totaladperformance Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

buldok
Level 1
Level 1
Příspěvky: 50
Registrován: červen 15
Pohlaví: Nespecifikováno
Stav:
Offline

Re: totaladperformance

Příspěvekod buldok » 27 čer 2015 09:41

# AdwCleaner v4.207 - Log vytvořen 27/06/2015 v 09:40:17
# Aktualizováno 21/06/2015 by Xplode
# Databáze : 2015-06-23.1 [Server]
# Operační system : Windows 7 Ultimate Service Pack 1 (x64)
# Uživatelské jméno : Admin - ADMIN-PC
# Spuštěno z : F:\Users\admin\Desktop\adwcleaner_4.207.exe
# Nastavení : Čištění

***** [ Služby ] *****


***** [ Soubory / Složky ] *****


***** [ Naplánované úlohy ] *****


***** [ Zástupci ] *****


***** [ Registry ] *****


***** [ Prohlížeče ] *****

-\\ Internet Explorer v11.0.9600.17840


-\\ Google Chrome v43.0.2357.130


*************************

AdwCleaner[R2].txt - [1084 bytů] - [26/06/2015 13:56:15]
AdwCleaner[R3].txt - [872 bytů] - [27/06/2015 09:39:48]
AdwCleaner[S2].txt - [1144 bytů] - [26/06/2015 13:56:59]
AdwCleaner[S3].txt - [798 bytů] - [27/06/2015 09:40:17]

########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [855 bytů] ##########

Reklama
buldok
Level 1
Level 1
Příspěvky: 50
Registrován: červen 15
Pohlaví: Nespecifikováno
Stav:
Offline

Re: totaladperformance

Příspěvekod buldok » 27 čer 2015 09:44

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.1.7 (06.26.2015:3)
OS: Windows 7 Ultimate x64
Ran by Admin on so 27.06.2015 at 9:42:54,17
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders

Successfully deleted: [Folder] C:\ProgramData\microsoft\windows\start menu\programs\driver booster 2
Successfully deleted: [Folder] C:\ProgramData\productdata
Successfully deleted: [Folder] C:\Users\Admin\AppData\Roaming\productdata
Successfully deleted: [Folder] C:\Windows\syswow64\ai_recyclebin



~~~ Chrome


[C:\Users\Admin\appdata\local\Google\Chrome\User Data\Default\Preferences] - default search provider reset

[C:\Users\Admin\appdata\local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:

[C:\Users\Admin\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset

[C:\Users\Admin\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on so 27.06.2015 at 9:44:26,29
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

buldok
Level 1
Level 1
Příspěvky: 50
Registrován: červen 15
Pohlaví: Nespecifikováno
Stav:
Offline

Re: totaladperformance

Příspěvekod buldok » 27 čer 2015 09:51

RogueKiller V10.8.6.0 (x64) [Jun 22 2015] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno : Normální režim
Uživatel : Admin [Práva správce]
Started from : F:\Users\admin\Desktop\RogueKillerX64.exe
Mód : Prohledat -- Datum : 06/27/2015 09:50:53

¤¤¤ Procesy : 0 ¤¤¤

¤¤¤ Registry : 0 ¤¤¤

¤¤¤ Úlohy : 0 ¤¤¤

¤¤¤ Soubory : 0 ¤¤¤

¤¤¤ Soubor HOSTS : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: KINGSTON SV300S37A60G SCSI Disk Device +++++
--- User ---
[MBR] b4eccd60e995a912a677289619fe140f
[BSP] b554568ea084b9e8c5d3b0fefa35bcee : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 57138 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: WDC WD10EZEX-00BN5A0 SCSI Disk Device +++++
--- User ---
[MBR] 07e86a268d297efc247ebdaf45cc0a75
[BSP] 25d44347d1531dd52916511d26c2e8b5 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 953766 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive2: Generic- SD/MMC USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )

+++++ PhysicalDrive3: Generic- Compact Flash USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )

+++++ PhysicalDrive4: Generic- SM/xD-Picture USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )

+++++ PhysicalDrive5: Generic- MS/MS-Pro USB Device +++++
Error reading User MBR! ([15] Za?ízení není p?ipraveno. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] Po?adavek není podporován. )

Uživatelský avatar
jerabina
člen Security týmu
Level 6
Level 6
Příspěvky: 3647
Registrován: březen 13
Bydliště: Litoměřice
Pohlaví: Muž
Stav:
Offline

Re: totaladperformance

Příspěvekod jerabina » 27 čer 2015 11:38

Vypni antivir
Stáhni
Zoek.exe

a uloz si ho na plochu.
Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
- pozor , náběh programu může trvat déle.

Do okna programu vlož skript níže:

Kód: Vybrat vše

autoclean;
emptyclsid;
iedefaults;
FFdefaults;
CHRdefaults;
emptyalltemp;
resethosts;


klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .

Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log
Zkopíruj sem celý obsah toho logu.

Vlož nový log z HJT + informuj o problémech.
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.

buldok
Level 1
Level 1
Příspěvky: 50
Registrován: červen 15
Pohlaví: Nespecifikováno
Stav:
Offline

Re: totaladperformance

Příspěvekod buldok » 28 čer 2015 15:32

Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by Admin on ne 28.06.2015 at 15:23:56,22.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: F:\Users\admin\Desktop\zoek.exe [Scan all users] [Script inserted]

==== Older Logs ======================

C:\zoek-results2015-06-27-105245.log 2049 bytes

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-4152200476-433967530-3830499835-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{310CA7B9-D56B-499A-B786-D9648270585E} deleted successfully
HKEY_USERS\S-1-5-21-4152200476-433967530-3830499835-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} deleted successfully

==== Deleting Services ======================


==== Deleting Files \ Folders ======================

C:\Users\Admin\AppData\Roaming\iLinker deleted
C:\Users\Admin\AppData\Roaming\ProductData deleted
C:\PROGRA~3\ProductData deleted
C:\PROGRA~3\Package Cache deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"smartwebprinting@hp.com"="F:\Digital Imaging\Smart Web Printing\MozillaAddOn3" [12.05.2015 14:28]
[HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions]
"smartwebprinting@hp.com"="F:\Digital Imaging\Smart Web Printing\MozillaAddOn3" [12.05.2015 14:28]

==== Chromium Look ======================

Google Chrome Version: 43.0.2357.130


HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions
apdfllckaahabafndbhieahigkjlhalf - C:\Users\Admin\AppData\Local\Google\Drive\user_default\apdfllckaahabafndbhieahigkjlhalf_live.crx[]
lmjegmlicamnimmfhcmpkclmigmmcbeh - No path found[]

Grand Theft Auto V Theme - Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fifpefgiomhnkmkkcldjopjcfadhmhhn

==== Chromium Startpages ======================

C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Preferences
e":{},"automatic_downloads":{},"cookies":{},"fullscreen":{"https://www.youtube.com:443,https://www.youtube.com:443":{"setting":1}},"geolocation":{},"images":{},"javascript":{},"media_stream":{},"media_stream_camera":{},"media_stream_mic":{},"metro_switch_to_desktop":{},"midi_sysex":{},"mixed_script":{},"mouselock":{},"notifications":{},"plugins":{},"popups":{},"ppapi_broker":{},"protocol_handlers":{},"push_messaging":{},"ssl_cert_decisions":{}},"pattern_pairs":{"https://vyuka.progredior.eu:443,https://vyuka.progredior.eu:443":{"ssl-cert-decisions":{"cert_exceptions_map":{"4294967094kT49fmNhwvEpG9EUKDaCIqV3NQOcnfqFy5QQXebU7/0=":1},"guid":"EF3DEE99-B86A-49B6-8803-C77826836B5B","version":1}},"https://www.youtube.com:443,https://www.youtube.com:443":{"fullscreen":1}},"pref_version":1},"default_content_setting_values":{"geolocation":2,"media_stream_camera":2,"media_stream_mic":2,"mouselock":2,"notifications":2},"default_content_settings":{"geolocation":2,"media-stream":2,"mouselock":2,"notifications":2},"exit_type":"Normal","exited_cleanly":true,"gaia_info_picture_url":"https://lh6.googleusercontent.com/-vQ1RGR-w_XM/AAAAAAAAAAI/AAAAAAAAAUs/YS6VVt9e2UQ/s256-c/photo.jpg","gaia_info_update_time":"13079907746795549","icon_version":3,"managed_user_id":"","managed_users":{},"migrated_content_settings_exceptions":true,"migrated_default_content_settings":true,"migrated_default_media_stream_content_settings":true,"name":"První uživatel","password_manager_enabled":true,"per_host_zoom_levels":{}},"protection":{"macs":{}},"reverse_autologin":{"enabled":false},"safebrowsing":{"extended_reporting_enabled":true},"savefile":{"default_directory":"F:\\Users\\admin\\Desktop"},"selectfile":{"last_directory":"F:\\Users\\admin\\Desktop"},"session":{"restore_on_startup_migrated":true,"startup_urls_migration_time":"13076074376281208"},"signin":{"signedin_time":"13076074392453501"},"sync":{"app_list":true,"app_settings":true,"apps":true,"autofill":true,"autofill_wallet":true,"bookmarks":true,"dictionary":true,"encryption_bootstrap_token":"AQAAANCMnd8BFdERjHoAwE/Cl+sBAAAAX2tc6qsotUmJqkZ3yD+KpwAAAAACAAAAAAAQZgAAAAEAACAAAACfZ51/4e75DqX77VegJ+QFjxmIwqCWAmA88GaDR5yu+QAAAAAOgAAAAAIAACAAAADlJheTrWwBbJStW4zhZwUzvTTwzDZGNoibLLUbDj8OsEAAAAAEWAdYkHPSKALC0kRV4gwrGN8MBg9dVv3/qe+9Cql1PKxqaBvWhC6igBsQq0seMmD2wbCXUtth4Uhm2prFNuDRQAAAAAdM1YctpGOUk5ob+PihGgdJKE2ThYZSNmbahqQYmas31ECOyfCuyRt6R/SMq959qcGszERKbdRjPWriKBF8tOk=","extension_settings":true,"extensions":true,"favicon_images":true,"favicon_tracking":true,"first_sync_time":"13076074392466188","has_setup_completed":true,"history_delete_directives":true,"keystore_encryption_bootstrap_token":"AQAAANCMnd8BFdERjHoAwE/Cl+sBAAAAX2tc6qsotUmJqkZ3yD+KpwAAAAACAAAAAAAQZgAAAAEAACAAAAABI3taBSL542D3svzVs0jBkqPnMHs698UbxVQ1Wh+a5QAAAAAOgAAAAAIAACAAAAAtBkS107NtUwcAciRBqCiua9TSqAf2fimdoJ+gHqrj7FAAAAB/ZZHMDhfXSudW5nj+FQMzb194412xRRmtvo6qhS49MWTWSiQiPVUBJxF7uekSeUBqYhX4uFTGsG/gq6Y9j1q9nr1hWQEdhlzjhiGoosi/TkAAAACw6h7P4FyrW97vzrGaHKb5y8oKbMx2WQgKQPXHU8DACHaPYpcE2JEWdDIYLKI3GkDlKR/Sfvb5Yok89xPWqmrK","last_synced_time":"13079971402894681","managed_user_settings":true,"managed_user_shared_settings":true,"managed_user_whitelists":true,"managed_users":true,"passwords":true,"preferences":true,"priority_preferences":true,"search_engines":true,"session_sync_guid":"session_syncSx5nFFJ51JBYbth1hOXJqw==","sessions":true,"suppress_start":false,"tabs":true,"themes":true,"typed_urls":true},"sync_promo":{"startup_count":1},"translate":{"enabled":true},"translate_accepted_count":{"de":0,"en":0,"es":0,"fr":0,"it":0,"pl":0,"pt":0,"ru":3,"sk":0,"zh-CN":1,"zh-TW":0},"translate_blocked_languages":["cs","sk","en","ar","es","it"],"translate_denied_count":{"de":2,"en":17,"es":7,"fr":1,"it":1,"pl":1,"pt":3,"ru":0,"sk":3,"zh-CN":0,"zh-TW":1},"translate_site_blacklist":["cz3.darkorbit.bigpoint.com","www.xtube.com"],"translate_too_often_denied":true,"translate_whitelists":{},"zerosuggest":{"cachedresults":""}}
ngs","permissions":["notifications"],"update_url":"http://clients2.google.com/service/update2/crx","version":"8.1"},"page_ordinal":"n","path":"pjkljhegncpnkpknbcohdijeoejaedia\\8.1_0","preferences":{},"regular_only_preferences":{},"state":1,"was_installed_by_default":true,"was_installed_by_oem":false}}},"google":{"services":{"last_username":"buldockova@gmail.com","username":"buldockova@gmail.com"}},"homepage":"http://seznam.cz/","homepage_is_newtabpage":true,"pinned_tabs":[],"protection":{"macs":{"browser":{"show_home_button":"5DCD8384C2CC10A5E2909EA18272782F31C7BFC2C4F8FB0E0A1A6B5366EE649A"},"default_search_provider":{"keyword":"206C98BE3592AA68F010ACEC1BBDF6D4503F7FE77645A81BEC4001D6E7FCAC42","name":"3E0195349AB251B129B88E6B37EAA0E62DAFE4925F31F11E9EC583A459ECDB77","search_url":"6A8EE84C6806BB85E94307F08D2AE85196174A469DF88CCCB6F0E535015EED13"},"default_search_provider_data":{"template_url_data":"AB03BD99D43D1A5255394DAA61744EE1D769B9EA9A2E13A3DBC7FB178F4DA95C"},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":"91C2E950EFCB5F67A483E57BCBC346738C7EB7245C7C681B686D85B0B772A075","bepbmhgboaologfdajaanbcjmnhjmhfn":"8DBCF41B32A070B6D1F05CD054C714375020C62D204E9D4B175CA7208A52876F","blpcfgokakmgnkcojhhkbfbldkacnbeo":"7C5E57492BAD6A1C2FF12AC75C4F0D34FD314858DF9E12748CBBDC3CEBE916CB","coobgpohoikkiipiblmjeljniedjpjpf":"9F85CA9433E02A20C92D70CC30B5DFA9C65A7ACBA356E71525E1416A295CA5EA","dbhjdbfgekjfcfkkfjjmlmojhbllhbho":"16129DA81C6F6B27AD64281919F0124651BA81B841E9BAD485FCC14279074002","eemcgdkfndhakfknompkggombfjjjeno":"9EC8613DB1172FE15D9E666259940D17D29FF3C843A7138AD4348C1E35CF8F42","ennkphjdgehloodpbhlhldgbnhmacadg":"FF1A0DBA1A64FA1FDB5271ACD8BDFA11154C5623631507FD0A226DB4A0A955F9","fifpefgiomhnkmkkcldjopjcfadhmhhn":"C5DC33FF3C3BD0BD90360B539F7AA029A045C7274DA504774BCDDD8C7A45E2BA","gfdkimpbcpahaombhbimeihdjnejgicl":"7F9594B28AA685394F70C0C70807380B970AC7EBA2C3BE9214410F37C3D5657E","hmjdkedhkcbmilnhghkeafajabfojimm":"39972242D65D5A775AA45D4B7302A3E7A313B974E34DEBDDEC91DC9BDFF44A4A","kmendfapggjehodndflmmgagdbamhnfd":"37A271BC371F40F49650609EE167D9B1D4508DA6A0DE6F42A09E217520EF1142","knebimhcckndhiglamoabbnifdkijidd":"D808532416230CBFA1B0E2EE0F60F438F24386CD0C50F18AE54888C3D549ECD6","lmjegmlicamnimmfhcmpkclmigmmcbeh":"0C9031A465F56510E868C6292CF1EBA12AC3B243229E0FA325859789D0E577CC","mfehgcgbbipciphmccgaenjidiccnmng":"0EFC785E07B99D6B3B2F70B0061A67BF97BF90D4C479D75E338E0402E4AB1DBE","mfffpogegjflfpflabcdkioaeobkgjik":"66383EBCDBDA69012746DEDE1874BD7DC0050854578A6A624D9257AFD37632E1","mgndgikekgjfcpckkfioiadnlibdjbkf":"312D1FD225387318CAC78957BE79EC34A1F959FB368C6C8CD531BBEBFDD3971F","mhjfbmdgcfjbbpaeojofohoefgiehjai":"F72B304FD39ACB0F8063203DC5CCCC47BAB11E8FD0855234EE81F3D23DE18C64","mihcahmgecmbnbcchbopgniflfhgnkff":"6A6E4A2DC03E8D7FF4BB95510B3DB819DDF4E5D018694DEB625B74F014740ABE","neajdppkdcdipfabeoofebfddakdcjhd":"6EC187E0D66637D389DA888846BEB2D9404365146A96CF28A945209CEDFC53DC","nkeimhogjdpnpccoofpliimaahmaaome":"42D64D47A1CC457CCEF802E79E830A018F6F315E1D6898D94CD356EE0A972DB9","nmmhkkegccagdldgiimedpiccmgmieda":"E44279DA090DC514C38210A2712E3A800D63B31B455FCE77B5A5FAD79F0F7039","pafkbggdmjlpgkdkcbjmhmfcdpncadgh":"090DB6C02270FA134A486EB624B62C2DF6216D3DF8CD14DCACF8A8B72B97C0FB","pjkljhegncpnkpknbcohdijeoejaedia":"F60E7CC680E632CFB5C3484460248B964E1E8526D8DD2C2A94D72AD5CD5EE67E"}},"google":{"services":{"last_username":"843BB8F47D37BF17587B03FC25B31080DEBE16A9F4F1BACAC056BED375850558","username":"8630F92A3A7C6135B0B3EE5DD79CA1BCBF248126327F58772FFC8211E9011D12"}},"homepage":"D13761A3CA78E97B4C1AC0FA76E3858F497E24DEE649D7DEBEF232776F366D20","homepage_is_newtabpage":"8823397E0925399EB05A2D4BAED58AC4ADD23901E9568D2F25B5680A8E075D07","pinned_tabs":"8307B561A920CE3D0FCFE0998912E90FE3653D392BB7F9CC082CF83A7EC68C29","prefs":{"preference_reset_time":"6902189FC7E173263EE3E5C3B2B0A7A810D529BFE1C51F86301933A7E194957D"},"profile":{"reset_prompt_memento":"BA8E1661F5D2D30EEBB5DA1041B1DC0DC7DD3A98CDD7FC628F5928B442AE8CAE"},"safebrowsing":{"incidents_sent":"E7E67AB9BF8DD732BC18602C3B2F664D9BC5393877F1AD402B811645DD8A15D7"},"search_provider_overrides":"05C33020DD41A8D068A88CA3CC5F776EBF4C2E644AF36D23FF19A81A1AEE383B","session":{"restore_on_startup":"C0F98532544034BA234A831EE01C69ED8E1B5174BEE27BD7A3B804BC18AAAF70","startup_urls":"FB090407C2332A1147DC8C1E3FAE62E7CDA61CB1D76F0A742C79618F524C4ED4"},"software_reporter":{"prompt_reason":"8413BD9BE3E1132F7296DFD3D27530FC07C4A378CD1C791591B3FA61601EE427","prompt_seed":"9AE81B7013B0943C784D9683FA89ADEBBFA97BFC978623174094FD62BE6F7C24","prompt_version":"678457E3B56C0567F8CCF022E9DD10B55793ABB2C83BB1324FF979C6D1CE5CF3"},"sync":{"remaining_rollback_tries":"4A4CA2C2FC687868D078A6AB411E75E9BD226924B345D0A7E1232C6EC4118157"}},"super_mac":"A5309ACF77049011727774AB4933BB53FDE9993F9E4D8BD44639DBFEA68804C9"},"session":{"restore_on_startup":1,"startup_urls":["https://www.facebook.com/home.php","http://www.google.com/","http://www.google.com"]},"sync":{"remaining_rollback_tries":0}}


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.msn.com/?ocid=iehp"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.msn.com/?ocid=iehp"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"

==== Reset Google Chrome ======================

C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully

==== Deleting Registry Keys ======================

HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\apdfllckaahabafndbhieahigkjlhalf deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GoogleDriveSync deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Infinit deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Live Update deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NetDrive2 deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=42 folders=39 119091400 bytes)

==== Empty Temp Folders ======================

C:\Users\Admin\AppData\Local\Temp will be emptied at reboot
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Admin\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\MpCmdRun.log" not found

==== EOF on ne 28.06.2015 at 15:31:24,40 ======================

Uživatelský avatar
jerabina
člen Security týmu
Level 6
Level 6
Příspěvky: 3647
Registrován: březen 13
Bydliště: Litoměřice
Pohlaví: Muž
Stav:
Offline

Re: totaladperformance

Příspěvekod jerabina » 28 čer 2015 16:36

Tak ještě HJT prosím :-)
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.

buldok
Level 1
Level 1
Příspěvky: 50
Registrován: červen 15
Pohlaví: Nespecifikováno
Stav:
Offline

Re: totaladperformance

Příspěvekod buldok » 28 čer 2015 17:50

Myslíš stáhnout program HJT a projet to sním? Ale i bez toho mi to tu již nevyskakuje :)

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: totaladperformance

Příspěvekod jaro3 » 28 čer 2015 21:08

Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.



Vlož nový log z HJT

Problémy nejsou?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

buldok
Level 1
Level 1
Příspěvky: 50
Registrován: červen 15
Pohlaví: Nespecifikováno
Stav:
Offline

Re: totaladperformance

Příspěvekod buldok » 29 čer 2015 11:15

aswMBR version 1.0.1.2290 Copyright(c) 2014 AVAST Software
Run date: 2015-06-29 11:12:52
-----------------------------
11:12:52.262 OS Version: Windows x64 6.1.7601 Service Pack 1
11:12:52.262 Number of processors: 4 586 0x3C03
11:12:52.262 ComputerName: ADMIN-PC UserName: Admin
11:12:52.371 Initialize success
11:12:52.418 VM: initialized successfully
11:12:52.418 VM: Intel CPU supported
11:12:57.932 VM: disk I/O iaStorA.sys
11:13:02.512 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000007e
11:13:02.512 Disk 0 Vendor: KINGSTON 525A Size: 57240MB BusType: 11
11:13:02.512 Disk 1 \Device\Harddisk1\DR1 -> \Device\0000007f
11:13:02.512 Disk 1 Vendor: WDC_____ 01.0 Size: 953868MB BusType: 11
11:13:02.528 Disk 0 MBR read successfully
11:13:02.528 Disk 0 MBR scan
11:13:02.528 Disk 0 Windows 7 default MBR code
11:13:02.528 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
11:13:02.528 Disk 0 Boot: NTFS code=2
11:13:02.528 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 57138 MB offset 206848
11:13:02.528 Disk 0 scanning C:\Windows\system32\drivers
11:13:03.308 Service scanning
11:13:05.351 Service ehdrv C:\Windows\system32\DRIVERS\ehdrv.sys **LOCKED** 5
11:13:05.382 Service epfw C:\Windows\system32\DRIVERS\epfw.sys **LOCKED** 5
11:13:05.382 Service EpfwLWF C:\Windows\system32\DRIVERS\EpfwLWF.sys **LOCKED** 5
11:13:05.398 Service epfwwfp C:\Windows\system32\DRIVERS\epfwwfp.sys **LOCKED** 5
11:13:05.991 Service NTIOLib_1_0_C D:\NTIOLib_X64.sys **LOCKED** 21
11:13:07.254 Modules scanning
11:13:07.254 Disk 0 trace - called modules:
11:13:07.254 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStorF.sys storport.sys hal.dll iaStorA.sys
11:13:07.254 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8009694060]
11:13:07.270 3 CLASSPNP.SYS[fffff8800120143f] -> nt!IofCallDriver -> [0xfffffa8009591b60]
11:13:07.270 5 iaStorF.sys[fffff88001ac3f84] -> nt!IofCallDriver -> \Device\0000007e[0xfffffa8006de39c0]
11:13:07.270 Disk 0 statistics 97802/0/0 @ 74,50 MB/s
11:13:07.270 Scan finished successfully
11:14:03.836 Disk 0 MBR has been saved successfully to "F:\Users\admin\Desktop\MBR.dat"
11:14:03.851 The log file has been saved successfully to "F:\Users\admin\Desktop\aswMBR.txt"

buldok
Level 1
Level 1
Příspěvky: 50
Registrován: červen 15
Pohlaví: Nespecifikováno
Stav:
Offline

Re: totaladperformance

Příspěvekod buldok » 29 čer 2015 11:15

No jsem na počítači již 3h v kuse a stále nic nevyskakuje. Tak je to asi pryč. Dříve to vyskakovalo cca 3x do hodiny.

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: totaladperformance

Příspěvekod Orcus » 29 čer 2015 13:43

Ještě dodej log z HiJackThis, ať to dočistíme. ;)
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

buldok
Level 1
Level 1
Příspěvky: 50
Registrován: červen 15
Pohlaví: Nespecifikováno
Stav:
Offline

Re: totaladperformance

Příspěvekod buldok » 29 čer 2015 13:47

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:46:35, on 29.6.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)


Boot mode: Normal

Running processes:
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
C:\Program Files (x86)\Bloody5\Bloody5\Bloody5.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
F:\Program Files (x86)\x86\SetPoint32.exe
F:\Users\admin\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O1 - Hosts: ::1 localhost
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - F:\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - F:\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe" 60
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Bloody2] "C:\Program Files (x86)\Bloody5\Bloody5\Bloody5.exe" Minimum
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://F:\PROGRA~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://F:\PROGRA~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Spustit klienta k monitoru &1 - C:\Windows\web\AOpenClient.htm
O8 - Extra context menu item: Spustit klienta k monitoru &2 - C:\Windows\web\AOpenClient.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files (x86)\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Zobrazit nebo skrýt HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - F:\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 8 (AdvancedSystemCareService8) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - F:\Program Files (x86)\DAEMON Tools Lite\DiscSoftBusService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GamingApp_Service - Micro-Star Int'l Co., Ltd. - C:\Program Files (x86)\MSI\MSI Gaming APP\GamingApp_Service.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Solutions Framework Service (HPSupportSolutionsFrameworkService) - Hewlett-Packard Company - C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Small Business Advantage (intelsba) - Intel Corporation - C:\Program Files\Intel\Intel(R) Small Business Advantage\Service\Intel.SmallBusinessAdvantage.WindowsService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMService - Malwarebytes Corporation - F:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MSIBIOSData_CC - MSI - C:\Program Files (x86)\MSI\Command Center\BIOSData\MSIBIOSDataService.exe
O23 - Service: MSIClock_CC - Unknown owner - C:\Program Files (x86)\MSI\Command Center\ClockGen\MSIClockService.exe
O23 - Service: MSICOMM_CC - Unknown owner - C:\Program Files (x86)\MSI\Command Center\MSICommService.exe
O23 - Service: MSICPU_CC - Unknown owner - C:\Program Files (x86)\MSI\Command Center\CPU\MSICPUService.exe
O23 - Service: MSICTL_CC - Unknown owner - C:\Program Files (x86)\MSI\Command Center\MSIControlService.exe
O23 - Service: MSIDDR_CC - Unknown owner - C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe
O23 - Service: MSISaveLoad_CC - Unknown owner - C:\Program Files (x86)\MSI\Command Center\MSISaveLoadService.exe
O23 - Service: MSISMB_CC - Unknown owner - C:\Program Files (x86)\MSI\Command Center\SMBus\MSISMBService.exe
O23 - Service: MSISuperIO_CC - Unknown owner - C:\Program Files (x86)\MSI\Command Center\SuperIO\MSISuperIOService.exe
O23 - Service: MSIWMI_CC - Unknown owner - C:\Program Files (x86)\MSI\Command Center\MSIWMIService.exe
O23 - Service: MSI_SuperCharger - MSI - C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - F:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Qualcomm Atheros Killer Service V2 - Qualcomm Atheros - C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - F:\Program Files (x86)\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: SuperRAIDSvc - Unknown owner - C:\MSI\Smart Utilities\SuperRAIDSvc.exe


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 45 hostů