Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

nejspis zavirovany pc, problem se skype, zpomaleny pc

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Jerma
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 08 dub 2017 15:52

nejspis zavirovany pc, problem se skype, zpomaleny pc

#1 Příspěvek od Jerma »

Zdravim, prosim o kontrolu logu, mam problem s funkcnosti skype, dale webkamera se spousti sama i kdyz ji udajne zadna aplikace nepouziva, mam podezreni ze mam pocitac zavirovany prave skrz skype.
Moc dekuju

Logfile of random's system information tool 1.10 (written by random/random)
Run by belfast at 2017-04-08 13:47:17
Microsoft Windows 8.1 Pro
System drive C: has 265 GB (57%) free of 467 GB
Total RAM: 4020 MB (46% free)


======Listing Processes======





wininit.exe

winlogon.exe

C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
"dwm.exe"
C:\Windows\system32\igfxCUIService.exe
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SRSPS
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SENDINPUT
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe 760375705232
\??\C:\Windows\system32\conhost.exe 0x4
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe"
"C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\adminservice.exe"
C:\Windows\system32\DptfParticipantProcessorService.exe
C:\Windows\system32\DptfPolicyCriticalService.exe
dashost.exe {b765a3b3-996f-4719-a994efa8a0118321}
"C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe"
"c:\Program Files\Intel\iCLS Client\HeciServer.exe"
C:\Windows\system32\svchost.exe -k imgsvc

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-62a34779-9c33-439d-a1dc-378ad7e7bd15 -SystemEventPortName:HostProcess-ba995269-cf0c-4203-91b2-8da6c93aa788 -IoCancelEventPortName:HostProcess-24ee23dd-b5ac-4a6b-be1b-bf471e38738b -NonStateChangingEventPortName:HostProcess-a10dc9bf-7b67-441c-a838-a23ba1b28818 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:53ff8ca4-f6bb-4579-bd97-8e3d053f0328 -DeviceGroupId:WudfDefaultDevicePool

taskhostex.exe
C:\Windows\Explorer.EXE
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
igfxEM.exe
igfxHK.exe
igfxTray.exe
/QuitInfo:000000000000098C;0000000000000990;
/loadhooks /Parent:0000000000000c3c
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe"
"C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\ActivateDesktop.exe"
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /MAXX5
"C:\Program Files\Dell\QuickSet\quickset.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe" /autorun
"C:\MAMPPRO\MAMPROSysTray.exe"
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /IM
"C:\Users\belfast\AppData\Roaming\Telegram Desktop\Telegram.exe"
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files (x86)\Dell Customer Connect\DCCService.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Dell\Dell Foundation Services\DFSSvc.exe"
"C:\Program Files (x86)\Dell Update\DellUpService.exe"
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
/x /hideintroballoon /launchedbywindowsservice
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe"
"C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe"
"C:\Program Files\Dell\Dell Foundation Services\DFS.Common.Agent.exe"
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files (x86)\Dell Backup and Recovery\COMPONENTS\DBRUPDATE\DBRUPD.EXE"
"C:\Program Files (x86)\Dell Backup and Recovery\TOASTER.EXE" C:\Users\belfast
C:\Windows\sysWOW64\wbem\wmiprvse.exe -Embedding
"C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBRCrawler.exe"
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe" -Embedding
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe" -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 "--database=C:\Users\belfast\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\belfast\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=57.0.2987.133 --initial-client-data=0x124,0x128,0x12c,0x120,0x130,0x665a7dc8,0x665a7dbc,0x665a7dd4
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=3632 --on-initialized-event-handle=448 --parent-handle=452 /prefetch:6
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1256 --disable-direct-composition --supports-dual-gpus=false --gpu-driver-bug-workarounds=7,10,18,19,20,23,41,61,74 --disable-gl-extensions="GL_KHR_blend_equation_advanced GL_KHR_blend_equation_advanced_coherent" --gpu-vendor-id=0x8086 --gpu-device-id=0x0a16 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.3945 --gpu-driver-date=9-16-2014 --service-request-channel-token=F07C43BC024396D0C1BB908F04A5144B --mojo-platform-channel-handle=1268 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1256 --primordial-pipe-token=E863DE6FA3B21838233BCF6845B5E51C --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=false --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=E863DE6FA3B21838233BCF6845B5E51C --renderer-client-id=19 --mojo-platform-channel-handle=5792 /prefetch:1

"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1256 --primordial-pipe-token=3093D91E121823AFE420CF3CC393A974 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=false --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=3093D91E121823AFE420CF3CC393A974 --renderer-client-id=57 --mojo-platform-channel-handle=5960 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi-broker --field-trial-handle=1256 --lang=en-US --device-scale-factor=1 --ppapi-antialiased-text-enabled=1 --ppapi-subpixel-rendering-setting=1 --service-request-channel-token=4DAA2B1866F369E7EEC50FA107F679E1 --mojo-platform-channel-handle=6400 /prefetch:4
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe10_ Global\UsGthrCtrlFltPipeMssGthrPipe10 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 556 560 568 65536 564
"C:\Users\belfast\Downloads\RSITx64.exe"

=========Mozilla firefox=========

ProfilePath - C:\Users\belfast\AppData\Roaming\Mozilla\Firefox\Profiles\1h0kthne.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.32.8\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.32.8\npGoogleUpdate3.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2014-08-06 7634648]
"RtHDVBg"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-07-28 1393520]
"IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2013-11-21 36352]
"QuickSet"=c:\Program Files\Dell\QuickSet\QuickSet.exe [2014-10-07 3859968]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"BtvStack"=C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe [2014-08-14 134784]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Fitbit Connect"=C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe [2015-10-28 4567720]
"MampTray"=C:\MAMPPRO\MAMPROSysTray.exe [2016-05-13 231936]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2017-03-14 27545048]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"DropboxOEM"=C:\Program Files (x86)\Dropbox\DropboxOEM\DropboxOEM.exe [2014-09-02 462160]
"Fitbit Connect"=C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe [2015-10-28 4567720]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"BtvStack"=C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe [2014-08-14 134784]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcapexe]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\McNaiAnn]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableCAD"=1
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0
"NoFolderOptions"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2017-04-08 13:47:17 ----D---- C:\rsit
2017-04-08 13:47:17 ----D---- C:\Program Files\trend micro
2017-04-01 20:42:02 ----RD---- C:\Program Files (x86)\Skype

======List of files/folders modified in the last 1 month======

2017-04-08 13:47:20 ----D---- C:\Windows\Prefetch
2017-04-08 13:47:17 ----RD---- C:\Program Files
2017-04-08 13:45:35 ----D---- C:\Users\belfast\AppData\Roaming\Skype
2017-04-08 13:23:22 ----D---- C:\Windows\System32
2017-04-08 13:23:22 ----D---- C:\Windows\Inf
2017-04-08 13:23:22 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-04-08 13:00:00 ----D---- C:\Windows\system32\sru
2017-04-08 12:26:37 ----D---- C:\Windows\Temp
2017-04-08 12:07:11 ----D---- C:\Users\belfast\AppData\Roaming\FileZilla
2017-04-08 10:19:05 ----D---- C:\Program Files (x86)\Dell Backup and Recovery
2017-04-08 10:12:27 ----D---- C:\Users\belfast\AppData\Roaming\Telegram Desktop
2017-04-07 17:23:40 ----D---- C:\Windows\system32\drivers
2017-04-07 00:10:03 ----D---- C:\Windows\Microsoft.NET
2017-04-06 23:31:50 ----D---- C:\KMPlayer
2017-04-06 20:14:10 ----SHD---- C:\Windows\Installer
2017-04-06 20:09:09 ----RD---- C:\Program Files (x86)
2017-04-06 14:57:56 ----D---- C:\sites
2017-04-01 20:42:10 ----D---- C:\ProgramData\Skype
2017-04-01 20:42:02 ----D---- C:\Program Files (x86)\Common Files
2017-04-01 20:41:04 ----D---- C:\ProgramData\Package Cache
2017-04-01 20:40:58 ----SHD---- C:\System Volume Information
2017-04-01 08:05:43 ----D---- C:\Program Files\SecurityKISS Tunnel
2017-03-26 23:46:44 ----D---- C:\Windows\system32\config
2017-03-14 16:30:29 ----D---- C:\Windows\SysWOW64
2017-03-14 16:30:11 ----D---- C:\Windows
2017-03-09 21:47:20 ----D---- C:\Windows\system32\NDF

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 BTATH_BUS;@oem191.inf,%BTATH_BUS.SVCDESC%;Qualcomm Atheros Bluetooth Bus; C:\Windows\System32\drivers\btath_bus.sys [2014-08-14 35016]
R0 iaStorA;iaStorA; C:\Windows\System32\drivers\iaStorA.sys [2014-02-26 632168]
R3 athr;@oem64.inf,%ATHR.Service.DispName%;Dell Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athwbx.sys [2014-07-11 3903488]
R3 BtFilter;BtFilter; C:\Windows\system32\DRIVERS\btfilter.sys [2014-08-14 598728]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2015-03-25 81920]
R3 DellRbtn;@oem60.inf,%DellRbtn%;Airplane Mode Switch; C:\Windows\System32\drivers\DellRbtn.sys [2013-01-24 10752]
R3 DptfDevGen;DptfDevGen; C:\Windows\System32\drivers\DptfDevGen.sys [2014-05-16 78504]
R3 DptfDevPch;DptfDevPch; C:\Windows\System32\drivers\DptfDevPch.sys [2014-05-16 116752]
R3 DptfDevProc;DptfDevProc; C:\Windows\System32\drivers\DptfDevProc.sys [2014-05-16 290256]
R3 DptfManager;DptfManager; C:\Windows\System32\drivers\DptfManager.sys [2014-05-16 494808]
R3 iaLPSS_GPIO;@oem69.inf,%iaLPSS_GPIO.SVCDESC%;Intel(R) Serial IO GPIO Driver; C:\Windows\System32\drivers\iaLPSS_GPIO.sys [2013-08-08 24568]
R3 iaLPSS_I2C;@oem70.inf,%iaLPSS_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver; C:\Windows\System32\drivers\iaLPSS_I2C.sys [2013-08-08 99320]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2014-09-30 3826320]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-08-06 4023920]
R3 iwdbus;@oem202.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\Windows\System32\drivers\iwdbus.sys [2014-08-01 27032]
R3 MEIx64;@oem67.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\Windows\System32\drivers\TeeDriverx64.sys [2013-12-04 100824]
R3 SensorsHIDClassDriver;@sensorshidclassdriver.inf,%WudfSensorsHIDClassDriverDisplayName%;Služba Reflektor UMDF pro knihovnu SensorsHIDClassDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [2015-03-25 226304]
R3 SensorsServiceDriver;@sensorsservicedriver.inf,%WudfSensorsServiceDriverDisplayName%;Služba Reflektor UMDF pro knihovnu SensorsServiceDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [2015-03-25 226304]
R3 tap0901;@oem205.inf,%DeviceDescription%;TAP-Win32 Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [2013-08-09 31232]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;Zobrazovací zařízení USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2015-03-25 212736]
R3 VirtualButtons;@oem190.inf,%VirtualButtons%;Intel(R) Virtual Buttons; C:\Windows\System32\drivers\VirtualButtons.sys [2013-10-04 32024]
S3 aswTap;@oem149.inf,%DeviceDescription%;avast! SecureLine TAP Adapter v3; C:\Windows\system32\DRIVERS\aswTap.sys [2014-09-05 44640]
S3 AthBTPort;@oem194.inf,%BTHSUPPORT.SvcDesc%;Qualcomm Atheros Virtual Bluetooth Class; C:\Windows\system32\DRIVERS\btath_flt.sys [2014-08-14 89800]
S3 BTATH_A2DP;@oem193.inf,%BTATH_A2DP.SvcDesc%;Bluetooth A2DP Audio Driver; C:\Windows\system32\drivers\btath_a2dp.sys [2014-08-14 338120]
S3 btath_avdt;@oem193.inf,%btath_avdt.SvcDesc%;Qualcomm Atheros Bluetooth AVDT Service; C:\Windows\system32\drivers\btath_avdt.sys [2014-08-14 118984]
S3 BTATH_HCRP;@oem196.inf,%BTATH_HCRP.SvcDesc%;Bluetooth HCRP Server driver; C:\Windows\System32\drivers\btath_hcrp.sys [2014-08-14 179432]
S3 BTATH_LWFLT;@oem198.inf,%BTATH_LWFLT%;Bluetooth LWFLT Device; C:\Windows\system32\DRIVERS\btath_lwflt.sys [2014-08-14 77464]
S3 BTATH_RCP;@oem200.inf,%BTATH_RCP%;Bluetooth AVRCP Device; C:\Windows\System32\drivers\btath_rcp.sys [2014-08-14 137928]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2015-03-25 53248]
S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Ovladač úspory energie technologie Bluetooth; C:\Windows\system32\DRIVERS\BthLEEnum.sys [2014-03-18 226304]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2015-03-25 118272]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2015-03-25 1198080]
S3 DDDriver;DDDriver; C:\Windows\system32\drivers\DDDriver64Dcsa.sys [2016-01-05 32464]
S3 DellProf;DellProf; C:\Windows\system32\drivers\DellProf.sys [2016-01-05 24240]
S3 dg_ssudbus;@oem152.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2016-09-05 131712]
S3 dot4;@oem126.inf,%Dot4_Name%;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2012-10-18 151968]
S3 Dot4Print;@oem129.inf,%Dot4Print_Name%;Print Class Driver for IEEE-1284.4; C:\Windows\System32\drivers\Dot4Prt.sys [2012-10-18 27040]
S3 dot4usb;@oem126.inf,%DOT4USB_NAME%;Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2012-10-18 49056]
S3 DptfDevDisplay;DptfDevDisplay; C:\Windows\System32\drivers\DptfDevDisplay.sys [2014-05-16 70752]
S3 DptfDevDram;DptfDevDram; C:\Windows\System32\drivers\DptfDevDram.sys [2014-05-16 145640]
S3 DptfDevFan;DptfDevFan; C:\Windows\System32\drivers\DptfDevFan.sys [2014-05-16 50640]
S3 DptfDevPower;DptfDevPower; C:\Windows\System32\drivers\DptfDevPower.sys [2014-05-16 71808]
S3 iaLPSS_SPI;@oem71.inf,%iaLPSS_SPI.SVCDESC%;Intel(R) Serial IO SPI Driver; C:\Windows\System32\drivers\iaLPSS_SPI.sys [2013-08-08 83960]
S3 iaLPSS_UART2;@oem72.inf,%iaLPSS_UART2.SVCDESC%;Intel(R) Serial IO UART Driver v2; C:\Windows\System32\drivers\iaLPSS_UART2.sys [2013-08-08 129528]
S3 intaud_WaveExtensible;@oem199.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\Windows\system32\drivers\intelaud.sys [2014-08-01 38296]
S3 IntcDAud;@oem195.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2014-09-23 454416]
S3 PCDSRVC{3B54B31B-D06B6431-06020200}_0;PCDSRVC{3B54B31B-D06B6431-06020200}_0 - PCDR Kernel Mode Service Helper Driver; \??\c:\program files\dell\supportassist\pcdsrvc_x64.pkms [2017-02-16 25584]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2014-03-18 167424]
S3 RTLU3E8023-W8-64;@oem63.inf,%Rtlunic.Service.DispName%;Realtek USB GBE NIC Family Windows8 64bit Driver; C:\Windows\system32\DRIVERS\rtu30x64w8.sys [2013-10-09 92376]
S3 ssudmdm;@oem158.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2016-09-05 165504]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2015-03-25 44544]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AERTFilters;Andrea RT Filters Service; C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-17 98208]
R2 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\adminservice.exe [2014-08-14 322176]
R2 Dell Customer Connect;Dell Customer Connect; C:\Program Files (x86)\Dell Customer Connect\DCCService.exe [2016-12-21 130936]
R2 Dell Foundation Services;Dell Foundation Services; C:\Program Files\Dell\Dell Foundation Services\DFSSvc.exe [2017-01-11 97616]
R2 DellUpdate;Dell Update Service; C:\Program Files (x86)\Dell Update\DellUpService.exe [2015-08-27 237272]
R2 DptfParticipantProcessorService;@oem68.inf,%WIN32_DPTF_PARTICIPANT_PROC_SERVICE_DISPLAY_NAME%;Intel(R) Dynamic Platform and Thermal Framework Processor Participant Service Application; C:\Windows\system32\DptfParticipantProcessorService.exe [2014-05-16 115656]
R2 DptfPolicyCriticalService;@oem68.inf,%WIN32_DPTF_POLICY_CRITICAL_SERVICE_DISPLAY_NAME%;Intel(R) Dynamic Platform and Thermal Framework Critical Service Application; C:\Windows\system32\DptfPolicyCriticalService.exe [2014-05-16 148160]
R2 Fitbit Connect;Fitbit Connect Service; C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe [2015-10-28 5906088]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-11-21 15720]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\Windows\system32\igfxCUIService.exe [2014-09-30 318568]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; c:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-08-27 747520]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-12-04 169432]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-12-04 390616]
R2 RtkAudioService;Realtek Audio Service; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [2014-07-22 291032]
R2 SftService;SoftThinks Agent Service; C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe [2014-07-02 1921768]
R2 SupportAssistAgent;Dell SupportAssist Agent; C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [2016-09-09 31704]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2014-03-18 43696]
S2 DellDigitalDelivery;Dell Digital Delivery Service; C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe [2015-03-16 237448]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-02-24 154440]
S2 MAMPDNS;MAMPRO DNS Service; C:\MAMPPRO\MAMPDNSService.exe [2016-05-13 22528]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2017-02-27 317400]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2014-09-30 280680]
S3 DellProdRegManager;Dell Product Registration Manager; C:\Program Files (x86)\Dell Product Registration\regmgrsvc.exe [2014-10-31 278568]
S3 emailrelay;E-MailRelay; C:\MAMP\bin\emailrelay\emailrelay-service.exe [2014-07-30 705536]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-02-24 154440]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-08-27 828376]
S3 MAMPPRO;MAMPRO Service; C:\MAMPPRO\MAMPPROService.exe [2016-05-13 25088]
S3 MAMPPRO-Apache;MAMPPRO-Apache; C:\MAMP\bin\apache\bin\httpd.exe [2016-05-06 18432]
S3 MAMPPRO-MySQL;MAMPPRO-MySQL; C:\MAMP\bin\mysql\bin\mysqld.exe [2016-05-05 8152064]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-11-13 146888]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119670
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: nejspis zavirovany pc, problem se skype, zpomaleny pc

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan<(hledání) a pak na >Clean< (mazání).
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Jerma
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 08 dub 2017 15:52

Re: nejspis zavirovany pc, problem se skype, zpomaleny pc

#3 Příspěvek od Jerma »

Dekuju, spusteno, log zde:

# AdwCleaner v6.045 - Log vytvořen 08/04/2017 v 16:05:58
# Aktualizováno dne 28/03/2017 z Malwarebytes
# Databáze : 2017-04-06.1 [Server]
# Operační systém : Windows 8.1 Pro (X64)
# Uživatelské jméno : belfast - GOODBYE-KITTY
# Spuštěno z : C:\Users\belfast\Desktop\adwcleaner_6.045.exe
# Mod: Čištění
# Podpora : https://www.malwarebytes.com/support



***** [ Služby ] *****



***** [ Složky ] *****



***** [ Soubory ] *****



***** [ DLL ] *****



***** [ WMI ] *****



***** [ Zástupci ] *****



***** [ Naplánované úlohy ] *****



***** [ Registry ] *****

[-] Klíč smazán: HKU\S-1-5-21-940258680-3092732010-732691022-1001\Software\Conduit
[#] Klíč smazán po restartu: HKCU\Software\Conduit
[-] Klíč smazán: HKLM\SOFTWARE\Conduit
[#] Klíč smazán po restartu: [x64] HKCU\Software\Conduit


***** [ Prohlížeče ] *****



*************************

:: "Tracing" klíče smazány
:: Winsock nastavení vyčištěno

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [1043 Bajty] - [08/04/2017 16:05:58]
C:\AdwCleaner\AdwCleaner[S0].txt - [1522 Bajty] - [08/04/2017 16:05:33]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [1189 Bajty] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119670
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: nejspis zavirovany pc, problem se skype, zpomaleny pc

#4 Příspěvek od Rudy »

Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Jerma
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 08 dub 2017 15:52

Re: nejspis zavirovany pc, problem se skype, zpomaleny pc

#5 Příspěvek od Jerma »

novy RSIT

Logfile of random's system information tool 1.10 (written by random/random)
Run by belfast at 2017-04-08 17:14:51
Microsoft Windows 8.1 Pro
System drive C: has 265 GB (57%) free of 467 GB
Total RAM: 4020 MB (60% free)


======Listing Processes======





wininit.exe

winlogon.exe

C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
"dwm.exe"
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\igfxCUIService.exe
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SRSPS
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SENDINPUT
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe 258488679040
\??\C:\Windows\system32\conhost.exe 0x4
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe"
"C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\adminservice.exe"
C:\Windows\system32\DptfParticipantProcessorService.exe
dashost.exe {2a3e1856-beec-4fce-ada374ba6f712e1f}
C:\Windows\system32\DptfPolicyCriticalService.exe
"C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe"
"c:\Program Files\Intel\iCLS Client\HeciServer.exe"
C:\Windows\system32\svchost.exe -k imgsvc

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-cb0dd155-8250-4b7a-a8bb-3dd77c8dd084 -SystemEventPortName:HostProcess-b8e2122b-1233-4999-9521-ff94ed6699d5 -IoCancelEventPortName:HostProcess-6d2f5b71-ff9d-4c26-b986-8ea74caa4a06 -NonStateChangingEventPortName:HostProcess-a64d4f0c-4400-44a1-bb19-1c9f579b24e0 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:b6f71c63-9ee7-48d0-8695-0259f3b3d7f7 -DeviceGroupId:WudfDefaultDevicePool

taskhostex.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\Explorer.EXE
igfxEM.exe
igfxHK.exe
igfxTray.exe
/QuitInfo:00000000000009A8;0000000000000998;
/loadhooks /Parent:0000000000000cac
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe"
"C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\ActivateDesktop.exe"
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /MAXX5
"C:\Program Files\Dell\QuickSet\quickset.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe" /autorun
"C:\MAMPPRO\MAMPROSysTray.exe"
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
C:\Windows\system32\wbem\wmiprvse.exe

"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /IM
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files (x86)\Dell Customer Connect\DCCService.exe"
"C:\Program Files\Dell\Dell Foundation Services\DFSSvc.exe"
"C:\Program Files (x86)\Dell Update\DellUpService.exe"
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
/x /hideintroballoon /launchedbywindowsservice
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe"
"C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe"
"C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe" -Embedding
"C:\Users\belfast\AppData\Roaming\Telegram Desktop\Telegram.exe"
"C:\Program Files\Dell\Dell Foundation Services\DFS.Common.Agent.exe"
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files (x86)\Dell Backup and Recovery\COMPONENTS\DBRUPDATE\DBRUPD.EXE"
"C:\Program Files (x86)\Dell Backup and Recovery\TOASTER.EXE" C:\Users\belfast
C:\Windows\sysWOW64\wbem\wmiprvse.exe -Embedding
"C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBRCrawler.exe"
\??\C:\Windows\system32\conhost.exe 0x4
taskeng.exe {87F409AB-BA19-49AE-8A12-FC1A47131E38}
"C:\Users\belfast\Downloads\RSITx64.exe"

=========Mozilla firefox=========

ProfilePath - C:\Users\belfast\AppData\Roaming\Mozilla\Firefox\Profiles\1h0kthne.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.32.8\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.32.8\npGoogleUpdate3.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2014-08-06 7634648]
"RtHDVBg"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-07-28 1393520]
"IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2013-11-21 36352]
"QuickSet"=c:\Program Files\Dell\QuickSet\QuickSet.exe [2014-10-07 3859968]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"BtvStack"=C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe [2014-08-14 134784]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Fitbit Connect"=C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe [2015-10-28 4567720]
"MampTray"=C:\MAMPPRO\MAMPROSysTray.exe [2016-05-13 231936]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2017-03-14 27545048]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"DropboxOEM"=C:\Program Files (x86)\Dropbox\DropboxOEM\DropboxOEM.exe [2014-09-02 462160]
"Fitbit Connect"=C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe [2015-10-28 4567720]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"BtvStack"=C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe [2014-08-14 134784]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcapexe]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\McNaiAnn]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableCAD"=1
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0
"NoFolderOptions"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2017-04-08 16:04:06 ----D---- C:\AdwCleaner
2017-04-08 13:47:17 ----D---- C:\rsit
2017-04-08 13:47:17 ----D---- C:\Program Files\trend micro
2017-04-01 20:42:02 ----RD---- C:\Program Files (x86)\Skype

======List of files/folders modified in the last 1 month======

2017-04-08 17:09:14 ----D---- C:\Users\belfast\AppData\Roaming\Skype
2017-04-08 17:00:02 ----D---- C:\Windows\system32\sru
2017-04-08 16:40:01 ----D---- C:\Windows\Temp
2017-04-08 16:15:10 ----D---- C:\Program Files (x86)\Dell Backup and Recovery
2017-04-08 16:12:55 ----D---- C:\Users\belfast\AppData\Roaming\Telegram Desktop
2017-04-08 16:08:16 ----D---- C:\Windows\Prefetch
2017-04-08 13:47:17 ----RD---- C:\Program Files
2017-04-08 13:23:22 ----D---- C:\Windows\System32
2017-04-08 13:23:22 ----D---- C:\Windows\Inf
2017-04-08 13:23:22 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-04-08 12:07:11 ----D---- C:\Users\belfast\AppData\Roaming\FileZilla
2017-04-07 17:23:40 ----D---- C:\Windows\system32\drivers
2017-04-07 00:10:03 ----D---- C:\Windows\Microsoft.NET
2017-04-06 23:31:50 ----D---- C:\KMPlayer
2017-04-06 20:14:10 ----SHD---- C:\Windows\Installer
2017-04-06 20:09:09 ----RD---- C:\Program Files (x86)
2017-04-06 14:57:56 ----D---- C:\sites
2017-04-01 20:42:10 ----D---- C:\ProgramData\Skype
2017-04-01 20:42:02 ----D---- C:\Program Files (x86)\Common Files
2017-04-01 20:41:04 ----D---- C:\ProgramData\Package Cache
2017-04-01 20:40:58 ----SHD---- C:\System Volume Information
2017-04-01 08:05:43 ----D---- C:\Program Files\SecurityKISS Tunnel
2017-03-26 23:46:44 ----D---- C:\Windows\system32\config
2017-03-14 16:30:29 ----D---- C:\Windows\SysWOW64
2017-03-14 16:30:11 ----D---- C:\Windows
2017-03-09 21:47:29 ----D---- C:\Windows\system32\NDF

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 BTATH_BUS;@oem191.inf,%BTATH_BUS.SVCDESC%;Qualcomm Atheros Bluetooth Bus; C:\Windows\System32\drivers\btath_bus.sys [2014-08-14 35016]
R0 iaStorA;iaStorA; C:\Windows\System32\drivers\iaStorA.sys [2014-02-26 632168]
R3 athr;@oem64.inf,%ATHR.Service.DispName%;Dell Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athwbx.sys [2014-07-11 3903488]
R3 BtFilter;BtFilter; C:\Windows\system32\DRIVERS\btfilter.sys [2014-08-14 598728]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2015-03-25 81920]
R3 DellRbtn;@oem60.inf,%DellRbtn%;Airplane Mode Switch; C:\Windows\System32\drivers\DellRbtn.sys [2013-01-24 10752]
R3 DptfDevGen;DptfDevGen; C:\Windows\System32\drivers\DptfDevGen.sys [2014-05-16 78504]
R3 DptfDevPch;DptfDevPch; C:\Windows\System32\drivers\DptfDevPch.sys [2014-05-16 116752]
R3 DptfDevProc;DptfDevProc; C:\Windows\System32\drivers\DptfDevProc.sys [2014-05-16 290256]
R3 DptfManager;DptfManager; C:\Windows\System32\drivers\DptfManager.sys [2014-05-16 494808]
R3 iaLPSS_GPIO;@oem69.inf,%iaLPSS_GPIO.SVCDESC%;Intel(R) Serial IO GPIO Driver; C:\Windows\System32\drivers\iaLPSS_GPIO.sys [2013-08-08 24568]
R3 iaLPSS_I2C;@oem70.inf,%iaLPSS_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver; C:\Windows\System32\drivers\iaLPSS_I2C.sys [2013-08-08 99320]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2014-09-30 3826320]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-08-06 4023920]
R3 iwdbus;@oem202.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\Windows\System32\drivers\iwdbus.sys [2014-08-01 27032]
R3 MEIx64;@oem67.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\Windows\System32\drivers\TeeDriverx64.sys [2013-12-04 100824]
R3 SensorsHIDClassDriver;@sensorshidclassdriver.inf,%WudfSensorsHIDClassDriverDisplayName%;Služba Reflektor UMDF pro knihovnu SensorsHIDClassDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [2015-03-25 226304]
R3 SensorsServiceDriver;@sensorsservicedriver.inf,%WudfSensorsServiceDriverDisplayName%;Služba Reflektor UMDF pro knihovnu SensorsServiceDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [2015-03-25 226304]
R3 tap0901;@oem205.inf,%DeviceDescription%;TAP-Win32 Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [2013-08-09 31232]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;Zobrazovací zařízení USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2015-03-25 212736]
R3 VirtualButtons;@oem190.inf,%VirtualButtons%;Intel(R) Virtual Buttons; C:\Windows\System32\drivers\VirtualButtons.sys [2013-10-04 32024]
S3 aswTap;@oem149.inf,%DeviceDescription%;avast! SecureLine TAP Adapter v3; C:\Windows\system32\DRIVERS\aswTap.sys [2014-09-05 44640]
S3 AthBTPort;@oem194.inf,%BTHSUPPORT.SvcDesc%;Qualcomm Atheros Virtual Bluetooth Class; C:\Windows\system32\DRIVERS\btath_flt.sys [2014-08-14 89800]
S3 BTATH_A2DP;@oem193.inf,%BTATH_A2DP.SvcDesc%;Bluetooth A2DP Audio Driver; C:\Windows\system32\drivers\btath_a2dp.sys [2014-08-14 338120]
S3 btath_avdt;@oem193.inf,%btath_avdt.SvcDesc%;Qualcomm Atheros Bluetooth AVDT Service; C:\Windows\system32\drivers\btath_avdt.sys [2014-08-14 118984]
S3 BTATH_HCRP;@oem196.inf,%BTATH_HCRP.SvcDesc%;Bluetooth HCRP Server driver; C:\Windows\System32\drivers\btath_hcrp.sys [2014-08-14 179432]
S3 BTATH_LWFLT;@oem198.inf,%BTATH_LWFLT%;Bluetooth LWFLT Device; C:\Windows\system32\DRIVERS\btath_lwflt.sys [2014-08-14 77464]
S3 BTATH_RCP;@oem200.inf,%BTATH_RCP%;Bluetooth AVRCP Device; C:\Windows\System32\drivers\btath_rcp.sys [2014-08-14 137928]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2015-03-25 53248]
S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Ovladač úspory energie technologie Bluetooth; C:\Windows\system32\DRIVERS\BthLEEnum.sys [2014-03-18 226304]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2015-03-25 118272]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2015-03-25 1198080]
S3 DDDriver;DDDriver; C:\Windows\system32\drivers\DDDriver64Dcsa.sys [2016-01-05 32464]
S3 DellProf;DellProf; C:\Windows\system32\drivers\DellProf.sys [2016-01-05 24240]
S3 dg_ssudbus;@oem152.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2016-09-05 131712]
S3 dot4;@oem126.inf,%Dot4_Name%;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2012-10-18 151968]
S3 Dot4Print;@oem129.inf,%Dot4Print_Name%;Print Class Driver for IEEE-1284.4; C:\Windows\System32\drivers\Dot4Prt.sys [2012-10-18 27040]
S3 dot4usb;@oem126.inf,%DOT4USB_NAME%;Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2012-10-18 49056]
S3 DptfDevDisplay;DptfDevDisplay; C:\Windows\System32\drivers\DptfDevDisplay.sys [2014-05-16 70752]
S3 DptfDevDram;DptfDevDram; C:\Windows\System32\drivers\DptfDevDram.sys [2014-05-16 145640]
S3 DptfDevFan;DptfDevFan; C:\Windows\System32\drivers\DptfDevFan.sys [2014-05-16 50640]
S3 DptfDevPower;DptfDevPower; C:\Windows\System32\drivers\DptfDevPower.sys [2014-05-16 71808]
S3 iaLPSS_SPI;@oem71.inf,%iaLPSS_SPI.SVCDESC%;Intel(R) Serial IO SPI Driver; C:\Windows\System32\drivers\iaLPSS_SPI.sys [2013-08-08 83960]
S3 iaLPSS_UART2;@oem72.inf,%iaLPSS_UART2.SVCDESC%;Intel(R) Serial IO UART Driver v2; C:\Windows\System32\drivers\iaLPSS_UART2.sys [2013-08-08 129528]
S3 intaud_WaveExtensible;@oem199.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\Windows\system32\drivers\intelaud.sys [2014-08-01 38296]
S3 IntcDAud;@oem195.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2014-09-23 454416]
S3 PCDSRVC{3B54B31B-D06B6431-06020200}_0;PCDSRVC{3B54B31B-D06B6431-06020200}_0 - PCDR Kernel Mode Service Helper Driver; \??\c:\program files\dell\supportassist\pcdsrvc_x64.pkms [2017-02-16 25584]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2014-03-18 167424]
S3 RTLU3E8023-W8-64;@oem63.inf,%Rtlunic.Service.DispName%;Realtek USB GBE NIC Family Windows8 64bit Driver; C:\Windows\system32\DRIVERS\rtu30x64w8.sys [2013-10-09 92376]
S3 ssudmdm;@oem158.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2016-09-05 165504]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2015-03-25 44544]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AERTFilters;Andrea RT Filters Service; C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-17 98208]
R2 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\adminservice.exe [2014-08-14 322176]
R2 Dell Customer Connect;Dell Customer Connect; C:\Program Files (x86)\Dell Customer Connect\DCCService.exe [2016-12-21 130936]
R2 Dell Foundation Services;Dell Foundation Services; C:\Program Files\Dell\Dell Foundation Services\DFSSvc.exe [2017-01-11 97616]
R2 DellUpdate;Dell Update Service; C:\Program Files (x86)\Dell Update\DellUpService.exe [2015-08-27 237272]
R2 DptfParticipantProcessorService;@oem68.inf,%WIN32_DPTF_PARTICIPANT_PROC_SERVICE_DISPLAY_NAME%;Intel(R) Dynamic Platform and Thermal Framework Processor Participant Service Application; C:\Windows\system32\DptfParticipantProcessorService.exe [2014-05-16 115656]
R2 DptfPolicyCriticalService;@oem68.inf,%WIN32_DPTF_POLICY_CRITICAL_SERVICE_DISPLAY_NAME%;Intel(R) Dynamic Platform and Thermal Framework Critical Service Application; C:\Windows\system32\DptfPolicyCriticalService.exe [2014-05-16 148160]
R2 Fitbit Connect;Fitbit Connect Service; C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe [2015-10-28 5906088]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-11-21 15720]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\Windows\system32\igfxCUIService.exe [2014-09-30 318568]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; c:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-08-27 747520]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-12-04 169432]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-12-04 390616]
R2 RtkAudioService;Realtek Audio Service; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [2014-07-22 291032]
R2 SftService;SoftThinks Agent Service; C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe [2014-07-02 1921768]
R2 SupportAssistAgent;Dell SupportAssist Agent; C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [2016-09-09 31704]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2014-03-18 43696]
S2 DellDigitalDelivery;Dell Digital Delivery Service; C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe [2015-03-16 237448]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-02-24 154440]
S2 MAMPDNS;MAMPRO DNS Service; C:\MAMPPRO\MAMPDNSService.exe [2016-05-13 22528]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2017-02-27 317400]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2014-09-30 280680]
S3 DellProdRegManager;Dell Product Registration Manager; C:\Program Files (x86)\Dell Product Registration\regmgrsvc.exe [2014-10-31 278568]
S3 emailrelay;E-MailRelay; C:\MAMP\bin\emailrelay\emailrelay-service.exe [2014-07-30 705536]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-02-24 154440]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-08-27 828376]
S3 MAMPPRO;MAMPRO Service; C:\MAMPPRO\MAMPPROService.exe [2016-05-13 25088]
S3 MAMPPRO-Apache;MAMPPRO-Apache; C:\MAMP\bin\apache\bin\httpd.exe [2016-05-06 18432]
S3 MAMPPRO-MySQL;MAMPPRO-MySQL; C:\MAMP\bin\mysql\bin\mysqld.exe [2016-05-05 8152064]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-11-13 146888]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119670
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: nejspis zavirovany pc, problem se skype, zpomaleny pc

#6 Příspěvek od Rudy »

Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Jerma
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 08 dub 2017 15:52

Re: nejspis zavirovany pc, problem se skype, zpomaleny pc

#7 Příspěvek od Jerma »

Logfile of random's system information tool 1.10 (written by random/random)
Run by belfast at 2017-04-09 08:33:20
Microsoft Windows 8.1 Pro
System drive C: has 266 GB (57%) free of 467 GB
Total RAM: 4020 MB (58% free)


======Listing Processes======





wininit.exe

winlogon.exe

C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\igfxCUIService.exe
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SRSPS
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SENDINPUT
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe 834988366112
\??\C:\Windows\system32\conhost.exe 0x4
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe"
"C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\adminservice.exe"
C:\Windows\system32\DptfParticipantProcessorService.exe
dashost.exe {ff9ea910-2a54-4045-afd4790f3ddbcc98}
C:\Windows\system32\DptfPolicyCriticalService.exe
"C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe"
"c:\Program Files\Intel\iCLS Client\HeciServer.exe"
C:\Windows\system32\svchost.exe -k imgsvc

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-c698f400-6dee-4ef4-b883-6ea3c22192d9 -SystemEventPortName:HostProcess-0e3f7ada-305a-44ce-8a1d-a72858a0027f -IoCancelEventPortName:HostProcess-61ec6df2-3195-44d1-8a30-f442abdc205d -NonStateChangingEventPortName:HostProcess-f2e2d246-60b0-4ca4-a268-0e65fb09fb57 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:419cbad9-23de-44a5-89e8-1c784500c458 -DeviceGroupId:WudfDefaultDevicePool

taskhostex.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\Explorer.EXE
igfxEM.exe
igfxHK.exe
igfxTray.exe
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /IM
C:\Windows\system32\SearchIndexer.exe /Embedding
/QuitInfo:0000000000000AAC;0000000000000AB0;
/loadhooks /Parent:0000000000000e5c
"C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe"
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /MAXX5
"C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\ActivateDesktop.exe"
"C:\Program Files\Dell\QuickSet\quickset.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe" /autorun
"C:\MAMPPRO\MAMPROSysTray.exe"
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 556 560 568 65536 564
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 "--database=C:\Users\belfast\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\belfast\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=57.0.2987.133 --initial-client-data=0x124,0x128,0x12c,0x120,0x130,0x63fd7dc8,0x63fd7dbc,0x63fd7dd4
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=2664 --on-initialized-event-handle=448 --parent-handle=452 /prefetch:6
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1176 --disable-direct-composition --supports-dual-gpus=false --gpu-driver-bug-workarounds=7,10,18,19,20,23,41,61,74 --disable-gl-extensions="GL_KHR_blend_equation_advanced GL_KHR_blend_equation_advanced_coherent" --gpu-vendor-id=0x8086 --gpu-device-id=0x0a16 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.3945 --gpu-driver-date=9-16-2014 --service-request-channel-token=8E5B9A979314633EBAEE90D0002E3144 --mojo-platform-channel-handle=1220 --ignored=" --type=renderer " /prefetch:2

"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1176 --primordial-pipe-token=B80A5FEEEE0049A1FE03688C51CE164B --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=false --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=B80A5FEEEE0049A1FE03688C51CE164B --renderer-client-id=7 --mojo-platform-channel-handle=4596 /prefetch:1
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files (x86)\Dell Customer Connect\DCCService.exe"
"C:\Program Files\Dell\Dell Foundation Services\DFSSvc.exe"
"C:\Program Files (x86)\Dell Update\DellUpService.exe"
/x /hideintroballoon /launchedbywindowsservice
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe"
"C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe"

C:\Windows\WinStore\WSHost.exe -Embedding
"C:\Users\belfast\Downloads\RSITx64.exe"

=========Mozilla firefox=========

ProfilePath - C:\Users\belfast\AppData\Roaming\Mozilla\Firefox\Profiles\1h0kthne.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.32.8\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.32.8\npGoogleUpdate3.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2014-08-06 7634648]
"RtHDVBg"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-07-28 1393520]
"IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2013-11-21 36352]
"QuickSet"=c:\Program Files\Dell\QuickSet\QuickSet.exe [2014-10-07 3859968]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"BtvStack"=C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe [2014-08-14 134784]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Fitbit Connect"=C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe [2015-10-28 4567720]
"MampTray"=C:\MAMPPRO\MAMPROSysTray.exe [2016-05-13 231936]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2017-03-14 27545048]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"DropboxOEM"=C:\Program Files (x86)\Dropbox\DropboxOEM\DropboxOEM.exe [2014-09-02 462160]
"Fitbit Connect"=C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe [2015-10-28 4567720]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"BtvStack"=C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe [2014-08-14 134784]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcapexe]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\McNaiAnn]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableCAD"=1
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0
"NoFolderOptions"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2017-04-09 08:26:49 ----D---- C:\_OTM
2017-04-08 16:04:06 ----D---- C:\AdwCleaner
2017-04-08 13:47:17 ----D---- C:\rsit
2017-04-08 13:47:17 ----D---- C:\Program Files\trend micro
2017-04-01 20:42:02 ----RD---- C:\Program Files (x86)\Skype

======List of files/folders modified in the last 1 month======

2017-04-09 08:32:25 ----D---- C:\Windows\Temp
2017-04-09 08:31:56 ----D---- C:\Program Files (x86)\Dell Backup and Recovery
2017-04-09 08:30:52 ----D---- C:\Users\belfast\AppData\Roaming\Skype
2017-04-09 08:30:27 ----D---- C:\Windows\Prefetch
2017-04-09 08:28:59 ----D---- C:\Windows
2017-04-09 08:22:42 ----D---- C:\Windows\system32\sru
2017-04-09 00:31:06 ----D---- C:\Users\belfast\AppData\Roaming\FileZilla
2017-04-08 17:33:09 ----D---- C:\Users\belfast\AppData\Roaming\Telegram Desktop
2017-04-08 13:47:17 ----RD---- C:\Program Files
2017-04-08 13:23:22 ----D---- C:\Windows\System32
2017-04-08 13:23:22 ----D---- C:\Windows\Inf
2017-04-08 13:23:22 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-04-07 17:23:40 ----D---- C:\Windows\system32\drivers
2017-04-07 00:10:03 ----D---- C:\Windows\Microsoft.NET
2017-04-06 23:31:50 ----D---- C:\KMPlayer
2017-04-06 20:14:10 ----SHD---- C:\Windows\Installer
2017-04-06 20:09:09 ----RD---- C:\Program Files (x86)
2017-04-06 14:57:56 ----D---- C:\sites
2017-04-01 20:42:10 ----D---- C:\ProgramData\Skype
2017-04-01 20:42:02 ----D---- C:\Program Files (x86)\Common Files
2017-04-01 20:41:04 ----D---- C:\ProgramData\Package Cache
2017-04-01 20:40:58 ----SHD---- C:\System Volume Information
2017-04-01 08:05:43 ----D---- C:\Program Files\SecurityKISS Tunnel
2017-03-26 23:46:44 ----D---- C:\Windows\system32\config
2017-03-14 16:30:29 ----D---- C:\Windows\SysWOW64

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 BTATH_BUS;@oem191.inf,%BTATH_BUS.SVCDESC%;Qualcomm Atheros Bluetooth Bus; C:\Windows\System32\drivers\btath_bus.sys [2014-08-14 35016]
R0 iaStorA;iaStorA; C:\Windows\System32\drivers\iaStorA.sys [2014-02-26 632168]
R3 athr;@oem64.inf,%ATHR.Service.DispName%;Dell Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athwbx.sys [2014-07-11 3903488]
R3 BtFilter;BtFilter; C:\Windows\system32\DRIVERS\btfilter.sys [2014-08-14 598728]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2015-03-25 81920]
R3 DellRbtn;@oem60.inf,%DellRbtn%;Airplane Mode Switch; C:\Windows\System32\drivers\DellRbtn.sys [2013-01-24 10752]
R3 DptfDevGen;DptfDevGen; C:\Windows\System32\drivers\DptfDevGen.sys [2014-05-16 78504]
R3 DptfDevPch;DptfDevPch; C:\Windows\System32\drivers\DptfDevPch.sys [2014-05-16 116752]
R3 DptfDevProc;DptfDevProc; C:\Windows\System32\drivers\DptfDevProc.sys [2014-05-16 290256]
R3 DptfManager;DptfManager; C:\Windows\System32\drivers\DptfManager.sys [2014-05-16 494808]
R3 iaLPSS_GPIO;@oem69.inf,%iaLPSS_GPIO.SVCDESC%;Intel(R) Serial IO GPIO Driver; C:\Windows\System32\drivers\iaLPSS_GPIO.sys [2013-08-08 24568]
R3 iaLPSS_I2C;@oem70.inf,%iaLPSS_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver; C:\Windows\System32\drivers\iaLPSS_I2C.sys [2013-08-08 99320]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2014-09-30 3826320]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-08-06 4023920]
R3 iwdbus;@oem202.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\Windows\System32\drivers\iwdbus.sys [2014-08-01 27032]
R3 MEIx64;@oem67.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\Windows\System32\drivers\TeeDriverx64.sys [2013-12-04 100824]
R3 SensorsHIDClassDriver;@sensorshidclassdriver.inf,%WudfSensorsHIDClassDriverDisplayName%;Služba Reflektor UMDF pro knihovnu SensorsHIDClassDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [2015-03-25 226304]
R3 SensorsServiceDriver;@sensorsservicedriver.inf,%WudfSensorsServiceDriverDisplayName%;Služba Reflektor UMDF pro knihovnu SensorsServiceDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [2015-03-25 226304]
R3 tap0901;@oem205.inf,%DeviceDescription%;TAP-Win32 Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [2013-08-09 31232]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;Zobrazovací zařízení USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2015-03-25 212736]
R3 VirtualButtons;@oem190.inf,%VirtualButtons%;Intel(R) Virtual Buttons; C:\Windows\System32\drivers\VirtualButtons.sys [2013-10-04 32024]
S3 aswTap;@oem149.inf,%DeviceDescription%;avast! SecureLine TAP Adapter v3; C:\Windows\system32\DRIVERS\aswTap.sys [2014-09-05 44640]
S3 AthBTPort;@oem194.inf,%BTHSUPPORT.SvcDesc%;Qualcomm Atheros Virtual Bluetooth Class; C:\Windows\system32\DRIVERS\btath_flt.sys [2014-08-14 89800]
S3 BTATH_A2DP;@oem193.inf,%BTATH_A2DP.SvcDesc%;Bluetooth A2DP Audio Driver; C:\Windows\system32\drivers\btath_a2dp.sys [2014-08-14 338120]
S3 btath_avdt;@oem193.inf,%btath_avdt.SvcDesc%;Qualcomm Atheros Bluetooth AVDT Service; C:\Windows\system32\drivers\btath_avdt.sys [2014-08-14 118984]
S3 BTATH_HCRP;@oem196.inf,%BTATH_HCRP.SvcDesc%;Bluetooth HCRP Server driver; C:\Windows\System32\drivers\btath_hcrp.sys [2014-08-14 179432]
S3 BTATH_LWFLT;@oem198.inf,%BTATH_LWFLT%;Bluetooth LWFLT Device; C:\Windows\system32\DRIVERS\btath_lwflt.sys [2014-08-14 77464]
S3 BTATH_RCP;@oem200.inf,%BTATH_RCP%;Bluetooth AVRCP Device; C:\Windows\System32\drivers\btath_rcp.sys [2014-08-14 137928]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2015-03-25 53248]
S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Ovladač úspory energie technologie Bluetooth; C:\Windows\system32\DRIVERS\BthLEEnum.sys [2014-03-18 226304]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2015-03-25 118272]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2015-03-25 1198080]
S3 DDDriver;DDDriver; C:\Windows\system32\drivers\DDDriver64Dcsa.sys [2016-01-05 32464]
S3 DellProf;DellProf; C:\Windows\system32\drivers\DellProf.sys [2016-01-05 24240]
S3 dg_ssudbus;@oem152.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2016-09-05 131712]
S3 dot4;@oem126.inf,%Dot4_Name%;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2012-10-18 151968]
S3 Dot4Print;@oem129.inf,%Dot4Print_Name%;Print Class Driver for IEEE-1284.4; C:\Windows\System32\drivers\Dot4Prt.sys [2012-10-18 27040]
S3 dot4usb;@oem126.inf,%DOT4USB_NAME%;Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2012-10-18 49056]
S3 DptfDevDisplay;DptfDevDisplay; C:\Windows\System32\drivers\DptfDevDisplay.sys [2014-05-16 70752]
S3 DptfDevDram;DptfDevDram; C:\Windows\System32\drivers\DptfDevDram.sys [2014-05-16 145640]
S3 DptfDevFan;DptfDevFan; C:\Windows\System32\drivers\DptfDevFan.sys [2014-05-16 50640]
S3 DptfDevPower;DptfDevPower; C:\Windows\System32\drivers\DptfDevPower.sys [2014-05-16 71808]
S3 iaLPSS_SPI;@oem71.inf,%iaLPSS_SPI.SVCDESC%;Intel(R) Serial IO SPI Driver; C:\Windows\System32\drivers\iaLPSS_SPI.sys [2013-08-08 83960]
S3 iaLPSS_UART2;@oem72.inf,%iaLPSS_UART2.SVCDESC%;Intel(R) Serial IO UART Driver v2; C:\Windows\System32\drivers\iaLPSS_UART2.sys [2013-08-08 129528]
S3 intaud_WaveExtensible;@oem199.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\Windows\system32\drivers\intelaud.sys [2014-08-01 38296]
S3 IntcDAud;@oem195.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2014-09-23 454416]
S3 PCDSRVC{3B54B31B-D06B6431-06020200}_0;PCDSRVC{3B54B31B-D06B6431-06020200}_0 - PCDR Kernel Mode Service Helper Driver; \??\c:\program files\dell\supportassist\pcdsrvc_x64.pkms [2017-02-16 25584]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2014-03-18 167424]
S3 RTLU3E8023-W8-64;@oem63.inf,%Rtlunic.Service.DispName%;Realtek USB GBE NIC Family Windows8 64bit Driver; C:\Windows\system32\DRIVERS\rtu30x64w8.sys [2013-10-09 92376]
S3 ssudmdm;@oem158.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2016-09-05 165504]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2015-03-25 44544]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AERTFilters;Andrea RT Filters Service; C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-17 98208]
R2 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\adminservice.exe [2014-08-14 322176]
R2 Dell Customer Connect;Dell Customer Connect; C:\Program Files (x86)\Dell Customer Connect\DCCService.exe [2016-12-21 130936]
R2 Dell Foundation Services;Dell Foundation Services; C:\Program Files\Dell\Dell Foundation Services\DFSSvc.exe [2017-01-11 97616]
R2 DellUpdate;Dell Update Service; C:\Program Files (x86)\Dell Update\DellUpService.exe [2015-08-27 237272]
R2 DptfParticipantProcessorService;@oem68.inf,%WIN32_DPTF_PARTICIPANT_PROC_SERVICE_DISPLAY_NAME%;Intel(R) Dynamic Platform and Thermal Framework Processor Participant Service Application; C:\Windows\system32\DptfParticipantProcessorService.exe [2014-05-16 115656]
R2 DptfPolicyCriticalService;@oem68.inf,%WIN32_DPTF_POLICY_CRITICAL_SERVICE_DISPLAY_NAME%;Intel(R) Dynamic Platform and Thermal Framework Critical Service Application; C:\Windows\system32\DptfPolicyCriticalService.exe [2014-05-16 148160]
R2 Fitbit Connect;Fitbit Connect Service; C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe [2015-10-28 5906088]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-11-21 15720]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\Windows\system32\igfxCUIService.exe [2014-09-30 318568]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; c:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-08-27 747520]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-12-04 169432]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-12-04 390616]
R2 RtkAudioService;Realtek Audio Service; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [2014-07-22 291032]
R2 SftService;SoftThinks Agent Service; C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe [2014-07-02 1921768]
R2 SupportAssistAgent;Dell SupportAssist Agent; C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [2016-09-09 31704]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2014-03-18 43696]
S2 DellDigitalDelivery;Dell Digital Delivery Service; C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe [2015-03-16 237448]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-02-24 154440]
S2 MAMPDNS;MAMPRO DNS Service; C:\MAMPPRO\MAMPDNSService.exe [2016-05-13 22528]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2017-02-27 317400]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2014-09-30 280680]
S3 DellProdRegManager;Dell Product Registration Manager; C:\Program Files (x86)\Dell Product Registration\regmgrsvc.exe [2014-10-31 278568]
S3 emailrelay;E-MailRelay; C:\MAMP\bin\emailrelay\emailrelay-service.exe [2014-07-30 705536]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-02-24 154440]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-08-27 828376]
S3 MAMPPRO;MAMPRO Service; C:\MAMPPRO\MAMPPROService.exe [2016-05-13 25088]
S3 MAMPPRO-Apache;MAMPPRO-Apache; C:\MAMP\bin\apache\bin\httpd.exe [2016-05-06 18432]
S3 MAMPPRO-MySQL;MAMPPRO-MySQL; C:\MAMP\bin\mysql\bin\mysqld.exe [2016-05-05 8152064]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-11-13 146888]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119670
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: nejspis zavirovany pc, problem se skype, zpomaleny pc

#8 Příspěvek od Rudy »

Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Jerma
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 08 dub 2017 15:52

Re: nejspis zavirovany pc, problem se skype, zpomaleny pc

#9 Příspěvek od Jerma »

Pocitac jede rychleji, skype vypada ze funguje ok, webkamera se zatim sama nezapina. jeste budu sledovat dale, kdyby pretrval problem s kamerou tak se ozvu.
Zatim moc diky.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119670
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: nejspis zavirovany pc, problem se skype, zpomaleny pc

#10 Příspěvek od Rudy »

Zatím nemáte zač! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Jerma
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 08 dub 2017 15:52

Re: nejspis zavirovany pc, problem se skype, zpomaleny pc

#11 Příspěvek od Jerma »

Tak vse vypadda v poradku, zaden problem nenastal, moc dekuju za pomoc :)

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119670
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: nejspis zavirovany pc, problem se skype, zpomaleny pc

#12 Příspěvek od Rudy »

Nemáte zač! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Jerma
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 08 dub 2017 15:52

Re: nejspis zavirovany pc, problem se skype, zpomaleny pc

#13 Příspěvek od Jerma »

Zdravim, bohuzel moje radost byla predcasna. Problem s webkamerou se vratil, zapne se sama, ale nevidim aplikaci, ktera by ji pouzivala. Zustal i problem se skype, kdyz chci uskutecnit videohovor, tak zavolat jde, ale nejde pustit webka, jen to vypise, ze ji pouziva jina aplikace. Muzete prosim poradit, co dal delat? Dekuju

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119670
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: nejspis zavirovany pc, problem se skype, zpomaleny pc

#14 Příspěvek od Rudy »

Udělejte kompletní sken MBAM: http://www.malwarebytes.org/mbam.php a dejte log. Předem nic nemažte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Jerma
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 08 dub 2017 15:52

Re: nejspis zavirovany pc, problem se skype, zpomaleny pc

#15 Příspěvek od Jerma »

Malwarebytes
www.malwarebytes.com

-Podrobnosti logovacího souboru-
Datum skenování: 13.04.17
Čas skenování: 15:32
Logovací soubor: scan.txt
Správce: Ano

-Informace o softwaru-
Verze: 3.0.6.1469
Verze komponentů: 1.0.103
Aktualizovat verzi balíku komponent: 1.0.1723
Licence: Zkušební

-Systémová informace-
OS: Windows 8.1
CPU: x64
Systém souborů: NTFS
Uživatel: goodbye-kitty\belfast

-Shrnutí skenování-
Typ skenování: Skenování hrozeb (Threat Scan)
Výsledek: Dokončeno
Skenované objekty: 334434
Uplynulý čas: 13 min, 23 sek

-Možnosti skenování-
Paměť: Povoleno
Start: Povoleno
Systém souborů: Povoleno
Archivy: Povoleno
Rootkity: Zakázáno
Heuristika: Povoleno
Potenciálně nežádoucí program: Povoleno
Potenciálně nežádoucí modifikace: Povoleno

-Podrobnosti skenování-
Proces: 0
(Nebyly zjištěny žádné škodlivé položky)

Modul: 0
(Nebyly zjištěny žádné škodlivé položky)

Klíč registru: 0
(Nebyly zjištěny žádné škodlivé položky)

Hodnota v registru: 0
(Nebyly zjištěny žádné škodlivé položky)

Data registrů: 0
(Nebyly zjištěny žádné škodlivé položky)

Datové proudy: 0
(Nebyly zjištěny žádné škodlivé položky)

Adresář: 0
(Nebyly zjištěny žádné škodlivé položky)

Soubor: 0
(Nebyly zjištěny žádné škodlivé položky)

Fyzický sektor: 0
(Nebyly zjištěny žádné škodlivé položky)


(end)

Odpovědět