Stránka 1 z 1

Prosím o kontrolu logu

Napsal: 16 pro 2013 23:12
od mrazik
Prosím o kontrolu logu, CPU většinou běží na plný výkon, nejčastěji při práci na internetu.
Díky

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-12-2013 02
Ran by Uživatel (administrator) on OEM-6235756B183 on 16-12-2013 22:42:42
Running from C:\Documents and Settings\Uživatel\Plocha
Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: Czech
Internet Explorer Version 6
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Analog Devices, Inc.) C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastUI.exe
() C:\Program Files\MRP\Tiskový manažer\W_mrpprn.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(HP) C:\WINDOWS\system32\HPZipm12.exe
(Analog Devices, Inc.) C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
(Vodafone) C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(forum.viry.cz) C:\Documents and Settings\Uživatel\Plocha\FRSTLauncher.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Smapp] - C:\Program Files\Analog Devices\SoundMAX\SMTray.exe [143360 2003-05-05] (Analog Devices, Inc.)
HKLM\...\Run: [avast5] - C:\Program Files\Alwil Software\Avast5\AvastUI.exe [4858968 2013-05-09] (AVAST Software)
HKLM\...\Run: [MobileConnect] - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe [2412032 2009-09-18] (Vodafone)
HKLM\...\Run: [20131121] - C:\Program Files\Alwil Software\Avast5\Setup\emupdate\155942ea-8c5d-4bb2-a2b9-ffbc5432eaa3.exe [180184 2013-11-25] (AVAST Software)
HKCU\...\Run: [W_MRPPRN] - C:\Program Files\MRP\Tiskový manažer\W_mrpprn.exe [1138688 2005-03-18] ()
MountPoints2: {9b3132e2-eee1-11e2-944f-0011d808d009} - E:\setup_vmc_lite.exe /checkApplicationPresence
MountPoints2: {9b3132e3-eee1-11e2-944f-0011d808d009} - E:\setup_vmc_lite.exe /checkApplicationPresence

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dl ... R}&ar=home
HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Společnost Microsoft)
Toolbar: HKCU - &Odkazy - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
Tcpip\Parameters: [DhcpNameServer] 10.89.1.2 193.85.214.17

FireFox:
========
FF ProfilePath: C:\Documents and Settings\Uživatel\Data aplikací\Mozilla\Firefox\Profiles\etnv822j.default
FF DefaultSearchEngine: Seznam
FF SelectedSearchEngine: Seznam
FF Homepage: hxxp://www.seznam.cz/
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\mall-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Xmarks - C:\Documents and Settings\Uživatel\Data aplikací\Mozilla\Firefox\Profiles\etnv822j.default\Extensions\foxmarks@kei(2).com
FF Extension: Forecastfox - C:\Documents and Settings\Uživatel\Data aplikací\Mozilla\Firefox\Profiles\etnv822j.default\Extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
FF Extension: Autocopy - C:\Documents and Settings\Uživatel\Data aplikací\Mozilla\Firefox\Profiles\etnv822j.default\Extensions\{0FED7D55-65D4-47b6-A6DE-9A4ADB55355F}
FF Extension: No Name - C:\Documents and Settings\Uživatel\Data aplikací\Mozilla\Firefox\Profiles\etnv822j.default\Extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
FF Extension: MR Tech Toolkit - C:\Documents and Settings\Uživatel\Data aplikací\Mozilla\Firefox\Profiles\etnv822j.default\Extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}
FF Extension: No Name - C:\Documents and Settings\Uživatel\Data aplikací\Mozilla\Firefox\Profiles\etnv822j.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}(2)
FF Extension: personas - C:\Documents and Settings\Uživatel\Data aplikací\Mozilla\Firefox\Profiles\etnv822j.default\Extensions\personas@christopher.beard.xpi
FF Extension: prefs - C:\Documents and Settings\Uživatel\Data aplikací\Mozilla\Firefox\Profiles\etnv822j.default\Extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}.xpi
FF Extension: Adblock Plus - C:\Documents and Settings\Uživatel\Data aplikací\Mozilla\Firefox\Profiles\etnv822j.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\Alwil Software\Avast5\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\Alwil Software\Avast5\WebRep\FF
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

========================== Services (Whitelisted) =================

R2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [46808 2013-05-09] (AVAST Software)
R2 SoundMAX Agent Service (default); C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe [45056 2002-09-20] (Analog Devices, Inc.)
R2 VMCService; C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [9216 2009-09-18] (Vodafone)
R2 JavaQuickStarterService; "C:\Program Files\Java\jre7\bin\jqs.exe" -service -config "C:\Program Files\Java\jre7\lib\deploy\jqs\jqs.conf"

==================== Drivers (Whitelisted) ====================

R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [29816 2013-05-09] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [66336 2013-05-09] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [49760 2013-05-09] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49376 2013-05-09] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [770344 2013-07-14] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [369584 2013-07-14] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [56080 2013-05-09] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [175176 2013-07-14] ()
R3 FETNDIS; C:\Windows\System32\DRIVERS\fetnd5b.sys [35328 2003-01-27] (VIA Technologies, Inc. )
R3 gameenum; C:\Windows\System32\DRIVERS\gameenum.sys [10624 2008-04-13] (Microsoft Corporation)
S3 HPZid412; C:\Windows\System32\DRIVERS\HPZid412.sys [51088 2004-06-22] (HP)
S3 HPZipr12; C:\Windows\System32\DRIVERS\HPZipr12.sys [16496 2004-06-22] (HP)
S3 HPZius12; C:\Windows\System32\DRIVERS\HPZius12.sys [21744 2004-06-22] (HP)
S3 hwusbfake; C:\Windows\System32\DRIVERS\ewusbfake.sys [100480 2009-07-23] (Huawei Technologies Co., Ltd.)
S3 NTSIM; C:\WINDOWS\system32\ntsim.sys [6016 2002-09-12] (VIA Technologies, Inc. )
R0 viaagp1; C:\Windows\System32\DRIVERS\viaagp1.sys [27904 2003-07-02] (VIA Technologies, Inc.)
S4 IntelIde; No ImagePath
U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
U1 WS2IFSL;

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-12-16 22:42 - 2013-12-16 22:42 - 00009803 _____ C:\Documents and Settings\Uživatel\Plocha\FRST.txt
2013-12-16 22:42 - 2013-12-16 22:42 - 00000000 ____D C:\FRST
2013-12-16 22:40 - 2013-12-16 22:40 - 01060997 _____ (Farbar) C:\Documents and Settings\Uživatel\Plocha\FRST.exe
2013-12-16 22:40 - 2013-12-16 22:40 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Uživatel\Plocha\FRSTLauncher.exe
2013-11-16 09:16 - 2013-11-16 16:15 - 00000000 ____D C:\Program Files\Mozilla Firefox

==================== One Month Modified Files and Folders =======

2013-12-16 22:42 - 2013-12-16 22:42 - 00009803 _____ C:\Documents and Settings\Uživatel\Plocha\FRST.txt
2013-12-16 22:42 - 2013-12-16 22:42 - 00000000 ____D C:\FRST
2013-12-16 22:42 - 2009-04-02 12:47 - 00000000 ____D C:\Documents and Settings\Uživatel\Plocha
2013-12-16 22:41 - 2009-10-10 10:05 - 00000000 ____D C:\Staženiny
2013-12-16 22:41 - 2009-04-03 08:52 - 00003547 ____C C:\WINDOWS\wincmd.ini
2013-12-16 22:41 - 2009-04-02 12:47 - 00000000 ___HD C:\Documents and Settings\Uživatel\Local Settings\Data aplikací
2013-12-16 22:40 - 2013-12-16 22:40 - 01060997 _____ (Farbar) C:\Documents and Settings\Uživatel\Plocha\FRST.exe
2013-12-16 22:40 - 2013-12-16 22:40 - 00112640 _____ (forum.viry.cz) C:\Documents and Settings\Uživatel\Plocha\FRSTLauncher.exe
2013-12-16 22:36 - 2009-04-02 12:39 - 00032490 _____ C:\WINDOWS\SchedLgU.Txt
2013-12-16 22:36 - 2009-04-02 12:39 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-12-16 22:11 - 2009-04-02 12:33 - 01562213 _____ C:\WINDOWS\WindowsUpdate.log
2013-12-16 22:09 - 2012-07-16 17:27 - 00000318 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job
2013-12-16 22:09 - 2009-04-02 14:18 - 00000159 _____ C:\WINDOWS\wiadebug.log
2013-12-16 22:09 - 2009-04-02 14:18 - 00000050 _____ C:\WINDOWS\wiaservc.log
2013-12-16 14:38 - 2009-04-02 12:47 - 00000178 ___SH C:\Documents and Settings\Uživatel\ntuser.ini
2013-12-16 11:17 - 2009-10-10 10:31 - 00000000 ____D C:\ZALOHA
2013-12-16 10:51 - 2006-03-02 13:00 - 00002422 _____ C:\WINDOWS\system32\wpa.dbl
2013-12-11 13:22 - 2009-11-24 10:32 - 00000000 ____D C:\Program Files\Inter Cars
2013-12-09 08:45 - 2009-04-02 12:47 - 00000000 ___RD C:\Documents and Settings\Uživatel\Dokumenty
2013-11-18 08:07 - 2012-04-26 07:27 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-11-16 16:15 - 2013-11-16 09:16 - 00000000 ____D C:\Program Files\Mozilla Firefox

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe
[2006-03-02 13:00] - [2008-04-14 04:22] - 1034240 ____A (Microsoft Corporation) 27afd587c462e280ee046b8cca3c2cd1

C:\Windows\System32\winlogon.exe
[2006-03-02 13:00] - [2008-04-14 04:22] - 0507904 ____A (Microsoft Corporation) cddb1f8e1aea356f3ad106f2cf9b7fea

C:\Windows\System32\svchost.exe
[2006-03-02 13:00] - [2008-04-14 04:22] - 0014336 ____A (Microsoft Corporation) be4a520e29b6391f49e79ccc52044d93

C:\Windows\System32\services.exe
[2006-03-02 13:00] - [2009-02-09 12:25] - 0111104 ____A (Microsoft Corporation) 9ef697af07bb8dd82c3b02ca953a95b7

C:\Windows\System32\User32.dll
[2006-03-02 13:00] - [2008-04-14 04:22] - 0578560 ____A (Microsoft Corporation) e16e0990967374e76f3e40cacafd3d53

C:\Windows\System32\userinit.exe
[2006-03-02 13:00] - [2008-04-14 04:22] - 0026112 ____A (Microsoft Corporation) 7dc1830f22e7d275b438127b68030239

C:\Windows\System32\Drivers\volsnap.sys
[2006-03-02 13:00] - [2008-04-14 03:12] - 0052480 ____A (Microsoft Corporation) 28a4b296b47782173c346e376cb374d1





===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================

Drive c: () (Fixed) (Total:149.04 GB) (Free:119.47 GB) NTFS ==>[Drive with boot components (Windows XP)]

Available physical RAM: 550.26 MB
Total physical RAM: 1023.53 MB
Percentage of memory in use: 46%

==================== MBR and Partition Table ==================

Disk: 0 (Size: 149 GB) (Disk ID: B7B4B7B4)
Partition 1: (Active) - (Size=149 GB) - (Type=07 NTFS)

==================== Scheduled Tasks (whitelisted) ==================

Task: C:\WINDOWS\Tasks\avast! Emergency Update.job => C:\Program Files\Alwil Software\Avast5\AvastEmUpdate.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: avast! Antivirus (Disabled - Up to date) {7591DB91-41F0-48A3-B128-1A293FD8233D}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Documents and Settings\Uivatel\Plocha" je 373 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DoNotAllowExceptions REG_DWORD 0x0


[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"


[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\\Documents and Settings\\Uivatel\\Local Settings\\Temp\\7zS1AD6\\HPDiagnosticCoreUI.exe"="C:\\Documents and Settings\\Uivatel\\Local Settings\\Temp\\7zS1AD6\\HPDiagnosticCoreUI.exe:*:Enabled:HPSAPS"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP"="1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007"
"2869:TCP"="2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008"


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000


==================== End Of Log ==============================

Re: Prosím o kontrolu logu

Napsal: 17 pro 2013 11:36
od JaRon
vypis 3 procesy, ktore najviac vytazuju CPU

Re: Prosím o kontrolu logu

Napsal: 17 pro 2013 14:36
od mrazik
Je to svchost.exe , zabere 99% CPU.

Re: Prosím o kontrolu logu

Napsal: 17 pro 2013 14:42
od JaRon
skus vypnut automaticke aktualizacie - nepodarok Made in MS :James008:

Re: Prosím o kontrolu logu

Napsal: 17 pro 2013 16:24
od mrazik
To už jsem zkusil, nepomohlo. Vypnu ho pouze ve správci, pak vše běží v pohodě, ale to trochu náročné pro běžného uživatele.

Re: Prosím o kontrolu logu

Napsal: 17 pro 2013 16:40
od cernohous13
Zdravím,

Aut. aktualizace zakaž v Ovládacích panelech

Aktualizuj IE na IE8
Vypni štíty Avastu do restartu (případně i FW a nikam jinam nelez)

v IE8 jdi na http://update.microsoft.com/microsoftup ... aspx?ln=cs
stáhni a instaluj - PC bude asi tak 1/2 hodiny nepoužitelné :(

pak napiš

Re: Prosím o kontrolu logu

Napsal: 17 pro 2013 16:49
od mrazik
OK, jdu na to

Re: Prosím o kontrolu logu

Napsal: 13 led 2014 06:46
od cernohous13