 - 0014794 _____ () C:\Users\E a D\AppData\Local\WiDiSetupLog.20140225.093520.wdl
2014-02-25 10:46 - 2014-02-25 10:47 - 0033880 _____ () C:\Users\E a D\AppData\Local\WiDiSetupLog.20140225.094617.wdl
2014-02-25 18:49 - 2014-02-25 18:50 - 0034108 _____ () C:\Users\E a D\AppData\Local\WiDiSetupLog.20140225.174929.wdl
2014-02-25 18:44 - 2014-02-25 18:44 - 0010183 _____ () C:\Users\E a D\AppData\Local\WiDiUtilsLog.20140225.174402.wdl
2014-02-25 10:22 - 2014-02-25 10:22 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Some files in TEMP:
====================
C:\Users\E a D\AppData\Local\Temp\libeay32.dll
C:\Users\E a D\AppData\Local\Temp\msvcr120.dll
C:\Users\E a D\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-05-26 07:26

==================== End of FRST.txt ============================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Vytížený procesor - kontrola logu

#10 Příspěvek od Rudy »

Otevřte poznámkový blok a zkopírujte do něj:
Start
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [595504 2016-01-29] (Oracle Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-3236442656-2299666597-949595860-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\E a D\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.8.824\_platform_specific\win_x86\widevinecdmadapter.dll => No File
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
C:\ProgramData\DP45977C.lfl
C:\Users\E a D\AppData\Local\Temp
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Rhonnyn
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 25 kvě 2016 18:40

Re: Vytížený procesor - kontrola logu

#11 Příspěvek od Rhonnyn »

Fix result of Farbar Recovery Scan Tool (x64) Version:25-05-2016 01
Ran by E a D (2016-05-26 21:17:46) Run:1
Running from C:\Users\E a D\Desktop
Loaded Profiles: E a D (Available Profiles: E a D)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [595504 2016-01-29] (Oracle Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-3236442656-2299666597-949595860-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\E a D\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.8.824\_platform_specific\win_x86\widevinecdmadapter.dll => No File
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
C:\ProgramData\DP45977C.lfl
C:\Users\E a D\AppData\Local\Temp
End

*****************

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value removed successfully
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
"HKU\S-1-5-21-3236442656-2299666597-949595860-1001\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => value removed successfully
HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => key not found.
C:\Users\E a D\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.8.824\_platform_specific\win_x86\widevinecdmadapter.dll => not found.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
C:\ProgramData\DP45977C.lfl => moved successfully

"C:\Users\E a D\AppData\Local\Temp" folder move:

Could not move "C:\Users\E a D\AppData\Local\Temp" => Scheduled to move on reboot.


Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 2016-05-26 21:18:53)

C:\Users\E a D\AppData\Local\Temp => moved successfully

==== End of Fixlog 21:18:55 ====

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Vytížený procesor - kontrola logu

#12 Příspěvek od Rudy »

Smazáno. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Rhonnyn
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 25 kvě 2016 18:40

Re: Vytížený procesor - kontrola logu

#13 Příspěvek od Rhonnyn »

ano procesor uz neni tak vytizeny a je to daleko lepsi...dekuju moc

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Vytížený procesor - kontrola logu

#14 Příspěvek od Rudy »

Rádo se stalo! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno