Preventivní kontrola
Napsal: 27 črc 2015 11:38
Zdravím,
mohli byste prosím zkontrolovat log? Nejedná se o můj počítač, ale co jsem vypozoval, tak docela dlouho startuje a strašně moc paměti a procesoru žere svchost. Dostalo se to až někam na 700 MB.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-07-2015
Ran by Lidka (administrator) on LIDKA-NTB (27-07-2015 12:33:11)
Running from C:\Users\Lidka\Desktop
Loaded Profiles: Lidka (Available Profiles: Lidka)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9b219d80a8843bf8\stacsv.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9b219d80a8843bf8\AEstSrv.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(PDF Complete Inc) C:\Program Files\PDF Complete\pdfsvc.exe
(Protexis Inc.) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
() C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Hewlett-Packard Development Company L.P.) C:\Program Files\Hewlett-Packard\Shared\hpCaslNotification.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
(forum.viry.cz) C:\Users\Lidka\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWXConfigManager.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [QLBController] => C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe [256056 2010-01-28] (Hewlett-Packard Company)
HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2010-01-08] (Intel Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1791272 2010-06-04] (Synaptics Incorporated)
HKLM\...\Run: [WirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [499768 2009-09-01] (Hewlett-Packard)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray.exe [495708 2010-01-29] (IDT, Inc.)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [981688 2015-04-30] (Microsoft Corporation)
Startup: C:\Users\Lidka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk [2010-12-25]
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk -> C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVH.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-3717163629-3764986352-816470501-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
SearchScopes: HKLM -> DefaultScope {783FB0DE-DAD1-42CA-BEEF-3AA2038443F1} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {783FB0DE-DAD1-42CA-BEEF-3AA2038443F1} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKU\S-1-5-21-3717163629-3764986352-816470501-1001 -> DefaultScope {783FB0DE-DAD1-42CA-BEEF-3AA2038443F1} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKU\S-1-5-21-3717163629-3764986352-816470501-1001 -> {783FB0DE-DAD1-42CA-BEEF-3AA2038443F1} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-03-26] (Adobe Systems Incorporated)
BHO: Pomocník pro přihlášení ke službě Windows Live -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22] (Microsoft Corporation)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Toolbar: HKU\S-1-5-21-3717163629-3764986352-816470501-1001 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{137A3A1B-F795-42CD-8AA8-75DE625DE4D8}: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{2DDB42A9-B35F-4C8D-BD19-FA566CDC0C71}: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\Lidka\AppData\Roaming\Mozilla\Firefox\Profiles\avc5dzqo.default-1434387255874
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-15] ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll [2012-03-26] (Adobe Systems Inc.)
FF Extension: Adblock Plus - C:\Users\Lidka\AppData\Roaming\Mozilla\Firefox\Profiles\avc5dzqo.default-1434387255874\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-07-24]
FF Extension: LG_LexFox_v2 - C:\Program Files\Mozilla Firefox\extensions\LG_LexFox_v2@lingea.com [2015-07-04]
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-07-04]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
R2 HP Health Check Service; C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [120832 2009-10-15] (Hewlett-Packard) [File not signed]
R2 hpHotkeyMonitor; C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [265272 2010-01-28] (Hewlett-Packard Company)
R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2010-01-22] (Hewlett-Packard Company) [File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2015-04-30] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [284504 2015-04-30] (Microsoft Corporation)
R2 pdfcDispatcher; C:\Program Files\PDF Complete\pdfsvc.exe [635416 2010-01-12] (PDF Complete Inc)
S3 Sony Ericsson PCCompanion; C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [155344 2011-06-29] (Avanquest Software) [File not signed]
R2 STacSV; C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9b219d80a8843bf8\STacSV.exe [229458 2010-01-29] (IDT, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
S2 PDFProFiltSrv; C:\Program Files\Nuance\PDF Professional 6\PDFProFiltSrv.exe [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 Andbus; C:\windows\System32\DRIVERS\lgandbus.sys [14336 2010-12-07] (LG Electronics Inc.)
S3 AndDiag; C:\windows\System32\DRIVERS\lganddiag.sys [20736 2010-12-07] (LG Electronics Inc.)
S3 AndGps; C:\windows\System32\DRIVERS\lgandgps.sys [20096 2010-12-07] (LG Electronics Inc.)
S3 ANDModem; C:\windows\System32\DRIVERS\lgandmodem.sys [25088 2010-12-07] (LG Electronics Inc.)
S3 androidusb; C:\windows\System32\Drivers\lgandadb.sys [25728 2010-08-02] (Google Inc)
S3 Dot4Scan; C:\windows\System32\DRIVERS\Dot4Scan.sys [10752 2009-07-14] (Microsoft Corporation)
R0 giveio; C:\windows\System32\giveio.sys [5248 1996-04-03] () [File not signed]
R0 MpFilter; C:\windows\System32\DRIVERS\MpFilter.sys [245096 2015-03-04] (Microsoft Corporation)
R3 rtsuvc; C:\windows\System32\DRIVERS\rtsuvc.sys [73344 2010-01-30] (Realtek Semiconductor Corp.)
R0 speedfan; C:\windows\System32\speedfan.sys [25240 2011-03-18] (Almico Software)
S3 usbbus; C:\windows\System32\DRIVERS\lgusbbus.sys [13056 2011-02-14] (LG Electronics Inc.)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-27 12:33 - 2015-07-27 12:34 - 00012084 ____C C:\Users\Lidka\Desktop\FRST.txt
2015-07-27 12:32 - 2015-07-27 12:33 - 00000000 ___DC C:\FRST
2015-07-27 12:31 - 2015-07-27 12:31 - 00112640 ____C (forum.viry.cz) C:\Users\Lidka\Desktop\FRSTLauncher.exe
2015-07-27 12:30 - 2015-07-27 12:30 - 01650688 ____C (Farbar) C:\Users\Lidka\Desktop\FRST.exe
2015-07-24 21:11 - 2015-07-24 21:15 - 00000000 ___DC C:\a615f1bb402f6ec223e19324d64462
2015-07-24 20:55 - 2015-07-24 21:10 - 00715200 _____ (Microsoft Corporation) C:\windows\system32\mcupdate_GenuineIntel.dll
2015-07-24 20:40 - 2015-07-24 21:09 - 04520448 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-07-24 20:40 - 2015-07-24 21:09 - 00620032 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-07-24 20:35 - 2015-07-24 21:10 - 00210432 _____ (Microsoft Corporation) C:\windows\system32\cewmdm.dll
2015-07-24 20:12 - 2015-07-24 21:09 - 19877376 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-07-24 20:12 - 2015-07-24 21:09 - 12855296 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-07-24 20:12 - 2015-07-24 21:09 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-07-24 20:12 - 2015-07-24 21:09 - 02279424 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-07-24 20:12 - 2015-07-24 21:09 - 01310720 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-07-24 20:12 - 2015-07-24 21:09 - 00479232 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 02052608 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-07-24 20:12 - 2015-07-24 21:08 - 01951232 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 01155072 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00710144 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00689152 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00685568 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-07-24 20:12 - 2015-07-24 21:08 - 00667648 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-07-24 20:12 - 2015-07-24 21:08 - 00664064 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00504320 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00418304 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00342736 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00341504 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2015-07-24 20:12 - 2015-07-24 21:08 - 00285696 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00115712 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-07-24 20:12 - 2015-07-24 21:08 - 00102912 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-07-24 20:12 - 2015-07-24 21:08 - 00076288 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00047616 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00047104 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-07-24 19:52 - 2015-07-24 20:21 - 00000320 ____C C:\windows\Tasks\HPCeeScheduleForLidka.job
2015-07-24 19:50 - 2015-07-24 19:50 - 00000000 ___DC C:\Users\Lidka\AppData\Roaming\Roxio Log Files
2015-07-24 19:39 - 2015-07-24 19:40 - 06609608 ____C (Piriform Ltd) C:\Users\Lidka\Downloads\ccsetup508.exe
2015-07-15 21:32 - 2015-07-15 21:33 - 01187008 ____C (Adobe Systems Incorporated) C:\Users\Lidka\Downloads\flashplayer18_ga_install(1).exe
2015-07-12 17:46 - 2015-07-12 17:46 - 00000000 _RSHC C:\MSDOS.SYS
2015-07-12 17:46 - 2015-07-12 17:46 - 00000000 _RSHC C:\IO.SYS
2015-07-12 17:37 - 2015-07-24 19:47 - 00000052 ____C C:\windows\system32\DOErrors.log
2015-07-06 09:59 - 2015-07-06 09:59 - 00000383 ____C C:\ftconfig.ini
2015-07-04 21:41 - 2015-07-06 12:47 - 00000000 ___DC C:\Program Files\Mozilla Firefox
2015-07-01 20:16 - 2015-07-02 16:37 - 00000000 ___DC C:\Users\Lidka\Desktop\USA 2015
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-27 12:32 - 2009-07-14 06:34 - 00019760 ____C C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-27 12:32 - 2009-07-14 06:34 - 00019760 ____C C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-27 12:27 - 2010-08-05 10:59 - 01251339 ____C C:\windows\WindowsUpdate.log
2015-07-27 12:24 - 2010-12-25 22:50 - 00000000 ___DC C:\Users\Lidka\AppData\Roaming\SoftGrid Client
2015-07-27 12:23 - 2009-07-14 06:53 - 00000006 ___HC C:\windows\Tasks\SA.DAT
2015-07-27 12:23 - 2009-07-14 06:39 - 00222823 ____C C:\windows\setupact.log
2015-07-24 21:34 - 2009-07-14 04:37 - 00000000 ___DC C:\windows\Microsoft.NET
2015-07-24 21:26 - 2010-03-27 04:50 - 01561788 ____C C:\windows\system32\PerfStringBackup.INI
2015-07-24 20:40 - 2012-04-21 10:40 - 00000914 ____C C:\windows\Tasks\Adobe Flash Player Updater.job
2015-07-24 20:23 - 2015-06-12 15:31 - 00000000 ___DC C:\windows\rescache
2015-07-24 20:23 - 2015-04-15 17:41 - 00000000 ___DC C:\windows\system32\appraiser
2015-07-24 20:23 - 2014-05-07 17:23 - 00000000 __SDC C:\windows\system32\CompatTel
2015-07-24 20:23 - 2010-03-27 04:48 - 00000000 ___DC C:\ProgramData\Hewlett-Packard
2015-07-24 20:23 - 2009-07-14 04:37 - 00000000 ___DC C:\windows\system32\wfp
2015-07-24 20:23 - 2009-07-14 04:37 - 00000000 ___DC C:\windows\registration
2015-07-24 20:23 - 2009-07-14 04:37 - 00000000 ___DC C:\Program Files\Common Files\microsoft shared
2015-07-24 20:21 - 2010-12-23 17:49 - 00137280 ____C C:\Users\Lidka\AppData\Local\GDIPFONTCACHEV1.DAT
2015-07-24 20:20 - 2010-03-27 05:35 - 00182832 ____C C:\windows\PFRO.log
2015-07-24 20:20 - 2010-03-27 05:27 - 00000000 ___DC C:\ProgramData\Uninstall
2015-07-24 20:20 - 2009-07-14 06:33 - 00490720 ____C C:\windows\system32\FNTCACHE.DAT
2015-07-24 20:18 - 2009-07-14 04:37 - 00000000 ___DC C:\windows\system32\LogFiles
2015-07-24 20:07 - 2010-03-27 05:24 - 00000000 ___DC C:\Program Files\Common Files\Roxio Shared
2015-07-24 19:41 - 2012-03-24 16:08 - 00000965 ____C C:\Users\Public\Desktop\CCleaner.lnk
2015-07-24 19:41 - 2012-03-24 16:08 - 00000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-07-24 19:40 - 2012-03-24 16:08 - 00000000 ___DC C:\Program Files\CCleaner
2015-07-24 19:34 - 2012-09-14 19:22 - 00000000 ___DC C:\Users\Lidka\AppData\Roaming\Skype
2015-07-24 19:26 - 2010-12-23 17:44 - 00000000 ___DC C:\Users\Lidka
2015-07-15 21:32 - 2014-07-13 09:50 - 00000000 ___DC C:\Users\Lidka\AppData\Local\Adobe
2015-07-15 21:31 - 2012-04-21 10:40 - 00778416 ____C (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe
2015-07-15 21:31 - 2011-07-03 13:40 - 00142512 ____C (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl
2015-07-15 21:22 - 2012-07-20 14:05 - 00000940 ____C C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-15 21:22 - 2012-07-20 14:05 - 00000936 ____C C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-06 12:47 - 2012-04-28 13:09 - 00000000 ___DC C:\Program Files\Mozilla Maintenance Service
2015-07-05 12:11 - 2011-02-21 19:39 - 00246952 ____C (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2015-07-03 20:41 - 2009-07-14 04:37 - 00000000 ___DC C:\windows\system32\NDF
2015-07-02 16:43 - 2015-04-17 21:48 - 00000000 ___DC C:\Users\Lidka\Desktop\2015 - výběr
2015-06-30 19:10 - 2009-07-14 06:53 - 00032580 _____ C:\windows\Tasks\SCHEDLGU.TXT
2015-06-29 06:18 - 2013-11-19 19:36 - 00000000 ___DC C:\ProgramData\firebird
2015-06-27 21:46 - 2010-12-23 17:54 - 00000000 ___DC C:\Users\Lidka\AppData\Local\Hewlett-Packard
==================== Files in the root of some directories =======
2013-12-12 21:27 - 2013-12-12 21:27 - 49940480 ____C () C:\Program Files\GUT54E3.tmp
2013-05-06 19:43 - 2015-02-03 20:25 - 0007605 ____C () C:\Users\Lidka\AppData\Local\Resmon.ResmonCfg
2011-02-28 22:28 - 2011-02-28 22:29 - 0000088 _RSHC () C:\ProgramData\54F5B40938.sys
2010-03-27 05:36 - 2010-03-27 05:36 - 0000187 ____C () C:\ProgramData\HPWALog.txt
2010-12-24 22:02 - 2011-02-28 22:29 - 0002828 __SHC () C:\ProgramData\KGyGaAvL.sys
Some files in TEMP:
====================
C:\Users\Lidka\AppData\Local\Temp\MyHeritage_Version_6_0_0_5634_Size_29083336.exe
C:\Users\Lidka\AppData\Local\Temp\sfamcc00001.dll
C:\Users\Lidka\AppData\Local\Temp\sfextra.dll
C:\Users\Lidka\AppData\Local\Temp\SP49029.exe
C:\Users\Lidka\AppData\Local\Temp\sp58915.exe
C:\Users\Lidka\AppData\Local\Temp\uninstall.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\windows\explorer.exe => File is digitally signed
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\HPCeeScheduleForLidka.job => C:\Program Files\Hewlett-Packard\HP Ceement\HPCEE.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Lidka\Desktop" je 27871 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
"C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Family Tree Builder Update
C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPAdvisorDock
C:\Program Files\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel
"C:\Program Files\Symantec\Norton Online Backup\Activation\NOBuActivation.exe" UNATTENDED [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NortonOnlineBackupReminder
"C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" -NoStart [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM2_Monitor
"C:\Program Files\OLYMPUS\OLYMPUS Viewer 3\FirstStart.exe" /OS [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OV3_Monitor
C:\Program Files\PDF Complete\pdfsty.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete
C:\Program Files\Nuance\PDF Professional 6\RegistryController.exe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF6 Registry Controller
C:\Program Files\Nuance\PDF Professional 6\pdfpro6hook.exe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDFHook
"C:\Program Files\QuickTime\qttask.exe" -atboottime [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
"C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype
Re�im ECHO je vypnut.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTTray.exe
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
mohli byste prosím zkontrolovat log? Nejedná se o můj počítač, ale co jsem vypozoval, tak docela dlouho startuje a strašně moc paměti a procesoru žere svchost. Dostalo se to až někam na 700 MB.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-07-2015
Ran by Lidka (administrator) on LIDKA-NTB (27-07-2015 12:33:11)
Running from C:\Users\Lidka\Desktop
Loaded Profiles: Lidka (Available Profiles: Lidka)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9b219d80a8843bf8\stacsv.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9b219d80a8843bf8\AEstSrv.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(PDF Complete Inc) C:\Program Files\PDF Complete\pdfsvc.exe
(Protexis Inc.) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation) C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
() C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Hewlett-Packard Development Company L.P.) C:\Program Files\Hewlett-Packard\Shared\hpCaslNotification.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
(forum.viry.cz) C:\Users\Lidka\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWXConfigManager.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [QLBController] => C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe [256056 2010-01-28] (Hewlett-Packard Company)
HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2010-01-08] (Intel Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1791272 2010-06-04] (Synaptics Incorporated)
HKLM\...\Run: [WirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [499768 2009-09-01] (Hewlett-Packard)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray.exe [495708 2010-01-29] (IDT, Inc.)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [981688 2015-04-30] (Microsoft Corporation)
Startup: C:\Users\Lidka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk [2010-12-25]
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk -> C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVH.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-3717163629-3764986352-816470501-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
SearchScopes: HKLM -> DefaultScope {783FB0DE-DAD1-42CA-BEEF-3AA2038443F1} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {783FB0DE-DAD1-42CA-BEEF-3AA2038443F1} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKU\S-1-5-21-3717163629-3764986352-816470501-1001 -> DefaultScope {783FB0DE-DAD1-42CA-BEEF-3AA2038443F1} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKU\S-1-5-21-3717163629-3764986352-816470501-1001 -> {783FB0DE-DAD1-42CA-BEEF-3AA2038443F1} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-03-26] (Adobe Systems Incorporated)
BHO: Pomocník pro přihlášení ke službě Windows Live -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22] (Microsoft Corporation)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Toolbar: HKU\S-1-5-21-3717163629-3764986352-816470501-1001 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{137A3A1B-F795-42CD-8AA8-75DE625DE4D8}: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{2DDB42A9-B35F-4C8D-BD19-FA566CDC0C71}: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\Lidka\AppData\Roaming\Mozilla\Firefox\Profiles\avc5dzqo.default-1434387255874
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-15] ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll [2012-03-26] (Adobe Systems Inc.)
FF Extension: Adblock Plus - C:\Users\Lidka\AppData\Roaming\Mozilla\Firefox\Profiles\avc5dzqo.default-1434387255874\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-07-24]
FF Extension: LG_LexFox_v2 - C:\Program Files\Mozilla Firefox\extensions\LG_LexFox_v2@lingea.com [2015-07-04]
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-07-04]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
R2 HP Health Check Service; C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [120832 2009-10-15] (Hewlett-Packard) [File not signed]
R2 hpHotkeyMonitor; C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [265272 2010-01-28] (Hewlett-Packard Company)
R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2010-01-22] (Hewlett-Packard Company) [File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2015-04-30] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [284504 2015-04-30] (Microsoft Corporation)
R2 pdfcDispatcher; C:\Program Files\PDF Complete\pdfsvc.exe [635416 2010-01-12] (PDF Complete Inc)
S3 Sony Ericsson PCCompanion; C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [155344 2011-06-29] (Avanquest Software) [File not signed]
R2 STacSV; C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9b219d80a8843bf8\STacSV.exe [229458 2010-01-29] (IDT, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
S2 PDFProFiltSrv; C:\Program Files\Nuance\PDF Professional 6\PDFProFiltSrv.exe [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 Andbus; C:\windows\System32\DRIVERS\lgandbus.sys [14336 2010-12-07] (LG Electronics Inc.)
S3 AndDiag; C:\windows\System32\DRIVERS\lganddiag.sys [20736 2010-12-07] (LG Electronics Inc.)
S3 AndGps; C:\windows\System32\DRIVERS\lgandgps.sys [20096 2010-12-07] (LG Electronics Inc.)
S3 ANDModem; C:\windows\System32\DRIVERS\lgandmodem.sys [25088 2010-12-07] (LG Electronics Inc.)
S3 androidusb; C:\windows\System32\Drivers\lgandadb.sys [25728 2010-08-02] (Google Inc)
S3 Dot4Scan; C:\windows\System32\DRIVERS\Dot4Scan.sys [10752 2009-07-14] (Microsoft Corporation)
R0 giveio; C:\windows\System32\giveio.sys [5248 1996-04-03] () [File not signed]
R0 MpFilter; C:\windows\System32\DRIVERS\MpFilter.sys [245096 2015-03-04] (Microsoft Corporation)
R3 rtsuvc; C:\windows\System32\DRIVERS\rtsuvc.sys [73344 2010-01-30] (Realtek Semiconductor Corp.)
R0 speedfan; C:\windows\System32\speedfan.sys [25240 2011-03-18] (Almico Software)
S3 usbbus; C:\windows\System32\DRIVERS\lgusbbus.sys [13056 2011-02-14] (LG Electronics Inc.)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-27 12:33 - 2015-07-27 12:34 - 00012084 ____C C:\Users\Lidka\Desktop\FRST.txt
2015-07-27 12:32 - 2015-07-27 12:33 - 00000000 ___DC C:\FRST
2015-07-27 12:31 - 2015-07-27 12:31 - 00112640 ____C (forum.viry.cz) C:\Users\Lidka\Desktop\FRSTLauncher.exe
2015-07-27 12:30 - 2015-07-27 12:30 - 01650688 ____C (Farbar) C:\Users\Lidka\Desktop\FRST.exe
2015-07-24 21:11 - 2015-07-24 21:15 - 00000000 ___DC C:\a615f1bb402f6ec223e19324d64462
2015-07-24 20:55 - 2015-07-24 21:10 - 00715200 _____ (Microsoft Corporation) C:\windows\system32\mcupdate_GenuineIntel.dll
2015-07-24 20:40 - 2015-07-24 21:09 - 04520448 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-07-24 20:40 - 2015-07-24 21:09 - 00620032 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-07-24 20:35 - 2015-07-24 21:10 - 00210432 _____ (Microsoft Corporation) C:\windows\system32\cewmdm.dll
2015-07-24 20:12 - 2015-07-24 21:09 - 19877376 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-07-24 20:12 - 2015-07-24 21:09 - 12855296 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-07-24 20:12 - 2015-07-24 21:09 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-07-24 20:12 - 2015-07-24 21:09 - 02279424 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-07-24 20:12 - 2015-07-24 21:09 - 01310720 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-07-24 20:12 - 2015-07-24 21:09 - 00479232 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 02052608 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-07-24 20:12 - 2015-07-24 21:08 - 01951232 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 01155072 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00710144 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00689152 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00685568 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-07-24 20:12 - 2015-07-24 21:08 - 00667648 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-07-24 20:12 - 2015-07-24 21:08 - 00664064 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00504320 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00418304 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00342736 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00341504 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2015-07-24 20:12 - 2015-07-24 21:08 - 00285696 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00115712 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-07-24 20:12 - 2015-07-24 21:08 - 00102912 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-07-24 20:12 - 2015-07-24 21:08 - 00076288 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00047616 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00047104 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-07-24 20:12 - 2015-07-24 21:08 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-07-24 19:52 - 2015-07-24 20:21 - 00000320 ____C C:\windows\Tasks\HPCeeScheduleForLidka.job
2015-07-24 19:50 - 2015-07-24 19:50 - 00000000 ___DC C:\Users\Lidka\AppData\Roaming\Roxio Log Files
2015-07-24 19:39 - 2015-07-24 19:40 - 06609608 ____C (Piriform Ltd) C:\Users\Lidka\Downloads\ccsetup508.exe
2015-07-15 21:32 - 2015-07-15 21:33 - 01187008 ____C (Adobe Systems Incorporated) C:\Users\Lidka\Downloads\flashplayer18_ga_install(1).exe
2015-07-12 17:46 - 2015-07-12 17:46 - 00000000 _RSHC C:\MSDOS.SYS
2015-07-12 17:46 - 2015-07-12 17:46 - 00000000 _RSHC C:\IO.SYS
2015-07-12 17:37 - 2015-07-24 19:47 - 00000052 ____C C:\windows\system32\DOErrors.log
2015-07-06 09:59 - 2015-07-06 09:59 - 00000383 ____C C:\ftconfig.ini
2015-07-04 21:41 - 2015-07-06 12:47 - 00000000 ___DC C:\Program Files\Mozilla Firefox
2015-07-01 20:16 - 2015-07-02 16:37 - 00000000 ___DC C:\Users\Lidka\Desktop\USA 2015
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-27 12:32 - 2009-07-14 06:34 - 00019760 ____C C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-27 12:32 - 2009-07-14 06:34 - 00019760 ____C C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-27 12:27 - 2010-08-05 10:59 - 01251339 ____C C:\windows\WindowsUpdate.log
2015-07-27 12:24 - 2010-12-25 22:50 - 00000000 ___DC C:\Users\Lidka\AppData\Roaming\SoftGrid Client
2015-07-27 12:23 - 2009-07-14 06:53 - 00000006 ___HC C:\windows\Tasks\SA.DAT
2015-07-27 12:23 - 2009-07-14 06:39 - 00222823 ____C C:\windows\setupact.log
2015-07-24 21:34 - 2009-07-14 04:37 - 00000000 ___DC C:\windows\Microsoft.NET
2015-07-24 21:26 - 2010-03-27 04:50 - 01561788 ____C C:\windows\system32\PerfStringBackup.INI
2015-07-24 20:40 - 2012-04-21 10:40 - 00000914 ____C C:\windows\Tasks\Adobe Flash Player Updater.job
2015-07-24 20:23 - 2015-06-12 15:31 - 00000000 ___DC C:\windows\rescache
2015-07-24 20:23 - 2015-04-15 17:41 - 00000000 ___DC C:\windows\system32\appraiser
2015-07-24 20:23 - 2014-05-07 17:23 - 00000000 __SDC C:\windows\system32\CompatTel
2015-07-24 20:23 - 2010-03-27 04:48 - 00000000 ___DC C:\ProgramData\Hewlett-Packard
2015-07-24 20:23 - 2009-07-14 04:37 - 00000000 ___DC C:\windows\system32\wfp
2015-07-24 20:23 - 2009-07-14 04:37 - 00000000 ___DC C:\windows\registration
2015-07-24 20:23 - 2009-07-14 04:37 - 00000000 ___DC C:\Program Files\Common Files\microsoft shared
2015-07-24 20:21 - 2010-12-23 17:49 - 00137280 ____C C:\Users\Lidka\AppData\Local\GDIPFONTCACHEV1.DAT
2015-07-24 20:20 - 2010-03-27 05:35 - 00182832 ____C C:\windows\PFRO.log
2015-07-24 20:20 - 2010-03-27 05:27 - 00000000 ___DC C:\ProgramData\Uninstall
2015-07-24 20:20 - 2009-07-14 06:33 - 00490720 ____C C:\windows\system32\FNTCACHE.DAT
2015-07-24 20:18 - 2009-07-14 04:37 - 00000000 ___DC C:\windows\system32\LogFiles
2015-07-24 20:07 - 2010-03-27 05:24 - 00000000 ___DC C:\Program Files\Common Files\Roxio Shared
2015-07-24 19:41 - 2012-03-24 16:08 - 00000965 ____C C:\Users\Public\Desktop\CCleaner.lnk
2015-07-24 19:41 - 2012-03-24 16:08 - 00000000 ___DC C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-07-24 19:40 - 2012-03-24 16:08 - 00000000 ___DC C:\Program Files\CCleaner
2015-07-24 19:34 - 2012-09-14 19:22 - 00000000 ___DC C:\Users\Lidka\AppData\Roaming\Skype
2015-07-24 19:26 - 2010-12-23 17:44 - 00000000 ___DC C:\Users\Lidka
2015-07-15 21:32 - 2014-07-13 09:50 - 00000000 ___DC C:\Users\Lidka\AppData\Local\Adobe
2015-07-15 21:31 - 2012-04-21 10:40 - 00778416 ____C (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe
2015-07-15 21:31 - 2011-07-03 13:40 - 00142512 ____C (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl
2015-07-15 21:22 - 2012-07-20 14:05 - 00000940 ____C C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-15 21:22 - 2012-07-20 14:05 - 00000936 ____C C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-06 12:47 - 2012-04-28 13:09 - 00000000 ___DC C:\Program Files\Mozilla Maintenance Service
2015-07-05 12:11 - 2011-02-21 19:39 - 00246952 ____C (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2015-07-03 20:41 - 2009-07-14 04:37 - 00000000 ___DC C:\windows\system32\NDF
2015-07-02 16:43 - 2015-04-17 21:48 - 00000000 ___DC C:\Users\Lidka\Desktop\2015 - výběr
2015-06-30 19:10 - 2009-07-14 06:53 - 00032580 _____ C:\windows\Tasks\SCHEDLGU.TXT
2015-06-29 06:18 - 2013-11-19 19:36 - 00000000 ___DC C:\ProgramData\firebird
2015-06-27 21:46 - 2010-12-23 17:54 - 00000000 ___DC C:\Users\Lidka\AppData\Local\Hewlett-Packard
==================== Files in the root of some directories =======
2013-12-12 21:27 - 2013-12-12 21:27 - 49940480 ____C () C:\Program Files\GUT54E3.tmp
2013-05-06 19:43 - 2015-02-03 20:25 - 0007605 ____C () C:\Users\Lidka\AppData\Local\Resmon.ResmonCfg
2011-02-28 22:28 - 2011-02-28 22:29 - 0000088 _RSHC () C:\ProgramData\54F5B40938.sys
2010-03-27 05:36 - 2010-03-27 05:36 - 0000187 ____C () C:\ProgramData\HPWALog.txt
2010-12-24 22:02 - 2011-02-28 22:29 - 0002828 __SHC () C:\ProgramData\KGyGaAvL.sys
Some files in TEMP:
====================
C:\Users\Lidka\AppData\Local\Temp\MyHeritage_Version_6_0_0_5634_Size_29083336.exe
C:\Users\Lidka\AppData\Local\Temp\sfamcc00001.dll
C:\Users\Lidka\AppData\Local\Temp\sfextra.dll
C:\Users\Lidka\AppData\Local\Temp\SP49029.exe
C:\Users\Lidka\AppData\Local\Temp\sp58915.exe
C:\Users\Lidka\AppData\Local\Temp\uninstall.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\windows\explorer.exe => File is digitally signed
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\HPCeeScheduleForLidka.job => C:\Program Files\Hewlett-Packard\HP Ceement\HPCEE.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Lidka\Desktop" je 27871 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
"C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Family Tree Builder Update
C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPAdvisorDock
C:\Program Files\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel
"C:\Program Files\Symantec\Norton Online Backup\Activation\NOBuActivation.exe" UNATTENDED [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NortonOnlineBackupReminder
"C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" -NoStart [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM2_Monitor
"C:\Program Files\OLYMPUS\OLYMPUS Viewer 3\FirstStart.exe" /OS [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OV3_Monitor
C:\Program Files\PDF Complete\pdfsty.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete
C:\Program Files\Nuance\PDF Professional 6\RegistryController.exe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF6 Registry Controller
C:\Program Files\Nuance\PDF Professional 6\pdfpro6hook.exe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDFHook
"C:\Program Files\QuickTime\qttask.exe" -atboottime [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
"C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype
Re�im ECHO je vypnut.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTTray.exe
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================