Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu, děkuji

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
tomik258
Návštěvník
Návštěvník
Příspěvky: 100
Registrován: 04 kvě 2009 17:53

Prosím o kontrolu, děkuji

#1 Příspěvek od tomik258 »

Ahoj, po nějaké době jsem nechal projet NTB na kontrolu, je o něco pomalejší, před nedávnem mě potkaly i 2 Bluescreeny, stěžovaly si na HDD. Tak ten bychom mohli taky zkontrolovat. Mám hodně souborů na C disku, s tím, že hodně je i na ploše, což mi tady vytýkali při kontrolách v minulosti, ale nevidím to jako relevantní, když mám disk rozdělený "virtuálně". Fyzicky je v NTB jenom jeden, tak to stejně nemá vliv, nebo se mýlím?

Za kontrolu předem dík !! :thumbsup:

Logfile of random's system information tool 1.10 (written by random/random)
Run by Tom at 2016-09-08 19:14:21
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 164 GB (39%) free of 420 GB
Total RAM: 6088 MB (65% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:14:29, on 8.9.2016
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18427)
Boot mode: Normal

Running processes:
C:\Users\Tom\Downloads\Core Temp.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Users\Tom\AppData\Local\Microsoft\BingSvc\BingSvc.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
C:\Users\Tom\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe
C:\windows\SysWOW64\RunDll32.exe
C:\Users\Tom\AppData\Local\Google\Chrome\User Data\SwReporter\10.66.3\software_reporter_tool.exe
C:\Program Files\trend micro\Tom.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.2.2:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [YouCam Mirage] "C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe"
O4 - HKLM\..\Run: [YouCam Tray] "C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe" /s
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [BingSvc] C:\Users\Tom\AppData\Local\Microsoft\BingSvc\BingSvc.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/f ... wflash.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: C:\windows\SysWOW64\nvinit.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Network Service (NvStreamNetworkSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\windows\system32\nvvsvc.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - E:\GAMES\Origin\OriginClientService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11348 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
winlogon.exe
C:\windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe"
"C:\windows\system32\nvvsvc.exe"
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs

C:\windows\system32\svchost.exe -k GPSvcGroup
"C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SRSPS
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\WLANExt.exe 31060464
\??\C:\windows\system32\conhost.exe "1743043569-1770424651958318578-1942071018410308101307191820114057104-52378703
C:\windows\System32\spoolsv.exe
taskeng.exe {0AB494DB-BEA2-49AB-BAB7-6DE61392DF47}
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe -first
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe"
C:\windows\System32\svchost.exe -k utcsvc
"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
C:\windows\system32\msiexec.exe /V
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe"
C:\windows\SysWOW64\PnkBstrA.exe
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
C:\windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
C:\windows\system32\wbem\unsecapp.exe -Embedding
WLIDSvcM.exe 2764
C:\windows\system32\wbem\wmiprvse.exe
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe"
C:\windows\system32\svchost.exe -k bthsvcs
C:\windows\servicing\TrustedInstaller.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"taskhost.exe"
"C:\windows\system32\Dwm.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide
taskeng.exe {40BC9B9E-F196-4539-9D9B-1206971BEAA9}
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe" serviceapp
\??\C:\windows\system32\conhost.exe "1139632004-1688570422-18399845362879813151808950301148316325816000728811456761886
"C:\Users\Tom\Downloads\Core Temp.exe"
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\Explorer.EXE
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PAN Tray
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\utility.exe"
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /LENOVO_DOLBYDRAGON
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /LENOVO_MICPKEY
C:\windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1"
"C:\Users\Tom\AppData\Local\Microsoft\BingSvc\BingSvc.exe"
"C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe"
C:\windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
C:\windows\system32\sppsvc.exe
"C:\Users\Tom\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe"
C:\windows\system32\wbem\wmiprvse.exe
taskeng.exe {B7617470-5BD7-43CC-A60D-2DCFE19DA3D1}
"C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe"
"C:\windows\SysWOW64\RunDll32.exe" "C:\Program Files\Lenovo\Bluetooth Software\SysWOW64\BtMmHook.dll",SetAndWaitBtMmHook
"C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe" -Embedding
C:\windows\system32\DllHost.exe /Processid:{B366DEBE-645B-43A5-B865-DDD82C345492}
"C:\Users\Tom\AppData\Local\Google\Chrome\User Data\SwReporter\10.66.3\software_reporter_tool.exe"
"C:\windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Users\Tom\Downloads\RSITx64.exe"
"C:\windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528

======Scheduled tasks folder======

C:\windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-07-25 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení k účtu Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-07-25 171944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2014-12-11 13776088]
"IntelPAN"=C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [2011-05-02 1935120]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2011-10-28 2841896]
"OnekeyStudio"=C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe [2012-05-19 789920]
"Lenovo EE Boot Optimizer"=C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [2012-05-19 206176]
"Energy Management"=C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [2012-05-19 9753024]
"EnergyUtility"=C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [2012-05-19 5908928]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2016-06-14 2397120]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2013-11-07 171992]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2013-11-07 399832]
"Persistence"=C:\windows\system32\igfxpers.exe [2013-11-07 442328]
"RtHDVBg_LENOVO_DOLBYDRAGON"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-12-11 1391472]
"RtHDVBg_LENOVO_MICPKEY"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-12-11 1391472]
"ShadowPlay"=C:\windows\system32\nvspcap64.dll [2016-06-14 1767944]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584]
"BingSvc"=C:\Users\Tom\AppData\Local\Microsoft\BingSvc\BingSvc.exe [2015-11-05 144008]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeriFaceManager]
C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe [2012-05-19 329056]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2011-01-12 283160]
"YouCam Mirage"=C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [2011-01-29 136488]
"YouCam Tray"=C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [2011-01-29 228448]
"amd_dc_opt"=C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [2008-07-22 77824]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\windows\system32\nvinitx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2013-11-07 442880]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux2"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux3"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux4"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"aux5"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"aux6"=wdmaud.drv
"wave9"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer9"=wdmaud.drv
"aux7"=wdmaud.drv
"aux8"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux9"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-09-08 19:14:20 ----D---- C:\rsit
2016-09-05 17:22:34 ----D---- C:\windows\SYSWOW64\NV
2016-09-05 17:22:34 ----D---- C:\windows\system32\NV
2016-09-05 17:22:24 ----A---- C:\windows\system32\vulkaninfo.exe
2016-09-05 17:22:23 ----A---- C:\windows\system32\vulkan-1.dll
2016-09-05 17:22:22 ----A---- C:\windows\SYSWOW64\vulkaninfo.exe
2016-09-05 17:22:21 ----A---- C:\windows\SYSWOW64\vulkan-1.dll
2016-09-05 17:19:35 ----A---- C:\windows\SYSWOW64\nvwgf2um.dll
2016-09-05 17:19:35 ----A---- C:\windows\SYSWOW64\nvptxJitCompiler.dll
2016-09-05 17:19:35 ----A---- C:\windows\SYSWOW64\nvopencl.dll
2016-09-05 17:19:35 ----A---- C:\windows\SYSWOW64\nvoglv32.dll
2016-09-05 17:19:35 ----A---- C:\windows\SYSWOW64\nvoglshim32.dll
2016-09-05 17:19:35 ----A---- C:\windows\SYSWOW64\NvIFR.dll
2016-09-05 17:19:35 ----A---- C:\windows\SYSWOW64\NvFBC.dll
2016-09-05 17:19:35 ----A---- C:\windows\SYSWOW64\nvfatbinaryLoader.dll
2016-09-05 17:19:35 ----A---- C:\windows\SYSWOW64\nvd3dum.dll
2016-09-05 17:19:35 ----A---- C:\windows\SYSWOW64\nvcuvid.dll
2016-09-05 17:19:35 ----A---- C:\windows\SYSWOW64\nvcuda.dll
2016-09-05 17:19:35 ----A---- C:\windows\SYSWOW64\nvcompiler.dll
2016-09-05 17:19:35 ----A---- C:\windows\system32\nvwgf2umx.dll
2016-09-05 17:19:35 ----A---- C:\windows\system32\nvptxJitCompiler.dll
2016-09-05 17:19:35 ----A---- C:\windows\system32\nvopencl.dll
2016-09-05 17:19:35 ----A---- C:\windows\system32\nvoglv64.dll
2016-09-05 17:19:35 ----A---- C:\windows\system32\nvoglshim64.dll
2016-09-05 17:19:35 ----A---- C:\windows\system32\NvIFR64.dll
2016-09-05 17:19:35 ----A---- C:\windows\system32\NvFBC64.dll
2016-09-05 17:19:35 ----A---- C:\windows\system32\nvfatbinaryLoader.dll
2016-09-05 17:19:35 ----A---- C:\windows\system32\nvdispgenco6437270.dll
2016-09-05 17:19:35 ----A---- C:\windows\system32\nvdispco6437270.dll
2016-09-05 17:19:35 ----A---- C:\windows\system32\nvd3dumx.dll
2016-09-05 17:19:35 ----A---- C:\windows\system32\nvcuvid.dll
2016-09-05 17:19:35 ----A---- C:\windows\system32\nvcuda.dll
2016-09-05 17:19:35 ----A---- C:\windows\system32\nvcompiler.dll
2016-09-05 17:19:35 ----A---- C:\windows\system32\drivers\nvpciflt.sys
2016-09-05 17:19:35 ----A---- C:\windows\system32\drivers\nvlddmkm.sys
2016-08-23 14:55:17 ----A---- C:\windows\system32\nvdispgenco6437254.dll
2016-08-23 14:55:17 ----A---- C:\windows\system32\nvdispco6437254.dll
2016-08-23 14:47:32 ----A---- C:\windows\SYSWOW64\tzres.dll
2016-08-23 14:47:32 ----A---- C:\windows\system32\tzres.dll
2016-08-11 21:14:21 ----A---- C:\windows\SYSWOW64\inseng.dll
2016-08-11 21:14:21 ----A---- C:\windows\SYSWOW64\iernonce.dll
2016-08-11 21:14:21 ----A---- C:\windows\SYSWOW64\ieetwproxystub.dll
2016-08-11 21:14:21 ----A---- C:\windows\system32\iernonce.dll
2016-08-11 21:14:21 ----A---- C:\windows\system32\ieetwcollector.exe
2016-08-11 21:14:20 ----A---- C:\windows\SYSWOW64\occache.dll
2016-08-11 21:14:20 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2016-08-11 21:14:20 ----A---- C:\windows\SYSWOW64\MshtmlDac.dll
2016-08-11 21:14:20 ----A---- C:\windows\system32\ieetwproxystub.dll
2016-08-11 21:14:19 ----A---- C:\windows\SYSWOW64\vbscript.dll
2016-08-11 21:14:19 ----A---- C:\windows\SYSWOW64\urlmon.dll
2016-08-11 21:14:19 ----A---- C:\windows\SYSWOW64\mshtml.dll
2016-08-11 21:14:19 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2016-08-11 21:14:19 ----A---- C:\windows\SYSWOW64\JavaScriptCollectionAgent.dll
2016-08-11 21:14:19 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2016-08-11 21:14:19 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2016-08-11 21:14:19 ----A---- C:\windows\system32\JavaScriptCollectionAgent.dll
2016-08-11 21:14:19 ----A---- C:\windows\system32\inseng.dll
2016-08-11 21:14:19 ----A---- C:\windows\system32\ie4uinit.exe
2016-08-11 21:14:18 ----A---- C:\windows\SYSWOW64\iesetup.dll
2016-08-11 21:14:18 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2016-08-11 21:14:18 ----A---- C:\windows\system32\occache.dll
2016-08-11 21:14:18 ----A---- C:\windows\system32\iedkcs32.dll
2016-08-11 21:14:17 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2016-08-11 21:14:17 ----A---- C:\windows\SYSWOW64\jscript9diag.dll
2016-08-11 21:14:17 ----A---- C:\windows\SYSWOW64\jscript.dll
2016-08-11 21:14:17 ----A---- C:\windows\SYSWOW64\ieui.dll
2016-08-11 21:14:17 ----A---- C:\windows\SYSWOW64\iertutil.dll
2016-08-11 21:14:17 ----A---- C:\windows\SYSWOW64\ieframe.dll
2016-08-11 21:14:17 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2016-08-11 21:14:17 ----A---- C:\windows\system32\urlmon.dll
2016-08-11 21:14:17 ----A---- C:\windows\system32\MsSpellCheckingFacility.exe
2016-08-11 21:14:17 ----A---- C:\windows\system32\msfeeds.dll
2016-08-11 21:14:17 ----A---- C:\windows\system32\ieetwcollectorres.dll
2016-08-11 21:14:17 ----A---- C:\windows\system32\dxtrans.dll
2016-08-11 21:14:16 ----A---- C:\windows\system32\iesetup.dll
2016-08-11 21:14:16 ----A---- C:\windows\system32\iertutil.dll
2016-08-11 21:14:16 ----A---- C:\windows\system32\ieapfltr.dll
2016-08-11 21:14:15 ----A---- C:\windows\SYSWOW64\wininet.dll
2016-08-11 21:14:15 ----A---- C:\windows\SYSWOW64\webcheck.dll
2016-08-11 21:14:15 ----A---- C:\windows\SYSWOW64\msrating.dll
2016-08-11 21:14:15 ----A---- C:\windows\SYSWOW64\mshtmlmedia.dll
2016-08-11 21:14:15 ----A---- C:\windows\SYSWOW64\jscript9.dll
2016-08-11 21:14:15 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2016-08-11 21:14:15 ----A---- C:\windows\system32\vbscript.dll
2016-08-11 21:14:15 ----A---- C:\windows\system32\jsproxy.dll
2016-08-11 21:14:14 ----A---- C:\windows\system32\mshtmled.dll
2016-08-11 21:14:14 ----A---- C:\windows\system32\ieui.dll
2016-08-11 21:14:14 ----A---- C:\windows\system32\ieframe.dll
2016-08-11 21:14:14 ----A---- C:\windows\system32\dxtmsft.dll
2016-08-11 21:14:13 ----A---- C:\windows\system32\webcheck.dll
2016-08-11 21:14:13 ----A---- C:\windows\system32\mshtmlmedia.dll
2016-08-11 21:14:13 ----A---- C:\windows\system32\jscript9diag.dll
2016-08-11 21:14:13 ----A---- C:\windows\system32\jscript9.dll
2016-08-11 21:14:13 ----A---- C:\windows\system32\jscript.dll
2016-08-11 21:14:13 ----A---- C:\windows\system32\ieUnatt.exe
2016-08-11 21:14:12 ----A---- C:\windows\system32\wininet.dll
2016-08-11 21:14:10 ----A---- C:\windows\system32\msrating.dll
2016-08-11 21:14:10 ----A---- C:\windows\system32\MshtmlDac.dll
2016-08-11 21:14:09 ----A---- C:\windows\system32\mshtml.dll
2016-08-11 21:13:26 ----A---- C:\windows\SYSWOW64\sspicli.dll
2016-08-11 21:13:26 ----A---- C:\windows\SYSWOW64\schannel.dll
2016-08-11 21:13:26 ----A---- C:\windows\SYSWOW64\rpcrt4.dll
2016-08-11 21:13:26 ----A---- C:\windows\SYSWOW64\certcli.dll
2016-08-11 21:13:26 ----A---- C:\windows\system32\schannel.dll
2016-08-11 21:13:26 ----A---- C:\windows\system32\rpcrt4.dll
2016-08-11 21:13:26 ----A---- C:\windows\system32\ncrypt.dll
2016-08-11 21:13:26 ----A---- C:\windows\system32\lsasrv.dll
2016-08-11 21:13:26 ----A---- C:\windows\system32\kerberos.dll
2016-08-11 21:13:26 ----A---- C:\windows\system32\drivers\mrxsmb10.sys
2016-08-11 21:13:26 ----A---- C:\windows\system32\drivers\mrxsmb.sys
2016-08-11 21:13:26 ----A---- C:\windows\system32\drivers\ksecpkg.sys
2016-08-11 21:13:26 ----A---- C:\windows\system32\drivers\ksecdd.sys
2016-08-11 21:13:26 ----A---- C:\windows\system32\certcli.dll
2016-08-11 21:13:25 ----A---- C:\windows\SYSWOW64\wdigest.dll
2016-08-11 21:13:25 ----A---- C:\windows\SYSWOW64\TSpkg.dll
2016-08-11 21:13:25 ----A---- C:\windows\SYSWOW64\secur32.dll
2016-08-11 21:13:25 ----A---- C:\windows\SYSWOW64\rpchttp.dll
2016-08-11 21:13:25 ----A---- C:\windows\SYSWOW64\ncrypt.dll
2016-08-11 21:13:25 ----A---- C:\windows\SYSWOW64\msv1_0.dll
2016-08-11 21:13:25 ----A---- C:\windows\SYSWOW64\msobjs.dll
2016-08-11 21:13:25 ----A---- C:\windows\SYSWOW64\msaudite.dll
2016-08-11 21:13:25 ----A---- C:\windows\SYSWOW64\kerberos.dll
2016-08-11 21:13:25 ----A---- C:\windows\SYSWOW64\cryptbase.dll
2016-08-11 21:13:25 ----A---- C:\windows\SYSWOW64\credssp.dll
2016-08-11 21:13:25 ----A---- C:\windows\SYSWOW64\auditpol.exe
2016-08-11 21:13:25 ----A---- C:\windows\SYSWOW64\adtschema.dll
2016-08-11 21:13:25 ----A---- C:\windows\system32\wdigest.dll
2016-08-11 21:13:25 ----A---- C:\windows\system32\TSpkg.dll
2016-08-11 21:13:25 ----A---- C:\windows\system32\sspisrv.dll
2016-08-11 21:13:25 ----A---- C:\windows\system32\sspicli.dll
2016-08-11 21:13:25 ----A---- C:\windows\system32\secur32.dll
2016-08-11 21:13:25 ----A---- C:\windows\system32\rpchttp.dll
2016-08-11 21:13:25 ----A---- C:\windows\system32\msv1_0.dll
2016-08-11 21:13:25 ----A---- C:\windows\system32\msobjs.dll
2016-08-11 21:13:25 ----A---- C:\windows\system32\msaudite.dll
2016-08-11 21:13:25 ----A---- C:\windows\system32\lsass.exe
2016-08-11 21:13:25 ----A---- C:\windows\system32\drivers\mrxsmb20.sys
2016-08-11 21:13:25 ----A---- C:\windows\system32\cryptbase.dll
2016-08-11 21:13:25 ----A---- C:\windows\system32\credssp.dll
2016-08-11 21:13:25 ----A---- C:\windows\system32\auditpol.exe
2016-08-11 21:13:25 ----A---- C:\windows\system32\adtschema.dll
2016-08-11 21:10:11 ----A---- C:\windows\system32\win32k.sys

======List of files/folders modified in the last 1 month======

2016-09-08 19:14:29 ----D---- C:\windows\Prefetch
2016-09-08 19:14:25 ----D---- C:\Program Files\trend micro
2016-09-08 19:14:05 ----D---- C:\windows\Temp
2016-09-08 19:14:01 ----A---- C:\windows\SYSWOW64\log.txt
2016-09-08 19:09:55 ----D---- C:\windows\system32\config
2016-09-07 21:31:47 ----D---- C:\Users\Tom\AppData\Roaming\Skype
2016-09-07 20:44:40 ----SHD---- C:\windows\Installer
2016-09-07 20:44:33 ----RD---- C:\Program Files (x86)\Skype
2016-09-07 20:44:28 ----D---- C:\ProgramData\Skype
2016-09-07 19:43:00 ----SHD---- C:\System Volume Information
2016-09-07 16:40:50 ----D---- C:\Users\Tom\AppData\Roaming\vlc
2016-09-06 16:35:09 ----D---- C:\Windows
2016-09-06 16:33:49 ----D---- C:\windows\System32
2016-09-06 16:33:49 ----D---- C:\windows\inf
2016-09-06 16:33:49 ----A---- C:\windows\system32\PerfStringBackup.INI
2016-09-06 16:29:44 ----D---- C:\windows\SysWOW64
2016-09-05 17:22:31 ----D---- C:\ProgramData\NVIDIA
2016-09-05 17:21:11 ----D---- C:\windows\system32\drivers
2016-09-05 17:20:56 ----D---- C:\windows\system32\DriverStore
2016-09-05 16:23:00 ----D---- C:\windows\Minidump
2016-08-30 19:44:37 ----D---- C:\Program Files (x86)\Adobe
2016-08-26 01:28:29 ----A---- C:\windows\SYSWOW64\nvumdshim.dll
2016-08-26 01:28:29 ----A---- C:\windows\SYSWOW64\nvinit.dll
2016-08-26 01:28:29 ----A---- C:\windows\SYSWOW64\nvapi.dll
2016-08-26 01:28:29 ----A---- C:\windows\system32\nvumdshimx.dll
2016-08-26 01:28:29 ----A---- C:\windows\system32\nvinitx.dll
2016-08-26 01:28:29 ----A---- C:\windows\system32\nvapi64.dll
2016-08-25 23:10:08 ----A---- C:\windows\system32\nvsvc64.dll
2016-08-25 23:10:08 ----A---- C:\windows\system32\nvcpl.dll
2016-08-25 23:10:06 ----A---- C:\windows\SYSWOW64\oemdspif.dll
2016-08-25 23:10:06 ----A---- C:\windows\system32\nvvsvc.exe
2016-08-25 23:10:06 ----A---- C:\windows\system32\nvsvcr.dll
2016-08-25 23:10:05 ----A---- C:\windows\system32\nvshext.dll
2016-08-25 23:10:05 ----A---- C:\windows\system32\nvmctray.dll
2016-08-25 23:10:05 ----A---- C:\windows\system32\nv3dappshextr.dll
2016-08-25 23:10:05 ----A---- C:\windows\system32\nv3dappshext.dll
2016-08-25 19:34:32 ----D---- C:\windows\rescache
2016-08-23 14:50:11 ----D---- C:\windows\winsxs
2016-08-23 14:49:32 ----D---- C:\windows\SYSWOW64\cs-CZ
2016-08-23 14:49:27 ----D---- C:\windows\system32\cs-CZ
2016-08-13 11:03:57 ----D---- C:\Users\Tom\AppData\Roaming\Audacity
2016-08-13 10:56:32 ----D---- C:\Users\Tom\AppData\Roaming\OBS
2016-08-11 21:46:30 ----D---- C:\windows\SYSWOW64\en-US
2016-08-11 21:46:30 ----D---- C:\Program Files\Internet Explorer
2016-08-11 21:46:29 ----D---- C:\windows\system32\en-US
2016-08-11 21:46:28 ----D---- C:\Program Files (x86)\Internet Explorer
2016-08-11 21:25:50 ----D---- C:\windows\system32\MRT
2016-08-11 21:16:25 ----D---- C:\windows\debug
2016-08-11 21:16:12 ----AC---- C:\windows\system32\MRT.exe
2016-08-11 21:12:06 ----D---- C:\windows\system32\catroot2

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 fbfmon;fbfmon; C:\windows\system32\drivers\fbfmon.sys [2012-05-19 57952]
R0 fltsrv;Acronis Storage Filter Management; C:\windows\system32\DRIVERS\fltsrv.sys [2012-08-30 132704]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2011-01-12 439320]
R0 LHDmgr;LHDmgr; C:\windows\System32\DRIVERS\LhdX64.sys [2012-05-19 39008]
R0 nvpciflt;nvpciflt; C:\windows\system32\DRIVERS\nvpciflt.sys [2016-08-26 39992]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 BPntDrv;BPntDrv; C:\windows\system32\drivers\BPntDrv.sys [2012-05-19 13408]
R1 eamonm;eamonm; C:\windows\system32\DRIVERS\eamonm.sys [2016-04-14 264552]
R1 ehdrv;ehdrv; C:\windows\system32\DRIVERS\ehdrv.sys [2016-04-14 186784]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R1 winioex;winioex; C:\windows\system32\drivers\winioex.sys [2012-05-19 15456]
R2 epfwwfpr;epfwwfpr; C:\windows\system32\DRIVERS\epfwwfpr.sys [2016-04-14 170792]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver; C:\windows\system32\DRIVERS\AcpiVpc.sys [2012-05-19 29792]
R3 ALSysIO;ALSysIO; \??\C:\Users\Tom\AppData\Local\Temp\ALSysIO64.sys []
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2011-09-29 80384]
R3 BTWAMPFL;btwampfl; C:\windows\system32\DRIVERS\btwampfl.sys [2011-05-13 437288]
R3 btwaudio;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys [2011-05-13 150568]
R3 btwavdt;Bluetooth AVDT Service; C:\windows\system32\DRIVERS\btwavdt.sys [2011-05-13 164392]
R3 BTWDPAN;Bluetooth Personal Area Network; C:\windows\system32\DRIVERS\btwdpan.sys [2011-05-13 89640]
R3 btwl2cap;Bluetooth L2CAP Service; C:\windows\system32\DRIVERS\btwl2cap.sys [2011-05-13 39976]
R3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys [2011-05-13 21544]
R3 clwvd;CyberLink WebCam Virtual Driver; C:\windows\system32\DRIVERS\clwvd.sys [2011-01-29 31088]
R3 DelayMan;ACPI DelayMan Filter Service; C:\windows\system32\DRIVERS\delayman.sys [2012-05-19 20064]
R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2013-11-07 5363200]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys [2014-12-11 4351960]
R3 IntcDAud;Intel(R) Display Audio; C:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 317440]
R3 JMCR;JMCR; C:\windows\system32\DRIVERS\jmcr.sys [2010-12-13 174168]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\k57nd60a.sys [2011-05-09 425000]
R3 LgBttPort;LGE Bluetooth TransPort; C:\windows\system32\DRIVERS\lgbtpt64.sys [2009-09-29 16384]
R3 lgbusenum;LG Bluetooth Bus Enumerator; C:\windows\system32\DRIVERS\lgbtbs64.sys [2009-09-29 14848]
R3 LGVMODEM;LGE Virtual Modem; C:\windows\system32\DRIVERS\lgvmdm64.sys [2009-09-29 17408]
R3 MEIx64;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
R3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\windows\system32\DRIVERS\NETwNs64.sys [2011-05-01 8593920]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2016-06-14 26560]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\windows\system32\drivers\nvvad64v.sys [2016-04-14 56384]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 SPUVCbv;SPUVCb Driver Service; C:\windows\System32\Drivers\usbvideo.sys [2013-07-12 185344]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2011-10-28 398896]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
R3 wdkmd;Intel WiDi KMD; C:\windows\system32\DRIVERS\WDKMD.sys [2010-12-01 42392]
S3 AF15BDA;AF9015 BDA Device; C:\windows\system32\DRIVERS\AF15BDA.sys [2014-05-19 507392]
S3 AndNetDiag;LGE AndroidNet USB Serial Port; C:\windows\system32\DRIVERS\lgandnetdiag64.sys [2013-04-18 29184]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver; C:\windows\system32\DRIVERS\CtClsFlt.sys []
S3 hamachi;Hamachi Network Interface; C:\windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
S3 sdbus;sdbus; C:\windows\system32\DRIVERS\sdbus.sys [2010-11-21 109056]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\windows\system32\DRIVERS\wdcsam64.sys [2015-04-30 23200]
S3 WinUsb;WinUsb; C:\windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-06-25 82128]
R2 btwdins;Bluetooth Service; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [2011-05-12 970016]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\windows\System32\svchost.exe [2009-07-14 27136]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2016-03-03 2520928]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2011-05-02 1517328]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2016-06-14 1163712]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-01-12 13336]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-12-21 325656]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2016-06-14 1879488]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2016-06-14 2521024]
R2 nvsvc;NVIDIA Display Driver Service; C:\windows\system32\nvvsvc.exe [2016-08-25 1362368]
R2 PnkBstrA;PnkBstrA; C:\windows\syswow64\PnkBstrA.exe [2014-11-18 75136]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2011-05-02 844560]
R2 RtkAudioService;Realtek Audio Service; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [2014-12-11 292568]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]
R3 NvStreamNetworkSvc;NVIDIA Streamer Network Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [2016-06-14 3632576]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2015-11-05 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2015-11-05 125112]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31 144200]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2016-05-23 324224]
S2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-21 2656280]
S3 BEService;BattlEye Service; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [2016-04-05 1860616]
S3 cphs;Intel(R) Content Protection HECI Service; C:\windows\SysWow64\IntelCpHeciSvc.exe [2013-11-07 279000]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31 144200]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2014-01-06 136120]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2016-08-02 114688]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2011-05-02 340240]
S3 Origin Client Service;Origin Client Service; E:\GAMES\Origin\OriginClientService.exe [2016-04-20 2119688]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2016-08-23 1465120]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2012-08-29 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2015-11-05 51376]
S4 NetMsmqActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
S4 NetPipeActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
S4 NetTcpActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]

-----------------EOF-----------------

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o kontrolu, děkuji

#2 Příspěvek od Márty84 »

Zdravim :)

Na plose maji byt hlavne zastupci. Cim mensi plocha, tim lepe.

:arrow: Stahnete crystal disk info http://www.slunecnice.cz/sw/crystaldiskinfo/
Nainstalujte (pozor na pripadne doplnky, ty odmitnete zrusenim zatrzitka) a spustte jako spravce. Za chvili se zobrazi vysledek.
Kliknete nahore na napis Úpravy a pak na napis Kopírovat. To co se zkopiruje (ulozi se to do pameti) mi sem vlozte (ctrl + V)

:arrow: Stahnete AdwCleaner https://toolslib.net/downloads/finish/1/ a ulozte ho na plochu.
Ukoncete vsechny programy, jinak to AdwCleaner udela za vas.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Kliknete na Scan a pockejte, az kontrola dobehne.
Pak kliknete na Cleaning
Program zacne pracovat (muze dojit k restartu pc) a vyplivne log (pripadne bude zde C:\AdwCleaner\AdwCleaner[C?].txt ). Ten mi sem zkopirujte.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

tomik258
Návštěvník
Návštěvník
Příspěvky: 100
Registrován: 04 kvě 2009 17:53

Re: Prosím o kontrolu, děkuji

#3 Příspěvek od tomik258 »

Hezký den, na tu plochu si budu muset vyhradit čas a pořádně to pročistit... Neumím číst jednoduché návody a adwcleaner jsem spustil ze stažených souborů, snad mi neutrhnete hlavu :arcisit:

# AdwCleaner v6.010 - Log soubor vytvořen 10/09/2016 na 10:18:28
# Aktualizováno dne 12/08/2016 z ToolsLib
# Databáze : 2016-09-10.1 [Server]
# Operační systém : Windows 7 Home Premium Service Pack 1 (X64)
# Uživatelské jméno : Tom - TOMES-PC
# Beží od : C:\Users\Tom\Downloads\adwcleaner_6.010.exe
# Mod: Čištění
# Podpora : https://toolslib.net/forum



***** [ Služby ] *****



***** [ Adresáře ] *****



***** [ Soubory ] *****



***** [ DLL ] *****



***** [ WMI ] *****



***** [ Zástupce ] *****



***** [ Plánovač úloh ] *****



***** [ Registry ] *****

[-] Klíč smazán:HKCU\Software\Google\Chrome\Extensions\fcfenmboojpjinhpgggodefccipikbpd


***** [ Prohlížeče ] *****

[-] [davesviewpoint.com] [Search Provider] Smazání:davesviewpoint.com
[-] [C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default] [extension] Smazání:fcfenmboojpjinhpgggodefccipikbpd


*************************

:: "Tracing" klíč smazán
:: Winsock nastavení vyčištěno

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [1085 Bajtů] - [10/09/2016 10:18:28]
C:\AdwCleaner\AdwCleaner[S0].txt - [1621 Bajtů] - [10/09/2016 10:17:40]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [1233 Bajtů] ##########


Crystaldisk zde:

----------------------------------------------------------------------------
CrystalDiskInfo 7.0.3 (C) 2008-2016 hiyohiyo
Crystal Dew World : http://crystalmark.info/
----------------------------------------------------------------------------

OS : Windows 7 Home Premium SP1 [6.1 Build 7601] (x64)
Date : 2016/09/10 10:27:09

-- Controller Map ----------------------------------------------------------
+ Intel(R) Mobile Express Chipset SATA AHCI Controller [ATA]
- PLDS DVD-RW DS8A8SH
- WDC WD10JPVT-24A1YT0

-- Disk List ---------------------------------------------------------------
(1) WDC WD10JPVT-24A1YT0 : 1000.2 GB [0/0/1, pd1] - wd

----------------------------------------------------------------------------
(1) WDC WD10JPVT-24A1YT0
----------------------------------------------------------------------------
Model : WDC WD10JPVT-24A1YT0
Firmware : 01.01A01
Serial Number : WD-WX61EC1UYX14
Disk Size : 1000.2 GB (8.4/137.4/1000.2/1000.2)
Buffer Size : 8192 KB
Queue Depth : 32
# of Sectors : 1953525168
Rotation Rate : 5400 RPM
Interface : Serial ATA
Major Version : ATA8-ACS
Minor Version : ----
Transfer Mode : SATA/300 | SATA/300
Power On Hours : 13696 hod.
Power On Count : 3417 krát
Temperature : 36 C (96 F)
Health Status : Dobrý
Features : S.M.A.R.T., APM, 48bit LBA, NCQ
APM Level : 0080h [ON]
AAM Level : ----
Drive Letter : C: D: E:

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 200 200 _51 000000000001 Počet chyb čtení
03 183 178 _21 00000000073A Čas na roztočení ploten
04 _95 _95 __0 0000000013BF Počet spuštění/zastavení
05 200 200 140 000000000000 Počet přemapovaných sektorů
07 200 200 __0 000000000000 Počet chybných hledání
09 _82 _82 __0 000000003580 Hodin v činnosti
0A 100 100 __0 000000000000 Počet opakovaných pokusů o roztočení ploten
0B 100 100 __0 000000000000 Počet pokusů o překalibrování
0C _97 _97 __0 000000000D59 Počet cyklů zapnutí zařízení
C0 200 200 __0 000000000022 Počet vypnutí disku
C1 178 178 __0 000000010341 Počet cyklů načítání/vymazání
C2 111 100 __0 000000000024 Teplota
C4 200 200 __0 000000000000 Počet udalostí s číslem realokování sektorů
C5 200 200 __0 000000000000 Počet podezřelých sektorů
C6 100 253 __0 000000000000 Počet neopravitelných sektorů
C7 200 200 __0 000000000000 Počet chyb v kontrolním součtu UltraDMA
C8 100 253 __0 000000000000 Počet chyb při zápisu sektorů

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 427A 3FFF C837 0010 0000 0000 003F 0000 0000 0000
010: 2020 2020 2057 442D 5758 3631 4543 3155 5958 3134
020: 0000 4000 0000 3031 2E30 3141 3031 5744 4320 5744
030: 3130 4A50 5654 2D32 3441 3159 5430 2020 2020 2020
040: 2020 2020 2020 2020 2020 2020 2020 8010 0000 2F00
050: 4001 0000 0000 0007 3FFF 0010 003F FC10 00FB 0110
060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0000
070: 0000 0000 0000 0000 0000 001F 1F06 0004 004C 004C
080: 01FE 0000 746B 7D09 6123 7469 BC09 6123 407F 005C
090: 005C 0080 FFFE 0000 0000 0000 0000 0000 0000 0000
100: 6DB0 7470 0000 0000 0000 0000 6003 0000 5001 4EE6
110: 57BB 55DB 0000 0000 0000 0000 0000 0000 0000 401C
120: 401C 0000 0000 0000 0000 0000 0000 0000 0029 0000
130: 0000 0000 0000 16E8 0000 0000 0000 0000 0000 0000
140: 0000 0000 0004 0000 0000 0000 0000 0000 0000 0000
150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 70B5 0000 0000 4000
210: 0000 0000 0000 0000 0000 0000 0000 1518 0000 0000
220: 0000 0000 103E 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0001 1000 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 7CA5

-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 2F 00 C8 C8 01 00 00 00 00 00 00 03 27
010: 00 B7 B2 3A 07 00 00 00 00 00 04 32 00 5F 5F BF
020: 13 00 00 00 00 00 05 33 00 C8 C8 00 00 00 00 00
030: 00 00 07 2E 00 C8 C8 00 00 00 00 00 00 00 09 32
040: 00 52 52 80 35 00 00 00 00 00 0A 32 00 64 64 00
050: 00 00 00 00 00 00 0B 32 00 64 64 00 00 00 00 00
060: 00 00 0C 32 00 61 61 59 0D 00 00 00 00 00 C0 32
070: 00 C8 C8 22 00 00 00 00 00 00 C1 32 00 B2 B2 41
080: 03 01 00 00 00 00 C2 22 00 6F 64 24 00 00 00 00
090: 00 00 C4 32 00 C8 C8 00 00 00 00 00 00 00 C5 32
0A0: 00 C8 C8 00 00 00 00 00 00 00 C6 30 00 64 FD 00
0B0: 00 00 00 00 00 00 C7 32 00 C8 C8 00 00 00 00 00
0C0: 00 00 C8 08 00 64 FD 00 00 00 00 00 00 00 00 00
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 8C 46 01 7B
170: 03 00 01 00 02 C5 05 00 00 00 00 00 00 00 00 00
180: 00 00 01 04 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 A9

-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 33 C8 C8 C8 C8 00 00 00 00 00 00 03 15
010: 00 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00
020: 00 00 00 00 00 00 05 8C 00 00 00 00 00 00 00 00
030: 00 00 07 00 C8 C8 C8 C8 00 00 00 00 00 00 09 00
040: 00 00 00 00 00 00 00 00 00 00 0A 00 00 00 00 00
050: 00 00 00 00 00 00 0B 00 00 00 00 00 00 00 00 00
060: 00 00 0C 00 00 00 00 00 00 00 00 00 00 00 C0 00
070: 00 00 00 00 00 00 00 00 00 00 C1 00 00 00 00 00
080: 00 00 00 00 00 00 C2 00 00 00 00 00 00 00 00 00
090: 00 00 C4 00 00 00 00 00 00 00 00 00 00 00 C5 00
0A0: 00 00 00 00 00 00 00 00 00 00 C6 00 00 00 00 00
0B0: 00 00 00 00 00 00 C7 00 00 00 00 00 00 00 00 00
0C0: 00 00 C8 00 00 00 00 00 00 00 00 00 00 00 00 00
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 7D

Děkuji mnohokrát

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o kontrolu, děkuji

#4 Příspěvek od Márty84 »

tomik258 píše:na tu plochu si budu muset vyhradit čas a pořádně to pročistit...
Neni to tak tezke. Pokud tam mate slozky s filmama, nebo fotkama atd, premistete je treba primo na korenovy adresar disku, cili napriklad C:\Fotky, C:\Filmy, C:\Hudba atd a na plochu vytvorte zastupce tech slozek a je to.

tomik258 píše:Neumím číst jednoduché návody a adwcleaner jsem spustil ze stažených souborů, snad mi neutrhnete hlavu :arcisit:
Tak zrovna u ADWCleaneru na tom az tak nezalezi, takze zatim hlavu necham byt :-D


:arrow: Udelejte kontrolu s MBAM. Test nastavte podle tohoto navodu (cili Vlastni sken vsech disku) http://forum.viry.cz/viewtopic.php?f=29&t=144868 a dejte sem vysledky. Predem nic nemazte, miva obcas falesne detekce
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

tomik258
Návštěvník
Návštěvník
Příspěvky: 100
Registrován: 04 kvě 2009 17:53

Re: Prosím o kontrolu, děkuji

#5 Příspěvek od tomik258 »

Tak plocha zredukována na 50mb. Mbam mi nenašel nic, jen na nějakou dobu zaměstnal PC :all_coholic:

Malwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 10.9.2016
Čas skenování: 12:26
Protokol: mbamlog.txt
Správce: Ano

Verze: 2.2.1.1043
Databáze malwaru: v2016.09.10.04
Databáze rootkitů: v2016.08.15.01
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Ochrana programu: Vypnuto

OS: Windows 7 Service Pack 1
CPU: x64
Souborový systém: NTFS
Uživatel: Tom

Typ skenu: Vlastní sken
Výsledek: Dokončeno
Prohledaných objektů: 615662
Uplynulý čas: 4 hod, 35 min, 18 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Zapnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto

Procesy: 0
(Nenalezeny žádné škodlivé položky)

Moduly: 0
(Nenalezeny žádné škodlivé položky)

Klíče registru: 0
(Nenalezeny žádné škodlivé položky)

Hodnoty registru: 0
(Nenalezeny žádné škodlivé položky)

Data registru: 0
(Nenalezeny žádné škodlivé položky)

Složky: 0
(Nenalezeny žádné škodlivé položky)

Soubory: 0
(Nenalezeny žádné škodlivé položky)

Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)


(end)

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o kontrolu, děkuji

#6 Příspěvek od Márty84 »

:arrow: Dejte logy podle tohoto navodu http://forum.viry.cz/viewtopic.php?f=13&t=133100 - vypnete na chvili antivir, je mozne, ze to bude blokovat jako skodnou, ale pouzivame to porad, jedna se o falesny poplach :)
(Kdyby nesel Launcher stahnout, dejte logy jen ze samotneho FRST, tedy bez pouziti Launcheru)
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

tomik258
Návštěvník
Návštěvník
Příspěvky: 100
Registrován: 04 kvě 2009 17:53

Re: Prosím o kontrolu, děkuji

#7 Příspěvek od tomik258 »

Přidávám log z FRST. Dneska při zapínání PC se zopakovala situace, kterou jsem měl asi 2 týdny zpátky. NTB po vypnutí odpojuju ze sítě, vytahuji z něj i baterii (po většinu času provozuju pouze ze sítě, na baterii funguji výjmečně, možná proto má i po 5 letech výdrž 4-5 hodin :D ), nicméně když jsem NTB pouze vypnul a nevypojil ze sítě, tak po zapnutí na druhý den, se systém "zasekne" na uvítací obrazovce. Normálním způsobem se spustí, zadám heslo ke svemu učtu, a končí to na obrazovce vítejte s loadovacím kolečkem vedle. Zkoušel jsem tvrdý restart, spuštění obvyklym zpusobem a situace se opakovala. Po vypnutí a odpojení ze sítě na cca 10-15 minut jsem nastartoval znovu a už se chytil a beží zase standartně. :?:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 31-08-2016
Ran by Tom (administrator) on TOMES-PC (11-09-2016 09:41:09)
Running from C:\Users\Tom\Desktop
Loaded Profiles: Tom (Available Profiles: Tom)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
() C:\Users\Tom\Downloads\Core Temp.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(© 2015 Microsoft Corporation) C:\Users\Tom\AppData\Local\Microsoft\BingSvc\BingSvc.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTStackServer.exe
() C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13776088 2014-12-11] (Realtek Semiconductor)
HKLM\...\Run: [IntelPAN] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-05-02] (Intel(R) Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2841896 2011-10-28] (Synaptics Incorporated)
HKLM\...\Run: [OnekeyStudio] => C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe [789920 2012-05-19] (Lenovo)
HKLM\...\Run: [Lenovo EE Boot Optimizer] => C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [206176 2012-05-19] (Lenovo)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [9753024 2012-05-19] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [5908928 2012-05-19] (Lenovo(beijing) Limited)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2397120 2016-06-14] (NVIDIA Corporation)
HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1391472 2014-12-11] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1391472 2014-12-11] (Realtek Semiconductor)
HKLM\...\Run: [ShadowPlay] => C:\windows\system32\nvspcap64.dll [1767944 2016-06-14] (NVIDIA Corporation)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-01-12] (Intel Corporation)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2011-01-29] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [228448 2011-01-29] (CyberLink Corp.)
HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1506385281-2691020431-3212168025-1001\...\Run: [BingSvc] => C:\Users\Tom\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-05] (© 2015 Microsoft Corporation)
AppInit_DLLs: C:\windows\system32\nvinitx.dll => C:\windows\system32\nvinitx.dll [181488 2016-08-26] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\windows\SysWOW64\nvinit.dll => C:\windows\SysWOW64\nvinit.dll [159352 2016-08-26] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [VeriFace Enc] -> {771C7324-DA80-49D3-8017-753B0AF60951} => C:\windows\system32\IcnOvrly.dll [2012-05-19] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2012-05-19]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyServer: [S-1-5-21-1506385281-2691020431-3212168025-1001] => 192.168.2.2:3128
Tcpip\Parameters: [DhcpNameServer] 192.168.0.254 192.168.1.1
Tcpip\..\Interfaces\{35861DEA-3F8E-4240-9B0D-714BE33F0309}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{891B5BDE-F6EE-4528-AA0E-F647F6FE4342}: [DhcpNameServer] 192.168.0.254 192.168.1.1

Internet Explorer:
==================
HKU\S-1-5-21-1506385281-2691020431-3212168025-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENN
SearchScopes: HKU\S-1-5-21-1506385281-2691020431-3212168025-1001 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={s ... lz=1I7LENN
SearchScopes: HKU\S-1-5-21-1506385281-2691020431-3212168025-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={s ... lz=1I7LENN
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-07-25] (Oracle Corporation)
BHO-x32: Pomocná služba pro přihlášení k účtu Microsoft -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-07-25] (Oracle Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll [2015-07-18] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [No File]
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-18] ()
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-03] (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.1.7 -> C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll [2013-05-30] (ESN Social Software AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-07-19] (VideoLAN)
FF Plugin HKU\S-1-5-21-1506385281-2691020431-3212168025-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2016-08-07] ()
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird => not found

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENN
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/","hxxp://google.cz/"
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.8.885\_platform_specific\win_x86\widevinecdmadapter.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\PepperFlash\22.0.0.209\pepflashplayer.dll => No File
CHR Profile: C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Lounge Assistant) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\enjonnlehciedbcidabdglnnihcncbml [2014-12-07]
CHR Extension: (AdBlock) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-08-25]
CHR Extension: (Převod měn) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\kjehaadplpgckpgeoddpnijogjaldela [2014-08-29]
CHR Extension: (Twitch Now) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlmbdmpjmlijibeockamioakdpmhjnpk [2016-07-25]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR Extension: (Oddshot) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\olnoeeagkgpkplnhmnnlgodjnjgckhja [2016-09-08]
CHR Extension: (Chrome Media Router) - C:\Users\Tom\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-09-07]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1860616 2016-04-05] ()
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [970016 2011-05-12] (Broadcom Corporation.)
R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2520928 2016-03-03] (ESET)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1163712 2016-06-14] (NVIDIA Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-02] ()
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-06-14] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [3632576 2016-06-14] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2521024 2016-06-14] (NVIDIA Corporation)
S3 Origin Client Service; E:\GAMES\Origin\OriginClientService.exe [2119688 2016-04-20] (Electronic Arts)
R2 PnkBstrA; C:\windows\SysWOW64\PnkBstrA.exe [75136 2014-11-18] ()
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [292568 2014-12-11] (Realtek Semiconductor)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2013-04-18] (LG Electronics Inc.) [File not signed]
R3 BTWDPAN; C:\Windows\System32\DRIVERS\btwdpan.sys [89640 2011-05-13] (Broadcom Corporation.)
R3 DelayMan; C:\Windows\System32\DRIVERS\delayman.sys [20064 2012-05-19] (Ensurebit Inc.)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [264552 2016-04-14] (ESET)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [186784 2016-04-14] (ESET)
R2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [170792 2016-04-14] (ESET)
R3 LgBttPort; C:\Windows\System32\DRIVERS\lgbtpt64.sys [16384 2009-09-29] (LG Electronics Inc.)
R3 lgbusenum; C:\Windows\System32\DRIVERS\lgbtbs64.sys [14848 2009-09-29] (LG Electronics Inc.)
R3 LGVMODEM; C:\Windows\System32\DRIVERS\lgvmdm64.sys [17408 2009-09-29] (LG Electronics Inc.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [26560 2016-06-14] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [56384 2016-04-14] (NVIDIA Corporation)
R3 SPUVCbv; C:\Windows\System32\Drivers\usbvideo.sys [185344 2013-07-12] (Microsoft Corporation)
R1 winioex; C:\Windows\System32\drivers\winioex.sys [15456 2012-05-19] (Ensurebit Inc.)
S3 XSplit_Dummy; C:\Windows\System32\drivers\xspltspk.sys [26200 2015-05-26] (SplitmediaLabs Limited)
R3 ALSysIO; \??\C:\Users\Tom\AppData\Local\Temp\ALSysIO64.sys [X]
S3 CtClsFlt; system32\DRIVERS\CtClsFlt.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-09-11 09:41 - 2016-09-11 09:41 - 00015861 _____ C:\Users\Tom\Desktop\FRST.txt
2016-09-11 09:40 - 2016-09-11 09:41 - 00000000 ____D C:\FRST
2016-09-11 09:38 - 2016-09-11 09:38 - 02397696 _____ (Farbar) C:\Users\Tom\Desktop\FRST64.exe
2016-09-11 09:38 - 2016-09-11 09:38 - 00112640 _____ (forum.viry.cz) C:\Users\Tom\Downloads\Nepotvrzeno 976299.crdownload
2016-09-10 17:05 - 2016-09-10 17:05 - 00001158 _____ C:\Users\Tom\Desktop\mbamlog.txt
2016-09-10 12:24 - 2016-09-10 12:26 - 00192216 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2016-09-10 12:24 - 2016-09-10 12:24 - 00001106 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-09-10 12:23 - 2016-09-10 12:24 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-09-10 12:23 - 2016-03-10 14:09 - 00064896 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2016-09-10 12:23 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamchameleon.sys
2016-09-10 12:23 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
2016-09-10 12:22 - 2016-09-10 12:23 - 22851472 _____ (Malwarebytes ) C:\Users\Tom\Downloads\mbam-setup-2.2.1.1043.exe
2016-09-10 12:09 - 2016-09-10 12:09 - 00001834 _____ C:\Users\Tom\Desktop\kázání – zástupce.lnk
2016-09-10 12:09 - 2016-09-10 12:09 - 00001778 _____ C:\Users\Tom\Desktop\filmy – zástupce.lnk
2016-09-10 11:45 - 2016-09-10 11:45 - 00002123 _____ C:\Users\Tom\Desktop\Lewis Clive Staples knihy – zástupce.lnk
2016-09-10 11:44 - 2016-09-10 11:44 - 00002101 _____ C:\Users\Tom\Desktop\Motoscuk 2016 lucký vrch – zástupce.lnk
2016-09-10 11:44 - 2016-09-10 11:44 - 00002075 _____ C:\Users\Tom\Desktop\Brno motodrom 6.7.2015 – zástupce.lnk
2016-09-10 11:44 - 2016-09-10 11:44 - 00001954 _____ C:\Users\Tom\Desktop\Složky z plochy – zástupce.lnk
2016-09-10 11:44 - 2016-09-10 11:44 - 00001921 _____ C:\Users\Tom\Desktop\Absolutorium – zástupce.lnk
2016-09-10 11:44 - 2016-09-10 11:44 - 00001864 _____ C:\Users\Tom\Desktop\alenka BT – zástupce.lnk
2016-09-10 11:44 - 2016-09-10 11:44 - 00001861 _____ C:\Users\Tom\Desktop\Oldtimer – zástupce.lnk
2016-09-10 11:44 - 2016-09-10 11:44 - 00001834 _____ C:\Users\Tom\Desktop\TOPGEAR – zástupce.lnk
2016-09-10 11:44 - 2016-09-10 11:44 - 00001827 _____ C:\Users\Tom\Desktop\zdenka – zástupce.lnk
2016-09-10 11:30 - 2016-09-10 11:30 - 00001819 _____ C:\Users\Tom\Desktop\Škola – zástupce.lnk
2016-09-10 10:15 - 2016-09-10 10:18 - 00000000 ____D C:\AdwCleaner
2016-09-10 10:12 - 2016-09-10 10:12 - 00001204 _____ C:\Users\Tom\Desktop\CrystalDiskInfo.lnk
2016-09-10 10:12 - 2016-09-10 10:12 - 00000000 ____D C:\Program Files (x86)\CrystalDiskInfo
2016-09-10 10:09 - 2016-09-10 10:09 - 11407001 _____ C:\Users\Tom\Downloads\CrystalDiskInfo7_0_3-en.exe
2016-09-10 10:09 - 2016-09-10 10:09 - 03826240 _____ C:\Users\Tom\Downloads\adwcleaner_6.010.exe
2016-09-08 19:14 - 2016-09-08 19:14 - 01222144 _____ C:\Users\Tom\Downloads\RSITx64.exe
2016-09-08 19:14 - 2016-09-08 19:14 - 00000000 ____D C:\rsit
2016-09-05 17:22 - 2016-09-05 17:22 - 00000000 ____D C:\windows\SysWOW64\NV
2016-09-05 17:22 - 2016-09-05 17:22 - 00000000 ____D C:\windows\system32\NV
2016-09-05 17:22 - 2016-05-04 04:23 - 00129824 _____ C:\windows\SysWOW64\vulkan-1.dll
2016-09-05 17:22 - 2016-05-04 04:22 - 00130848 _____ C:\windows\system32\vulkan-1.dll
2016-09-05 17:22 - 2016-05-04 04:22 - 00045344 _____ C:\windows\system32\vulkaninfo.exe
2016-09-05 17:22 - 2016-05-04 04:22 - 00040224 _____ C:\windows\SysWOW64\vulkaninfo.exe
2016-09-05 17:19 - 2016-08-26 01:28 - 40070200 _____ C:\windows\system32\nvcompiler.dll
2016-09-05 17:19 - 2016-08-26 01:28 - 35182648 _____ C:\windows\SysWOW64\nvcompiler.dll
2016-09-05 17:19 - 2016-08-26 01:28 - 34801088 _____ (NVIDIA Corporation) C:\windows\system32\nvoglv64.dll
2016-09-05 17:19 - 2016-08-26 01:28 - 28207672 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvoglv32.dll
2016-09-05 17:19 - 2016-08-26 01:28 - 19848080 _____ (NVIDIA Corporation) C:\windows\system32\nvwgf2umx.dll
2016-09-05 17:19 - 2016-08-26 01:28 - 17463088 _____ (NVIDIA Corporation) C:\windows\system32\nvd3dumx.dll
2016-09-05 17:19 - 2016-08-26 01:28 - 17263792 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvwgf2um.dll
2016-09-05 17:19 - 2016-08-26 01:28 - 14352816 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvd3dum.dll
2016-09-05 17:19 - 2016-08-26 01:28 - 14093368 _____ (NVIDIA Corporation) C:\windows\system32\Drivers\nvlddmkm.sys
2016-09-05 17:19 - 2016-08-26 01:28 - 10865704 _____ C:\windows\system32\nvptxJitCompiler.dll
2016-09-05 17:19 - 2016-08-26 01:28 - 10737632 _____ (NVIDIA Corporation) C:\windows\system32\nvopencl.dll
2016-09-05 17:19 - 2016-08-26 01:28 - 10278080 _____ (NVIDIA Corporation) C:\windows\system32\nvcuda.dll
2016-09-05 17:19 - 2016-08-26 01:28 - 09086856 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvopencl.dll
2016-09-05 17:19 - 2016-08-26 01:28 - 08875408 _____ C:\windows\SysWOW64\nvptxJitCompiler.dll
2016-09-05 17:19 - 2016-08-26 01:28 - 08680696 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuda.dll
2016-09-05 17:19 - 2016-08-26 01:28 - 03594808 _____ (NVIDIA Corporation) C:\windows\system32\nvcuvid.dll
2016-09-05 17:19 - 2016-08-26 01:28 - 03160512 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuvid.dll
2016-09-05 17:19 - 2016-08-26 01:28 - 01920960 _____ (NVIDIA Corporation) C:\windows\system32\nvdispco6437270.dll
2016-09-05 17:19 - 2016-08-26 01:28 - 01586744 _____ (NVIDIA Corporation) C:\windows\system32\nvdispgenco6437270.dll
2016-09-05 17:19 - 2016-08-26 01:28 - 01019960 _____ (NVIDIA Corporation) C:\windows\system32\NvFBC64.dll
2016-09-05 17:19 - 2016-08-26 01:28 - 00956352 _____ (NVIDIA Corporation) C:\windows\SysWOW64\NvFBC.dll
2016-09-05 17:19 - 2016-08-26 01:28 - 00941504 _____ (NVIDIA Corporation) C:\windows\system32\NvIFR64.dll
2016-09-05 17:19 - 2016-08-26 01:28 - 00892864 _____ (NVIDIA Corporation) C:\windows\SysWOW64\NvIFR.dll
2016-09-05 17:19 - 2016-08-26 01:28 - 00686896 _____ C:\windows\system32\nvfatbinaryLoader.dll
2016-09-05 17:19 - 2016-08-26 01:28 - 00575984 _____ C:\windows\SysWOW64\nvfatbinaryLoader.dll
2016-09-05 17:19 - 2016-08-26 01:28 - 00153368 _____ (NVIDIA Corporation) C:\windows\system32\nvoglshim64.dll
2016-09-05 17:19 - 2016-08-26 01:28 - 00131536 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvoglshim32.dll
2016-09-05 17:19 - 2016-08-26 01:28 - 00039992 _____ (NVIDIA Corporation) C:\windows\system32\Drivers\nvpciflt.sys
2016-09-05 16:23 - 2016-09-05 16:23 - 00311920 _____ C:\windows\Minidump\090516-40232-01.dmp
2016-09-05 16:22 - 2016-09-05 16:22 - 608917082 _____ C:\windows\MEMORY.DMP
2016-09-01 20:16 - 2016-09-01 20:16 - 00000000 ____D C:\Users\Tom\Downloads\Nová složka
2016-08-25 17:57 - 2016-08-25 17:57 - 00039949 _____ C:\Users\Tom\Downloads\Top.Gear.Extra.Gear.S01E05.cz.srt
2016-08-25 17:57 - 2016-08-25 17:57 - 00034332 _____ C:\Users\Tom\Downloads\Top.Gear.Extra.Gear.S01E06.cz.srt
2016-08-25 17:56 - 2016-08-25 17:56 - 00040328 _____ C:\Users\Tom\Downloads\Top.Gear.Extra.Gear.S01E03.cz.srt
2016-08-25 17:56 - 2016-08-25 17:56 - 00037768 _____ C:\Users\Tom\Downloads\Top.Gear.Extra.Gear.S01E04.cz.srt
2016-08-25 17:56 - 2016-08-25 17:56 - 00036512 _____ C:\Users\Tom\Downloads\Top.Gear.Extra.Gear.S01E02.cz.srt
2016-08-23 17:04 - 2016-08-23 17:04 - 00077753 _____ C:\Users\Tom\Downloads\Top.Gear.S23E06.cz.srt
2016-08-23 17:03 - 2016-08-23 17:03 - 00082428 _____ C:\Users\Tom\Downloads\Top.Gear.S23E05.cz.srt
2016-08-23 17:03 - 2016-08-23 17:03 - 00081883 _____ C:\Users\Tom\Downloads\Top.Gear.S23E04.cz.srt
2016-08-23 17:03 - 2016-08-23 17:03 - 00080363 _____ C:\Users\Tom\Downloads\Top.Gear.S23E02.cz.srt
2016-08-23 17:03 - 2016-08-23 17:03 - 00077761 _____ C:\Users\Tom\Downloads\Top.Gear.S23E03.cz.srt
2016-08-23 14:55 - 2016-08-26 01:28 - 00039731 _____ C:\windows\system32\nvinfo.pb
2016-08-23 14:55 - 2016-08-11 16:31 - 01922616 _____ (NVIDIA Corporation) C:\windows\system32\nvdispco6437254.dll
2016-08-23 14:55 - 2016-08-11 16:31 - 01586744 _____ (NVIDIA Corporation) C:\windows\system32\nvdispgenco6437254.dll
2016-08-23 14:55 - 2016-08-11 16:31 - 00000669 _____ C:\windows\SysWOW64\nv-vk32.json
2016-08-23 14:55 - 2016-08-11 16:31 - 00000669 _____ C:\windows\system32\nv-vk64.json
2016-08-23 14:47 - 2016-07-08 17:32 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2016-08-23 14:47 - 2016-07-08 17:16 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-09-11 09:36 - 2012-09-17 21:01 - 00000000 ____D C:\Users\Tom\AppData\Roaming\vlc
2016-09-11 09:03 - 2009-07-14 06:45 - 00028928 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-09-11 09:03 - 2009-07-14 06:45 - 00028928 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-09-11 09:01 - 2012-05-19 04:13 - 00669070 _____ C:\windows\system32\perfh005.dat
2016-09-11 09:01 - 2012-05-19 04:13 - 00141696 _____ C:\windows\system32\perfc005.dat
2016-09-11 09:01 - 2009-07-14 07:13 - 01584368 _____ C:\windows\system32\PerfStringBackup.INI
2016-09-11 09:01 - 2009-07-14 05:20 - 00000000 ____D C:\windows\inf
2016-09-11 08:55 - 2016-07-29 13:41 - 00000948 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-09-11 08:55 - 2012-05-19 13:36 - 00214396 _____ C:\windows\system32\fastboot.set
2016-09-11 08:54 - 2009-07-14 07:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2016-09-10 22:29 - 2015-02-01 12:57 - 00000000 ____D C:\Users\Tom\Documents\Euro Truck Simulator 2
2016-09-10 21:46 - 2016-07-29 13:41 - 00000952 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-09-10 21:03 - 2012-09-07 09:08 - 00000000 ____D C:\Users\Tom\AppData\Roaming\Skype
2016-09-10 15:10 - 2014-12-22 13:03 - 00000000 ____D C:\Users\Tom\AppData\Roaming\TS3Client
2016-09-10 12:23 - 2013-09-01 09:34 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-09-08 19:48 - 2012-05-19 13:35 - 00002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-09-08 19:14 - 2013-08-30 23:13 - 00000000 ____D C:\Program Files\trend micro
2016-09-07 20:44 - 2015-04-15 17:45 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-09-07 20:44 - 2012-09-07 09:08 - 00000000 ____D C:\ProgramData\Skype
2016-09-07 18:31 - 2015-12-26 23:26 - 00000000 ____D C:\Users\Tom\AppData\Local\CrashDumps
2016-09-05 17:22 - 2012-05-19 12:47 - 00000000 ____D C:\ProgramData\NVIDIA
2016-09-05 16:23 - 2013-09-20 15:20 - 00000000 ____D C:\windows\Minidump
2016-09-05 15:42 - 2012-08-29 12:40 - 00000000 ____D C:\Users\Tom\Documents\Youcam
2016-08-30 19:44 - 2012-09-19 07:51 - 00000000 ____D C:\Program Files (x86)\Adobe
2016-08-26 01:28 - 2016-06-26 13:25 - 03917512 _____ (NVIDIA Corporation) C:\windows\system32\nvapi64.dll
2016-08-26 01:28 - 2016-06-26 13:25 - 03456888 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvapi.dll
2016-08-26 01:28 - 2016-06-26 13:25 - 00493608 _____ (NVIDIA Corporation) C:\windows\system32\nvumdshimx.dll
2016-08-26 01:28 - 2016-06-26 13:25 - 00408784 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvumdshim.dll
2016-08-26 01:28 - 2016-06-26 13:25 - 00181488 _____ (NVIDIA Corporation) C:\windows\system32\nvinitx.dll
2016-08-26 01:28 - 2016-06-26 13:25 - 00159352 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvinit.dll
2016-08-25 23:10 - 2016-06-26 13:34 - 06385720 _____ (NVIDIA Corporation) C:\windows\system32\nvcpl.dll
2016-08-25 23:10 - 2016-06-26 13:34 - 02475064 _____ (NVIDIA Corporation) C:\windows\system32\nvsvc64.dll
2016-08-25 23:10 - 2016-06-26 13:34 - 01764408 _____ (NVIDIA Corporation) C:\windows\system32\nvsvcr.dll
2016-08-25 23:10 - 2016-06-26 13:34 - 01362368 _____ (NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
2016-08-25 23:10 - 2016-06-26 13:34 - 00548408 _____ (NVIDIA Corporation) C:\windows\system32\nv3dappshext.dll
2016-08-25 23:10 - 2016-06-26 13:34 - 00393784 _____ (NVIDIA Corporation) C:\windows\system32\nvmctray.dll
2016-08-25 23:10 - 2016-06-26 13:34 - 00144832 _____ (NVIDIA Corporation) C:\windows\SysWOW64\oemdspif.dll
2016-08-25 23:10 - 2016-06-26 13:34 - 00081856 _____ (NVIDIA Corporation) C:\windows\system32\nv3dappshextr.dll
2016-08-25 23:10 - 2016-06-26 13:34 - 00071224 _____ (NVIDIA Corporation) C:\windows\system32\nvshext.dll
2016-08-25 19:34 - 2009-07-14 05:20 - 00000000 ____D C:\windows\rescache
2016-08-22 17:18 - 2016-06-26 13:34 - 07320235 _____ C:\windows\system32\nvcoproc.bin
2016-08-13 11:03 - 2013-01-25 17:32 - 00000000 ____D C:\Users\Tom\AppData\Roaming\Audacity
2016-08-13 10:56 - 2015-07-25 14:48 - 00000000 ____D C:\Users\Tom\AppData\Roaming\OBS

==================== Files in the root of some directories =======

2015-02-19 09:32 - 2015-11-06 15:06 - 0008192 _____ () C:\Users\Tom\AppData\Roaming\records_db
2014-05-07 16:58 - 2014-05-07 16:59 - 0005120 _____ () C:\Users\Tom\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-05-27 13:30 - 2014-05-27 13:30 - 0004096 ____H () C:\Users\Tom\AppData\Local\keyfile3.drm
2014-10-31 14:06 - 2014-10-31 14:06 - 0029696 _____ () C:\Users\Tom\AppData\Local\MSGBOX.EXE
2012-08-28 23:38 - 2012-08-28 23:38 - 0001567 _____ () C:\Users\Tom\AppData\Local\PDLSetup.20120828.233811.txt
2012-09-03 15:07 - 2012-09-03 15:07 - 0001541 _____ () C:\Users\Tom\AppData\Local\PDLSetup.20120903.150709.txt
2012-10-31 12:48 - 2012-10-31 12:48 - 0001541 _____ () C:\Users\Tom\AppData\Local\PDLSetup.20121031.114803.txt
2013-10-06 13:05 - 2016-04-26 15:10 - 0007601 _____ () C:\Users\Tom\AppData\Local\Resmon.ResmonCfg
2014-05-19 15:50 - 2014-05-19 16:31 - 0001061 _____ () C:\ProgramData\LmeUSB.log
2014-05-19 15:50 - 2014-05-19 16:31 - 0001060 _____ () C:\ProgramData\LSDmbTH.log

Some files in TEMP:
====================
C:\Users\Tom\AppData\Local\Temp\BSvcProcessor.exe
C:\Users\Tom\AppData\Local\Temp\BSvcUpdater.exe
C:\Users\Tom\AppData\Local\Temp\libeay32.dll
C:\Users\Tom\AppData\Local\Temp\msvcr120.dll
C:\Users\Tom\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Tom\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\SysWOW64\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-09-05 18:02

==================== End of FRST.txt ============================
Addition.rar
(13.01 KiB) Staženo 69 x

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o kontrolu, děkuji

#8 Příspěvek od Márty84 »

:arrow: Otevrete si poznamkovy blok a zkopirujte do nej tento skript

Kód: Vybrat vše

Start
CloseProcesses:
CreateRestorePoint:

HKU\S-1-5-21-1506385281-2691020431-3212168025-1001\...\Run: [BingSvc] => C:\Users\Tom\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-05] (© 2015 Microsoft Corporation)

Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-06-25 82128]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31 144200]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2016-05-23 324224]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31 144200]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2014-01-06 136120]

Hosts:
EmptyTemp:
Reboot:
End
Vlevo nahore kliknete na napis Soubor
Kliknete na napis Ulozit jako...
Napiste spravne ten cerveny nazev fixlist a ulozte na plochu.
Vypnete antivir i dalsi pripadne zabezpeceni.
Spustte FRST jako spravce, kliknete na napis Fix a program vykona prikazy.
Po restartu pc by se mel objevit novy log - s nazvem fixlog, ten mi sem zase zkopirujte.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

tomik258
Návštěvník
Návštěvník
Příspěvky: 100
Registrován: 04 kvě 2009 17:53

Re: Prosím o kontrolu, děkuji

#9 Příspěvek od tomik258 »

výsledek zde :)

Fix result of Farbar Recovery Scan Tool (x64) Version: 31-08-2016
Ran by Tom (11-09-2016 17:26:02) Run:1
Running from C:\Users\Tom\Desktop
Loaded Profiles: Tom (Available Profiles: Tom)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:

HKU\S-1-5-21-1506385281-2691020431-3212168025-1001\...\Run: [BingSvc] => C:\Users\Tom\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-05] (© 2015 Microsoft Corporation)

Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-06-25 82128]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31 144200]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2016-05-23 324224]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31 144200]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2014-01-06 136120]

Hosts:
EmptyTemp:
Reboot:
End

*****************

Processes closed successfully.
Restore point was successfully created.
HKU\S-1-5-21-1506385281-2691020431-3212168025-1001\Software\Microsoft\Windows\CurrentVersion\Run\\BingSvc => value removed successfully
C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully
C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully
AdobeARMservice => service removed successfully
gupdate => service removed successfully
SkypeUpdate => service removed successfully
gupdatem => service removed successfully
gusvc => service removed successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 35993239 B
Java, Flash, Steam htmlcache => 343561290 B
Windows/system/drivers => 1391703 B
Edge => 0 B
Chrome => 791990723 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 128 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 30244 B
UpdatusUser => 0 B
Tom => 172442041 B
UpdatusUser => 0 B

RecycleBin => 0 B
EmptyTemp: => 1.3 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 17:26:38 ====

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o kontrolu, děkuji

#10 Příspěvek od Márty84 »

:!: Vsechny tyto programy - vcetne pripadne instalace - spoustejte jako spravce (kliknete na ne pravym mysidlem a zvolte - Spustit jako spravce)

:arrow:
vyosek píše: :arrow: DelFix https://toolslib.net/downloads/finish/2/
  • Stahnete a spustte
  • Ponechte zatrzitkou pouze u volby Remove disinfection tools
  • Kliknete na Run
:arrow: Stahnete Ccleaner http://www.filehippo.com/download_ccleaner a spustte.
Pri instalaci pozor na toolbar (ci jine doplnky), jestli vam nabidne jeho instalaci, tak zruste zatrzitko.
Po spusteni se ocitnete ve funkci Cistic. Vlevo je spousta zatrzitek. Pozor dejte hlavne na kos, pokud nechate zatrzene, vzdy ho vysype.
Dale, podle toho jak je nastaven, smaze vsechna hesla ulozena na netu!!! Takze jestli mate nastavene, at si pocitac hesla pamatuje (coz neni pro bezpecnost dobre), budete je muset pak napsat znova rucne (napr mail, facebook, ruzna fora atd.)
Kliknete na Analyzovat a az dokonci analyzu, kliknete na Spustit Cleaner.
Potom kliknete vlevo na funkci Registry
Kliknete na Hledej problemy, kdyz najde, kliknete na Opravit problemy. Nabidne Vam zalohu, tu udelejte a ulozte ji tak, at ji v pripade potreby najdete.
Funkce Nastroje umoznuje odinstalovani programu. Je dukladnejsi nez samotny windows!
(Pokud je v pc vice uzivatelskych uctu, pouzijte program i v nich)

:arrow: Defragmentujte disk(y) (SSD Disky ne!)
Stahnete program Defraggler https://www.piriform.com/defraggler/download/standard
Pri instalaci opet pozor na toolbar a dalsi nesmysly.
Po nainstalovani program spustte a kliknete na Analyzovat, po analyze kliknete na Defragmentovat a programek odvede svou praci.




:arrow: Pak napiste, jak to s pc vypada.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

tomik258
Návštěvník
Návštěvník
Příspěvky: 100
Registrován: 04 kvě 2009 17:53

Re: Prosím o kontrolu, děkuji

#11 Příspěvek od tomik258 »

tak chová se celkem standartně, problémy nebyly, šlo vyloženě o preventivku :) budu spíš sledovat ty starty.
Crystal disk a MBAM mužu odinstalovat? A defragmentace mi smysl když je fragmentováno 10 a více procent?

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o kontrolu, děkuji

#12 Příspěvek od Márty84 »

tomik258 píše:Crystal disk a MBAM
Ano
tomik258 píše:A defragmentace mi smysl když je fragmentováno 10 a více procent?
Defragmentaci provedte. Psal jste, ze disk mel nejaky problem, takze defragmentace ho aspon taky proveri.

Jinak logy vypadaji ciste. Starty sledujte, ale i kdyby to zlobilo, pres forum to asi nevyresime. Uvidime, snad to pobezi bez potizi :-)
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

tomik258
Návštěvník
Návštěvník
Příspěvky: 100
Registrován: 04 kvě 2009 17:53

Re: Prosím o kontrolu, děkuji

#13 Příspěvek od tomik258 »

Děkuji mnohokráte za pomoc, stejně tak i celému týmu forum.viry.cz! :thumbsup:

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o kontrolu, děkuji

#14 Příspěvek od Márty84 »

Nemate zac! :)

Tema necham par dnu otevrene. Dejte vedet, jak to slape.

Zatim se mejte :bye:
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

tomik258
Návštěvník
Návštěvník
Příspěvky: 100
Registrován: 04 kvě 2009 17:53

Re: Prosím o kontrolu, děkuji

#15 Příspěvek od tomik258 »

Tak to ještě otevřu :?: teď jsem zapnul NTB po 1 dni co odpočíval (baterka ven, odpojen od sítě), tak jsem ho zapnul v posteli, odinstaloval MBAM a crystaldisk. Spustil obvyklé programy (jmenovitě chrome, steam, a ješte skype) v prohlížeči jsem se díval na streamované video, ve vysoké kvalitě, to NTB vždycky trochu topí, nicméně po zavření záložky topil pořád a stále, za půl hodinky vycucal skoro polovinu baterie. Procesor jel 25-30%, chrome mi žere hlavně RAMku, s procákem psí kusy nedělá. Tak jsem vše povypinal a zrestartoval. Po restartu vše v pořádku, zapnul jsem všechny programy co minule a sledoval změny. Nic se nedělo, 6 záložek ve chromu, procák idloval mezi 5-9% zatížení. No po chvilce to vyskočilo znovu na 30% a drží se tak doted, vypnutí aplikací nepomůže (dříve vypnutí chromu a spadlo to do 2-7%)

Logfile of random's system information tool 1.10 (written by random/random)
Run by Tom at 2016-09-14 20:37:36
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 183 GB (44%) free of 420 GB
Total RAM: 6088 MB (58% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:37:41, on 14.9.2016
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18427)
Boot mode: Normal

Running processes:
C:\Users\Tom\Downloads\Core Temp.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe
C:\windows\SysWOW64\RunDll32.exe
C:\Program Files\Lenovo\Bluetooth Software\Bluetooth Headset Helper.exe
C:\Program Files\trend micro\Tom.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.2.2:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [YouCam Mirage] "C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe"
O4 - HKLM\..\Run: [YouCam Tray] "C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe" /s
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/f ... wflash.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: C:\windows\SysWOW64\nvinit.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Network Service (NvStreamNetworkSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\windows\system32\nvvsvc.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - E:\GAMES\Origin\OriginClientService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10432 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
winlogon.exe
"C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe"
"C:\windows\system32\nvvsvc.exe"
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs

C:\windows\system32\svchost.exe -k GPSvcGroup
"C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SRSPS
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\WLANExt.exe 30037856
\??\C:\windows\system32\conhost.exe "-1133973297-665304757476391674-1927299834-267473162-537964453-64664680193524490
taskeng.exe {AB4B868A-F764-4F1C-9FC3-B489BD2CE2CA}
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe"
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe -first
C:\windows\System32\svchost.exe -k utcsvc
"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe"
C:\windows\SysWOW64\PnkBstrA.exe
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
C:\windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 2572
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe"
C:\windows\system32\wbem\unsecapp.exe -Embedding
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\svchost.exe -k bthsvcs
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"taskhost.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe" serviceapp
\??\C:\windows\system32\conhost.exe "-956895744520217820-2063541616-15167343301775701077-1240073852141661885-922833302
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\windows\system32\Dwm.exe"
taskeng.exe {0900C03D-56DF-467D-8B96-7DA341E6C624}
C:\windows\Explorer.EXE
"C:\Users\Tom\Downloads\Core Temp.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PAN Tray
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\utility.exe"
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /LENOVO_DOLBYDRAGON
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /LENOVO_MICPKEY
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe"
C:\windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1"
C:\windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe"
"C:\windows\SysWOW64\RunDll32.exe" "C:\Program Files\Lenovo\Bluetooth Software\SysWOW64\BtMmHook.dll",SetAndWaitBtMmHook
"C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe" -Embedding
"C:\Program Files\Lenovo\Bluetooth Software\Bluetooth Headset Helper.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
C:\windows\system32\svchost.exe -k SDRSVC
C:\windows\system32\DllHost.exe /Processid:{B366DEBE-645B-43A5-B865-DDD82C345492}
"C:\windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
"C:\Users\Tom\Desktop\RSITx64.exe"
C:\windows\system32\wbem\wmiprvse.exe

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-07-25 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení k účtu Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-07-25 171944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2014-12-11 13776088]
"IntelPAN"=C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [2011-05-02 1935120]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2011-10-28 2841896]
"OnekeyStudio"=C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe [2012-05-19 789920]
"Lenovo EE Boot Optimizer"=C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [2012-05-19 206176]
"Energy Management"=C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [2012-05-19 9753024]
"EnergyUtility"=C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [2012-05-19 5908928]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2016-06-14 2397120]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2013-11-07 171992]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2013-11-07 399832]
"Persistence"=C:\windows\system32\igfxpers.exe [2013-11-07 442328]
"RtHDVBg_LENOVO_DOLBYDRAGON"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-12-11 1391472]
"RtHDVBg_LENOVO_MICPKEY"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-12-11 1391472]
"ShadowPlay"=C:\windows\system32\nvspcap64.dll [2016-06-14 1767944]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeriFaceManager]
C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe [2012-05-19 329056]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2011-01-12 283160]
"YouCam Mirage"=C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [2011-01-29 136488]
"YouCam Tray"=C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [2011-01-29 228448]
"amd_dc_opt"=C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [2008-07-22 77824]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\windows\system32\nvinitx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2013-11-07 442880]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux2"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux3"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux4"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"aux5"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"aux6"=wdmaud.drv
"wave9"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer9"=wdmaud.drv
"aux7"=wdmaud.drv
"aux8"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux9"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-09-14 20:37:36 ----D---- C:\rsit
2016-09-05 17:22:34 ----D---- C:\windows\SYSWOW64\NV
2016-09-05 17:22:34 ----D---- C:\windows\system32\NV
2016-09-05 17:22:24 ----A---- C:\windows\system32\vulkaninfo.exe
2016-09-05 17:22:23 ----A---- C:\windows\system32\vulkan-1.dll
2016-09-05 17:22:22 ----A---- C:\windows\SYSWOW64\vulkaninfo.exe
2016-09-05 17:22:21 ----A---- C:\windows\SYSWOW64\vulkan-1.dll
2016-09-05 17:19:35 ----A---- C:\windows\SYSWOW64\nvwgf2um.dll
2016-09-05 17:19:35 ----A---- C:\windows\SYSWOW64\nvptxJitCompiler.dll
2016-09-05 17:19:35 ----A---- C:\windows\SYSWOW64\nvopencl.dll
2016-09-05 17:19:35 ----A---- C:\windows\SYSWOW64\nvoglv32.dll
2016-09-05 17:19:35 ----A---- C:\windows\SYSWOW64\nvoglshim32.dll
2016-09-05 17:19:35 ----A---- C:\windows\SYSWOW64\NvIFR.dll
2016-09-05 17:19:35 ----A---- C:\windows\SYSWOW64\NvFBC.dll
2016-09-05 17:19:35 ----A---- C:\windows\SYSWOW64\nvfatbinaryLoader.dll
2016-09-05 17:19:35 ----A---- C:\windows\SYSWOW64\nvd3dum.dll
2016-09-05 17:19:35 ----A---- C:\windows\SYSWOW64\nvcuvid.dll
2016-09-05 17:19:35 ----A---- C:\windows\SYSWOW64\nvcuda.dll
2016-09-05 17:19:35 ----A---- C:\windows\SYSWOW64\nvcompiler.dll
2016-09-05 17:19:35 ----A---- C:\windows\system32\nvwgf2umx.dll
2016-09-05 17:19:35 ----A---- C:\windows\system32\nvptxJitCompiler.dll
2016-09-05 17:19:35 ----A---- C:\windows\system32\nvopencl.dll
2016-09-05 17:19:35 ----A---- C:\windows\system32\nvoglv64.dll
2016-09-05 17:19:35 ----A---- C:\windows\system32\nvoglshim64.dll
2016-09-05 17:19:35 ----A---- C:\windows\system32\NvIFR64.dll
2016-09-05 17:19:35 ----A---- C:\windows\system32\NvFBC64.dll
2016-09-05 17:19:35 ----A---- C:\windows\system32\nvfatbinaryLoader.dll
2016-09-05 17:19:35 ----A---- C:\windows\system32\nvdispgenco6437270.dll
2016-09-05 17:19:35 ----A---- C:\windows\system32\nvdispco6437270.dll
2016-09-05 17:19:35 ----A---- C:\windows\system32\nvd3dumx.dll
2016-09-05 17:19:35 ----A---- C:\windows\system32\nvcuvid.dll
2016-09-05 17:19:35 ----A---- C:\windows\system32\nvcuda.dll
2016-09-05 17:19:35 ----A---- C:\windows\system32\nvcompiler.dll
2016-09-05 17:19:35 ----A---- C:\windows\system32\drivers\nvpciflt.sys
2016-09-05 17:19:35 ----A---- C:\windows\system32\drivers\nvlddmkm.sys
2016-08-23 14:55:17 ----A---- C:\windows\system32\nvdispgenco6437254.dll
2016-08-23 14:55:17 ----A---- C:\windows\system32\nvdispco6437254.dll
2016-08-23 14:47:32 ----A---- C:\windows\SYSWOW64\tzres.dll
2016-08-23 14:47:32 ----A---- C:\windows\system32\tzres.dll

======List of files/folders modified in the last 1 month======

2016-09-14 20:37:42 ----D---- C:\windows\Prefetch
2016-09-14 20:37:41 ----D---- C:\Program Files\trend micro
2016-09-14 20:37:17 ----D---- C:\Users\Tom\AppData\Roaming\Skype
2016-09-14 20:36:54 ----D---- C:\windows\Temp
2016-09-14 20:33:45 ----D---- C:\windows\system32\config
2016-09-14 20:23:34 ----D---- C:\windows\System32
2016-09-14 20:23:34 ----D---- C:\windows\inf
2016-09-14 20:23:34 ----A---- C:\windows\system32\PerfStringBackup.INI
2016-09-14 20:20:03 ----A---- C:\windows\SYSWOW64\log.txt
2016-09-14 19:44:52 ----RD---- C:\Program Files (x86)
2016-09-14 19:44:52 ----D---- C:\windows\system32\drivers
2016-09-12 19:07:44 ----D---- C:\Users\Tom\AppData\Roaming\vlc
2016-09-12 14:42:12 ----D---- C:\Windows
2016-09-11 19:12:23 ----D---- C:\windows\Minidump
2016-09-11 19:12:23 ----D---- C:\windows\debug
2016-09-11 19:11:22 ----A---- C:\DelFix.txt
2016-09-11 17:26:22 ----D---- C:\windows\Tasks
2016-09-11 17:26:22 ----D---- C:\windows\system32\drivers\etc
2016-09-11 17:26:21 ----SHD---- C:\System Volume Information
2016-09-10 15:10:17 ----D---- C:\Users\Tom\AppData\Roaming\TS3Client
2016-09-10 12:23:59 ----D---- C:\ProgramData\Malwarebytes
2016-09-09 14:40:42 ----D---- C:\windows\system32\catroot2
2016-09-07 20:44:40 ----SHD---- C:\windows\Installer
2016-09-07 20:44:33 ----RD---- C:\Program Files (x86)\Skype
2016-09-07 20:44:28 ----D---- C:\ProgramData\Skype
2016-09-06 16:29:44 ----D---- C:\windows\SysWOW64
2016-09-05 17:22:31 ----D---- C:\ProgramData\NVIDIA
2016-09-05 17:20:56 ----D---- C:\windows\system32\DriverStore
2016-08-30 19:44:37 ----D---- C:\Program Files (x86)\Adobe
2016-08-26 01:28:29 ----A---- C:\windows\SYSWOW64\nvumdshim.dll
2016-08-26 01:28:29 ----A---- C:\windows\SYSWOW64\nvinit.dll
2016-08-26 01:28:29 ----A---- C:\windows\SYSWOW64\nvapi.dll
2016-08-26 01:28:29 ----A---- C:\windows\system32\nvumdshimx.dll
2016-08-26 01:28:29 ----A---- C:\windows\system32\nvinitx.dll
2016-08-26 01:28:29 ----A---- C:\windows\system32\nvapi64.dll
2016-08-25 23:10:08 ----A---- C:\windows\system32\nvsvc64.dll
2016-08-25 23:10:08 ----A---- C:\windows\system32\nvcpl.dll
2016-08-25 23:10:06 ----A---- C:\windows\SYSWOW64\oemdspif.dll
2016-08-25 23:10:06 ----A---- C:\windows\system32\nvvsvc.exe
2016-08-25 23:10:06 ----A---- C:\windows\system32\nvsvcr.dll
2016-08-25 23:10:05 ----A---- C:\windows\system32\nvshext.dll
2016-08-25 23:10:05 ----A---- C:\windows\system32\nvmctray.dll
2016-08-25 23:10:05 ----A---- C:\windows\system32\nv3dappshextr.dll
2016-08-25 23:10:05 ----A---- C:\windows\system32\nv3dappshext.dll
2016-08-25 19:34:32 ----D---- C:\windows\rescache
2016-08-23 14:50:11 ----D---- C:\windows\winsxs
2016-08-23 14:49:32 ----D---- C:\windows\SYSWOW64\cs-CZ
2016-08-23 14:49:27 ----D---- C:\windows\system32\cs-CZ

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 fbfmon;fbfmon; C:\windows\system32\drivers\fbfmon.sys [2012-05-19 57952]
R0 fltsrv;Acronis Storage Filter Management; C:\windows\system32\DRIVERS\fltsrv.sys [2012-08-30 132704]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2011-01-12 439320]
R0 LHDmgr;LHDmgr; C:\windows\System32\DRIVERS\LhdX64.sys [2012-05-19 39008]
R0 nvpciflt;nvpciflt; C:\windows\system32\DRIVERS\nvpciflt.sys [2016-08-26 39992]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 BPntDrv;BPntDrv; C:\windows\system32\drivers\BPntDrv.sys [2012-05-19 13408]
R1 eamonm;eamonm; C:\windows\system32\DRIVERS\eamonm.sys [2016-04-14 264552]
R1 ehdrv;ehdrv; C:\windows\system32\DRIVERS\ehdrv.sys [2016-04-14 186784]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R1 winioex;winioex; C:\windows\system32\drivers\winioex.sys [2012-05-19 15456]
R2 epfwwfpr;epfwwfpr; C:\windows\system32\DRIVERS\epfwwfpr.sys [2016-04-14 170792]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver; C:\windows\system32\DRIVERS\AcpiVpc.sys [2012-05-19 29792]
R3 ALSysIO;ALSysIO; \??\C:\Users\Tom\AppData\Local\Temp\ALSysIO64.sys []
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2011-09-29 80384]
R3 BTWAMPFL;btwampfl; C:\windows\system32\DRIVERS\btwampfl.sys [2011-05-13 437288]
R3 btwaudio;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys [2011-05-13 150568]
R3 btwavdt;Bluetooth AVDT Service; C:\windows\system32\DRIVERS\btwavdt.sys [2011-05-13 164392]
R3 BTWDPAN;Bluetooth Personal Area Network; C:\windows\system32\DRIVERS\btwdpan.sys [2011-05-13 89640]
R3 btwl2cap;Bluetooth L2CAP Service; C:\windows\system32\DRIVERS\btwl2cap.sys [2011-05-13 39976]
R3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys [2011-05-13 21544]
R3 clwvd;CyberLink WebCam Virtual Driver; C:\windows\system32\DRIVERS\clwvd.sys [2011-01-29 31088]
R3 DelayMan;ACPI DelayMan Filter Service; C:\windows\system32\DRIVERS\delayman.sys [2012-05-19 20064]
R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2013-11-07 5363200]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys [2014-12-11 4351960]
R3 IntcDAud;Intel(R) Display Audio; C:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 317440]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\k57nd60a.sys [2011-05-09 425000]
R3 LgBttPort;LGE Bluetooth TransPort; C:\windows\system32\DRIVERS\lgbtpt64.sys [2009-09-29 16384]
R3 lgbusenum;LG Bluetooth Bus Enumerator; C:\windows\system32\DRIVERS\lgbtbs64.sys [2009-09-29 14848]
R3 LGVMODEM;LGE Virtual Modem; C:\windows\system32\DRIVERS\lgvmdm64.sys [2009-09-29 17408]
R3 MEIx64;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
R3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\windows\system32\DRIVERS\NETwNs64.sys [2011-05-01 8593920]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2016-06-14 26560]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\windows\system32\drivers\nvvad64v.sys [2016-04-14 56384]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 SPUVCbv;SPUVCb Driver Service; C:\windows\System32\Drivers\usbvideo.sys [2013-07-12 185344]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2011-10-28 398896]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
R3 wdkmd;Intel WiDi KMD; C:\windows\system32\DRIVERS\WDKMD.sys [2010-12-01 42392]
S3 AF15BDA;AF9015 BDA Device; C:\windows\system32\DRIVERS\AF15BDA.sys [2014-05-19 507392]
S3 AndNetDiag;LGE AndroidNet USB Serial Port; C:\windows\system32\DRIVERS\lgandnetdiag64.sys [2013-04-18 29184]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver; C:\windows\system32\DRIVERS\CtClsFlt.sys []
S3 hamachi;Hamachi Network Interface; C:\windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
S3 JMCR;JMCR; C:\windows\system32\DRIVERS\jmcr.sys [2010-12-13 174168]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
S3 sdbus;sdbus; C:\windows\system32\DRIVERS\sdbus.sys [2010-11-21 109056]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\windows\system32\DRIVERS\wdcsam64.sys [2015-04-30 23200]
S3 WinUsb;WinUsb; C:\windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
S3 wsvd;wsvd; C:\windows\system32\DRIVERS\wsvd.sys [2009-07-21 121840]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 btwdins;Bluetooth Service; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [2011-05-12 970016]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\windows\System32\svchost.exe [2009-07-14 27136]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2016-03-03 2520928]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2011-05-02 1517328]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2016-06-14 1163712]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-01-12 13336]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-12-21 325656]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2016-06-14 1879488]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2016-06-14 2521024]
R2 nvsvc;NVIDIA Display Driver Service; C:\windows\system32\nvvsvc.exe [2016-08-25 1362368]
R2 PnkBstrA;PnkBstrA; C:\windows\syswow64\PnkBstrA.exe [2014-11-18 75136]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2011-05-02 844560]
R2 RtkAudioService;Realtek Audio Service; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [2014-12-11 292568]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-21 2656280]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]
R3 NvStreamNetworkSvc;NVIDIA Streamer Network Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [2016-06-14 3632576]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2015-11-05 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2015-11-05 125112]
S3 BEService;BattlEye Service; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [2016-04-05 1860616]
S3 cphs;Intel(R) Content Protection HECI Service; C:\windows\SysWow64\IntelCpHeciSvc.exe [2013-11-07 279000]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2016-08-02 114688]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2011-05-02 340240]
S3 Origin Client Service;Origin Client Service; E:\GAMES\Origin\OriginClientService.exe [2016-04-20 2119688]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2016-08-23 1465120]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2012-08-29 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2015-11-05 51376]
S4 NetMsmqActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
S4 NetPipeActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
S4 NetTcpActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]

-----------------EOF-----------------

Zamčeno