Prosím o kontrolu logu - velmi pomalý nb Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
Pernee44
Level 3.5
Level 3.5
Příspěvky: 943
Registrován: říjen 07
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Prosím o kontrolu logu - velmi pomalý nb

Příspěvekod Pernee44 » 15 říj 2014 00:58

Dobrý den :-) notebook je velmi pomalý, instalace windows 7 asi před měsícem. Například kliknu v chromu na jednu ze záložek, co mám otevřené a čekám třeba 10 sekund. Časem je to plynulejší. To samé mám při otevírání programů. Předem děkuji za váš čas.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 0:57:54, on 15.10.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17280)
Boot mode: Normal

Running processes:
C:\Users\Pernee\AppData\Local\Viber\Viber.exe
C:\Users\Pernee\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\USB Camera\VM331_STI.EXE
C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Pernee\Downloads\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: PriceeDowinlaoaider - {2A63D34D-4BED-0FA7-D78B-CA976DDDAEB2} - C:\ProgramData\PriceeDowinlaoaider\J.dll (file missing)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Dolby Advanced Audio v2] "C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe" -autostart
O4 - HKLM\..\Run: [331BigDog] C:\Program Files (x86)\USB Camera\VM331_STI.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [tvncontrol] "C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe" -controlservice -slave
O4 - HKCU\..\Run: [Xvid] C:\Program Files (x86)\Xvid\CheckUpdate.exe
O4 - HKCU\..\Run: [Viber] "C:\Users\Pernee\AppData\Local\Viber\Viber.exe" StartMinimized
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\system32\StikyNot.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Dropbox.lnk = C:\Users\Pernee\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Startup: EvernoteClipper.lnk = C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
O4 - Global Startup: Start GeekBuddy.lnk = C:\Program Files\COMODO\GeekBuddy\launcher.exe
O8 - Extra context menu item: Nová poznámka - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\NewNote.html
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{0F720B69-3C5F-44CE-89EF-692854E656C0}: NameServer = 156.154.70.25,156.154.71.25
O17 - HKLM\System\CCS\Services\Tcpip\..\{12A13936-60AC-46EC-955A-15D22FF42274}: NameServer = 156.154.70.25,156.154.71.25
O17 - HKLM\System\CS1\Services\Tcpip\..\{0F720B69-3C5F-44CE-89EF-692854E656C0}: NameServer = 156.154.70.25,156.154.71.25
O17 - HKLM\System\CS2\Services\Tcpip\..\{0F720B69-3C5F-44CE-89EF-692854E656C0}: NameServer = 156.154.70.25,156.154.71.25
O20 - AppInit_DLLs: c:\windows\syswow64\nvinit.dll,c:\windows\syswow64\nvinit.dll,C:\Windows\SysWOW64\nvinit.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service (AMPPALR3) - Intel Corporation - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
O23 - Service: Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service (BTHSSecurityMgr) - Intel(R) Corporation - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
O23 - Service: COMODO LPS Launcher (CLPSLauncher) - Comodo Security Solutions, Inc. - C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe
O23 - Service: COMODO Internet Security Helper Service (CmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @C:\Windows\system32\CxAudMsg64.exe,-100 (CxAudMsg) - Unknown owner - C:\Windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: COMODO Dragon Update Service (DragonUpdater) - Unknown owner - C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GeekBuddyRSP Server (GeekBuddyRSP) - Comodo Security Solutions, Inc. - C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: IePlugin Services (IePluginServices) - Unknown owner - C:\ProgramData\IePluginServices\PluginService.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11430 bytes
Core i5 4570, 8GB DDR3, msi gtx1070 8GB, 240GB SSD Kingston, 550W Zdroj

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - velmi pomalý nb

Příspěvekod jaro3 » 15 říj 2014 10:13

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.

- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.


Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

Stáhni AdwCleaner (by Xplode)
http://www.bleepingcomputer.com/download/adwcleaner/

Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.

Stáhni si Malwarebytes' Anti-Malware
- Při instalaci odeber zatržítko u „Povolit bezplatnou zkušební verzi Malwarebytes' Anti-Malware Premium“
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a klikni na Skenovat nyní a
- po proběhnutí programu se ti objeví hláška vpravo dole tak klikni na b] Kopírovat do schránky [/b]a a vlož sem celý log.

- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).

Pokud budou problémy , spusť v nouz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Pernee44
Level 3.5
Level 3.5
Příspěvky: 943
Registrován: říjen 07
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Re: Prosím o kontrolu logu - velmi pomalý nb

Příspěvekod Pernee44 » 15 říj 2014 11:12

# AdwCleaner v4.000 - Report created 15/10/2014 at 10:32:05
# Updated 12/10/2014 by Xplode
# Database : 2014-10-15.7
# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)
# Username : Pernee - PERNEE-PC
# Running from : C:\Users\Pernee\Desktop\AdwCleaner.exe
# Option : Scan

***** [ Services ] *****

Service Found : IePluginServices
Service Found : {00c97d86-accb-4288-9972-6d929c1fe93a}Gw64

***** [ Files / Folders ] *****

File Found : C:\Users\Pernee\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_istart.webssearches.com_0.localstorage
File Found : C:\Users\Pernee\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_istart.webssearches.com_0.localstorage-journal
File Found : C:\Users\Pernee\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
File Found : C:\Users\Pernee\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
File Found : C:\Windows\System32\\drivers\{00c97d86-accb-4288-9972-6d929c1fe93a}Gw64.sys
File Found : C:\Windows\System32\roboot64.exe
Folder Found : C:\Program Files (x86)\Optimizer Pro
Folder Found : C:\Program Files (x86)\PC Speed Maximizer
Folder Found : C:\Program Files (x86)\SupTab
Folder Found : C:\Program Files\Enigma Software Group
Folder Found : C:\ProgramData\374311380
Folder Found : C:\ProgramData\IePluginServices
Folder Found : C:\ProgramData\Performance Optimizer
Folder Found : C:\ProgramData\PriceeDowinlaoaider
Folder Found : C:\ProgramData\WindowsMangerProtect
Folder Found : C:\Users\Pernee\AppData\Roaming\OpenCandy
Folder Found : C:\Users\Pernee\AppData\Roaming\pdfforge
Folder Found : C:\Users\Pernee\AppData\Roaming\webssearches
Folder Found : C:\Users\Pernee\Documents\Optimizer Pro
Folder Found : C:\Users\Pernee\Documents\PC Speed Maximizer

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Found : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Found : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Found : HKCU\Software\b1.org
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : HKCU\Software\Optimizer Pro
Key Found : HKCU\Software\Softonic
Key Found : HKCU\Software\SupHpUISoft
Key Found : [x64] HKCU\Software\b1.org
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : [x64] HKCU\Software\Optimizer Pro
Key Found : [x64] HKCU\Software\Softonic
Key Found : [x64] HKCU\Software\SupHpUISoft
Key Found : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Found : HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Found : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Found : HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Key Found : HKLM\SOFTWARE\b1.org
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{2A63D34D-4BED-0FA7-D78B-CA976DDDAEB2}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Found : HKLM\SOFTWARE\Classes\PriceDoWnloaderr.PriceDoWnloaderr
Key Found : HKLM\SOFTWARE\Classes\PriceDoWnloaderr.PriceDoWnloaderr.2.4
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SupTab_v5_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SupTab_v5_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\wpm_v20_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\wpm_v20_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A63D34D-4BED-0FA7-D78B-CA976DDDAEB2}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2A63D34D-4BED-0FA7-D78B-CA976DDDAEB2}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2D471A31-4FA7-95BA-1880-D441113ED736}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2D471A31-4FA7-95BA-1880-D441113ED736}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{892cc6a3}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\webssearches uninstall
Key Found : HKLM\SOFTWARE\SupDp
Key Found : HKLM\SOFTWARE\SupTab
Key Found : HKLM\SOFTWARE\supWindowsMangerProtect
Key Found : HKLM\SOFTWARE\webssearchesSoftware
Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Key Found : [x64] HKLM\SOFTWARE\b1.org
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{2A63D34D-4BED-0FA7-D78B-CA976DDDAEB2}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Found : [x64] HKLM\SOFTWARE\EnigmaSoftwareGroup
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A63D34D-4BED-0FA7-D78B-CA976DDDAEB2}

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17280

Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://istart.webssearches.com/web/?typ ... C765775&q={searchTerms}
Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - hxxp://istart.webssearches.com/web/?typ ... C765775&q={searchTerms}

-\\ Google Chrome v38.0.2125.101

Found [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}

*************************

AdwCleaner[R0].txt - [6603 octets] - [15/10/2014 10:32:05]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [6663 octets] ##########




Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 15.10.2014
Scan Time: 10:49:21
Logfile:
Administrator: Yes

Version: 2.00.3.1025
Malware Database: v2014.10.15.02
Rootkit Database: v2014.10.15.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Pernee

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 306929
Time Elapsed: 12 min, 34 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 23
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\CLSID\{2A63D34D-4BED-0FA7-D78B-CA976DDDAEB2}, , [ca34070d5b215adc04beffba748dbd43],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{2A63D34D-4BED-0FA7-D78B-CA976DDDAEB2}, , [ca34070d5b215adc04beffba748dbd43],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{2A63D34D-4BED-0FA7-D78B-CA976DDDAEB2}, , [ca34070d5b215adc04beffba748dbd43],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\PriceDoWnloaderr.PriceDoWnloaderr, , [ca34070d5b215adc04beffba748dbd43],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\PriceDoWnloaderr.PriceDoWnloaderr.2.4, , [ca34070d5b215adc04beffba748dbd43],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceDoWnloaderr.PriceDoWnloaderr, , [ca34070d5b215adc04beffba748dbd43],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceDoWnloaderr.PriceDoWnloaderr.2.4, , [ca34070d5b215adc04beffba748dbd43],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{2A63D34D-4BED-0FA7-D78B-CA976DDDAEB2}, , [ca34070d5b215adc04beffba748dbd43],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{2A63D34D-4BED-0FA7-D78B-CA976DDDAEB2}, , [ca34070d5b215adc04beffba748dbd43],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{2A63D34D-4BED-0FA7-D78B-CA976DDDAEB2}, , [ca34070d5b215adc04beffba748dbd43],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\CLSID\{2A63D34D-4BED-0FA7-D78B-CA976DDDAEB2}\INPROCSERVER32, , [ca34070d5b215adc04beffba748dbd43],
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{00c97d86-accb-4288-9972-6d929c1fe93a}Gw64, , [26d829ebe894a5912cb0988c26ddbb45],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [de2066aeadcf1e1888cb343c27ddc040],
PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, , [eb138b89d3a95ed849734d37c4402ad6],
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\webssearchesSoftware, , [b04e4bc97c00f145fb1e380a4cb730d0],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [53ab041083f9a78fcb889cd47f850af6],
PUP.Optional.Booster.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{5F189DF5-2D05-472B-9091-84D9848AE48B}{892cc6a3}, , [9d610410adcf3bfba79c65c526dddc24],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPDP, , [33cba96b8cf0e551f5af19050bf8d729],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB, , [847ae33178049a9cf7de0c1249baa858],
PUP.Optional.WebSearches.A, HKU\S-1-5-21-1945533246-1627020581-2872599212-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SupHpUISoft, , [8c7263b12d4f83b3c9c1a47c2ad97d83],
PUP.Optional.Qone8, HKU\S-1-5-21-1945533246-1627020581-2872599212-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [f30bf1233349a4921240026ef70d3ac6],
PUP.Optional.Softonic.A, HKU\S-1-5-21-1945533246-1627020581-2872599212-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, , [ac52c3514f2d60d66d4815287291e719],
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\webssearches uninstall, , [34cad341f587fb3bdf72737d28da28d8],

Registry Values: 2
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPDP|dir, C:\Program Files (x86)\SupTab, , [33cba96b8cf0e551f5af19050bf8d729]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB|ptid, cvs, , [847ae33178049a9cf7de0c1249baa858]

Registry Data: 2
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, http://istart.webssearches.com/web/?typ ... C765775&q={searchTerms}, Good: (www.google.com), Bad: (http://istart.webssearches.com/web/?typ ... C765775&q={searchTerms}),,[25d935dfea9272c4965515007491cf31]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[b14dfc18106c7bbb4cc3011f996cab55]

Folders: 38
Rogue.Multiple, C:\ProgramData\374311380, , [2fcfb064f983ae88f534e4f643bf817f],
PUP.Optional.OpenCandy, C:\Users\Pernee\AppData\Roaming\OpenCandy, , [3bc349cb4e2e5adce0e52fba887af907],
PUP.Optional.OpenCandy, C:\Users\Pernee\AppData\Roaming\OpenCandy\3B96FFFCD0A8451CB75078566A199CE4, , [3bc349cb4e2e5adce0e52fba887af907],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\images, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\images\code, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\log, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices, , [20de8d874d2f49ed84d94cb3669ce719],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update, , [20de8d874d2f49ed84d94cb3669ce719],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, , [8975957fa8d489ad2e95cc359a697b85],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log, , [8975957fa8d489ad2e95cc359a697b85],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, , [8975957fa8d489ad2e95cc359a697b85],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW, , [d12df51f166638fe90453bcc976cb44c],

Files: 98
PUP.Optional.MultiPlug, C:\ProgramData\PriceeDowinlaoaider\J.x64.dll, , [ca34070d5b215adc04beffba748dbd43],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, , [f806b163f686ad89a57c6634fc0540c0],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\DpInterface64.dll, , [01fd53c11666b185a27fa6f4ae53fb05],
PUP.Optional.IEPluginService.A, C:\Program Files (x86)\SupTab\RSHP.exe, , [29d592823745db5bda6edba2bf424eb2],
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{00c97d86-accb-4288-9972-6d929c1fe93a}Gw64.sys, , [26d829ebe894a5912cb0988c26ddbb45],
PUP.Optional.WebSearchs.A, C:\Users\Pernee\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_istart.webssearches.com_0.localstorage, , [df1fc153fa8288ae5590c26480836a96],
PUP.Optional.WebSearchs.A, C:\Users\Pernee\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_istart.webssearches.com_0.localstorage-journal, , [2ad40e06fb8123134c9932f4e91a639d],
PUP.Optional.OpenCandy, C:\Users\Pernee\AppData\Roaming\OpenCandy\3B96FFFCD0A8451CB75078566A199CE4\AVG-PC-TuneUp2014-cz-CZ-p4v1.exe, , [3bc349cb4e2e5adce0e52fba887af907],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\255.json, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\MessageBox.xml, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\uninstallDlg2.xml, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\UninstallManager.exe, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\images\bg.png, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\images\bg1.png, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\images\bk_shadow.png, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\images\button.png, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\images\button1.png, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\images\checkbox.png, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\images\checkbox_select.png, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\images\checked.png, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\images\close.png, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\images\loading_bg.png, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\images\loading_light.png, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\images\min.png, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\images\scrollbar.bmp, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\images\Thumbs.db, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\images\unchecked.png, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\images\code\code1.jpg, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\images\code\code2.jpg, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\images\code\code3.jpg, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\images\code\code4.jpg, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\images\code\code5.jpg, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\images\code\code6.jpg, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\images\code\Thumbs.db, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\log\UninstallManager_2014-09-10[10-59-23-976].log, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\log\UninstallManager_2014-09-10[10-59-30-312].log, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\log\UninstallManager_2014-09-10[10-59-47-773].log, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\log\UninstallManager_2014-09-10[11-01-42-553].log, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\log\UninstallManager_2014-09-10[11-04-51-521].log, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.WebsSearches.A, C:\Users\Pernee\AppData\Roaming\webssearches\log\UninstallManager_2014-09-23[11-18-33-097].log, , [34cad341f587fb3bdf72737d28da28d8],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update\conf, , [20de8d874d2f49ed84d94cb3669ce719],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log\ProtectWindowsManager_2014-08-27[15-56-36-618].log, , [8975957fa8d489ad2e95cc359a697b85],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\conf, , [8975957fa8d489ad2e95cc359a697b85],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\BHOEnabler.exe, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\HpUI.exe, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\ient.json, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\install.data, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcp110.dll, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcr110.dll, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\uninstall.exe, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WindowsSupportDll64.dll, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\bk_shadow.png, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\btn.png, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\close.png, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\main.xml, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\main.xml.bak, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image\ck_box.png, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image\ck_check.png, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image\radio_bk.png, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image\radio_check.png, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\data.html, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE.html, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE8.html, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\main.css, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\ver.txt, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\google_trends.png, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon128.png, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon16.png, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon48.png, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\loading.gif, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\logo32.ico, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\common.js, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ga.js, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery-1.11.0.min.js, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery.autocomplete.js, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\js.js, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\library.js, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit-ie8.js, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit2.0.js, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US\messages.json, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419\messages.json, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES\messages.json, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE\messages.json, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA\messages.json, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH\messages.json, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR\messages.json, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU\messages.json, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH\messages.json, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT\messages.json, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl\messages.json, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt\messages.json, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR\messages.json, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru\messages.json, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO\messages.json, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR\messages.json, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI\messages.json, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN\messages.json, , [d12df51f166638fe90453bcc976cb44c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW\messages.json, , [d12df51f166638fe90453bcc976cb44c],

Physical Sectors: 0
(No malicious items detected)


(end)
Core i5 4570, 8GB DDR3, msi gtx1070 8GB, 240GB SSD Kingston, 550W Zdroj

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - velmi pomalý nb

Příspěvekod jaro3 » 15 říj 2014 18:40

Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
klikni na „Prohledat-Scan“, po prohledání klikni na „ Vymazat-Clean

Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.

Stáhni si Junkware Removal Tool by Thisisu

na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.

. spusť znovu MbAM a dej Skenovat nyní
- po proběhnutí programu se ti objeví hláška tak klikni na „Vše do karantény(smazat vybrané)“ a na „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a někam ho ulož. Zkopíruj se celý obsah toho logu.

Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit

-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Pernee44
Level 3.5
Level 3.5
Příspěvky: 943
Registrován: říjen 07
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Re: Prosím o kontrolu logu - velmi pomalý nb

Příspěvekod Pernee44 » 15 říj 2014 18:58

# AdwCleaner v4.000 - Report created 15/10/2014 at 18:52:02
# DB v2014-10-15.7
# Updated 12/10/2014 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)
# Username : Pernee - PERNEE-PC
# Running from : C:\Users\Pernee\Desktop\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****

[#] Service Deleted : IePluginServices
Service Deleted : {00c97d86-accb-4288-9972-6d929c1fe93a}Gw64

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\374311380
Folder Deleted : C:\ProgramData\IePluginServices
Folder Deleted : C:\Users\Pernee\AppData\Roaming\OpenCandy
Folder Deleted : C:\Program Files (x86)\Optimizer Pro
Folder Deleted : C:\Users\Pernee\Documents\Optimizer Pro
Folder Deleted : C:\Program Files (x86)\PC Speed Maximizer
Folder Deleted : C:\Users\Pernee\Documents\PC Speed Maximizer
Folder Deleted : C:\Users\Pernee\AppData\Roaming\pdfforge
Folder Deleted : C:\ProgramData\Performance Optimizer
Folder Deleted : C:\Program Files (x86)\SupTab
Folder Deleted : C:\Users\Pernee\AppData\Roaming\webssearches
Folder Deleted : C:\ProgramData\WindowsMangerProtect
Folder Deleted : C:\Program Files\Enigma Software Group
Folder Deleted : C:\ProgramData\PriceeDowinlaoaider
File Deleted : C:\Windows\System32\roboot64.exe
File Deleted : C:\Windows\System32\\drivers\{00c97d86-accb-4288-9972-6d929c1fe93a}Gw64.sys
File Deleted : C:\Users\Pernee\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_istart.webssearches.com_0.localstorage
File Deleted : C:\Users\Pernee\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_istart.webssearches.com_0.localstorage-journal
File Deleted : C:\Users\Pernee\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
File Deleted : C:\Users\Pernee\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****

Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Shortcut Disinfected : C:\Users\Pernee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Shortcut Disinfected : C:\Users\Pernee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Shortcut Disinfected : C:\Users\Pernee\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
Shortcut Disinfected : C:\Users\Pernee\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Shortcut Disinfected : C:\Users\Pernee\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk

***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SupTab_v5_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SupTab_v5_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\wpm_v20_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\wpm_v20_RASMANCS
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\Classes\PriceDoWnloaderr.PriceDoWnloaderr
Key Deleted : HKLM\SOFTWARE\Classes\PriceDoWnloaderr.PriceDoWnloaderr.2.4
Key Deleted : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{892cc6a3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2A63D34D-4BED-0FA7-D78B-CA976DDDAEB2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A63D34D-4BED-0FA7-D78B-CA976DDDAEB2}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2A63D34D-4BED-0FA7-D78B-CA976DDDAEB2}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{2A63D34D-4BED-0FA7-D78B-CA976DDDAEB2}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A63D34D-4BED-0FA7-D78B-CA976DDDAEB2}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKCU\Software\b1.org
Key Deleted : HKCU\Software\Optimizer Pro
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\SupHpUISoft
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Deleted : HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Key Deleted : HKLM\SOFTWARE\b1.org
Key Deleted : HKLM\SOFTWARE\SupDp
Key Deleted : HKLM\SOFTWARE\SupTab
Key Deleted : HKLM\SOFTWARE\supWindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\webssearchesSoftware
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2D471A31-4FA7-95BA-1880-D441113ED736}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\webssearches uninstall
Key Deleted : [x64] HKLM\SOFTWARE\b1.org
Key Deleted : [x64] HKLM\SOFTWARE\EnigmaSoftwareGroup

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17280

Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]

-\\ Google Chrome v38.0.2125.101

Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}

*************************

AdwCleaner[R0].txt - [6807 octets] - [15/10/2014 10:32:05]
AdwCleaner[R1].txt - [6791 octets] - [15/10/2014 18:49:50]
AdwCleaner[S0].txt - [6923 octets] - [15/10/2014 18:52:02]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6983 octets] ##########
Core i5 4570, 8GB DDR3, msi gtx1070 8GB, 240GB SSD Kingston, 550W Zdroj

Uživatelský avatar
Pernee44
Level 3.5
Level 3.5
Příspěvky: 943
Registrován: říjen 07
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Re: Prosím o kontrolu logu - velmi pomalý nb

Příspěvekod Pernee44 » 15 říj 2014 19:21

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.3 (10.14.2014:1)
OS: Windows 7 Ultimate x64
Ran by Pernee on st 15.10.2014 at 18:58:43,38
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL



~~~ Registry Keys



~~~ Files

Successfully deleted: [File] C:\Windows\Tasks\DriverToolkit Autorun.job



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on st 15.10.2014 at 19:12:24,29
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Core i5 4570, 8GB DDR3, msi gtx1070 8GB, 240GB SSD Kingston, 550W Zdroj

Uživatelský avatar
Pernee44
Level 3.5
Level 3.5
Příspěvky: 943
Registrován: říjen 07
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Re: Prosím o kontrolu logu - velmi pomalý nb

Příspěvekod Pernee44 » 15 říj 2014 19:44

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 15.10.2014
Scan Time: 19:23:33
Logfile:
Administrator: Yes

Version: 2.00.3.1025
Malware Database: v2014.10.15.06
Rootkit Database: v2014.10.15.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Pernee

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 307420
Time Elapsed: 20 min, 12 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)
Core i5 4570, 8GB DDR3, msi gtx1070 8GB, 240GB SSD Kingston, 550W Zdroj

Uživatelský avatar
Pernee44
Level 3.5
Level 3.5
Příspěvky: 943
Registrován: říjen 07
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Re: Prosím o kontrolu logu - velmi pomalý nb

Příspěvekod Pernee44 » 15 říj 2014 21:18

Tak a poslední tu:

RogueKiller V10.0.1.0 (x64) [Oct 10 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Pernee [Administrator]
Mode : Scan -- Date : 10/15/2014 21:14:06

¤¤¤ Processes : 0 ¤¤¤

¤¤¤ Registry : 21 ¤¤¤
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-1945533246-1627020581-2872599212-1000\Software\Microsoft\Windows\CurrentVersion\Run | Viber : "C:\Users\Pernee\AppData\Local\Viber\Viber.exe" StartMinimized -> Found
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-1945533246-1627020581-2872599212-1000\Software\Microsoft\Windows\CurrentVersion\Run | Viber : "C:\Users\Pernee\AppData\Local\Viber\Viber.exe" StartMinimized -> Found
[PUM.SearchPage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01 -> Found
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-1945533246-1627020581-2872599212-1000\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01 -> Found
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-1945533246-1627020581-2872599212-1000\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01 -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.138 -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.138 -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.138 -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0F720B69-3C5F-44CE-89EF-692854E656C0} | DhcpNameServer : 10.0.0.138 -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{0F720B69-3C5F-44CE-89EF-692854E656C0} | DhcpNameServer : 10.0.0.138 -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{0F720B69-3C5F-44CE-89EF-692854E656C0} | DhcpNameServer : 10.0.0.138 -> Found
[PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Found
[PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Found
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-1945533246-1627020581-2872599212-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {645FF040-5081-101B-9F08-00AA002F954E} : 1 -> Found
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-1945533246-1627020581-2872599212-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {645FF040-5081-101B-9F08-00AA002F954E} : 1 -> Found
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Found
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Found
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Found
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Found
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-1945533246-1627020581-2872599212-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {645FF040-5081-101B-9F08-00AA002F954E} : 1 -> Found
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-1945533246-1627020581-2872599212-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {645FF040-5081-101B-9F08-00AA002F954E} : 1 -> Found

¤¤¤ Tasks : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ Hosts File : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: ST1000LM024 HN-M101MBB ATA Device +++++
--- User ---
[MBR] 13c7b34bca752fde092d12a3da6edfb5
[BSP] e07e3c1e1371844ea3ee70be1d7034ca : Linux MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 249900 MB
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 512002048 | Size: 300000 MB
3 - [XXXXXX] EXTEN-LBA (0xf) [VISIBLE] Offset (sectors): 1126404094 | Size: 403867 MB
User = LL1 ... OK
User = LL2 ... OK
Core i5 4570, 8GB DDR3, msi gtx1070 8GB, 240GB SSD Kingston, 550W Zdroj

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - velmi pomalý nb

Příspěvekod jaro3 » 16 říj 2014 09:56

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB (kromě myši s klávesnice) nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Pak klikni na "Prohledat " ,po jeho skončení:


- V záložkách (Registry , Tasks , Web Browser apod.) vše zatrhni (dej zatržítka)

- Klikni na "Smazat"
- Počkej, dokud Status box nezobrazí " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller

Stáhni
Zoek.exe

a uloz si ho na plochu.
Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
- pozor , náběh programu může trvat déle.

Do okna programu vlož skript níže:

Kód: Vybrat vše

autoclean;
emptyclsid;
iedefaults;
FFdefaults;
CHRdefaults;
emptyalltemp;
resethosts;


klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .

Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log
Zkopíruj sem celý obsah toho logu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Pernee44
Level 3.5
Level 3.5
Příspěvky: 943
Registrován: říjen 07
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Re: Prosím o kontrolu logu - velmi pomalý nb

Příspěvekod Pernee44 » 16 říj 2014 18:44

RogueKiller V10.0.2.0 (x64) [Oct 16 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno : Normální režim
Uživatel : Pernee [Práva správce]
Mód : Smazat -- Datum : 10/16/2014 18:43:27

¤¤¤ Procesy : 0 ¤¤¤

¤¤¤ Registry : 22 ¤¤¤
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-1945533246-1627020581-2872599212-1000\Software\Microsoft\Windows\CurrentVersion\Run | Viber : "C:\Users\Pernee\AppData\Local\Viber\Viber.exe" StartMinimized [7][x] -> Smazáno
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-1945533246-1627020581-2872599212-1000\Software\Microsoft\Windows\CurrentVersion\Run | Viber : "C:\Users\Pernee\AppData\Local\Viber\Viber.exe" StartMinimized -> ERROR [2]
[Hidden.From.SCM] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tsusbhub (system32\drivers\tsusbhub.sys) -> Nevybráno
[PUM.SearchPage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01 -> Nevybráno
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-1945533246-1627020581-2872599212-1000\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01 -> Nevybráno
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-1945533246-1627020581-2872599212-1000\Software\Microsoft\Internet Explorer\Main | Search Page : http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01 -> Nevybráno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.138 -> Nevybráno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.138 -> Nevybráno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.138 -> Nevybráno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0F720B69-3C5F-44CE-89EF-692854E656C0} | DhcpNameServer : 10.0.0.138 -> Nevybráno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{0F720B69-3C5F-44CE-89EF-692854E656C0} | DhcpNameServer : 10.0.0.138 -> Nevybráno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{0F720B69-3C5F-44CE-89EF-692854E656C0} | DhcpNameServer : 10.0.0.138 -> Nevybráno
[PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Nevybráno
[PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Nevybráno
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-1945533246-1627020581-2872599212-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {645FF040-5081-101B-9F08-00AA002F954E} : 1 -> Nevybráno
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-1945533246-1627020581-2872599212-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {645FF040-5081-101B-9F08-00AA002F954E} : 1 -> Nevybráno
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Nevybráno
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Nevybráno
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Nevybráno
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Nevybráno
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-1945533246-1627020581-2872599212-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {645FF040-5081-101B-9F08-00AA002F954E} : 1 -> Nevybráno
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-1945533246-1627020581-2872599212-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {645FF040-5081-101B-9F08-00AA002F954E} : 1 -> Nevybráno

¤¤¤ Úlohy : 0 ¤¤¤

¤¤¤ Soubory : 0 ¤¤¤

¤¤¤ Soubor HOSTS : 0 ¤¤¤

¤¤¤ Antirootkit : 37 (Driver: Nahrán) ¤¤¤
[IAT:Addr] (explorer.exe @ POWRPROF.dll) SETUPAPI.dll - CM_Get_DevNode_Status : C:\Windows\system32\CFGMGR32.dll @ 0x7fefd2d30c0
[IAT:Addr] (explorer.exe @ POWRPROF.dll) SETUPAPI.dll - CM_Get_Device_IDW : C:\Windows\system32\CFGMGR32.dll @ 0x7fefd2d4034
[IAT:Addr] (explorer.exe @ urlmon.dll) api-ms-win-downlevel-ole32-l1-1-0.dll - CLSIDFromString : C:\Windows\system32\ole32.dll @ 0x7fefe8e0680
[IAT:Addr] (explorer.exe @ urlmon.dll) api-ms-win-downlevel-ole32-l1-1-0.dll - StringFromCLSID : C:\Windows\system32\ole32.dll @ 0x7fefe8d9370
[IAT:Addr] (explorer.exe @ urlmon.dll) api-ms-win-downlevel-ole32-l1-1-0.dll - CoGetClassObject : C:\Windows\system32\ole32.dll @ 0x7fefe902e18
[IAT:Addr] (explorer.exe @ urlmon.dll) api-ms-win-downlevel-ole32-l1-1-0.dll - CoCreateInstance : C:\Windows\system32\ole32.dll @ 0x7fefe8f7490
[IAT:Addr] (explorer.exe @ urlmon.dll) api-ms-win-downlevel-ole32-l1-1-0.dll - CoInitializeEx : C:\Windows\system32\ole32.dll @ 0x7fefe8f2a30
[IAT:Addr] (explorer.exe @ urlmon.dll) api-ms-win-downlevel-ole32-l1-1-0.dll - CoUnmarshalInterface : C:\Windows\system32\ole32.dll @ 0x7fefe8fea20
[IAT:Addr] (explorer.exe @ urlmon.dll) api-ms-win-downlevel-ole32-l1-1-0.dll - CoSetProxyBlanket : C:\Windows\system32\ole32.dll @ 0x7fefe90bf00
[IAT:Addr] (explorer.exe @ urlmon.dll) api-ms-win-downlevel-ole32-l1-1-0.dll - CoGetTreatAsClass : C:\Windows\system32\ole32.dll @ 0x7fefe8e3e90
[IAT:Addr] (explorer.exe @ urlmon.dll) api-ms-win-downlevel-ole32-l1-1-0.dll - CoFreeUnusedLibraries : C:\Windows\system32\ole32.dll @ 0x7fefe8d8284
[IAT:Addr] (explorer.exe @ urlmon.dll) api-ms-win-downlevel-ole32-l1-1-0.dll - CoCreateGuid : C:\Windows\system32\ole32.dll @ 0x7fefe8dd9d0
[IAT:Addr] (explorer.exe @ urlmon.dll) api-ms-win-downlevel-ole32-l1-1-0.dll - CoGetMarshalSizeMax : C:\Windows\system32\ole32.dll @ 0x7fefe8fef20
[IAT:Addr] (explorer.exe @ urlmon.dll) api-ms-win-downlevel-ole32-l1-1-0.dll - CoMarshalInterface : C:\Windows\system32\ole32.dll @ 0x7fefe8ff1ac
[IAT:Addr] (explorer.exe @ urlmon.dll) api-ms-win-downlevel-ole32-l1-1-0.dll - StringFromGUID2 : C:\Windows\system32\ole32.dll @ 0x7fefe8f3560
[IAT:Addr] (explorer.exe @ urlmon.dll) api-ms-win-downlevel-ole32-l1-1-0.dll - CLSIDFromProgID : C:\Windows\system32\ole32.dll @ 0x7fefe8e9980
[IAT:Addr] (explorer.exe @ urlmon.dll) api-ms-win-downlevel-ole32-l1-1-0.dll - FreePropVariantArray : C:\Windows\system32\ole32.dll @ 0x7fefe9f9440
[IAT:Addr] (explorer.exe @ urlmon.dll) api-ms-win-downlevel-ole32-l1-1-0.dll - CoTaskMemAlloc : C:\Windows\system32\ole32.dll @ 0x7fefe8f8e70
[IAT:Addr] (explorer.exe @ urlmon.dll) api-ms-win-downlevel-ole32-l1-1-0.dll - CoTaskMemFree : C:\Windows\system32\ole32.dll @ 0x7fefe8f8e20
[IAT:Addr] (explorer.exe @ urlmon.dll) api-ms-win-downlevel-ole32-l1-1-0.dll - CoUninitialize : C:\Windows\system32\ole32.dll @ 0x7fefe8f1314
[IAT:Addr] (explorer.exe @ urlmon.dll) api-ms-win-downlevel-version-l1-1-0.dll - GetFileVersionInfoExW : C:\Windows\system32\VERSION.dll @ 0x7fefcd8193c
[IAT:Addr] (explorer.exe @ urlmon.dll) api-ms-win-downlevel-version-l1-1-0.dll - VerQueryValueW : C:\Windows\system32\VERSION.dll @ 0x7fefcd815e0
[IAT:Addr] (explorer.exe @ urlmon.dll) api-ms-win-downlevel-version-l1-1-0.dll - GetFileVersionInfoSizeExW : C:\Windows\system32\VERSION.dll @ 0x7fefcd814e8
[IAT:Addr] (explorer.exe @ iertutil.dll) api-ms-win-downlevel-version-l1-1-0.dll - VerQueryValueW : C:\Windows\system32\VERSION.dll @ 0x7fefcd815e0
[IAT:Addr] (explorer.exe @ iertutil.dll) api-ms-win-downlevel-version-l1-1-0.dll - GetFileVersionInfoExW : C:\Windows\system32\VERSION.dll @ 0x7fefcd8193c
[IAT:Addr] (explorer.exe @ iertutil.dll) api-ms-win-downlevel-version-l1-1-0.dll - GetFileVersionInfoSizeExW : C:\Windows\system32\VERSION.dll @ 0x7fefcd814e8
[IAT:Addr] (explorer.exe @ WININET.dll) api-ms-win-downlevel-version-l1-1-0.dll - VerQueryValueW : C:\Windows\system32\VERSION.dll @ 0x7fefcd815e0
[IAT:Addr] (explorer.exe @ WININET.dll) api-ms-win-downlevel-version-l1-1-0.dll - GetFileVersionInfoSizeExW : C:\Windows\system32\VERSION.dll @ 0x7fefcd814e8
[IAT:Addr] (explorer.exe @ WININET.dll) api-ms-win-downlevel-version-l1-1-0.dll - GetFileVersionInfoExW : C:\Windows\system32\VERSION.dll @ 0x7fefcd8193c
[IAT:Addr] (explorer.exe @ WININET.dll) api-ms-win-downlevel-version-l1-1-0.dll - VerQueryValueA : C:\Windows\system32\VERSION.dll @ 0x7fefcd81b94
[IAT:Addr] (explorer.exe @ ieframe.dll) api-ms-win-downlevel-version-l1-1-0.dll - GetFileVersionInfoSizeExW : C:\Windows\system32\VERSION.dll @ 0x7fefcd814e8
[IAT:Addr] (explorer.exe @ ieframe.dll) api-ms-win-downlevel-version-l1-1-0.dll - GetFileVersionInfoExW : C:\Windows\system32\VERSION.dll @ 0x7fefcd8193c
[IAT:Addr] (explorer.exe @ ieframe.dll) api-ms-win-downlevel-version-l1-1-0.dll - VerQueryValueW : C:\Windows\system32\VERSION.dll @ 0x7fefcd815e0
[IAT:Addr] (explorer.exe @ nvapi64.dll) SETUPAPI.dll - CM_Get_DevNode_Status_Ex : C:\Windows\system32\CFGMGR32.dll @ 0x7fefd2d2fb4
[IAT:Addr] (explorer.exe @ nvapi64.dll) SETUPAPI.dll - CM_Reenumerate_DevNode : C:\Windows\system32\CFGMGR32.dll @ 0x7fefd2dcff0
[IAT:Addr] (explorer.exe @ nvapi64.dll) SETUPAPI.dll - CM_Get_Device_ID_ExW : C:\Windows\system32\CFGMGR32.dll @ 0x7fefd2d2d90
[IAT:Addr] (explorer.exe @ acppage.dll) sfc.dll - SfcIsFileProtected : C:\Windows\system32\sfc_os.DLL @ 0x7feed9316f0

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: ST1000LM024 HN-M101MBB ATA Device +++++
--- User ---
[MBR] 13c7b34bca752fde092d12a3da6edfb5
[BSP] e07e3c1e1371844ea3ee70be1d7034ca : Linux MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 249900 MB
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 512002048 | Size: 300000 MB
3 - [XXXXXX] EXTEN-LBA (0xf) [VISIBLE] Offset (sectors): 1126404094 | Size: 403867 MB
User = LL1 ... OK
User = LL2 ... OK


============================================
RKreport_SCN_10152014_211406.log - RKreport_SCN_10162014_184252.log
Core i5 4570, 8GB DDR3, msi gtx1070 8GB, 240GB SSD Kingston, 550W Zdroj

Uživatelský avatar
Pernee44
Level 3.5
Level 3.5
Příspěvky: 943
Registrován: říjen 07
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Re: Prosím o kontrolu logu - velmi pomalý nb

Příspěvekod Pernee44 » 16 říj 2014 18:54

tohle mi zoek pořád vypisuje.
Přílohy
Výstřižek.PNG
tu
Core i5 4570, 8GB DDR3, msi gtx1070 8GB, 240GB SSD Kingston, 550W Zdroj

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - velmi pomalý nb

Příspěvekod jaro3 » 16 říj 2014 19:23

zoek: stáhni znovu na plochu a spousť v nouz. režimu.

Ještě jednou:
Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB (kromě myši s klávesnice) nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Pak klikni na "Prohledat " ,po jeho skončení:


- V záložkách (Registry , Tasks , Web Browser apod.) vše zatrhni (dej zatržítka)

- Klikni na "Smazat"
- Počkej, dokud Status box nezobrazí " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 101 hostů