Zasekaný a pomalý počítač

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Odpovědět
Zpráva
Autor
Krokoman
Návštěvník
Návštěvník
Příspěvky: 19
Registrován: 05 Dub 2012 13:27

Zasekaný a pomalý počítač

#1 Příspěvek od Krokoman »

Zdravím, prosím o kontrolu logu. Mám nějaký zasekaný a pomalý počítač. Předem děkuji.


Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-02-2014 01
Ran by Kroky (administrator) on BEZEBUB on 12-02-2014 11:56:44
Running from C:\Users\Kroky\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
() C:\Program Files (x86)\ASUS\PCI-N10 WLAN Card Utilities\Common\ASUSService.exe
() C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\ASUS\PCI-N10 WLAN Card Utilities\Common\RaRegistry.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\ASUS\PCI-N10 WLAN Card Utilities\Common\RaRegistry64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
(Sony) C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe
(Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe
() C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe
(Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
(Nokia) C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\PCI-N10 WLAN Card Utilities\Common\RaUI.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclUSBSrv64.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
(Google Inc.) C:\Users\Kroky\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Kroky\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Kroky\AppData\Local\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Kroky\Desktop\FRSTLauncher.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7981088 2009-07-20] (Realtek Semiconductor)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-08-13] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35696 2009-10-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [935288 2009-09-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4241512 2012-03-07] (AVAST Software)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [NokiaMServer] - C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles
HKLM-x32\...\Run: [Nokia FastStart] - C:\Program Files (x86)\Nokia\Nokia Music\NokiaMusic.exe [2376992 2009-02-26] (Nokia)
HKLM-x32\...\Run: [NSU_agent] - C:\Program Files (x86)\Nokia\Nokia Software Updater\nsu3ui_agent.exe [190768 2012-02-28] ()
HKU\S-1-5-21-2823639791-3167687777-3475818333-1001\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [369200 2009-10-30] (DT Soft Ltd)
HKU\S-1-5-21-2823639791-3167687777-3475818333-1001\...\Run: [Sony PC Companion] - C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [449760 2013-10-31] (Sony)
HKU\S-1-5-21-2823639791-3167687777-3475818333-1001\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] - C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [149040 2007-03-12] (Nero AG)
HKU\S-1-5-21-2823639791-3167687777-3475818333-1001\...\Run: [Steam] - C:\Program Files (x86)\Steam\steam.exe [1824000 2014-02-11] (Valve Corporation)
HKU\S-1-5-21-2823639791-3167687777-3475818333-1001\...\Run: [Infium] - "C:\Program Files (x86)\QIP 2012\qip.exe" /autorun
HKU\S-1-5-21-2823639791-3167687777-3475818333-1001\...\Run: [Google Update] - C:\Users\Kroky\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-11-27] (Google Inc.)
HKU\S-1-5-21-2823639791-3167687777-3475818333-1001\...\Run: [CPN Notifier] - C:\Program Files (x86)\CardCasino\PokerNotifier.exe
HKU\S-1-5-21-2823639791-3167687777-3475818333-1001\...\MountPoints2: {4df89ed2-6fa0-11e2-b795-406186370292} - H:\Startme.exe
HKU\S-1-5-21-2823639791-3167687777-3475818333-1001\...\MountPoints2: {9234d926-861c-11e1-95a0-406186370292} - G:\autorun.exe
HKU\S-1-5-21-2823639791-3167687777-3475818333-1001\...\MountPoints2: {b5d8293b-ccf7-11e1-b930-406186370292} - E:\Startme.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages =
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search = http://search.icq.com/search/results.ph ... &ch_id=osd
SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = http://search.icq.com/search/results.ph ... &ch_id=osd
SearchScopes: HKCU - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} URL = http://search.qip.ru/search?query={searchTerms}&from=IE
SearchScopes: HKCU - {F9C4363D-9557-4FA9-BDA2-76612FB2D520} URL = http://websearch.ask.com/redirect?clien ... 0C06842A2B
BHO: avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO-x32: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: KMP Media Toolbar - {daf5b34c-1aa3-4c33-ae24-766a370635d2} - C:\Program Files (x86)\kmpmediatoolbar\searchresultsDx.dll (Ask.com)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Yontoo - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll (Yontoo LLC)
Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKLM-x32 - KMP Media Toolbar - {daf5b34c-1aa3-4c33-ae24-766a370635d2} - C:\Program Files (x86)\kmpmediatoolbar\searchresultsDx.dll (Ask.com)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF ProfilePath: C:\Users\Kroky\AppData\Roaming\Mozilla\Firefox\Profiles\vt9s8jg7.default
FF user.js: detected! => C:\Users\Kroky\AppData\Roaming\Mozilla\Firefox\Profiles\vt9s8jg7.default\user.js
FF DefaultSearchEngine: Ask.com
FF SearchEngineOrder.1: Ask.com
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.seznam.cz/
FF Keyword.URL: hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.5.1&q=
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @live.heroesandgenerals.com/npretox - C:\Program Files (x86)\Heroes & Generals\live\npretoxlive.dll (Reto-Moto ApS)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @playstation.com/PsndlCheck,version=1.00 - C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.)
FF Plugin-x32: @SonyCreativeSoftware.com/Media Go,version=1.0 - C:\Program Files (x86)\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Kroky\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Kroky\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Kroky\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFFICE.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Kroky\AppData\Roaming\Mozilla\Firefox\Profiles\vt9s8jg7.default\searchplugins\askcom.xml
FF SearchPlugin: C:\Users\Kroky\AppData\Roaming\Mozilla\Firefox\Profiles\vt9s8jg7.default\searchplugins\icqplugin-1.xml
FF SearchPlugin: C:\Users\Kroky\AppData\Roaming\Mozilla\Firefox\Profiles\vt9s8jg7.default\searchplugins\icqplugin-2.xml
FF SearchPlugin: C:\Users\Kroky\AppData\Roaming\Mozilla\Firefox\Profiles\vt9s8jg7.default\searchplugins\icqplugin.xml
FF SearchPlugin: C:\Users\Kroky\AppData\Roaming\Mozilla\Firefox\Profiles\vt9s8jg7.default\searchplugins\qip-search.xml
FF SearchPlugin: C:\Users\Kroky\AppData\Roaming\Mozilla\Firefox\Profiles\vt9s8jg7.default\searchplugins\searchplugins-backup
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\mall-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\slunecnice-cz.xml
FF Extension: ICQ Toolbar - C:\Users\Kroky\AppData\Roaming\Mozilla\Firefox\Profiles\vt9s8jg7.default\Extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2012-10-17]
FF Extension: KMP Media Toolbar - C:\Users\Kroky\AppData\Roaming\Mozilla\Firefox\Profiles\vt9s8jg7.default\Extensions\{daf5b34c-1aa3-4c33-ae24-766a370635d2} [2012-06-17]
FF Extension: OneClickDownloader - C:\Users\Kroky\AppData\Roaming\Mozilla\Firefox\Profiles\vt9s8jg7.default\Extensions\OneClickDownload@OneClickDownload.com.xpi [2013-02-11]
FF Extension: Yontoo - C:\Users\Kroky\AppData\Roaming\Mozilla\Firefox\Profiles\vt9s8jg7.default\Extensions\plugin@yontoo.com.xpi [2013-02-28]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! WebRep - C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-04-13]

Chrome:
=======
CHR HomePage: hxxp://www.seznam.cz/
CHR Plugin: (Shockwave Flash) - C:\Users\Kroky\AppData\Local\Google\Chrome\Application\32.0.1700.107\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Kroky\AppData\Local\Google\Chrome\Application\32.0.1700.107\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Kroky\AppData\Local\Google\Chrome\Application\32.0.1700.107\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.310.5) - C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll (Sun Microsystems, Inc.)
CHR Plugin: (Microsoft Office 2003) - C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFFICE.DLL (Microsoft Corporation)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Uplay PC) - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
CHR Extension: (Disk Google) - C:\Users\Kroky\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2012-11-27]
CHR Extension: (YouTube) - C:\Users\Kroky\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-11-27]
CHR Extension: (Vyhledávání Google) - C:\Users\Kroky\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-11-27]
CHR Extension: (avast! WebRep) - C:\Users\Kroky\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda [2012-11-28]
CHR Extension: (Peněženka Google) - C:\Users\Kroky\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-01]
CHR Extension: (Gmail) - C:\Users\Kroky\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-11-27]
CHR Extension: (OneClickDownload) - C:\Users\Kroky\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmlghpafmmnmmkjdhacccolfgnkiboco [2012-11-27]
CHR HKLM-x32\...\Chrome\Extension: [icmlaeflemplmjndnaapfdbbnpncnbda] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2012-04-13]
CHR HKLM-x32\...\Chrome\Extension: [niapdbllcanepiiimjjndipklodoedlc] - C:\Users\Kroky\AppData\Local\Temp\YontooLayers.crx [2012-07-28]
CHR HKLM-x32\...\Chrome\Extension: [pmlghpafmmnmmkjdhacccolfgnkiboco] - C:\Program Files (x86)\1ClickDownload\oneclickdownloader10.crx [2012-06-05]

==================== Services (Whitelisted) =================

R2 ASUSWireless; C:\Program Files (x86)\ASUS\PCI-N10 WLAN Card Utilities\Common\ASUSService.exe [184320 2011-12-29] ()
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [44768 2012-03-07] (AVAST Software)
R2 DokanMounter; C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe [14848 2011-01-10] ()
R3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [271920 2007-03-12] (Nero AG)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-09-16] ()
R2 RalinkRegistryWriter; C:\Program Files (x86)\ASUS\PCI-N10 WLAN Card Utilities\Common\RaRegistry.exe [374112 2011-12-29] (Ralink Technology, Corp.)
R2 RalinkRegistryWriter64; C:\Program Files (x86)\ASUS\PCI-N10 WLAN Card Utilities\Common\RaRegistry64.exe [451936 2011-12-29] (Ralink Technology, Corp.)

==================== Drivers (Whitelisted) ====================

R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [24408 2012-03-07] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [69976 2012-03-07] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [53080 2012-03-07] (AVAST Software)
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [819032 2012-03-07] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [337240 2012-03-07] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [59224 2012-03-07] (AVAST Software)
S3 ATICDSDr; C:\Users\Kroky\AppData\Local\Temp\ATICDSDr.sys [6656 2009-08-14] (ATI Technologies Inc.)
S2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [303616 2012-11-27] ()
R2 Dokan; C:\Windows\system32\drivers\dokan.sys [120408 2011-01-10] (Windows (R) Win 7 DDK provider)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [42696 2012-10-09] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2012-04-13] ()
U3 appo0oon; C:\Windows\System32\Drivers\appo0oon.sys [0 ] (Microsoft Corporation)
S3 cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x64.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-02-12 11:56 - 2014-02-12 11:56 - 00019505 _____ () C:\Users\Kroky\Desktop\FRST.txt
2014-02-12 11:56 - 2014-02-12 11:56 - 00000000 ____D () C:\FRST
2014-02-12 11:55 - 2014-02-12 11:55 - 00112640 _____ (forum.viry.cz) C:\Users\Kroky\Desktop\FRSTLauncher.exe
2014-02-12 11:54 - 2014-02-12 11:54 - 00112640 _____ (forum.viry.cz) C:\Users\Kroky\Downloads\Nepotvrzeno 438187.crdownload
2014-02-12 11:50 - 2014-02-12 11:51 - 02151424 _____ (Farbar) C:\Users\Kroky\Desktop\FRST64.exe
2014-02-06 11:03 - 2014-02-06 11:05 - 356017860 _____ () C:\Users\Kroky\Downloads\Priya Rai - Milfs Like it Big - Palmistry Penis.wmv
2014-02-04 17:47 - 2014-02-04 17:47 - 00002231 _____ () C:\Users\Public\Desktop\Fable - The Lost Chapters.lnk
2014-02-04 17:43 - 2014-02-04 17:43 - 00000000 ____D () C:\Program Files (x86)\Microsoft Games
2014-02-04 17:36 - 2014-02-04 17:38 - 00000000 ____D () C:\Users\Kroky\Desktop\fable
2014-02-04 17:36 - 2014-02-04 17:36 - 178342290 _____ () C:\Users\Kroky\Downloads\Milf Diamond Foxxx is Horny.avi
2014-02-04 17:33 - 2014-02-04 17:35 - 423797602 _____ () C:\Users\Kroky\Downloads\fable.part3.rar
2014-02-04 17:29 - 2014-02-04 17:33 - 996147200 _____ () C:\Users\Kroky\Downloads\fable.part2.rar
2014-02-04 17:23 - 2014-02-04 17:27 - 996147200 _____ () C:\Users\Kroky\Downloads\fable.part1.rar
2014-01-30 16:19 - 2014-01-30 16:19 - 00001082 _____ () C:\Users\Public\Desktop\NecroVisioN DX10.lnk
2014-01-30 16:19 - 2014-01-30 16:19 - 00001070 _____ () C:\Users\Public\Desktop\NecroVisioN.lnk
2014-01-30 16:19 - 2014-01-30 16:19 - 00000000 ____D () C:\Program Files (x86)\1C Publishing
2014-01-27 16:56 - 2014-01-27 16:56 - 15535168 _____ () C:\Users\Kroky\Downloads\Fable - The Lost Chapters cz.rar
2014-01-20 20:47 - 2014-01-27 17:05 - 00000000 ____D () C:\Program Files (x86)\Football Manager 2014
2014-01-15 11:45 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-01-15 11:45 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-01-15 11:45 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-01-15 11:45 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-01-15 11:45 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-01-15 11:45 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-01-15 11:45 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-01-15 11:45 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-01-15 11:45 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys

==================== One Month Modified Files and Folders =======

2014-02-12 11:56 - 2014-02-12 11:56 - 00019505 _____ () C:\Users\Kroky\Desktop\FRST.txt
2014-02-12 11:56 - 2014-02-12 11:56 - 00000000 ____D () C:\FRST
2014-02-12 11:55 - 2014-02-12 11:55 - 00112640 _____ (forum.viry.cz) C:\Users\Kroky\Desktop\FRSTLauncher.exe
2014-02-12 11:55 - 2012-04-13 16:35 - 00000000 ____D () C:\Users\Kroky\AppData\Roaming\AIMP3
2014-02-12 11:54 - 2014-02-12 11:54 - 00112640 _____ (forum.viry.cz) C:\Users\Kroky\Downloads\Nepotvrzeno 438187.crdownload
2014-02-12 11:51 - 2014-02-12 11:50 - 02151424 _____ (Farbar) C:\Users\Kroky\Desktop\FRST64.exe
2014-02-12 11:41 - 2012-11-27 20:34 - 00000910 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2823639791-3167687777-3475818333-1001Core.job
2014-02-12 11:33 - 2012-11-27 20:34 - 00000962 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2823639791-3167687777-3475818333-1001UA.job
2014-02-12 11:30 - 2012-05-08 14:31 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-12 11:23 - 2012-05-26 11:31 - 00000000 ____D () C:\Users\Kroky\AppData\Local\PokerStars
2014-02-12 11:13 - 2012-11-20 14:36 - 00000950 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-12 11:12 - 2012-04-13 16:01 - 01231455 _____ () C:\Windows\WindowsUpdate.log
2014-02-12 10:18 - 2012-08-22 12:50 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-02-12 10:17 - 2012-11-20 14:36 - 00000946 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-12 10:15 - 2009-07-14 05:45 - 00014832 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-12 10:15 - 2009-07-14 05:45 - 00014832 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-12 10:12 - 2009-07-14 16:18 - 00639440 _____ () C:\Windows\system32\perfh005.dat
2014-02-12 10:12 - 2009-07-14 16:18 - 00125224 _____ () C:\Windows\system32\perfc005.dat
2014-02-12 10:12 - 2009-07-14 06:13 - 01493818 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-12 10:07 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-12 10:07 - 2009-07-14 05:51 - 00077041 _____ () C:\Windows\setupact.log
2014-02-09 13:15 - 2012-05-26 11:31 - 00000000 ____D () C:\Program Files (x86)\PokerStars
2014-02-09 12:30 - 2012-04-15 20:28 - 00000000 ____D () C:\Users\Kroky\Desktop\sharerapid
2014-02-09 12:29 - 2012-04-15 20:29 - 00001152 _____ () C:\Users\Kroky\AppData\Local\SRDownloader.nast
2014-02-06 11:05 - 2014-02-06 11:03 - 356017860 _____ () C:\Users\Kroky\Downloads\Priya Rai - Milfs Like it Big - Palmistry Penis.wmv
2014-02-04 17:54 - 2012-04-14 16:40 - 00000000 ____D () C:\Users\Kroky\Documents\My Games
2014-02-04 17:52 - 2012-04-16 17:24 - 00000000 ____D () C:\Users\Kroky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-02-04 17:48 - 2012-04-13 16:07 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-02-04 17:47 - 2014-02-04 17:47 - 00002231 _____ () C:\Users\Public\Desktop\Fable - The Lost Chapters.lnk
2014-02-04 17:47 - 2012-04-14 16:10 - 00359062 _____ () C:\Windows\DirectX.log
2014-02-04 17:43 - 2014-02-04 17:43 - 00000000 ____D () C:\Program Files (x86)\Microsoft Games
2014-02-04 17:38 - 2014-02-04 17:36 - 00000000 ____D () C:\Users\Kroky\Desktop\fable
2014-02-04 17:36 - 2014-02-04 17:36 - 178342290 _____ () C:\Users\Kroky\Downloads\Milf Diamond Foxxx is Horny.avi
2014-02-04 17:35 - 2014-02-04 17:33 - 423797602 _____ () C:\Users\Kroky\Downloads\fable.part3.rar
2014-02-04 17:33 - 2014-02-04 17:29 - 996147200 _____ () C:\Users\Kroky\Downloads\fable.part2.rar
2014-02-04 17:27 - 2014-02-04 17:23 - 996147200 _____ () C:\Users\Kroky\Downloads\fable.part1.rar
2014-02-03 17:26 - 2012-06-16 08:31 - 00493708 _____ () C:\Windows\DPINST.LOG
2014-01-30 16:19 - 2014-01-30 16:19 - 00001082 _____ () C:\Users\Public\Desktop\NecroVisioN DX10.lnk
2014-01-30 16:19 - 2014-01-30 16:19 - 00001070 _____ () C:\Users\Public\Desktop\NecroVisioN.lnk
2014-01-30 16:19 - 2014-01-30 16:19 - 00000000 ____D () C:\Program Files (x86)\1C Publishing
2014-01-27 17:05 - 2014-01-20 20:47 - 00000000 ____D () C:\Program Files (x86)\Football Manager 2014
2014-01-27 16:56 - 2014-01-27 16:56 - 15535168 _____ () C:\Users\Kroky\Downloads\Fable - The Lost Chapters cz.rar
2014-01-20 20:54 - 2012-11-06 18:52 - 00000000 ____D () C:\Users\Public\Documents\Sports Interactive
2014-01-20 20:54 - 2012-11-06 18:52 - 00000000 ____D () C:\Users\Kroky\Documents\Sports Interactive
2014-01-20 20:54 - 2012-11-06 18:52 - 00000000 ____D () C:\Users\Kroky\AppData\Local\Sports Interactive
2014-01-20 20:16 - 2012-04-18 12:36 - 00017738 _____ () C:\Users\Kroky\AppData\Local\SRDownloader.err
2014-01-20 20:05 - 2013-09-19 06:50 - 00002026 _____ () C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk
2014-01-20 19:59 - 2009-07-14 05:45 - 00303288 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-01-15 12:27 - 2013-08-16 14:43 - 00000000 ____D () C:\Windows\system32\MRT
2014-01-15 12:25 - 2012-10-26 11:57 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-13 11:39 - 2012-11-25 15:13 - 00000000 ____D () C:\Users\Kroky\AppData\Roaming\TS3Client

Some content of TEMP:
====================
C:\Users\Kroky\AppData\Local\Temp\AskSLib.dll
C:\Users\Kroky\AppData\Local\Temp\bwincomPokerSetup.exe
C:\Users\Kroky\AppData\Local\Temp\cardcasinosetup.exe
C:\Users\Kroky\AppData\Local\Temp\CojLauncher.exe
C:\Users\Kroky\AppData\Local\Temp\contentDATs.exe
C:\Users\Kroky\AppData\Local\Temp\FP_PL_PFS_INSTALLER_32bit.exe
C:\Users\Kroky\AppData\Local\Temp\help.exe
C:\Users\Kroky\AppData\Local\Temp\InstallAX.exe
C:\Users\Kroky\AppData\Local\Temp\NEventMessages.dll
C:\Users\Kroky\AppData\Local\Temp\OptChrome.exe
C:\Users\Kroky\AppData\Local\Temp\ptu3A47_tmp.exe
C:\Users\Kroky\AppData\Local\Temp\ptu7BB6_tmp.exe
C:\Users\Kroky\AppData\Local\Temp\ptuF5BE_tmp.exe
C:\Users\Kroky\AppData\Local\Temp\RDtemp.exe
C:\Users\Kroky\AppData\Local\Temp\SecurityScan_Release.exe
C:\Users\Kroky\AppData\Local\Temp\setup.exe
C:\Users\Kroky\AppData\Local\Temp\SIInvoker.exe
C:\Users\Kroky\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Kroky\AppData\Local\Temp\sqlite3.exe
C:\Users\Kroky\AppData\Local\Temp\temp38D6L39WOCV73_updater.exe
C:\Users\Kroky\AppData\Local\Temp\tmp9950.exe
C:\Users\Kroky\AppData\Local\Temp\tmpC627.exe
C:\Users\Kroky\AppData\Local\Temp\YontooIEClient.dll
C:\Users\Kroky\AppData\Local\Temp\YontooSetup-S.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-02-09 14:06




===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================

Drive c: () (Fixed) (Total:465.56 GB) (Free:250.84 GB) NTFS
Drive e: (OneTouch 4) (Fixed) (Total:465.76 GB) (Free:49.21 GB) NTFS

Available physical RAM: 1519.86 MB
Total physical RAM: 3071.24 MB
Percentage of memory in use: 50%

==================== MBR and Partition Table ==================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: F795F2AE)
Partition 1: (Active) - (Size=200 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=466 GB) - (Type=07 NTFS)
Disk: 1 (Size: 466 GB) (Disk ID: 963F5135)
Partition 1: (Active) - (Size=466 GB) - (Type=07 NTFS)

==================== Scheduled Tasks (whitelisted) ==================

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2823639791-3167687777-3475818333-1001Core.job => C:\Users\Kroky\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2823639791-3167687777-3475818333-1001UA.job => C:\Users\Kroky\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Alternate Data Streams (whitelisted) ==================

AlternateDataStreams: C:\Program Files (x86)\CardCasino:MID

==================== Security Center ==================

AV: avast! Antivirus (Disabled - Up to date) {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AS: avast! Antivirus (Disabled - Up to date) {904CF271-6431-DA47-5FCE-A87D98DFB681}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Kroky\Desktop" je 21582 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================

Avatar uživatele
JaRon
Moderátor
Moderátor
Příspěvky: 15924
Registrován: 29 Bře 2005 13:39
Místo/Bydliště: BB-SK

Re: Zasekaný a pomalý počítač

#2 Příspěvek od JaRon »

ahoj,
najprv urob nieco s tymto :!:
Velikost slozky "C:\Users\Kroky\Desktop" je 21582 MB.

potom vycisti PC s ADWCleanerom
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Odpovědět