Stránka 1 z 2

Přetížení CPU

Napsal: 21 led 2014 16:18
od pauleta11
Prosím o kontrolu logu. Přetižuje se mi CPU, hlavně při surfování na google chrome. Počítač je čerstvě vyčištěn, a antivir avira nic nenašel. (pomalu na mě- jsem amamtér) díky :)




Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:01:42, on 21.1.2014
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16526)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\pavel\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... on&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.certified-toolbar.com?si= ... bs=true&q=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.certified-toolbar.com?si= ... bs=true&q=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.certified-toolbar.com?si= ... bs=true&q=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... on&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.certified-toolbar.com?si= ... bs=true&q=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.certified-toolbar.com?si= ... bs=true&q=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.certified-toolbar.com?si= ... bs=true&q=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.certified-toolbar.com?si= ... e&tid=2937
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.certified-toolbar.com?si= ... bs=true&q=
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.certified-toolbar.com?si= ... bs=true&q=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Avira SearchFree Toolbar BHO - {41564952-412D-5637-4300-7A786E7484D7} - "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport.dll" (file missing)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport.dll" (file missing)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [ApnTBMon] "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"
O4 - HKLM\..\Run: [mobilegeni daemon] "C:\Program Files (x86)\Mobogenie\DaemonProcess.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\pavel\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Avira Mail Protection (AntiVirMailService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Norton Internet Security - Unknown owner - C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Audio Service (STacSV) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_8aadd48d\STacSV64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9878 bytes

Re: Přetížení CPU

Napsal: 21 led 2014 16:51
od vyosek
Zdravim :)

:arrow: Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
  • Ulozte nejlepe na plochu
  • Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
  • Probehne vytvoreni zalohy a nasledne prohledavani
  • Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte
:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte

Re: Přetížení CPU

Napsal: 21 led 2014 20:21
od pauleta11
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.0 (01.07.2014:1)
OS: Windows (TM) Vista Home Premium x64
Ran by pavel on Łt 21.01.2014 at 20:08:40,27
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Łt 21.01.2014 at 20:16:12,01
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Re: Přetížení CPU

Napsal: 21 led 2014 20:28
od pauleta11
# AdwCleaner v3.017 - Report created 21/01/2014 at 20:25:07
# Updated 12/01/2014 by Xplode
# Operating System : Windows (TM) Vista Home Premium Service Pack 2 (64 bits)
# Username : pavel - PAVEL-PC
# Running from : C:\Users\pavel\Downloads\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

[!] Folder Deleted : C:\ProgramData\Ask
[!] Folder Deleted : C:\ProgramData\ICQ\ICQToolbar
[!] Folder Deleted : C:\Program Files (x86)\Red Sky
[!] Folder Deleted : C:\Program Files (x86)\Common Files\AVG Secure Search
[!] Folder Deleted : C:\Users\pavel\AppData\Local\genienext
[!] Folder Deleted : C:\Users\pavel\AppData\Local\Mobogenie
[!] Folder Deleted : C:\Users\pavel\AppData\Local\Temp\outobox
[!] Folder Deleted : C:\Users\pavel\AppData\Roaming\newnext.me
[!] Folder Deleted : C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\ICQToolbarData
[!] Folder Deleted : C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}
[!] Folder Deleted : C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\Extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}
[!] Folder Deleted : C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\Extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}
File Deleted : C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\Extensions\pdfforge@mybrowserbar.com
File Deleted : C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\Extensions\wtxpcom@mybrowserbar.com
File Deleted : C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\searchplugins\Askcom.xml
File Deleted : C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\searchplugins\askcomsearch.xml
File Deleted : C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\searchplugins\Babylon.xml
File Deleted : C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\searchplugins\browsemngr.xml
File Deleted : C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\searchplugins\icqplugin.xml
File Deleted : C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\searchplugins\icqplugin-1.xml
File Deleted : C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\searchplugins\icqplugin-2.xml
File Deleted : C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\searchplugins\icqplugin-3.xml
File Deleted : C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\searchplugins\icqplugin-4.xml
File Deleted : C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\searchplugins\icqplugin-5.xml
File Deleted : C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\searchplugins\icqplugin-6.xml
File Deleted : C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\searchplugins\icqplugin-7.xml
File Deleted : C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\searchplugins\icqplugin-8.xml
File Deleted : C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\searchplugins\icqplugin-9.xml
File Deleted : C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\searchplugins\Web Search.xml
File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\Web Search.xml
File Deleted : C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\user.js
File Deleted : C:\Windows\System32\Tasks\GoforFilesUpdate
File Deleted : C:\Windows\System32\Tasks\ProtectedSearch
File Deleted : C:\Windows\System32\Tasks\YourFile Update

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\bcjagnifjocnddgeknajocbkkhlgibem
Key Deleted : HKCU\Software\Classes\pokki
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [mobilegeni daemon]
Key Deleted : HKCU\Software\f538fdabd6aed46
Key Deleted : HKLM\SOFTWARE\f538fdabd6aed46
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{761F6A83-F007-49E4-8EAC-CDB6808EF06F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{76C45B18-A29E-43EA-AAF8-AF55C2E1AE17}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{96EF404C-24C7-43D0-9096-4CCC8BB7CCAC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{97720195-206A-42AE-8E65-260B9BA5589F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{97D69524-BB57-4185-9C7F-5F05593B771A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{986F7A5A-9676-47E1-8642-F41F8C3FCF82}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B18788A4-92BD-440E-A4D1-380C36531119}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E327B07A-0E11-4FD4-BEF2-B2C5605B59C6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFD485F0-96BD-47CD-BB6D-CD7DDA95F102}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\GoforFiles
Key Deleted : HKCU\Software\ProtectedSearch
Key Deleted : HKLM\Software\GoforFiles
Key Deleted : HKLM\Software\ICQ\ICQToolbar
Key Deleted : HKLM\Software\PIP
Key Deleted : HKLM\Software\Uniblue
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{A0B139A7-E8D5-49E8-A7BF-12421E652208}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyPC Backup
Key Deleted : [x64] HKLM\SOFTWARE\Speedchecker Limited

***** [ Browsers ] *****

-\\ Internet Explorer v9.0.8112.16526

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Default_Page_URL]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Bar]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Start Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Start Default_Page_URL]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Search Bar]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Search Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Start Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Start Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Default_Search_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Search Bar]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Search Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [(Default)]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [(Default)]

-\\ Mozilla Firefox v

[ File : C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\prefs.js ]

Line Deleted : user_pref("browser.search.defaulturl", "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.3&q=");
Line Deleted : user_pref("icqtoolbar.allowSendURL", false);
Line Deleted : user_pref("icqtoolbar.defSearchChange", true);
Line Deleted : user_pref("icqtoolbar.engineVerified", true);
Line Deleted : user_pref("icqtoolbar.geolastmodified", 1326725637);
Line Deleted : user_pref("icqtoolbar.hiddenElements", "itb_options");
Line Deleted : user_pref("icqtoolbar.history", "search.yahoo.com%2Fsearch%3Fp%3Dharcinik.kvalitne.cz%252Fprofesni%252Fskola%252F5_semestr.html%26fr%3Dgreentree_ff1%26ei%3Dutf-8%26ilc%3D12%26type%3D971163||harcinik.k[...]
Line Deleted : user_pref("icqtoolbar.hpChange", true);
Line Deleted : user_pref("icqtoolbar.icqgeo", 42);
Line Deleted : user_pref("icqtoolbar.installTime", "1324143233");
Line Deleted : user_pref("icqtoolbar.installsource", "1");
Line Deleted : user_pref("icqtoolbar.newtab_state", "1");
Line Deleted : user_pref("icqtoolbar.numberOfSearches", 0);
Line Deleted : user_pref("icqtoolbar.previousFFVersion", "7.0.1");
Line Deleted : user_pref("icqtoolbar.skip_default_search", "no");
Line Deleted : user_pref("icqtoolbar.suggestions", false);
Line Deleted : user_pref("icqtoolbar.uniqueID", "130090324313009032431300910341502");
Line Deleted : user_pref("icqtoolbar.usageStatstTimestamp", 1324248547);
Line Deleted : user_pref("icqtoolbar.userHpApproved", true);
Line Deleted : user_pref("icqtoolbar.version", "1.4.1");
Line Deleted : user_pref("icqtoolbar.voucherHideClicks", 0);
Line Deleted : user_pref("icqtoolbar.voucherMoreLinkClicks", 0);
Line Deleted : user_pref("icqtoolbar.voucherRedeemClicks", 0);
Line Deleted : user_pref("icqtoolbar.voucherWasShown", 0);
Line Deleted : user_pref("icqtoolbar.xmlEnableHomePageDsGuard", false);
Line Deleted : user_pref("icqtoolbar.xmlEnableSuggestions", false);
Line Deleted : user_pref("icqtoolbar.xmlLanguage", "cs");
Line Deleted : user_pref("extensions.asktb.ff-original-keyword-url", "hxxp://search.certified-toolbar.com?si=41460&tid=592&bs=true&q=");

-\\ Google Chrome v32.0.1700.76

[ File : C:\Users\pavel\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [11251 octets] - [21/01/2014 20:22:55]
AdwCleaner[S0].txt - [10131 octets] - [21/01/2014 20:25:07]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [10192 octets] ##########





(omlouvám se za spoždění, měl jsem tréning)

Re: Přetížení CPU

Napsal: 21 led 2014 22:17
od pauleta11
poradte někdo. stačí mi otevřít dvě záložky v chromu a komp mi hučí

Re: Přetížení CPU

Napsal: 21 led 2014 22:24
od vyosek
:arrow: Vy jste mel sve zaliby, my je mame ted tez - uvedomte si mlaskave, zenase forum funguje na bazi dobrovolnosti, vsichni jsme tu zdarma a venujeme NAS VOLNY cas na reseni VASICH problemu. Pokud se Vam nechce cekat, nikdo Vas tu nenuti byt, tlacitko Odhlasit mate vlevo nahore a pak si muzete zaplatit servis, ktery muzete uhanet at uz to ma hotove.

:arrow: Dejte log dle tohoto navodu http://forum.viry.cz/viewtopic.php?f=13&t=133100

Re: Přetížení CPU

Napsal: 21 led 2014 22:59
od pauleta11
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-01-2014
Ran by pavel (administrator) on PAVEL-PC on 21-01-2014 22:57:10
Running from C:\Users\pavel\Desktop
Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: Czech
Internet Explorer Version 9
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_8aadd48d\stacsv64.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe
(forum.viry.cz) C:\Users\pavel\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\SysWOW64\conime.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1560872 2008-07-24] (Synaptics, Inc.)
HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1584184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [441856 2008-10-26] (IDT, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-09] (Avira Operations GmbH & Co. KG)
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [138240 2008-01-21] (Microsoft Corporation)
HKCU\...\Run: [Google Update] - C:\Users\pavel\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2012-02-27] (Google Inc.)
HKCU\...\Run: [ABBYY Screenshot Reader Bonus] - [x]
MountPoints2: G - G:\HTC_Sync_Manager_PC.exe
MountPoints2: {42c3e172-1d19-11e3-b4dc-00247ea06d8f} - F:\HTC_Sync_Manager_PC.exe
MountPoints2: {9172e86b-5553-11e0-9a3e-00247ea06d8f} - G:\Bolt.exe
MountPoints2: {fe06b6a3-1df0-11e3-a2ee-00247ea06d8f} - G:\HTC_Sync_Manager_PC.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.cz/
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId= ... on&pf=cnnb
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... on&pf=cnnb
URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {D6275609-6280-4335-AEDA-B09C03158BE1} URL = http://slirsredirect.search.aol.com/sli ... bie7-cs-cz
SearchScopes: HKLM - {D6275609-6280-4335-AEDA-B09C03158BE1} URL = http://slirsredirect.search.aol.com/sli ... bie7-cs-cz
SearchScopes: HKCU - {A7E07061-8C53-4F58-9D44-7337419A302F} URL = http://search.yahoo.com/search?fr=chr-g ... earchTerms}
BHO: Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll (APN LLC.)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport.dll (APN LLC.)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll (APN LLC.)
Toolbar: HKLM-x32 - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport.dll (APN LLC.)
Toolbar: HKCU - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll (APN LLC.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [50176] (Společnost Microsoft)
Winsock: Catalog5-x64 02 %SystemRoot%\system32\napinsp.dll [62976] (Společnost Microsoft)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.254

FireFox:
========
FF ProfilePath: C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default
FF DefaultSearchEngine: Ask.com Search
FF NetworkProxy: "type", 0
FF SearchEngineOrder.1: Ask.com Search
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @lastpass.com/NPLastPass - C:\Program Files (x86)\LastPass\nplastpass64.dll (LastPass)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll (Adobe Systems, Inc.)
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @graphisoft.com/GDL Web Plug-in - C:\Program Files (x86)\GRAPHISOFT\GDLWebControl\npGDLMozilla.dll ()
FF Plugin-x32: @java.com/DTPlugin - C:\Program Files (x86)\Java\jre6\bin\npDeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @lastpass.com/NPLastPass - C:\Program Files (x86)\LastPass\nplastpass.dll (LastPass)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\pavel\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\pavel\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\pavel\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\pavel\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\pavel\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\pavel\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\pavel\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\pavel\AppData\Roaming\mozilla\plugins\npgtpo3dautoplugin.dll ()
FF Plugin ProgramFiles/Appdata: C:\Users\pavel\AppData\Roaming\mozilla\plugins\npo1d.dll (Google)
FF SearchPlugin: C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\searchplugins\searchplugins-backup
FF Extension: DownloadHelper - C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2011-12-17]
FF Extension: Greasemonkey - C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781} [2011-12-17]
FF Extension: Office Black - C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\Extensions\Office2007Black@JBBS.xpi [2011-03-23]
FF Extension: BlackFox V1-Blue - C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\Extensions\zigboom.designs@gmail.com.xpi [2011-03-23]
FF Extension: ImTranslator - C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\Extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi [2011-03-23]
FF Extension: Green Fox - C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\Extensions\{d122ad80-ff45-11dd-87af-0800200c9a66}.xpi [2011-03-23]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} [2011-04-22]
FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012-12-15]

Chrome:
=======
CHR Extension: (Dokumenty Google) - C:\Users\pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-21]
CHR Extension: (Disk Google) - C:\Users\pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-21]
CHR Extension: (YouTube) - C:\Users\pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-21]
CHR Extension: (Vyhled\u00E1v\u00E1n\u00ED Google) - C:\Users\pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-21]
CHR Extension: (Pen\u011B\u017Eenka Google) - C:\Users\pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-21]
CHR Extension: (Avira SearchFree Toolbar plus Web Protection) - C:\Users\pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pcoohmdcpejoeggdnihdfhohjgdbllgm [2014-01-21]
CHR Extension: (Gmail) - C:\Users\pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-21]
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-12-12]
CHR HKLM-x32\...\Chrome\Extension: [pcoohmdcpejoeggdnihdfhohjgdbllgm] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7C\CRX\ToolbarCR.crx [2013-12-20]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

S4 ABBYY.Licensing.PDFTransformer.Classic.3.0; C:\Program Files (x86)\ABBYY PDF Transformer 3.0\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
S4 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_8aadd48d\AESTSr64.exe [89088 2008-06-27] (Andrea Electronics Corporation)
R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe [896056 2013-12-09] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-12-09] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-12-09] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1011768 2013-12-09] (Avira Operations GmbH & Co. KG)
S4 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-12-20] (APN LLC.)
S4 Connectify; C:\Program Files (x86)\Connectify\ConnectifyService.exe [65536 2012-11-09] ()
S4 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] ()
S4 Recovery Service for Windows; C:\Program Files (x86)\SMINST\BLService.exe [365952 2008-12-17] ()
R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_8aadd48d\STacSV64.exe [279040 2008-10-26] (IDT, Inc.)
S4 TVCapSvc; C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe [296320 2008-11-26] ()
S4 TVSched; C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe [116096 2008-11-26] ()
R2 ezSharedSvc; C:\Windows\System32\ezsvc7.dll [x]
S2 Norton Internet Security; "C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe" /s "Norton Internet Security" /m "C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\diMaster.dll" /prefetch:1

==================== Drivers (Whitelisted) ====================

S3 AVerAF15; C:\Windows\System32\Drivers\AVerAF15.sys [306688 2008-07-04] (AVerMedia TECHNOLOGIES, Inc.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-09] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-09] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-12-09] (Avira Operations GmbH & Co. KG)
S3 cnnctfy2; C:\Windows\System32\DRIVERS\cnnctfy2.sys [35440 2013-09-30] (Connectify)
R3 cnnctfy2MP; C:\Windows\System32\DRIVERS\cnnctfy2.sys [35440 2013-09-30] (Connectify)
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [275432 2009-04-11] (Společnost Microsoft)
R3 Ntfs; C:\Windows\System32\Drivers\Ntfs.sys [1513320 2013-03-03] (Společnost Microsoft)
S2 Sentinel64; C:\Windows\System32\Drivers\Sentinel64.sys [145448 2009-09-17] (SafeNet, Inc.)
S3 avfwim; system32\DRIVERS\avfwim.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 JMCR; system32\DRIVERS\jmcr.sys [x]
S3 NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\ENG64.SYS [x]
S3 NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\EX64.SYS [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [x]
S1 SRTSP; \??\C:\Windows\system32\drivers\NISx64\1000000.07D\SRTSP64.SYS [x]
S1 SRTSPX; \??\C:\Windows\system32\drivers\NISx64\1000000.07D\SRTSPX64.SYS [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-01-21 22:57 - 2014-01-21 22:57 - 00018122 _____ C:\Users\pavel\Desktop\FRST.txt
2014-01-21 22:56 - 2014-01-21 22:56 - 00000000 ____D C:\FRST
2014-01-21 22:54 - 2014-01-21 22:54 - 00112640 _____ (forum.viry.cz) C:\Users\pavel\Downloads\FRSTLauncher (1).exe
2014-01-21 22:54 - 2014-01-21 22:54 - 00112640 _____ (forum.viry.cz) C:\Users\pavel\Desktop\FRSTLauncher.exe
2014-01-21 22:53 - 2014-01-21 22:53 - 00112640 _____ (forum.viry.cz) C:\Users\pavel\Downloads\Nepotvrzeno 989826.crdownload
2014-01-21 22:33 - 2014-01-21 22:32 - 02077184 _____ (Farbar) C:\Users\pavel\Desktop\FRST64.exe
2014-01-21 21:36 - 2014-01-21 21:36 - 00000640 _____ C:\Users\pavel\Desktop\JRT.txt
2014-01-21 21:18 - 2014-01-21 21:18 - 00001156 _____ C:\Users\Public\Desktop\My LastPass Vault.lnk
2014-01-21 20:52 - 2014-01-21 21:20 - 00000000 ____D C:\Program Files (x86)\LastPass
2014-01-21 20:52 - 2014-01-21 21:18 - 00000000 ____D C:\Users\pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass
2014-01-21 20:22 - 2014-01-21 20:25 - 00000000 ____D C:\AdwCleaner
2014-01-21 17:16 - 2014-01-21 17:16 - 00000000 ____D C:\Windows\ERUNT
2014-01-21 16:45 - 2014-01-21 16:45 - 00002025 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2014-01-21 16:42 - 2014-01-21 16:52 - 49940480 _____ C:\Program Files (x86)\GUT6430.tmp
2014-01-21 16:42 - 2014-01-21 16:42 - 00000000 ____D C:\Program Files (x86)\GUM6410.tmp
2014-01-21 16:41 - 2014-01-21 16:41 - 00000000 ____D C:\Users\pavel\AppData\Local\AskPartnerNetwork
2014-01-21 16:37 - 2014-01-21 21:53 - 00000000 ____D C:\Users\pavel\AppData\Roaming\Google Chrome Backup
2014-01-21 16:36 - 2014-01-21 16:36 - 00000000 ____D C:\Program Files (x86)\Google Chrome Backup
2014-01-21 15:40 - 2014-01-21 15:45 - 00004245 _____ C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log
2014-01-21 14:58 - 2014-01-21 14:58 - 00003034 _____ C:\Windows\System32\Tasks\{C7AA77F6-B8D8-4978-9036-96056C70D212}
2014-01-21 14:57 - 2014-01-21 14:57 - 00000000 ____D C:\Intel
2014-01-21 12:42 - 2014-01-21 13:47 - 523547951 _____ C:\Users\pavel\Downloads\DALLAS-BUYERS-CLUB-KLUB-POSLEDNÍ-NADĚJE-CZ-TITULKY-DVDScr-2013-MIGON14.mkv
2014-01-01 21:10 - 2014-01-01 21:12 - 00000000 ____D C:\Users\pavel\AppData\Local\cache
2014-01-01 21:10 - 2014-01-01 21:10 - 00000000 ____D C:\Users\pavel\.android
2014-01-01 21:10 - 2014-01-01 21:10 - 00000000 _____ C:\Users\pavel\daemonprocess.txt
2013-12-29 11:18 - 2013-12-29 11:18 - 00000000 ____D C:\Users\pavel\AppData\Local\VNT
2013-12-29 11:17 - 2013-12-29 11:17 - 00000000 ____D C:\Users\pavel\AppData\Roaming\Avira
2013-12-29 11:17 - 2013-12-29 11:17 - 00000000 ____D C:\ProgramData\AskPartnerNetwork
2013-12-29 11:17 - 2013-12-29 11:17 - 00000000 ____D C:\Program Files (x86)\VNT
2013-12-29 11:17 - 2013-12-29 11:17 - 00000000 ____D C:\Program Files (x86)\AskPartnerNetwork
2013-12-29 11:15 - 2013-12-29 11:15 - 00001901 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2013-12-29 11:15 - 2013-12-29 11:15 - 00000000 ____D C:\Program Files (x86)\Avira
2013-12-29 11:15 - 2013-12-09 11:43 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-12-29 11:15 - 2013-12-09 11:43 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-12-29 11:15 - 2013-12-09 11:43 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-12-29 10:45 - 2013-12-29 10:57 - 140347096 _____ C:\Users\pavel\Downloads\avira_internet_security_suite_en.exe
2013-12-28 13:20 - 2013-12-28 13:20 - 00000512 _____ C:\Users\pavel\Downloads\Avira_14_9_2015.key
2013-12-26 15:03 - 2013-12-26 15:58 - 912747418 _____ C:\Users\pavel\Downloads\Cesta-(-2009-).avi

==================== One Month Modified Files and Folders =======

2014-01-21 22:57 - 2014-01-21 22:57 - 00018122 _____ C:\Users\pavel\Desktop\FRST.txt
2014-01-21 22:57 - 2011-09-05 14:53 - 00000950 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-21 22:56 - 2014-01-21 22:56 - 00000000 ____D C:\FRST
2014-01-21 22:54 - 2014-01-21 22:54 - 00112640 _____ (forum.viry.cz) C:\Users\pavel\Downloads\FRSTLauncher (1).exe
2014-01-21 22:54 - 2014-01-21 22:54 - 00112640 _____ (forum.viry.cz) C:\Users\pavel\Desktop\FRSTLauncher.exe
2014-01-21 22:54 - 2011-03-22 23:07 - 01234898 _____ C:\Windows\WindowsUpdate.log
2014-01-21 22:53 - 2014-01-21 22:53 - 00112640 _____ (forum.viry.cz) C:\Users\pavel\Downloads\Nepotvrzeno 989826.crdownload
2014-01-21 22:49 - 2011-09-05 14:53 - 00000946 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-21 22:49 - 2006-11-02 16:42 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-21 22:49 - 2006-11-02 16:22 - 00003344 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-21 22:49 - 2006-11-02 16:22 - 00003344 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-21 22:47 - 2011-03-22 23:06 - 00006323 _____ C:\Windows\bthservsdp.dat
2014-01-21 22:47 - 2006-11-02 16:42 - 00032556 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2014-01-21 22:32 - 2014-01-21 22:33 - 02077184 _____ (Farbar) C:\Users\pavel\Desktop\FRST64.exe
2014-01-21 22:29 - 2011-03-23 06:32 - 00000000 ____D C:\Users\pavel
2014-01-21 22:20 - 2012-02-27 23:39 - 00000962 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4165329744-351483473-3812913338-1000UA.job
2014-01-21 22:18 - 2013-02-24 19:49 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-21 22:02 - 2013-10-10 17:21 - 00000000 ____D C:\Program Files\CCleaner
2014-01-21 22:02 - 2012-09-12 11:34 - 00000000 ____D C:\Users\pavel\AppData\Local\CrashDumps
2014-01-21 22:02 - 2012-08-08 16:00 - 00000000 ____D C:\Windows\Minidump
2014-01-21 21:53 - 2014-01-21 16:37 - 00000000 ____D C:\Users\pavel\AppData\Roaming\Google Chrome Backup
2014-01-21 21:36 - 2014-01-21 21:36 - 00000640 _____ C:\Users\pavel\Desktop\JRT.txt
2014-01-21 21:20 - 2014-01-21 20:52 - 00000000 ____D C:\Program Files (x86)\LastPass
2014-01-21 21:18 - 2014-01-21 21:18 - 00001156 _____ C:\Users\Public\Desktop\My LastPass Vault.lnk
2014-01-21 21:18 - 2014-01-21 20:52 - 00000000 ____D C:\Users\pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass
2014-01-21 20:40 - 2011-10-18 16:30 - 00000982 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4165329744-351483473-3812913338-1000UA.job
2014-01-21 20:26 - 2011-03-23 18:58 - 00000000 ____D C:\ProgramData\ICQ
2014-01-21 20:25 - 2014-01-21 20:22 - 00000000 ____D C:\AdwCleaner
2014-01-21 17:40 - 2006-11-02 16:21 - 00405264 _____ C:\Windows\system32\FNTCACHE.DAT
2014-01-21 17:16 - 2014-01-21 17:16 - 00000000 ____D C:\Windows\ERUNT
2014-01-21 16:52 - 2014-01-21 16:42 - 49940480 _____ C:\Program Files (x86)\GUT6430.tmp
2014-01-21 16:45 - 2014-01-21 16:45 - 00002025 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2014-01-21 16:44 - 2011-09-05 14:52 - 00000000 ____D C:\Program Files (x86)\Google
2014-01-21 16:43 - 2011-03-23 18:50 - 00111616 _____ C:\Users\pavel\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-01-21 16:42 - 2014-01-21 16:42 - 00000000 ____D C:\Program Files (x86)\GUM6410.tmp
2014-01-21 16:41 - 2014-01-21 16:41 - 00000000 ____D C:\Users\pavel\AppData\Local\AskPartnerNetwork
2014-01-21 16:36 - 2014-01-21 16:36 - 00000000 ____D C:\Program Files (x86)\Google Chrome Backup
2014-01-21 15:45 - 2014-01-21 15:40 - 00004245 _____ C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log
2014-01-21 15:43 - 2009-02-23 08:53 - 00000000 ____D C:\Program Files (x86)\Java
2014-01-21 14:58 - 2014-01-21 14:58 - 00003034 _____ C:\Windows\System32\Tasks\{C7AA77F6-B8D8-4978-9036-96056C70D212}
2014-01-21 14:57 - 2014-01-21 14:57 - 00000000 ____D C:\Intel
2014-01-21 14:57 - 2013-09-23 15:03 - 00000000 ____D C:\swsetup
2014-01-21 14:44 - 2012-01-20 12:52 - 00000000 ____D C:\Windows\pss
2014-01-21 14:36 - 2013-09-07 14:55 - 00000000 ___RD C:\Users\pavel\Dropbox
2014-01-21 14:36 - 2013-09-07 12:11 - 00000000 ____D C:\Users\pavel\AppData\Roaming\Dropbox
2014-01-21 13:52 - 2011-09-11 10:15 - 00000000 ____D C:\Users\pavel\Documents\ŠKOLA
2014-01-21 13:51 - 2011-10-04 21:30 - 00000000 ____D C:\Users\pavel\Documents\TISK
2014-01-21 13:48 - 2011-11-23 13:19 - 00000000 ____D C:\Users\pavel\Desktop\DOWNLOAD
2014-01-21 13:47 - 2014-01-21 12:42 - 523547951 _____ C:\Users\pavel\Downloads\DALLAS-BUYERS-CLUB-KLUB-POSLEDNÍ-NADĚJE-CZ-TITULKY-DVDScr-2013-MIGON14.mkv
2014-01-21 13:46 - 2013-12-12 19:26 - 00000000 ____D C:\Users\pavel\Downloads\Peťko jede bomby!
2014-01-20 12:44 - 2009-02-23 15:22 - 02624550 _____ C:\Windows\system32\perfh005.dat
2014-01-20 12:44 - 2009-02-23 15:22 - 00848584 _____ C:\Windows\system32\perfc005.dat
2014-01-20 12:44 - 2006-11-02 13:46 - 00006622 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-20 11:40 - 2011-10-18 16:30 - 00000960 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4165329744-351483473-3812913338-1000Core.job
2014-01-18 20:32 - 2013-09-07 14:55 - 00000919 _____ C:\Users\pavel\Desktop\Dropbox.lnk
2014-01-18 20:32 - 2013-09-07 13:57 - 00000000 ____D C:\Users\pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-01-17 10:22 - 2011-03-23 18:55 - 00000000 ____D C:\Users\pavel\AppData\Roaming\Mozilla
2014-01-16 13:28 - 2012-02-27 23:39 - 00000910 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4165329744-351483473-3812913338-1000Core.job
2014-01-16 00:48 - 2011-03-23 19:39 - 00000000 ____D C:\ProgramData\Microsoft Help
2014-01-16 00:47 - 2013-07-30 13:57 - 00000000 ____D C:\Windows\system32\MRT
2014-01-16 00:44 - 2006-11-02 13:35 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-01-15 20:21 - 2011-03-23 19:53 - 00000000 ____D C:\Users\pavel\AppData\Roaming\vlc
2014-01-12 23:55 - 2011-03-23 18:57 - 00000000 ____D C:\Users\pavel\AppData\Roaming\ICQ
2014-01-07 11:34 - 2011-03-23 20:36 - 00000000 ____D C:\Users\pavel\Graphisoft
2014-01-01 21:12 - 2014-01-01 21:10 - 00000000 ____D C:\Users\pavel\AppData\Local\cache
2014-01-01 21:11 - 2012-12-30 21:01 - 00000874 _____ C:\Users\pavel\Desktop\KMPlayer.lnk
2014-01-01 21:10 - 2014-01-01 21:10 - 00000000 ____D C:\Users\pavel\.android
2014-01-01 21:10 - 2014-01-01 21:10 - 00000000 _____ C:\Users\pavel\daemonprocess.txt
2013-12-29 11:18 - 2013-12-29 11:18 - 00000000 ____D C:\Users\pavel\AppData\Local\VNT
2013-12-29 11:17 - 2013-12-29 11:17 - 00000000 ____D C:\Users\pavel\AppData\Roaming\Avira
2013-12-29 11:17 - 2013-12-29 11:17 - 00000000 ____D C:\ProgramData\AskPartnerNetwork
2013-12-29 11:17 - 2013-12-29 11:17 - 00000000 ____D C:\Program Files (x86)\VNT
2013-12-29 11:17 - 2013-12-29 11:17 - 00000000 ____D C:\Program Files (x86)\AskPartnerNetwork
2013-12-29 11:15 - 2013-12-29 11:15 - 00001901 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2013-12-29 11:15 - 2013-12-29 11:15 - 00000000 ____D C:\Program Files (x86)\Avira
2013-12-29 11:15 - 2012-11-20 10:20 - 00000000 ____D C:\ProgramData\Avira
2013-12-29 10:57 - 2013-12-29 10:45 - 140347096 _____ C:\Users\pavel\Downloads\avira_internet_security_suite_en.exe
2013-12-28 13:20 - 2013-12-28 13:20 - 00000512 _____ C:\Users\pavel\Downloads\Avira_14_9_2015.key
2013-12-26 15:58 - 2013-12-26 15:03 - 912747418 _____ C:\Users\pavel\Downloads\Cesta-(-2009-).avi
2013-12-23 21:06 - 2011-03-23 19:53 - 00000000 ____D C:\Users\pavel\AppData\Roaming\dvdcss

Files to move or delete:
====================
C:\Users\pavel\AppData\Roaming\skype.ini


Some content of TEMP:
====================
C:\Users\pavel\AppData\Local\Temp\avgnt.exe
C:\Users\pavel\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================


==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: Avira Desktop (Disabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Disabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\pavel\Desktop" je 19364 MB.


***** Startup Programs *****

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ABBYY Screenshot Reader Bonus
"C:\Program Files (x86)\ABBYY PDF Transformer 3.0\Bonus.ScreenshotReader.exe" -autorun [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader
"C:\Program Files (x86)\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
"C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon
"C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlazeServoTool
"C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe" [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer for HP TouchSmart
"C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe" [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Connectify
C:\Program Files (x86)\Connectify\Connectify.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXMediaServer
"C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate
"C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DpAgent
C:\Program Files (x86)\DigitalPersona\Bin\dpagent.exe [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDAgent
"C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe" [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update
"C:\Users\pavel\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FileOpenBroker
C:\Program Files\FileOpen\Services\FileOpenBroker64.exe [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor
"C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler
c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update
C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ
"C:\Program Files (x86)\ICQ7.5\ICQ.exe" silent loginmode=4 [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\linkdoumi
C:\Program Files (x86)\linkdoumi\linkdoumi.exe [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\linkdoumiagent
C:\Program Files (x86)\linkdoumi\linkdoumiagent.exe [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr
"C:\Program Files (x86)\MSN Messenger\MsnMsgr.Exe" /background [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NextLive
C:\Windows\SysWOW64\rundll32.exe "C:\Users\pavel\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer
C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2
C:\Program Files (x86)\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe -tray [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NSU_agent
"C:\Program Files (x86)\Nokia\Nokia Software Updater\nsu3ui_agent.exe" [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl.exe
"C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /Start [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
"C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ROC_roc_ssl_v12
"C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12 [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchSettings
"C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe" [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartMenu
%ProgramFiles%\Hewlett-Packard\HP MediaSmart\SmartMenu.exe [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedUpMyComputer
C:\Program Files (x86)\SmartTweak\SpeedUpMyComputer\SpeedUpMyComputer.exe /ot /as [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TSMAgent
"C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe" [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TVAgent
"C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UCam_Menu
"C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Media\Webcam" update "Software\Hewlett-Packard\Media\Webcam" [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateLBPShortCut
"C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateP2GoShortCut
"C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePDIRShortCut
"C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0" [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePSTShortCut
"C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter" [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Vectir
C:\Program Files (x86)\Vectir\Vectir.exe /Startup [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VNT
C:\Program Files (x86)\VNT\vntldr.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WirelessAssistant
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wondershare Helper Compact.exe
C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTTray.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk
C:\PROGRA~2\HP\DIGITA~1\bin\hpqtra08.exe [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^pavel^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk
C:\Users\pavel\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [x]


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
DoNotAllowExceptions REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
DoNotAllowExceptions REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000001


==================== End Of Log ==============================

Re: Přetížení CPU

Napsal: 21 led 2014 23:15
od vyosek
:arrow: Maly dotaz, tu Aviru pouzivate free nebo internet security + zakoupeny klic??

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
    HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [138240 2008-01-21] (Microsoft Corporation)
    HKCU\...\Run: [Google Update] - C:\Users\pavel\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2012-02-27] (Google Inc.)
    HKCU\...\Run: [ABBYY Screenshot Reader Bonus] - [x]
    MountPoints2: G - G:\HTC_Sync_Manager_PC.exe
    MountPoints2: {42c3e172-1d19-11e3-b4dc-00247ea06d8f} - F:\HTC_Sync_Manager_PC.exe
    MountPoints2: {9172e86b-5553-11e0-9a3e-00247ea06d8f} - G:\Bolt.exe
    MountPoints2: {fe06b6a3-1df0-11e3-a2ee-00247ea06d8f} - G:\HTC_Sync_Manager_PC.exe
    
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId= ... on&pf=cnnb
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... on&pf=cnnb
    URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
    StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
    SearchScopes: HKLM - DefaultScope {D6275609-6280-4335-AEDA-B09C03158BE1} URL = http://slirsredirect.search.aol.com/sli ... 632&query={searchTerms}&invocationType=tb50hpcnnbie7-cs-cz
    SearchScopes: HKLM - {D6275609-6280-4335-AEDA-B09C03158BE1} URL = http://slirsredirect.search.aol.com/sli ... 632&query={searchTerms}&invocationType=tb50hpcnnbie7-cs-cz
    SearchScopes: HKCU - {A7E07061-8C53-4F58-9D44-7337419A302F} URL = http://search.yahoo.com/search?fr=chr-g ... =971163&p={searchTerms}
    BHO: Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll (APN LLC.)
    BHO-x32: Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport.dll (APN LLC.)
    Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll (APN LLC.)
    Toolbar: HKLM-x32 - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport.dll (APN LLC.)
    Toolbar: HKCU - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll (APN LLC.)
    
    FF DefaultSearchEngine: Ask.com Search
    FF SearchEngineOrder.1: Ask.com Search
    
    CHR Extension: (Avira SearchFree Toolbar plus Web Protection) - C:\Users\pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pcoohmdcpejoeggdnihdfhohjgdbllgm [2014-01-21]
    CHR HKLM-x32\...\Chrome\Extension: [pcoohmdcpejoeggdnihdfhohjgdbllgm] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7C\CRX\ToolbarCR.crx [2013-12-20]
    CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
    
    S4 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-12-20] (APN LLC.)
    R2 ezSharedSvc; C:\Windows\System32\ezsvc7.dll [x]
    
    C:\Program Files (x86)\SmartTweak
    C:\Program Files (x86)\AVG Secure Search
    C:\Users\pavel\AppData\Roaming\newnext.me
    C:\Program Files (x86)\linkdoumi
    2014-01-21 22:54 - 2014-01-21 22:54 - 00112640 _____ (forum.viry.cz) C:\Users\pavel\Downloads\FRSTLauncher (1).exe
    2014-01-21 22:54 - 2014-01-21 22:54 - 00112640 _____ (forum.viry.cz) C:\Users\pavel\Desktop\FRSTLauncher.exe
    2014-01-21 22:53 - 2014-01-21 22:53 - 00112640 _____ (forum.viry.cz) C:\Users\pavel\Downloads\Nepotvrzeno 989826.crdownload
    2014-01-21 21:36 - 2014-01-21 21:36 - 00000640 _____ C:\Users\pavel\Desktop\JRT.txt
    2014-01-21 16:41 - 2014-01-21 16:41 - 00000000 ____D C:\Users\pavel\AppData\Local\AskPartnerNetwork
    2013-12-29 11:17 - 2013-12-29 11:17 - 00000000 ____D C:\ProgramData\AskPartnerNetwork
    2013-12-29 11:17 - 2013-12-29 11:17 - 00000000 ____D C:\Program Files (x86)\AskPartnerNetwork
    C:\Users\pavel\AppData\Roaming\skype.ini
    C:\Users\pavel\AppData\Local\Temp\avgnt.exe
    C:\Users\pavel\AppData\Local\Temp\Quarantine.exe
    
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ABBYY Screenshot Reader Bonus" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlazeServoTool" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXMediaServer" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDAgent" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FileOpenBroker" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\linkdoumi" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\linkdoumiagent" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NextLive" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NSU_agent" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchSettings" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedUpMyComputer" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UCam_Menu" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateLBPShortCut" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateP2GoShortCut" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePDIRShortCut" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePSTShortCut" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Vectir" /f
    REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VNT" /f
    
    Hosts:
    CMD: shutdown /r /f /t 2
    
    End
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt

Re: Přetížení CPU

Napsal: 21 led 2014 23:30
od pauleta11
no mám internet security + časově omezenej klíč z jednoho warfora




Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 21-01-2014
Ran by pavel at 2014-01-21 23:23:28 Run:2
Running from C:\Users\pavel\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [138240 2008-01-21] (Microsoft Corporation)
HKCU\...\Run: [Google Update] - C:\Users\pavel\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2012-02-27] (Google Inc.)
HKCU\...\Run: [ABBYY Screenshot Reader Bonus] - [x]
MountPoints2: G - G:\HTC_Sync_Manager_PC.exe
MountPoints2: {42c3e172-1d19-11e3-b4dc-00247ea06d8f} - F:\HTC_Sync_Manager_PC.exe
MountPoints2: {9172e86b-5553-11e0-9a3e-00247ea06d8f} - G:\Bolt.exe
MountPoints2: {fe06b6a3-1df0-11e3-a2ee-00247ea06d8f} - G:\HTC_Sync_Manager_PC.exe

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId= ... on&pf=cnnb
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... on&pf=cnnb
URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {D6275609-6280-4335-AEDA-B09C03158BE1} URL = http://slirsredirect.search.aol.com/sli ... 632&query={searchTerms}&invocationType=tb50hpcnnbie7-cs-cz
SearchScopes: HKLM - {D6275609-6280-4335-AEDA-B09C03158BE1} URL = http://slirsredirect.search.aol.com/sli ... 632&query={searchTerms}&invocationType=tb50hpcnnbie7-cs-cz
SearchScopes: HKCU - {A7E07061-8C53-4F58-9D44-7337419A302F} URL = http://search.yahoo.com/search?fr=chr-g ... =971163&p={searchTerms}
BHO: Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll (APN LLC.)
BHO-x32: Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport.dll (APN LLC.)
Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll (APN LLC.)
Toolbar: HKLM-x32 - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport.dll (APN LLC.)
Toolbar: HKCU - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll (APN LLC.)

FF DefaultSearchEngine: Ask.com Search
FF SearchEngineOrder.1: Ask.com Search

CHR Extension: (Avira SearchFree Toolbar plus Web Protection) - C:\Users\pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pcoohmdcpejoeggdnihdfhohjgdbllgm [2014-01-21]
CHR HKLM-x32\...\Chrome\Extension: [pcoohmdcpejoeggdnihdfhohjgdbllgm] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7C\CRX\ToolbarCR.crx [2013-12-20]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

S4 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-12-20] (APN LLC.)
R2 ezSharedSvc; C:\Windows\System32\ezsvc7.dll [x]

C:\Program Files (x86)\SmartTweak
C:\Program Files (x86)\AVG Secure Search
C:\Users\pavel\AppData\Roaming\newnext.me
C:\Program Files (x86)\linkdoumi
2014-01-21 22:54 - 2014-01-21 22:54 - 00112640 _____ (forum.viry.cz) C:\Users\pavel\Downloads\FRSTLauncher (1).exe
2014-01-21 22:54 - 2014-01-21 22:54 - 00112640 _____ (forum.viry.cz) C:\Users\pavel\Desktop\FRSTLauncher.exe
2014-01-21 22:53 - 2014-01-21 22:53 - 00112640 _____ (forum.viry.cz) C:\Users\pavel\Downloads\Nepotvrzeno 989826.crdownload
2014-01-21 21:36 - 2014-01-21 21:36 - 00000640 _____ C:\Users\pavel\Desktop\JRT.txt
2014-01-21 16:41 - 2014-01-21 16:41 - 00000000 ____D C:\Users\pavel\AppData\Local\AskPartnerNetwork
2013-12-29 11:17 - 2013-12-29 11:17 - 00000000 ____D C:\ProgramData\AskPartnerNetwork
2013-12-29 11:17 - 2013-12-29 11:17 - 00000000 ____D C:\Program Files (x86)\AskPartnerNetwork
C:\Users\pavel\AppData\Roaming\skype.ini
C:\Users\pavel\AppData\Local\Temp\avgnt.exe
C:\Users\pavel\AppData\Local\Temp\Quarantine.exe

REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ABBYY Screenshot Reader Bonus" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlazeServoTool" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXMediaServer" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDAgent" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FileOpenBroker" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\linkdoumi" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\linkdoumiagent" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NextLive" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NSU_agent" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchSettings" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedUpMyComputer" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UCam_Menu" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateLBPShortCut" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateP2GoShortCut" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePDIRShortCut" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePSTShortCut" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Vectir" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VNT" /f

Hosts:
CMD: shutdown /r /f /t 2

End
*****************

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => Value not found.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\ehTray.exe => Value not found.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update => Value not found.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\ABBYY Screenshot Reader Bonus => Value not found.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G => Key not found.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{42c3e172-1d19-11e3-b4dc-00247ea06d8f} => Key not found.
HKCR\CLSID\{42c3e172-1d19-11e3-b4dc-00247ea06d8f} => Key not found.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9172e86b-5553-11e0-9a3e-00247ea06d8f} => Key not found.
HKCR\CLSID\{9172e86b-5553-11e0-9a3e-00247ea06d8f} => Key not found.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fe06b6a3-1df0-11e3-a2ee-00247ea06d8f} => Key deleted successfully.
HKCR\CLSID\{fe06b6a3-1df0-11e3-a2ee-00247ea06d8f} => Key not found.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\ => Value not found.
HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D6275609-6280-4335-AEDA-B09C03158BE1} => Key not found.
HKCR\CLSID\{D6275609-6280-4335-AEDA-B09C03158BE1} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A7E07061-8C53-4F58-9D44-7337419A302F} => Key not found.
HKCR\CLSID\{A7E07061-8C53-4F58-9D44-7337419A302F} => Key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41564952-412D-5637-4300-7A786E7484D7} => Key not found.
HKCR\CLSID\{41564952-412D-5637-4300-7A786E7484D7} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41564952-412D-5637-4300-7A786E7484D7} => Key not found.
HKCR\Wow6432Node\CLSID\{41564952-412D-5637-4300-7A786E7484D7} => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{41564952-412D-5637-4300-7A786E7484D7} => Value not found.
HKCR\CLSID\{41564952-412D-5637-4300-7A786E7484D7} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{41564952-412D-5637-4300-7A786E7484D7} => Value not found.
HKCR\Wow6432Node\CLSID\{41564952-412D-5637-4300-7A786E7484D7} => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{41564952-412D-5637-4300-7A786E7484D7} => Value not found.
HKCR\CLSID\{41564952-412D-5637-4300-7A786E7484D7} => Key not found.
Firefox DefaultSearchEngine deleted successfully.
Firefox SearchEngineOrder.1 deleted successfully.
C:\Users\pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pcoohmdcpejoeggdnihdfhohjgdbllgm directory not found.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pcoohmdcpejoeggdnihdfhohjgdbllgm => Key not found.
"C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7C\CRX\ToolbarCR.crx" => File/Directory not found.
HKLM\SOFTWARE\Policies\Google => Key not found.
APNMCP => Service not found.
ezSharedSvc => Service not found.
"C:\Program Files (x86)\SmartTweak" => File/Directory not found.
"C:\Program Files (x86)\AVG Secure Search" => File/Directory not found.
"C:\Users\pavel\AppData\Roaming\newnext.me" => File/Directory not found.
"C:\Program Files (x86)\linkdoumi" => File/Directory not found.
"C:\Users\pavel\Downloads\FRSTLauncher (1).exe" => File/Directory not found.
C:\Users\pavel\Desktop\FRSTLauncher.exe => Moved successfully.
"C:\Users\pavel\Downloads\Nepotvrzeno 989826.crdownload" => File/Directory not found.
"C:\Users\pavel\Desktop\JRT.txt" => File/Directory not found.
"C:\Users\pavel\AppData\Local\AskPartnerNetwork" => File/Directory not found.
"C:\ProgramData\AskPartnerNetwork" => File/Directory not found.
"C:\Program Files (x86)\AskPartnerNetwork" => File/Directory not found.
"C:\Users\pavel\AppData\Roaming\skype.ini" => File/Directory not found.
C:\Users\pavel\AppData\Local\Temp\avgnt.exe => Moved successfully.
C:\Users\pavel\AppData\Local\Temp\Quarantine.exe => Moved successfully.

========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ABBYY Screenshot Reader Bonus" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlazeServoTool" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXMediaServer" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDAgent" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FileOpenBroker" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\linkdoumi" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\linkdoumiagent" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NextLive" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NSU_agent" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchSettings" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedUpMyComputer" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UCam_Menu" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateLBPShortCut" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateP2GoShortCut" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePDIRShortCut" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePSTShortCut" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Vectir" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VNT" /f =========

Operace byla dokonźena ŁspŘçnŘ.



========= End of Reg: =========

C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.

========= shutdown /r /f /t 2 =========


========= End of CMD: =========


==== End of Fixlog ====

Re: Přetížení CPU

Napsal: 21 led 2014 23:33
od vyosek
pauleta11 píše:no mám internet security + časově omezenej klíč z jednoho warfora
Takze cinknuta a v rozporu s licencnimi podminkami ze :roll: :roll:


:arrow: Pred pokracovanim, vas musim pozadat o odstraneni NELEGALNI Aviry. Tento muj "pozadavek" vychazi z platnych pravidel fora http://forum.viry.cz/viewtopic.php?f=12&t=115512, ktere jste vy i ja povinnen dodrzovat
Pomáhat NELZE:
2) Pokud stroj uživatele prokazatelně obsahuje nelegální hostitelský čí ochranný software
(operační systém, antivir, firewall, atd.), je nutné navést uživatele k nápravě, např. skrze neplacený software,
a začít řešit, až v době kdy je PC "v pořádku". V případě že uživatel nechce na pravidla přistoupit,
je nutné jej vyzvat ať fórum opustí, a vrátí se až je splní.
:arrow: Takze pokud chcete pomoci, tak jej odinstalujte, nainstalujte free reseni (napr. Avast Free), napiste a budeme pokracovat

Re: Přetížení CPU

Napsal: 21 led 2014 23:42
od pauleta11
Dobrá, už jsem jí odinstaloval a instaluji aviru free antivirus

Re: Přetížení CPU

Napsal: 21 led 2014 23:49
od vyosek
:arrow: Tak si tam hlavne zas nenaistalujte i ten doplnek Ask.com. Pote dejte log z SC

:arrow: Stahnete SecurityCheck http://screen317.spywareinfoforum.org/SecurityCheck.exe
  • Ulozte nejlepe na Plochu
  • Spustte tradicne dvouklikem a postupujte dle pokynu utility
  • Po dokonceni skenu se vytvori a otevre log, ten mi sem vlozte

Re: Přetížení CPU

Napsal: 21 led 2014 23:57
od pauleta11
Results of screen317's Security Check version 0.99.79
Windows Vista Service Pack 2 x64 (UAC is enabled)
Internet Explorer 9
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
Java(TM) 6 Update 24
Java 7 Update 45
Java(TM) 6 Update 7
Java version out of Date!
Adobe Flash Player 11.9.900.170
Adobe Reader 10.1.9 Adobe Reader out of Date!
Google Chrome 32.0.1700.76
````````Process Check: objlist.exe by Laurent````````
Windows Defender MSASCui.exe
pavel Desktop avira_oe_client_antivirus_en (1).exe
Windows Defender MSASCui.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: %
````````````````````End of Log``````````````````````

Re: Přetížení CPU

Napsal: 22 led 2014 00:00
od vyosek
:arrow: Avira uspesne nainstalovana??

:arrow: Pripadne udelejte restart a dejte mi novy log z FRST

Re: Přetížení CPU

Napsal: 22 led 2014 00:20
od pauleta11
už je nainstalovaný, ale při stahování i spuštění launcheru byl vypnutý



Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-01-2014
Ran by pavel (administrator) on PAVEL-PC on 22-01-2014 00:18:13
Running from C:\Users\pavel\Desktop
Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: Czech
Internet Explorer Version 9
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_8aadd48d\stacsv64.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(Microsoft Corporation) C:\Windows\System32\lpremove.exe
(Microsoft Corporation) C:\Windows\System32\lpksetup.exe
(forum.viry.cz) C:\Users\pavel\Desktop\FRSTLauncher.exe
(Adobe Systems Incorporated) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1560872 2008-07-24] (Synaptics, Inc.)
HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1584184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [441856 2008-10-26] (IDT, Inc.)
HKLM-x32\...\Run: [Avira Systray] - C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [174648 2013-12-16] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-09] (Avira Operations GmbH & Co. KG)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.cz/
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [50176] (Společnost Microsoft)
Winsock: Catalog5-x64 02 %SystemRoot%\system32\napinsp.dll [62976] (Společnost Microsoft)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.254

FireFox:
========
FF ProfilePath: C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @lastpass.com/NPLastPass - C:\Program Files (x86)\LastPass\nplastpass64.dll (LastPass)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll (Adobe Systems, Inc.)
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @graphisoft.com/GDL Web Plug-in - C:\Program Files (x86)\GRAPHISOFT\GDLWebControl\npGDLMozilla.dll ()
FF Plugin-x32: @java.com/DTPlugin - C:\Program Files (x86)\Java\jre6\bin\npDeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @lastpass.com/NPLastPass - C:\Program Files (x86)\LastPass\nplastpass.dll (LastPass)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\pavel\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\pavel\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\pavel\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\pavel\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\pavel\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\pavel\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\pavel\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\pavel\AppData\Roaming\mozilla\plugins\npgtpo3dautoplugin.dll ()
FF Plugin ProgramFiles/Appdata: C:\Users\pavel\AppData\Roaming\mozilla\plugins\npo1d.dll (Google)
FF SearchPlugin: C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\searchplugins\searchplugins-backup
FF Extension: DownloadHelper - C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2011-12-17]
FF Extension: Greasemonkey - C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781} [2011-12-17]
FF Extension: Office Black - C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\Extensions\Office2007Black@JBBS.xpi [2011-03-23]
FF Extension: BlackFox V1-Blue - C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\Extensions\zigboom.designs@gmail.com.xpi [2011-03-23]
FF Extension: ImTranslator - C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\Extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi [2011-03-23]
FF Extension: Green Fox - C:\Users\pavel\AppData\Roaming\Mozilla\Firefox\Profiles\5pcc7lpo.default\Extensions\{d122ad80-ff45-11dd-87af-0800200c9a66}.xpi [2011-03-23]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} [2011-04-22]
FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012-12-15]

Chrome:
=======
CHR HomePage:
CHR Extension: (Dokumenty Google) - C:\Users\pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-21]
CHR Extension: (Disk Google) - C:\Users\pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-21]
CHR Extension: (YouTube) - C:\Users\pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-21]
CHR Extension: (Vyhled\u00E1v\u00E1n\u00ED Google) - C:\Users\pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-21]
CHR Extension: (AdBlock) - C:\Users\pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-01-21]
CHR Extension: (LastPass) - C:\Users\pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2014-01-21]
CHR Extension: (Pen\u011B\u017Eenka Google) - C:\Users\pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-21]
CHR Extension: (Gmail) - C:\Users\pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-21]
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-12-12]

==================== Services (Whitelisted) =================

S4 ABBYY.Licensing.PDFTransformer.Classic.3.0; C:\Program Files (x86)\ABBYY PDF Transformer 3.0\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
S4 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_8aadd48d\AESTSr64.exe [89088 2008-06-27] (Andrea Electronics Corporation)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-12-09] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-12-09] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1011768 2013-12-09] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [103480 2013-12-16] (Avira Operations GmbH & Co. KG)
S4 Connectify; C:\Program Files (x86)\Connectify\ConnectifyService.exe [65536 2012-11-09] ()
S4 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] ()
S4 Recovery Service for Windows; C:\Program Files (x86)\SMINST\BLService.exe [365952 2008-12-17] ()
R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_8aadd48d\STacSV64.exe [279040 2008-10-26] (IDT, Inc.)
S4 TVCapSvc; C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe [296320 2008-11-26] ()
S4 TVSched; C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe [116096 2008-11-26] ()
S2 Norton Internet Security; "C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe" /s "Norton Internet Security" /m "C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\diMaster.dll" /prefetch:1

==================== Drivers (Whitelisted) ====================

S3 AVerAF15; C:\Windows\System32\Drivers\AVerAF15.sys [306688 2008-07-04] (AVerMedia TECHNOLOGIES, Inc.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-09] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-09] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-12-09] (Avira Operations GmbH & Co. KG)
S3 cnnctfy2; C:\Windows\System32\DRIVERS\cnnctfy2.sys [35440 2013-09-30] (Connectify)
R3 cnnctfy2MP; C:\Windows\System32\DRIVERS\cnnctfy2.sys [35440 2013-09-30] (Connectify)
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [275432 2009-04-11] (Společnost Microsoft)
R3 Ntfs; C:\Windows\System32\Drivers\Ntfs.sys [1513320 2013-03-03] (Společnost Microsoft)
S2 Sentinel64; C:\Windows\System32\Drivers\Sentinel64.sys [145448 2009-09-17] (SafeNet, Inc.)
S3 avfwim; system32\DRIVERS\avfwim.sys [x]
U2 ezSharedSvc;
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 JMCR; system32\DRIVERS\jmcr.sys [x]
S3 NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\ENG64.SYS [x]
S3 NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\EX64.SYS [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [x]
S1 SRTSP; \??\C:\Windows\system32\drivers\NISx64\1000000.07D\SRTSP64.SYS [x]
S1 SRTSPX; \??\C:\Windows\system32\drivers\NISx64\1000000.07D\SRTSPX64.SYS [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-01-22 00:18 - 2014-01-22 00:18 - 00016036 _____ C:\Users\pavel\Desktop\FRST.txt
2014-01-22 00:17 - 2014-01-22 00:17 - 00112640 _____ (forum.viry.cz) C:\Users\pavel\Desktop\FRSTLauncher.exe
2014-01-22 00:15 - 2014-01-22 00:15 - 00000000 ____D C:\Users\pavel\AppData\Roaming\Avira
2014-01-22 00:09 - 2013-12-09 11:37 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-01-22 00:09 - 2013-12-09 11:37 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-01-22 00:09 - 2013-12-09 11:37 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2014-01-22 00:01 - 2014-01-22 00:01 - 00000526 _____ C:\Windows\PFRO.log
2014-01-21 23:39 - 2014-01-21 23:39 - 00001040 _____ C:\Users\Public\Desktop\Avira.lnk
2014-01-21 23:38 - 2014-01-21 23:38 - 00000000 ____D C:\ProgramData\Package Cache
2014-01-21 22:56 - 2014-01-21 23:23 - 00000000 ____D C:\FRST
2014-01-21 22:33 - 2014-01-21 22:32 - 02077184 _____ (Farbar) C:\Users\pavel\Desktop\FRST64.exe
2014-01-21 21:18 - 2014-01-21 21:18 - 00001156 _____ C:\Users\Public\Desktop\My LastPass Vault.lnk
2014-01-21 20:52 - 2014-01-21 21:20 - 00000000 ____D C:\Program Files (x86)\LastPass
2014-01-21 20:52 - 2014-01-21 21:18 - 00000000 ____D C:\Users\pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass
2014-01-21 20:22 - 2014-01-21 20:25 - 00000000 ____D C:\AdwCleaner
2014-01-21 17:16 - 2014-01-21 17:16 - 00000000 ____D C:\Windows\ERUNT
2014-01-21 16:45 - 2014-01-21 16:45 - 00002025 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2014-01-21 16:42 - 2014-01-21 16:52 - 49940480 _____ C:\Program Files (x86)\GUT6430.tmp
2014-01-21 16:42 - 2014-01-21 16:42 - 00000000 ____D C:\Program Files (x86)\GUM6410.tmp
2014-01-21 16:37 - 2014-01-21 21:53 - 00000000 ____D C:\Users\pavel\AppData\Roaming\Google Chrome Backup
2014-01-21 16:36 - 2014-01-21 16:36 - 00000000 ____D C:\Program Files (x86)\Google Chrome Backup
2014-01-21 15:40 - 2014-01-21 15:45 - 00004245 _____ C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log
2014-01-21 14:58 - 2014-01-21 14:58 - 00003034 _____ C:\Windows\System32\Tasks\{C7AA77F6-B8D8-4978-9036-96056C70D212}
2014-01-21 14:57 - 2014-01-21 14:57 - 00000000 ____D C:\Intel
2014-01-21 12:42 - 2014-01-21 13:47 - 523547951 _____ C:\Users\pavel\Downloads\DALLAS-BUYERS-CLUB-KLUB-POSLEDNÍ-NADĚJE-CZ-TITULKY-DVDScr-2013-MIGON14.mkv
2014-01-01 21:10 - 2014-01-01 21:12 - 00000000 ____D C:\Users\pavel\AppData\Local\cache
2014-01-01 21:10 - 2014-01-01 21:10 - 00000000 ____D C:\Users\pavel\.android
2014-01-01 21:10 - 2014-01-01 21:10 - 00000000 _____ C:\Users\pavel\daemonprocess.txt
2013-12-29 11:18 - 2013-12-29 11:18 - 00000000 ____D C:\Users\pavel\AppData\Local\VNT
2013-12-29 11:17 - 2013-12-29 11:17 - 00000000 ____D C:\Program Files (x86)\VNT
2013-12-29 11:15 - 2014-01-22 00:09 - 00000000 ____D C:\Program Files (x86)\Avira
2013-12-29 10:45 - 2013-12-29 10:57 - 140347096 _____ C:\Users\pavel\Downloads\avira_internet_security_suite_en.exe
2013-12-28 13:20 - 2013-12-28 13:20 - 00000512 _____ C:\Users\pavel\Downloads\Avira_14_9_2015.key
2013-12-26 15:03 - 2013-12-26 15:58 - 912747418 _____ C:\Users\pavel\Downloads\Cesta-(-2009-).avi

==================== One Month Modified Files and Folders =======

2014-01-22 00:18 - 2014-01-22 00:18 - 00016036 _____ C:\Users\pavel\Desktop\FRST.txt
2014-01-22 00:18 - 2013-02-24 19:49 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-22 00:17 - 2014-01-22 00:17 - 00112640 _____ (forum.viry.cz) C:\Users\pavel\Desktop\FRSTLauncher.exe
2014-01-22 00:15 - 2014-01-22 00:15 - 00000000 ____D C:\Users\pavel\AppData\Roaming\Avira
2014-01-22 00:09 - 2013-12-29 11:15 - 00000000 ____D C:\Program Files (x86)\Avira
2014-01-22 00:09 - 2012-11-20 10:20 - 00000000 ____D C:\ProgramData\Avira
2014-01-22 00:08 - 2011-03-22 23:07 - 01253635 _____ C:\Windows\WindowsUpdate.log
2014-01-22 00:02 - 2011-09-05 14:53 - 00000946 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-22 00:02 - 2006-11-02 16:42 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-22 00:02 - 2006-11-02 16:22 - 00003344 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-22 00:02 - 2006-11-02 16:22 - 00003344 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-22 00:01 - 2014-01-22 00:01 - 00000526 _____ C:\Windows\PFRO.log
2014-01-22 00:01 - 2011-03-22 23:06 - 00006323 _____ C:\Windows\bthservsdp.dat
2014-01-22 00:01 - 2006-11-02 16:42 - 00032556 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2014-01-21 23:57 - 2011-09-05 14:53 - 00000950 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-21 23:40 - 2011-10-18 16:30 - 00000982 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4165329744-351483473-3812913338-1000UA.job
2014-01-21 23:39 - 2014-01-21 23:39 - 00001040 _____ C:\Users\Public\Desktop\Avira.lnk
2014-01-21 23:38 - 2014-01-21 23:38 - 00000000 ____D C:\ProgramData\Package Cache
2014-01-21 23:23 - 2014-01-21 22:56 - 00000000 ____D C:\FRST
2014-01-21 23:19 - 2012-02-27 23:39 - 00000962 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4165329744-351483473-3812913338-1000UA.job
2014-01-21 22:32 - 2014-01-21 22:33 - 02077184 _____ (Farbar) C:\Users\pavel\Desktop\FRST64.exe
2014-01-21 22:29 - 2011-03-23 06:32 - 00000000 ____D C:\Users\pavel
2014-01-21 22:02 - 2013-10-10 17:21 - 00000000 ____D C:\Program Files\CCleaner
2014-01-21 22:02 - 2012-09-12 11:34 - 00000000 ____D C:\Users\pavel\AppData\Local\CrashDumps
2014-01-21 22:02 - 2012-08-08 16:00 - 00000000 ____D C:\Windows\Minidump
2014-01-21 21:53 - 2014-01-21 16:37 - 00000000 ____D C:\Users\pavel\AppData\Roaming\Google Chrome Backup
2014-01-21 21:20 - 2014-01-21 20:52 - 00000000 ____D C:\Program Files (x86)\LastPass
2014-01-21 21:18 - 2014-01-21 21:18 - 00001156 _____ C:\Users\Public\Desktop\My LastPass Vault.lnk
2014-01-21 21:18 - 2014-01-21 20:52 - 00000000 ____D C:\Users\pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass
2014-01-21 20:26 - 2011-03-23 18:58 - 00000000 ____D C:\ProgramData\ICQ
2014-01-21 20:25 - 2014-01-21 20:22 - 00000000 ____D C:\AdwCleaner
2014-01-21 17:40 - 2006-11-02 16:21 - 00405264 _____ C:\Windows\system32\FNTCACHE.DAT
2014-01-21 17:16 - 2014-01-21 17:16 - 00000000 ____D C:\Windows\ERUNT
2014-01-21 16:52 - 2014-01-21 16:42 - 49940480 _____ C:\Program Files (x86)\GUT6430.tmp
2014-01-21 16:45 - 2014-01-21 16:45 - 00002025 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2014-01-21 16:44 - 2011-09-05 14:52 - 00000000 ____D C:\Program Files (x86)\Google
2014-01-21 16:43 - 2011-03-23 18:50 - 00111616 _____ C:\Users\pavel\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-01-21 16:42 - 2014-01-21 16:42 - 00000000 ____D C:\Program Files (x86)\GUM6410.tmp
2014-01-21 16:36 - 2014-01-21 16:36 - 00000000 ____D C:\Program Files (x86)\Google Chrome Backup
2014-01-21 15:45 - 2014-01-21 15:40 - 00004245 _____ C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log
2014-01-21 15:43 - 2009-02-23 08:53 - 00000000 ____D C:\Program Files (x86)\Java
2014-01-21 14:58 - 2014-01-21 14:58 - 00003034 _____ C:\Windows\System32\Tasks\{C7AA77F6-B8D8-4978-9036-96056C70D212}
2014-01-21 14:57 - 2014-01-21 14:57 - 00000000 ____D C:\Intel
2014-01-21 14:57 - 2013-09-23 15:03 - 00000000 ____D C:\swsetup
2014-01-21 14:44 - 2012-01-20 12:52 - 00000000 ____D C:\Windows\pss
2014-01-21 14:36 - 2013-09-07 14:55 - 00000000 ___RD C:\Users\pavel\Dropbox
2014-01-21 14:36 - 2013-09-07 12:11 - 00000000 ____D C:\Users\pavel\AppData\Roaming\Dropbox
2014-01-21 13:52 - 2011-09-11 10:15 - 00000000 ____D C:\Users\pavel\Documents\ŠKOLA
2014-01-21 13:51 - 2011-10-04 21:30 - 00000000 ____D C:\Users\pavel\Documents\TISK
2014-01-21 13:48 - 2011-11-23 13:19 - 00000000 ____D C:\Users\pavel\Desktop\DOWNLOAD
2014-01-21 13:47 - 2014-01-21 12:42 - 523547951 _____ C:\Users\pavel\Downloads\DALLAS-BUYERS-CLUB-KLUB-POSLEDNÍ-NADĚJE-CZ-TITULKY-DVDScr-2013-MIGON14.mkv
2014-01-21 13:46 - 2013-12-12 19:26 - 00000000 ____D C:\Users\pavel\Downloads\Peťko jede bomby!
2014-01-20 12:44 - 2009-02-23 15:22 - 02624550 _____ C:\Windows\system32\perfh005.dat
2014-01-20 12:44 - 2009-02-23 15:22 - 00848584 _____ C:\Windows\system32\perfc005.dat
2014-01-20 12:44 - 2006-11-02 13:46 - 00006622 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-20 11:40 - 2011-10-18 16:30 - 00000960 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4165329744-351483473-3812913338-1000Core.job
2014-01-18 20:32 - 2013-09-07 14:55 - 00000919 _____ C:\Users\pavel\Desktop\Dropbox.lnk
2014-01-18 20:32 - 2013-09-07 13:57 - 00000000 ____D C:\Users\pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-01-17 10:22 - 2011-03-23 18:55 - 00000000 ____D C:\Users\pavel\AppData\Roaming\Mozilla
2014-01-16 13:28 - 2012-02-27 23:39 - 00000910 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4165329744-351483473-3812913338-1000Core.job
2014-01-16 00:48 - 2011-03-23 19:39 - 00000000 ____D C:\ProgramData\Microsoft Help
2014-01-16 00:47 - 2013-07-30 13:57 - 00000000 ____D C:\Windows\system32\MRT
2014-01-16 00:44 - 2006-11-02 13:35 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-01-15 20:21 - 2011-03-23 19:53 - 00000000 ____D C:\Users\pavel\AppData\Roaming\vlc
2014-01-12 23:55 - 2011-03-23 18:57 - 00000000 ____D C:\Users\pavel\AppData\Roaming\ICQ
2014-01-07 11:34 - 2011-03-23 20:36 - 00000000 ____D C:\Users\pavel\Graphisoft
2014-01-01 21:12 - 2014-01-01 21:10 - 00000000 ____D C:\Users\pavel\AppData\Local\cache
2014-01-01 21:11 - 2012-12-30 21:01 - 00000874 _____ C:\Users\pavel\Desktop\KMPlayer.lnk
2014-01-01 21:10 - 2014-01-01 21:10 - 00000000 ____D C:\Users\pavel\.android
2014-01-01 21:10 - 2014-01-01 21:10 - 00000000 _____ C:\Users\pavel\daemonprocess.txt
2013-12-29 11:18 - 2013-12-29 11:18 - 00000000 ____D C:\Users\pavel\AppData\Local\VNT
2013-12-29 11:17 - 2013-12-29 11:17 - 00000000 ____D C:\Program Files (x86)\VNT
2013-12-29 10:57 - 2013-12-29 10:45 - 140347096 _____ C:\Users\pavel\Downloads\avira_internet_security_suite_en.exe
2013-12-28 13:20 - 2013-12-28 13:20 - 00000512 _____ C:\Users\pavel\Downloads\Avira_14_9_2015.key
2013-12-26 15:58 - 2013-12-26 15:03 - 912747418 _____ C:\Users\pavel\Downloads\Cesta-(-2009-).avi
2013-12-23 21:06 - 2011-03-23 19:53 - 00000000 ____D C:\Users\pavel\AppData\Roaming\dvdcss

Some content of TEMP:
====================
C:\Users\pavel\AppData\Local\Temp\avgnt.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-01-22 00:10




===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================

Drive c: () (Fixed) (Total:287.97 GB) (Free:66.42 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (RECOVERY) (Fixed) (Total:10.11 GB) (Free:1.73 GB) NTFS ==>[System with boot components (obtained from reading drive)]

Available physical RAM: 1360.18 MB
Total physical RAM: 3068.36 MB
Percentage of memory in use: 55%

==================== MBR and Partition Table ==================

Disk: 0 (Size: 298 GB) (Disk ID: 3B8D3C22)
Partition 1: (Active) - (Size=288 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=10 GB) - (Type=07 NTFS)

==================== Scheduled Tasks (whitelisted) ==================

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4165329744-351483473-3812913338-1000Core.job => C:\Users\pavel\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4165329744-351483473-3812913338-1000UA.job => C:\Users\pavel\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4165329744-351483473-3812913338-1000Core.job => C:\Users\pavel\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4165329744-351483473-3812913338-1000UA.job => C:\Users\pavel\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Alternate Data Streams (whitelisted) ==================

AlternateDataStreams: C:\Program Files (x86)\Vectir:{7A004600-3600-4100-3800-520058003400}

==================== Security Center ==================

AV: Avira Desktop (Disabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Disabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\pavel\Desktop" je 19364 MB.


***** Startup Programs *****

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon
"C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer for HP TouchSmart
"C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe" [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Connectify
C:\Program Files (x86)\Connectify\Connectify.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DpAgent
C:\Program Files (x86)\DigitalPersona\Bin\dpagent.exe [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler
c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl.exe
"C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /Start [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ROC_roc_ssl_v12
"C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12 [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartMenu
%ProgramFiles%\Hewlett-Packard\HP MediaSmart\SmartMenu.exe [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TSMAgent
"C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe" [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TVAgent
"C:\Program Files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WirelessAssistant
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wondershare Helper Compact.exe
C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTTray.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk
C:\PROGRA~2\HP\DIGITA~1\bin\hpqtra08.exe [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^pavel^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk
C:\Users\pavel\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [x]


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
DoNotAllowExceptions REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x0
DisableNotifications REG_DWORD 0x0
DoNotAllowExceptions REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000001


==================== End Of Log ==============================