Stránka 1 z 1

pomalý start

Napsal: 23 bře 2017 12:09
od vladypd
po asi 12min. proběhne připojení k internetu, dle ikony vpravo v liště. PC je do té doby pomalé, ale dá se pracovat. Po přihlášení do sítě je rychlost normální,
Díky

Logfile of random's system information tool 1.16 (written by random/random)
Run by spravce at 2017-03-23 12:09:14
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 174 GB (36%) free of 477 GB
Total RAM: 8080 MB (69% free)
X64

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:09:15, on 23.3.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18618)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Cobian Backup 11\cbInterface.exe
C:\Program Files (x86)\HP\HP UT\bin\hppusg.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Munis\triada.app\MunisAsm\app\MunisAsmTrayIcon.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\spravce_RSITx64.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Cobian Backup 11 interface] "C:\Program Files (x86)\Cobian Backup 11\cbInterface.exe" -service
O4 - HKLM\..\Run: [HPUsageTracking] "C:\Program Files (x86)\HP\HP UT\bin\hppusg.exe" "C:\Program Files (x86)\HP\HP UT\"
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [CtrlV.cz] "C:\Users\spravce\AppData\Local\Apps\2.0\17ZBH2T8.4E9\11DALN96.M48\test..tion_0000000000000000_0001.0000_983f02b9edcf5689\TestCtrlV.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files (x86)\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: MunisAsm.lnk = C:\Munis\triada.app\MunisAsm\app\MunisAsmTrayIcon.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O23 - Service: 602Updater (602XML Updater) - Software602 a.s. - C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ApacheTriada - Apache Software Foundation - c:\munis\triada.app\apache\bin\httpd.exe
O23 - Service: Cobian Backup 11 Stínová kopie - Requester (cbVSCService11) - CobianSoft, Luis Cobian - C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe
O23 - Service: Cobian Backup 11 Gravity (CobianBackup11) - Luis Cobian, CobianSoft - C:\Program Files (x86)\Cobian Backup 11\cbService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP LaserJet Service - HP - C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: SACSrv - SafeNet, Inc. - C:\Program Files (x86)\SafeNet\Authentication\SAC\x64\SACSrv.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Triada - Servisní služba (TriadaBootloader) - Triada, spol. s r. o. - c:\munis\triada.app\MunisAsm\bootloader\MunisBootloaderService.exe
O23 - Service: Triada - MunisAsm (TriadaMunisAsm) - Triada, spol. s r.o. - c:\munis\triada.app\MunisAsm\app\MunisAsmService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: Stínová kopie svazku (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10597 bytes

====== Enumerating Processes ======

C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"c:\munis\triada.app\apache\bin\httpd.exe" -k runservice
C:\Windows\system32\taskhost.exe
"C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\system32\igfxsrvc.exe" -Embedding
"C:\Program Files (x86)\HP\HP Color LaserJet CM2320 MFP Series\hppfaxprintersrv.exe" "HP Color LaserJet CM2320 MFP Series Fax"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\Cobian Backup 11\cbService.exe"
"C:\Program Files (x86)\SafeNet\Authentication\SAC\x64\SACMonitor.exe"
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Users\spravce\AppData\Local\Apps\2.0\17ZBH2T8.4E9\11DALN96.M48\test..tion_0000000000000000_0001.0000_983f02b9edcf5689\TestCtrlV.exe"
"C:\Program Files (x86)\Cobian Backup 11\cbInterface.exe" -service
"C:\Program Files (x86)\HP\HP UT\bin\hppusg.exe" "C:\Program Files (x86)\HP\HP UT\"
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"C:\Munis\triada.app\MunisAsm\app\MunisAsmTrayIcon.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
C:\munis\triada.app\apache\bin\httpd.exe -d C:/Munis/triada.app/apache
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe"
"C:\Program Files\Microsoft SQL Server\MSSQL10_50.TRIADA\MSSQL\Binn\sqlservr.exe" -sTRIADA
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
"C:\Program Files (x86)\SafeNet\Authentication\SAC\x64\SACSrv.exe"
"C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe"
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
"c:\munis\triada.app\MunisAsm\bootloader\MunisBootloaderService.exe"
"c:\munis\triada.app\MunisAsm\app\MunisAsmService.exe"
C:\Windows\system32\vssvc.exe
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Microsoft SQL Server\MSSQL10_50.TRIADA\MSSQL\Binn\fdlauncher.exe" -s MSSQL10_50.TRIADA
"C:\Program Files\Microsoft SQL Server\MSSQL10_50.TRIADA\MSSQL\Binn\fdhost.exe" "MSSQL10_50.TRIADAFfc3ff4dbfddbff423dfa517fd414ed62c82f15n0a" "MSSQL10_50.TRIADA" "MSSQL10_50.TRIADA" "8" "" "8192" "M" "0" "" "" ""
\??\C:\Windows\system32\conhost.exe "-90767442135062332110599348421102523215-95700383916141090571290115481-1085334138
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
C:\Windows\system32\taskeng.exe
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -contentproc --channel="5436.0.547696123\1864403500" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" 5436 "\\.\pipe\gecko-crash-server-pipe.5436" tab
C:\Windows\system32\taskeng.exe
"C:\Users\spravce\Downloads\RSITx64.exe"

====== Scheduled tasks folder ======

C:\Windows\tasks\WebReg .job - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqwrg.exe ""
C:\Windows\system32\tasks\Adobe Acrobat Update Task - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\system32\tasks\Adobe Flash Player Updater - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\system32\tasks\CreateChoiceProcessTask - C:\Windows\System32\browserchoice.exe /launch
C:\Windows\system32\tasks\CrystalDiskInfo - "C:\Program Files (x86)\CrystalDiskInfo\DiskInfo32.exe" /Startup
C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore1cf91774e7a0edd - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA1cf91774f59d037 - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\system32\tasks\{71D25AFD-9FB3-4814-BFCF-FC4A6CD353B9} - C:\Users\spravce\Downloads\dotnetfx35.exe
C:\Windows\system32\tasks\{80FA0D22-ACE5-45CB-97A5-6859F850D386} - C:\Windows\system32\pcalua.exe -a C:\Users\spravce\Desktop\kzsetupo.exe -d C:\Users\spravce\Desktop
C:\Windows\system32\tasks\{B88EA70E-2DBE-4A5F-84AD-32B44F5ADE5C} - C:\Windows\system32\pcalua.exe -a "C:\Zaloha starý počítač\install\64-bit iKey Driver v4.1.1.10 (EXE)\64-bit iKey Driver v4.1.1.10 (EXE)\iKeyDrvr64.exe" -d "C:\Zaloha starý počítač\install\64-bit iKey Driver v4.1.1.10 (EXE)\64-bit iKey Driver v4.1.1.10 (EXE)"
C:\Windows\system32\tasks\{DC3989BA-FF0D-441B-85DC-B520261A6FB1} - C:\Windows\system32\pcalua.exe -a C:\Users\spravce\Desktop\sesetupo.exe -d C:\Users\spravce\Desktop
C:\Windows\system32\tasks\{DEED8096-4E15-4790-B3F4-278A32099EBC} - C:\Windows\system32\pcalua.exe -a C:\Users\spravce\Downloads\dotnetfx35.exe -d C:\Users\spravce\Desktop
C:\Windows\system32\tasks\Microsoft\Windows Defender\MP Scheduled Scan - c:\program files\windows defender\MpCmdRun.exe Scan -ScheduleJob -WinTask -RestrictPrivilegesScan
C:\Windows\system32\tasks\Microsoft\Windows\WindowsBackup\ConfigNotification - %systemroot%\System32\sdclt.exe /CONFIGNOTIFICATION
C:\Windows\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\Windows\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\Windows\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -queuereporting
C:\Windows\system32\tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask - %SystemRoot%\system32\Wat\WatAdminSvc.exe /run
C:\Windows\system32\tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline - %SystemRoot%\system32\schtasks.exe /run /I /TN "\Microsoft\Windows\Windows Activation Technologies\ValidationTask"
C:\Windows\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\Windows\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\Windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict1 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
C:\Windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict2 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
C:\Windows\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
C:\Windows\system32\tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask - sc.exe start sppsvc
C:\Windows\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\Windows\system32\tasks\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem - %SystemRoot%\System32\powercfg.exe -energy -auto
C:\Windows\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\Windows\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService - %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks - %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ehDRMInit - %SystemRoot%\ehome\ehPrivJob.exe /DRMInit
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\InstallPlayReady - %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\mcupdate - %SystemRoot%\ehome\mcupdate $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\OCURActivate - %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\OCURDiscovery - %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscovery - %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 - %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 - %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PeriodicScanRetry - %windir%\ehome\MCUpdate.exe -pscn 0
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PvrRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PvrScheduleTask - %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\RecordingRestart - %SystemRoot%\ehome\ehrec /RestartRecording
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\RegisterSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ReindexSearchRoot - %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\UpdateRecordPath - %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotifications.exe
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\Windows\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c
C:\Windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\Windows\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\AitAgent - aitagent
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattel\DiagTrackRunner.exe /UploadEtlFilesOnly
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\compattelrunner.exe -maintenance
C:\Windows\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\Windows\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\spravce\AppData\Roaming\Mozilla\Firefox\Profiles\5vqazo7u.default

prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 25.0.0.127 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_127.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.121.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.121.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@software602.cz/602XML Filler]
"Description"=602XML Filler Plugin
"Path"=C:\Program Files (x86)\Software602\602XML\Filler\npfiller.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 25.0.0.127 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_25_0_0_127.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled


C:\Users\spravce\AppData\Roaming\Mozilla\Firefox\Profiles\5vqazo7u.default\addons.json

C:\Users\spravce\AppData\Roaming\Mozilla\Firefox\Profiles\5vqazo7u.default\extensions.json
Application Update Service Helper - extension - aushelper@mozilla.org - C:\Users\spravce\AppData\Roaming\Mozilla\Firefox\Profiles\5vqazo7u.default\features\{0efd3145-8a60-4df7-b8bd-b0507be0ef85}\aushelper@mozilla.org.xpi
Diagnostics - extension - diagnostics@mozilla.org - C:\Users\spravce\AppData\Roaming\Mozilla\Firefox\Profiles\5vqazo7u.default\features\{0efd3145-8a60-4df7-b8bd-b0507be0ef85}\diagnostics@mozilla.org.xpi
SHA-1 deprecation staged rollout - extension - disableSHA1rollout@mozilla.org - C:\Users\spravce\AppData\Roaming\Mozilla\Firefox\Profiles\5vqazo7u.default\features\{0efd3145-8a60-4df7-b8bd-b0507be0ef85}\disableSHA1rollout@mozilla.org.xpi
Send HSTS Priming Requests - extension - hsts-priming@mozilla.org - C:\Users\spravce\AppData\Roaming\Mozilla\Firefox\Profiles\5vqazo7u.default\features\{0efd3145-8a60-4df7-b8bd-b0507be0ef85}\hsts-priming@mozilla.org.xpi
Multi-process staged rollout - extension - e10srollout@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\e10srollout@mozilla.org.xpi
Pocket - extension - firefox@getpocket.com - C:\Program Files (x86)\Mozilla Firefox\browser\features\firefox@getpocket.com.xpi
Web Compat - extension - webcompat@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\webcompat@mozilla.org.xpi
Application Update Service Helper - extension - aushelper@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\aushelper@mozilla.org.xpi
Default - theme - {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi

C:\Users\spravce\AppData\Roaming\Mozilla\Firefox\Profiles\5vqazo7u.default\pluginreg.dat
Plugin - Shockwave Flash - 25.0.0.127 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_127.dll

=========Google Chrome=========

C:\Users\spravce\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Extension ahfgeienlihckogmohjhadlkjgocpleb 1 Store 0.2
Extension aohghmighlieiainnegkcijnfilokake 1 Dokumenty Google 0.9
Extension apdfllckaahabafndbhieahigkjlhalf 1 Disk Google 14.1
Extension bepbmhgboaologfdajaanbcjmnhjmhfn 0
Extension blpcfgokakmgnkcojhhkbfbldkacnbeo 1 YouTube 4.2.8
Extension coobgpohoikkiipiblmjeljniedjpjpf 1 Vyhledávání Google 0.0.0.60
Extension eemcgdkfndhakfknompkggombfjjjeno 1 Bookmark Manager 0.1
Extension ennkphjdgehloodpbhlhldgbnhmacadg Settings 0.2
Extension gfdkimpbcpahaombhbimeihdjnejgicl 1 Feedback 1.0
Extension ghbmnnjooekpmoecnnnilnnbdlolhkhi 1 Dokumenty Google offline 1.4
Extension kmendfapggjehodndflmmgagdbamhnfd 1 CryptoTokenExtension 0.9.46
Extension mfehgcgbbipciphmccgaenjidiccnmng 1 Cloud Print 0.1
Extension mgndgikekgjfcpckkfioiadnlibdjbkf Chrome 0.1
Extension mhjfbmdgcfjbbpaeojofohoefgiehjai 1 Chrome PDF Viewer 1
Extension neajdppkdcdipfabeoofebfddakdcjhd 1 Google Network Speech 1.0
Extension nkeimhogjdpnpccoofpliimaahmaaome 1 Google Hangouts 1.3.2
Extension nmmhkkegccagdldgiimedpiccmgmieda 1 Platby Internetového obchodu Chrome 1.0.0.2
Extension pafkbggdmjlpgkdkcbjmhmfcdpncadgh Google Now 1.2.0.1
Extension pjkljhegncpnkpknbcohdijeoejaedia 1 Gmail 8.1
Extension pkedcjkdefgpdelpbcmbmeomcjbeemfm 1 Chrome Media Router 5616.1121.0.3
Homepage: http://www.google.com/
default_search_provider.search_url:
C:\Users\spravce\AppData\Local\Google\Chrome\User Data\Default\Preferences
Homepage:
default_search_provider.search_url:

======Registry dump ======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={6A1806CD-94D4-4689-BA73-E35EA1EA9990}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}]
"URL"=http://www.google.com/search?q={searchT ... urceid=ie7


[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={6A1806CD-94D4-4689-BA73-E35EA1EA9990}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}]
"URL"=http://www.google.com/search?q={searchT ... urceid=ie7

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-27 255088]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-03-22 473152]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení k účtu Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-27 193136]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-03-22 186944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-27 255088]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-27 193136]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2013-05-24 407536]
"HP Color LaserJet CM2320 MFP Series Fax"=C:\Program Files (x86)\HP\HP Color LaserJet CM2320 MFP Series\hppfaxprintersrv.exe [2009-09-22 3700736]
"IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2013-04-30 36352]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2013-05-24 165872]
"Persistence"=C:\Windows\system32\igfxpers.exe [2013-05-24 444400]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2013-02-26 13423688]
"SACMonitor"=C:\Program Files (x86)\SafeNet\Authentication\SAC\x64\SACMonitor.exe [2011-01-13 1227464]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2014-01-13 39408]
"CtrlV.cz"=C:\Users\spravce\AppData\Local\Apps\2.0\17ZBH2T8.4E9\11DALN96.M48\test..tion_0000000000000000_0001.0000_983f02b9edcf5689\TestCtrlV.exe [2017-03-22 40448]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes TrayApp]
C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
""= []
"Cobian Backup 11 interface"=C:\Program Files (x86)\Cobian Backup 11\cbInterface.exe [2013-03-07 4407808]
"HPUsageTracking"=C:\Program Files (x86)\HP\HP UT\bin\hppusg.exe [2009-05-11 24576]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2013-04-26 292848]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2016-12-12 587288]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Microsoft Office.lnk - C:\Program Files (x86)\Microsoft Office\Office\OSA9.EXE
MunisAsm.lnk - C:\Munis\triada.app\MunisAsm\app\MunisAsmTrayIcon.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2013-05-17 440832]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders" = credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MBAMService]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

====== File associations ======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

====== List of files/folders created in the last 1 month ======

2017-03-23 11:19:26 ----D---- C:\rsit
2017-03-23 11:19:26 ----D---- C:\Program Files\trend micro
2017-03-22 20:02:24 ----HD---- C:\$WINDOWS.~BT
2017-03-22 19:44:43 ----D---- C:\Windows\SYSWOW64\directx
2017-03-22 11:21:04 ----D---- C:\Windows\pss
2017-03-22 11:15:16 ----A---- C:\Windows\ntbtlog.txt
2017-03-22 11:09:07 ----D---- C:\Program Files (x86)\HD Tune Pro
2017-03-15 07:42:54 ----A---- C:\Windows\SYSWOW64\occache.dll
2017-03-15 07:42:54 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2017-03-15 07:42:54 ----A---- C:\Windows\SYSWOW64\inseng.dll
2017-03-15 07:42:54 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2017-03-15 07:42:54 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2017-03-15 07:42:54 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2017-03-15 07:42:54 ----A---- C:\Windows\system32\iertutil.dll
2017-03-15 07:42:54 ----A---- C:\Windows\system32\iernonce.dll
2017-03-15 07:42:54 ----A---- C:\Windows\system32\ieetwproxystub.dll
2017-03-15 07:42:54 ----A---- C:\Windows\system32\ieetwcollector.exe
2017-03-15 07:42:54 ----A---- C:\Windows\system32\ie4uinit.exe
2017-03-15 07:42:53 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2017-03-15 07:42:53 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2017-03-15 07:42:53 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2017-03-15 07:42:53 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2017-03-15 07:42:53 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2017-03-15 07:42:53 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2017-03-15 07:42:53 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2017-03-15 07:42:53 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-03-15 07:42:53 ----A---- C:\Windows\system32\inseng.dll
2017-03-15 07:42:52 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2017-03-15 07:42:52 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2017-03-15 07:42:52 ----A---- C:\Windows\SYSWOW64\jscript.dll
2017-03-15 07:42:52 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2017-03-15 07:42:52 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2017-03-15 07:42:52 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2017-03-15 07:42:52 ----A---- C:\Windows\system32\urlmon.dll
2017-03-15 07:42:52 ----A---- C:\Windows\system32\occache.dll
2017-03-15 07:42:52 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2017-03-15 07:42:52 ----A---- C:\Windows\system32\iedkcs32.dll
2017-03-15 07:42:51 ----A---- C:\Windows\SYSWOW64\ieui.dll
2017-03-15 07:42:51 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2017-03-15 07:42:51 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2017-03-15 07:42:51 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2017-03-15 07:42:51 ----A---- C:\Windows\system32\msfeeds.dll
2017-03-15 07:42:51 ----A---- C:\Windows\system32\iesetup.dll
2017-03-15 07:42:51 ----A---- C:\Windows\system32\ieapfltr.dll
2017-03-15 07:42:51 ----A---- C:\Windows\system32\dxtrans.dll
2017-03-15 07:42:50 ----A---- C:\Windows\SYSWOW64\wininet.dll
2017-03-15 07:42:50 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2017-03-15 07:42:50 ----A---- C:\Windows\SYSWOW64\msrating.dll
2017-03-15 07:42:50 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2017-03-15 07:42:50 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2017-03-15 07:42:50 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2017-03-15 07:42:50 ----A---- C:\Windows\system32\vbscript.dll
2017-03-15 07:42:50 ----A---- C:\Windows\system32\jsproxy.dll
2017-03-15 07:42:50 ----A---- C:\Windows\system32\ieUnatt.exe
2017-03-15 07:42:49 ----A---- C:\Windows\system32\mshtmled.dll
2017-03-15 07:42:49 ----A---- C:\Windows\system32\ieui.dll
2017-03-15 07:42:49 ----A---- C:\Windows\system32\ieframe.dll
2017-03-15 07:42:49 ----A---- C:\Windows\system32\dxtmsft.dll
2017-03-15 07:42:48 ----A---- C:\Windows\system32\wininet.dll
2017-03-15 07:42:48 ----A---- C:\Windows\system32\webcheck.dll
2017-03-15 07:42:48 ----A---- C:\Windows\system32\mshtmlmedia.dll
2017-03-15 07:42:48 ----A---- C:\Windows\system32\jscript9diag.dll
2017-03-15 07:42:48 ----A---- C:\Windows\system32\jscript9.dll
2017-03-15 07:42:48 ----A---- C:\Windows\system32\jscript.dll
2017-03-15 07:42:47 ----A---- C:\Windows\system32\msrating.dll
2017-03-15 07:42:47 ----A---- C:\Windows\system32\MshtmlDac.dll
2017-03-15 07:42:47 ----A---- C:\Windows\system32\mshtml.dll
2017-03-15 07:42:46 ----A---- C:\Windows\system32\ntoskrnl.exe
2017-03-15 07:42:45 ----A---- C:\Windows\system32\win32k.sys
2017-03-15 07:42:44 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2017-03-15 07:42:44 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2017-03-15 07:42:44 ----A---- C:\Windows\system32\ntdll.dll
2017-03-15 07:42:44 ----A---- C:\Windows\system32\lsasrv.dll
2017-03-15 07:42:43 ----A---- C:\Windows\system32\schannel.dll
2017-03-15 07:42:43 ----A---- C:\Windows\system32\rpcrt4.dll
2017-03-15 07:42:43 ----A---- C:\Windows\system32\msxml3.dll
2017-03-15 07:42:43 ----A---- C:\Windows\system32\kerberos.dll
2017-03-15 07:42:43 ----A---- C:\Windows\system32\DWrite.dll
2017-03-15 07:42:42 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2017-03-15 07:42:42 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2017-03-15 07:42:42 ----A---- C:\Windows\system32\KernelBase.dll
2017-03-15 07:42:42 ----A---- C:\Windows\system32\advapi32.dll
2017-03-15 07:42:41 ----A---- C:\Windows\SYSWOW64\schannel.dll
2017-03-15 07:42:41 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2017-03-15 07:42:41 ----A---- C:\Windows\system32\msv1_0.dll
2017-03-15 07:42:41 ----A---- C:\Windows\system32\kernel32.dll
2017-03-15 07:42:40 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2017-03-15 07:42:40 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2017-03-15 07:42:40 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2017-03-15 07:42:40 ----A---- C:\Windows\system32\usp10.dll
2017-03-15 07:42:40 ----A---- C:\Windows\system32\rpchttp.dll
2017-03-15 07:42:40 ----A---- C:\Windows\system32\quartz.dll
2017-03-15 07:42:40 ----A---- C:\Windows\system32\ncrypt.dll
2017-03-15 07:42:40 ----A---- C:\Windows\system32\FntCache.dll
2017-03-15 07:42:40 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2017-03-15 07:42:40 ----A---- C:\Windows\HelpPane.exe
2017-03-15 07:42:39 ----A---- C:\Windows\SYSWOW64\usp10.dll
2017-03-15 07:42:39 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2017-03-15 07:42:39 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2017-03-15 07:42:39 ----A---- C:\Windows\system32\gdi32.dll
2017-03-15 07:42:39 ----A---- C:\Windows\system32\drivers\srv.sys
2017-03-15 07:42:39 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2017-03-15 07:42:39 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2017-03-15 07:42:39 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2017-03-15 07:42:39 ----A---- C:\Windows\system32\certcli.dll
2017-03-15 07:42:39 ----A---- C:\Windows\system32\adtschema.dll
2017-03-15 07:42:38 ----A---- C:\Windows\SYSWOW64\rpchttp.dll
2017-03-15 07:42:38 ----A---- C:\Windows\SYSWOW64\quartz.dll
2017-03-15 07:42:38 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2017-03-15 07:42:38 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2017-03-15 07:42:38 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2017-03-15 07:42:38 ----A---- C:\Windows\system32\wow64win.dll
2017-03-15 07:42:38 ----A---- C:\Windows\system32\inetcomm.dll
2017-03-15 07:42:38 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2017-03-15 07:42:37 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2017-03-15 07:42:37 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2017-03-15 07:42:37 ----A---- C:\Windows\system32\wow64.dll
2017-03-15 07:42:37 ----A---- C:\Windows\system32\winsrv.dll
2017-03-15 07:42:37 ----A---- C:\Windows\system32\wdigest.dll
2017-03-15 07:42:36 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2017-03-15 07:42:36 ----A---- C:\Windows\SYSWOW64\certcli.dll
2017-03-15 07:42:36 ----A---- C:\Windows\system32\TSpkg.dll
2017-03-15 07:42:36 ----A---- C:\Windows\system32\srcore.dll
2017-03-15 07:42:36 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2017-03-15 07:42:36 ----A---- C:\Windows\system32\conhost.exe
2017-03-15 07:42:36 ----A---- C:\Windows\system32\bcrypt.dll
2017-03-15 07:42:36 ----A---- C:\Windows\system32\appidsvc.dll
2017-03-15 07:42:35 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2017-03-15 07:42:35 ----A---- C:\Windows\SYSWOW64\bcrypt.dll
2017-03-15 07:42:35 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2017-03-15 07:42:35 ----A---- C:\Windows\system32\mscms.dll
2017-03-15 07:42:35 ----A---- C:\Windows\system32\icm32.dll
2017-03-15 07:42:35 ----A---- C:\Windows\system32\drivers\appid.sys
2017-03-15 07:42:35 ----A---- C:\Windows\system32\csrsrv.dll
2017-03-15 07:42:35 ----A---- C:\Windows\system32\appidapi.dll
2017-03-15 07:42:34 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2017-03-15 07:42:34 ----A---- C:\Windows\SYSWOW64\mscms.dll
2017-03-15 07:42:34 ----A---- C:\Windows\SYSWOW64\icm32.dll
2017-03-15 07:42:34 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2017-03-15 07:42:34 ----A---- C:\Windows\system32\sspicli.dll
2017-03-15 07:42:34 ----A---- C:\Windows\system32\smss.exe
2017-03-15 07:42:34 ----A---- C:\Windows\system32\secur32.dll
2017-03-15 07:42:34 ----A---- C:\Windows\system32\rstrui.exe
2017-03-15 07:42:34 ----A---- C:\Windows\system32\lsass.exe
2017-03-15 07:42:34 ----A---- C:\Windows\system32\cryptbase.dll
2017-03-15 07:42:34 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2017-03-15 07:42:33 ----A---- C:\Windows\SYSWOW64\WcsPlugInService.dll
2017-03-15 07:42:33 ----A---- C:\Windows\SYSWOW64\secur32.dll
2017-03-15 07:42:33 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2017-03-15 07:42:33 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2017-03-15 07:42:33 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2017-03-15 07:42:33 ----A---- C:\Windows\system32\WcsPlugInService.dll
2017-03-15 07:42:33 ----A---- C:\Windows\system32\ntvdm64.dll
2017-03-15 07:42:33 ----A---- C:\Windows\system32\msaudite.dll
2017-03-15 07:42:33 ----A---- C:\Windows\system32\auditpol.exe
2017-03-15 07:42:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-03-15 07:42:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-03-15 07:42:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-03-15 07:42:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-03-15 07:42:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-03-15 07:42:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-03-15 07:42:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-03-15 07:42:32 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-03-15 07:42:32 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-03-15 07:42:32 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-03-15 07:42:32 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-03-15 07:42:32 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-03-15 07:42:32 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-03-15 07:42:32 ----A---- C:\Windows\SYSWOW64\wow32.dll
2017-03-15 07:42:32 ----A---- C:\Windows\SYSWOW64\srclient.dll
2017-03-15 07:42:32 ----A---- C:\Windows\SYSWOW64\setup16.exe
2017-03-15 07:42:32 ----A---- C:\Windows\SYSWOW64\instnm.exe
2017-03-15 07:42:32 ----A---- C:\Windows\SYSWOW64\credssp.dll
2017-03-15 07:42:32 ----A---- C:\Windows\system32\wow64cpu.dll
2017-03-15 07:42:32 ----A---- C:\Windows\system32\sspisrv.dll
2017-03-15 07:42:32 ----A---- C:\Windows\system32\srclient.dll
2017-03-15 07:42:32 ----A---- C:\Windows\system32\setbcdlocale.dll
2017-03-15 07:42:32 ----A---- C:\Windows\system32\credssp.dll
2017-03-15 07:42:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2017-03-15 07:42:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-03-15 07:42:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-03-15 07:42:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-03-15 07:42:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-03-15 07:42:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-03-15 07:42:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-03-15 07:42:31 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-03-15 07:42:31 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-03-15 07:42:31 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-03-15 07:42:31 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-03-15 07:42:31 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-03-15 07:42:31 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-03-15 07:42:31 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-03-15 07:42:31 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2017-03-15 07:42:31 ----A---- C:\Windows\system32\apisetschema.dll
2017-03-15 07:42:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2017-03-15 07:42:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-03-15 07:42:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2017-03-15 07:42:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-03-15 07:42:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-03-15 07:42:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-03-15 07:42:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2017-03-15 07:42:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-03-15 07:42:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2017-03-15 07:42:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-03-15 07:42:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-03-15 07:42:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-03-15 07:42:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-03-15 07:42:30 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2017-03-15 07:42:30 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-03-15 07:42:30 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-03-15 07:42:30 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-03-15 07:42:30 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-03-15 07:42:30 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-03-15 07:42:30 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-03-15 07:42:30 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-03-15 07:42:30 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-03-15 07:42:30 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-03-15 07:42:30 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-03-15 07:42:30 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-03-15 07:42:30 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-03-15 07:42:30 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-03-15 07:42:30 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-03-15 07:42:30 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-03-15 07:42:30 ----A---- C:\Windows\SYSWOW64\user.exe
2017-03-15 07:42:30 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2017-03-15 07:42:30 ----A---- C:\Windows\SYSWOW64\INETRES.dll
2017-03-15 07:42:30 ----A---- C:\Windows\system32\msobjs.dll
2017-03-15 07:42:30 ----A---- C:\Windows\system32\INETRES.dll
2017-03-15 07:42:30 ----A---- C:\Windows\system32\drivers\srvnet.sys
2017-03-15 07:42:30 ----A---- C:\Windows\system32\drivers\srv2.sys
2017-03-15 07:42:29 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2017-03-15 07:42:29 ----A---- C:\Windows\system32\msxml3r.dll
2017-03-15 07:41:27 ----A---- C:\Windows\system32\aepic.dll
2017-03-15 07:41:27 ----A---- C:\Windows\system32\aeinv.dll
2017-03-15 07:41:26 ----A---- C:\Windows\system32\invagent.dll
2017-03-15 07:41:26 ----A---- C:\Windows\system32\generaltel.dll
2017-03-15 07:41:26 ----A---- C:\Windows\system32\devinv.dll
2017-03-15 07:41:26 ----A---- C:\Windows\system32\CompatTelRunner.exe
2017-03-15 07:41:26 ----A---- C:\Windows\system32\centel.dll
2017-03-15 07:41:26 ----A---- C:\Windows\system32\appraiser.dll
2017-03-15 07:41:25 ----A---- C:\Windows\system32\acmigration.dll
2017-03-14 16:22:13 ----N---- C:\Windows\system32\hppfaxprintermonui5.dll
2017-03-14 16:22:13 ----N---- C:\Windows\system32\hppfaxprintermon5.dll
2017-03-14 16:22:12 ----A---- C:\Windows\system32\hppfaxprinter5.ini
2017-03-14 16:18:42 ----A---- C:\Windows\SYSWOW64\hpcdmc32.DLL
2017-03-14 16:18:42 ----A---- C:\Windows\system32\hpcpn093.dll
2017-03-14 16:18:40 ----A---- C:\Windows\SYSWOW64\hpcc3093.DLL
2017-03-14 16:18:40 ----A---- C:\Windows\SYSWOW64\fxcompchannel.dll
2017-03-14 16:18:40 ----A---- C:\Windows\system32\fxcompchannel_x64.dll
2017-03-14 16:12:22 ----N---- C:\Windows\hppmdl12.dat
2017-03-14 16:12:22 ----A---- C:\Windows\hppins12.dat
2017-03-14 16:12:07 ----A---- C:\Windows\system32\hppdpr12_x64.dll
2017-03-14 16:11:47 ----A---- C:\Windows\system32\hppapr12.dat
2017-03-09 16:44:17 ----A---- C:\Windows\system32\Z%25C3%25A1pis%2520ze%2520zased%25C3%25A1n%25C3%25AD%2520dozor%25C4%258D%25C3%25AD%2520rady%2520%2520Diakonie%2520%25C4%258CCE%2520St%25C5%2599edn%25C3%25AD%2520%25C4%258Cechy%252021.%25209.%25.docx.lnk

====== List of files/folders modified in the last 1 month ======

2017-03-23 12:09:14 ----D---- C:\Windows\Temp
2017-03-23 11:48:11 ----D---- C:\Windows\system32\config
2017-03-23 11:19:26 ----RD---- C:\Program Files
2017-03-23 11:05:20 ----SHD---- C:\Windows\Installer
2017-03-23 11:05:20 ----HD---- C:\Config.Msi
2017-03-23 11:05:20 ----D---- C:\Program Files (x86)\GIGABYTE
2017-03-23 11:05:04 ----SHD---- C:\System Volume Information
2017-03-23 11:00:25 ----D---- C:\Windows\system32\NDF
2017-03-23 10:59:39 ----D---- C:\Windows\Prefetch
2017-03-23 10:50:13 ----D---- C:\Program Files (x86)\HP
2017-03-23 10:48:38 ----D---- C:\Program Files\WONDEREX center Station
2017-03-23 10:46:36 ----HD---- C:\ProgramData
2017-03-23 10:46:36 ----D---- C:\Windows\system32\drivers
2017-03-23 10:45:46 ----RD---- C:\Program Files (x86)
2017-03-23 10:45:34 ----D---- C:\Windows\system32\Tasks
2017-03-23 09:55:30 ----D---- C:\Windows\SysWOW64
2017-03-23 09:55:30 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2017-03-23 09:55:22 ----D---- C:\Windows\inf
2017-03-23 09:55:14 ----D---- C:\Windows\System32
2017-03-23 09:55:14 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-03-22 22:05:16 ----D---- C:\Windows\SYSWOW64\cs-CZ
2017-03-22 22:05:16 ----D---- C:\Windows\system32\cs-CZ
2017-03-22 20:03:41 ----D---- C:\Windows\Panther
2017-03-22 20:02:19 ----D---- C:\Windows
2017-03-22 19:44:43 ----D---- C:\Windows\Logs
2017-03-22 10:45:31 ----D---- C:\ProgramData\Ashampoo
2017-03-22 10:22:39 ----D---- C:\Windows\Minidump
2017-03-22 10:22:39 ----D---- C:\Windows\debug
2017-03-22 09:24:21 ----D---- C:\ProgramData\Oracle
2017-03-22 09:22:30 ----D---- C:\Program Files (x86)\Java
2017-03-22 09:21:51 ----D---- C:\Program Files (x86)\Common Files
2017-03-22 09:20:50 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2017-03-22 09:16:13 ----D---- C:\Program Files (x86)\WinPcap
2017-03-21 20:56:29 ----A---- C:\Windows\triada.ini
2017-03-21 16:25:39 ----D---- C:\Windows\Tasks
2017-03-20 13:12:51 ----D---- C:\Program Files (x86)\Mozilla Firefox
2017-03-20 13:12:48 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2017-03-19 20:23:32 ----A---- C:\Windows\softpc.ini
2017-03-16 09:54:18 ----D---- C:\Windows\rescache
2017-03-15 17:53:56 ----D---- C:\Windows\winsxs
2017-03-15 17:47:25 ----D---- C:\Program Files (x86)\Internet Explorer
2017-03-15 17:47:24 ----D---- C:\Program Files\Internet Explorer
2017-03-15 17:47:23 ----D---- C:\Windows\SYSWOW64\migration
2017-03-15 17:47:23 ----D---- C:\Windows\SYSWOW64\en-US
2017-03-15 17:47:23 ----D---- C:\Program Files\DVD Maker
2017-03-15 17:47:18 ----D---- C:\Windows\system32\migration
2017-03-15 17:47:18 ----D---- C:\Windows\system32\en-US
2017-03-15 17:47:12 ----D---- C:\Windows\AppPatch
2017-03-15 17:47:11 ----D---- C:\Windows\system32\Boot
2017-03-15 17:47:10 ----SD---- C:\Windows\system32\CompatTel
2017-03-15 17:47:09 ----D---- C:\Windows\system32\appraiser
2017-03-15 15:06:13 ----D---- C:\ProgramData\Microsoft Help
2017-03-15 15:06:05 ----D---- C:\Windows\system32\MRT
2017-03-15 15:03:28 ----AC---- C:\Windows\system32\MRT.exe
2017-03-15 07:34:18 ----D---- C:\Windows\system32\catroot2
2017-03-14 22:12:30 ----D---- C:\Windows\system32\FxsTmp
2017-03-14 21:48:08 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2017-03-14 21:48:06 ----D---- C:\Windows\system32\Macromed
2017-03-14 21:48:04 ----D---- C:\Windows\SYSWOW64\Macromed
2017-03-14 16:24:10 ----A---- C:\Windows\win.ini
2017-03-14 16:20:06 ----D---- C:\Windows\system32\DriverStore
2017-03-14 16:18:29 ----A---- C:\Windows\system32\AddPort.ini
2017-03-14 16:18:28 ----A---- C:\Windows\hpntwksetup.ini
2017-03-14 15:59:12 ----D---- C:\Windows\system32\catroot
2017-03-04 12:37:56 ----D---- C:\Windows\system32\wfp
2017-03-04 12:37:56 ----D---- C:\Windows\system32\wbem
2017-03-04 12:37:55 ----D---- C:\Users\spravce\AppData\Roaming\gepro
2017-03-04 12:37:52 ----D---- C:\ProgramData\gepro
2017-03-04 12:37:48 ----D---- C:\Windows\registration
2017-03-02 20:37:59 ----D---- C:\ossz_eviden_listy
2017-03-01 19:07:20 ----D---- C:\ossz

File C:\Windows\system32\winlogon.exe is digitally signed
File C:\Windows\system32\wininit.exe is digitally signed
File C:\Windows\explorer.exe is digitally signed
File C:\Windows\SysWOW64\explorer.exe is digitally signed
File C:\Windows\system32\svchost.exe is digitally signed
File C:\Windows\SysWOW64\svchost.exe is digitally signed
File C:\Windows\system32\services.exe is digitally signed
File C:\Windows\system32\User32.dll is digitally signed
File C:\Windows\SysWOW64\User32.dll is digitally signed
File C:\Windows\system32\userinit.exe is digitally signed
File C:\Windows\SysWOW64\userinit.exe is digitally signed
File C:\Windows\system32\rpcss.dll is digitally signed
File C:\Windows\system32\Drivers\volsnap.sys is digitally signed

====== List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======

R0 iaStorA;iaStorA; C:\Windows\system32\DRIVERS\iaStorA.sys [2013-04-30 677360]
R0 iaStorF;iaStorF; C:\Windows\system32\DRIVERS\iaStorF.sys [2013-04-30 28656]
R0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hcs.sys [2013-04-26 20464]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R3 AKSIFDH;Aladdin IFD Handler; C:\Windows\system32\DRIVERS\aksifdh.sys [2008-07-30 62632]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2013-05-17 4433696]
R3 iKeyEnum;Rainbow iKey Enumerator; C:\Windows\system32\DRIVERS\ikeyenum.sys [2011-07-06 16160]
R3 iKeyIFD;Rainbow iKey Virtual Reader; C:\Windows\system32\DRIVERS\ikeyifd.sys [2011-07-06 22304]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2013-02-26 3333576]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2013-05-17 442368]
R3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hub.sys [2013-04-26 368112]
R3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3xhc.sys [2013-04-26 786416]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\HECIx64.sys [2013-04-11 64624]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2012-10-25 769168]
R3 StillCam;Ovladač digitálního fotoaparátu pro sériový port; C:\Windows\system32\DRIVERS\serscan.sys [2009-07-14 12288]
S2 Hardlock;Hardlock; \??\C:\Windows\system32\drivers\hardlock.sys [2005-06-14 296448]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys []
S3 HPEWSFXBULK;HPEWSFXBULK; C:\Windows\system32\drivers\hpfx64bulk.sys [2016-09-13 29248]
S3 HPFXBULK;HPFXBULK; C:\Windows\system32\drivers\hpfx64bulk.sys [2016-09-13 29248]
S3 HPFXFAX;HPFXFAX; C:\Windows\system32\drivers\hpfx64fax.sys [2007-07-16 23064]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RnbToken;Rainbow iKey Token Service; C:\Windows\system32\DRIVERS\rnbtoken.sys [2011-07-06 24352]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
S3 WSDPrintDevice;Podpora tisku WSD prostřednictvím funkce UMB; C:\Windows\system32\DRIVERS\WSDPrint.sys [2009-07-14 23040]
S4 RsFx0151;RsFx0151 Driver; C:\Windows\system32\DRIVERS\RsFx0151.sys [2011-06-17 313696]

====== List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======

R2 602XML Updater;602Updater; C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe [2011-10-10 85344]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-12-19 82640]
R2 ApacheTriada;ApacheTriada; c:\munis\triada.app\apache\bin\httpd.exe [2008-12-09 24636]
R2 cbVSCService11;Cobian Backup 11 Stínová kopie - Requester; C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe [2013-03-07 67584]
R2 CobianBackup11;Cobian Backup 11 Gravity; C:\Program Files (x86)\Cobian Backup 11\cbService.exe [2013-03-07 1131008]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\cscsvc.dll
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; %SystemRoot%\System32\svchost.exe -k utcsvc;"ServiceDll" = %SystemRoot%\system32\diagtrack.dll
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; %SystemRoot%\system32\svchost.exe -k hpdevmgmt;"ServiceDll" = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-04-30 15344]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-02-13 731648]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-04-11 169432]
R2 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
R2 MSSQL$TRIADA;SQL Server (TRIADA); C:\Program Files\Microsoft SQL Server\MSSQL10_50.TRIADA\MSSQL\Binn\sqlservr.exe [2011-06-17 62111072]
R2 Net Driver HPZ12;Net Driver HPZ12; %SystemRoot%\System32\svchost.exe -k HPZ12;"ServiceDll" = C:\Windows\system32\HPZinw12.dll
R2 Pml Driver HPZ12;Pml Driver HPZ12; %SystemRoot%\System32\svchost.exe -k HPZ12;"ServiceDll" = C:\Windows\system32\HPZipm12.dll
R2 SACSrv;SACSrv; C:\Program Files (x86)\SafeNet\Authentication\SAC\x64\SACSrv.exe [2011-01-13 8904]
R2 SQLBrowser;SQL Server Browser; C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2010-04-03 267616]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2010-04-03 146272]
R2 TriadaBootloader;Triada - Servisní služba; c:\munis\triada.app\MunisAsm\bootloader\MunisBootloaderService.exe [2013-05-10 15872]
R2 TriadaMunisAsm;Triada - MunisAsm; c:\munis\triada.app\MunisAsm\app\MunisAsmService.exe [2017-02-10 25672]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]
R3 hpqcxs08;hpqcxs08; %SystemRoot%\system32\svchost.exe -k hpdevmgmt;"ServiceDll" = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll
R3 MSSQLFDLauncher$TRIADA;SQL Full-text Filter Daemon Launcher (TRIADA); C:\Program Files\Microsoft SQL Server\MSSQL10_50.TRIADA\MSSQL\Binn\fdlauncher.exe [2010-04-03 32096]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2016-11-29 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2016-11-29 125112]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29 144200]
S2 HP LaserJet Service;HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [2009-06-01 136192]
S2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-04-11 366552]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-03-14 271960]
S3 AppMgmt;@appmgmts.dll,-3250; %SystemRoot%\system32\svchost.exe -k netsvcs;"ServiceDll" = %SystemRoot%\System32\appmgmts.dll
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2016-11-29 51384]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2013-05-24 279024]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29 144200]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2014-01-13 194032]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2017-03-04 114688]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-02-13 820184]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2017-03-20 172488]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; %SystemRoot%\System32\svchost.exe -k PeerDist;"ServiceDll" = %SystemRoot%\system32\peerdistsvc.dll
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll" = %SystemRoot%\system32\storsvc.dll
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\umrdp.dll
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-01-13 1255736]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; C:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2010-04-03 59744]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-11-29 135848]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-11-29 135848]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-11-29 135848]
S4 SQLAgent$TRIADA;SQL Server Agent (TRIADA); C:\Program Files\Microsoft SQL Server\MSSQL10_50.TRIADA\MSSQL\Binn\SQLAGENT.EXE [2011-06-17 431456]

-----------------EOF-----------------

Re: pomalý start

Napsal: 23 bře 2017 17:56
od Roli
Zdravím, smaž nepotřebné soubory

pomocí CCleaneru

návod :

Čistič - tady vyčistíš PC od nepotřebných souborů a vysypeš Koš

Registry - tady vyčistíš registry (před použitím doporučuji udělat jejich zálohu kterou CCleaner nabízí)

čištění registru je třeba několikrát zopakovat !

Nástroje - tady lze odinstalovat programy, upravit co se spustí po Startu systému a obnovit systém


Stáhni a spusť AdwCleaner,

ukonči všechny programy včetně prohlížeče a dvojklikem jej spusť,

objeví se okno kde vlevo nahoře klikni na Scan.

Po dokončení skenu klikni na Clean,

proběhne restart PC kdy dojde ke smazání nepořádku.

Po té mi sem zkopíruj Report.


Stáhni a ulož na plochu ComboFix,

spusť aplikaci jako Administrátor a povol instalaci Konzole pro zotavení - Recovery Console.

Poté se zobrazí okno s licenčními podmínkami které potvrdíš kliknutím na ANO,

pak ještě jednou klik na ANO a už to jede.

Celá akce trvá okolo 10 minut ale může i déle, během skenu se nepokoušej spouštět nic jiného.

Při skenovaní může být PC i restartováno nelekat se.

Upozornění: po dobu skenu vypni rezidentní štít Antiviru a AntiSpy programu,

protože Combofix se pokouší napadené soubory smazat a tyto programy mu můžou bránit.

Po dokončení skenu nebo následném restartu aplikace vytvoří log, uložený na C:/Combofix.txt

(při opakovaném použití jsou logy číslovány Combofix2.txt atd.), jeho obsah zkopíruj sem.


V případě nejasností je ZDE obrázkový návod.

Re: pomalý start

Napsal: 23 bře 2017 21:46
od vladypd
Adwcleaner nic nenašel

ComboFix 17-03-21.01 - spravce 23.03.2017 21:29:45.1.4 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.8080.6005 [GMT 1:00]
Spuštěný z: c:\users\spravce\Downloads\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\program files (x86)\WinPCap
c:\windows\SysWow64\drivers\npf.sys
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2017-02-23 do 2017-03-23 )))))))))))))))))))))))))))))))
.
.
2017-03-23 20:36 . 2017-03-23 20:36 -------- d-----w- c:\users\Default\AppData\Local\temp
2017-03-23 20:14 . 2017-03-23 20:15 -------- d-----w- C:\AdwCleaner
2017-03-23 12:23 . 2017-03-23 12:23 -------- d-----w- c:\program files\CCleaner
2017-03-23 10:19 . 2017-03-23 11:09 -------- d-----w- c:\program files\trend micro
2017-03-23 10:19 . 2017-03-23 10:19 -------- d-----w- C:\rsit
2017-03-22 19:02 . 2017-03-22 19:03 -------- d-----w- C:\$WINDOWS.~BT
2017-03-22 08:47 . 2017-02-22 10:48 12654400 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F4F58278-DE90-454C-9544-00698EE0892F}\mpengine.dll
2017-03-22 08:21 . 2017-03-22 08:21 -------- d-----w- c:\program files (x86)\Common Files\Java
2017-03-20 18:14 . 2017-03-20 18:14 47087 ----a-w- c:\windows\system32\epfwdata.bin
2017-03-15 06:41 . 2017-02-22 23:37 1285632 ----a-w- c:\windows\system32\aeinv.dll
2017-03-15 06:41 . 2016-12-31 15:36 233984 ----a-w- c:\windows\system32\aepic.dll
2017-03-15 06:41 . 2017-02-22 23:42 84712 ----a-w- c:\windows\system32\CompatTelRunner.exe
2017-03-15 06:41 . 2017-02-18 14:05 646656 ----a-w- c:\windows\system32\generaltel.dll
2017-03-15 06:41 . 2017-02-18 14:05 1609216 ----a-w- c:\windows\system32\appraiser.dll
2017-03-15 06:41 . 2016-12-31 15:36 335360 ----a-w- c:\windows\system32\invagent.dll
2017-03-15 06:41 . 2016-12-31 15:36 556544 ----a-w- c:\windows\system32\devinv.dll
2017-03-15 06:41 . 2016-12-31 15:36 293376 ----a-w- c:\windows\system32\centel.dll
2017-03-15 06:41 . 2016-12-31 15:36 133632 ----a-w- c:\windows\system32\acmigration.dll
2017-03-14 16:16 . 2017-03-20 12:12 527816 ----a-w- c:\program files (x86)\Mozilla Firefox\minidump-analyzer.exe
2017-03-14 15:22 . 2009-09-22 19:44 22016 ------w- c:\windows\system32\hppfaxprintermon5.dll
2017-03-14 15:22 . 2009-09-22 19:44 16384 ------w- c:\windows\system32\hppfaxprintermonui5.dll
2017-03-14 15:18 . 2009-10-14 12:25 157184 ----a-w- c:\windows\system32\hpcpn093.dll
2017-03-14 15:18 . 2009-02-25 19:08 671816 ----a-w- c:\windows\SysWow64\hpcdmc32.DLL
2017-03-14 15:18 . 2009-10-14 12:16 276480 ----a-w- c:\windows\SysWow64\hpcc3093.DLL
2017-03-14 15:18 . 2007-07-16 14:29 60440 ----a-w- c:\windows\system32\fxcompchannel_x64.dll
2017-03-14 15:18 . 2007-07-16 14:29 59928 ----a-w- c:\windows\SysWow64\fxcompchannel.dll
2017-03-14 15:12 . 2008-09-30 15:52 165376 ----a-w- c:\windows\system32\hppdpr12_x64.dll
2017-02-23 14:27 . 2017-02-23 14:27 -------- d-----w- C:\LocalStorage
2017-02-23 14:26 . 2016-08-10 17:52 38344 ----a-w- c:\windows\SysWow64\drivers\InstallNpfApp.exe
2017-02-23 14:24 . 2016-08-10 17:52 36600 ----a-w- c:\windows\SysWow64\drivers\npf64.sys
2017-02-23 14:24 . 2017-03-23 09:48 -------- d-----w- c:\program files\WONDEREX center Station
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2017-03-22 08:20 . 2016-08-10 12:31 97856 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2017-03-15 14:03 . 2014-01-13 14:00 138634176 -c--a-w- c:\windows\system32\MRT.exe
2017-03-14 20:48 . 2014-01-13 15:19 802904 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2017-03-14 20:48 . 2014-01-13 15:19 144472 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2017-03-14 15:22 . 2014-01-16 11:10 608 --sha-w- c:\windows\system32\winzvprt5.sys
2017-02-09 16:32 . 2017-03-15 06:42 345600 ----a-w- c:\windows\system32\schannel.dll
2017-02-09 16:32 . 2017-03-15 06:42 190464 ----a-w- c:\windows\system32\rpchttp.dll
2017-02-09 16:14 . 2017-03-15 06:42 254464 ----a-w- c:\windows\SysWow64\schannel.dll
2017-02-09 16:14 . 2017-03-15 06:42 141312 ----a-w- c:\windows\SysWow64\rpchttp.dll
2017-02-09 16:14 . 2017-03-15 06:42 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2017-02-03 19:05 . 2016-08-09 17:59 63 ----a-w- C:\ISP.bat
2017-01-07 09:08 . 2012-07-17 13:37 24800 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2014-01-13 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Cobian Backup 11 interface"="c:\program files (x86)\Cobian Backup 11\cbInterface.exe" [2013-03-07 4407808]
"HPUsageTracking"="c:\program files (x86)\HP\HP UT\bin\hppusg.exe" [2009-05-11 24576]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2016-12-12 587288]
"USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2013-04-26 292848]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
MunisAsm.lnk - c:\munis\triada.app\MunisAsm\app\MunisAsmTrayIcon.exe [2014-1-15 208968]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R2 ApacheTriada;ApacheTriada;c:\munis\triada.app\apache\bin\httpd.exe;c:\munis\triada.app\apache\bin\httpd.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 HP LaserJet Service;HP LaserJet Service;c:\program files (x86)\HP\HPLaserJetService\HPLaserJetService.exe;c:\program files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [x]
R2 MSSQL$TRIADA;SQL Server (TRIADA);c:\program files\Microsoft SQL Server\MSSQL10_50.TRIADA\MSSQL\Binn\sqlservr.exe;c:\program files\Microsoft SQL Server\MSSQL10_50.TRIADA\MSSQL\Binn\sqlservr.exe [x]
R2 TriadaBootloader;Triada - Servisní služba;c:\munis\triada.app\MunisAsm\bootloader\MunisBootloaderService.exe;c:\munis\triada.app\MunisAsm\bootloader\MunisBootloaderService.exe [x]
R2 TriadaMunisAsm;Triada - MunisAsm;c:\munis\triada.app\MunisAsm\app\MunisAsmService.exe;c:\munis\triada.app\MunisAsm\app\MunisAsmService.exe [x]
R3 HPEWSFXBULK;HPEWSFXBULK;c:\windows\system32\drivers\hpfx64bulk.sys;c:\windows\SYSNATIVE\drivers\hpfx64bulk.sys [x]
R3 HPFXFAX;HPFXFAX;c:\windows\system32\drivers\hpfx64fax.sys;c:\windows\SYSNATIVE\drivers\hpfx64fax.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;c:\program files\Intel\iCLS Client\SocketHeciServer.exe;c:\program files\Intel\iCLS Client\SocketHeciServer.exe [x]
R3 MSSQLFDLauncher$TRIADA;SQL Full-text Filter Daemon Launcher (TRIADA);c:\program files\Microsoft SQL Server\MSSQL10_50.TRIADA\MSSQL\Binn\fdlauncher.exe;c:\program files\Microsoft SQL Server\MSSQL10_50.TRIADA\MSSQL\Binn\fdlauncher.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RnbToken;Rainbow iKey Token Service;c:\windows\system32\DRIVERS\rnbtoken.sys;c:\windows\SYSNATIVE\DRIVERS\rnbtoken.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [x]
R4 RsFx0151;RsFx0151 Driver;c:\windows\system32\DRIVERS\RsFx0151.sys;c:\windows\SYSNATIVE\DRIVERS\RsFx0151.sys [x]
R4 SQLAgent$TRIADA;SQL Server Agent (TRIADA);c:\program files\Microsoft SQL Server\MSSQL10_50.TRIADA\MSSQL\Binn\SQLAGENT.EXE;c:\program files\Microsoft SQL Server\MSSQL10_50.TRIADA\MSSQL\Binn\SQLAGENT.EXE [x]
S0 iaStorA;iaStorA;c:\windows\system32\DRIVERS\iaStorA.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorA.sys [x]
S0 iaStorF;iaStorF;c:\windows\system32\DRIVERS\iaStorF.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorF.sys [x]
S0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
S2 602XML Updater;602Updater;c:\program files (x86)\Common Files\soft602\602updsvc\602updsvc.exe;c:\program files (x86)\Common Files\soft602\602updsvc\602updsvc.exe [x]
S2 cbVSCService11;Cobian Backup 11 Stínová kopie - Requester;c:\program files (x86)\Cobian Backup 11\cbVSCService11.exe;c:\program files (x86)\Cobian Backup 11\cbVSCService11.exe [x]
S2 CobianBackup11;Cobian Backup 11 Gravity;c:\program files (x86)\Cobian Backup 11\cbService.exe;c:\program files (x86)\Cobian Backup 11\cbService.exe [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 SACSrv;SACSrv;c:\program files (x86)\SafeNet\Authentication\SAC\x64\SACSrv.exe;c:\program files (x86)\SafeNet\Authentication\SAC\x64\SACSrv.exe [x]
S3 iKeyEnum;Rainbow iKey Enumerator;c:\windows\system32\DRIVERS\ikeyenum.sys;c:\windows\SYSNATIVE\DRIVERS\ikeyenum.sys [x]
S3 iKeyIFD;Rainbow iKey Virtual Reader;c:\windows\system32\DRIVERS\ikeyifd.sys;c:\windows\SYSNATIVE\DRIVERS\ikeyifd.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr QWAVE wcncsvc
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2017-02-02 06:06 1368920 ----a-w- c:\program files (x86)\Google\Chrome\Application\56.0.2924.87\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2017-03-21 c:\windows\Tasks\WebReg .job
- c:\program files (x86)\HP\Digital Imaging\bin\hpqwrg.exe [2007-10-14 19:40]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2013-05-24 407536]
"HP Color LaserJet CM2320 MFP Series Fax"="c:\program files (x86)\HP\HP Color LaserJet CM2320 MFP Series\hppfaxprintersrv.exe" [2009-09-22 3700736]
"IAStorIcon"="c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" [2013-04-30 36352]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2013-05-24 165872]
"Persistence"="c:\windows\system32\igfxpers.exe" [2013-05-24 444400]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2013-02-26 13423688]
"SACMonitor"="c:\program files (x86)\SafeNet\Authentication\SAC\x64\SACMonitor.exe" [2011-01-13 1227464]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = https://www.seznam.cz/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
Trusted Zone: chotanky.cz\www
Trusted Zone: eset.com\help
TCP: Interfaces\{C92DCD57-5364-467F-BB92-0E5FBA6284B5}: NameServer = 192.168.1.1
FF - ProfilePath - c:\users\spravce\AppData\Roaming\Mozilla\Firefox\Profiles\5vqazo7u.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
Notify-ScCertProp - (no file)
SafeBoot-MBAMService
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_25_0_0_127_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_25_0_0_127_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_25_0_0_127_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_25_0_0_127_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_25_0_0_127.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.25"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_25_0_0_127.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_25_0_0_127.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_25_0_0_127.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2017-03-23 21:38:35
ComboFix-quarantined-files.txt 2017-03-23 20:38
.
Před spuštěním: Volných bajtů: 195 212 566 528
Po spuštění: Volných bajtů: 194 801 577 984
.
- - End Of File - - C662CB41219134E3595D3A9B8B1821FF
A36C5E4F47E84449FF07ED3517B43A31

Re: pomalý start

Napsal: 24 bře 2017 20:46
od Roli
Přes Start >> Spustit zkopíruj do okna:

ComboFix /Uninstall

a stiskni Enter

To odinstaluje ComboFix a smaže s ním související soubory a složky.


Použij T-Cleaner, který smaže případné zbytky po aplikacích které jsme použili.

Jen před jeho stažením a při použití stopni antivir, protože ho muže detekovat jako vir ale není tomu tak.


Pak dej vědět jak se PC chová.


P.S. nemáš na Ploše velké soubory (fotky, hudbu, videa, ...) ?

Re: pomalý start

Napsal: 04 dub 2017 22:58
od vladypd
na ploše bylo asi 30GB malých souborů - fotky atd, smazal jsem, defragmentoval. Stejné, než naběhne ikona sítového pripojení (kabelem) je to přes 10 min. potom už pracuje téměř v pohodě.

Re: pomalý start

Napsal: 05 dub 2017 17:22
od Roli
vladypd píše:na ploše bylo asi 30GB malých souborů
No nazdar :shock:
vladypd píše:Stejné, než naběhne ikona sítového pripojení (kabelem) je to přes 10 min. potom už pracuje téměř v pohodě.
Zkusíme aktualizovat ovladače síťovky.

Použij AIDA 64

Sice se jedná o trial ale náš účel splní.

Nainstaluj ji >> spusť >> klik na Počítač >> dále Přehled,

nahoře v aplikaci klikni na Zpráva vyber Rychlá zpráva >> Prostý text

a zkopíruj mi sem vše po Síť :, kouknu se co se s tím dá dělat.