Problém s odebráním USB flasch,zpomalený PC

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Zpráva
Autor
Avatar uživatele
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8720
Registrován: 09 Pro 2006 06:19
Místo/Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Problém s odebráním USB flasch,zpomalený PC

#16 Příspěvek od cernohous13 »

je to nějaká podivná záležitost z 06/10/2012 - netušíš :???:
Klikni na https://www.virustotal.com
klik "Procházet" > po kliknutí na "Choose File" jen zkopíruj do řádku "Název souboru":

C:\hwevid\akt.exe

"Scan It" (pokud byl již testován, nech testovat znovu - Reanalyse)
Trpělivě vyčkej dokončení scanu dokud se neobjeví konečný výsledek např.0/41
Do fóra zkopíruj výsledný log. nebo odkaz z adresního řádku na stránku.
Pokud nebude nález stačí jen oznámit
totéž se souborem:
C:\hwevid\hwevid.exe
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Sagitt62
Návštěvník
Návštěvník
Příspěvky: 131
Registrován: 25 Kvě 2008 13:40

Re: Problém s odebráním USB flasch,zpomalený PC

#17 Příspěvek od Sagitt62 »

Něco asi nalezeno bylo,klasický log ale nemůžu najít.6/10/2012 se dělal patch na Il-2 Sturmovik,aspoň si myslím. Co tohle:

SHA256: 3921f89573082513a2c6d4f90a472de788b951cb74616497b506e6a0116c526f
SHA1: ce58b90eaa69f55375eb08f0f07412917f7d3829
MD5: 642698fcb64faf5a5b6d9e91cc13b885
File size: 805.0 KB ( 824320 bytes )
File name: akt.exe
File type: Win32 EXE
Detection ratio: 11 / 46
Analysis date: 2013-02-24 16:37:51 UTC ( 0 minut ago )
0
0
Less details

Analysis
Comments
Votes
Additional information

ssdeep
24576:wpNByZvzHEkeRBrU74jUUq1X2g7OGjg6T3x:+ByZLkde7ezqdk6TB
TrID
Win32 Executable Borland Delphi 7 (69.6%)
Win32 Executable Borland Delphi 6 (27.3%)
Win32 Executable Delphi generic (1.5%)
Win32 Executable Generic (0.8%)
Win16/32 Executable Delphi generic (0.2%)
PEiD packer identifier
BobSoft Mini Delphi -> BoB / BobSoft
ExifTool

MIMEType.................: application/octet-stream
Subsystem................: Windows GUI
MachineType..............: Intel 386 or later, and compatibles
TimeStamp................: 1992:06:19 23:22:17+01:00
FileType.................: Win32 EXE
PEType...................: PE32
CodeSize.................: 649216
LinkerVersion............: 2.25
EntryPoint...............: 0x9f628
InitializedDataSize......: 174080
SubsystemVersion.........: 4.0
ImageVersion.............: 0.0
OSVersion................: 4.0
UninitializedDataSize....: 0

Portable Executable structural information

Compilation timedatestamp.....: 1992-06-19 22:22:17
Target machine................: 0x14C (Intel 386 or later processors and compatible processors)
Entry point address...........: 0x0009F628

PE Sections...................:

Name Virtual Address Virtual Size Raw Size Entropy MD5
CODE 4096 648872 649216 6.54 05b4db531d49d8ffb93b203d85e3fb1a
DATA 655360 8272 8704 5.00 4bc191c41885b4ec6fe1b4aec4ad1fa3
BSS 667648 4169 0 0.00 d41d8cd98f00b204e9800998ecf8427e
.idata 675840 10588 10752 4.87 75e5470b774611fbf57c1e8a838cfdfb
.tls 688128 36 0 0.00 d41d8cd98f00b204e9800998ecf8427e
.rdata 692224 24 512 0.18 bdf1aadf8f39805b91cbad6481f499ce
.reloc 696320 44956 45056 6.65 58233331fd615de88fd2de9a0fec7b71
.rsrc 741376 109056 109056 6.82 4a8a21932036e191ba45b9949d799270

PE Imports....................:

[[mpr.dll]]
WNetOpenEnumA, WNetGetUniversalNameA, WNetEnumResourceA, WNetCloseEnum

[[version.dll]]
GetFileVersionInfoSizeA, GetFileVersionInfoA, VerQueryValueA

[[gdi32.dll]]
GetBrushOrgEx, GetDIBColorTable, DeleteEnhMetaFile, GetWindowOrgEx, PatBlt, GetClipBox, GetCurrentPositionEx, SaveDC, CreateFontIndirectA, GetTextMetricsA, MaskBlt, CreateBrushIndirect, SetStretchBltMode, GetEnhMetaFilePaletteEntries, GetPixel, GetDCOrgEx, Rectangle, BitBlt, GetObjectA, ExcludeClipRect, LineTo, DeleteDC, RestoreDC, SetBkMode, GetSystemPaletteEntries, SetPixel, CreateSolidBrush, DeleteObject, IntersectClipRect, CreateHalftonePalette, CreateDIBSection, CopyEnhMetaFileA, RealizePalette, SetTextColor, GetDeviceCaps, MoveToEx, SetEnhMetaFileBits, CreateBitmap, RectVisible, CreatePalette, GetStockObject, CreateDIBitmap, SetViewportOrgEx, SelectPalette, ExtTextOutA, UnrealizeObject, GetDIBits, GetEnhMetaFileBits, SetBrushOrgEx, SelectClipRgn, PlayEnhMetaFile, StretchBlt, GetBitmapBits, CreateCompatibleDC, SetROP2, SelectObject, GetTextExtentPoint32A, GetWinMetaFileBits, SetDIBColorTable, GetEnhMetaFileHeader, GetPaletteEntries, SetWindowOrgEx, Polyline, GetTextExtentPointA, SetBkColor, SetWinMetaFileBits, GetTextExtentPoint32W, CreateCompatibleBitmap, CreatePenIndirect

[[advapi32.dll]]
RegOpenKeyExA, RegQueryValueExA, RegCloseKey

[[kernel32.dll]]
SetThreadLocale, GetStdHandle, FileTimeToDosDateTime, FileTimeToSystemTime, GetFileAttributesA, WaitForSingleObject, GetDriveTypeA, GetLocalTime, DeleteCriticalSection, GetLocaleInfoA, LocalAlloc, SetErrorMode, GetLogicalDrives, GetFileInformationByHandle, GetTempPathA, WideCharToMultiByte, InterlockedExchange, WriteFile, FormatMessageW, GetDiskFreeSpaceA, GetFullPathNameA, SetEvent, LocalFree, MoveFileA, InitializeCriticalSection, LoadResource, GlobalHandle, FindClose, TlsGetValue, FormatMessageA, GetFullPathNameW, GetStringTypeExA, SetLastError, GlobalFindAtomA, ExitProcess, GetModuleFileNameA, EnumCalendarInfoA, GetVolumeInformationA, LoadLibraryExA, UnhandledExceptionFilter, InterlockedDecrement, MultiByteToWideChar, GetModuleHandleA, CreateThread, GlobalAddAtomA, MulDiv, ExitThread, GlobalAlloc, LocalFileTimeToFileTime, SetEndOfFile, GetCurrentThreadId, InterlockedIncrement, SetCurrentDirectoryA, EnterCriticalSection, FreeLibrary, GetTickCount, VirtualProtect, GetVersionExA, LoadLibraryA, RtlUnwind, GetStartupInfoA, GetDateFormatA, GetFileSize, CreateDirectoryA, DeleteFileA, GetCPInfo, GetUserDefaultLCID, CompareStringW, GlobalReAlloc, lstrcmpA, FindFirstFileA, lstrcpyA, ResetEvent, GetTempFileNameA, FindNextFileA, GetProcAddress, CreateFileW, CreateEventA, CopyFileA, GetFileType, SetVolumeLabelA, TlsSetValue, CreateFileA, LeaveCriticalSection, GetLastError, DosDateTimeToFileTime, GlobalDeleteAtom, GetSystemInfo, lstrlenA, GlobalFree, GetThreadLocale, GlobalUnlock, VirtualQuery, RemoveDirectoryA, FileTimeToLocalFileTime, SizeofResource, CompareFileTime, GetCurrentProcessId, LockResource, SetFileTime, GetCurrentDirectoryA, GetCommandLineA, RaiseException, SetFilePointer, ReadFile, CloseHandle, lstrcpynA, GetACP, GlobalLock, GetVersion, FreeResource, VirtualFree, Sleep, FindResourceA, VirtualAlloc, CompareStringA

[[oleaut32.dll]]
VariantChangeType, SafeArrayGetLBound, SafeArrayPtrOfIndex, SysAllocStringLen, VariantClear, SafeArrayCreate, SysReAllocStringLen, SafeArrayGetUBound, VariantCopy, GetErrorInfo, SysFreeString, VariantInit

[[shell32.dll]]
ShellExecuteA, SHFileOperationA

[[ole32.dll]]
CoUninitialize, CoCreateInstance, CoInitialize, CoTaskMemAlloc

[[user32.dll]]
RedrawWindow, GetMessagePos, DestroyWindow, EnableScrollBar, DestroyMenu, PostQuitMessage, GetForegroundWindow, LoadBitmapA, SetWindowPos, IsWindow, DispatchMessageA, EndPaint, SetMenuItemInfoA, CharUpperBuffA, WindowFromPoint, DrawIcon, VkKeyScanW, SetMenuItemInfoW, SetActiveWindow, GetMenuItemID, GetCursorPos, ReleaseDC, GetClassInfoA, SendMessageW, UnregisterClassA, SendMessageA, UnregisterClassW, GetClientRect, DrawTextW, SetScrollPos, CallNextHookEx, GetKeyboardState, ClientToScreen, GetTopWindow, ShowCursor, GetWindowTextW, GetWindowTextLengthW, ScrollWindow, GetWindowTextA, GetKeyState, PtInRect, DrawEdge, GetParent, UpdateWindow, SetPropA, EqualRect, EnumWindows, DefMDIChildProcA, ShowWindow, SetClassLongA, GetPropA, GetDesktopWindow, DestroyIcon, TranslateMDISysAccel, EnableWindow, SetWindowPlacement, CharUpperW, PeekMessageA, ChildWindowFromPoint, GetClipboardData, TranslateMessage, IsWindowEnabled, GetWindow, ActivateKeyboardLayout, InsertMenuItemA, CreatePopupMenu, CharNextExA, GetIconInfo, LoadStringA, SetParent, RegisterClassW, CharLowerA, IsZoomed, GetWindowPlacement, LoadStringW, GetKeyboardLayoutList, DrawMenuBar, IsIconic, RegisterClassA, GetMenuItemCount, GetWindowLongA, SetTimer, OemToCharA, GetActiveWindow, IsDialogMessageW, FillRect, EnumThreadWindows, CharNextA, GetSysColorBrush, IsWindowUnicode, CreateWindowExW, GetWindowLongW, GetMenuItemInfoW, IsChild, IsDialogMessageA, SetFocus, MapVirtualKeyA, SetCapture, BeginPaint, OffsetRect, DefWindowProcW, GetScrollPos, KillTimer, MapVirtualKeyW, RegisterWindowMessageA, DefWindowProcA, DrawFocusRect, MapWindowPoints, GetSystemMetrics, SetWindowLongW, SetScrollRange, GetWindowRect, InflateRect, PostMessageA, ReleaseCapture, GetScrollRange, SetWindowLongA, PostMessageW, GetKeyNameTextW, RemovePropA, SetWindowTextA, CheckMenuItem, GetSubMenu, GetLastActivePopup, DrawIconEx, SetWindowTextW, CreateWindowExA, ScreenToClient, InsertMenuA, LoadCursorA, LoadIconA, TrackPopupMenu, SetWindowsHookExA, GetMenuStringA, CreateIconFromResource, GetMenuState, ShowOwnedPopups, GetSystemMenu, GetDC, SetForegroundWindow, GetMenuStringW, DrawTextA, IntersectRect, GetScrollInfo, GetKeyboardLayout, CreateIcon, GetCapture, WaitMessage, FindWindowA, MessageBeep, RemoveMenu, GetWindowThreadProcessId, ShowScrollBar, GetMenu, DrawFrameControl, UnhookWindowsHookEx, RegisterClipboardFormatA, CallWindowProcA, MessageBoxA, GetClassNameA, GetWindowDC, DestroyCursor, AdjustWindowRectEx, LoadKeyboardLayoutA, GetSysColor, SetScrollInfo, GetMenuItemInfoA, SystemParametersInfoA, EnableMenuItem, GetKeyNameTextA, IsWindowVisible, CharToOemA, GetDCEx, WinHelpA, DispatchMessageW, FrameRect, SetRect, DeleteMenu, InvalidateRect, DefFrameProcA, CallWindowProcW, GetClassNameW, CharLowerBuffA, GetClassInfoW, SetWindowsHookExW, IsRectEmpty, GetCursor, GetFocus, CreateMenu, GetKeyboardType, SetMenu, SetCursor

[[comctl32.dll]]
ImageList_BeginDrag, ImageList_SetBkColor, ImageList_Replace, InitCommonControls, ImageList_SetDragCursorImage, ImageList_Read, ImageList_GetDragImage, ImageList_Create, ImageList_DragMove, ImageList_DrawEx, ImageList_SetIconSize, ImageList_Write, ImageList_GetImageCount, ImageList_Destroy, ImageList_Draw, ImageList_GetIconSize, ImageList_DragLeave, ImageList_GetBkColor, ImageList_ReplaceIcon, ImageList_DragEnter, ImageList_Add, ImageList_DragShowNolock, ImageList_Remove, ImageList_EndDrag

PE Resources..................:

Resource type Number of resources
RT_STRING 30
RT_BITMAP 14
RT_GROUP_CURSOR 7
RT_CURSOR 7
RT_RCDATA 4
RT_DIALOG 1
RT_MANIFEST 1
RT_ICON 1
RT_GROUP_ICON 1

Resource language Number of resources
NEUTRAL 64
CZECH DEFAULT 2

First seen by VirusTotal
2013-01-26 16:23:14 UTC ( 4 týdny, 1 den ago )
Last seen by VirusTotal
2013-02-24 16:37:51 UTC ( 4 minuty ago )
File names (max. 25)

akt.exe
642698fcb64faf5a5b6d9e91cc13b885

Avatar uživatele
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8720
Registrován: 09 Pro 2006 06:19
Místo/Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Problém s odebráním USB flasch,zpomalený PC

#18 Příspěvek od cernohous13 »

11/46 není moc dobré vysvědčení pro uvedený soubor :shock:

co s tím patchem provedeme? necháš si ho nebo ho smažu?
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Sagitt62
Návštěvník
Návštěvník
Příspěvky: 131
Registrován: 25 Kvě 2008 13:40

Re: Problém s odebráním USB flasch,zpomalený PC

#19 Příspěvek od Sagitt62 »

Ještě čekám na proskenování to druhého souboru,už se to šrotuje 5 min.,moment.

Sagitt62
Návštěvník
Návštěvník
Příspěvky: 131
Registrován: 25 Kvě 2008 13:40

Re: Problém s odebráním USB flasch,zpomalený PC

#20 Příspěvek od Sagitt62 »

Tady:
SHA256: 0b15b62aa24e3eecfba997353bd82f543b9e68961b526dcff97975896466302d
File name: hwevid.exe
Detection ratio: 3 / 45
Analysis date: 2013-02-24 16:50:07 UTC ( 5 minut ago )
0
0
More details

Analysis
Comments
Votes
Additional information

ssdeep
24576:fH0xs+4/RH52HCz9YNFid2FysjYKLKZy6m43a0PSoqJfitydRw7DlGb8V4/iT+7c:fREHCz9YNS2FvLSy6mM1c7dUm
TrID
Win32 Executable Borland Delphi 7 (58.2%)
Win32 Executable Borland Delphi 5 (39.2%)
Win32 Executable Delphi generic (1.2%)
Win32 Executable Generic (0.7%)
Win16/32 Executable Delphi generic (0.1%)
ExifTool

LegalTrademarks..........:
SubsystemVersion.........: 4.0
Comments.................:
InitializedDataSize......: 1039360
ImageVersion.............: 0.0
FileSubtype..............: 0
FileVersionNumber........: 1.4.4.94
LanguageCode.............: Czech
FileFlagsMask............: 0x003f
FileDescription..........:
CharacterSet.............: Windows, Latin2 (Eastern European)
LinkerVersion............: 2.25
FileOS...................: Win32
MIMEType.................: application/octet-stream
LegalCopyright...........:
FileVersion..............: 1.4.4.94
TimeStamp................: 1992:06:19 23:22:17+01:00
FileType.................: Win32 EXE
PEType...................: PE32
InternalName.............:
ProductVersion...........: 1.4.2
UninitializedDataSize....: 0
OSVersion................: 4.0
OriginalFilename.........:
Subsystem................: Windows GUI
MachineType..............: Intel 386 or later, and compatibles
CompanyName..............:
CodeSize.................: 1243648
ProductName..............:
ProductVersionNumber.....: 1.4.4.94
EntryPoint...............: 0x130674
ObjectFileType...........: Executable application

Portable Executable structural information

Compilation timedatestamp.....: 1992-06-19 22:22:17
Target machine................: 0x14C (Intel 386 or later processors and compatible processors)
Entry point address...........: 0x00130674

PE Sections...................:

Name Virtual Address Virtual Size Raw Size Entropy MD5
CODE 4096 1243440 1243648 6.43 9a527ebab7463a59ecc962b9eb902b45
DATA 1249280 21876 22016 5.08 012a7d69edecad0eaed13de83c68f8b3
BSS 1273856 17853 0 0.00 d41d8cd98f00b204e9800998ecf8427e
.idata 1294336 12958 13312 5.00 348a319f99c88ab7becb884f84e21d19
.tls 1310720 44 0 0.00 d41d8cd98f00b204e9800998ecf8427e
.rdata 1314816 24 512 0.16 d0e787b079e05024a537051df4df35f9
.reloc 1318912 85812 86016 6.63 f43bf55d71fecd3cff5756c5188dc90e
.rsrc 1404928 917504 917504 6.22 a39666a8407b840297d5a1c613ff82c7

PE Imports....................:

[[mpr.dll]]
WNetGetConnectionA

[[wsock32.dll]]
WSAStartup, gethostbyname, inet_ntoa, gethostname, WSACleanup

[[version.dll]]
GetFileVersionInfoSizeA, GetFileVersionInfoA, VerQueryValueA

[[wininet.dll]]
InternetQueryOptionA

[[gdi32.dll]]
GetBrushOrgEx, GetDIBColorTable, DeleteEnhMetaFile, GetWindowOrgEx, PatBlt, GetClipBox, GetCurrentPositionEx, SaveDC, GdiFlush, GetTextMetricsA, MaskBlt, CreateBrushIndirect, SetStretchBltMode, GetEnhMetaFilePaletteEntries, GetPixel, GetDCOrgEx, Rectangle, BitBlt, GetObjectA, ExcludeClipRect, LineTo, DeleteDC, RestoreDC, SetBkMode, GetSystemPaletteEntries, SetPixel, CreateSolidBrush, DeleteObject, IntersectClipRect, CreateHalftonePalette, CreateDIBSection, CopyEnhMetaFileA, RealizePalette, SetTextColor, GetDeviceCaps, MoveToEx, SetEnhMetaFileBits, CreateBitmap, ExtTextOutW, RectVisible, CreatePalette, GetStockObject, CreateDIBitmap, SetViewportOrgEx, SelectPalette, ExtTextOutA, UnrealizeObject, GetDIBits, GetEnhMetaFileBits, SetBrushOrgEx, SelectClipRgn, PlayEnhMetaFile, StretchBlt, GetBitmapBits, CreateCompatibleDC, SetROP2, CreateFontIndirectA, SelectObject, GetTextExtentPoint32A, GetWinMetaFileBits, SetDIBColorTable, GetEnhMetaFileHeader, GetPaletteEntries, SetWindowOrgEx, Polyline, GetTextExtentPointA, SetBkColor, SetWinMetaFileBits, GetTextExtentPoint32W, CreateCompatibleBitmap, CreatePenIndirect

[[shell32.dll]]
SHGetPathFromIDListA, SHGetSpecialFolderLocation, SHGetMalloc, ShellExecuteA, DragQueryFileA

[[kernel32.dll]]
SetThreadLocale, GetStdHandle, FileTimeToDosDateTime, ReleaseMutex, CreateFileMappingA, GetFileAttributesA, WaitForSingleObject, CreateIoCompletionPort, GetDriveTypeA, GetLocalTime, DeleteCriticalSection, GetCurrentProcess, GetLocaleInfoA, LocalAlloc, ExpandEnvironmentStringsA, OpenFileMappingA, SetErrorMode, GetLogicalDrives, GetTempPathA, WideCharToMultiByte, InterlockedExchange, WriteFile, GetDiskFreeSpaceA, GetFullPathNameA, SetEvent, LocalFree, FormatMessageW, ResumeThread, InitializeCriticalSection, LoadResource, GlobalHandle, FindClose, TlsGetValue, FormatMessageA, GetFullPathNameW, GetStringTypeExA, SetLastError, DeviceIoControl, GetEnvironmentVariableA, GlobalFindAtomA, ExitProcess, GetModuleFileNameA, RaiseException, EnumCalendarInfoA, GetVolumeInformationA, LoadLibraryExA, GetPrivateProfileStringA, SetThreadPriority, UnhandledExceptionFilter, InterlockedDecrement, MultiByteToWideChar, FlushInstructionCache, CreateMutexA, GetModuleHandleA, CreateThread, GetExitCodeThread, GlobalAddAtomA, MulDiv, ExitThread, SetEnvironmentVariableA, VirtualQuery, VirtualQueryEx, SetEndOfFile, GetCurrentThreadId, InterlockedIncrement, SetCurrentDirectoryA, EnterCriticalSection, FreeLibrary, QueryPerformanceCounter, GetTickCount, VirtualProtect, GetVersionExA, LoadLibraryA, RtlUnwind, GetStartupInfoA, GetDateFormatA, GetFileSize, OpenProcess, CreateDirectoryA, DeleteFileA, GetCPInfo, GetProcAddress, CompareStringW, GlobalReAlloc, lstrcmpA, FindFirstFileA, lstrcpyA, ResetEvent, GetComputerNameA, FindNextFileA, GlobalLock, GetTimeZoneInformation, ReadDirectoryChangesW, CreateFileW, CreateEventA, CopyFileA, GetFileType, TlsSetValue, CreateFileA, LeaveCriticalSection, GetLastError, GlobalDeleteAtom, GetSystemInfo, lstrlenA, GlobalFree, GetThreadLocale, GlobalUnlock, GlobalAlloc, WinExec, GetQueuedCompletionStatus, FileTimeToLocalFileTime, SizeofResource, GetCurrentDirectoryW, WritePrivateProfileStringA, GetCurrentProcessId, LockResource, GetCurrentDirectoryA, GetCommandLineA, InterlockedCompareExchange, SuspendThread, QueryPerformanceFrequency, MapViewOfFile, SetFilePointer, ReadFile, CloseHandle, lstrcpynA, GetACP, GetVersion, FreeResource, UnmapViewOfFile, PostQueuedCompletionStatus, VirtualFree, Sleep, IsBadReadPtr, FindResourceA, VirtualAlloc, CompareStringA

[[oleaut32.dll]]
VariantChangeType, SafeArrayGetLBound, SafeArrayPtrOfIndex, SysAllocStringLen, VariantClear, GetActiveObject, SafeArrayCreate, SysReAllocStringLen, SafeArrayGetUBound, VariantCopy, GetErrorInfo, SysFreeString, VariantInit

[[netapi32.dll]]
NetWkstaGetInfo, NetUserEnum, NetApiBufferFree

[[advapi32.dll]]
RegFlushKey, RegCloseKey, GetUserNameA, RegQueryValueExA, RegSetValueExA, LogonUserA, RegEnumValueA, RegCreateKeyExA, RegOpenKeyExA, RegDeleteValueA, RegEnumKeyExA, RegQueryInfoKeyA

[[advapi32]]
CreateProcessWithLogonW

[[comctl32.dll]]
ImageList_BeginDrag, ImageList_SetBkColor, ImageList_Replace, InitCommonControls, ImageList_SetDragCursorImage, ImageList_Read, ImageList_GetDragImage, ImageList_Create, ImageList_DragMove, ImageList_DrawEx, ImageList_SetIconSize, ImageList_Write, ImageList_GetImageCount, ImageList_Destroy, ImageList_Draw, ImageList_GetIconSize, ImageList_DragLeave, ImageList_GetBkColor, ImageList_ReplaceIcon, ImageList_DragEnter, ImageList_Add, ImageList_DragShowNolock, ImageList_Remove, ImageList_EndDrag

[[ole32.dll]]
ProgIDFromCLSID, CLSIDFromProgID, CoInitialize, CoTaskMemAlloc, CoCreateInstance, StringFromCLSID, CoUninitialize, IsEqualGUID, CoTaskMemFree

[[user32.dll]]
RedrawWindow, GetMessagePos, DdeAccessData, DestroyWindow, EnableScrollBar, DestroyMenu, PostQuitMessage, GetForegroundWindow, LoadBitmapA, SetWindowPos, DdeDisconnect, DdeCreateStringHandleA, IsWindow, DispatchMessageA, EndPaint, SetMenuItemInfoA, CharUpperBuffA, WindowFromPoint, DrawIcon, VkKeyScanW, SetMenuItemInfoW, SetActiveWindow, GetMenuItemID, ChangeClipboardChain, GetCursorPos, ReleaseDC, DdeInitializeA, GetClassInfoA, SendMessageW, UnregisterClassA, IsDialogMessageW, GetWindowTextLengthA, SendMessageA, UnregisterClassW, GetClientRect, ToAscii, DrawTextW, DdeFreeStringHandle, SetScrollPos, CallNextHookEx, DdeFreeDataHandle, IsClipboardFormatAvailable, GetKeyboardState, ClientToScreen, GetTopWindow, ShowCursor, GetWindowTextW, EnumClipboardFormats, GetWindowTextLengthW, MsgWaitForMultipleObjects, ScrollWindow, GetWindowTextA, GetKeyState, DdeQueryStringA, PtInRect, DrawEdge, GetParent, UpdateWindow, SetPropA, DdeCmpStringHandles, EqualRect, EnumWindows, DefMDIChildProcA, DdeUninitialize, ShowWindow, SetClassLongA, GetPropA, GetDesktopWindow, DestroyIcon, TranslateMDISysAccel, EnableWindow, SetWindowPlacement, PeekMessageA, ChildWindowFromPoint, GetClipboardData, TranslateMessage, IsWindowEnabled, GetWindow, ActivateKeyboardLayout, RegisterClassW, InsertMenuItemA, CreatePopupMenu, GetIconInfo, LoadStringA, SetParent, SetClipboardData, GetSystemMetrics, IsZoomed, GetWindowPlacement, LoadStringW, DdeConnect, GetKeyboardLayoutList, DrawMenuBar, CharLowerA, IsIconic, RegisterClassA, GetMenuItemCount, GetWindowLongA, SetTimer, DdeClientTransaction, OemToCharA, DdeUnaccessData, GetActiveWindow, ShowOwnedPopups, FillRect, GetMenuItemInfoW, EnumThreadWindows, CharNextA, GetSysColorBrush, IsWindowUnicode, DdeNameService, CreateWindowExW, GetWindowLongW, GetMenuStringW, IsChild, IsDialogMessageA, SetFocus, MapVirtualKeyA, SetCapture, BeginPaint, OffsetRect, DefWindowProcW, GetScrollPos, KillTimer, MapVirtualKeyW, RegisterWindowMessageA, DefWindowProcA, DrawFocusRect, SetClipboardViewer, RegisterDeviceNotificationA, SetWindowLongW, SetScrollRange, GetWindowRect, InflateRect, PostMessageA, ReleaseCapture, GetScrollRange, SetWindowLongA, PostMessageW, GetKeyNameTextW, RemovePropA, SetWindowTextA, CheckMenuItem, GetSubMenu, GetLastActivePopup, DrawIconEx, SetWindowTextW, CreateWindowExA, DdeGetLastError, ScreenToClient, DdePostAdvise, InsertMenuA, LoadCursorA, LoadIconA, TrackPopupMenu, SetWindowsHookExA, GetMenuStringA, GetMenuState, SetWindowsHookExW, GetSystemMenu, GetDC, SetForegroundWindow, OpenClipboard, EmptyClipboard, DrawTextA, IntersectRect, GetScrollInfo, GetKeyboardLayout, CreateIcon, GetCapture, WaitMessage, FindWindowA, MessageBeep, RemoveMenu, GetWindowThreadProcessId, DdeCreateDataHandle, ShowScrollBar, GetMenu, DrawFrameControl, UnhookWindowsHookEx, RegisterClipboardFormatA, DdeSetUserHandle, CallWindowProcA, MessageBoxA, GetClassNameA, GetWindowDC, DestroyCursor, AdjustWindowRectEx, LoadKeyboardLayoutA, GetSysColor, SetScrollInfo, GetMenuItemInfoA, SystemParametersInfoA, EnableMenuItem, GetKeyNameTextA, IsWindowVisible, CharToOemA, GetDCEx, WinHelpA, DispatchMessageW, FrameRect, SetRect, DeleteMenu, InvalidateRect, DefFrameProcA, DdeQueryConvInfo, CallWindowProcW, GetClassNameW, CharLowerBuffA, GetClassInfoW, IsRectEmpty, GetCursor, GetFocus, CreateMenu, CloseClipboard, SetCursor, GetKeyboardType, SetMenu, MapWindowPoints

[[userenv]]
CreateEnvironmentBlock, DestroyEnvironmentBlock

PE Resources..................:

Resource type Number of resources
RT_STRING 35
RT_BITMAP 24
RT_RCDATA 8
RT_GROUP_CURSOR 7
RT_CURSOR 7
UNICODEDATA 6
RT_DIALOG 1
RT_ICON 1
RT_MANIFEST 1
RT_VERSION 1
RT_GROUP_ICON 1

Resource language Number of resources
NEUTRAL 82
FRENCH 6
CZECH DEFAULT 4

ClamAV PUA Engine
Possibly Unwanted Application. While not necessarily malicious, the scanned file presents certain characteristics which depending on the user policies and environment may or may not represent a threat. For full details see: http://www.clamav.net/support/faq/pua.
First seen by VirusTotal
2013-02-24 16:50:07 UTC ( 7 minut ago )
Last seen by VirusTotal
2013-02-24 16:50:07 UTC ( 7 minut ago )
File names (max. 25)

hwevid.exe

Nejsem si jistý,jestli to datum patchování sedí... Faktem zůstává,že ho raději oželím. Jaká je tvá rada? :cry:

Avatar uživatele
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8720
Registrován: 09 Pro 2006 06:19
Místo/Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Problém s odebráním USB flasch,zpomalený PC

#21 Příspěvek od cernohous13 »

Jednoznačná - pokud o něm zobrazuje Google minimum informací, z nichž jedna spojuje soubor s výrazem "Špion", tak při vykradení hesel nebo vyluxování bankovního účtu znáš pachatele :roll:
Stahni Avenger zde:
http://swandog46.geekstogo.com/avenger.exe
Spusť a všude souhlas „Yes“
Hlavní okno
Obrázek
dole dej fajfku do obou čtverečků

Do pole „Input script here“ zkopíruj zelený text scriptu -> „Execute“ -> „Yes“
Bude restart a je potřeba vyčkat na otevření Notepadu a jeho obsah sem vložit. (C:\avenger.txt)
Script

Kód: Vybrat vše

Folders to delete:
C:\hwevid
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Sagitt62
Návštěvník
Návštěvník
Příspěvky: 131
Registrován: 25 Kvě 2008 13:40

Re: Problém s odebráním USB flasch,zpomalený PC

#22 Příspěvek od Sagitt62 »

Mrcha bastardovitá! Ještě,že na kontě nic nemám... :P No tak jdu na to. Dám vědět. Zatím dík. S62

Sagitt62
Návštěvník
Návštěvník
Příspěvky: 131
Registrován: 25 Kvě 2008 13:40

Re: Problém s odebráním USB flasch,zpomalený PC

#23 Příspěvek od Sagitt62 »

Takže provedeno. Po restartu Avira začala hlásit virus a našla BAT/Delplug.A Skončil v karanténě. Ale nenašel jsem nikde ten pozn.blok s logem z Avengeru. Kde ho najdu? :o

Avatar uživatele
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8720
Registrován: 09 Pro 2006 06:19
Místo/Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Problém s odebráním USB flasch,zpomalený PC

#24 Příspěvek od cernohous13 »

Podle návodu zde C:\avenger.txt

Který soubor dala Avira do karantény?
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Sagitt62
Návštěvník
Návštěvník
Příspěvky: 131
Registrován: 25 Kvě 2008 13:40

Re: Problém s odebráním USB flasch,zpomalený PC

#25 Příspěvek od Sagitt62 »

Na disku C texťák avengeru není. Tu cestu jsem zkoušel 3x. Zkusit celý postup Avengerem znovu? :)
Tady je log z Aviry-jestli je k něčemu...


Avira Free Antivirus
Report file date: 24. února 2013 18:23


The program is running as an unrestricted full version.
Online services are available.

Licensee : Avira Free Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows 7 Home Premium
Windows version : (Service Pack 1) [6.1.7601]
Boot mode : Normally booted
Username : SYSTEM
Computer name : BARRY-PC

Version information:
BUILD.DAT : 13.0.0.3185 47702 Bytes 30.1.2013 10:13:00
AVSCAN.EXE : 13.6.0.584 640224 Bytes 6.2.2013 10:27:50
AVSCANRC.DLL : 13.4.0.360 54560 Bytes 29.11.2012 08:30:16
LUKE.DLL : 13.6.0.602 67808 Bytes 6.2.2013 10:28:06
AVSCPLR.DLL : 13.6.0.628 94432 Bytes 6.2.2013 03:15:07
AVREG.DLL : 13.6.0.600 250592 Bytes 6.2.2013 03:15:07
avlode.dll : 13.6.2.624 434912 Bytes 6.2.2013 03:15:07
avlode.rdf : 13.0.0.38 15231 Bytes 13.2.2013 09:24:57
VBASE000.VDF : 7.10.0.0 19875328 Bytes 6.11.2009 13:50:29
VBASE001.VDF : 7.11.0.0 13342208 Bytes 14.12.2010 13:50:31
VBASE002.VDF : 7.11.19.170 14374912 Bytes 20.12.2011 13:50:34
VBASE003.VDF : 7.11.21.238 4472832 Bytes 1.2.2012 13:50:36
VBASE004.VDF : 7.11.26.44 4329472 Bytes 28.3.2012 13:50:37
VBASE005.VDF : 7.11.34.116 4034048 Bytes 29.6.2012 13:42:40
VBASE006.VDF : 7.11.41.250 4902400 Bytes 6.9.2012 13:42:40
VBASE007.VDF : 7.11.50.230 3904512 Bytes 22.11.2012 12:43:11
VBASE008.VDF : 7.11.60.10 6627328 Bytes 7.2.2013 03:55:05
VBASE009.VDF : 7.11.60.11 2048 Bytes 7.2.2013 03:55:05
VBASE010.VDF : 7.11.60.12 2048 Bytes 7.2.2013 03:55:05
VBASE011.VDF : 7.11.60.13 2048 Bytes 7.2.2013 03:55:05
VBASE012.VDF : 7.11.60.14 2048 Bytes 7.2.2013 03:55:05
VBASE013.VDF : 7.11.60.62 351232 Bytes 8.2.2013 18:59:27
VBASE014.VDF : 7.11.60.115 190976 Bytes 9.2.2013 15:03:55
VBASE015.VDF : 7.11.60.177 282624 Bytes 11.2.2013 07:38:11
VBASE016.VDF : 7.11.60.249 215552 Bytes 13.2.2013 04:01:04
VBASE017.VDF : 7.11.61.65 151040 Bytes 15.2.2013 18:00:10
VBASE018.VDF : 7.11.61.135 159232 Bytes 18.2.2013 07:49:45
VBASE019.VDF : 7.11.61.163 152064 Bytes 18.2.2013 07:49:47
VBASE020.VDF : 7.11.61.207 164352 Bytes 19.2.2013 03:41:17
VBASE021.VDF : 7.11.62.43 206336 Bytes 21.2.2013 17:51:22
VBASE022.VDF : 7.11.62.111 136192 Bytes 23.2.2013 12:07:44
VBASE023.VDF : 7.11.62.112 2048 Bytes 23.2.2013 12:07:44
VBASE024.VDF : 7.11.62.113 2048 Bytes 23.2.2013 12:07:44
VBASE025.VDF : 7.11.62.114 2048 Bytes 23.2.2013 12:07:44
VBASE026.VDF : 7.11.62.115 2048 Bytes 23.2.2013 12:07:44
VBASE027.VDF : 7.11.62.116 2048 Bytes 23.2.2013 12:07:44
VBASE028.VDF : 7.11.62.117 2048 Bytes 23.2.2013 12:07:45
VBASE029.VDF : 7.11.62.118 2048 Bytes 23.2.2013 12:07:45
VBASE030.VDF : 7.11.62.119 2048 Bytes 23.2.2013 12:07:45
VBASE031.VDF : 7.11.62.142 75776 Bytes 24.2.2013 17:06:50
Engine version : 8.2.12.8
AEVDF.DLL : 8.1.2.10 102772 Bytes 19.9.2012 13:42:55
AESCRIPT.DLL : 8.1.4.94 467324 Bytes 22.2.2013 19:03:29
AESCN.DLL : 8.1.10.0 131445 Bytes 17.12.2012 04:57:39
AESBX.DLL : 8.2.5.12 606578 Bytes 28.8.2012 15:58:06
AERDL.DLL : 8.2.0.88 643444 Bytes 10.1.2013 15:43:57
AEPACK.DLL : 8.3.1.10 815480 Bytes 20.2.2013 03:41:19
AEOFFICE.DLL : 8.1.2.50 201084 Bytes 5.11.2012 14:00:38
AEHEUR.DLL : 8.1.4.218 5792121 Bytes 22.2.2013 19:03:28
AEHELP.DLL : 8.1.25.2 258423 Bytes 12.10.2012 14:52:32
AEGEN.DLL : 8.1.6.16 434549 Bytes 24.1.2013 15:16:01
AEEXP.DLL : 8.4.0.4 188789 Bytes 22.2.2013 19:03:29
AEEMU.DLL : 8.1.3.2 393587 Bytes 19.9.2012 13:42:55
AECORE.DLL : 8.1.31.2 201080 Bytes 20.2.2013 03:41:18
AEBB.DLL : 8.1.1.4 53619 Bytes 5.11.2012 14:00:38
AVWINLL.DLL : 13.6.0.480 26480 Bytes 6.2.2013 10:27:44
AVPREF.DLL : 13.6.0.480 51056 Bytes 6.2.2013 10:27:49
AVREP.DLL : 13.6.0.480 178544 Bytes 6.2.2013 03:15:07
AVARKT.DLL : 13.6.0.624 260832 Bytes 6.2.2013 10:27:45
AVEVTLOG.DLL : 13.6.0.600 167648 Bytes 6.2.2013 10:27:48
SQLITE3.DLL : 3.7.0.1 397088 Bytes 19.9.2012 17:17:40
AVSMTP.DLL : 13.6.0.480 62832 Bytes 6.2.2013 10:27:50
NETNT.DLL : 13.6.0.480 16240 Bytes 6.2.2013 10:28:06
RCIMAGE.DLL : 13.4.0.360 4782880 Bytes 28.11.2012 14:09:40
RCTEXT.DLL : 13.6.0.480 66928 Bytes 6.2.2013 10:27:44

Configuration settings for the scan:
Jobname.............................: AVGuardAsyncScan
Configuration file..................: C:\ProgramData\Avira\AntiVir Desktop\TEMP\AVGUARD_512a4c60\guard_slideup.avp
Reporting...........................: default
Primary action......................: Interactive
Secondary action....................: Quarantine
Scan master boot sector.............: on
Scan boot sector....................: off
Process scan........................: on
Scan registry.......................: off
Search for rootkits.................: off
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Limit recursion depth...............: 20
Smart extensions....................: on
Macrovirus heuristic................: on
File heuristic......................: Complete

Start of the scan: 24. února 2013 18:23

The scan of running processes will be started:
Scan process 'svchost.exe' - '57' Module(s) have been scanned
Scan process 'nvvsvc.exe' - '35' Module(s) have been scanned
Scan process 'nvSCPAPISvr.exe' - '34' Module(s) have been scanned
Scan process 'svchost.exe' - '40' Module(s) have been scanned
Scan process 'svchost.exe' - '58' Module(s) have been scanned
Scan process 'svchost.exe' - '83' Module(s) have been scanned
Scan process 'svchost.exe' - '137' Module(s) have been scanned
Scan process 'svchost.exe' - '28' Module(s) have been scanned
Scan process 'svchost.exe' - '60' Module(s) have been scanned
Scan process 'svchost.exe' - '71' Module(s) have been scanned
Scan process 'nvxdsync.exe' - '51' Module(s) have been scanned
Scan process 'nvvsvc.exe' - '47' Module(s) have been scanned
Scan process 'spoolsv.exe' - '86' Module(s) have been scanned
Scan process 'sched.exe' - '43' Module(s) have been scanned
Scan process 'svchost.exe' - '61' Module(s) have been scanned
Scan process 'armsvc.exe' - '28' Module(s) have been scanned
Scan process 'avguard.exe' - '80' Module(s) have been scanned
Scan process 'AsSysCtrlService.exe' - '21' Module(s) have been scanned
Scan process 'DVMExportService.exe' - '27' Module(s) have been scanned
Scan process 'HiSuiteOuc64.exe' - '23' Module(s) have been scanned
Scan process 'svchost.exe' - '50' Module(s) have been scanned
Scan process 'HuaweiHiSuiteService64.exe' - '21' Module(s) have been scanned
Scan process 'svchost.exe' - '21' Module(s) have been scanned
Scan process 'svchost.exe' - '21' Module(s) have been scanned
Scan process 'Updater.exe' - '35' Module(s) have been scanned
Scan process 'svchost.exe' - '35' Module(s) have been scanned
Scan process 'WLIDSVC.EXE' - '75' Module(s) have been scanned
Scan process 'WLIDSvcM.exe' - '17' Module(s) have been scanned
Scan process 'avshadow.exe' - '20' Module(s) have been scanned
Scan process 'svchost.exe' - '33' Module(s) have been scanned
Scan process 'svchost.exe' - '37' Module(s) have been scanned
Scan process 'taskhost.exe' - '52' Module(s) have been scanned
Scan process 'Dwm.exe' - '31' Module(s) have been scanned
Scan process 'taskeng.exe' - '28' Module(s) have been scanned
Scan process 'taskeng.exe' - '30' Module(s) have been scanned
Scan process 'Explorer.EXE' - '151' Module(s) have been scanned
Scan process 'UpdateChecker.exe' - '47' Module(s) have been scanned
Scan process 'FourEngine.exe' - '50' Module(s) have been scanned
Scan process 'LiveUpdateTip.exe' - '48' Module(s) have been scanned
Scan process 'PCSuite.exe' - '67' Module(s) have been scanned
Scan process 'HiSuite.exe' - '208' Module(s) have been scanned
Scan process 'hpqtra08.exe' - '85' Module(s) have been scanned
Scan process 'VDeck.exe' - '56' Module(s) have been scanned
Scan process 'QFanHelp.exe' - '36' Module(s) have been scanned
Scan process 'vicamon.exe' - '51' Module(s) have been scanned
Scan process 'avgnt.exe' - '80' Module(s) have been scanned
Scan process 'ServiceLayer.exe' - '39' Module(s) have been scanned
Scan process 'nvtray.exe' - '53' Module(s) have been scanned
Scan process 'NclUSBSrv64.exe' - '25' Module(s) have been scanned
Scan process 'hwevid.exe' - '61' Module(s) have been scanned
Scan process 'NclRSSrv.exe' - '22' Module(s) have been scanned
Scan process 'NclMSBTSrvEx.exe' - '38' Module(s) have been scanned
Scan process 'SearchIndexer.exe' - '49' Module(s) have been scanned
Scan process 'hpqSTE08.exe' - '65' Module(s) have been scanned
Scan process 'hpqbam08.exe' - '34' Module(s) have been scanned
Scan process 'hpqgpc01.exe' - '55' Module(s) have been scanned
Scan process 'hwtransport.exe' - '38' Module(s) have been scanned
Scan process 'wmiprvse.exe' - '52' Module(s) have been scanned
Scan process 'SearchProtocolHost.exe' - '37' Module(s) have been scanned
Scan process 'SearchFilterHost.exe' - '27' Module(s) have been scanned
Scan process 'wmiprvse.exe' - '92' Module(s) have been scanned
Scan process 'WmiApSrv.exe' - '32' Module(s) have been scanned
Scan process 'wmiprvse.exe' - '33' Module(s) have been scanned
Scan process 'avscan.exe' - '108' Module(s) have been scanned
Scan process 'smss.exe' - '2' Module(s) have been scanned
Scan process 'csrss.exe' - '16' Module(s) have been scanned
Scan process 'wininit.exe' - '26' Module(s) have been scanned
Scan process 'csrss.exe' - '18' Module(s) have been scanned
Scan process 'services.exe' - '33' Module(s) have been scanned
Scan process 'lsass.exe' - '63' Module(s) have been scanned
Scan process 'lsm.exe' - '16' Module(s) have been scanned
Scan process 'winlogon.exe' - '31' Module(s) have been scanned

Starting the file scan:

Begin scan in 'C:\cleanup.bat'
C:\cleanup.bat
[DETECTION] Contains recognition pattern of the BAT/Delplug.A batch virus

Beginning disinfection:
C:\cleanup.bat
[DETECTION] Contains recognition pattern of the BAT/Delplug.A batch virus
[NOTE] The file was moved to the quarantine directory under the name '5628ee17.qua'!


End of the scan: 24. února 2013 18:24
Used time: 00:07 Minute(s)

The scan has been done completely.

0 Scanned directories
870 Files were scanned
1 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 Files were deleted
0 Viruses and unwanted programs were repaired
1 Files were moved to quarantine
0 Files were renamed
0 Files cannot be scanned
869 Files not concerned
2 Archives were scanned
0 Warnings
1 Notes


The scan results will be transferred to the Guard.


Tady opis z karantény: file BAT/Delplug.A C:/cleanup.bat (source)

Avatar uživatele
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8720
Registrován: 09 Pro 2006 06:19
Místo/Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Problém s odebráním USB flasch,zpomalený PC

#26 Příspěvek od cernohous13 »

Dej aktuální RSIT
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Sagitt62
Návštěvník
Návštěvník
Příspěvky: 131
Registrován: 25 Kvě 2008 13:40

Re: Problém s odebráním USB flasch,zpomalený PC

#27 Příspěvek od Sagitt62 »

Tak tady je:

Logfile of random's system information tool 1.08 (written by random/random)
Run by Barry at 2013-02-24 19:17:21
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 35 GB (19%) free of 180 GB
Total RAM: 4087 MB (58% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:17:30, on 24.2.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16464)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe
C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files (x86)\HiSuite\HiSuite.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files (x86)\ASUS\AI Suite\QFan3\QFanHelp.exe
C:\Program Files (x86)\IM Magician\vicamon.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\hwevid\hwevid.exe
C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Users\Barry\AppData\Local\HiSuite\userdata\hwtools\hwtransport.exe
C:\Program Files\trend micro\Barry.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: QIPBHO Class - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Users\Barry\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll (file missing)
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: QIPBHO - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Users\Barry\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll (file missing)
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [QFan Help] "C:\Program Files (x86)\ASUS\AI Suite\QFan3\QFanHelp.exe"
O4 - HKLM\..\Run: [Cpu Level Up help] "C:\Program Files (x86)\ASUS\AI Suite\CpuLevelUpHelp.exe"
O4 - HKLM\..\Run: [IMMON] "C:\Program Files (x86)\IM Magician\Vicamon.exe"
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [hwevid] C:\hwevid\akt.exe hwevid
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [Mobile Partner] C:\Program Files (x86)\HiSuite\HiSuite.exe -s
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Zobrazit nebo skrýt HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://asia.msi.com.tw
O15 - Trusted Zone: http://global.msi.com.tw
O15 - Trusted Zone: http://www.rothwell.cz
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlcdnet.asus.com/pub/ASUS/misc/d ... .2.5.0.cab
O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/L ... nstall.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: c:\progra~3\browse~1\23796~1.11\{16cdf~1\browse~1.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: ASUS System Control Service (AsSysCtrlService) - ASUSTeK Computer Inc. - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe
O23 - Service: DeviceVM Meta Data Export Service (DvmMDES) - DeviceVM, Inc. - C:\ASUS.SYS\config\DVMExportService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HiSuiteOuc64.exe - Unknown owner - C:\ProgramData\HiSuiteOuc\HiSuiteOuc64.exe
O23 - Service: HuaweiHiSuiteService64.exe - Unknown owner - C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10830 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe"
"C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe"
"C:\ASUS.SYS\config\DVMExportService.exe"
"C:\ProgramData\HiSuiteOuc\HiSuiteOuc64.exe" -/service
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
"C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe" -/service
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 1968
"C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe" avshadowcontrol0_00000654
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
taskeng.exe {B97560F1-5193-48EB-BAEA-638BBC00292F}
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe" -b
"C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
"C:\Program Files (x86)\HiSuite\HiSuite.exe" -s
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe"
"C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" -r
"C:\Program Files (x86)\ASUS\AI Suite\QFan3\QFanHelp.exe"
"C:\Program Files (x86)\IM Magician\vicamon.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
"C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
{404AE620-D9C9-4EEC-AF7A-7D34B83514FA}
"C:\hwevid\hwevid.exe"
{B502964A-4141-4E4A-9E5C-424E05E993B2}
{D2436CC8-3D48-4F8C-8FBD-EF7CDBD2C27D}
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe" -CtxID "#Hewlett-Packard#HP Deskjet F4200 series#1305985133" -Startup
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe" -Embedding
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe" -Embedding
adb fork-server server
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Users\Barry\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-20 328248]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95289393-33EA-4F8D-B952-483415B9C955}]
QIPBHO Class - C:\Users\Barry\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-20 509496]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"PC Suite Tray"=C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe [2010-12-21 1483264]
"Mobile Partner"=C:\Program Files (x86)\HiSuite\HiSuite.exe [2012-12-24 557232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe -autorun []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [2008-07-22 150528]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
C:\PROGRA~2\HP\DIGITA~1\bin\hpqtra08.exe [2009-09-20 270336]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2010-05-24 2439072]
"QFan Help"=C:\Program Files (x86)\ASUS\AI Suite\QFan3\QFanHelp.exe [2010-04-19 611968]
"Cpu Level Up help"=C:\Program Files (x86)\ASUS\AI Suite\CpuLevelUpHelp.exe [2009-12-28 887936]
"IMMON"=C:\Program Files (x86)\IM Magician\Vicamon.exe [2009-05-07 143360]
"hpqSRMon"=C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [2008-07-22 150528]
"hwevid"=C:\hwevid\akt.exe [2012-10-06 824320]
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2013-02-06 385248]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2013-02-24 18:20:56 ----A---- C:\zip.exe
2013-02-24 18:20:56 ----A---- C:\Windows\SYSWOW64\drivers\ovsy.sys
2013-02-24 18:20:56 ----A---- C:\Program Files (x86)\uaux.txt
2013-02-24 18:20:56 ----A---- C:\cleanup.exe
2013-02-24 13:44:08 ----D---- C:\rsit
2013-02-24 13:44:08 ----D---- C:\Program Files\trend micro
2013-02-24 11:43:51 ----A---- C:\AdwCleaner[S2].txt
2013-02-24 11:43:18 ----A---- C:\AdwCleaner[S1].txt
2013-02-24 08:10:28 ----A---- C:\AdwCleaner[R2].txt
2013-02-24 06:43:01 ----A---- C:\AdwCleaner[R1].txt
2013-02-20 05:24:00 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-02-13 05:41:13 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2013-02-13 05:41:13 ----A---- C:\Windows\SYSWOW64\url.dll
2013-02-13 05:41:13 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2013-02-13 05:41:13 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2013-02-13 05:41:13 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-02-13 05:41:13 ----A---- C:\Windows\system32\url.dll
2013-02-13 05:41:13 ----A---- C:\Windows\system32\mshtmled.dll
2013-02-13 05:41:13 ----A---- C:\Windows\system32\ieUnatt.exe
2013-02-13 05:41:13 ----A---- C:\Windows\system32\ieui.dll
2013-02-13 05:41:12 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-02-13 05:41:12 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-02-13 05:41:12 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-02-13 05:41:12 ----A---- C:\Windows\system32\urlmon.dll
2013-02-13 05:41:12 ----A---- C:\Windows\system32\msfeeds.dll
2013-02-13 05:41:12 ----A---- C:\Windows\system32\jscript9.dll
2013-02-13 05:41:11 ----A---- C:\Windows\system32\wininet.dll
2013-02-13 05:41:10 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-02-13 05:41:10 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-02-13 05:41:10 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-02-13 05:41:10 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-02-13 05:41:10 ----A---- C:\Windows\system32\vbscript.dll
2013-02-13 05:41:10 ----A---- C:\Windows\system32\jsproxy.dll
2013-02-13 05:41:10 ----A---- C:\Windows\system32\jscript.dll
2013-02-13 05:41:10 ----A---- C:\Windows\system32\iertutil.dll
2013-02-13 05:41:09 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-02-13 05:41:08 ----A---- C:\Windows\system32\mshtml.dll
2013-02-13 05:41:07 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-02-13 05:41:07 ----A---- C:\Windows\system32\ieframe.dll
2013-02-13 05:02:07 ----A---- C:\Windows\system32\ntoskrnl.exe
2013-02-13 05:02:06 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2013-02-13 05:02:06 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2013-02-13 05:02:02 ----A---- C:\Windows\system32\win32k.sys
2013-02-13 05:01:59 ----A---- C:\Windows\SYSWOW64\wow32.dll
2013-02-13 05:01:59 ----A---- C:\Windows\SYSWOW64\setup16.exe
2013-02-13 05:01:59 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2013-02-13 05:01:59 ----A---- C:\Windows\SYSWOW64\instnm.exe
2013-02-13 05:01:59 ----A---- C:\Windows\system32\winsrv.dll
2013-02-13 05:01:58 ----A---- C:\Windows\SYSWOW64\user.exe
2013-02-13 05:01:57 ----A---- C:\Windows\system32\drivers\tcpip.sys
2013-02-13 05:01:57 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2013-01-25 20:41:45 ----D---- C:\ProgramData\HiSuiteOuc
2013-01-25 20:41:45 ----D---- C:\ProgramData\HandSetService
2013-01-25 20:41:00 ----A---- C:\Windows\system32\WdfCoInstaller01007.dll
2013-01-25 20:41:00 ----A---- C:\Windows\system32\drivers\WUDFUpdate_01007.dll
2013-01-25 20:41:00 ----A---- C:\Windows\system32\drivers\WinUSBCoInstaller.dll
2013-01-25 20:41:00 ----A---- C:\Windows\system32\drivers\WdfCoInstaller01007.dll
2013-01-25 20:41:00 ----A---- C:\Windows\system32\drivers\hw_usbdev.sys
2013-01-25 20:41:00 ----A---- C:\Windows\system32\drivers\hw_quusbnet.sys
2013-01-25 20:41:00 ----A---- C:\Windows\system32\drivers\hw_quusbmdm.sys
2013-01-25 20:40:54 ----A---- C:\Windows\system32\WinUSBCoInstaller.dll
2013-01-25 20:40:52 ----D---- C:\Program Files (x86)\HiSuite

======List of files/folders modified in the last 1 months======

2013-02-24 19:17:30 ----D---- C:\Windows\Temp
2013-02-24 19:13:47 ----D---- C:\Windows\Prefetch
2013-02-24 18:31:20 ----D---- C:\Windows\System32
2013-02-24 18:31:20 ----D---- C:\Windows\inf
2013-02-24 18:31:20 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-02-24 18:22:39 ----D---- C:\ProgramData\NVIDIA
2013-02-24 18:21:31 ----D---- C:\Windows\system32\config
2013-02-24 18:20:56 ----RD---- C:\Program Files (x86)
2013-02-24 18:20:56 ----D---- C:\Windows\SYSWOW64\drivers
2013-02-24 13:44:08 ----RD---- C:\Program Files
2013-02-24 13:40:38 ----SHD---- C:\System Volume Information
2013-02-24 06:15:41 ----SHD---- C:\Windows\Installer
2013-02-24 06:15:41 ----HD---- C:\Config.Msi
2013-02-22 23:12:13 ----D---- C:\Windows\system32\Tasks
2013-02-22 21:56:33 ----HD---- C:\ProgramData
2013-02-22 20:32:27 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-02-22 20:32:26 ----D---- C:\Windows\system32\drivers
2013-02-21 20:17:49 ----D---- C:\Windows\system32\DriverStore
2013-02-21 20:17:49 ----D---- C:\Windows\system32\catroot
2013-02-21 08:56:02 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2013-02-15 18:59:54 ----D---- C:\ProgramData\Adobe
2013-02-15 18:59:47 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-02-15 07:31:32 ----D---- C:\Windows\system32\catroot2
2013-02-13 09:33:09 ----RSD---- C:\Windows\assembly
2013-02-13 09:33:09 ----D---- C:\Windows\Microsoft.NET
2013-02-13 09:25:11 ----D---- C:\Windows\winsxs
2013-02-13 09:23:12 ----D---- C:\Windows\SysWOW64
2013-02-13 09:23:12 ----D---- C:\Windows\AppPatch
2013-02-13 09:23:11 ----D---- C:\Windows\SYSWOW64\migration
2013-02-13 09:23:11 ----D---- C:\Windows\system32\migration
2013-02-13 09:23:11 ----D---- C:\Program Files\Internet Explorer
2013-02-13 09:23:11 ----D---- C:\Program Files (x86)\Internet Explorer
2013-02-13 05:46:13 ----D---- C:\ProgramData\Microsoft Help
2013-02-13 05:44:30 ----A---- C:\Windows\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2009-08-04 13440]
R1 AsUpIO;AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [2009-07-06 13368]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2012-12-03 129216]
R1 avkmgr;avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [2012-11-16 27800]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2012-12-03 99912]
R2 npf;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2010-01-27 47632]
R3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 15416]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2010-11-12 155752]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2010-05-15 1327520]
S0 ydad;ydad; C:\Windows\system32\drivers\ovsy.sys []
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2009-07-14 145920]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\drivers\Dot4Prt.sys [2010-11-20 19968]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2009-07-14 43008]
S3 MSICDSetup;MSICDSetup; \??\E:\CDriver64.sys []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2008-08-28 25600]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 Ser2pl;Prolific Serial port WDF driver; C:\Windows\system32\DRIVERS\ser2pl64.sys [2012-07-30 158720]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 WinUsb;Android USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-12-18 65192]
R2 AntiVirService;Avira Real-Time Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2013-02-06 110816]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2013-02-06 86752]
R2 AsSysCtrlService;ASUS System Control Service; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2009-12-28 96896]
R2 DvmMDES;DeviceVM Meta Data Export Service; C:\ASUS.SYS\config\DVMExportService.exe [2009-10-16 319488]
R2 HiSuiteOuc64.exe;HiSuiteOuc64.exe; C:\ProgramData\HiSuiteOuc\HiSuiteOuc64.exe [2012-12-24 138416]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 HuaweiHiSuiteService64.exe;HuaweiHiSuiteService64.exe; C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe [2012-11-21 201608]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 NVSvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2012-10-02 891240]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 2292096]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2010-12-08 628736]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-03-31 136176]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-10-10 1258856]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-02-15 251248]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-03-31 136176]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-02-20 115608]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-03-14 1255736]

-----------------EOF-----------------

Sagitt62
Návštěvník
Návštěvník
Příspěvky: 131
Registrován: 25 Kvě 2008 13:40

Re: Problém s odebráním USB flasch,zpomalený PC

#28 Příspěvek od Sagitt62 »

Musím končit,pokračování zítra. Zatím dík a ahoj.

Avatar uživatele
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8720
Registrován: 09 Pro 2006 06:19
Místo/Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Problém s odebráním USB flasch,zpomalený PC

#29 Příspěvek od cernohous13 »

Sagitt62 napsal:Zkusit celý postup Avengerem znovu? :)
Avenger nezabral, zkus celý návod opakovat :(

Stačí zítra - to nevypustíme :wink:
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Sagitt62
Návštěvník
Návštěvník
Příspěvky: 131
Registrován: 25 Kvě 2008 13:40

Re: Problém s odebráním USB flasch,zpomalený PC

#30 Příspěvek od Sagitt62 »

Zdravím.
Tak jsem ten postup s Avengerem zkusik ještě 2x,i s vypnutou Avirou. Je to stejné: po restartu hlásí Avira detekci "BAT/Delplug.A". Je přesunut do karantény,ale při dalším projetí Avengerem se objeví znovu. V logu stále zůstává i soubor "C:\hwevid",který měl být vymazán. Blíží se přeinstalace? :cry:

Zamčeno