Pomalý notebook, prosím o kontrolu logu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
Mety
Level 2.5
Level 2.5
Příspěvky: 304
Registrován: duben 12
Bydliště: Markvartovice
Pohlaví: Muž
Stav:
Offline

Pomalý notebook, prosím o kontrolu logu

Příspěvekod Mety » 16 úno 2023 01:52

Zdravím, v poslední době mi přijde notebook hodně zasekaný a pomalý. Prosím o kontrolu logu.

Log z HJT:

Logfile of HiJackThis Fork by Alex Dragokas v.2.9.0.26

Platform: x64 Windows 10 (Home), 10.0.19045.2604 (ReleaseId: 2009), Service Pack: 0
Time: 16.02.2023 - 01:51 (UTC+01:00)
Language: OS: Czech (0x405). Display: Czech (0x405). Non-Unicode: Czech (0x405)
Elevated: Yes
Ran by: mates (group: Administrator) on LAPTOP-O2MJJQRI, FirstRun: yes

Chrome: 110.0.5481.100
Internet Explorer: 11.0.19041.1566
Default: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --single-argument %1 (Google Chrome)

Boot mode: Normal

Running processes:
Number | Path
1 C:\Program Files (x86)\BloodyToneMaker\BloodyToneMaker\Bloody ToneMaker1.exe
1 C:\Program Files (x86)\BloodyToneMaker\BloodyToneMaker\SDK\CM_LibraryIO.exe
1 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
1 C:\Program Files (x86)\Common Files\Overwolf\0.218.0.8\OverwolfHelper.exe
1 C:\Program Files (x86)\Common Files\Overwolf\0.218.0.8\OverwolfHelper64.exe
16 C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
1 C:\Program Files (x86)\Google\Update\1.3.36.152\GoogleCrashHandler.exe
1 C:\Program Files (x86)\Google\Update\1.3.36.152\GoogleCrashHandler64.exe
1 C:\Program Files (x86)\HP\HP CoolSense\CoolSense.exe
1 C:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe
1 C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe
1 C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe
1 C:\Program Files (x86)\HP\Shared\hpqwmiex.exe
1 C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAService.exe
1 C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAUpdateService.exe
1 C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
3 C:\Program Files (x86)\Overwolf\0.218.0.8\OverwolfBrowser.exe
1 C:\Program Files (x86)\Overwolf\Overwolf.exe
1 C:\Program Files (x86)\Wondershare\WAF\2.4.3.237\WsAppService.exe
1 C:\Program Files\AVAST Software\Avast\AvastSvc.exe
4 C:\Program Files\AVAST Software\Avast\AvastUI.exe
1 C:\Program Files\AVAST Software\Avast\aswEngSrv.exe
1 C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe
1 C:\Program Files\AVAST Software\Avast\aswidsagent.exe
1 C:\Program Files\AVAST Software\Avast\wsc_proxy.exe
1 C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
1 C:\Program Files\HPCommRecovery\HPCommRecovery.exe
1 C:\Program Files\HP\HP Enabling Services\AppHelperCap.exe
1 C:\Program Files\HP\HP Enabling Services\BridgeCommunication.exe
1 C:\Program Files\HP\HP Enabling Services\DiagsCap.exe
1 C:\Program Files\HP\HP Enabling Services\NetworkCap.exe
1 C:\Program Files\HP\HP Enabling Services\SysInfoCap.exe
1 C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
1 C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
1 C:\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe
1 C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe
1 C:\Program Files\Intel\WiFi\bin\EvtEng.exe
1 C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
2 C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
1 C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
1 C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
1 C:\Program Files\Riot Vanguard\vgtray.exe
1 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
1 C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
1 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
1 C:\Program Files\WinRAR\WinRAR.exe
1 C:\Program Files\WindowsApps\AppleInc.iTunes_12127.1.57051.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe
1 C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2204.13303.0_x64__8wekyb3d8bbwe\Cortana.exe
1 C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.14326.21318.0_x64__8wekyb3d8bbwe\HxTsr.exe
2 C:\Users\mates\AppData\Local\Discord\app-1.0.9011\Discord.exe
1 C:\Users\mates\AppData\Local\Overwolf\ProcessCache\0.218.0.8\aheglebeeekjdnkljmpngplhpedgejncjhojnndh\MetaTFT.exe
1 C:\Users\mates\AppData\Local\Overwolf\ProcessCache\0.218.0.8\pibhbkkgefgheeglaeemkkfjlhidhcedalapdggh\Porofessor.gg.exe
1 C:\Users\mates\Desktop\HiJackThis\HiJackThis.exe
1 C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
1 C:\Windows\SysWOW64\XtuService.exe
1 C:\Windows\System32\ApplicationFrameHost.exe
1 C:\Windows\System32\CompPkgSrv.exe
1 C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe
1 C:\Windows\System32\DriverStore\FileRepository\ki129369.inf_amd64_3b3c0bad4e037f26\IntelCpHDCPSvc.exe
1 C:\Windows\System32\DriverStore\FileRepository\ki129369.inf_amd64_3b3c0bad4e037f26\IntelCpHeciSvc.exe
1 C:\Windows\System32\DriverStore\FileRepository\ki129369.inf_amd64_3b3c0bad4e037f26\igfxCUIService.exe
1 C:\Windows\System32\DriverStore\FileRepository\ki129369.inf_amd64_3b3c0bad4e037f26\igfxEM.exe
1 C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_fddb643595e0b8d0\LMS.exe
2 C:\Windows\System32\DriverStore\FileRepository\nvhmi.inf_amd64_79ac8a251bb72cf6\Display.NvContainer\NVDisplay.Container.exe
1 C:\Windows\System32\Intel\DPTF\esif_uf.exe
6 C:\Windows\System32\RuntimeBroker.exe
1 C:\Windows\System32\SearchFilterHost.exe
1 C:\Windows\System32\SearchIndexer.exe
2 C:\Windows\System32\SearchProtocolHost.exe
1 C:\Windows\System32\SecurityHealthService.exe
1 C:\Windows\System32\SecurityHealthSystray.exe
1 C:\Windows\System32\SgrmBroker.exe
2 C:\Windows\System32\WUDFHost.exe
1 C:\Windows\System32\audiodg.exe
1 C:\Windows\System32\backgroundTaskHost.exe
1 C:\Windows\System32\conhost.exe
2 C:\Windows\System32\csrss.exe
1 C:\Windows\System32\ctfmon.exe
3 C:\Windows\System32\dllhost.exe
1 C:\Windows\System32\dwm.exe
2 C:\Windows\System32\fontdrvhost.exe
1 C:\Windows\System32\ibtsiva.exe
1 C:\Windows\System32\lsass.exe
1 C:\Windows\System32\oobe\UserOOBEBroker.exe
1 C:\Windows\System32\rundll32.exe
1 C:\Windows\System32\services.exe
1 C:\Windows\System32\sihost.exe
1 C:\Windows\System32\smartscreen.exe
1 C:\Windows\System32\smss.exe
1 C:\Windows\System32\spoolsv.exe
79 C:\Windows\System32\svchost.exe
4 C:\Windows\System32\taskhostw.exe
1 C:\Windows\System32\wbem\WmiPrvSE.exe
2 C:\Windows\System32\wbem\unsecapp.exe
1 C:\Windows\System32\wininit.exe
1 C:\Windows\System32\winlogon.exe
2 C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
1 C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe
1 C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe
1 C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
1 C:\Windows\explorer.exe
4 D:\HRY\Riot Games\VALORANT\live\Engine\Binaries\Win64\UnrealCEFSubProcess.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main: [Start Page] = http://hp17win10.msn.com/?pc=HCTE
O2 - HKLM\..\BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\HP\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll
O2 - HKLM\..\BHO: IEToEdge BHO - {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} - C:\Program Files (x86)\Microsoft\Edge\Application\110.0.1587.41\BHO\ie_to_edge_bho_64.dll
O2-32 - HKLM\..\BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\HP\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O2-32 - HKLM\..\BHO: IEToEdge BHO - {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} - C:\Program Files (x86)\Microsoft\Edge\Application\110.0.1587.41\BHO\ie_to_edge_bho.dll
O2-32 - HKLM\..\BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_251\bin\jp2ssv.dll
O2-32 - HKLM\..\BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_251\bin\ssv.dll
O4 - HKCU\..\Run: [BloodyToneMaker] = C:\Program Files (x86)\BloodyToneMaker\BloodyToneMaker\Bloody ToneMaker1.exe Minimum
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] = C:\Program Files\CCleaner\CCleaner64.exe /MONITOR
O4 - HKCU\..\Run: [Discord] = C:\Users\mates\AppData\Local\Discord\Update.exe --processStart Discord.exe
O4 - HKCU\..\Run: [Overwolf] = C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe -overwolfsilent
O4 - HKCU\..\Run: [Steam] = D:\Steam\steam.exe -silent
O4 - HKLM\..\Run: [AvastUI.exe] = C:\Program Files\AVAST Software\Avast\AvLaunch.exe /gui
O4 - HKLM\..\Run: [IAStorIcon] = C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
O4 - HKLM\..\Run: [RTHDVCPL] = C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s
O4 - HKLM\..\Run: [Riot Vanguard] = C:\Program Files\Riot Vanguard\vgtray.exe
O4 - HKU\S-1-5-19\..\RunOnce: [WAB Migrate] = C:\Program Files\Windows Mail\wab.exe /Upgrade
O4 - HKU\S-1-5-20\..\RunOnce: [WAB Migrate] = C:\Program Files\Windows Mail\wab.exe /Upgrade
O4-32 - HKLM\..\Run: [HPMessageService] = C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe
O4-32 - HKLM\..\Run: [Intel Driver & Support Assistant] = C:\Program Files (x86)\Intel\Driver and Support Assistant\DSATray.exe
O9 - Button: HKLM\..\{25510184-5A38-4A99-B273-DCA8EEF6CD08}: Spustí nástroj Kontrola sítě HP, který vám pomůže vyřešit problémy s připojením - C:\Program Files (x86)\HP\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Tools menu item: HKLM\..\{25510184-5A38-4A99-B273-DCA8EEF6CD08}: Kontrola sítě HP - C:\Program Files (x86)\HP\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9-32 - Button: HKLM\..\{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}: Přidat na blog - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9-32 - Button: HKLM\..\{25510184-5A38-4A99-B273-DCA8EEF6CD08}: Spustí nástroj Kontrola sítě HP, který vám pomůže vyřešit problémy s připojením - C:\Program Files (x86)\HP\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9-32 - Tools menu item: HKLM\..\{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}: &Přidat na blog prostřednictvím aplikace Windows Live Writer - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9-32 - Tools menu item: HKLM\..\{25510184-5A38-4A99-B273-DCA8EEF6CD08}: Kontrola sítě HP - C:\Program Files (x86)\HP\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O17 - DHCP DNS 1: 192.168.0.1
O21 - HKLM\..\ShellIconOverlayIdentifiers\00asw: avast - {472083B0-C522-11CF-8763-00608CC02F24} - C:\Program Files\AVAST Software\Avast\ashShell.dll
O21-32 - HKLM\..\ShellIconOverlayIdentifiers\00asw: avast - {472083B0-C522-11CF-8763-00608CC02F24} - C:\Program Files\AVAST Software\Avast\x86\ashShell.dll
O22 - Task (.job): CCleanerCrashReporting.job - C:\Program Files\CCleaner\CCleanerBugReport.exe --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --configpath "C:\Program Files\CCleaner\Setup" --guid "08ccf8ea-e8fa-467b-bd11-355c65831321" --version "6.08.10255" --silent
O22 - Task: (disabled) (update) \Microsoft\Windows\UpdateOrchestrator\Reboot_AC - C:\WINDOWS\system32\MusNotification.exe /RunOnAC RebootDialog (Microsoft)
O22 - Task: (disabled) (update) \Microsoft\Windows\UpdateOrchestrator\Reboot_Battery - C:\WINDOWS\system32\MusNotification.exe /RunOnBattery RebootDialog (Microsoft)
O22 - Task: (disabled) Adobe Flash Player PPAPI Notifier - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_255_pepper.exe -check pepperplugin
O22 - Task: (disabled) Adobe Flash Player Updater - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O22 - Task: (disabled) HPAudioSwitch - C:\Program Files (x86)\HP\HPAudioSwitch\HPAudioSwitch.exe
O22 - Task: (disabled) HPEA3JOBS - C:\Program Files\HP\HP ePrint\hpeprint.exe /CheckJobs (file missing)
O22 - Task: (disabled) HPJumpStartLaunch - C:\Program Files (x86)\HP\HP JumpStart Launch\HPJumpStartLaunch.exe
O22 - Task: (disabled) OMEN Command Center BackGround Process - C:\Program Files\HP\OMEN Ally\HPOMENBG.exe
O22 - Task: (disabled) \Agent Activation Runtime\S-1-5-21-3338606067-1684232597-4108431110-1001 - C:\WINDOWS\System32\AgentActivationRuntimeStarter.exe
O22 - Task: (disabled) \Microsoft\Windows\Management\Autopilot\DetectHardwareChange - {62B2DD2C-F129-42EE-BF59-55D3FD21C215},DetectHardwareChange - C:\WINDOWS\System32\Autopilot.dll (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\Management\Autopilot\RemediateHardwareChange - {62B2DD2C-F129-42EE-BF59-55D3FD21C215},RemediateHardwareChange - C:\WINDOWS\System32\Autopilot.dll (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\Management\Provisioning\Retry - C:\WINDOWS\system32\ProvTool.exe /turn 5 /source ProvRetryTask (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\Management\Provisioning\RunOnReboot - C:\WINDOWS\system32\ProvTool.exe /turn 5 /source ContinueSessionTask (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\Shell\FamilySafetyMonitorToastTask - {D2CBF5F7-5702-440B-8D8F-8203034A6B82},$(Arg0) - (no file)
O22 - Task: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Maintenance Work - C:\WINDOWS\system32\usoclient.exe StartMaintenanceWork (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Wake To Work - C:\WINDOWS\system32\usoclient.exe StartWork (Microsoft)
O22 - Task: (telemetry) NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe
O22 - Task: (telemetry) NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe
O22 - Task: (telemetry) NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe
O22 - Task: (telemetry) NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe
O22 - Task: (telemetry) \Microsoft\Office\Office 15 Subscription Heartbeat - C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe (Microsoft)
O22 - Task: (telemetry) \Microsoft\Office\OfficeTelemetryAgentFallBack - C:\Program Files\Microsoft Office\Office15\msoia.exe scan upload mininterval:2880 (Microsoft)
O22 - Task: (telemetry) \Microsoft\Office\OfficeTelemetryAgentLogOn - C:\Program Files\Microsoft Office\Office15\msoia.exe scan upload (Microsoft)
O22 - Task: (telemetry) \Microsoft\Windows\Application Experience\PcaPatchDbTask - C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\PcaSvc.dll,PcaPatchSdbTask (Microsoft)
O22 - Task: (update) \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker - C:\WINDOWS\system32\MusNotification.exe (Microsoft)
O22 - Task: Adobe Acrobat Update Task - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
O22 - Task: Avast Emergency Update - C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
O22 - Task: CCleaner Update - C:\Program Files\CCleaner\CCUpdate.exe
O22 - Task: CCleanerCrashReporting - C:\Program Files\CCleaner\CCleanerBugReport.exe --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --configpath "C:\Program Files\CCleaner\Setup" --guid "08ccf8ea-e8fa-467b-bd11-355c65831321" --version "6.08.10255" --silent
O22 - Task: CCleanerSkipUAC - mates - C:\Program Files\CCleaner\CCleaner.exe $(Arg0)
O22 - Task: GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
O22 - Task: GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
O22 - Task: IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 - C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic (file missing)
O22 - Task: IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 - C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe --automatic
O22 - Task: IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon - C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe --automatic
O22 - Task: NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe
O22 - Task: NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
O22 - Task: NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe --launcher=TaskScheduler
O22 - Task: NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe
O22 - Task: NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe
O22 - Task: Opera scheduled Autoupdate 1610194232 - C:\Users\mates\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate $(Arg0)
O22 - Task: Overwolf Updater Task - C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe /RunningFrom Schedule
O22 - Task: USER_ESRV_SVC_QUEENCREEK - C:\WINDOWS\System32\Wscript.exe //B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs"
O22 - Task: \AVAST Software\Overseer - C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe /from_scheduler:1
O22 - Task: \HP\HP CoolSense\HP CoolSense Start at Logon - C:\Program Files (x86)\HP\HP CoolSense\CoolSense.exe /byrunkey
O22 - Task: \Hewlett-Packard\HP Support Assistant\HP Support Assistant Update Notice - C:\Program Files (x86)\HP\HP Support Framework\Resources\BingPopup\BingPopup.exe /show
O22 - Task: \Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report - C:\Program Files (x86)\HP\HP Support Framework\Resources\HPSFReport.exe /send
O22 - Task: \Microsoft\Windows Live\SOXE\Extractor Definitions Update Task - {3519154C-227E-47F3-9CC9-12C3F05817F1} - (no file)
O22 - Task: \Microsoft\Windows\AppListBackup\Backup - {E0DCC2CC-3354-45F2-8914-519E07809082} - C:\WINDOWS\system32\AppListBackupLauncher.dll (Microsoft)
O22 - Task: \Microsoft\Windows\Printing\PrinterCleanupTask - {C56F065E-DE49-4E42-BE7C-305C45609D25} - C:\WINDOWS\System32\PrinterCleanupTask.dll (Microsoft)
O22 - Task: \Microsoft\Windows\SMB\UninstallSMB1ClientTask - C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Unrestricted -NonInteractive -NoProfile -WindowStyle Hidden "& C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -Scenario Client"
O22 - Task: \Microsoft\Windows\SMB\UninstallSMB1ServerTask - C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Unrestricted -NonInteractive -NoProfile -WindowStyle Hidden "& C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -Scenario Server"
O22 - Task: \Microsoft\Windows\Shell\ThemesSyncedImageDownload - {79F8E185-4E45-4B74-8182-02AA430661E4} - C:\WINDOWS\System32\Themes.SsfDownload.ScheduledTask.dll (Microsoft)
O22 - Task: \Microsoft\Windows\UpdateOrchestrator\AC Power Install - C:\WINDOWS\system32\usoclient.exe StartInstall (Microsoft)
O22 - Task: \Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler - C:\Program Files\RUXIM\PLUGscheduler.exe (Microsoft)
O22 - Task: \Microsoft\Windows\rempl\shell - C:\Program Files\rempl\sedlauncher.exe (file missing)
O23 - Service R2: Adobe Acrobat Update Service - (AdobeARMservice) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service R2: Avast Antivirus - (avast! Antivirus) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe /runassvc
O23 - Service R2: Avast Tools - (avast! Tools) - C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe /runassvc
O23 - Service R2: AvastWscReporter - C:\Program Files\AVAST Software\Avast\wsc_proxy.exe /runassvc /rpcserver
O23 - Service R2: Energy Server Service queencreek - (ESRV_SVC_QUEENCREEK) - C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe "--AUTO_START" "--start" "--start_options_registry_key" "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\ESRV_SVC_QUEENCREEK\_start"
O23 - Service R2: HP App Helper HSA Service - (HPAppHelperCap) - C:\Program Files\HP\HP Enabling Services\AppHelperCap.exe
O23 - Service R2: HP Comm Recovery - (HP Comm Recover) - C:\Program Files\HPCommRecovery\HPCommRecovery.exe
O23 - Service R2: HP Diagnostics HSA Service - (HPDiagsCap) - C:\Program Files\HP\HP Enabling Services\DiagsCap.exe
O23 - Service R2: HP JumpStart Bridge - (HPJumpStartBridge) - c:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe
O23 - Service R2: HP Network HSA Service - (HPNetworkCap) - C:\Program Files\HP\HP Enabling Services\NetworkCap.exe
O23 - Service R2: HP System Info HSA Service - (HPSysInfoCap) - C:\Program Files\HP\HP Enabling Services\SysInfoCap.exe
O23 - Service R2: HPWMISVC - C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe
O23 - Service R2: Intel Bluetooth Service - (ibtsiva) - C:\WINDOWS\System32\ibtsiva.exe
O23 - Service R2: Intel(R) Content Protection HDCP Service - (cplspcon) - C:\WINDOWS\System32\DriverStore\FileRepository\ki129369.inf_amd64_3b3c0bad4e037f26\IntelCpHDCPSvc.exe
O23 - Service R2: Intel(R) Driver & Support Assistant - (DSAService) - C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAService.exe
O23 - Service R2: Intel(R) Dynamic Application Loader Host Interface Service - (jhi_service) - C:\WINDOWS\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe
O23 - Service R2: Intel(R) Dynamic Platform and Thermal Framework service - (esifsvc) - C:\WINDOWS\System32\Intel\DPTF\esif_uf.exe
O23 - Service R2: Intel(R) HD Graphics Control Panel Service - (igfxCUIService2.0.0.0) - C:\WINDOWS\System32\DriverStore\FileRepository\ki129369.inf_amd64_3b3c0bad4e037f26\igfxCUIService.exe
O23 - Service R2: Intel(R) Management and Security Application Local Management Service - (LMS) - C:\WINDOWS\System32\DriverStore\FileRepository\lms.inf_amd64_fddb643595e0b8d0\LMS.exe
O23 - Service R2: Intel(R) PROSet/Wireless Event Log - (EvtEng) - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service R2: Intel(R) PROSet/Wireless Registry Service - (RegSrvc) - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service R2: Intel(R) PROSet/Wireless Zero Configuration Service - (ZeroConfigService) - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
O23 - Service R2: Intel(R) Rapid Storage Technology - (IAStorDataMgrSvc) - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service R2: Intel(R) System Usage Report Service SystemUsageReportSvc_QUEENCREEK - (SystemUsageReportSvc_QUEENCREEK) - C:\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe
O23 - Service R2: NVIDIA Display Container LS - (NVDisplay.ContainerLocalSystem) - C:\WINDOWS\System32\DriverStore\FileRepository\nvhmi.inf_amd64_79ac8a251bb72cf6\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nvhmi.inf_amd64_79ac8a251bb72cf6\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
O23 - Service R2: NVIDIA LocalSystem Container - (NvContainerLocalSystem) - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe -s NvContainerLocalSystem -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000 -st "C:\Program Files\NVIDIA Corporation\NvContainer\NvContainerTelemetryApi.dll"
O23 - Service R2: Realtek Audio Service - (RtkAudioService) - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service R2: SynTPEnh Caller Service - (SynTPEnhService) - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service R2: Wondershare Application Framework Service - (WsAppService) - C:\Program Files (x86)\Wondershare\WAF\2.4.3.237\WsAppService.exe
O23 - Service R2: XTUOCDriverService - (XTU3SERVICE) - C:\WINDOWS\SysWOW64\XtuService.exe
O23 - Service R3: HP CASL Framework Service - (hpqcaslwmiex) - C:\Program Files (x86)\HP\Shared\hpqwmiex.exe
O23 - Service R3: Intel(R) Content Protection HECI Service - (cphs) - C:\WINDOWS\System32\DriverStore\FileRepository\ki129369.inf_amd64_3b3c0bad4e037f26\IntelCpHeciSvc.exe
O23 - Service R3: Intel(R) Driver & Support Assistant Updater - (DSAUpdateService) - C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAUpdateService.exe
O23 - Service R3: aswbIDSAgent - C:\Program Files\AVAST Software\Avast\aswidsagent.exe
O23 - Service S2: Intel(R) TPM Provisioning Service - C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_76523213b78d9046\lib\TPMProvisioningService.exe
O23 - Service S2: Služba Aktualizace Google (gupdate) - (gupdate) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /svc
O23 - Service S3: Adobe Flash Player Update Service - (AdobeFlashPlayerUpdateSvc) - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service S3: BattlEye Service - (BEService) - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service S3: EasyAntiCheat - C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe
O23 - Service S3: Google Chrome Elevation Service (GoogleChromeElevationService) - (GoogleChromeElevationService) - C:\Program Files (x86)\Google\Chrome\Application\110.0.5481.100\elevation_service.exe
O23 - Service S3: Intel(R) Capability Licensing Service TCP IP Interface - C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_76523213b78d9046\lib\SocketHeciServer.exe
O23 - Service S3: Intel(R) Optane(TM) Memory Service - (iaStorAfsService) - C:\windows\IAStorAfsService\iaStorAfsService.exe
O23 - Service S3: Intel(R) SUR QC Software Asset Manager - (Intel(R) SUR QC SAM) - C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe
O23 - Service S3: NVIDIA FrameView SDK service - (FvSvc) - C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe -service
O23 - Service S3: Office 64 Source Engine - (ose64) - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
O23 - Service S3: Overwolf Updater Windows SCM - (OverwolfUpdater) - C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe /RunningFrom SCM
O23 - Service S3: Služba Aktualizace Google (gupdatem) - (gupdatem) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /medsvc
O23 - Service S3: Steam Client Service - C:\Program Files (x86)\Common Files\Steam\steamservice.exe /RunAsService
O23 - Service S3: User Energy Server Service queencreek - (USER_ESRV_SVC_QUEENCREEK) - C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe "--run_as_user_process"
O23 - Service S3: Wireless PAN DHCP Server - (MyWiFiDHCPDNS) - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service S3: vgc - C:\Program Files\Riot Vanguard\vgc.exe


--
End of file - Time spent: 14,3 sec. - 55454 bytes, CRC32: FFFFFFFF. Sign: ᘗ

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43061
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Pomalý notebook, prosím o kontrolu logu

Příspěvekod jaro3 » 16 úno 2023 14:54

Raději tento HJT:
https://sourceforge.net/projects/hjt/fi ... e/download

Stáhni si ATF Cleaner
https://www.majorgeeks.com/mg/getmirror ... ner,2.html
Poklepej na ATF Cleaner.exe, klikni na select all, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
- Pokud používáš jen Google Chrome ,Edge , tak ATF nemusíš použít.


Stáhni si TFC
http://www.geekstogo.com/forum/files/fi ... -oldtimer/
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

Stáhni AdwCleaner (by Xplode)
http://www.bleepingcomputer.com/download/adwcleaner/
http://www.adlice.com/downloadprogress/
pro majitele win7 stáhni zde:
https://filehippo.com/download_adwcleaner/ ( nedávej aktualizaci!)

Ulož si ho na svojí plochu . Klikni na „Souhlasím“ k povrzení podmínek.
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Skenování“
Po skenu se objeví log , který se otevře. ( jinak je uložen systémovem disku jako) C:\AdwCleaner\Logs, jeho obsah sem celý vlož.

Stáhni si Malwarebytes' Anti-Malware
https://www.malwarebytes.com/mwb-download/thankyou/

na plochu , nainstaluj a spusť ho
-Pokud není program aktuální , klikni na možnost „Aktualizovat nyní“ či „Opravit nyní“.
- bude nalezena aktualizace a nainstaluje se.
- poté klikni na Spustit skenování
- po proběhnutí skenu se ti objeví hláška vpravo dole, tak klikni na Zobrazit zprávu a vyber Export a vyber Kopírovat do schránky a vlož sem celý log. Nebo klikni na „Textový soubor ( .txt)“ a log si ulož.
-jinak se log nachází v programu po kliknutí na „Zprávy“ , nebo je uložen zde: C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Logs

- po té klikni na tlačítko Dokončit, a program zavři křížkem vpravo nahoře.
(zatím nic nemaž!).
Pokud budou problémy , spusť v nouz. režimu.

Stáhni si CrystalDiskInfo
https://www.stahuj.cz/utility_a_ostatni ... ldiskinfo/
Spusť program a klikni na Úpravy-Kopírovat. Poté sem vlož pomocí Ctrl+V obsah logu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Mety
Level 2.5
Level 2.5
Příspěvky: 304
Registrován: duben 12
Bydliště: Markvartovice
Pohlaví: Muž
Stav:
Offline

Re: Pomalý notebook, prosím o kontrolu logu

Příspěvekod Mety » 16 úno 2023 14:55

Přikládám nový log z HJT:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:55:17, on 16.02.2023
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.19041.1566)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
C:\Program Files (x86)\BloodyToneMaker\BloodyToneMaker\Bloody ToneMaker1.exe
C:\Program Files (x86)\HP\HP CoolSense\CoolSense.exe
C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe
D:\Steam\steam.exe
C:\Users\mates\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hp17win10.msn.com/?pc=HCTE
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: IEToEdge BHO - {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} - C:\Program Files (x86)\Microsoft\Edge\Application\110.0.1587.41\BHO\ie_to_edge_bho.dll
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_251\bin\ssv.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_251\bin\jp2ssv.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\HP\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O4 - HKLM\..\Run: [HPMessageService] C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe
O4 - HKLM\..\Run: [Intel Driver & Support Assistant] C:\Program Files (x86)\Intel\Driver and Support Assistant\DSATray.exe
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [BloodyToneMaker] "C:\Program Files (x86)\BloodyToneMaker\BloodyToneMaker\Bloody ToneMaker1.exe" Minimum
O4 - HKCU\..\Run: [Overwolf] C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe -overwolfsilent
O4 - HKCU\..\Run: [Steam] "D:\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [Discord] "C:\Users\mates\AppData\Local\Discord\Update.exe" --processStart Discord.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office15\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: @C:\Program Files (x86)\HP\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\HP\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\HP\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\HP\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Inc. - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: aswbIDSAgent - AVAST Software - C:\Program Files\AVAST Software\Avast\aswidsagent.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Avast Tools (avast! Tools) - AVAST Software - C:\Program Files\AVAST Software\Avast\aswToolsSvc.exe
O23 - Service: AvastWscReporter - AVAST Software - C:\Program Files\AVAST Software\Avast\wsc_proxy.exe
O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\ki129369.inf_amd64_3b3c0bad4e037f26\IntelCpHeciSvc.exe
O23 - Service: Intel(R) Content Protection HDCP Service (cplspcon) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\ki129369.inf_amd64_3b3c0bad4e037f26\IntelCpHDCPSvc.exe
O23 - Service: @%SystemRoot%\system32\CredentialEnrollmentManager.exe,-100 (CredentialEnrollmentManagerUserSvc) - Unknown owner - C:\WINDOWS\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: CredentialEnrollmentManagerUserSvc_493c5 - Unknown owner - C:\WINDOWS\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: Intel(R) Driver & Support Assistant (DSAService) - Intel - C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAService.exe
O23 - Service: Intel(R) Driver & Support Assistant Updater (DSAUpdateService) - Intel - C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAUpdateService.exe
O23 - Service: EasyAntiCheat - Epic Games, Inc - C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @oem3.inf,%ServiceDisplayName%;Intel(R) Dynamic Platform and Thermal Framework service (esifsvc) - Unknown owner - C:\WINDOWS\System32\Intel\DPTF\esif_uf.exe (file missing)
O23 - Service: Energy Server Service queencreek (ESRV_SVC_QUEENCREEK) - Unknown owner - C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: NVIDIA FrameView SDK service (FvSvc) - NVIDIA - C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) (GoogleChromeElevationService) - Google LLC - C:\Program Files (x86)\Google\Chrome\Application\110.0.5481.100\elevation_service.exe
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Comm Recovery (HP Comm Recover) - HP Inc. - C:\Program Files\HPCommRecovery\HPCommRecovery.exe
O23 - Service: HP App Helper HSA Service (HPAppHelperCap) - HP Inc. - C:\Program Files\HP\HP Enabling Services\AppHelperCap.exe
O23 - Service: HP Diagnostics HSA Service (HPDiagsCap) - HP Inc. - C:\Program Files\HP\HP Enabling Services\DiagsCap.exe
O23 - Service: HP JumpStart Bridge (HPJumpStartBridge) - HP Inc. - c:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe
O23 - Service: HP Network HSA Service (HPNetworkCap) - HP Inc. - C:\Program Files\HP\HP Enabling Services\NetworkCap.exe
O23 - Service: HP CASL Framework Service (hpqcaslwmiex) - HP - C:\Program Files (x86)\HP\Shared\hpqwmiex.exe
O23 - Service: HP System Info HSA Service (HPSysInfoCap) - HP Inc. - C:\Program Files\HP\HP Enabling Services\SysInfoCap.exe
O23 - Service: HPWMISVC - HP Inc. - C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe
O23 - Service: Intel(R) Optane(TM) Memory Service (iaStorAfsService) - Intel Corporation - C:\windows\IAStorAfsService\iaStorAfsService.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @oem32.inf,%SERVICE_NAME%;Intel Bluetooth Service (ibtsiva) - Unknown owner - C:\WINDOWS\System32\ibtsiva (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\ki129369.inf_amd64_3b3c0bad4e037f26\igfxCUIService.exe
O23 - Service: @oem92.inf,%SocketHECIServiceName%;Intel(R) Capability Licensing Service TCP IP Interface (Intel(R) Capability Licensing Service TCP IP Interface) - Intel(R) Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_76523213b78d9046\lib\SocketHeciServer.exe
O23 - Service: Intel(R) SUR QC Software Asset Manager (Intel(R) SUR QC SAM) - Intel Corporation - C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe
O23 - Service: @oem92.inf,%TPMProvisioningServiceName%;Intel(R) TPM Provisioning Service (Intel(R) TPM Provisioning Service) - Intel(R) Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_76523213b78d9046\lib\TPMProvisioningService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\lms.inf_amd64_fddb643595e0b8d0\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\nvhmi.inf_amd64_79ac8a251bb72cf6\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: Overwolf Updater Windows SCM (OverwolfUpdater) - Overwolf LTD - C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe
O23 - Service: @%systemroot%\system32\PerceptionSimulation\PerceptionSimulationService.exe,-101 (perceptionsimulation) - Unknown owner - C:\WINDOWS\system32\PerceptionSimulation\PerceptionSimulationService.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\WINDOWS\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SgrmBroker.exe,-100 (SgrmBroker) - Unknown owner - C:\WINDOWS\system32\SgrmBroker.exe (file missing)
O23 - Service: @firewallapi.dll,-50323 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\WINDOWS\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\steamservice.exe
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: Intel(R) System Usage Report Service SystemUsageReportSvc_QUEENCREEK (SystemUsageReportSvc_QUEENCREEK) - Unknown owner - C:\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: User Energy Server Service queencreek (USER_ESRV_SVC_QUEENCREEK) - Unknown owner - C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: vgc - Riot Games, Inc. - C:\Program Files\Riot Vanguard\vgc.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Wondershare Application Framework Service (WsAppService) - Wondershare - C:\Program Files (x86)\Wondershare\WAF\2.4.3.237\WsAppService.exe
O23 - Service: @oem13.inf,%OCServiceName%;XTUOCDriverService (XTU3SERVICE) - Intel(R) Corporation - C:\WINDOWS\SysWOW64\XtuService.exe
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe

--
End of file - 17573 bytes

Uživatelský avatar
Mety
Level 2.5
Level 2.5
Příspěvky: 304
Registrován: duben 12
Bydliště: Markvartovice
Pohlaví: Muž
Stav:
Offline

Re: Pomalý notebook, prosím o kontrolu logu

Příspěvekod Mety » 16 úno 2023 15:01

Log z AdwCleaner:

# -------------------------------
# Malwarebytes AdwCleaner 8.4.0.0
# -------------------------------
# Build: 08-30-2022
# Database: 2022-10-10.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 02-16-2023
# Duration: 00:00:06
# OS: Windows 10 (Build 19045.2604)
# Scanned: 32100
# Detected: 29


***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

No malicious folders found.

***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

No malicious registry entries found.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries found.

***** [ Chromium URLs ] *****

No malicious Chromium URLs found.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries found.

***** [ Firefox URLs ] *****

No malicious Firefox URLs found.

***** [ Hosts File Entries ] *****

No malicious hosts file entries found.

***** [ Preinstalled Software ] *****

Preinstalled.HPAudioSwitch Folder C:\Program Files (x86)\HP\HPAUDIOSWITCH
Preinstalled.HPAudioSwitch Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{054EBA81-8C83-451D-85A3-E766A01BECA5}
Preinstalled.HPAudioSwitch Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HPAudioSwitch
Preinstalled.HPAudioSwitch Task C:\Windows\System32\Tasks\HPAUDIOSWITCH
Preinstalled.HPCoolSense Folder C:\Program Files (x86)\HP\HP COOLSENSE
Preinstalled.HPCoolSense Folder C:\Users\mates\AppData\Local\HP\HP COOLSENSE
Preinstalled.HPCoolSense Folder C:\Windows\System32\Tasks\HP\HP COOLSENSE
Preinstalled.HPCoolSense Registry HKLM\Software\Classes\CLSID\{224695A4-BD5E-4C38-B354-A4C828E61BF7}
Preinstalled.HPJumpStartBridge Folder C:\Program Files (x86)\HP\HP JUMPSTART BRIDGE
Preinstalled.HPJumpStartLaunch Folder C:\Program Files (x86)\HP\HP JUMPSTART LAUNCH
Preinstalled.HPJumpStartLaunch Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D88C2449-7232-402B-AB2C-E68BCF0CF4D6}
Preinstalled.HPJumpStartLaunch Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HPJumpStartLaunch
Preinstalled.HPJumpStartLaunch Task C:\Windows\System32\Tasks\HPJUMPSTARTLAUNCH
Preinstalled.HPRegistrationService Folder C:\Program Files (x86)\HP\HP REGISTRATION SERVICE
Preinstalled.HPRegistrationService Folder C:\ProgramData\HP\HP REGISTRATION SERVICE
Preinstalled.HPSupportAssistant Folder C:\HP\SUPPORT
Preinstalled.HPSupportAssistant Folder C:\Program Files (x86)\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
Preinstalled.HPSupportAssistant Folder C:\ProgramData\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
Preinstalled.HPSupportAssistant Folder C:\Users\mates\AppData\Roaming\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
Preinstalled.HPSupportAssistant Folder C:\Windows\System32\config\systemprofile\AppData\Local\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
Preinstalled.HPSupportAssistant Registry HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Preinstalled.HPSupportAssistant Registry HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Preinstalled.HPSupportAssistant Registry HKLM\Software\Classes\CLSID\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Preinstalled.HPSupportAssistant Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Preinstalled.HPSupportAssistant Registry HKLM\Software\Wow6432Node\\Classes\CLSID\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Preinstalled.HPSupportAssistant Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Preinstalled.HPSupportAssistant Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{4AAC4B07-77EF-4BCF-88DC-D24E4DE683E8}
Preinstalled.HPSureConnect Folder C:\Program Files\HPCOMMRECOVERY
Preinstalled.HPSureConnect Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{6468C4A5-E47E-405F-B675-A70A70983EA6}


AdwCleaner[S00].txt - [4700 octets] - [19/08/2022 22:12:08]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S01].txt ##########

Uživatelský avatar
Mety
Level 2.5
Level 2.5
Příspěvky: 304
Registrován: duben 12
Bydliště: Markvartovice
Pohlaví: Muž
Stav:
Offline

Re: Pomalý notebook, prosím o kontrolu logu

Příspěvekod Mety » 16 úno 2023 15:08

Log z Mbam:

Malwarebytes
www.malwarebytes.com

-Podrobnosti logovacího souboru-
Datum skenování: 16.02.23
Čas skenování: 15:03
Logovací soubor: a5acdaa6-ae02-11ed-a003-ace2d359d050.json

-Informace o softwaru-
Verze: 4.5.22.236
Verze komponentů: 1.0.1915
Aktualizovat verzi balíku komponent: 1.0.65772
Licence: Zkušební

-Systémová informace-
OS: Windows 10 (Build 19045.2604)
CPU: x64
Systém souborů: NTFS
Uživatel: LAPTOP-O2MJJQRI\mates

-Shrnutí skenování-
Typ skenování: Skenování hrozeb (Threat Scan)
Spuštění skenování: Ruční
Výsledek: Dokončeno
Skenované objekty: 333185
Zjištěné hrozby: 0
Hrozby umístěné do karantény: 0
Uplynulý čas: 4 min, 22 sek

-Možnosti skenování-
Paměť: Povoleno
Start: Povoleno
Systém souborů: Povoleno
Archivy: Povoleno
Rootkity: Zakázáno
Heuristika: Povoleno
Potenciálně nežádoucí program: Detekovat
Potenciálně nežádoucí modifikace: Detekovat

-Podrobnosti skenování-
Proces: 0
(Nebyly zjištěny žádné škodlivé položky)

Modul: 0
(Nebyly zjištěny žádné škodlivé položky)

Klíč registru: 0
(Nebyly zjištěny žádné škodlivé položky)

Hodnota v registru: 0
(Nebyly zjištěny žádné škodlivé položky)

Data registrů: 0
(Nebyly zjištěny žádné škodlivé položky)

Datové proudy: 0
(Nebyly zjištěny žádné škodlivé položky)

Adresář: 0
(Nebyly zjištěny žádné škodlivé položky)

Soubor: 0
(Nebyly zjištěny žádné škodlivé položky)

Fyzický sektor: 0
(Nebyly zjištěny žádné škodlivé položky)

WMI: 0
(Nebyly zjištěny žádné škodlivé položky)


(end)

Uživatelský avatar
Mety
Level 2.5
Level 2.5
Příspěvky: 304
Registrován: duben 12
Bydliště: Markvartovice
Pohlaví: Muž
Stav:
Offline

Re: Pomalý notebook, prosím o kontrolu logu

Příspěvekod Mety » 16 úno 2023 15:10

Log z CrystalDiskInfo:

----------------------------------------------------------------------------
CrystalDiskInfo 8.17.14 (C) 2008-2022 hiyohiyo
Crystal Dew World: https://crystalmark.info/
----------------------------------------------------------------------------

OS : Windows 10 [10.0 Build 19045] (x64)
Date : 2023/02/16 15:09:24

-- Controller Map ----------------------------------------------------------
+ Intel(R) 100 Series/C230 Chipset Family SATA AHCI Controller [ATA]
- ST1000LM049-2GH172
- Řadič prostorů úložišť [SCSI]
+ Řadič Standard NVM Express [SCSI]
- SAMSUNG MZVLW256HEHP-000H1

-- Disk List ---------------------------------------------------------------
(01) SAMSUNG MZVLW256HEHP-000H1 : 256,0 GB [0/0/0, sq] - nv
(02) ST1000LM049-2GH172 : 1000,2 GB [1/1/2, pd1]

----------------------------------------------------------------------------
(01) SAMSUNG MZVLW256HEHP-000H1
----------------------------------------------------------------------------
Model : SAMSUNG MZVLW256HEHP-000H1
Firmware : CXB73H1Q
Serial Number : S340NX0JC04389
Disk Size : 256,0 GB
Interface : NVM Express
Standard : NVM Express 1.2
Transfer Mode : PCIe 3.0 x4 | PCIe 3.0 x4
Power On Hours : 3576 hodin
Power On Count : 4997 krát
Host Reads : 28998 GB
Host Writes : 20986 GB
Temperature : 43 C (109 F)
Health Status : Dobrý (91 %)
Features : S.M.A.R.T., TRIM, VolatileWriteCache
Drive Letter : C:

-- S.M.A.R.T. --------------------------------------------------------------
ID RawValues(6) Attribute Name
01 000000000000 Kritické varování
02 00000000013C Složená teplota
03 000000000064 Rezerva k dispozici
04 000000000005 Dostupná náhradní prahová hodnota
05 000000000009 Použité procento
06 0000039FF0C8 Čtení datových jednotek
07 0000029F9104 Zapsané datové jednotky
08 000035948005 Příkazy pro hostitelské čtení
09 00002A2A412C Příkazy pro zápis hostitele
0A 000000000A56 Čas obsazení řadiče
0B 000000001385 Napájecí cykly
0C 000000000DF8 Hodiny napájení
0D 000000000027 Nebezpečné vypnutí
0E 000000000000 Chyby v médiích a integritě dat
0F 00000000129C Počet položek protokolu chybových informací

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 144D 144D 3353 3034 584E 4A30 3043 3334 3938 2020
010: 2020 2020 4153 534D 4E55 2047 5A4D 4C56 3257 3635
020: 4548 5048 302D 3030 3148 2020 2020 2020 2020 2020
030: 2020 2020 5843 3742 4833 5131 3802 0025 0000 0002
040: 0200 0001 86A0 0001 4B40 004C 0000 0000 0000 0000
050: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
060: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
070: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
080: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
090: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
100: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
110: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
120: 0000 0000 0000 0000 0000 0000 0000 0000 0017 0707
130: 0316 043F 0101 0155 0158 0032 0000 0000 0000 0000
140: 6000 9E65 003B 0000 0000 0000 0000 0000 0000 0000
150: 0000 0000 0000 0000 0000 0000 0000 0000 0023 0000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
210: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
220: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 0000

-- SMART_NVME --------------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 00 3C 01 64 05 09 00 00 00 00 00 00 00 00 00 00
010: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
020: C9 F0 9F 03 00 00 00 00 00 00 00 00 00 00 00 00
030: 06 91 9F 02 00 00 00 00 00 00 00 00 00 00 00 00
040: 2D 80 94 35 00 00 00 00 00 00 00 00 00 00 00 00
050: 3F 41 2A 2A 00 00 00 00 00 00 00 00 00 00 00 00
060: 56 0A 00 00 00 00 00 00 00 00 00 00 00 00 00 00
070: 85 13 00 00 00 00 00 00 00 00 00 00 00 00 00 00
080: F8 0D 00 00 00 00 00 00 00 00 00 00 00 00 00 00
090: 27 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0B0: 9C 12 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0C0: 00 00 00 00 00 00 00 00 3C 01 52 01 00 00 00 00
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

----------------------------------------------------------------------------
(02) ST1000LM049-2GH172
----------------------------------------------------------------------------
Model : ST1000LM049-2GH172
Firmware : RXM3
Serial Number : WGS0DWVE
Disk Size : 1000,2 GB (8,4/137,4/1000,2/----)
Buffer Size : Neznámy údaj
Queue Depth : 32
# of Sectors : 1953525168
Rotation Rate : 7200 RPM
Interface : Serial ATA
Major Version : ACS-3
Minor Version : ACS-3 Revision 3b
Transfer Mode : SATA/600 | SATA/600
Power On Hours : 9500 hodin
Power On Count : 4995 krát
Temperature : 34 C (93 F)
Health Status : Dobrý
Features : S.M.A.R.T., APM, NCQ, TRIM, GPL
APM Level : 8080h [ON]
AAM Level : ----
Drive Letter : D: E:

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 _76 _64 __6 0000090E240D Počet chyb čtení
03 _99 _99 __0 000000000000 Čas na roztočení ploten
04 _89 _89 __0 000000002E69 Počet spuštění/zastavení
05 100 100 _36 000000000000 Počet přemapovaných sektorů
07 _81 _60 _45 000007402BF5 Počet chybných hledání
09 _90 _90 __0 6CF80000251C Hodin v činnosti
0A 100 100 _97 000000000000 Počet opakovaných pokusů o roztočení ploten
0C _96 _96 __0 000000001383 Počet cyklů zapnutí zařízení
B7 100 100 __0 000000000000 Specifický pro výrobce
B8 100 100 _97 000000000000 Ukončovacích chyb
BB 100 100 __0 000000000000 Ohlášeno neopravitelných chyb
BC 100 100 __0 000000000000 Časový limit příkazu
BD 100 100 __0 000000000000 Vysoká rychlost zápisu
BE _66 _47 _40 000022160022 Teplota toku vzduchu
BF 100 100 __0 00000000000B Počet udalostí zaznamenaných otřesovým senzorem
C0 100 100 __0 00000000000A Počet vypnutí disku
C1 _35 _35 __0 00000001FD5A Počet cyklů načítání/vymazání
C2 _34 _53 __0 000500000022 Teplota
C4 100 100 __0 000000000000 Počet udalostí s číslem realokování sektorů
C5 100 100 __0 000000000000 Počet podezřelých sektorů
C6 100 100 __0 000000000000 Počet neopravitelných sektorů
C7 100 100 __0 000000000000 Počet chyb v kontrolním součtu UltraDMA
FE 100 100 __0 000000000000 Ochrana proti pádu

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 0C5A 3FFF C837 0010 0000 0000 003F 0000 0000 0000
010: 5747 5330 4457 5645 2020 2020 2020 2020 2020 2020
020: 0000 0000 0000 5258 4D33 2020 2020 5354 3130 3030
030: 4C4D 3034 392D 3247 4831 3732 2020 2020 2020 2020
040: 2020 2020 2020 2020 2020 2020 2020 8010 4000 2F00
050: 4000 0200 0200 0007 3FFF 0010 003F FC10 00FB 5910
060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0100
070: 0000 0000 0000 0000 0000 001F 8D0E 0006 004C 004C
080: 07F0 001F 706B 7469 6123 7069 B449 6123 203F 003D
090: 003D 8080 FFFE 0000 0000 0000 0000 0000 0000 0000
100: 6DB0 7470 0000 0000 0000 0008 6003 0000 5000 C500
110: AC69 BA2E 0000 0000 0000 0000 0000 0000 0000 401C
120: 401C 0000 0000 0000 0000 0000 0000 0000 0021 6DB0
130: 7470 6DB0 7470 2020 0002 0140 0100 5000 3C06 3C0A
140: 0000 0078 0000 0008 0000 0000 BDFF 0280 0000 0000
150: 0008 0000 0000 0027 0000 8000 0000 0100 AE00 8000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0003 0001
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 303D 0000 0000 4000
210: 0000 0000 0000 0000 0000 0000 0000 1C20 0000 0000
220: 0000 0000 107F 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0001 0080 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 9CA5

-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 0A 00 01 2F 00 4C 40 0D 24 0E 09 00 00 00 03 27
010: 00 63 63 00 00 00 00 00 00 00 04 32 00 59 59 69
020: 2E 00 00 00 00 00 05 33 00 64 64 00 00 00 00 00
030: 00 00 07 2F 00 51 3C F5 2B 40 07 00 00 00 09 32
040: 00 5A 5A 1C 25 00 00 F8 6C 07 0A 33 00 64 64 00
050: 00 00 00 00 00 00 0C 32 00 60 60 83 13 00 00 00
060: 00 00 B7 32 00 64 64 00 00 00 00 00 00 00 B8 3B
070: 00 64 64 00 00 00 00 00 00 00 BB 32 00 64 64 00
080: 00 00 00 00 00 00 BC 32 00 64 64 00 00 00 00 00
090: 00 00 BD 3A 00 64 64 00 00 00 00 00 00 00 BE 22
0A0: 00 42 2F 22 00 16 22 00 00 00 BF 32 00 64 64 0B
0B0: 00 00 00 00 00 00 C0 32 00 64 64 0A 00 00 00 00
0C0: 00 01 C1 32 00 23 23 5A FD 01 00 00 00 00 C2 22
0D0: 00 22 35 22 00 00 00 05 00 00 C4 32 00 64 64 00
0E0: 00 00 00 00 00 00 C5 32 00 64 64 00 00 00 00 00
0F0: 00 00 C6 30 00 64 64 00 00 00 00 00 00 00 C7 32
100: 00 64 64 00 00 00 00 00 00 00 FE 32 00 64 64 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 51
170: 03 00 01 00 02 78 00 00 00 00 00 00 00 00 00 00
180: 00 00 02 00 FC 00 00 00 05 01 01 01 01 01 01 01
190: 01 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00
1A0: 00 00 00 00 0B 00 00 00 3B A7 02 F3 1A 1F 00 00
1B0: 00 00 00 00 01 00 B6 07 D5 28 38 DB 01 00 00 00
1C0: 3B 59 74 77 03 00 00 00 00 00 00 00 00 00 00 00
1D0: 01 00 00 00 04 00 00 00 56 0B 00 00 01 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 02
1F0: 00 00 00 00 00 00 00 00 00 00 03 17 00 00 00 AA

-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 20 00 01 06 00 00 00 00 00 00 00 00 00 00 03 00
010: 00 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00
020: 00 00 00 00 00 00 05 24 00 00 00 00 00 00 00 00
030: 00 00 07 2D 00 00 00 00 00 00 00 00 00 00 09 00
040: 00 00 00 00 00 00 00 00 00 00 0A 61 00 00 00 00
050: 00 00 00 00 00 00 0C 00 00 00 00 00 00 00 00 00
060: 00 00 B7 00 00 00 00 00 00 00 00 00 00 00 B8 61
070: 00 00 00 00 00 00 00 00 00 00 BB 00 00 00 00 00
080: 00 00 00 00 00 00 BC 00 00 00 00 00 00 00 00 00
090: 00 00 BD 00 00 00 00 00 00 00 00 00 00 00 BE 28
0A0: 00 00 00 00 00 00 00 00 00 00 BF 00 00 00 00 00
0B0: 00 00 00 00 00 00 C0 00 00 00 00 00 00 00 00 00
0C0: 00 00 C1 00 00 00 00 00 00 00 00 00 00 00 C2 00
0D0: 00 00 00 00 00 00 00 00 00 00 C4 00 00 00 00 00
0E0: 00 00 00 00 00 00 C5 00 00 00 00 00 00 00 00 00
0F0: 00 00 C6 00 00 00 00 00 00 00 00 00 00 00 C7 00
100: 00 00 00 00 00 00 00 00 00 00 FE 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 F5

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43061
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Pomalý notebook, prosím o kontrolu logu

Příspěvekod jaro3 » 16 úno 2023 16:52

Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
klikni na „Skenování“ , po prohledání klikni na „ do karantény

Program provede opravu, po automatickém restartu klikni na Zobrazit logovací soubor“ a pak poklepej na odpovídají log, (C:\AdwCleaner [C?].txt) , jeho obsah sem celý vlož.

Stáhni si Junkware Removal Tool by Thisisu
http://www.bleepingcomputer.com/downloa ... oval-tool/
https://downloads.malwarebytes.com/file/JRT-EOL
na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dlouho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.


Sophos Virus Removal Tool je praktický softwarový nástroj, který by mohl odstranit infekce, které antivirový program nedetekuje .
Stáhněte si ho zde z některého odkazu:
https://www.majorgeeks.com/mg/getmirror ... ool,1.html
https://www.majorgeeks.com/mg/get/sopho ... ool,1.html
http://www.majorgeeks.com/mg/getmirror/ ... ool,1.html
http://www.majorgeeks.com/mg/getmirror/ ... ool,2.html

Viry mohou zpomalit počítač, nebo se snaží ukrást vaše data, a ani nevíte , že je máte. Co potřebujete, je rychlý a snadný způsob, jak je najít a zbavit se jich, pokud již máte antivirový program v počítači nainstalován , můžete nainstalovat i nástroj Sophos Virus Removal , který identifikuje a vyčistí zbylé infekce, které mohl Váš antivirový program přehlédnout.
K použití Sophos Virus Removal Tool na něj poklepejte a stiskněte tlačítko „Start scanning“ . Pak bude Sophos Virus Removal Tool vyhledávat a odstraňovat viry, které najde. Může být vyžadován restart.
Pokud byly nalezeny viry , tak po skenu klikni na „Details…“ a potom na „View log file“. Zkopíruj celý log a vlož ho sem. Potom zavři „threat detail“ a klikni na „Start cleanup“.
Jinak se log nachází zde:
C:\ProgramData\Sophos\Sophos Virus Removal Tool\Logs


Stáhni si RogueKiller by Adlice Software
http://www.adlice.com/download/roguekiller/
http://www.bleepingcomputer.com/download/roguekiller/
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- - klikni na „Scan“. V novém okně nic neměň a klikni dole na „Start“ ve sloupci „Quick Scan“
- Program skenuje procesy PC. Po proskenování klikni na „Results “ , v dalším okně pak levým t. na „Export“ a vyber : „Text File“ , log nazvi třeb RK a ulož do dokumentů nebo na plochu. Otevři soubor a celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
-pokud bude mít log více než 60.000 znaků , rozděl ho a vlož do více příspěvků
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Mety
Level 2.5
Level 2.5
Příspěvky: 304
Registrován: duben 12
Bydliště: Markvartovice
Pohlaví: Muž
Stav:
Offline

Re: Pomalý notebook, prosím o kontrolu logu

Příspěvekod Mety » 17 úno 2023 06:52

Log z AdwCleaner:

# -------------------------------
# Malwarebytes AdwCleaner 8.4.0.0
# -------------------------------
# Build: 08-30-2022
# Database: 2022-10-10.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 02-17-2023
# Duration: 00:00:01
# OS: Windows 10 (Build 19045.2604)
# Cleaned: 29
# Failed: 0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

No malicious registry entries cleaned.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Hosts File Entries ] *****

No malicious hosts file entries cleaned.

***** [ Preinstalled Software ] *****

Deleted Preinstalled.HPAudioSwitch Folder C:\Program Files (x86)\HP\HPAUDIOSWITCH
Deleted Preinstalled.HPAudioSwitch Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{054EBA81-8C83-451D-85A3-E766A01BECA5}
Deleted Preinstalled.HPAudioSwitch Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HPAudioSwitch
Deleted Preinstalled.HPAudioSwitch Task C:\Windows\System32\Tasks\HPAUDIOSWITCH
Deleted Preinstalled.HPCoolSense Folder C:\Program Files (x86)\HP\HP COOLSENSE
Deleted Preinstalled.HPCoolSense Folder C:\Users\mates\AppData\Local\HP\HP COOLSENSE
Deleted Preinstalled.HPCoolSense Folder C:\Windows\System32\Tasks\HP\HP COOLSENSE
Deleted Preinstalled.HPCoolSense Registry HKLM\Software\Classes\CLSID\{224695A4-BD5E-4C38-B354-A4C828E61BF7}
Deleted Preinstalled.HPJumpStartBridge Folder C:\Program Files (x86)\HP\HP JUMPSTART BRIDGE
Deleted Preinstalled.HPJumpStartLaunch Folder C:\Program Files (x86)\HP\HP JUMPSTART LAUNCH
Deleted Preinstalled.HPJumpStartLaunch Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D88C2449-7232-402B-AB2C-E68BCF0CF4D6}
Deleted Preinstalled.HPJumpStartLaunch Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HPJumpStartLaunch
Deleted Preinstalled.HPJumpStartLaunch Task C:\Windows\System32\Tasks\HPJUMPSTARTLAUNCH
Deleted Preinstalled.HPRegistrationService Folder C:\Program Files (x86)\HP\HP REGISTRATION SERVICE
Deleted Preinstalled.HPRegistrationService Folder C:\ProgramData\HP\HP REGISTRATION SERVICE
Deleted Preinstalled.HPSupportAssistant Folder C:\HP\SUPPORT
Deleted Preinstalled.HPSupportAssistant Folder C:\Program Files (x86)\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
Deleted Preinstalled.HPSupportAssistant Folder C:\ProgramData\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
Deleted Preinstalled.HPSupportAssistant Folder C:\Users\mates\AppData\Roaming\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
Deleted Preinstalled.HPSupportAssistant Folder C:\Windows\System32\config\systemprofile\AppData\Local\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
Deleted Preinstalled.HPSupportAssistant Registry HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Deleted Preinstalled.HPSupportAssistant Registry HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Deleted Preinstalled.HPSupportAssistant Registry HKLM\Software\Classes\CLSID\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Deleted Preinstalled.HPSupportAssistant Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Deleted Preinstalled.HPSupportAssistant Registry HKLM\Software\Wow6432Node\\Classes\CLSID\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Deleted Preinstalled.HPSupportAssistant Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Deleted Preinstalled.HPSupportAssistant Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{4AAC4B07-77EF-4BCF-88DC-D24E4DE683E8}
Deleted Preinstalled.HPSureConnect Folder C:\Program Files\HPCOMMRECOVERY
Deleted Preinstalled.HPSureConnect Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{6468C4A5-E47E-405F-B675-A70A70983EA6}


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [4700 octets] - [19/08/2022 22:12:08]
AdwCleaner[S01].txt - [4757 octets] - [16/02/2023 15:00:20]
AdwCleaner[S02].txt - [4818 octets] - [17/02/2023 06:50:47]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C02].txt ##########

Uživatelský avatar
Mety
Level 2.5
Level 2.5
Příspěvky: 304
Registrován: duben 12
Bydliště: Markvartovice
Pohlaví: Muž
Stav:
Offline

Re: Pomalý notebook, prosím o kontrolu logu

Příspěvekod Mety » 17 úno 2023 06:58

Log z JRT:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 10 Home x64
Ran by mates (Administrator) on 17.02.2023 at 6:54:25,73
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 3

Successfully deleted: C:\ProgramData\mntemp (File)
Successfully deleted: C:\ProgramData\thunder network (Folder)
Successfully deleted: C:\Users\Public\thunder network (Folder)



Registry: 2

Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1FD49718-1D00-4B19-AF5F-070AF6D5D54C} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1FD49718-1D00-4B19-AF5F-070AF6D5D54C} (Registry Key)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 17.02.2023 at 6:56:04,55
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Uživatelský avatar
Mety
Level 2.5
Level 2.5
Příspěvky: 304
Registrován: duben 12
Bydliště: Markvartovice
Pohlaví: Muž
Stav:
Offline

Re: Pomalý notebook, prosím o kontrolu logu

Příspěvekod Mety » 17 úno 2023 08:09

Sophos mi nic nenašel.

Log z RogueKiller:

Program : RogueKiller Anti-Malware
Version : 15.8.0.0
x64 : Yes
Program Date : Jan 26 2023
Location : C:\Program Files\RogueKiller\RogueKiller64.exe
Premium : No
Company : Adlice Software
Website : https://www.adlice.com/
Contact : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 10 (10.0.19045) 64-bit
64-bit OS : Yes
Startup : 0
WindowsPE : No
User : mates
User is Admin : Yes
Date : 2023/02/17 07:04:22
Type : Scan
Aborted : No
Scan Mode : Quick
Duration : 12
Found items : 0
Total scanned : 1030
Signatures Version : 20230209_084111
Truesight Driver : Yes
Updates Count : 0
Arguments : -minimize

************************* Warnings *************************

************************* Processes *************************

************************* Modules *************************

************************* Services *************************

************************* Scheduled Tasks *************************

************************* Registry *************************

************************* WMI *************************

************************* Hosts File *************************
is_too_big : No
hosts_file_path : N/A


************************* Filesystem *************************

************************* Web Browsers *************************

************************* Antirootkit *************************

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43061
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Pomalý notebook, prosím o kontrolu logu

Příspěvekod jaro3 » 17 úno 2023 15:00

Vypni antivir i firewall, RogueKiller, Malwarebytes Antimalware, windowsDefender
Stáhni zoek:
https://uloz.to/file/nFH1LwSrGioP/zoek1-rar

Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
-pozor , náběh programu může trvat déle.
Do okna programu vlož skript níže:

Kód: Vybrat vše

autoclean;
resethosts;
emptyclsid;
IEdefaults;
FFdefaults;
CHRdefaults;
emptyIEcache;
emptyFFcache;
emptyCHRcache;
emptyalltemp;
emptyflash;
emptyjava;
emptyrecycle.bin;

klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .
Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log Zkopíruj sem celý obsah toho logu.
Pokud budou problémy , spusť zoek v nouz. režimu.


Stáhni si Zemana AntiMalware Free z tohoto odkazu:
https://www.zemana.com/Download/AntiMal ... .Setup.exe

(posuvník dolu na download)
a ulož si ho na plochu.
Poklepej na tento soubor na ploše a postupuj podle pokynů k instalaci programu.
Přijmi licenci k používání programu EULA , pokud se nabídne.
Pokud je k dispozici aktualizace programu , klepni na tlačítko „Update now“ ( aktualizovat nyní).
Zavři všechny otevřené soubory, složky a prohlížeče
Neměň žádné nastavení. Klikni na „Skenovat nyní“.
Po skenu lze vidět , zda jsou nějaké nákazy. Klikni na „Vykonat“ ( vymazat). Nákazy budou přemístěny do karantény.
Když je skenování dokončeno, klikni vlevo na „zprávy“ a pak na „otevři zprávu“ a zkopíruj sem celý obsah té zprávy.


Vlož nový log z HJT + informuj o problémech
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Mety
Level 2.5
Level 2.5
Příspěvky: 304
Registrován: duben 12
Bydliště: Markvartovice
Pohlaví: Muž
Stav:
Offline

Re: Pomalý notebook, prosím o kontrolu logu

Příspěvekod Mety » 17 úno 2023 16:02

Log ze zoek 1. část:

Zoek.exe v5.0.0.2 Updated 03-May-2018(Online Version)
Tool run by mates on 17.02.2023 at 15:28:18,60.
Microsoft Windows 10 Home 10.0.19045 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\mates\AppData\Local\Temp\Rar$EXa8376.7640\zoek1\zoek (1).exe [Scan all users] [Script inserted]

==== System Restore Info ======================

17.02.2023 15:30:09 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Empty Folders Check ======================

C:\PROGRA~2\Hewlett-Packard deleted successfully
C:\PROGRA~2\Rockstar Games deleted successfully
C:\Program Files\Rockstar Games deleted successfully
C:\PROGRA~3\Disc-Soft deleted successfully
C:\PROGRA~3\SoftwareDistribution deleted successfully
C:\PROGRA~3\ssh deleted successfully
C:\Users\mates\AppData\Roaming\Disc-Soft deleted successfully
C:\Users\mates\AppData\Roaming\Hewlett-Packard deleted successfully
C:\Users\mates\AppData\Roaming\Overwolf deleted successfully
C:\WINDOWS\serviceprofiles\networkservice\AppData\Roaming\hpqLog deleted successfully
C:\WINDOWS\serviceprofiles\Localservice\AppData\Roaming\hpqLog deleted successfully
C:\Users\mates\AppData\Local\DBG deleted successfully
C:\Users\mates\AppData\Local\GHISLER deleted successfully
C:\Users\mates\AppData\Local\Opera Software deleted successfully

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== Deleting Files \ Folders ======================

C:\PROGRA~2\Hewlett-Packard not found
C:\PROGRA~2\Rockstar Games not found
C:\Users\mates\AppData\Local\Hewlett-Packard deleted
C:\Users\mates\AppData\Local\Rockstar Games deleted
C:\Users\mates\AppData\Roaming\discord deleted
C:\Users\mates\AppData\Roaming\mobalytics-desktop deleted
C:\Users\mates\.android deleted
C:\PROGRA~2\Wondershare deleted
C:\Users\mates\AppData\Roaming\Wondershare deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\mates\AppData\Local\WonderShare deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\CM22934.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\CM2ACA.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\CM2DC73.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-120c-3c50-2df4c32.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-120c-3c50-2df4c34.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-120c-3c50-2df4c46.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-120c-3c50-2df4c48.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-120c-3c50-2df4c4a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-120c-3c50-2df4c4c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-120c-3c50-2df4c5d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-120c-3c50-2df4c5f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-120c-3c50-2df4c61.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-120c-3c50-2df4c63.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-120c-3c50-2df4c75.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-120c-3c50-2df4c77.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-120c-3c50-2df4c79.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-120c-3c50-2df4c7b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-120c-3c50-2df4c8d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-120c-3c50-2df4c8f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-120c-3c50-2df4c91.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-120c-3c50-2df4c93.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-120c-3c50-2df4ca4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-14b8-3678-14b979.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-14b8-3678-14b97b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-14b8-3678-14b97d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-14b8-3678-14b97f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-14b8-3678-14b990.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-14b8-3678-14b992.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-14b8-3678-14b994.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-14b8-3678-14b9a6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-14b8-3678-14b9a8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-14b8-3678-14b9aa.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-14b8-3678-14b9ac.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-14b8-3678-14b9ae.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-14b8-3678-14b9b0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-14b8-3678-14b9c1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-14b8-3678-14b9c3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-14b8-3678-14b9c5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-14b8-3678-14b9c7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-14b8-3678-14b9d9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-14b8-3678-14b9db.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1508-2440-21242f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1508-2440-212450.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1508-2440-212490.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1508-2440-2124b2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1508-2440-212540.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1508-2440-212571.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1508-2440-212592.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1508-2440-2125c3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1508-2440-2125c5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1508-2440-2125d7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1508-2440-212608.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1508-2440-212619.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1508-2440-21263b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1508-2440-21266b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1508-2440-21267d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1508-2440-21269e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1508-2440-2126cf.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1508-2440-212710.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1508-2440-212712.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1548-1e20-2d0070.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1548-1e20-2d013d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1548-1e20-2d0314.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1548-1e20-2d0335.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1548-1e20-2d0337.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1548-1e20-2d0491.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1548-1e20-2d059c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1548-1e20-2d0669.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1548-1e20-2d06ba.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1548-1e20-2d0767.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1548-1e20-2d0789.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1548-1e20-2d0875.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1548-1e20-2d08d5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1548-1e20-2d08d7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1548-1e20-2d0a21.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1548-1e20-2d0a61.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1548-1e20-2d0a83.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1548-1e20-2d0ad3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1548-1e20-2d0b23.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-156c-3c48-b29f6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-156c-3c48-b2a08.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-156c-3c48-b2a0a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-156c-3c48-b2a0c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-156c-3c48-b2a0e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-156c-3c48-b2a1f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-156c-3c48-b2a21.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-156c-3c48-b2a23.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-156c-3c48-b2a25.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-156c-3c48-b2a37.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-156c-3c48-b2a39.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-156c-3c48-b2a3b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-156c-3c48-b2a3d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-156c-3c48-b2a4f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-156c-3c48-b2a51.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-156c-3c48-b2a53.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-156c-3c48-b2a64.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-156c-3c48-b2a66.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-156c-3c48-b2a78.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-167c-34d4-57fec9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-167c-34d4-57feea.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-167c-34d4-57feec.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-167c-34d4-57fefe.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-167c-34d4-57ff2f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-167c-34d4-57ff31.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-167c-34d4-57ff52.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-167c-34d4-57ff54.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-167c-34d4-57ff56.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-167c-34d4-57ff67.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-167c-34d4-57ff79.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-167c-34d4-57ffaa.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-167c-34d4-57ffac.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-167c-34d4-57ffae.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-167c-34d4-57ffc0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-167c-34d4-57ffd1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-167c-34d4-580002.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-167c-34d4-580043.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-167c-34d4-580073.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16cc-3eac-4e0ef68.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16cc-3eac-4e0ef89.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16cc-3eac-4e0ef9b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16cc-3eac-4e0efad.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16cc-3eac-4e0efbe.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16cc-3eac-4e0efd0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16cc-3eac-4e0efe2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16cc-3eac-4e0eff3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16cc-3eac-4e0f014.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16cc-3eac-4e0f036.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16cc-3eac-4e0f038.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16cc-3eac-4e0f059.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16cc-3eac-4e0f07a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16cc-3eac-4e0f08c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16cc-3eac-4e0f0ad.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16cc-3eac-4e0f0ce.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16cc-3eac-4e0f0e0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16cc-3eac-4e0f0f2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-16cc-3eac-4e0f103.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1708-152c-257c1f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1708-152c-257c30.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1708-152c-257c52.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1708-152c-257c54.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1708-152c-257c56.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1708-152c-257c77.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1708-152c-257c89.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1708-152c-257c9a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1708-152c-257c9c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1708-152c-257c9e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1708-152c-257cb0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1708-152c-257cc1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1708-152c-257cc3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1708-152c-257cc5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1708-152c-257ce7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1708-152c-257d08.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1708-152c-257d1a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1708-152c-257d1c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1708-152c-257d1e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-174c-5ec-2f3bd9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-174c-5ec-2f3beb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-174c-5ec-2f3bed.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-174c-5ec-2f3bfe.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-174c-5ec-2f3c00.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-174c-5ec-2f3c12.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-174c-5ec-2f3c14.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-174c-5ec-2f3c16.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-174c-5ec-2f3c18.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-174c-5ec-2f3c2a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-174c-5ec-2f3c2c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-174c-5ec-2f3c2e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-174c-5ec-2f3c30.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-174c-5ec-2f3c32.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-174c-5ec-2f3c43.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-174c-5ec-2f3c45.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-174c-5ec-2f3c47.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-174c-5ec-2f3c68.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-174c-5ec-2f3c6a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17bc-48dc-1395c9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17bc-48dc-1395cb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17bc-48dc-1395cd.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17bc-48dc-1395cf.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17bc-48dc-1395e0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17bc-48dc-1395e2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17bc-48dc-1395e4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17bc-48dc-1395e6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17bc-48dc-1395f8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17bc-48dc-1395fa.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17bc-48dc-1395fc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17bc-48dc-1395fe.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17bc-48dc-139610.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17bc-48dc-139612.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17bc-48dc-139614.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17bc-48dc-139616.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17bc-48dc-139627.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17bc-48dc-139629.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17bc-48dc-13962b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17e8-1edc-17b39e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17e8-1edc-17b3a0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17e8-1edc-17b3a2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17e8-1edc-17b3b4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17e8-1edc-17b3b6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17e8-1edc-17b3b8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17e8-1edc-17b3ba.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17e8-1edc-17b3cb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17e8-1edc-17b3cd.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17e8-1edc-17b3cf.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17e8-1edc-17b3d1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17e8-1edc-17b3e3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17e8-1edc-17b3e5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17e8-1edc-17b3e7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17e8-1edc-17b3e9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17e8-1edc-17b3fa.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17e8-1edc-17b3fc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17e8-1edc-17b3fe.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-17e8-1edc-17b400.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1828-1858-2504e8b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1828-1858-2504e8d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1828-1858-2504e9f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1828-1858-2504ea1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1828-1858-2504ea3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1828-1858-2504eb5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1828-1858-2504eb7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1828-1858-2504eb9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1828-1858-2504ebb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1828-1858-2504ecc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1828-1858-2504ece.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1828-1858-2504ed0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1828-1858-2504ed2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1828-1858-2504ee4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1828-1858-2504ee6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1828-1858-2504ee8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1828-1858-2504ef9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1828-1858-2504efb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1828-1858-2504efd.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-182c-2fcc-2f237f2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-182c-2fcc-2f237f4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-182c-2fcc-2f23806.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-182c-2fcc-2f23808.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-182c-2fcc-2f2380a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-182c-2fcc-2f2380c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-182c-2fcc-2f2380e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-182c-2fcc-2f2381f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-182c-2fcc-2f23821.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-182c-2fcc-2f23823.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-182c-2fcc-2f23825.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-182c-2fcc-2f239ed.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-182c-2fcc-2f23cbd.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-182c-2fcc-2f23d0d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-182c-2fcc-2f23d2f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-182c-2fcc-2f23d6f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-182c-2fcc-2f23d90.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-182c-2fcc-2f23da2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-182c-2fcc-2f23e50.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1840-1850-26edcf.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1840-1850-26fb7d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1840-1850-26fda2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1840-1850-26ffa8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1840-1850-27017f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1840-1850-27024c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1840-1850-270403.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1840-1850-270473.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1840-1850-2705cc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1840-1850-270745.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1840-1850-270870.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1840-1850-270a76.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1840-1850-2711ea.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1840-1850-2713ff.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1840-1850-27152a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1840-1850-271655.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1840-1850-271703.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1840-1850-271995.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1840-1850-271cb4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-199c-340c-df57a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-199c-340c-df57c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-199c-340c-df57e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-199c-340c-df580.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-199c-340c-df582.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-199c-340c-df594.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-199c-340c-df596.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-199c-340c-df598.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-199c-340c-df59a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-199c-340c-df5ab.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-199c-340c-df5ad.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-199c-340c-df5af.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-199c-340c-df5b1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-199c-340c-df5c3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-199c-340c-df5c5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-199c-340c-df5c7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-199c-340c-df5c9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-199c-340c-df5da.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-199c-340c-df5dc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19a8-2aec-30f234.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19a8-2aec-30f245.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19a8-2aec-30f247.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19a8-2aec-30f249.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19a8-2aec-30f24b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19a8-2aec-30f24d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19a8-2aec-30f25f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19a8-2aec-30f261.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19a8-2aec-30f263.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19a8-2aec-30f265.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19a8-2aec-30f277.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19a8-2aec-30f279.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19a8-2aec-30f27b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19a8-2aec-30ffac.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19a8-2aec-31003a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19a8-2aec-3104a1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19a8-2aec-310511.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19a8-2aec-310551.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19a8-2aec-310592.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c8c-2650-2321c4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c8c-2650-232252.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c8c-2650-2322b2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c8c-2650-2322c4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c8c-2650-232352.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c8c-2650-232354.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c8c-2650-232366.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c8c-2650-232368.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c8c-2650-23237a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c8c-2650-23238b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c8c-2650-23239d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c8c-2650-2323ce.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c8c-2650-2323ff.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c8c-2650-232410.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c8c-2650-232412.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c8c-2650-232424.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c8c-2650-232426.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c8c-2650-232466.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c8c-2650-2324b6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d88-fb8-97467e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d88-fb8-974680.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d88-fb8-974691.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d88-fb8-974693.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d88-fb8-974695.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d88-fb8-974697.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d88-fb8-9746a9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d88-fb8-9746ab.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d88-fb8-9746ad.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d88-fb8-9746af.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d88-fb8-9746b1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d88-fb8-9746c3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d88-fb8-9746c5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d88-fb8-9746c7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d88-fb8-9746c9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d88-fb8-9746da.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d88-fb8-9746dc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d88-fb8-9746de.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d88-fb8-9746e0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2148-3978-17508f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2148-3978-175091.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2148-3978-175093.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2148-3978-175095.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2148-3978-1750a6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2148-3978-1750a8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2148-3978-1750aa.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2148-3978-1750ac.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2148-3978-1750be.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2148-3978-1750c0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2148-3978-1750c2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2148-3978-1750c4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2148-3978-1750d5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2148-3978-1750d7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2148-3978-1750d9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2148-3978-1750db.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2148-3978-1750ed.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2148-3978-1750ef.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2148-3978-1750f1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2404-4454-98520.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2404-4454-98531.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2404-4454-98533.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2404-4454-98535.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2404-4454-98537.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2404-4454-98539.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2404-4454-9854b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2404-4454-9854d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2404-4454-9854f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2404-4454-98551.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2404-4454-98563.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2404-4454-98565.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2404-4454-98567.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2404-4454-98569.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2404-4454-9856b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2404-4454-9857c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2404-4454-9857e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2404-4454-98580.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2404-4454-98582.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2418-2420-1b337e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2418-2420-1b3380.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2418-2420-1b3391.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2418-2420-1b3393.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2418-2420-1b3395.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2418-2420-1b3397.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2418-2420-1b33a9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2418-2420-1b33bb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2418-2420-1b33bd.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2418-2420-1b33ce.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2418-2420-1b33d0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2418-2420-1b33d2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2418-2420-1b33e4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2418-2420-1b33e6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2418-2420-1b33f7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2418-2420-1b33f9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2418-2420-1b341b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2418-2420-1b341d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2418-2420-1b341f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-24ac-6b8-d9a4e9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-24ac-6b8-d9a4eb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-24ac-6b8-d9a4fc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-24ac-6b8-d9a4fe.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-24ac-6b8-d9a500.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-24ac-6b8-d9a502.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-24ac-6b8-d9a514.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-24ac-6b8-d9a516.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-24ac-6b8-d9a537.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-24ac-6b8-d9a539.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-24ac-6b8-d9a53b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-24ac-6b8-d9a53d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-24ac-6b8-d9a54f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-24ac-6b8-d9a551.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-24ac-6b8-d9a553.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-24ac-6b8-d9a555.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-24ac-6b8-d9a566.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-24ac-6b8-d9a568.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-24ac-6b8-d9a58a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2510-32b8-a2538.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2510-32b8-a254a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2510-32b8-a254c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2510-32b8-a254e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2510-32b8-a2550.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2510-32b8-a2561.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2510-32b8-a2563.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2510-32b8-a2565.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2510-32b8-a2567.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2510-32b8-a2579.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2510-32b8-a257b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2510-32b8-a257d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2510-32b8-a258f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2510-32b8-a2591.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2510-32b8-a2593.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2510-32b8-a25a4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2510-32b8-a25a6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2510-32b8-a25a8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2510-32b8-a25aa.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2550-28fc-1ba2a3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2550-28fc-1ba2a5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2550-28fc-1ba2a7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2550-28fc-1ba2b8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2550-28fc-1ba2ba.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2550-28fc-1ba2cc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2550-28fc-1ba2ed.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2550-28fc-1ba30f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2550-28fc-1ba330.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2550-28fc-1ba361.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2550-28fc-1ba372.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2550-28fc-1ba384.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2550-28fc-1ba3b5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2550-28fc-1ba3d6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2550-28fc-1ba3e8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2550-28fc-1ba3f9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2550-28fc-1ba40b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2550-28fc-1ba42c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2550-28fc-1ba43e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2568-1910-14cf81.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2568-1910-14cf83.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2568-1910-14cf95.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2568-1910-14cf97.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2568-1910-14cf99.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2568-1910-14cf9b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2568-1910-14cf9d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2568-1910-14cfae.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2568-1910-14cfb0.tmp deleted


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 28 hostů