Stránka 1 z 1

Zpomalený prohlížeč

Napsal: 17 zář 2014 08:40
od pedemo
Dobrý den.
Poslední dobou se mi při najíždění na net hodně zpomalil prohlížeč. Používal jsem Firefox, který ale přestal přehrávat flash videa a proto jsem přešel na Operu. Ten sice videa přehrává, ale oba prohlížeče hodně dlouho najíždí a při otvírání více oken najednou zamrzají a najíždějí po dlouhé době. Zkusil jsem návody co jsem našel na netu, ale nic nepomohlo. Antivir taky nic nenašel. Prosím o radu a pomoc. Děkuji.
Vkládám log RSIT

Logfile of random's system information tool 1.10 (written by random/random)
Run by Pitris at 2014-09-17 09:20:22
Microsoft Windows 7 Ultimate
System drive C: has 54 GB (48%) free of 114 GB
Total RAM: 3582 MB (50% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:20:47, on 17.9.2014
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SoundMAX.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Windows\system32\wuauclt.exe
E:\Stahuj\RSIT.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\trend micro\Pitris.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [FortKnoxPersonalFirewall] "C:\Program Files\NETGATE\FortKnox Personal Firewall\FortKnoxGUI.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\soundmax.exe /tray
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files\AMD AVT\bin\kdbsync.exe" aml
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Připojit cíl vazby k existujícímu PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Připojit k existujícímu PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Stiahnuť s IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Stiahnuť s IDM všetky prepojenia - C:\Program Files\Internet Download Manager\IEGetAll.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\Windows\system32\AEADISRV.EXE
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FortKnox Personal Firewall (fortknox) - NETGATE Technologies s.r.o. - C:\Program Files\NETGATE\FortKnox Personal Firewall\FortKnox.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Moborobo Device Service (MoboroboDeviceService) - Unknown owner - C:\Program Files\MoboRobo\MoboroboDeviceService.exe
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\system32\nlssrv32.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: SpyHunter 4 Service - Enigma Software Group USA, LLC. - C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

--
End of file - 8106 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
IDM integration (IDMIEHlprObj Class) - C:\Program Files\Internet Download Manager\IDMIECC.dll [2014-08-20 417816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"FortKnoxPersonalFirewall"=C:\Program Files\NETGATE\FortKnox Personal Firewall\FortKnoxGUI.exe [2012-12-11 1810312]
"SwitchBoard"=C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\soundmax.exe [2009-05-18 3866624]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2014-02-24 5075104]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2009-06-05 1310720]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2014-01-17 421888]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2013-04-30 642304]
"AMD AVT"=Cmd.exe /c start AMD Accelerated Video Transcoding device initialization /min C:\Program Files\AMD AVT\bin\kdbsync.exe aml []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2014-07-24 21653096]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1173504]
"IDMan"=C:\Program Files\Internet Download Manager\IDMan.exe [2014-09-03 3878480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"vidc.mjpg"=pvmjpg30.dll
"vidc.pDAD"=prodad-codec.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.VP60"=C:\Windows\system32\vp6vfw.dll
"vidc.VP61"=C:\Windows\system32\vp6vfw.dll
"VIDC.ACDV"=ACDV.dll
"msacm.dvacm_vspx6"=c:\PROGRA~1\Corel\CORELV~2\COMMON~1\Vio\Dvacm.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux2"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-09-17 09:20:22 ----D---- C:\rsit
2014-09-15 21:43:59 ----D---- C:\Program Files\Mozilla Firefox
2014-09-12 10:26:11 ----D---- C:\Users\Pitris\AppData\Roaming\IDM
2014-09-12 10:26:05 ----D---- C:\Program Files\Internet Download Manager
2014-09-09 12:15:29 ----D---- C:\Users\Pitris\AppData\Roaming\Opera
2014-09-09 11:18:00 ----D---- C:\Users\Pitris\AppData\Roaming\Darq Software
2014-09-09 11:15:41 ----D---- C:\Program Files\Darq Software
2014-09-09 10:34:06 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2014-09-09 10:31:28 ----D---- C:\ProgramData\ATI
2014-09-09 10:31:26 ----D---- C:\Program Files\AMD AVT
2014-09-09 10:31:24 ----D---- C:\Program Files\AMD APP
2014-09-09 10:31:17 ----D---- C:\Program Files\Common Files\ATI Technologies
2014-09-09 09:12:34 ----D---- C:\Users\Pitris\AppData\Roaming\Opera Software
2014-09-09 09:12:26 ----D---- C:\Program Files\Opera
2014-09-06 22:43:52 ----D---- C:\Users\Pitris\AppData\Roaming\ATI
2014-09-06 22:42:49 ----D---- C:\ProgramData\AMD
2014-09-06 22:42:42 ----A---- C:\Windows\system32\drivers\amdiox86.sys
2014-09-06 22:41:29 ----D---- C:\Program Files\ATI Technologies
2014-09-06 22:41:27 ----D---- C:\Program Files\ATI
2014-09-06 22:40:18 ----D---- C:\AMD
2014-09-04 13:44:47 ----D---- C:\Program Files\QuickTime
2014-09-04 12:42:51 ----A---- C:\Windows\system32\browserchoice.exe
2014-09-04 12:42:30 ----A---- C:\Windows\system32\ntkrnlpa.exe
2014-09-04 12:42:29 ----A---- C:\Windows\system32\ntoskrnl.exe
2014-09-04 12:42:10 ----A---- C:\Windows\system32\kerberos.dll
2014-09-04 12:16:16 ----D---- C:\Program Files\DriverDoc
2014-08-30 14:16:17 ----A---- C:\autoexec.bat
2014-08-30 06:27:48 ----A---- C:\Users\Pitris\AppData\Roaming\System Monitor II_Settings.ini
2014-08-29 21:28:35 ----D---- C:\ProgramData\ESET
2014-08-29 11:32:09 ----D---- C:\Program Files\KtLauncher
2014-08-26 15:02:47 ----A---- C:\Windows\system32\d3dx10_39.dll
2014-08-26 15:02:47 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2014-08-26 15:02:46 ----A---- C:\Windows\system32\D3DX9_39.dll
2014-08-24 16:12:47 ----D---- C:\ProgramData\BlueStacks
2014-08-24 16:11:45 ----D---- C:\ProgramData\BlueStacksSetup
2014-08-23 14:57:01 ----D---- C:\ProgramData\pdf995
2014-08-23 14:57:00 ----A---- C:\Windows\system32\pdfmona.dll
2014-08-23 14:57:00 ----A---- C:\Windows\system32\pdf995mon.dll
2014-08-23 14:56:59 ----D---- C:\Program Files\pdf995
2014-08-23 14:47:58 ----D---- C:\Users\Pitris\AppData\Roaming\PSpad
2014-08-23 14:47:49 ----D---- C:\Program Files\PSPad editor

======List of files/folders modified in the last 1 month======

2014-09-17 09:20:33 ----D---- C:\Program Files\trend micro
2014-09-17 09:20:28 ----D---- C:\Windows\Prefetch
2014-09-17 09:20:08 ----D---- C:\Windows\Temp
2014-09-17 09:02:58 ----SHD---- C:\Windows\Installer
2014-09-17 09:01:49 ----D---- C:\Windows\system32\catroot
2014-09-17 09:01:48 ----D---- C:\Windows\system32\catroot2
2014-09-17 09:01:05 ----SHD---- C:\System Volume Information
2014-09-17 08:59:29 ----D---- C:\Windows\system32\config
2014-09-17 08:59:10 ----D---- C:\Windows\winsxs
2014-09-17 08:57:47 ----AD---- C:\ProgramData\TEMP
2014-09-17 08:56:35 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2014-09-17 08:56:35 ----AD---- C:\Windows
2014-09-17 08:56:32 ----D---- C:\Program Files\NVIDIA Corporation
2014-09-17 08:45:51 ----D---- C:\Windows\inf
2014-09-17 08:45:50 ----D---- C:\Windows\Minidump
2014-09-16 23:29:44 ----D---- C:\Users\Pitris\AppData\Roaming\DMCache
2014-09-16 22:15:16 ----D---- C:\Users\Pitris\AppData\Roaming\XnView
2014-09-16 17:11:22 ----D---- C:\Users\Pitris\AppData\Roaming\Skype
2014-09-16 15:51:06 ----D---- C:\Windows\System32
2014-09-16 15:51:06 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-09-15 21:44:30 ----RD---- C:\Program Files
2014-09-12 10:26:06 ----D---- C:\Windows\system32\drivers
2014-09-10 10:10:40 ----D---- C:\ProgramData\Origin
2014-09-09 13:12:10 ----D---- C:\Windows\system32\Tasks
2014-09-09 10:34:17 ----D---- C:\Windows\Tasks
2014-09-09 10:31:28 ----HD---- C:\ProgramData
2014-09-09 10:31:17 ----D---- C:\Program Files\Common Files
2014-09-09 10:29:57 ----D---- C:\Windows\system32\DriverStore
2014-09-09 10:27:47 ----D---- C:\Windows\SoftwareDistribution
2014-09-09 10:26:36 ----D---- C:\Users\Pitris\AppData\Roaming\Winamp
2014-09-09 10:22:30 ----SHD---- C:\$Recycle.Bin
2014-09-09 10:18:07 ----D---- C:\ProgramData\NVIDIA Corporation
2014-09-04 13:13:41 ----D---- C:\Users\Pitris\AppData\Roaming\uTorrent
2014-09-04 13:13:38 ----D---- C:\Windows\Logs
2014-09-04 13:13:38 ----D---- C:\Windows\debug
2014-09-04 12:46:00 ----D---- C:\ProgramData\Microsoft Help
2014-09-04 12:44:40 ----D---- C:\Windows\system32\MRT
2014-09-04 12:44:37 ----A---- C:\Windows\system32\MRT.exe
2014-08-30 13:19:19 ----D---- C:\Program Files\PowerISO
2014-08-29 12:23:42 ----RSD---- C:\Windows\assembly
2014-08-26 16:16:47 ----HD---- C:\Program Files\InstallShield Installation Information
2014-08-24 18:00:47 ----D---- C:\Windows\Microsoft.NET

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2013-09-17 188808]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2013-09-17 134248]
R1 fortknox_drv;fortknox_drv; C:\Windows\system32\drivers\fortknoxfw.sys [2009-11-15 57808]
R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2014-06-27 116320]
R1 VD_FileDisk;VD_FileDisk; C:\Windows\system32\drivers\VD_FileDisk.sys [2011-01-26 24680]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2013-09-17 122376]
R2 IDMWFP;IDMWFP; C:\Windows\system32\DRIVERS\idmwfp.sys [2014-06-09 113680]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\ADIHdAud.sys [2009-06-05 380416]
R3 amdiox86;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox86.sys [2010-02-18 37944]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2013-04-30 10070016]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2013-04-30 290304]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW73.sys [2012-05-14 86656]
R3 Fkndisf;FortKnox Firewall NDIS Filter Service; C:\Windows\system32\DRIVERS\fortknoxfw_ndisim.sys [2009-09-17 23120]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 26840]
R3 MarvinBus;Pinnacle Marvin Bus; C:\Windows\system32\DRIVERS\MarvinBus.sys [2005-09-23 171520]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2014-05-12 23256]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 13216]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x32.sys [2009-07-14 347264]
R3 P17;SB Live! 24-bit; C:\Windows\system32\drivers\P17.sys [2007-02-05 1122304]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2014-03-15 47360]
S2 BstHdDrv;BlueStacks Hypervisor; \??\C:\Program Files\BlueStacks\HD-Hypervisor-x86.sys []
S2 WCMVCAM;WebcamMax, WDM Video Capture; C:\Windows\system32\DRIVERS\wcmvcam.sys [2011-06-23 1068216]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2013-04-30 10070016]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 esgiguard;esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [2014-01-07 15384]
S3 EsgScanner;EsgScanner; C:\Windows\system32\DRIVERS\EsgScanner.sys [2012-06-22 19984]
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2014-05-12 51928]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-07-14 15872]
S3 usbsmi;Integrated Camera; C:\Windows\system32\DRIVERS\SMIksdrv.sys [2009-11-23 181120]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S3 WinUsb;YunOS USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944]
S4 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad32v.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 AEADIFilters;Andrea ADI Filters Service; C:\Windows\system32\AEADISRV.EXE [2009-06-05 90112]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2013-04-30 217088]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2013-04-29 291840]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2013-09-07 55624]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-31 390504]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2014-02-24 1343408]
R2 fortknox;FortKnox Personal Firewall; C:\Program Files\NETGATE\FortKnox Personal Firewall\FortKnox.exe [2011-08-16 553048]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-05-12 1809720]
R2 nlsX86cc;Nalpeiron Licensing Service; C:\Windows\system32\nlssrv32.exe [2011-10-24 66560]
R2 PSI_SVC_2;Protexis Licensing V2; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2010-03-10 189728]
R2 SpyHunter 4 Service;SpyHunter 4 Service; C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [2014-01-09 770432]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-10-04 116648]
S2 MBAMService;MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [2014-05-12 860472]
S2 MoboroboDeviceService;Moborobo Device Service; C:\Program Files\MoboRobo\MoboroboDeviceService.exe [2014-03-28 70952]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2014-04-11 45744]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-10-04 116648]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2013-10-23 553288]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 30814400]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2009-07-16 316664]
S3 SwitchBoard;SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]

-----------------EOF-----------------

Re: Zpomalený prohlížeč

Napsal: 17 zář 2014 08:56
od Márty84
Zdravim :)

:arrow: Stahnete OTL http://oldtimer.geekstogo.com/OTL.exe a ulozte na plochu.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce
Oznacte polozky (dejte tam zatrzitka) Pro všechny uživatele, Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
Do spodniho okna vlozte nasledujici text

Kód: Vybrat vše

CREATERESTOREPOINT

netsvcs
drivers32
savembr:0

/md5start
adp3132.sys
AGP440.sys
ahcix86.sys
ahcix86s.sys
atapi.sys
autochk.exe
cdrom.sys
cngaudit.dll
cryptsvc.dll
eNetHook.dll
eventlog.dll
explorer.exe
hal.dll
Changer.sys
iaStor.sys
iastorv.sys
IdeChnDr.sys
isapnp.sys
JakNDis.sys
KR10N.sys
logevent.dll
lsass.exe
mv61xx.sys
ndis.sys
netlogon.dll
ntelogon.dll
nvata.sys
nvatabus.sys
nvgts.sys
nvraid.sys
nvrd32.sys
nvstor.sys
nvstor32.sys
scecli.dll
sceclt.dll
smss.exe
svchost.exe
symmpi.sys
tcpip.sys
userinit.exe
vaxscsi.sys
viamraid.sys
viasraid.sys
ViPrt.sys
winlogon.exe
ws2_32.dll
/md5stop

%systemroot%*.* /U /s
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
%SYSTEMDRIVE%\*.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c

type c:\boot.ini >> test.txt /c
%SystemDrive%\PhysicalMBR.bin /md5

*crack* /s
*keygen* /s
*AntiWPA* /s
*loader* /s
*minodlogin* /s
*tnod* /s
*AutoKMS* /s
*activator* /s
*serial* /s
*w7lxe* /s
Kliknete na Prohledat
Po skenu se vytvori dva logy (OTL.Txt a Extras.txt), oba sem vlozte (kdyz budou dlouhe, rozdelte je do vice prispevku).

Re: Zpomalený prohlížeč

Napsal: 17 zář 2014 14:21
od pedemo
Zdravím. Jen se chci ujistit. Je normální, že sken trvá přes 3 hodiny a neskončil ?

Re: Zpomalený prohlížeč

Napsal: 17 zář 2014 18:24
od Márty84
Nekdy je dlouhy. Ale taky se mohl seknout. To ja odsud neposoudim :42:

Re: Zpomalený prohlížeč

Napsal: 17 zář 2014 19:58
od pedemo
ok. Zruším ho a dám skenovat v noci.

Re: Zpomalený prohlížeč

Napsal: 17 zář 2014 20:54
od Márty84
OK, pripadne v nouzovem rezimu.

Re: Zpomalený prohlížeč

Napsal: 18 zář 2014 07:15
od pedemo
Zdravím.
OTL byl puštěný celou noc a ráno jsem zjistil , že je seklý. Zkoušel jsem ho včera rozjet čtyřikrát a pokaždé se zasekl. Tak nevím :cry:

Re: Zpomalený prohlížeč

Napsal: 18 zář 2014 11:13
od Márty84
:arrow: Spustte ho podle stejneho navodu jeste jednou, ale s timto upravenym skriptem

Kód: Vybrat vše

CREATERESTOREPOINT

netsvcs
drivers32
savembr:0

/md5start
atapi.sys
autochk.exe
cdrom.sys
explorer.exe
hal.dll
scecli.dll
svchost.exe
tcpip.sys
userinit.exe
winlogon.exe
/md5stop

%systemroot%*.* /U /s
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
%SYSTEMDRIVE%\*.exe

*crack* /s
*keygen* /s
*AntiWPA* /s
*loader* /s
*minodlogin* /s
*tnod* /s
*AutoKMS* /s
*activator* /s
*serial* /s
*w7lxe* /s

Kdyz nepujde ani to, tak...
:arrow: Udelejte kontrolu s MBAM. Test nastavte podle tohoto navodu http://forum.viry.cz/viewtopic.php?f=29&t=137928 a dejte sem vysledky. Predem nic nemazte, miva obcas falesne detekce

Re: Zpomalený prohlížeč

Napsal: 18 zář 2014 22:32
od pedemo
Zdravím.
Tak dneska se OTL sekl 2x, tak jsem použil MBAM dle návodu. Výsledek mě celkem překvapil. Pěkná sbírka :

Malwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 18.9.2014
Čas skenování: 20:34:13
Protokol: scan mbam.txt
Správce: Ano

Verze: 2.00.2.1012
Databáze malwaru: v2014.09.18.06
Databáze rootkitů: v2014.09.18.01
Licence: Premium
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Self-protection: Vypnuto

OS: Windows 7 Service Pack 1
CPU: x86
Souborový systém: NTFS
Uživatel: Pitris

Typ skenu: Vlastní sken
Výsledek: Dokončeno
Prohledaných objektů: 582183
Uplynulý čas: 2 hod, 12 min, 26 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristics: Zapnuto
PUP: Zapnuto
PUM: Zapnuto

Procesy: 0
(No malicious items detected)

Moduly: 0
(No malicious items detected)

Klíče registru: 0
(No malicious items detected)

Hodnoty registru: 0
(No malicious items detected)

Data registru: 0
(No malicious items detected)

Složky: 0
(No malicious items detected)

Soubory: 19
PUP.RiskwareTool.CK, C:\Program Files\Adobe\Adobe Photoshop CS6\amtlib.dll, , [c05e8a65cbb072c464913ef517eb50b0],
Trojan.BitMiner, C:\Windows\inf\mncxrjr\mncxrjr.exe, , [ae7020cf97e4043277f0647978899c64],
BitcoinMiner, C:\Windows\inf\msfgvcea\msfgvcea.exe, , [63bbc42b1b60a39361f7ee1fdb2658a8],
Trojan.Agent.W, C:\Windows\Setup\SCRIPTS\Windows7Loader.exe, , [4fcf8f602b5040f6235ab1101aea39c7],
PUP.RiskwareTool.CK, D:\Baksa a spol\Adobe Photoshop CS6 13.0 Final CZ\32bit\amtlib.dll, , [041af1fed3a84de9b540ad86a959f60a],
Trojan.Agent.CK, D:\Baksa a spol\ESET NOD32 Antivirus 4 + cracky\2-2-eset-tnod-user-password-finder\TNod User & Password Finder\uninst-tnod.exe, , [e43a20cff28941f5396542d210f529d7],
PUP.Optional.OpenCandy, D:\Baksa a spol\Freemake.Video.Converter.Gold.4.1.3.5\FreemakeVideoConverter_4.1.3.5.exe, , [18062bc41467f442a36651cd34cd4eb2],
PUP.Optional.OpenCandy, D:\Baksa a spol\Freemake.Video.Converter.Gold.4.1.3.5\Freemake.Video.Converter.Gold.4.1.3.5\FreemakeVideoConverter_4.1.3.5.exe, , [62bcea052c4fec4a8c7d50ce22dfd42c],
RiskWare.Tool.CK, D:\Baksa a spol\SPORE 1+2\SPORE\keygen\fff-ea177.exe, , [60beec03a5d674c235a154b613f2d030],
PUP.Keygen.Intro, D:\Baksa a spol\TuneUp.Utilities.2012.v12.0.Incl.Keymaker-CORE\TuneUp.Utilities.2012.v12.0.Incl.Keymaker-CORE\CORE10k.EXE, , [1905bc337efd6dc95310377841c332ce],
RiskWare.Tool.CK, D:\Baksa a spol\ZA!loha\Stazeno z internetu\Baksa\ostatnA­\idman619\(IDM) Keygen + Patch Update 1\(IDM) Keygen + Patch Update 1 -UnREaL.exe, , [74aad21d1b604de92bfd33dfb25314ec],
PUP.Keygen.Intro, D:\Baksa a spol\ZA!loha\Stazeno z internetu\Baksa\Photoshop\Alien_Skin_Bokeh_2.0.0.3.339\Keygen\CORE10k.EXE, , [76a82bc48bf0fe380b58624d2fd507f9],
CrackTool.Agent, D:\Baksa a spol\ZA!loha\Stazeno z internetu\Baksa\Photoshop\Silver_Efex_Pro_2.0\silver.efex.pro.2.0-mpt.rar.vir, , [36e825ca22592d0938eb43ed1ae7be42],
RiskWare.Tool.CK, E:\System Volume Information\_restore{5318991C-5DE8-495D-AC28-76C1EF4943CB}\RP103\A0021923.exe, , [a17d19d68eed1b1b56c56bb550b24ab6],
RiskWare.Tool.HCK, E:\Stahuj\TCUP-5.8\TCUP 5.8\Total Commander Ultima Prime 5.8\Keygen.exe, , [43db995681faae887c9ab37320e2738d],
RiskWare.Tool.HCK, E:\Stahuj\Xilisoft Video Converter Ultimate 7.8.1.20140505\Xilisoft Video Converter Ultimate 7.8.1.20140505\crack\Xilisoft.4Media.ImToo.Multipatch.v0.4-BBB.exe, , [8f8f17d80873ca6c3eebf941df237a86],
PUP.Riskware.Patcher, E:\Stahuj\Xilisoft Video Converter Ultimate 7.8.1.20140505\Xilisoft Video Converter Ultimate 7.8.1.20140505\crack4\xilisoft.all.products-patch.exe, , [e638f7f8f9828caac2c6869654adca36],
PUP.Optional.OpenCandy, E:\STAHUJ !!!\Programs\Stepmania\StepMania-3.9a.exe, , [54ca816e0279fc3ae171131610f547b9],
RiskWare.Tool.CK, F:\System Volume Information\_restore{5318991C-5DE8-495D-AC28-76C1EF4943CB}\RP103\A0022138.exe, , [5ec0b6396f0c2d09c556ba66e0226a96],

Fyzické sektory: 0
(No malicious items detected)


(end)

Re: Zpomalený prohlížeč

Napsal: 19 zář 2014 01:52
od Márty84
Ano, pekna sbirka.

Mimochodem, jak je to s legalitou systemu? Ultimate neni zrovna bezna domaci verze :?:




11.10. pro neaktivitu :lock: http://forum.viry.cz/viewtopic.php?f=12&t=123975