Stránka 2 z 2

Re: Vysoké využití CPU (jsem lajk)

Napsal: 08 úno 2015 21:39
od Rudy
Musíme se na to kouknout ještě jednou. Poprosím o nový log RSIT.

Re: Vysoké využití CPU (jsem lajk)

Napsal: 10 úno 2015 18:41
od richardpeterka
Logfile of random's system information tool 1.10 (written by random/random)
Run by Richard Peterka at 2015-02-10 17:59:06
Microsoft® Windows Vista™ Home Premium Service Pack 1
System drive C: has 191 GB (38%) free of 501 GB
Total RAM: 3327 MB (40% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:59:41, on 10.2.2015
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18639)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Windows\PixArt\PAC207\Monitor.exe
C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe
C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.234\deploy\LoLLauncher.exe
C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.18\deploy\LoLPatcher.exe
C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.127\deploy\LolClient.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Richard Peterka\Downloads\RSIT.exe
C:\Program Files\trend micro\Richard Peterka.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://services.freshy.com/general/newh ... AB605E}&i=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://services.freshy.com/general/newh ... AB605E}&i=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll
O3 - Toolbar: Yahoo Toolbar - {A67A1E2A-000A-4E80-A921-A61D7DC3E7B5} - C:\Program Files\TNT2\Profiles\11185\passport.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [Monitor] C:\Windows\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [C:\AeriaGames\Downloader\aeria_ignite_install.exe] C:\AeriaGames\Downloader\aeria_ignite_install.exe /exenoupdates /exelang 0 /prereqs "1" /quiet
O4 - HKCU\..\Run: [{6B84E528-9705-4D36-9C97-97B8E23DAB75}] "C:\Users\Richard Peterka\Downloads\LeagueofLegends_EUNE_Installer_9_15_2014.exe" /cmdloc "HKCU\Software\Riot Games AiTemp\{6B84E528-9705-4D36-9C97-97B8E23DAB75}"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HP SI Service (HPSIService) - HP - C:\Windows\system32\HPSIsvc.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

--
End of file - 7837 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\Check for updates (Spybot - Search & Destroy).job - C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe /autoupdate /silent /autoclose /background
C:\Windows\tasks\C__AeriaGames_Downloader_aeria_ignite_install.exe.job - C:\AeriaGames\Downloader\aeria_ignite_install.exe /exenoupdates /exelang 0 /prereqs "1" /quiet
C:\Windows\tasks\C__Users_Richard Peterka_AppData_Local_Opera_Opera_temporary_downloads_aeria_ignite_install.exe.job - C:\Users\Richard Peterka\AppData\Local\Opera\Opera\temporary_downloads\aeria_ignite_install.exe /exenoupdates /exelang 0 /prereqs "1"
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\ParetoLogic Update Version3 Startup Task.job - C:\Program Files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe -StartupTask
C:\Windows\tasks\Refresh immunization (Spybot - Search & Destroy).job - C:\Program Files\Spybot - Search & Destroy 2\SDImmunize.exe /immunize /silent /autoclose
C:\Windows\tasks\RegCure Pro_sch_102DE03D-1718-11E4-A419-6CF0499E8183.job - C:\Program Files\ParetoLogic\RegCure Pro\RegCurePro.exe /schedule:"102DE03D-1718-11E4-A419-6CF0499E8183"
C:\Windows\tasks\Scan the system (Spybot - Search & Destroy).job - C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe /scan /cleanclose

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2009-01-14 92504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll [2014-11-02 460712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-11-02 172968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{A67A1E2A-000A-4E80-A921-A61D7DC3E7B5} - Yahoo Toolbar - C:\Program Files\TNT2\Profiles\11185\passport.dll [2015-01-28 11520]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-05-24 1008184]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2012-09-28 642728]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2014-08-22 974432]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2012-06-11 10996368]
"Monitor"=C:\Windows\PixArt\PAC207\Monitor.exe [2006-11-03 319488]
"kbdsprt"= []
"SDTray"=C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [2014-06-24 4101576]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"=C:\Program Files\Steam\steam.exe [2015-02-06 2874048]
"C:\AeriaGames\Downloader\aeria_ignite_install.exe"=C:\AeriaGames\Downloader\aeria_ignite_install.exe [2013-04-30 3538712]
"{6B84E528-9705-4D36-9C97-97B8E23DAB75}"=C:\Users\Richard Peterka\Downloads\LeagueofLegends_EUNE_Installer_9_15_2014.exe [2014-12-23 30993712]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-05-24 202240]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2015-01-23 31087200]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ Peterka]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:]
[]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SDWinLogon]
SDWinLogon.dll []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe"="C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot - Search & Destroy tray access"
"C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe"="C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service"
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe"="C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater"
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe"="C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"msacm.vorbis"=vorbis.acm

======List of files/folders created in the last 1 month======

2015-02-10 17:59:06 ----D---- C:\rsit
2015-02-10 17:21:25 ----D---- C:\Program Files\Common Files\Skype
2015-02-01 21:16:37 ----A---- C:\Windows\wininit.ini
2015-02-01 19:46:30 ----A---- C:\Windows\system32\sdnclean.exe
2015-02-01 19:46:28 ----D---- C:\ProgramData\Spybot - Search & Destroy
2015-02-01 19:46:18 ----D---- C:\Program Files\Spybot - Search & Destroy 2
2015-02-01 19:40:11 ----D---- C:\Program Files\Defraggler
2015-01-31 14:53:36 ----D---- C:\Windows\Minidump
2015-01-29 21:21:28 ----A---- C:\Windows\system32\drivers\{30146816-14e7-4e15-8f14-ea69dd580e97}Gt.sys
2015-01-28 22:01:42 ----A---- C:\Windows\system32\drivers\{bc82a6f8-51d8-440c-8e51-32a0c3b95ab4}Gt.sys
2015-01-28 21:52:13 ----D---- C:\Program Files\gate snapper
2015-01-28 21:51:45 ----D---- C:\Program Files\TNT2
2015-01-27 17:51:16 ----D---- C:\Program Files\AVG
2015-01-27 17:47:31 ----D---- C:\Users\Richard Peterka\AppData\Roaming\OpenCandy
2015-01-27 17:44:30 ----D---- C:\Users\Richard Peterka\AppData\Roaming\Image-Line
2015-01-27 17:44:00 ----D---- C:\Users\Richard Peterka\AppData\Roaming\FlowStone
2015-01-27 17:43:59 ----D---- C:\Program Files\DSPRobotics
2015-01-27 17:37:29 ----D---- C:\Program Files\Image-Line
2015-01-19 23:14:23 ----D---- C:\Users\Richard Peterka\AppData\Roaming\java

======List of files/folders modified in the last 1 month======

2015-02-10 17:59:19 ----D---- C:\Windows\Prefetch
2015-02-10 17:59:09 ----D---- C:\Program Files\trend micro
2015-02-10 17:59:01 ----D---- C:\Windows\Temp
2015-02-10 17:53:00 ----D---- C:\Users\Richard Peterka\AppData\Roaming\Skype
2015-02-10 17:21:42 ----SHD---- C:\Windows\Installer
2015-02-10 17:21:42 ----D---- C:\ProgramData\Skype
2015-02-10 17:21:25 ----RD---- C:\Program Files\Skype
2015-02-10 17:21:25 ----D---- C:\Program Files\Common Files
2015-02-10 17:21:22 ----D---- C:\Windows\System32
2015-02-10 17:21:18 ----D---- C:\Windows\inf
2015-02-10 17:15:59 ----RD---- C:\Program Files
2015-02-10 17:15:58 ----D---- C:\Windows\Tasks
2015-02-10 17:15:51 ----D---- C:\Program Files\Steam
2015-02-10 17:15:31 ----D---- C:\Windows
2015-02-10 17:09:25 ----D---- C:\Program Files\Google
2015-02-10 17:09:13 ----D---- C:\Windows\system32\Tasks
2015-02-10 13:09:33 ----D---- C:\Program Files\Opera
2015-02-10 11:40:50 ----SHD---- C:\System Volume Information
2015-02-08 22:59:22 ----A---- C:\Windows\system32\PnkBstrB.exe
2015-02-08 19:57:59 ----D---- C:\Program Files\Common Files\Steam
2015-02-07 21:14:18 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2015-02-01 21:16:37 ----D---- C:\Program Files\HomeKeylogger
2015-02-01 19:46:41 ----SD---- C:\ProgramData\Microsoft
2015-02-01 19:46:28 ----HD---- C:\ProgramData
2015-02-01 18:24:41 ----D---- C:\Windows\system32\catroot2
2015-01-31 16:59:40 ----D---- C:\Program Files\Heroes of Newerth
2015-01-31 16:48:28 ----D---- C:\Program Files\TeamSpeak 3 Client
2015-01-31 16:48:04 ----D---- C:\Program Files\SpeedFan
2015-01-31 14:26:31 ----D---- C:\Windows\system32\wbem
2015-01-31 14:25:21 ----D---- C:\Windows\system32\config
2015-01-31 14:25:04 ----D---- C:\Windows\twain_32
2015-01-31 14:25:04 ----D---- C:\Windows\system32\spool
2015-01-31 14:25:03 ----D---- C:\Windows\system32\drivers
2015-01-31 14:25:02 ----SD---- C:\Users\Richard Peterka\AppData\Roaming\Microsoft
2015-01-31 14:25:02 ----D---- C:\Users\Richard Peterka\AppData\Roaming\RCP 6
2015-01-31 14:25:01 ----D---- C:\ProgramData\Package Cache
2015-01-31 14:25:00 ----D---- C:\Program Files\ReaConverter 6.8 Standard
2015-01-31 14:25:00 ----D---- C:\Program Files\Minecraft-1.7.2
2015-01-31 14:24:59 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2015-01-31 14:24:59 ----D---- C:\Program Files\Microsoft Silverlight
2015-01-31 14:24:56 ----HD---- C:\Program Files\InstallShield Installation Information
2015-01-31 14:24:56 ----D---- C:\Program Files\LG Electronics
2015-01-31 14:24:40 ----D---- C:\Program Files\Common Files\PAC207
2015-01-31 14:24:39 ----D---- C:\Program Files\Common Files\microsoft shared
2015-01-31 14:24:38 ----D---- C:\Windows\registration
2015-01-31 14:13:33 ----D---- C:\Windows\Logs
2015-01-31 14:12:02 ----D---- C:\Windows\winsxs
2015-01-31 14:02:28 ----D---- C:\Users\Richard Peterka\AppData\Roaming\.minecraft
2015-01-31 13:58:59 ----RSD---- C:\Windows\assembly
2015-01-30 15:30:34 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-01-30 12:35:19 ----A---- C:\Windows\win.ini
2015-01-28 22:10:42 ----D---- C:\Users\Richard Peterka\AppData\Roaming\vlc
2015-01-28 21:50:50 ----D---- C:\Windows\Resources
2015-01-28 12:55:35 ----D---- C:\Program Files\Microsoft Games
2015-01-27 17:51:38 ----D---- C:\Users\Richard Peterka\AppData\Roaming\AVG
2015-01-27 17:50:16 ----D---- C:\ProgramData\AVG
2015-01-22 00:33:05 ----D---- C:\ricˇrd
2015-01-15 23:34:40 ----D---- C:\Windows\Debug
2015-01-15 03:15:24 ----D---- C:\Windows\system32\MRT
2015-01-15 03:05:52 ----A---- C:\Windows\system32\mrt.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2014-07-17 231800]
R0 nvstor32;nvstor32; C:\Windows\system32\DRIVERS\nvstor32.sys [2007-08-09 110624]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2013-03-30 717296]
R1 {30146816-14e7-4e15-8f14-ea69dd580e97}Gt;{30146816-14e7-4e15-8f14-ea69dd580e97}Gt; C:\Windows\system32\drivers\{30146816-14e7-4e15-8f14-ea69dd580e97}Gt.sys [2015-01-29 55832]
R1 {bc82a6f8-51d8-440c-8e51-32a0c3b95ab4}Gt;{bc82a6f8-51d8-440c-8e51-32a0c3b95ab4}Gt; C:\Windows\system32\drivers\{bc82a6f8-51d8-440c-8e51-32a0c3b95ab4}Gt.sys [2015-01-28 55832]
R2 AODDriver4.2;AODDriver4.2; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [2012-04-09 48256]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2014-07-17 95920]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-03-09 9183232]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-03-09 265216]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdLH3.sys [2012-02-23 83984]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2012-06-19 3240400]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2007-11-18 1040544]
R3 PAC207;Trust WB-1400T Webcam; C:\Windows\system32\DRIVERS\PFC027.SYS [2007-05-14 508288]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-05-24 5632]
S3 EagleXNt;EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys []
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-05-24 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-05-24 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-05-24 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-05-24 6016]
S3 mvusbews;USB EWS Device; C:\Windows\System32\Drivers\mvusbews.sys [2012-11-08 16896]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-05-24 35328]
S3 WinUSB;SAMSUNG Android USB Driver; C:\Windows\system32\DRIVERS\WinUSB.sys [2008-05-24 31616]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-05-24 39936]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-05-24 83328]
S4 ErrDev;Ovladače chybového zařízení hardwaru Microsoft; C:\Windows\system32\drivers\errdev.sys [2008-05-24 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-05-24 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2012-03-09 163328]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-09-28 291840]
R2 HPSIService;HP SI Service; C:\Windows\system32\HPSIsvc.exe [2012-11-08 100232]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2014-08-22 22192]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2014-07-05 76888]
R2 SDScannerService;Spybot-S&D 2 Scanner Service; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [2014-06-24 1738168]
R2 SDUpdateService;Spybot-S&D 2 Updating Service; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2014-06-27 2088408]
R2 SDWSCService;Spybot-S&D 2 Security Center Service; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [2014-04-25 171928]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2014-08-22 288120]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-02-10 107912]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2015-01-02 315488]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-07 267440]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-02-10 107912]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\system32\GameMon.des [2012-03-06 4199520]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2015-02-06 835776]

-----------------EOF-----------------

Re: Vysoké využití CPU (jsem lajk)

Napsal: 10 úno 2015 19:15
od Rudy
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.

Re: Vysoké využití CPU (jsem lajk)

Napsal: 10 úno 2015 20:48
od richardpeterka
# AdwCleaner v4.110 - Logfile created 10/02/2015 at 20:43:36
# Updated 05/02/2015 by Xplode
# Database : 2015-02-09.1 [Server]
# Operating system : Windows Vista (TM) Home Premium Service Pack 1 (x86)
# Username : Richard Peterka - RICHARD-PC
# Running from : C:\Users\Richard Peterka\Desktop\adwcleaner_4.110.exe
# Option : Cleaning

***** [ Services ] *****

[#] Service Deleted : {30146816-14e7-4e15-8f14-ea69dd580e97}Gt
[#] Service Deleted : {bc82a6f8-51d8-440c-8e51-32a0c3b95ab4}Gt

***** [ Files / Folders ] *****

Folder Deleted : C:\Program Files\TNT2
Folder Deleted : C:\Users\Richard Peterka\AppData\Local\TNT2
Folder Deleted : C:\Users\Richard Peterka\AppData\Roaming\OpenCandy
File Deleted : C:\Windows\system32\drivers\{30146816-14e7-4e15-8f14-ea69dd580e97}Gt.sys
File Deleted : C:\Windows\system32\drivers\{bc82a6f8-51d8-440c-8e51-32a0c3b95ab4}Gt.sys

***** [ Scheduled tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DEDAF650-12B8-48F5-A843-BBA100716106}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D2CE3E00-F94A-4740-988E-03DC2F38C34F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8DCB7100-DF86-4384-8842-8FA844297B3F}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{86EB1BB0-FA5E-44C8-8765-DECE7C69C642}
Key Deleted : HKCU\Software\TNT2
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4F524A2D-5350-4500-76A7-A758B70C1500}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{4F524A2D-5350-4500-76A7-A758B70C1500}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7AB5857A57A0687786597A857BFFFFFF
Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <local>

***** [ Web browsers ] *****

-\\ Internet Explorer v7.0.6001.18639


-\\ Google Chrome v40.0.2214.111

[C:\Users\Richard Peterka\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.findwide.com/serp?guid={324BEE7B-CB31-4954-A72F-C99CAEAB605E}&k={searchTerms}
[C:\Users\Richard Peterka\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.findwide.com/serp?guid={324BEE7B-CB31-4954-A72F-C99CAEAB605E}&k={searchTerms}

-\\ Comodo Dragon v

[C:\Users\Richard Peterka\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.findwide.com/serp?guid={324BEE7B-CB31-4954-A72F-C99CAEAB605E}&k={searchTerms}
[C:\Users\Richard Peterka\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.findwide.com/serp?guid={324BEE7B-CB31-4954-A72F-C99CAEAB605E}&k={searchTerms}

-\\ Chrome Canary v

[C:\Users\Richard Peterka\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.findwide.com/serp?guid={324BEE7B-CB31-4954-A72F-C99CAEAB605E}&k={searchTerms}
[C:\Users\Richard Peterka\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.findwide.com/serp?guid={324BEE7B-CB31-4954-A72F-C99CAEAB605E}&k={searchTerms}

*************************

AdwCleaner[R0].txt - [7635 bytes] - [27/11/2014 21:30:29]
AdwCleaner[R1].txt - [3062 bytes] - [10/02/2015 20:32:40]
AdwCleaner[R2].txt - [3119 bytes] - [10/02/2015 20:35:25]
AdwCleaner[S0].txt - [7286 bytes] - [27/11/2014 21:34:28]
AdwCleaner[S1].txt - [3918 bytes] - [10/02/2015 20:43:36]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [3977 bytes] ##########

Re: Vysoké využití CPU (jsem lajk)

Napsal: 10 úno 2015 21:05
od Rudy
Dejte nový log RSIT.

Re: Vysoké využití CPU (jsem lajk)

Napsal: 10 úno 2015 21:09
od richardpeterka
Logfile of random's system information tool 1.10 (written by random/random)
Run by Richard Peterka at 2015-02-10 21:06:49
Microsoft® Windows Vista™ Home Premium Service Pack 1
System drive C: has 190 GB (38%) free of 501 GB
Total RAM: 3327 MB (67% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:07:57, on 10.2.2015
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18639)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Windows\PixArt\PAC207\Monitor.exe
C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\wuauclt.exe
C:\Users\Richard Peterka\Downloads\RSIT.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\trend micro\Richard Peterka.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://services.freshy.com/general/newh ... AB605E}&i=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://services.freshy.com/general/newh ... AB605E}&i=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll
O3 - Toolbar: Yahoo Toolbar - {A67A1E2A-000A-4E80-A921-A61D7DC3E7B5} - C:\Program Files\TNT2\Profiles\11185\passport.dll (file missing)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [Monitor] C:\Windows\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [C:\AeriaGames\Downloader\aeria_ignite_install.exe] C:\AeriaGames\Downloader\aeria_ignite_install.exe /exenoupdates /exelang 0 /prereqs "1" /quiet
O4 - HKCU\..\Run: [{6B84E528-9705-4D36-9C97-97B8E23DAB75}] "C:\Users\Richard Peterka\Downloads\LeagueofLegends_EUNE_Installer_9_15_2014.exe" /cmdloc "HKCU\Software\Riot Games AiTemp\{6B84E528-9705-4D36-9C97-97B8E23DAB75}"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HP SI Service (HPSIService) - HP - C:\Windows\system32\HPSIsvc.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

--
End of file - 7351 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\Check for updates (Spybot - Search & Destroy).job - C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe /autoupdate /silent /autoclose /background
C:\Windows\tasks\C__AeriaGames_Downloader_aeria_ignite_install.exe.job - C:\AeriaGames\Downloader\aeria_ignite_install.exe /exenoupdates /exelang 0 /prereqs "1" /quiet
C:\Windows\tasks\C__Users_Richard Peterka_AppData_Local_Opera_Opera_temporary_downloads_aeria_ignite_install.exe.job - C:\Users\Richard Peterka\AppData\Local\Opera\Opera\temporary_downloads\aeria_ignite_install.exe /exenoupdates /exelang 0 /prereqs "1"
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\ParetoLogic Update Version3 Startup Task.job - C:\Program Files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe -StartupTask
C:\Windows\tasks\Refresh immunization (Spybot - Search & Destroy).job - C:\Program Files\Spybot - Search & Destroy 2\SDImmunize.exe /immunize /silent /autoclose
C:\Windows\tasks\RegCure Pro_sch_102DE03D-1718-11E4-A419-6CF0499E8183.job - C:\Program Files\ParetoLogic\RegCure Pro\RegCurePro.exe /schedule:"102DE03D-1718-11E4-A419-6CF0499E8183"
C:\Windows\tasks\Scan the system (Spybot - Search & Destroy).job - C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe /scan /cleanclose

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2009-01-14 92504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll [2014-11-02 460712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-11-02 172968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{A67A1E2A-000A-4E80-A921-A61D7DC3E7B5} - Yahoo Toolbar - C:\Program Files\TNT2\Profiles\11185\passport.dll []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-05-24 1008184]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2012-09-28 642728]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2014-08-22 974432]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2012-06-11 10996368]
"Monitor"=C:\Windows\PixArt\PAC207\Monitor.exe [2006-11-03 319488]
"kbdsprt"= []
"SDTray"=C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [2014-06-24 4101576]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"=C:\Program Files\Steam\steam.exe [2015-02-10 2874048]
"C:\AeriaGames\Downloader\aeria_ignite_install.exe"=C:\AeriaGames\Downloader\aeria_ignite_install.exe [2013-04-30 3538712]
"{6B84E528-9705-4D36-9C97-97B8E23DAB75}"=C:\Users\Richard Peterka\Downloads\LeagueofLegends_EUNE_Installer_9_15_2014.exe [2014-12-23 30993712]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-05-24 202240]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2015-01-23 31087200]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ Peterka]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:]
[]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SDWinLogon]
SDWinLogon.dll []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe"="C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot - Search & Destroy tray access"
"C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe"="C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service"
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe"="C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater"
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe"="C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"msacm.vorbis"=vorbis.acm

======List of files/folders created in the last 1 month======

2015-02-10 20:25:55 ----A---- C:\Windows\system32\FNTCACHE.DAT
2015-02-10 17:59:06 ----D---- C:\rsit
2015-02-10 17:21:25 ----D---- C:\Program Files\Common Files\Skype
2015-02-01 21:16:37 ----A---- C:\Windows\wininit.ini
2015-02-01 19:46:30 ----A---- C:\Windows\system32\sdnclean.exe
2015-02-01 19:46:28 ----D---- C:\ProgramData\Spybot - Search & Destroy
2015-02-01 19:46:18 ----D---- C:\Program Files\Spybot - Search & Destroy 2
2015-02-01 19:40:11 ----D---- C:\Program Files\Defraggler
2015-01-31 14:53:36 ----D---- C:\Windows\Minidump
2015-01-28 21:52:13 ----D---- C:\Program Files\gate snapper
2015-01-27 17:51:16 ----D---- C:\Program Files\AVG
2015-01-27 17:44:30 ----D---- C:\Users\Richard Peterka\AppData\Roaming\Image-Line
2015-01-27 17:44:00 ----D---- C:\Users\Richard Peterka\AppData\Roaming\FlowStone
2015-01-27 17:43:59 ----D---- C:\Program Files\DSPRobotics
2015-01-27 17:37:29 ----D---- C:\Program Files\Image-Line
2015-01-19 23:14:23 ----D---- C:\Users\Richard Peterka\AppData\Roaming\java

======List of files/folders modified in the last 1 month======

2015-02-10 21:07:45 ----D---- C:\Program Files\trend micro
2015-02-10 21:07:37 ----D---- C:\Users\Richard Peterka\AppData\Roaming\Skype
2015-02-10 21:07:01 ----D---- C:\Windows\Temp
2015-02-10 21:01:41 ----D---- C:\Windows\Prefetch
2015-02-10 21:01:27 ----SHD---- C:\System Volume Information
2015-02-10 20:55:18 ----D---- C:\Program Files\Steam
2015-02-10 20:48:12 ----D---- C:\Program Files\Common Files\Steam
2015-02-10 20:43:37 ----D---- C:\AdwCleaner
2015-02-10 20:43:36 ----RD---- C:\Program Files
2015-02-10 20:43:36 ----D---- C:\Windows\system32\drivers
2015-02-10 20:25:55 ----D---- C:\Windows\System32
2015-02-10 20:25:52 ----D---- C:\Windows
2015-02-10 17:21:42 ----SHD---- C:\Windows\Installer
2015-02-10 17:21:42 ----D---- C:\ProgramData\Skype
2015-02-10 17:21:25 ----RD---- C:\Program Files\Skype
2015-02-10 17:21:25 ----D---- C:\Program Files\Common Files
2015-02-10 17:21:18 ----D---- C:\Windows\inf
2015-02-10 17:15:58 ----D---- C:\Windows\Tasks
2015-02-10 17:09:25 ----D---- C:\Program Files\Google
2015-02-10 17:09:13 ----D---- C:\Windows\system32\Tasks
2015-02-10 13:09:33 ----D---- C:\Program Files\Opera
2015-02-08 22:59:22 ----A---- C:\Windows\system32\PnkBstrB.exe
2015-02-07 21:14:18 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2015-02-01 21:16:37 ----D---- C:\Program Files\HomeKeylogger
2015-02-01 19:46:41 ----SD---- C:\ProgramData\Microsoft
2015-02-01 19:46:28 ----HD---- C:\ProgramData
2015-02-01 18:24:41 ----D---- C:\Windows\system32\catroot2
2015-01-31 16:59:40 ----D---- C:\Program Files\Heroes of Newerth
2015-01-31 16:48:28 ----D---- C:\Program Files\TeamSpeak 3 Client
2015-01-31 16:48:04 ----D---- C:\Program Files\SpeedFan
2015-01-31 14:26:31 ----D---- C:\Windows\system32\wbem
2015-01-31 14:25:21 ----D---- C:\Windows\system32\config
2015-01-31 14:25:04 ----D---- C:\Windows\twain_32
2015-01-31 14:25:04 ----D---- C:\Windows\system32\spool
2015-01-31 14:25:02 ----SD---- C:\Users\Richard Peterka\AppData\Roaming\Microsoft
2015-01-31 14:25:02 ----D---- C:\Users\Richard Peterka\AppData\Roaming\RCP 6
2015-01-31 14:25:01 ----D---- C:\ProgramData\Package Cache
2015-01-31 14:25:00 ----D---- C:\Program Files\ReaConverter 6.8 Standard
2015-01-31 14:25:00 ----D---- C:\Program Files\Minecraft-1.7.2
2015-01-31 14:24:59 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2015-01-31 14:24:59 ----D---- C:\Program Files\Microsoft Silverlight
2015-01-31 14:24:56 ----HD---- C:\Program Files\InstallShield Installation Information
2015-01-31 14:24:56 ----D---- C:\Program Files\LG Electronics
2015-01-31 14:24:40 ----D---- C:\Program Files\Common Files\PAC207
2015-01-31 14:24:39 ----D---- C:\Program Files\Common Files\microsoft shared
2015-01-31 14:24:38 ----D---- C:\Windows\registration
2015-01-31 14:13:33 ----D---- C:\Windows\Logs
2015-01-31 14:12:02 ----D---- C:\Windows\winsxs
2015-01-31 14:02:28 ----D---- C:\Users\Richard Peterka\AppData\Roaming\.minecraft
2015-01-31 13:58:59 ----RSD---- C:\Windows\assembly
2015-01-30 15:30:34 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-01-30 12:35:19 ----A---- C:\Windows\win.ini
2015-01-28 22:10:42 ----D---- C:\Users\Richard Peterka\AppData\Roaming\vlc
2015-01-28 21:50:50 ----D---- C:\Windows\Resources
2015-01-28 12:55:35 ----D---- C:\Program Files\Microsoft Games
2015-01-27 17:51:38 ----D---- C:\Users\Richard Peterka\AppData\Roaming\AVG
2015-01-27 17:50:16 ----D---- C:\ProgramData\AVG
2015-01-22 00:33:05 ----D---- C:\ricˇrd
2015-01-15 23:34:40 ----D---- C:\Windows\Debug
2015-01-15 03:15:24 ----D---- C:\Windows\system32\MRT
2015-01-15 03:05:52 ----A---- C:\Windows\system32\mrt.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2014-07-17 231800]
R0 nvstor32;nvstor32; C:\Windows\system32\DRIVERS\nvstor32.sys [2007-08-09 110624]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2013-03-30 717296]
R2 AODDriver4.2;AODDriver4.2; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [2012-04-09 48256]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2014-07-17 95920]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-03-09 9183232]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-03-09 265216]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdLH3.sys [2012-02-23 83984]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2012-06-19 3240400]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2007-11-18 1040544]
R3 PAC207;Trust WB-1400T Webcam; C:\Windows\system32\DRIVERS\PFC027.SYS [2007-05-14 508288]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-05-24 5632]
S3 EagleXNt;EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys []
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-05-24 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-05-24 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-05-24 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-05-24 6016]
S3 mvusbews;USB EWS Device; C:\Windows\System32\Drivers\mvusbews.sys [2012-11-08 16896]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-05-24 35328]
S3 WinUSB;SAMSUNG Android USB Driver; C:\Windows\system32\DRIVERS\WinUSB.sys [2008-05-24 31616]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-05-24 39936]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-05-24 83328]
S4 ErrDev;Ovladače chybového zařízení hardwaru Microsoft; C:\Windows\system32\drivers\errdev.sys [2008-05-24 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-05-24 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2012-03-09 163328]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-09-28 291840]
R2 HPSIService;HP SI Service; C:\Windows\system32\HPSIsvc.exe [2012-11-08 100232]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2014-08-22 22192]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2014-07-05 76888]
R2 SDScannerService;Spybot-S&D 2 Scanner Service; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [2014-06-24 1738168]
R2 SDUpdateService;Spybot-S&D 2 Updating Service; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2014-06-27 2088408]
R2 SDWSCService;Spybot-S&D 2 Security Center Service; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [2014-04-25 171928]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2014-08-22 288120]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-02-10 107912]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2015-01-02 315488]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-07 267440]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-02-10 107912]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\system32\GameMon.des [2012-03-06 4199520]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2015-02-10 835776]

-----------------EOF-----------------

Re: Vysoké využití CPU (jsem lajk)

Napsal: 10 úno 2015 21:14
od Rudy
Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.

Re: Vysoké využití CPU (jsem lajk)

Napsal: 10 úno 2015 21:25
od richardpeterka
Provedeno co dál ? Mimo jiné me znepokojuje např. Csrss

Re: Vysoké využití CPU (jsem lajk)

Napsal: 10 úno 2015 22:10
od Rudy
Kde je csrss jako soubor umístěn? Za normálních okolností to je systémový soubor. Ještě bych prosil nový log RSIT. Děkuji.

Re: Vysoké využití CPU (jsem lajk)

Napsal: 10 úno 2015 22:35
od richardpeterka
csrss C:\Windows\System32
Logfile of random's system information tool 1.10 (written by random/random)
Run by Richard Peterka at 2015-02-10 22:25:46
Microsoft® Windows Vista™ Home Premium Service Pack 1
System drive C: has 189 GB (38%) free of 501 GB
Total RAM: 3327 MB (81% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:26:18, on 10.2.2015
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18639)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Windows\PixArt\PAC207\Monitor.exe
C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Richard Peterka\Desktop\RSIT.exe
C:\Program Files\trend micro\Richard Peterka.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://services.freshy.com/general/newh ... AB605E}&i=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://services.freshy.com/general/newh ... AB605E}&i=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [Monitor] C:\Windows\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [C:\AeriaGames\Downloader\aeria_ignite_install.exe] C:\AeriaGames\Downloader\aeria_ignite_install.exe /exenoupdates /exelang 0 /prereqs "1" /quiet
O4 - HKCU\..\Run: [{6B84E528-9705-4D36-9C97-97B8E23DAB75}] "C:\Users\Richard Peterka\Downloads\LeagueofLegends_EUNE_Installer_9_15_2014.exe" /cmdloc "HKCU\Software\Riot Games AiTemp\{6B84E528-9705-4D36-9C97-97B8E23DAB75}"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HP SI Service (HPSIService) - HP - C:\Windows\system32\HPSIsvc.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

--
End of file - 7139 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\Check for updates (Spybot - Search & Destroy).job - C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe /autoupdate /silent /autoclose /background
C:\Windows\tasks\C__AeriaGames_Downloader_aeria_ignite_install.exe.job - C:\AeriaGames\Downloader\aeria_ignite_install.exe /exenoupdates /exelang 0 /prereqs "1" /quiet
C:\Windows\tasks\C__Users_Richard Peterka_AppData_Local_Opera_Opera_temporary_downloads_aeria_ignite_install.exe.job - C:\Users\Richard Peterka\AppData\Local\Opera\Opera\temporary_downloads\aeria_ignite_install.exe /exenoupdates /exelang 0 /prereqs "1"
C:\Windows\tasks\ParetoLogic Update Version3 Startup Task.job - C:\Program Files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe -StartupTask
C:\Windows\tasks\Refresh immunization (Spybot - Search & Destroy).job - C:\Program Files\Spybot - Search & Destroy 2\SDImmunize.exe /immunize /silent /autoclose
C:\Windows\tasks\RegCure Pro_sch_102DE03D-1718-11E4-A419-6CF0499E8183.job - C:\Program Files\ParetoLogic\RegCure Pro\RegCurePro.exe /schedule:"102DE03D-1718-11E4-A419-6CF0499E8183"
C:\Windows\tasks\Scan the system (Spybot - Search & Destroy).job - C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe /scan /cleanclose

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2009-01-14 92504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll [2014-11-02 460712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-11-02 172968]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-05-24 1008184]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2012-09-28 642728]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2014-08-22 974432]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2012-06-11 10996368]
"Monitor"=C:\Windows\PixArt\PAC207\Monitor.exe [2006-11-03 319488]
"kbdsprt"= []
"SDTray"=C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [2014-06-24 4101576]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"=C:\Program Files\Steam\steam.exe [2015-02-10 2874048]
"C:\AeriaGames\Downloader\aeria_ignite_install.exe"=C:\AeriaGames\Downloader\aeria_ignite_install.exe [2013-04-30 3538712]
"{6B84E528-9705-4D36-9C97-97B8E23DAB75}"=C:\Users\Richard Peterka\Downloads\LeagueofLegends_EUNE_Installer_9_15_2014.exe [2014-12-23 30993712]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-05-24 202240]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2015-01-23 31087200]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ Peterka]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:]
[]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SDWinLogon]
SDWinLogon.dll []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe"="C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot - Search & Destroy tray access"
"C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe"="C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service"
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe"="C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater"
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe"="C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"msacm.vorbis"=vorbis.acm

======List of files/folders created in the last 1 month======

2015-02-10 22:25:46 ----D---- C:\rsit
2015-02-10 21:19:10 ----D---- C:\_OTM
2015-02-10 20:25:55 ----A---- C:\Windows\system32\FNTCACHE.DAT
2015-02-10 17:21:25 ----D---- C:\Program Files\Common Files\Skype
2015-02-01 21:16:37 ----A---- C:\Windows\wininit.ini
2015-02-01 19:46:30 ----A---- C:\Windows\system32\sdnclean.exe
2015-02-01 19:46:28 ----D---- C:\ProgramData\Spybot - Search & Destroy
2015-02-01 19:46:18 ----D---- C:\Program Files\Spybot - Search & Destroy 2
2015-02-01 19:40:11 ----D---- C:\Program Files\Defraggler
2015-01-31 14:53:36 ----D---- C:\Windows\Minidump
2015-01-28 21:52:13 ----D---- C:\Program Files\gate snapper
2015-01-27 17:51:16 ----D---- C:\Program Files\AVG
2015-01-27 17:44:30 ----D---- C:\Users\Richard Peterka\AppData\Roaming\Image-Line
2015-01-27 17:44:00 ----D---- C:\Users\Richard Peterka\AppData\Roaming\FlowStone
2015-01-27 17:43:59 ----D---- C:\Program Files\DSPRobotics
2015-01-27 17:37:29 ----D---- C:\Program Files\Image-Line
2015-01-19 23:14:23 ----D---- C:\Users\Richard Peterka\AppData\Roaming\java

======List of files/folders modified in the last 1 month======

2015-02-10 22:26:15 ----D---- C:\Program Files\trend micro
2015-02-10 22:25:52 ----D---- C:\Windows\Prefetch
2015-02-10 22:25:42 ----D---- C:\Windows\Temp
2015-02-10 21:44:43 ----D---- C:\Users\Richard Peterka\AppData\Roaming\Skype
2015-02-10 21:27:41 ----D---- C:\Program Files\Steam
2015-02-10 21:23:08 ----D---- C:\Program Files\Common Files\Steam
2015-02-10 21:19:10 ----D---- C:\Windows\Tasks
2015-02-10 21:01:27 ----SHD---- C:\System Volume Information
2015-02-10 20:43:37 ----D---- C:\AdwCleaner
2015-02-10 20:43:36 ----RD---- C:\Program Files
2015-02-10 20:43:36 ----D---- C:\Windows\system32\drivers
2015-02-10 20:25:55 ----D---- C:\Windows\System32
2015-02-10 20:25:52 ----D---- C:\Windows
2015-02-10 17:21:42 ----SHD---- C:\Windows\Installer
2015-02-10 17:21:42 ----D---- C:\ProgramData\Skype
2015-02-10 17:21:25 ----RD---- C:\Program Files\Skype
2015-02-10 17:21:25 ----D---- C:\Program Files\Common Files
2015-02-10 17:21:18 ----D---- C:\Windows\inf
2015-02-10 17:09:25 ----D---- C:\Program Files\Google
2015-02-10 17:09:13 ----D---- C:\Windows\system32\Tasks
2015-02-10 13:09:33 ----D---- C:\Program Files\Opera
2015-02-08 22:59:22 ----A---- C:\Windows\system32\PnkBstrB.exe
2015-02-07 21:14:18 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2015-02-01 21:16:37 ----D---- C:\Program Files\HomeKeylogger
2015-02-01 19:46:41 ----SD---- C:\ProgramData\Microsoft
2015-02-01 19:46:28 ----HD---- C:\ProgramData
2015-02-01 18:24:41 ----D---- C:\Windows\system32\catroot2
2015-01-31 16:59:40 ----D---- C:\Program Files\Heroes of Newerth
2015-01-31 16:48:28 ----D---- C:\Program Files\TeamSpeak 3 Client
2015-01-31 16:48:04 ----D---- C:\Program Files\SpeedFan
2015-01-31 14:26:31 ----D---- C:\Windows\system32\wbem
2015-01-31 14:25:21 ----D---- C:\Windows\system32\config
2015-01-31 14:25:04 ----D---- C:\Windows\twain_32
2015-01-31 14:25:04 ----D---- C:\Windows\system32\spool
2015-01-31 14:25:02 ----SD---- C:\Users\Richard Peterka\AppData\Roaming\Microsoft
2015-01-31 14:25:02 ----D---- C:\Users\Richard Peterka\AppData\Roaming\RCP 6
2015-01-31 14:25:01 ----D---- C:\ProgramData\Package Cache
2015-01-31 14:25:00 ----D---- C:\Program Files\ReaConverter 6.8 Standard
2015-01-31 14:25:00 ----D---- C:\Program Files\Minecraft-1.7.2
2015-01-31 14:24:59 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2015-01-31 14:24:59 ----D---- C:\Program Files\Microsoft Silverlight
2015-01-31 14:24:56 ----HD---- C:\Program Files\InstallShield Installation Information
2015-01-31 14:24:56 ----D---- C:\Program Files\LG Electronics
2015-01-31 14:24:40 ----D---- C:\Program Files\Common Files\PAC207
2015-01-31 14:24:39 ----D---- C:\Program Files\Common Files\microsoft shared
2015-01-31 14:24:38 ----D---- C:\Windows\registration
2015-01-31 14:13:33 ----D---- C:\Windows\Logs
2015-01-31 14:12:02 ----D---- C:\Windows\winsxs
2015-01-31 14:02:28 ----D---- C:\Users\Richard Peterka\AppData\Roaming\.minecraft
2015-01-31 13:58:59 ----RSD---- C:\Windows\assembly
2015-01-30 15:30:34 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-01-30 12:35:19 ----A---- C:\Windows\win.ini
2015-01-28 22:10:42 ----D---- C:\Users\Richard Peterka\AppData\Roaming\vlc
2015-01-28 21:50:50 ----D---- C:\Windows\Resources
2015-01-28 12:55:35 ----D---- C:\Program Files\Microsoft Games
2015-01-27 17:51:38 ----D---- C:\Users\Richard Peterka\AppData\Roaming\AVG
2015-01-27 17:50:16 ----D---- C:\ProgramData\AVG
2015-01-22 00:33:05 ----D---- C:\ricˇrd
2015-01-15 23:34:40 ----D---- C:\Windows\Debug
2015-01-15 03:15:24 ----D---- C:\Windows\system32\MRT
2015-01-15 03:05:52 ----A---- C:\Windows\system32\mrt.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2014-07-17 231800]
R0 nvstor32;nvstor32; C:\Windows\system32\DRIVERS\nvstor32.sys [2007-08-09 110624]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2013-03-30 717296]
R2 AODDriver4.2;AODDriver4.2; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [2012-04-09 48256]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2014-07-17 95920]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-03-09 9183232]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-03-09 265216]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdLH3.sys [2012-02-23 83984]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2012-06-19 3240400]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2007-11-18 1040544]
R3 PAC207;Trust WB-1400T Webcam; C:\Windows\system32\DRIVERS\PFC027.SYS [2007-05-14 508288]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-05-24 5632]
S3 EagleXNt;EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys []
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-05-24 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-05-24 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-05-24 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-05-24 6016]
S3 mvusbews;USB EWS Device; C:\Windows\System32\Drivers\mvusbews.sys [2012-11-08 16896]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-05-24 35328]
S3 WinUSB;SAMSUNG Android USB Driver; C:\Windows\system32\DRIVERS\WinUSB.sys [2008-05-24 31616]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-05-24 39936]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-05-24 83328]
S4 ErrDev;Ovladače chybového zařízení hardwaru Microsoft; C:\Windows\system32\drivers\errdev.sys [2008-05-24 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-05-24 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2012-03-09 163328]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-09-28 291840]
R2 HPSIService;HP SI Service; C:\Windows\system32\HPSIsvc.exe [2012-11-08 100232]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2014-08-22 22192]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2014-07-05 76888]
R2 SDScannerService;Spybot-S&D 2 Scanner Service; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [2014-06-24 1738168]
R2 SDUpdateService;Spybot-S&D 2 Updating Service; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2014-06-27 2088408]
R2 SDWSCService;Spybot-S&D 2 Security Center Service; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [2014-04-25 171928]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2014-08-22 288120]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-02-10 107912]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2015-01-02 315488]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-07 267440]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-02-10 107912]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\system32\GameMon.des [2012-03-06 4199520]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2015-02-10 835776]

-----------------EOF-----------------

Re: Vysoké využití CPU (jsem lajk)

Napsal: 10 úno 2015 22:46
od Rudy
Pokud je soubor csrss zde: C:\Windows\System32 , je legitimní. Dvouklikem na soubor C:\Program Files\trend micro\Richard Peterka.exe spusťte HijackThis. Klikněte na "Do a system scan only" a v otevřeném okně vlevo ve čtverečcích zaškrtněte:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://services.freshy.com/general/newh ... 1185&guid={324BEE7B-CB31-4954-A72F-C99CAEAB605E}&i=
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
Klikněte na >FixChecked<. Pak znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC.

Re: Vysoké využití CPU (jsem lajk)

Napsal: 10 úno 2015 23:00
od richardpeterka
Hotovo

Re: Vysoké využití CPU (jsem lajk)

Napsal: 11 úno 2015 13:36
od richardpeterka
Jestli je to vše, tak moc děkuji za pomoc a doufám, že je problém vyřešen.

Re: Vysoké využití CPU (jsem lajk)

Napsal: 11 úno 2015 17:36
od Rudy
Neemáte-li jiný problém, je to vše. Nemáte zač! :)