Stránka 1 z 2

Prosím o kontrolu logu - výrazné zpomalení počítače

Napsal: 26 zář 2021 08:43
od Tucci
Dobré dopoledne všem, prosím o kontrolu logu. NTB se výrazně zpomalil, RAD i HDD jsou vytíženy na 100%. Ikdyž RAM není velká, ke zpomalení došlo teprve nedávno. Děkuji za radu a přeji hezký den.
FRST.zip
(23.58 KiB) Staženo 87 x

Re: Prosím o kontrolu logu - výrazné zpomalení počítače

Napsal: 26 zář 2021 10:23
od Rudy
Zdravím!
Spusťte tuto utilitu:
Ulozte na plochu AdwCleaner https://malwarebytes.com/adwcleaner/ nebo http://www.bleepingcomputer.com/download/adwcleaner/

ukoncete vsechny programy
odsouhlaste licencni podmiky (EULA) klikem na Souhlasim
kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
kliknete na Skenovat nyni (Scan now), pote na Cisteni a opravy (Clean and Repair)
po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\Logs\AdwCleaner[Cxx].txt), jehoz obsah zkopirujte do pristi odpovedi

Re: Prosím o kontrolu logu - výrazné zpomalení počítače

Napsal: 26 zář 2021 11:41
od Tucci
děkuji, provedeno, posílám.

-----------------------------

# -------------------------------
# Malwarebytes AdwCleaner 8.3.0.0
# -------------------------------
# Build: 06-29-2021
# Database: 2021-09-09.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 09-26-2021
# Duration: 00:04:06
# OS: Windows 10 Home
# Cleaned: 69
# Failed: 0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

Deleted C:\ProgramData\Pokki
Deleted C:\Users\Public\Pokki
Deleted C:\Users\trener\AppData\Local\Pokki
Deleted C:\Users\trener\AppData\Local\SweetLabs App Platform
Deleted C:\Windows\ServiceProfiles\LocalService\AppData\Local\Pokki
Deleted C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Pokki

***** [ Files ] *****

Deleted C:\Users\trener\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
Deleted C:\Windows\System32\Tasks_Migrated\SweetLabs App Platform

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

Deleted C:\Windows\System32\Tasks\SWEETLABS APP PLATFORM

***** [ Registry ] *****

Deleted HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Pokki_04bb6df446330549a2cb8d67fbd1a745025b7bd1
Deleted HKCU\Software\Classes\AllFileSystemObjects\shell\pokki
Deleted HKCU\Software\Classes\Directory\shell\pokki
Deleted HKCU\Software\Classes\Drive\shell\pokki
Deleted HKCU\Software\Classes\lnkfile\shell\pokki
Deleted HKCU\Software\Classes\pokki
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\SweetLabs_AP
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\SweetLabs_Start_Menu
Deleted HKCU\Software\SweetLabs App Platform
Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DEA7B20E-77A1-426E-BE9F-435F68BD9E29}
Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SweetLabs App Platform

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Hosts File Entries ] *****

No malicious hosts file entries cleaned.

***** [ Preinstalled Software ] *****

Deleted Preinstalled.HPCleanFLC File C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office.lnk
Deleted Preinstalled.HightailforLenovo Folder C:\Program Files (x86)\HIGHTAIL\HIGHTAIL FOR LENOVO
Deleted Preinstalled.HightailforLenovo Folder C:\Program Files\HIGHTAIL\HIGHTAIL FOR LENOVO
Deleted Preinstalled.HightailforLenovo Folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HIGHTAIL\HIGHTAIL FOR LENOVO
Deleted Preinstalled.HightailforLenovo Registry HKLM\Software\Classes\CLSID\{1E9CED2C-E7B4-4C47-B07A-25416393B67B}
Deleted Preinstalled.HightailforLenovo Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{2F10E937-F6D7-4174-8AB9-B299E8FC5CEC}
Deleted Preinstalled.HightailforLenovo Registry HKLM\Software\Wow6432Node\\Classes\CLSID\{1E9CED2C-E7B4-4C47-B07A-25416393B67B}
Deleted Preinstalled.LenovoEnergyManager Folder C:\LENOVO\ENERGY MANAGER
Deleted Preinstalled.LenovoEnergyManager Folder C:\Program Files (x86)\LENOVO\ENERGY MANAGER
Deleted Preinstalled.LenovoEnergyManager Folder C:\Users\trener\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LENOVO\ENERGY MANAGER
Deleted Preinstalled.LenovoEnergyManager Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|Energy Manager
Deleted Preinstalled.LenovoEnergyManager Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|Lenovo Utility
Deleted Preinstalled.LenovoEnergyManager Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Energy Manager
Deleted Preinstalled.LenovoEnergyManager Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Lenovo Utility
Deleted Preinstalled.LenovoEnergyManager Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}
Deleted Preinstalled.LenovoEnergyManager Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{AC768037-7079-4658-AC24-2897650E0ABE}
Deleted Preinstalled.LenovoIMController Folder C:\ProgramData\LENOVO\IMCONTROLLER
Deleted Preinstalled.LenovoIMController Folder C:\Users\trener\AppData\Local\LENOVO\IMCONTROLLER
Deleted Preinstalled.LenovoIMController Folder C:\Windows\LENOVO\IMCONTROLLER
Deleted Preinstalled.LenovoIMController Folder C:\Windows\System32\Tasks\LENOVO\IMCONTROLLER
Deleted Preinstalled.LenovoIMController Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{0788641D-D31A-478D-BB34-C41564AE9F93}
Deleted Preinstalled.LenovoIMController Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\Lenovo Dependency Package_is1
Deleted Preinstalled.LenovoPhoneCompanion Folder C:\Program Files\LENOVO PHONECOMPANION
Deleted Preinstalled.LenovoPhoneCompanion Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|PhoneCompanion
Deleted Preinstalled.LenovoPhoneCompanion Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Run|PhoneCompanion
Deleted Preinstalled.LenovoPhoneCompanion Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{0F82EA83-B0C5-4AB9-9695-DFE92C5FD57B}
Deleted Preinstalled.LenovoPhoneCompanion Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{0F82EA83-B0C5-4AB9-9695-DFE92C5FD57B}
Deleted Preinstalled.LenovoPhotoMaster Folder C:\Program Files (x86)\LENOVO\LENOVO PHOTO MASTER
Deleted Preinstalled.LenovoPhotoMaster Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{BC94C56A-3649-420C-8756-2ADEBE399D33}
Deleted Preinstalled.LenovoPhotoMaster Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{BC94C56A-3649-420C-8756-2ADEBE399D33}
Deleted Preinstalled.LenovoPower2Go Folder C:\Program Files (x86)\LENOVO\POWER2GO
Deleted Preinstalled.LenovoPower2Go Folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LENOVO\POWER2GO
Deleted Preinstalled.LenovoPower2Go Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32|UpdateP2GShortCut
Deleted Preinstalled.LenovoPower2Go Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Run|UpdateP2GShortCut
Deleted Preinstalled.LenovoPower2Go Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{40BF1E83-20EB-11D8-97C5-0009C5020658}
Deleted Preinstalled.LenovoSHAREit Folder C:\Program Files (x86)\LENOVO\SHAREIT
Deleted Preinstalled.LenovoSHAREit Registry HKLM\Software\Classes\CLSID\{430BD134-576D-4E75-87CD-0F5C6221A82B}
Deleted Preinstalled.LenovoSHAREit Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\Lenovo SHAREit_is1
Deleted Preinstalled.LenovoServiceBridge Folder C:\Users\trener\AppData\Local\PROGRAMS\LENOVO\LENOVO SERVICE BRIDGE
Deleted Preinstalled.LenovoServiceBridge Registry HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{2C74547D-EF88-47F4-85F5-BE46A31E26B7}_is1
Deleted Preinstalled.LenovoSettings Folder C:\Program Files (x86)\LENOVO\LENOVO SETTINGS
Deleted Preinstalled.LenovoSettings Folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LENOVO\LENOVO SETTINGS
Deleted Preinstalled.LenovoSettings Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{42F8AFC3-7944-46CC-9689-94FF9869D0A7}
Deleted Preinstalled.LenovoSettings Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{42F8AFC3-7944-46CC-9689-94FF9869D0A7}
Deleted Preinstalled.LenovoSolutionCenter Folder C:\Program Files\LENOVO\LENOVO SOLUTION CENTER
Deleted Preinstalled.LenovoSolutionCenter Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4386A5EF-BD23-49F4-9DAD-CD76B4F6A8BF}
Deleted Preinstalled.LenovoUpdate Folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LENOVO\LENOVO UPDATES
Deleted Preinstalled.Pokki File C:\Users\trener\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Start Menu.lnk
Deleted Preinstalled.Pokki File C:\Users\trener\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Menu.lnk


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [9042 octets] - [26/09/2021 12:09:47]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########

Re: Prosím o kontrolu logu - výrazné zpomalení počítače

Napsal: 26 zář 2021 16:38
od Rudy
OK. Dejte nové logy FRST+Addition.

Re: Prosím o kontrolu logu - výrazné zpomalení počítače

Napsal: 26 zář 2021 17:21
od Tucci
FRST_2.zip
(22.97 KiB) Staženo 86 x

Re: Prosím o kontrolu logu - výrazné zpomalení počítače

Napsal: 26 zář 2021 18:03
od Rudy
Otevřte poznámkový blok a zkopírujte do něj:
Start

CloseProcesses:
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {00C6A38C-D790-4C73-9E16-07A64E5663F4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-12-23] (Google Inc -> Google Inc.)
Task: {26E8C8D6-50BF-47A9-A653-C416D0F70068} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {27489411-B6B2-4DE7-8201-FF00091D3C09} - \Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance -> No File <==== ATTENTION
Task: {345FCE3B-F8AE-4054-BDA2-075E116F1C5D} - \Lenovo\ImController\Lenovo iM Controller Monitor -> No File <==== ATTENTION
Task: {3ABE4B19-15E7-479F-B416-0DE3B12CB7C4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-12-23] (Google Inc -> Google Inc.)
Task: {40B98C8A-C33E-4958-8FEF-BFCE7AD11154} - \Lenovo\ImController\TimeBasedEvents\e26e78a0-a06b-4fc9-b4dc-fc1beac86103 -> No File <==== ATTENTION
Task: {4A74DD90-0E8A-470D-975A-2D0F5F1EBA99} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {6E98FA43-A7A7-49BB-9280-E0F44D169D51} - \Lenovo\ImController\TimeBasedEvents\0323e848-7a19-4918-a52a-ae5ded3ffb82 -> No File <==== ATTENTION
Task: {71AF1D2C-A3E9-40EC-AE74-FE438C178170} - \Lenovo\ImController\TimeBasedEvents\e645aca1-0626-4a1b-8e38-c6cb5c5ba745 -> No File <==== ATTENTION
Task: {9893A1DB-95AF-4A99-B27E-756EE2B2F754} - \Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask -> No File <==== ATTENTION
Task: {AC676EE9-BB2A-45DB-90FB-897451C5E7B3} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {BB608588-23ED-4529-A5C1-AC7C4E081D4D} - \Lenovo\ImController\TimeBasedEvents\474488dc-3a6d-4776-9f29-e5f73e253dcf -> No File <==== ATTENTION
Task: {C1A3BBCB-322A-4A78-AE13-1D51D42165F4} - \Lenovo\ImController\TimeBasedEvents\22bb562b-4b1b-4ba9-b90a-0d925faf2d50 -> No File <==== ATTENTION
Task: {CDACDCB0-B025-4C7D-9758-4FC0F5391ACB} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {D274C3CC-2F71-4DAE-A218-A63B817624C8} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {FF7894D7-1BF1-4A9A-8927-5C51B238C21B} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Edge Extension: (No Name) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [not found]
Edge Extension: (No Name) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [not found]
Edge Extension: (No Name) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [not found]
Edge Extension: (No Name) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [not found]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK => not found
FF Plugin: @mcafee.com/MSC,version=10 -> C:\Program Files\mcafee\msc\npMcSnFFPl64.dll [No File]
FF Plugin-x32: @mcafee.com/MSC,version=10 -> C:\Program Files (x86)\McAfee\msc\npMcSnFFPl.dll [No File]
C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
ShellIconOverlayIdentifiers: [00001LenovoSyncComplete] -> {1E9CED2C-E7B4-4C47-B07A-25416393B67B} => -> No File
ContextMenuHandlers1: [SHAREit.FileContextMenuExt] -> {430BD134-576D-4E75-87CD-0F5C6221A82B} => -> No File
ContextMenuHandlers4: [SHAREit.FileContextMenuExt] -> {430BD134-576D-4E75-87CD-0F5C6221A82B} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
SearchScopes: HKU\S-1-5-21-259254674-3041541296-1202822968-1001 -> DefaultScope {F980E548-B9FF-48F8-9447-EC02B908E095} URL =
SearchScopes: HKU\S-1-5-21-259254674-3041541296-1202822968-1001 -> {F980E548-B9FF-48F8-9447-EC02B908E095} URL =
FirewallRules: [UDP Query User{4B6B6C2C-50DA-4314-A96F-508A63FDF816}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe => No File
FirewallRules: [TCP Query User{ECC1A1AD-CEE7-4112-A0A2-FFF7366A15D5}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe => No File
FirewallRules: [UDP Query User{A8A7A94F-D831-4514-8BA4-BFEBE52EA389}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe => No File
FirewallRules: [TCP Query User{0CA250C6-97C6-457E-9770-FDE31B62592E}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe => No File

EmptyTemp:
End
Uložte do C:\Users\trener\Downloads jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.

Re: Prosím o kontrolu logu - výrazné zpomalení počítače

Napsal: 26 zář 2021 19:47
od Tucci
OK, provedl jsem. Po skončení to provedlo restart. Pustil jsem znovu FRST a log přikládám.
FRST_3.zip
(21.34 KiB) Staženo 72 x

Re: Prosím o kontrolu logu - výrazné zpomalení počítače

Napsal: 26 zář 2021 20:50
od Rudy
Potřebuji vidět log z fixlog.txt. Soubor najdete v C:\Users\trener\Downloads. Děkuji.

Re: Prosím o kontrolu logu - výrazné zpomalení počítače

Napsal: 26 zář 2021 21:09
od Tucci
posílám
Fixlog.zip
(3.17 KiB) Staženo 87 x

Re: Prosím o kontrolu logu - výrazné zpomalení počítače

Napsal: 27 zář 2021 09:21
od Rudy
Smazáno. Nastala nějaká změna?

Re: Prosím o kontrolu logu - výrazné zpomalení počítače

Napsal: 28 zář 2021 10:57
od Tucci
Zdravím, je to určitě rychlejší, ikdyž by to ještě něco chtělo. Vytížení disku stále hlásí 100%, ale posun je znát.

Re: Prosím o kontrolu logu - výrazné zpomalení počítače

Napsal: 28 zář 2021 11:01
od Rudy
Jaký proces vám ten disk vytěžuje?

Re: Prosím o kontrolu logu - výrazné zpomalení počítače

Napsal: 02 říj 2021 10:26
od Tucci
nejsou tam žádné výrazné procesy, nicméně disk hlásí 100% zatížení
scan je v příloze
děkuji
zatizeni_disku.jpg
zatizeni_disku.jpg (60.69 KiB) Zobrazeno 817 x

Re: Prosím o kontrolu logu - výrazné zpomalení počítače

Napsal: 02 říj 2021 10:53
od Rudy
Tak to tohio moc nevíme. Zkuste defragmentovat disk.

Re: Prosím o kontrolu logu - výrazné zpomalení počítače

Napsal: 03 říj 2021 13:01
od Tucci
hotovo. Disk je zaplněn pouze velmi málo, je to 1TB, zaplněno cca 200 GB. Když je NTB nastartovaný a chvíli pracuje, tak se zatížení disku sníží, i na 10%. Částečně to přisuzuji i malé RAM (4 GB).