Dobrý den,
nevím čím to je, ale pokaždé, když PC tak 30 minut jede, tak najednou zamrzne a musím ho vyresetovat. Netuším co může být špatně. provedl jsem scandisc, projel PC avastem v režimu před bootem a také ho projel Spyware Teminátorem - všechno bylo bez nálezů.
Logfile of random's system information tool 1.10 (written by random/random)
Run by jana at 2014-07-27 22:21:25
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 33 GB (7%) free of 461 GB
Total RAM: 3959 MB (61% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:21:28, on 27.7.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17207)
Boot mode: Normal
Running processes:
C:\Windows\PLFSetL.exe
C:\Windows\snuvcdsm.exe
C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\jana.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.buenosearch.com/?babsrc=HP_s ... 3&tsp=5220
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [uTorrent] "C:\Users\jana\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Programy\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Spyware Terminator 2012 Realtime Shield Service (ST2012_Svc) - Crawler.com - C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 7075 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe 4406288
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
\??\C:\Windows\system32\conhost.exe "934327468-18727420858503932591372323524287867837771279415646352373-843493237
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Windows\PLFSetL.exe"
"C:\Windows\snuvcdsm.exe"
"C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe" /ELEVATED
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="1356.0.406379132\240920130" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,16 --gpu-vendor-id=0x1002 --gpu-device-id=0x68e4 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=13.251.0.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_10/UMA-Uniformity-Trial-1-Percent/group_60/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --channel="1356.2.756953065\582188628" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_10/UMA-Uniformity-Trial-1-Percent/group_60/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --channel="1356.3.880097743\1709357442" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_10/UMA-Uniformity-Trial-1-Percent/group_60/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --channel="1356.7.306739978\1036366262" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_10/UMA-Uniformity-Trial-1-Percent/group_60/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --channel="1356.8.9082029\305818250" /prefetch:673131151
taskeng.exe {51C226A9-5444-4149-B763-1625CACB3858}
taskmgr.exe /3
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group9 pct:10i stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_10/UMA-Uniformity-Trial-1-Percent/group_60/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --channel="1356.11.444259334\1704319633" /prefetch:673131151
"C:\Users\jana\Downloads\RSITx64.exe"
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\00e1002c-7029-4aa8-96af-5a4f99b861b7-1.job - C:\Program Files (x86)\Torntv V9.0\Torntv V9.0-codedownloader.exe /KNosn /ceSvSK=task /heUCr='Torntv V9.0' /PpSKBO=51390 /FqNnsylxw='001062' /asCBYCeX='0' /tdZTLM='0' /rYJRMSPK=279CA28CDD8144339541801BC1427F77IE /GjLwxmx=609459b492415d7393136890b6c5a12d /vTpzEx=1_34_3_28 /eUIoWTDb=1.34.3.28 /owweQb=1397748826 /awRUFZ=http://stats.clientdemocloud.com /dGfIRu=http://errors.clientdemocloud.com /XdRbiHzea=http://cr.install-daddy.com /pGPTYifb=ch /teQgT /XDdFXOUod='http://update.clientdemocloud.com/ie_co ... pdate.json' /ceSvSK='task' /TyvjOTY=''
C:\Windows\tasks\00e1002c-7029-4aa8-96af-5a4f99b861b7-3.job - C:\Program Files (x86)\Torntv V9.0\00e1002c-7029-4aa8-96af-5a4f99b861b7-3.exe /zQIQyWFMK=F1rBFGopZQ3GQ7RdAOfpmW2UWvVxFwRRfzTEQ+DrWA4ryDqq5RuCaVaX/Cp9ewkQxm7WP/YyFhGrhGqMkCoAQ/RLZsJHThr/c6GJI4XjNss1KmUypABKVH/tpsguDwd5hK2lY6ZO8Sz209d7rV5KIvUibJun8SdFr7pm9/+i6WpUxef00cM5AYrcuFmeVCE9g3UeN+W77X6zSZS+LWgt1sfzWEVL3fudnx6UW1Ay9Hu/HzLPoSDUj0+pEE/oyjJLledKlGhNMndrqERNA6GoSRM5+XbyCWEyuapZw818mZ/UHPiehfLBZc/uaWryGdTfZDQKBrjDhw4ows3rRcpKeL6rKVWHTid7UPRN6IrP43Qsg9T/NpfO54Hh31uusaNr6Ay4lKKNaJyQxlw2e+XM8SG+GxN7tfEa/m2aRKEiz31NsM/Dem5PkruF3njwLRKQvSlQmOAFUWBpGWivOM40O9DF8hXeR8DkKJuEErY5zSS7TlFKZs4GlQO1fGLyMgyrleY0ED05ZwPf0QZdY/4pALToprGIjYPUyEu7B279xzUlR15GevEshUrBdKwx49XhyhVm6Yearc0KjRxC+W8VRW3Qps92rdQznIqaKWqiIgOzxEHAkfOv+zDd/o9j8/hTjn2zCR+jdofKY1ZY6v9H2rPaf2tz0BnZ6qbZZH1+vo68IENIhyuq0Bv/D8uPy/NJzh/pT4H9EomxekQA7We+uhJiPDrl6uwxdCnlcR9zQ+xGYHLjU+9whTjpKIHUJ+j/e5KtIc41B2Ph52NF0cUaCJ5QCKeY88DYVHKftnF0BJMl68kk7dP/ZfcPhXXMCwTvM57xioYp7ORT6TOAu88ukSgFdiEYo6IMQh3JWmvkdSoV34ieTHogUH9vPIk6J3tnz0giwqi+ryoQRxmI3r5rP+59dHXp5UAOX3zVNr+z8e/0c1gcds6rSKqKDM//T6D0ex0alw0Nw5WxRbKv/Xj0/q4lL5Ecm5PwtILVfqFTPbXg8c7mTeLdDHmY+FhsiMQtFo9UnNPiMK1bDu6202JZFjbkQDpvENMiBPF/UGFTZ8MQvHSQGGGuPXIrOWGcSe7uejngNCfoQE9ydhfRbPZPmUEKLUZpQ5gHHP4whMTsT9KQEs7pnvLRlEj/1+MJzdWWe5IgzRQKRR31aN7ICjSBfT7A8Mg/VSF2Uth7+MrELFA=
C:\Windows\tasks\00e1002c-7029-4aa8-96af-5a4f99b861b7-4.job - C:\Program Files (x86)\Torntv V9.0\00e1002c-7029-4aa8-96af-5a4f99b861b7-4.exe /zbLvJxp /heUCr='Torntv V9.0' /LwCYe='C:\Program Files (x86)\Torntv V9.0\51390.xpi' /PpSKBO=51390 /FqNnsylxw='001062' /asCBYCeX='0' /tdZTLM='0' /rYJRMSPK=279CA28CDD8144339541801BC1427F77IE /GjLwxmx=609459b492415d7393136890b6c5a12d /vTpzEx=1_34_3_28 /eUIoWTDb=1.34.3.28 /owweQb=1397748826 /awRUFZ=http://stats.clientdemocloud.com /dGfIRu=http://errors.clientdemocloud.com /PJmiDDcv=300 /krczaMzH=5a6bf058-b978-4b84-a2ec-6f5462cfccb2@10120365-d3c0-4ec9-8624-5fac2592d0df.com /QENJRXKAQ=0.94 /GVDAy=a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390 /LpxRXSk=https://w9u6a2p6.ssl.hwcdn.net/plugin/f ... /51390.rdf /nNiSqAI='Torntv V9.0' /dLGCLWsIV='The must-have App extensions for Television fans! Watch free TV channels, live sports and more' /lDyVOM='installdaddy' /pGPTYifb=ch /teQgT /zZpAkr /kHGMgPVW /XDdFXOUod='http://update.clientdemocloud.com/ff_ag ... pdate.json' /ceSvSK='task' /TyvjOTY=''
C:\Windows\tasks\00e1002c-7029-4aa8-96af-5a4f99b861b7-5.job - C:\Program Files (x86)\Torntv V9.0\00e1002c-7029-4aa8-96af-5a4f99b861b7-5.exe /GZvOTW /heUCr='Torntv V9.0' /PpSKBO=51390 /FqNnsylxw='001062' /asCBYCeX='0' /tdZTLM='0' /rYJRMSPK=279CA28CDD8144339541801BC1427F77IE /GjLwxmx=609459b492415d7393136890b6c5a12d /vTpzEx=1_34_3_28 /owweQb=1397748826 /awRUFZ=http://stats.clientdemocloud.com /dGfIRu=http://errors.clientdemocloud.com /QXhcmrQ=http://ipgeoapi.com/ /bmVVI=http://update.clientdemocloud.com /dlzwP=2 /UMGJC=http://logs.clientdemocloud.com /XDdFXOUod='http://update.clientdemocloud.com/updat ... pdate.json' /ceSvSK='task' /TyvjOTY=''
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511131190}]
Torntv V9.0 - C:\Program Files (x86)\Torntv V9.0\Torntv V9.0-bho64.dll [2014-04-17 702464]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-07-27 612248]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-07-27 457712]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2013-10-24 13662936]
"PLFSetL"=C:\Windows\PLFSetL.exe [2011-01-13 99712]
"SNUVCDSM"=C:\Windows\snuvcdsm.exe [2011-01-13 30080]
"SpywareTerminatorShield"=C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe [2012-09-07 2777296]
"SpywareTerminatorUpdater"=C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [2014-05-13 3681688]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"=C:\Users\jana\AppData\Roaming\uTorrent\uTorrent.exe [2014-03-18 1853008]
"DAEMON Tools Lite"=C:\Programy\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2013-12-06 766208]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-07-27 4086432]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.ffds"=ff_vfw.dll
"msacm.aacacm"=AACACM.acm
"msacm.ac3acm"=AC3ACM.acm
"msacm.lameacm"=LameACM.acm
"VIDC.LAGS"=lagarith.dll
"VIDC.MLCY"=mlc.dll
"VIDC.ULRA"=C:\Windows\system32\utv_vcm.dll
"VIDC.ULRG"=C:\Windows\system32\utv_vcm.dll
"VIDC.ULY0"=C:\Windows\system32\utv_vcm.dll
"VIDC.ULY2"=C:\Windows\system32\utv_vcm.dll
"VIDC.ULH0"=C:\Windows\system32\utv_vcm.dll
"VIDC.ULH2"=C:\Windows\system32\utv_vcm.dll
"vidc.x264"=C:\PROGRA~1\X264VF~1\X264VF~1.DLL
"vidc.XVID"=xvidvfw.dll
"VIDC.VP80"=vp8vfw.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-07-27 22:16:57 ----D---- C:\rsit
2014-07-27 22:16:57 ----D---- C:\Program Files\trend micro
2014-07-27 21:36:42 ----N---- C:\bootsqm.dat
2014-07-27 12:28:10 ----D---- C:\Users\jana\AppData\Roaming\AVAST Software
2014-07-27 12:23:20 ----A---- C:\Windows\system32\drivers\aswStm.sys
2014-07-27 12:23:19 ----A---- C:\Windows\system32\drivers\aswVmm.sys
2014-07-27 12:23:18 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2014-07-27 12:23:17 ----A---- C:\Windows\system32\drivers\aswsp.sys
2014-07-27 12:23:16 ----A---- C:\Windows\system32\drivers\aswRvrt.sys
2014-07-27 12:23:15 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2014-07-27 12:23:14 ----A---- C:\Windows\system32\drivers\aswHwid.sys
2014-07-27 12:23:13 ----A---- C:\Windows\system32\drivers\aswRdr2.sys
2014-07-27 12:23:10 ----A---- C:\Windows\system32\aswBoot.exe
2014-07-27 12:22:53 ----A---- C:\Windows\avastSS.scr
2014-07-27 12:16:36 ----D---- C:\Program Files\AVAST Software
2014-07-27 11:02:01 ----D---- C:\ProgramData\AVAST Software
2014-07-27 11:01:24 ----A---- C:\Windows\system32\drivers\stflt.sys
2014-07-27 11:01:23 ----D---- C:\Users\jana\AppData\Roaming\Spyware Terminator
2014-07-27 11:01:23 ----D---- C:\ProgramData\Spyware Terminator
2014-07-27 11:01:20 ----D---- C:\Program Files (x86)\Spyware Terminator
2014-07-09 21:28:33 ----A---- C:\Windows\SYSWOW64\osk.exe
2014-07-09 21:28:33 ----A---- C:\Windows\system32\win32k.sys
2014-07-09 21:28:33 ----A---- C:\Windows\system32\osk.exe
2014-07-09 21:28:32 ----A---- C:\Windows\SYSWOW64\qedit.dll
2014-07-09 21:28:32 ----A---- C:\Windows\system32\qedit.dll
2014-07-09 21:28:30 ----A---- C:\Windows\system32\drivers\afd.sys
2014-07-09 21:28:22 ----A---- C:\Windows\system32\schannel.dll
2014-07-09 21:28:21 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2014-07-09 21:28:21 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2014-07-09 21:28:21 ----A---- C:\Windows\SYSWOW64\schannel.dll
2014-07-09 21:28:21 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2014-07-09 21:28:21 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2014-07-09 21:28:21 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2014-07-09 21:28:21 ----A---- C:\Windows\SYSWOW64\credssp.dll
2014-07-09 21:28:21 ----A---- C:\Windows\system32\wdigest.dll
2014-07-09 21:28:21 ----A---- C:\Windows\system32\TSpkg.dll
2014-07-09 21:28:21 ----A---- C:\Windows\system32\ncrypt.dll
2014-07-09 21:28:21 ----A---- C:\Windows\system32\msv1_0.dll
2014-07-09 21:28:21 ----A---- C:\Windows\system32\kerberos.dll
2014-07-09 21:28:21 ----A---- C:\Windows\system32\credssp.dll
2014-07-09 21:28:16 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-07-09 21:28:16 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-07-09 21:28:16 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-07-09 21:28:16 ----A---- C:\Windows\system32\iernonce.dll
2014-07-09 21:28:15 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-07-09 21:28:15 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-07-09 21:28:15 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-07-09 21:28:15 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-07-09 21:28:15 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-07-09 21:28:15 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-07-09 21:28:15 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-09 21:28:15 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-07-09 21:28:15 ----A---- C:\Windows\system32\iedkcs32.dll
2014-07-09 21:28:14 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-07-09 21:28:13 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-07-09 21:28:13 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-07-09 21:28:13 ----A---- C:\Windows\system32\urlmon.dll
2014-07-09 21:28:13 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-07-09 21:28:12 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-07-09 21:28:12 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-07-09 21:28:12 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-07-09 21:28:12 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-07-09 21:28:12 ----A---- C:\Windows\system32\msfeeds.dll
2014-07-09 21:28:12 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-07-09 21:28:12 ----A---- C:\Windows\system32\dxtmsft.dll
2014-07-09 21:28:11 ----A---- C:\Windows\system32\iesetup.dll
2014-07-09 21:28:11 ----A---- C:\Windows\system32\ie4uinit.exe
2014-07-09 21:28:10 ----A---- C:\Windows\system32\iertutil.dll
2014-07-09 21:28:09 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-07-09 21:28:09 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-07-09 21:28:09 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-07-09 21:28:09 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-07-09 21:28:09 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-07-09 21:28:09 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-07-09 21:28:09 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-07-09 21:28:09 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-07-09 21:28:09 ----A---- C:\Windows\system32\jsproxy.dll
2014-07-09 21:28:08 ----A---- C:\Windows\system32\ieui.dll
2014-07-09 21:28:08 ----A---- C:\Windows\system32\ieframe.dll
2014-07-09 21:28:08 ----A---- C:\Windows\system32\dxtrans.dll
2014-07-09 21:28:07 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-07-09 21:28:07 ----A---- C:\Windows\system32\mshtmled.dll
2014-07-09 21:28:07 ----A---- C:\Windows\system32\jscript9diag.dll
2014-07-09 21:28:07 ----A---- C:\Windows\system32\jscript9.dll
2014-07-09 21:28:07 ----A---- C:\Windows\system32\ieUnatt.exe
2014-07-09 21:28:06 ----A---- C:\Windows\system32\wininet.dll
2014-07-09 21:28:06 ----A---- C:\Windows\system32\vbscript.dll
2014-07-09 21:28:06 ----A---- C:\Windows\system32\ieapfltr.dll
2014-07-09 21:28:05 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-09 21:28:05 ----A---- C:\Windows\system32\msrating.dll
2014-07-09 21:28:05 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-07-09 21:28:05 ----A---- C:\Windows\system32\mshtml.dll
2014-07-09 21:24:57 ----A---- C:\Windows\system32\lsasrv.dll
2014-07-09 21:24:55 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2014-07-09 21:24:55 ----A---- C:\Windows\SYSWOW64\secur32.dll
2014-07-03 14:17:31 ----A---- C:\Windows\system32\wups2.dll
2014-07-03 14:17:31 ----A---- C:\Windows\system32\wucltux.dll
2014-07-03 14:17:31 ----A---- C:\Windows\system32\wuauclt.exe
2014-07-03 14:17:30 ----A---- C:\Windows\system32\wuaueng.dll
2014-07-03 14:17:19 ----A---- C:\Windows\SYSWOW64\wups.dll
2014-07-03 14:17:19 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2014-07-03 14:17:19 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2014-07-03 14:17:19 ----A---- C:\Windows\system32\wups.dll
2014-07-03 14:17:19 ----A---- C:\Windows\system32\wudriver.dll
2014-07-03 14:17:19 ----A---- C:\Windows\system32\wuapi.dll
2014-07-03 14:16:58 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2014-07-03 14:16:58 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2014-07-03 14:16:58 ----A---- C:\Windows\system32\wuwebv.dll
2014-07-03 14:16:58 ----A---- C:\Windows\system32\wuapp.exe
======List of files/folders modified in the last 1 month======
2014-07-27 22:21:28 ----D---- C:\Windows\Temp
2014-07-27 22:20:41 ----D---- C:\Windows\Prefetch
2014-07-27 22:16:57 ----D---- C:\Program Files
2014-07-27 22:16:48 ----D---- C:\Users\jana\AppData\Roaming\uTorrent
2014-07-27 21:22:06 ----D---- C:\Windows\system32\catroot2
2014-07-27 19:05:18 ----D---- C:\Windows\system32\config
2014-07-27 18:54:36 ----SHD---- C:\System Volume Information
2014-07-27 15:46:38 ----D---- C:\Windows\system32\drivers
2014-07-27 12:23:28 ----D---- C:\Windows\system32\Tasks
2014-07-27 12:23:11 ----D---- C:\Windows\winsxs
2014-07-27 12:23:10 ----AD---- C:\Windows\System32
2014-07-27 12:23:09 ----D---- C:\Windows
2014-07-27 11:21:17 ----RD---- C:\Program Files (x86)
2014-07-27 11:21:17 ----HD---- C:\ProgramData
2014-07-27 11:20:12 ----D---- C:\Windows\system32\NDF
2014-07-27 11:02:50 ----D---- C:\ProgramData\Package Cache
2014-07-27 11:02:48 ----SHD---- C:\Windows\Installer
2014-07-27 11:01:24 ----D---- C:\Windows\inf
2014-07-27 10:43:39 ----D---- C:\Windows\debug
2014-07-27 10:16:33 ----A---- C:\Windows\win.ini
2014-07-24 19:22:15 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-07-15 09:21:47 ----D---- C:\Windows\system32\wdi
2014-07-13 19:07:31 ----D---- C:\Users\jana\AppData\Roaming\vlc
2014-07-10 11:25:22 ----D---- C:\Windows\rescache
2014-07-10 03:21:02 ----D---- C:\Program Files\Windows Journal
2014-07-10 03:21:01 ----D---- C:\Windows\SYSWOW64\Dism
2014-07-10 03:21:01 ----D---- C:\Windows\system32\Dism
2014-07-10 03:20:58 ----D---- C:\Windows\ehome
2014-07-10 03:20:58 ----AD---- C:\Windows\SysWOW64
2014-07-10 03:20:57 ----D---- C:\Windows\system32\cs-CZ
2014-07-10 03:20:56 ----D---- C:\Program Files\Internet Explorer
2014-07-10 03:20:55 ----D---- C:\Windows\SYSWOW64\en-US
2014-07-10 03:20:54 ----D---- C:\Windows\system32\en-US
2014-07-10 03:20:52 ----D---- C:\Program Files (x86)\Internet Explorer
2014-07-10 03:04:33 ----D---- C:\Windows\system32\MRT
2014-07-10 03:03:05 ----A---- C:\Windows\system32\MRT.exe
2014-07-09 21:24:43 ----D---- C:\Windows\system32\catroot
2014-07-06 12:48:21 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-07-02 02:10:55 ----D---- C:\Windows\system32\drivers\UMDF
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2014-07-27 65776]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2014-07-27 224896]
R0 iaStorA;iaStorA; C:\Windows\system32\DRIVERS\iaStorA.sys [2013-09-20 630632]
R0 iaStorF;iaStorF; C:\Windows\system32\DRIVERS\iaStorF.sys [2013-09-20 28008]
R0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hcs.sys [2013-07-17 20464]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 {2635ac50-5488-40bf-9bfd-accb158f8f3f}w64;{2635ac50-5488-40bf-9bfd-accb158f8f3f}w64; C:\Windows\system32\drivers\{2635ac50-5488-40bf-9bfd-accb158f8f3f}w64.sys [2014-04-24 61120]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2014-07-27 93568]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2014-07-27 1041168]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2014-07-27 427360]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-03-25 283064]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2014-07-27 29208]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2014-07-27 79184]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2014-07-27 92008]
R2 sp_rsdrv2;Spyware Terminator Driver Filter; C:\Windows\system32\DRIVERS\stflt.sys [2014-07-27 51496]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2013-12-06 13207552]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2013-12-06 626176]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2013-09-24 94208]
R3 BCM43XX;Ovladač síťového adaptéru Broadcom 802.11; C:\Windows\system32\DRIVERS\bcmwl664.sys [2013-11-05 9082576]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2013-02-19 57848]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2013-11-05 3707864]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\k57nd60a.sys [2013-07-26 458960]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2011-01-13 1806592]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2013-12-06 239616]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-07-27 50344]
R2 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service; C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe [2012-09-07 1148664]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-18 116648]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-18 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-06-19 111616]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-03-19 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
-----------------EOF-----------------

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
PC zamrzá
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
- Rudy
- Site Admin
- Příspěvky: 119542
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: PC zamrzá
Zdravím!
Spusťte nejprve tuto utilitu:
Spusťte nejprve tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: PC zamrzá
# AdwCleaner v3.300 - Report created 27/07/2014 at 22:25:51
# Updated 27/07/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : jana - JANA-PC
# Running from : C:\Users\jana\Desktop\adwcleaner_3.300.exe
# Option : Clean
***** [ Services ] *****
Service Deleted : {2635ac50-5488-40bf-9bfd-accb158f8f3f}w64
***** [ Files / Folders ] *****
Folder Deleted : C:\Program Files (x86)\Torntv V9.0
Folder Deleted : C:\Users\jana\AppData\Local\Mobogenie
Folder Deleted : C:\Users\jana\AppData\Roaming\OpenCandy
File Deleted : C:\END
File Deleted : C:\Windows\System32\drivers\wStLibG64.sys
File Deleted : C:\Users\jana\daemonprocess.txt
***** [ Tâches planifiées ] *****
Tâche supprimée : 00e1002c-7029-4aa8-96af-5a4f99b861b7-1
Tâche supprimée : 00e1002c-7029-4aa8-96af-5a4f99b861b7-3
Tâche supprimée : 00e1002c-7029-4aa8-96af-5a4f99b861b7-4
Tâche supprimée : 00e1002c-7029-4aa8-96af-5a4f99b861b7-5
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Mobogenie_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Mobogenie_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550555135590}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660566136690}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{828DC97A-2277-4E10-92A9-4907FA0922A9}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F1C81E40-2485-4DB6-8C9D-04BD596B281E}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550555135590}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660566136690}
Key Deleted : HKCU\Software\1ClickDownload
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AppDataLow\Software\Torntv V9.0
Key Deleted : HKLM\Software\InstalledBrowserExtensions
Key Deleted : HKLM\Software\Torntv V9.0
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Torntv V9.0
Key Deleted : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17207
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
-\\ Google Chrome v36.0.1985.125
[ File : C:\Users\jana\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Search Provider] : hxxp://www.buenosearch.com/?q={searchTerms}&ba ... 3&tsp=5220
Deleted [Startup_urls] : hxxp://www.buenosearch.com/?babsrc=HP_ss&mntrI ... 3&tsp=5220
Deleted [Homepage] : hxxp://www.buenosearch.com/?babsrc=HP_ss&mntrI ... 3&tsp=5220
Deleted [Extension] : acfoobbgoakpihljnfedbcfaipcdlfhk
*************************
AdwCleaner[R0].txt - [4255 octets] - [27/07/2014 22:24:49]
AdwCleaner[S0].txt - [3896 octets] - [27/07/2014 22:25:51]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3956 octets] ##########
# Updated 27/07/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : jana - JANA-PC
# Running from : C:\Users\jana\Desktop\adwcleaner_3.300.exe
# Option : Clean
***** [ Services ] *****
Service Deleted : {2635ac50-5488-40bf-9bfd-accb158f8f3f}w64
***** [ Files / Folders ] *****
Folder Deleted : C:\Program Files (x86)\Torntv V9.0
Folder Deleted : C:\Users\jana\AppData\Local\Mobogenie
Folder Deleted : C:\Users\jana\AppData\Roaming\OpenCandy
File Deleted : C:\END
File Deleted : C:\Windows\System32\drivers\wStLibG64.sys
File Deleted : C:\Users\jana\daemonprocess.txt
***** [ Tâches planifiées ] *****
Tâche supprimée : 00e1002c-7029-4aa8-96af-5a4f99b861b7-1
Tâche supprimée : 00e1002c-7029-4aa8-96af-5a4f99b861b7-3
Tâche supprimée : 00e1002c-7029-4aa8-96af-5a4f99b861b7-4
Tâche supprimée : 00e1002c-7029-4aa8-96af-5a4f99b861b7-5
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Mobogenie_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Mobogenie_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550555135590}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660566136690}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{828DC97A-2277-4E10-92A9-4907FA0922A9}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F1C81E40-2485-4DB6-8C9D-04BD596B281E}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550555135590}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660566136690}
Key Deleted : HKCU\Software\1ClickDownload
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AppDataLow\Software\Torntv V9.0
Key Deleted : HKLM\Software\InstalledBrowserExtensions
Key Deleted : HKLM\Software\Torntv V9.0
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Torntv V9.0
Key Deleted : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17207
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
-\\ Google Chrome v36.0.1985.125
[ File : C:\Users\jana\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Search Provider] : hxxp://www.buenosearch.com/?q={searchTerms}&ba ... 3&tsp=5220
Deleted [Startup_urls] : hxxp://www.buenosearch.com/?babsrc=HP_ss&mntrI ... 3&tsp=5220
Deleted [Homepage] : hxxp://www.buenosearch.com/?babsrc=HP_ss&mntrI ... 3&tsp=5220
Deleted [Extension] : acfoobbgoakpihljnfedbcfaipcdlfhk
*************************
AdwCleaner[R0].txt - [4255 octets] - [27/07/2014 22:24:49]
AdwCleaner[S0].txt - [3896 octets] - [27/07/2014 22:25:51]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3956 octets] ##########
Re: PC zamrzá
Problém přetrvává i po vyčištění AdwCleanerem. Nějaké další nápady?
- Rudy
- Site Admin
- Příspěvky: 119542
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: PC zamrzá
Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.