Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Problém s odebráním USB flasch,zpomalený PC

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Problém s odebráním USB flasch,zpomalený PC

#16 Příspěvek od cernohous13 »

je to nějaká podivná záležitost z 06/10/2012 - netušíš :???:
Klikni na https://www.virustotal.com
klik "Procházet" > po kliknutí na "Choose File" jen zkopíruj do řádku "Název souboru":

C:\hwevid\akt.exe

"Scan It" (pokud byl již testován, nech testovat znovu - Reanalyse)
Trpělivě vyčkej dokončení scanu dokud se neobjeví konečný výsledek např.0/41
Do fóra zkopíruj výsledný log. nebo odkaz z adresního řádku na stránku.
Pokud nebude nález stačí jen oznámit
totéž se souborem:
C:\hwevid\hwevid.exe
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Sagitt62
Návštěvník
Návštěvník
Příspěvky: 131
Registrován: 25 kvě 2008 13:40

Re: Problém s odebráním USB flasch,zpomalený PC

#17 Příspěvek od Sagitt62 »

Něco asi nalezeno bylo,klasický log ale nemůžu najít.6/10/2012 se dělal patch na Il-2 Sturmovik,aspoň si myslím. Co tohle:

SHA256: 3921f89573082513a2c6d4f90a472de788b951cb74616497b506e6a0116c526f
SHA1: ce58b90eaa69f55375eb08f0f07412917f7d3829
MD5: 642698fcb64faf5a5b6d9e91cc13b885
File size: 805.0 KB ( 824320 bytes )
File name: akt.exe
File type: Win32 EXE
Detection ratio: 11 / 46
Analysis date: 2013-02-24 16:37:51 UTC ( 0 minut ago )
0
0
Less details

Analysis
Comments
Votes
Additional information

ssdeep
24576:wpNByZvzHEkeRBrU74jUUq1X2g7OGjg6T3x:+ByZLkde7ezqdk6TB
TrID
Win32 Executable Borland Delphi 7 (69.6%)
Win32 Executable Borland Delphi 6 (27.3%)
Win32 Executable Delphi generic (1.5%)
Win32 Executable Generic (0.8%)
Win16/32 Executable Delphi generic (0.2%)
PEiD packer identifier
BobSoft Mini Delphi -> BoB / BobSoft
ExifTool

MIMEType.................: application/octet-stream
Subsystem................: Windows GUI
MachineType..............: Intel 386 or later, and compatibles
TimeStamp................: 1992:06:19 23:22:17+01:00
FileType.................: Win32 EXE
PEType...................: PE32
CodeSize.................: 649216
LinkerVersion............: 2.25
EntryPoint...............: 0x9f628
InitializedDataSize......: 174080
SubsystemVersion.........: 4.0
ImageVersion.............: 0.0
OSVersion................: 4.0
UninitializedDataSize....: 0

Portable Executable structural information

Compilation timedatestamp.....: 1992-06-19 22:22:17
Target machine................: 0x14C (Intel 386 or later processors and compatible processors)
Entry point address...........: 0x0009F628

PE Sections...................:

Name Virtual Address Virtual Size Raw Size Entropy MD5
CODE 4096 648872 649216 6.54 05b4db531d49d8ffb93b203d85e3fb1a
DATA 655360 8272 8704 5.00 4bc191c41885b4ec6fe1b4aec4ad1fa3
BSS 667648 4169 0 0.00 d41d8cd98f00b204e9800998ecf8427e
.idata 675840 10588 10752 4.87 75e5470b774611fbf57c1e8a838cfdfb
.tls 688128 36 0 0.00 d41d8cd98f00b204e9800998ecf8427e
.rdata 692224 24 512 0.18 bdf1aadf8f39805b91cbad6481f499ce
.reloc 696320 44956 45056 6.65 58233331fd615de88fd2de9a0fec7b71
.rsrc 741376 109056 109056 6.82 4a8a21932036e191ba45b9949d799270

PE Imports....................:

[[mpr.dll]]
WNetOpenEnumA, WNetGetUniversalNameA, WNetEnumResourceA, WNetCloseEnum

[[version.dll]]
GetFileVersionInfoSizeA, GetFileVersionInfoA, VerQueryValueA

[[gdi32.dll]]
GetBrushOrgEx, GetDIBColorTable, DeleteEnhMetaFile, GetWindowOrgEx, PatBlt, GetClipBox, GetCurrentPositionEx, SaveDC, CreateFontIndirectA, GetTextMetricsA, MaskBlt, CreateBrushIndirect, SetStretchBltMode, GetEnhMetaFilePaletteEntries, GetPixel, GetDCOrgEx, Rectangle, BitBlt, GetObjectA, ExcludeClipRect, LineTo, DeleteDC, RestoreDC, SetBkMode, GetSystemPaletteEntries, SetPixel, CreateSolidBrush, DeleteObject, IntersectClipRect, CreateHalftonePalette, CreateDIBSection, CopyEnhMetaFileA, RealizePalette, SetTextColor, GetDeviceCaps, MoveToEx, SetEnhMetaFileBits, CreateBitmap, RectVisible, CreatePalette, GetStockObject, CreateDIBitmap, SetViewportOrgEx, SelectPalette, ExtTextOutA, UnrealizeObject, GetDIBits, GetEnhMetaFileBits, SetBrushOrgEx, SelectClipRgn, PlayEnhMetaFile, StretchBlt, GetBitmapBits, CreateCompatibleDC, SetROP2, SelectObject, GetTextExtentPoint32A, GetWinMetaFileBits, SetDIBColorTable, GetEnhMetaFileHeader, GetPaletteEntries, SetWindowOrgEx, Polyline, GetTextExtentPointA, SetBkColor, SetWinMetaFileBits, GetTextExtentPoint32W, CreateCompatibleBitmap, CreatePenIndirect

[[advapi32.dll]]
RegOpenKeyExA, RegQueryValueExA, RegCloseKey

[[kernel32.dll]]
SetThreadLocale, GetStdHandle, FileTimeToDosDateTime, FileTimeToSystemTime, GetFileAttributesA, WaitForSingleObject, GetDriveTypeA, GetLocalTime, DeleteCriticalSection, GetLocaleInfoA, LocalAlloc, SetErrorMode, GetLogicalDrives, GetFileInformationByHandle, GetTempPathA, WideCharToMultiByte, InterlockedExchange, WriteFile, FormatMessageW, GetDiskFreeSpaceA, GetFullPathNameA, SetEvent, LocalFree, MoveFileA, InitializeCriticalSection, LoadResource, GlobalHandle, FindClose, TlsGetValue, FormatMessageA, GetFullPathNameW, GetStringTypeExA, SetLastError, GlobalFindAtomA, ExitProcess, GetModuleFileNameA, EnumCalendarInfoA, GetVolumeInformationA, LoadLibraryExA, UnhandledExceptionFilter, InterlockedDecrement, MultiByteToWideChar, GetModuleHandleA, CreateThread, GlobalAddAtomA, MulDiv, ExitThread, GlobalAlloc, LocalFileTimeToFileTime, SetEndOfFile, GetCurrentThreadId, InterlockedIncrement, SetCurrentDirectoryA, EnterCriticalSection, FreeLibrary, GetTickCount, VirtualProtect, GetVersionExA, LoadLibraryA, RtlUnwind, GetStartupInfoA, GetDateFormatA, GetFileSize, CreateDirectoryA, DeleteFileA, GetCPInfo, GetUserDefaultLCID, CompareStringW, GlobalReAlloc, lstrcmpA, FindFirstFileA, lstrcpyA, ResetEvent, GetTempFileNameA, FindNextFileA, GetProcAddress, CreateFileW, CreateEventA, CopyFileA, GetFileType, SetVolumeLabelA, TlsSetValue, CreateFileA, LeaveCriticalSection, GetLastError, DosDateTimeToFileTime, GlobalDeleteAtom, GetSystemInfo, lstrlenA, GlobalFree, GetThreadLocale, GlobalUnlock, VirtualQuery, RemoveDirectoryA, FileTimeToLocalFileTime, SizeofResource, CompareFileTime, GetCurrentProcessId, LockResource, SetFileTime, GetCurrentDirectoryA, GetCommandLineA, RaiseException, SetFilePointer, ReadFile, CloseHandle, lstrcpynA, GetACP, GlobalLock, GetVersion, FreeResource, VirtualFree, Sleep, FindResourceA, VirtualAlloc, CompareStringA

[[oleaut32.dll]]
VariantChangeType, SafeArrayGetLBound, SafeArrayPtrOfIndex, SysAllocStringLen, VariantClear, SafeArrayCreate, SysReAllocStringLen, SafeArrayGetUBound, VariantCopy, GetErrorInfo, SysFreeString, VariantInit

[[shell32.dll]]
ShellExecuteA, SHFileOperationA

[[ole32.dll]]
CoUninitialize, CoCreateInstance, CoInitialize, CoTaskMemAlloc

[[user32.dll]]
RedrawWindow, GetMessagePos, DestroyWindow, EnableScrollBar, DestroyMenu, PostQuitMessage, GetForegroundWindow, LoadBitmapA, SetWindowPos, IsWindow, DispatchMessageA, EndPaint, SetMenuItemInfoA, CharUpperBuffA, WindowFromPoint, DrawIcon, VkKeyScanW, SetMenuItemInfoW, SetActiveWindow, GetMenuItemID, GetCursorPos, ReleaseDC, GetClassInfoA, SendMessageW, UnregisterClassA, SendMessageA, UnregisterClassW, GetClientRect, DrawTextW, SetScrollPos, CallNextHookEx, GetKeyboardState, ClientToScreen, GetTopWindow, ShowCursor, GetWindowTextW, GetWindowTextLengthW, ScrollWindow, GetWindowTextA, GetKeyState, PtInRect, DrawEdge, GetParent, UpdateWindow, SetPropA, EqualRect, EnumWindows, DefMDIChildProcA, ShowWindow, SetClassLongA, GetPropA, GetDesktopWindow, DestroyIcon, TranslateMDISysAccel, EnableWindow, SetWindowPlacement, CharUpperW, PeekMessageA, ChildWindowFromPoint, GetClipboardData, TranslateMessage, IsWindowEnabled, GetWindow, ActivateKeyboardLayout, InsertMenuItemA, CreatePopupMenu, CharNextExA, GetIconInfo, LoadStringA, SetParent, RegisterClassW, CharLowerA, IsZoomed, GetWindowPlacement, LoadStringW, GetKeyboardLayoutList, DrawMenuBar, IsIconic, RegisterClassA, GetMenuItemCount, GetWindowLongA, SetTimer, OemToCharA, GetActiveWindow, IsDialogMessageW, FillRect, EnumThreadWindows, CharNextA, GetSysColorBrush, IsWindowUnicode, CreateWindowExW, GetWindowLongW, GetMenuItemInfoW, IsChild, IsDialogMessageA, SetFocus, MapVirtualKeyA, SetCapture, BeginPaint, OffsetRect, DefWindowProcW, GetScrollPos, KillTimer, MapVirtualKeyW, RegisterWindowMessageA, DefWindowProcA, DrawFocusRect, MapWindowPoints, GetSystemMetrics, SetWindowLongW, SetScrollRange, GetWindowRect, InflateRect, PostMessageA, ReleaseCapture, GetScrollRange, SetWindowLongA, PostMessageW, GetKeyNameTextW, RemovePropA, SetWindowTextA, CheckMenuItem, GetSubMenu, GetLastActivePopup, DrawIconEx, SetWindowTextW, CreateWindowExA, ScreenToClient, InsertMenuA, LoadCursorA, LoadIconA, TrackPopupMenu, SetWindowsHookExA, GetMenuStringA, CreateIconFromResource, GetMenuState, ShowOwnedPopups, GetSystemMenu, GetDC, SetForegroundWindow, GetMenuStringW, DrawTextA, IntersectRect, GetScrollInfo, GetKeyboardLayout, CreateIcon, GetCapture, WaitMessage, FindWindowA, MessageBeep, RemoveMenu, GetWindowThreadProcessId, ShowScrollBar, GetMenu, DrawFrameControl, UnhookWindowsHookEx, RegisterClipboardFormatA, CallWindowProcA, MessageBoxA, GetClassNameA, GetWindowDC, DestroyCursor, AdjustWindowRectEx, LoadKeyboardLayoutA, GetSysColor, SetScrollInfo, GetMenuItemInfoA, SystemParametersInfoA, EnableMenuItem, GetKeyNameTextA, IsWindowVisible, CharToOemA, GetDCEx, WinHelpA, DispatchMessageW, FrameRect, SetRect, DeleteMenu, InvalidateRect, DefFrameProcA, CallWindowProcW, GetClassNameW, CharLowerBuffA, GetClassInfoW, SetWindowsHookExW, IsRectEmpty, GetCursor, GetFocus, CreateMenu, GetKeyboardType, SetMenu, SetCursor

[[comctl32.dll]]
ImageList_BeginDrag, ImageList_SetBkColor, ImageList_Replace, InitCommonControls, ImageList_SetDragCursorImage, ImageList_Read, ImageList_GetDragImage, ImageList_Create, ImageList_DragMove, ImageList_DrawEx, ImageList_SetIconSize, ImageList_Write, ImageList_GetImageCount, ImageList_Destroy, ImageList_Draw, ImageList_GetIconSize, ImageList_DragLeave, ImageList_GetBkColor, ImageList_ReplaceIcon, ImageList_DragEnter, ImageList_Add, ImageList_DragShowNolock, ImageList_Remove, ImageList_EndDrag

PE Resources..................:

Resource type Number of resources
RT_STRING 30
RT_BITMAP 14
RT_GROUP_CURSOR 7
RT_CURSOR 7
RT_RCDATA 4
RT_DIALOG 1
RT_MANIFEST 1
RT_ICON 1
RT_GROUP_ICON 1

Resource language Number of resources
NEUTRAL 64
CZECH DEFAULT 2

First seen by VirusTotal
2013-01-26 16:23:14 UTC ( 4 týdny, 1 den ago )
Last seen by VirusTotal
2013-02-24 16:37:51 UTC ( 4 minuty ago )
File names (max. 25)

akt.exe
642698fcb64faf5a5b6d9e91cc13b885

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Problém s odebráním USB flasch,zpomalený PC

#18 Příspěvek od cernohous13 »

11/46 není moc dobré vysvědčení pro uvedený soubor :shock:

co s tím patchem provedeme? necháš si ho nebo ho smažu?
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Sagitt62
Návštěvník
Návštěvník
Příspěvky: 131
Registrován: 25 kvě 2008 13:40

Re: Problém s odebráním USB flasch,zpomalený PC

#19 Příspěvek od Sagitt62 »

Ještě čekám na proskenování to druhého souboru,už se to šrotuje 5 min.,moment.

Sagitt62
Návštěvník
Návštěvník
Příspěvky: 131
Registrován: 25 kvě 2008 13:40

Re: Problém s odebráním USB flasch,zpomalený PC

#20 Příspěvek od Sagitt62 »

Tady:
SHA256: 0b15b62aa24e3eecfba997353bd82f543b9e68961b526dcff97975896466302d
File name: hwevid.exe
Detection ratio: 3 / 45
Analysis date: 2013-02-24 16:50:07 UTC ( 5 minut ago )
0
0
More details

Analysis
Comments
Votes
Additional information

ssdeep
24576:fH0xs+4/RH52HCz9YNFid2FysjYKLKZy6m43a0PSoqJfitydRw7DlGb8V4/iT+7c:fREHCz9YNS2FvLSy6mM1c7dUm
TrID
Win32 Executable Borland Delphi 7 (58.2%)
Win32 Executable Borland Delphi 5 (39.2%)
Win32 Executable Delphi generic (1.2%)
Win32 Executable Generic (0.7%)
Win16/32 Executable Delphi generic (0.1%)
ExifTool

LegalTrademarks..........:
SubsystemVersion.........: 4.0
Comments.................:
InitializedDataSize......: 1039360
ImageVersion.............: 0.0
FileSubtype..............: 0
FileVersionNumber........: 1.4.4.94
LanguageCode.............: Czech
FileFlagsMask............: 0x003f
FileDescription..........:
CharacterSet.............: Windows, Latin2 (Eastern European)
LinkerVersion............: 2.25
FileOS...................: Win32
MIMEType.................: application/octet-stream
LegalCopyright...........:
FileVersion..............: 1.4.4.94
TimeStamp................: 1992:06:19 23:22:17+01:00
FileType.................: Win32 EXE
PEType...................: PE32
InternalName.............:
ProductVersion...........: 1.4.2
UninitializedDataSize....: 0
OSVersion................: 4.0
OriginalFilename.........:
Subsystem................: Windows GUI
MachineType..............: Intel 386 or later, and compatibles
CompanyName..............:
CodeSize.................: 1243648
ProductName..............:
ProductVersionNumber.....: 1.4.4.94
EntryPoint...............: 0x130674
ObjectFileType...........: Executable application

Portable Executable structural information

Compilation timedatestamp.....: 1992-06-19 22:22:17
Target machine................: 0x14C (Intel 386 or later processors and compatible processors)
Entry point address...........: 0x00130674

PE Sections...................:

Name Virtual Address Virtual Size Raw Size Entropy MD5
CODE 4096 1243440 1243648 6.43 9a527ebab7463a59ecc962b9eb902b45
DATA 1249280 21876 22016 5.08 012a7d69edecad0eaed13de83c68f8b3
BSS 1273856 17853 0 0.00 d41d8cd98f00b204e9800998ecf8427e
.idata 1294336 12958 13312 5.00 348a319f99c88ab7becb884f84e21d19
.tls 1310720 44 0 0.00 d41d8cd98f00b204e9800998ecf8427e
.rdata 1314816 24 512 0.16 d0e787b079e05024a537051df4df35f9
.reloc 1318912 85812 86016 6.63 f43bf55d71fecd3cff5756c5188dc90e
.rsrc 1404928 917504 917504 6.22 a39666a8407b840297d5a1c613ff82c7

PE Imports....................:

[[mpr.dll]]
WNetGetConnectionA

[[wsock32.dll]]
WSAStartup, gethostbyname, inet_ntoa, gethostname, WSACleanup

[[version.dll]]
GetFileVersionInfoSizeA, GetFileVersionInfoA, VerQueryValueA

[[wininet.dll]]
InternetQueryOptionA

[[gdi32.dll]]
GetBrushOrgEx, GetDIBColorTable, DeleteEnhMetaFile, GetWindowOrgEx, PatBlt, GetClipBox, GetCurrentPositionEx, SaveDC, GdiFlush, GetTextMetricsA, MaskBlt, CreateBrushIndirect, SetStretchBltMode, GetEnhMetaFilePaletteEntries, GetPixel, GetDCOrgEx, Rectangle, BitBlt, GetObjectA, ExcludeClipRect, LineTo, DeleteDC, RestoreDC, SetBkMode, GetSystemPaletteEntries, SetPixel, CreateSolidBrush, DeleteObject, IntersectClipRect, CreateHalftonePalette, CreateDIBSection, CopyEnhMetaFileA, RealizePalette, SetTextColor, GetDeviceCaps, MoveToEx, SetEnhMetaFileBits, CreateBitmap, ExtTextOutW, RectVisible, CreatePalette, GetStockObject, CreateDIBitmap, SetViewportOrgEx, SelectPalette, ExtTextOutA, UnrealizeObject, GetDIBits, GetEnhMetaFileBits, SetBrushOrgEx, SelectClipRgn, PlayEnhMetaFile, StretchBlt, GetBitmapBits, CreateCompatibleDC, SetROP2, CreateFontIndirectA, SelectObject, GetTextExtentPoint32A, GetWinMetaFileBits, SetDIBColorTable, GetEnhMetaFileHeader, GetPaletteEntries, SetWindowOrgEx, Polyline, GetTextExtentPointA, SetBkColor, SetWinMetaFileBits, GetTextExtentPoint32W, CreateCompatibleBitmap, CreatePenIndirect

[[shell32.dll]]
SHGetPathFromIDListA, SHGetSpecialFolderLocation, SHGetMalloc, ShellExecuteA, DragQueryFileA

[[kernel32.dll]]
SetThreadLocale, GetStdHandle, FileTimeToDosDateTime, ReleaseMutex, CreateFileMappingA, GetFileAttributesA, WaitForSingleObject, CreateIoCompletionPort, GetDriveTypeA, GetLocalTime, DeleteCriticalSection, GetCurrentProcess, GetLocaleInfoA, LocalAlloc, ExpandEnvironmentStringsA, OpenFileMappingA, SetErrorMode, GetLogicalDrives, GetTempPathA, WideCharToMultiByte, InterlockedExchange, WriteFile, GetDiskFreeSpaceA, GetFullPathNameA, SetEvent, LocalFree, FormatMessageW, ResumeThread, InitializeCriticalSection, LoadResource, GlobalHandle, FindClose, TlsGetValue, FormatMessageA, GetFullPathNameW, GetStringTypeExA, SetLastError, DeviceIoControl, GetEnvironmentVariableA, GlobalFindAtomA, ExitProcess, GetModuleFileNameA, RaiseException, EnumCalendarInfoA, GetVolumeInformationA, LoadLibraryExA, GetPrivateProfileStringA, SetThreadPriority, UnhandledExceptionFilter, InterlockedDecrement, MultiByteToWideChar, FlushInstructionCache, CreateMutexA, GetModuleHandleA, CreateThread, GetExitCodeThread, GlobalAddAtomA, MulDiv, ExitThread, SetEnvironmentVariableA, VirtualQuery, VirtualQueryEx, SetEndOfFile, GetCurrentThreadId, InterlockedIncrement, SetCurrentDirectoryA, EnterCriticalSection, FreeLibrary, QueryPerformanceCounter, GetTickCount, VirtualProtect, GetVersionExA, LoadLibraryA, RtlUnwind, GetStartupInfoA, GetDateFormatA, GetFileSize, OpenProcess, CreateDirectoryA, DeleteFileA, GetCPInfo, GetProcAddress, CompareStringW, GlobalReAlloc, lstrcmpA, FindFirstFileA, lstrcpyA, ResetEvent, GetComputerNameA, FindNextFileA, GlobalLock, GetTimeZoneInformation, ReadDirectoryChangesW, CreateFileW, CreateEventA, CopyFileA, GetFileType, TlsSetValue, CreateFileA, LeaveCriticalSection, GetLastError, GlobalDeleteAtom, GetSystemInfo, lstrlenA, GlobalFree, GetThreadLocale, GlobalUnlock, GlobalAlloc, WinExec, GetQueuedCompletionStatus, FileTimeToLocalFileTime, SizeofResource, GetCurrentDirectoryW, WritePrivateProfileStringA, GetCurrentProcessId, LockResource, GetCurrentDirectoryA, GetCommandLineA, InterlockedCompareExchange, SuspendThread, QueryPerformanceFrequency, MapViewOfFile, SetFilePointer, ReadFile, CloseHandle, lstrcpynA, GetACP, GetVersion, FreeResource, UnmapViewOfFile, PostQueuedCompletionStatus, VirtualFree, Sleep, IsBadReadPtr, FindResourceA, VirtualAlloc, CompareStringA

[[oleaut32.dll]]
VariantChangeType, SafeArrayGetLBound, SafeArrayPtrOfIndex, SysAllocStringLen, VariantClear, GetActiveObject, SafeArrayCreate, SysReAllocStringLen, SafeArrayGetUBound, VariantCopy, GetErrorInfo, SysFreeString, VariantInit

[[netapi32.dll]]
NetWkstaGetInfo, NetUserEnum, NetApiBufferFree

[[advapi32.dll]]
RegFlushKey, RegCloseKey, GetUserNameA, RegQueryValueExA, RegSetValueExA, LogonUserA, RegEnumValueA, RegCreateKeyExA, RegOpenKeyExA, RegDeleteValueA, RegEnumKeyExA, RegQueryInfoKeyA

[[advapi32]]
CreateProcessWithLogonW

[[comctl32.dll]]
ImageList_BeginDrag, ImageList_SetBkColor, ImageList_Replace, InitCommonControls, ImageList_SetDragCursorImage, ImageList_Read, ImageList_GetDragImage, ImageList_Create, ImageList_DragMove, ImageList_DrawEx, ImageList_SetIconSize, ImageList_Write, ImageList_GetImageCount, ImageList_Destroy, ImageList_Draw, ImageList_GetIconSize, ImageList_DragLeave, ImageList_GetBkColor, ImageList_ReplaceIcon, ImageList_DragEnter, ImageList_Add, ImageList_DragShowNolock, ImageList_Remove, ImageList_EndDrag

[[ole32.dll]]
ProgIDFromCLSID, CLSIDFromProgID, CoInitialize, CoTaskMemAlloc, CoCreateInstance, StringFromCLSID, CoUninitialize, IsEqualGUID, CoTaskMemFree

[[user32.dll]]
RedrawWindow, GetMessagePos, DdeAccessData, DestroyWindow, EnableScrollBar, DestroyMenu, PostQuitMessage, GetForegroundWindow, LoadBitmapA, SetWindowPos, DdeDisconnect, DdeCreateStringHandleA, IsWindow, DispatchMessageA, EndPaint, SetMenuItemInfoA, CharUpperBuffA, WindowFromPoint, DrawIcon, VkKeyScanW, SetMenuItemInfoW, SetActiveWindow, GetMenuItemID, ChangeClipboardChain, GetCursorPos, ReleaseDC, DdeInitializeA, GetClassInfoA, SendMessageW, UnregisterClassA, IsDialogMessageW, GetWindowTextLengthA, SendMessageA, UnregisterClassW, GetClientRect, ToAscii, DrawTextW, DdeFreeStringHandle, SetScrollPos, CallNextHookEx, DdeFreeDataHandle, IsClipboardFormatAvailable, GetKeyboardState, ClientToScreen, GetTopWindow, ShowCursor, GetWindowTextW, EnumClipboardFormats, GetWindowTextLengthW, MsgWaitForMultipleObjects, ScrollWindow, GetWindowTextA, GetKeyState, DdeQueryStringA, PtInRect, DrawEdge, GetParent, UpdateWindow, SetPropA, DdeCmpStringHandles, EqualRect, EnumWindows, DefMDIChildProcA, DdeUninitialize, ShowWindow, SetClassLongA, GetPropA, GetDesktopWindow, DestroyIcon, TranslateMDISysAccel, EnableWindow, SetWindowPlacement, PeekMessageA, ChildWindowFromPoint, GetClipboardData, TranslateMessage, IsWindowEnabled, GetWindow, ActivateKeyboardLayout, RegisterClassW, InsertMenuItemA, CreatePopupMenu, GetIconInfo, LoadStringA, SetParent, SetClipboardData, GetSystemMetrics, IsZoomed, GetWindowPlacement, LoadStringW, DdeConnect, GetKeyboardLayoutList, DrawMenuBar, CharLowerA, IsIconic, RegisterClassA, GetMenuItemCount, GetWindowLongA, SetTimer, DdeClientTransaction, OemToCharA, DdeUnaccessData, GetActiveWindow, ShowOwnedPopups, FillRect, GetMenuItemInfoW, EnumThreadWindows, CharNextA, GetSysColorBrush, IsWindowUnicode, DdeNameService, CreateWindowExW, GetWindowLongW, GetMenuStringW, IsChild, IsDialogMessageA, SetFocus, MapVirtualKeyA, SetCapture, BeginPaint, OffsetRect, DefWindowProcW, GetScrollPos, KillTimer, MapVirtualKeyW, RegisterWindowMessageA, DefWindowProcA, DrawFocusRect, SetClipboardViewer, RegisterDeviceNotificationA, SetWindowLongW, SetScrollRange, GetWindowRect, InflateRect, PostMessageA, ReleaseCapture, GetScrollRange, SetWindowLongA, PostMessageW, GetKeyNameTextW, RemovePropA, SetWindowTextA, CheckMenuItem, GetSubMenu, GetLastActivePopup, DrawIconEx, SetWindowTextW, CreateWindowExA, DdeGetLastError, ScreenToClient, DdePostAdvise, InsertMenuA, LoadCursorA, LoadIconA, TrackPopupMenu, SetWindowsHookExA, GetMenuStringA, GetMenuState, SetWindowsHookExW, GetSystemMenu, GetDC, SetForegroundWindow, OpenClipboard, EmptyClipboard, DrawTextA, IntersectRect, GetScrollInfo, GetKeyboardLayout, CreateIcon, GetCapture, WaitMessage, FindWindowA, MessageBeep, RemoveMenu, GetWindowThreadProcessId, DdeCreateDataHandle, ShowScrollBar, GetMenu, DrawFrameControl, UnhookWindowsHookEx, RegisterClipboardFormatA, DdeSetUserHandle, CallWindowProcA, MessageBoxA, GetClassNameA, GetWindowDC, DestroyCursor, AdjustWindowRectEx, LoadKeyboardLayoutA, GetSysColor, SetScrollInfo, GetMenuItemInfoA, SystemParametersInfoA, EnableMenuItem, GetKeyNameTextA, IsWindowVisible, CharToOemA, GetDCEx, WinHelpA, DispatchMessageW, FrameRect, SetRect, DeleteMenu, InvalidateRect, DefFrameProcA, DdeQueryConvInfo, CallWindowProcW, GetClassNameW, CharLowerBuffA, GetClassInfoW, IsRectEmpty, GetCursor, GetFocus, CreateMenu, CloseClipboard, SetCursor, GetKeyboardType, SetMenu, MapWindowPoints

[[userenv]]
CreateEnvironmentBlock, DestroyEnvironmentBlock

PE Resources..................:

Resource type Number of resources
RT_STRING 35
RT_BITMAP 24
RT_RCDATA 8
RT_GROUP_CURSOR 7
RT_CURSOR 7
UNICODEDATA 6
RT_DIALOG 1
RT_ICON 1
RT_MANIFEST 1
RT_VERSION 1
RT_GROUP_ICON 1

Resource language Number of resources
NEUTRAL 82
FRENCH 6
CZECH DEFAULT 4

ClamAV PUA Engine
Possibly Unwanted Application. While not necessarily malicious, the scanned file presents certain characteristics which depending on the user policies and environment may or may not represent a threat. For full details see: http://www.clamav.net/support/faq/pua.
First seen by VirusTotal
2013-02-24 16:50:07 UTC ( 7 minut ago )
Last seen by VirusTotal
2013-02-24 16:50:07 UTC ( 7 minut ago )
File names (max. 25)

hwevid.exe

Nejsem si jistý,jestli to datum patchování sedí... Faktem zůstává,že ho raději oželím. Jaká je tvá rada? :cry:

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Problém s odebráním USB flasch,zpomalený PC

#21 Příspěvek od cernohous13 »

Jednoznačná - pokud o něm zobrazuje Google minimum informací, z nichž jedna spojuje soubor s výrazem "Špion", tak při vykradení hesel nebo vyluxování bankovního účtu znáš pachatele :roll:
Stahni Avenger zde:
http://swandog46.geekstogo.com/avenger.exe
Spusť a všude souhlas „Yes“
Hlavní okno
Obrázek
dole dej fajfku do obou čtverečků

Do pole „Input script here“ zkopíruj zelený text scriptu -> „Execute“ -> „Yes“
Bude restart a je potřeba vyčkat na otevření Notepadu a jeho obsah sem vložit. (C:\avenger.txt)
Script

Kód: Vybrat vše

Folders to delete:
C:\hwevid
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Sagitt62
Návštěvník
Návštěvník
Příspěvky: 131
Registrován: 25 kvě 2008 13:40

Re: Problém s odebráním USB flasch,zpomalený PC

#22 Příspěvek od Sagitt62 »

Mrcha bastardovitá! Ještě,že na kontě nic nemám... :P No tak jdu na to. Dám vědět. Zatím dík. S62

Sagitt62
Návštěvník
Návštěvník
Příspěvky: 131
Registrován: 25 kvě 2008 13:40

Re: Problém s odebráním USB flasch,zpomalený PC

#23 Příspěvek od Sagitt62 »

Takže provedeno. Po restartu Avira začala hlásit virus a našla BAT/Delplug.A Skončil v karanténě. Ale nenašel jsem nikde ten pozn.blok s logem z Avengeru. Kde ho najdu? :o

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Problém s odebráním USB flasch,zpomalený PC

#24 Příspěvek od cernohous13 »

Podle návodu zde C:\avenger.txt

Který soubor dala Avira do karantény?
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Sagitt62
Návštěvník
Návštěvník
Příspěvky: 131
Registrován: 25 kvě 2008 13:40

Re: Problém s odebráním USB flasch,zpomalený PC

#25 Příspěvek od Sagitt62 »

Na disku C texťák avengeru není. Tu cestu jsem zkoušel 3x. Zkusit celý postup Avengerem znovu? :)
Tady je log z Aviry-jestli je k něčemu...


Avira Free Antivirus
Report file date: 24. února 2013 18:23


The program is running as an unrestricted full version.
Online services are available.

Licensee : Avira Free Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows 7 Home Premium
Windows version : (Service Pack 1) [6.1.7601]
Boot mode : Normally booted
Username : SYSTEM
Computer name : BARRY-PC

Version information:
BUILD.DAT : 13.0.0.3185 47702 Bytes 30.1.2013 10:13:00
AVSCAN.EXE : 13.6.0.584 640224 Bytes 6.2.2013 10:27:50
AVSCANRC.DLL : 13.4.0.360 54560 Bytes 29.11.2012 08:30:16
LUKE.DLL : 13.6.0.602 67808 Bytes 6.2.2013 10:28:06
AVSCPLR.DLL : 13.6.0.628 94432 Bytes 6.2.2013 03:15:07
AVREG.DLL : 13.6.0.600 250592 Bytes 6.2.2013 03:15:07
avlode.dll : 13.6.2.624 434912 Bytes 6.2.2013 03:15:07
avlode.rdf : 13.0.0.38 15231 Bytes 13.2.2013 09:24:57
VBASE000.VDF : 7.10.0.0 19875328 Bytes 6.11.2009 13:50:29
VBASE001.VDF : 7.11.0.0 13342208 Bytes 14.12.2010 13:50:31
VBASE002.VDF : 7.11.19.170 14374912 Bytes 20.12.2011 13:50:34
VBASE003.VDF : 7.11.21.238 4472832 Bytes 1.2.2012 13:50:36
VBASE004.VDF : 7.11.26.44 4329472 Bytes 28.3.2012 13:50:37
VBASE005.VDF : 7.11.34.116 4034048 Bytes 29.6.2012 13:42:40
VBASE006.VDF : 7.11.41.250 4902400 Bytes 6.9.2012 13:42:40
VBASE007.VDF : 7.11.50.230 3904512 Bytes 22.11.2012 12:43:11
VBASE008.VDF : 7.11.60.10 6627328 Bytes 7.2.2013 03:55:05
VBASE009.VDF : 7.11.60.11 2048 Bytes 7.2.2013 03:55:05
VBASE010.VDF : 7.11.60.12 2048 Bytes 7.2.2013 03:55:05
VBASE011.VDF : 7.11.60.13 2048 Bytes 7.2.2013 03:55:05
VBASE012.VDF : 7.11.60.14 2048 Bytes 7.2.2013 03:55:05
VBASE013.VDF : 7.11.60.62 351232 Bytes 8.2.2013 18:59:27
VBASE014.VDF : 7.11.60.115 190976 Bytes 9.2.2013 15:03:55
VBASE015.VDF : 7.11.60.177 282624 Bytes 11.2.2013 07:38:11
VBASE016.VDF : 7.11.60.249 215552 Bytes 13.2.2013 04:01:04
VBASE017.VDF : 7.11.61.65 151040 Bytes 15.2.2013 18:00:10
VBASE018.VDF : 7.11.61.135 159232 Bytes 18.2.2013 07:49:45
VBASE019.VDF : 7.11.61.163 152064 Bytes 18.2.2013 07:49:47
VBASE020.VDF : 7.11.61.207 164352 Bytes 19.2.2013 03:41:17
VBASE021.VDF : 7.11.62.43 206336 Bytes 21.2.2013 17:51:22
VBASE022.VDF : 7.11.62.111 136192 Bytes 23.2.2013 12:07:44
VBASE023.VDF : 7.11.62.112 2048 Bytes 23.2.2013 12:07:44
VBASE024.VDF : 7.11.62.113 2048 Bytes 23.2.2013 12:07:44
VBASE025.VDF : 7.11.62.114 2048 Bytes 23.2.2013 12:07:44
VBASE026.VDF : 7.11.62.115 2048 Bytes 23.2.2013 12:07:44
VBASE027.VDF : 7.11.62.116 2048 Bytes 23.2.2013 12:07:44
VBASE028.VDF : 7.11.62.117 2048 Bytes 23.2.2013 12:07:45
VBASE029.VDF : 7.11.62.118 2048 Bytes 23.2.2013 12:07:45
VBASE030.VDF : 7.11.62.119 2048 Bytes 23.2.2013 12:07:45
VBASE031.VDF : 7.11.62.142 75776 Bytes 24.2.2013 17:06:50
Engine version : 8.2.12.8
AEVDF.DLL : 8.1.2.10 102772 Bytes 19.9.2012 13:42:55
AESCRIPT.DLL : 8.1.4.94 467324 Bytes 22.2.2013 19:03:29
AESCN.DLL : 8.1.10.0 131445 Bytes 17.12.2012 04:57:39
AESBX.DLL : 8.2.5.12 606578 Bytes 28.8.2012 15:58:06
AERDL.DLL : 8.2.0.88 643444 Bytes 10.1.2013 15:43:57
AEPACK.DLL : 8.3.1.10 815480 Bytes 20.2.2013 03:41:19
AEOFFICE.DLL : 8.1.2.50 201084 Bytes 5.11.2012 14:00:38
AEHEUR.DLL : 8.1.4.218 5792121 Bytes 22.2.2013 19:03:28
AEHELP.DLL : 8.1.25.2 258423 Bytes 12.10.2012 14:52:32
AEGEN.DLL : 8.1.6.16 434549 Bytes 24.1.2013 15:16:01
AEEXP.DLL : 8.4.0.4 188789 Bytes 22.2.2013 19:03:29
AEEMU.DLL : 8.1.3.2 393587 Bytes 19.9.2012 13:42:55
AECORE.DLL : 8.1.31.2 201080 Bytes 20.2.2013 03:41:18
AEBB.DLL : 8.1.1.4 53619 Bytes 5.11.2012 14:00:38
AVWINLL.DLL : 13.6.0.480 26480 Bytes 6.2.2013 10:27:44
AVPREF.DLL : 13.6.0.480 51056 Bytes 6.2.2013 10:27:49
AVREP.DLL : 13.6.0.480 178544 Bytes 6.2.2013 03:15:07
AVARKT.DLL : 13.6.0.624 260832 Bytes 6.2.2013 10:27:45
AVEVTLOG.DLL : 13.6.0.600 167648 Bytes 6.2.2013 10:27:48
SQLITE3.DLL : 3.7.0.1 397088 Bytes 19.9.2012 17:17:40
AVSMTP.DLL : 13.6.0.480 62832 Bytes 6.2.2013 10:27:50
NETNT.DLL : 13.6.0.480 16240 Bytes 6.2.2013 10:28:06
RCIMAGE.DLL : 13.4.0.360 4782880 Bytes 28.11.2012 14:09:40
RCTEXT.DLL : 13.6.0.480 66928 Bytes 6.2.2013 10:27:44

Configuration settings for the scan:
Jobname.............................: AVGuardAsyncScan
Configuration file..................: C:\ProgramData\Avira\AntiVir Desktop\TEMP\AVGUARD_512a4c60\guard_slideup.avp
Reporting...........................: default
Primary action......................: Interactive
Secondary action....................: Quarantine
Scan master boot sector.............: on
Scan boot sector....................: off
Process scan........................: on
Scan registry.......................: off
Search for rootkits.................: off
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Limit recursion depth...............: 20
Smart extensions....................: on
Macrovirus heuristic................: on
File heuristic......................: Complete

Start of the scan: 24. února 2013 18:23

The scan of running processes will be started:
Scan process 'svchost.exe' - '57' Module(s) have been scanned
Scan process 'nvvsvc.exe' - '35' Module(s) have been scanned
Scan process 'nvSCPAPISvr.exe' - '34' Module(s) have been scanned
Scan process 'svchost.exe' - '40' Module(s) have been scanned
Scan process 'svchost.exe' - '58' Module(s) have been scanned
Scan process 'svchost.exe' - '83' Module(s) have been scanned
Scan process 'svchost.exe' - '137' Module(s) have been scanned
Scan process 'svchost.exe' - '28' Module(s) have been scanned
Scan process 'svchost.exe' - '60' Module(s) have been scanned
Scan process 'svchost.exe' - '71' Module(s) have been scanned
Scan process 'nvxdsync.exe' - '51' Module(s) have been scanned
Scan process 'nvvsvc.exe' - '47' Module(s) have been scanned
Scan process 'spoolsv.exe' - '86' Module(s) have been scanned
Scan process 'sched.exe' - '43' Module(s) have been scanned
Scan process 'svchost.exe' - '61' Module(s) have been scanned
Scan process 'armsvc.exe' - '28' Module(s) have been scanned
Scan process 'avguard.exe' - '80' Module(s) have been scanned
Scan process 'AsSysCtrlService.exe' - '21' Module(s) have been scanned
Scan process 'DVMExportService.exe' - '27' Module(s) have been scanned
Scan process 'HiSuiteOuc64.exe' - '23' Module(s) have been scanned
Scan process 'svchost.exe' - '50' Module(s) have been scanned
Scan process 'HuaweiHiSuiteService64.exe' - '21' Module(s) have been scanned
Scan process 'svchost.exe' - '21' Module(s) have been scanned
Scan process 'svchost.exe' - '21' Module(s) have been scanned
Scan process 'Updater.exe' - '35' Module(s) have been scanned
Scan process 'svchost.exe' - '35' Module(s) have been scanned
Scan process 'WLIDSVC.EXE' - '75' Module(s) have been scanned
Scan process 'WLIDSvcM.exe' - '17' Module(s) have been scanned
Scan process 'avshadow.exe' - '20' Module(s) have been scanned
Scan process 'svchost.exe' - '33' Module(s) have been scanned
Scan process 'svchost.exe' - '37' Module(s) have been scanned
Scan process 'taskhost.exe' - '52' Module(s) have been scanned
Scan process 'Dwm.exe' - '31' Module(s) have been scanned
Scan process 'taskeng.exe' - '28' Module(s) have been scanned
Scan process 'taskeng.exe' - '30' Module(s) have been scanned
Scan process 'Explorer.EXE' - '151' Module(s) have been scanned
Scan process 'UpdateChecker.exe' - '47' Module(s) have been scanned
Scan process 'FourEngine.exe' - '50' Module(s) have been scanned
Scan process 'LiveUpdateTip.exe' - '48' Module(s) have been scanned
Scan process 'PCSuite.exe' - '67' Module(s) have been scanned
Scan process 'HiSuite.exe' - '208' Module(s) have been scanned
Scan process 'hpqtra08.exe' - '85' Module(s) have been scanned
Scan process 'VDeck.exe' - '56' Module(s) have been scanned
Scan process 'QFanHelp.exe' - '36' Module(s) have been scanned
Scan process 'vicamon.exe' - '51' Module(s) have been scanned
Scan process 'avgnt.exe' - '80' Module(s) have been scanned
Scan process 'ServiceLayer.exe' - '39' Module(s) have been scanned
Scan process 'nvtray.exe' - '53' Module(s) have been scanned
Scan process 'NclUSBSrv64.exe' - '25' Module(s) have been scanned
Scan process 'hwevid.exe' - '61' Module(s) have been scanned
Scan process 'NclRSSrv.exe' - '22' Module(s) have been scanned
Scan process 'NclMSBTSrvEx.exe' - '38' Module(s) have been scanned
Scan process 'SearchIndexer.exe' - '49' Module(s) have been scanned
Scan process 'hpqSTE08.exe' - '65' Module(s) have been scanned
Scan process 'hpqbam08.exe' - '34' Module(s) have been scanned
Scan process 'hpqgpc01.exe' - '55' Module(s) have been scanned
Scan process 'hwtransport.exe' - '38' Module(s) have been scanned
Scan process 'wmiprvse.exe' - '52' Module(s) have been scanned
Scan process 'SearchProtocolHost.exe' - '37' Module(s) have been scanned
Scan process 'SearchFilterHost.exe' - '27' Module(s) have been scanned
Scan process 'wmiprvse.exe' - '92' Module(s) have been scanned
Scan process 'WmiApSrv.exe' - '32' Module(s) have been scanned
Scan process 'wmiprvse.exe' - '33' Module(s) have been scanned
Scan process 'avscan.exe' - '108' Module(s) have been scanned
Scan process 'smss.exe' - '2' Module(s) have been scanned
Scan process 'csrss.exe' - '16' Module(s) have been scanned
Scan process 'wininit.exe' - '26' Module(s) have been scanned
Scan process 'csrss.exe' - '18' Module(s) have been scanned
Scan process 'services.exe' - '33' Module(s) have been scanned
Scan process 'lsass.exe' - '63' Module(s) have been scanned
Scan process 'lsm.exe' - '16' Module(s) have been scanned
Scan process 'winlogon.exe' - '31' Module(s) have been scanned

Starting the file scan:

Begin scan in 'C:\cleanup.bat'
C:\cleanup.bat
[DETECTION] Contains recognition pattern of the BAT/Delplug.A batch virus

Beginning disinfection:
C:\cleanup.bat
[DETECTION] Contains recognition pattern of the BAT/Delplug.A batch virus
[NOTE] The file was moved to the quarantine directory under the name '5628ee17.qua'!


End of the scan: 24. února 2013 18:24
Used time: 00:07 Minute(s)

The scan has been done completely.

0 Scanned directories
870 Files were scanned
1 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 Files were deleted
0 Viruses and unwanted programs were repaired
1 Files were moved to quarantine
0 Files were renamed
0 Files cannot be scanned
869 Files not concerned
2 Archives were scanned
0 Warnings
1 Notes


The scan results will be transferred to the Guard.


Tady opis z karantény: file BAT/Delplug.A C:/cleanup.bat (source)

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Problém s odebráním USB flasch,zpomalený PC

#26 Příspěvek od cernohous13 »

Dej aktuální RSIT
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Sagitt62
Návštěvník
Návštěvník
Příspěvky: 131
Registrován: 25 kvě 2008 13:40

Re: Problém s odebráním USB flasch,zpomalený PC

#27 Příspěvek od Sagitt62 »

Tak tady je:

Logfile of random's system information tool 1.08 (written by random/random)
Run by Barry at 2013-02-24 19:17:21
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 35 GB (19%) free of 180 GB
Total RAM: 4087 MB (58% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:17:30, on 24.2.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16464)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe
C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files (x86)\HiSuite\HiSuite.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files (x86)\ASUS\AI Suite\QFan3\QFanHelp.exe
C:\Program Files (x86)\IM Magician\vicamon.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\hwevid\hwevid.exe
C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Users\Barry\AppData\Local\HiSuite\userdata\hwtools\hwtransport.exe
C:\Program Files\trend micro\Barry.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: QIPBHO Class - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Users\Barry\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll (file missing)
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: QIPBHO - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Users\Barry\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll (file missing)
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [QFan Help] "C:\Program Files (x86)\ASUS\AI Suite\QFan3\QFanHelp.exe"
O4 - HKLM\..\Run: [Cpu Level Up help] "C:\Program Files (x86)\ASUS\AI Suite\CpuLevelUpHelp.exe"
O4 - HKLM\..\Run: [IMMON] "C:\Program Files (x86)\IM Magician\Vicamon.exe"
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [hwevid] C:\hwevid\akt.exe hwevid
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [Mobile Partner] C:\Program Files (x86)\HiSuite\HiSuite.exe -s
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Zobrazit nebo skrýt HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://asia.msi.com.tw
O15 - Trusted Zone: http://global.msi.com.tw
O15 - Trusted Zone: http://www.rothwell.cz
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlcdnet.asus.com/pub/ASUS/misc/d ... .2.5.0.cab
O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/L ... nstall.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: c:\progra~3\browse~1\23796~1.11\{16cdf~1\browse~1.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: ASUS System Control Service (AsSysCtrlService) - ASUSTeK Computer Inc. - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe
O23 - Service: DeviceVM Meta Data Export Service (DvmMDES) - DeviceVM, Inc. - C:\ASUS.SYS\config\DVMExportService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HiSuiteOuc64.exe - Unknown owner - C:\ProgramData\HiSuiteOuc\HiSuiteOuc64.exe
O23 - Service: HuaweiHiSuiteService64.exe - Unknown owner - C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10830 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe"
"C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe"
"C:\ASUS.SYS\config\DVMExportService.exe"
"C:\ProgramData\HiSuiteOuc\HiSuiteOuc64.exe" -/service
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
"C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe" -/service
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 1968
"C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe" avshadowcontrol0_00000654
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
taskeng.exe {B97560F1-5193-48EB-BAEA-638BBC00292F}
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe" -b
"C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
"C:\Program Files (x86)\HiSuite\HiSuite.exe" -s
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe"
"C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" -r
"C:\Program Files (x86)\ASUS\AI Suite\QFan3\QFanHelp.exe"
"C:\Program Files (x86)\IM Magician\vicamon.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
"C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
{404AE620-D9C9-4EEC-AF7A-7D34B83514FA}
"C:\hwevid\hwevid.exe"
{B502964A-4141-4E4A-9E5C-424E05E993B2}
{D2436CC8-3D48-4F8C-8FBD-EF7CDBD2C27D}
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe" -CtxID "#Hewlett-Packard#HP Deskjet F4200 series#1305985133" -Startup
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe" -Embedding
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe" -Embedding
adb fork-server server
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Users\Barry\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-20 328248]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95289393-33EA-4F8D-B952-483415B9C955}]
QIPBHO Class - C:\Users\Barry\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-20 509496]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"PC Suite Tray"=C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe [2010-12-21 1483264]
"Mobile Partner"=C:\Program Files (x86)\HiSuite\HiSuite.exe [2012-12-24 557232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe -autorun []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [2008-07-22 150528]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
C:\PROGRA~2\HP\DIGITA~1\bin\hpqtra08.exe [2009-09-20 270336]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2010-05-24 2439072]
"QFan Help"=C:\Program Files (x86)\ASUS\AI Suite\QFan3\QFanHelp.exe [2010-04-19 611968]
"Cpu Level Up help"=C:\Program Files (x86)\ASUS\AI Suite\CpuLevelUpHelp.exe [2009-12-28 887936]
"IMMON"=C:\Program Files (x86)\IM Magician\Vicamon.exe [2009-05-07 143360]
"hpqSRMon"=C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [2008-07-22 150528]
"hwevid"=C:\hwevid\akt.exe [2012-10-06 824320]
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2013-02-06 385248]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2013-02-24 18:20:56 ----A---- C:\zip.exe
2013-02-24 18:20:56 ----A---- C:\Windows\SYSWOW64\drivers\ovsy.sys
2013-02-24 18:20:56 ----A---- C:\Program Files (x86)\uaux.txt
2013-02-24 18:20:56 ----A---- C:\cleanup.exe
2013-02-24 13:44:08 ----D---- C:\rsit
2013-02-24 13:44:08 ----D---- C:\Program Files\trend micro
2013-02-24 11:43:51 ----A---- C:\AdwCleaner[S2].txt
2013-02-24 11:43:18 ----A---- C:\AdwCleaner[S1].txt
2013-02-24 08:10:28 ----A---- C:\AdwCleaner[R2].txt
2013-02-24 06:43:01 ----A---- C:\AdwCleaner[R1].txt
2013-02-20 05:24:00 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-02-13 05:41:13 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2013-02-13 05:41:13 ----A---- C:\Windows\SYSWOW64\url.dll
2013-02-13 05:41:13 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2013-02-13 05:41:13 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2013-02-13 05:41:13 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-02-13 05:41:13 ----A---- C:\Windows\system32\url.dll
2013-02-13 05:41:13 ----A---- C:\Windows\system32\mshtmled.dll
2013-02-13 05:41:13 ----A---- C:\Windows\system32\ieUnatt.exe
2013-02-13 05:41:13 ----A---- C:\Windows\system32\ieui.dll
2013-02-13 05:41:12 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-02-13 05:41:12 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-02-13 05:41:12 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-02-13 05:41:12 ----A---- C:\Windows\system32\urlmon.dll
2013-02-13 05:41:12 ----A---- C:\Windows\system32\msfeeds.dll
2013-02-13 05:41:12 ----A---- C:\Windows\system32\jscript9.dll
2013-02-13 05:41:11 ----A---- C:\Windows\system32\wininet.dll
2013-02-13 05:41:10 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-02-13 05:41:10 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-02-13 05:41:10 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-02-13 05:41:10 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-02-13 05:41:10 ----A---- C:\Windows\system32\vbscript.dll
2013-02-13 05:41:10 ----A---- C:\Windows\system32\jsproxy.dll
2013-02-13 05:41:10 ----A---- C:\Windows\system32\jscript.dll
2013-02-13 05:41:10 ----A---- C:\Windows\system32\iertutil.dll
2013-02-13 05:41:09 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-02-13 05:41:08 ----A---- C:\Windows\system32\mshtml.dll
2013-02-13 05:41:07 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-02-13 05:41:07 ----A---- C:\Windows\system32\ieframe.dll
2013-02-13 05:02:07 ----A---- C:\Windows\system32\ntoskrnl.exe
2013-02-13 05:02:06 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2013-02-13 05:02:06 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2013-02-13 05:02:02 ----A---- C:\Windows\system32\win32k.sys
2013-02-13 05:01:59 ----A---- C:\Windows\SYSWOW64\wow32.dll
2013-02-13 05:01:59 ----A---- C:\Windows\SYSWOW64\setup16.exe
2013-02-13 05:01:59 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2013-02-13 05:01:59 ----A---- C:\Windows\SYSWOW64\instnm.exe
2013-02-13 05:01:59 ----A---- C:\Windows\system32\winsrv.dll
2013-02-13 05:01:58 ----A---- C:\Windows\SYSWOW64\user.exe
2013-02-13 05:01:57 ----A---- C:\Windows\system32\drivers\tcpip.sys
2013-02-13 05:01:57 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2013-01-25 20:41:45 ----D---- C:\ProgramData\HiSuiteOuc
2013-01-25 20:41:45 ----D---- C:\ProgramData\HandSetService
2013-01-25 20:41:00 ----A---- C:\Windows\system32\WdfCoInstaller01007.dll
2013-01-25 20:41:00 ----A---- C:\Windows\system32\drivers\WUDFUpdate_01007.dll
2013-01-25 20:41:00 ----A---- C:\Windows\system32\drivers\WinUSBCoInstaller.dll
2013-01-25 20:41:00 ----A---- C:\Windows\system32\drivers\WdfCoInstaller01007.dll
2013-01-25 20:41:00 ----A---- C:\Windows\system32\drivers\hw_usbdev.sys
2013-01-25 20:41:00 ----A---- C:\Windows\system32\drivers\hw_quusbnet.sys
2013-01-25 20:41:00 ----A---- C:\Windows\system32\drivers\hw_quusbmdm.sys
2013-01-25 20:40:54 ----A---- C:\Windows\system32\WinUSBCoInstaller.dll
2013-01-25 20:40:52 ----D---- C:\Program Files (x86)\HiSuite

======List of files/folders modified in the last 1 months======

2013-02-24 19:17:30 ----D---- C:\Windows\Temp
2013-02-24 19:13:47 ----D---- C:\Windows\Prefetch
2013-02-24 18:31:20 ----D---- C:\Windows\System32
2013-02-24 18:31:20 ----D---- C:\Windows\inf
2013-02-24 18:31:20 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-02-24 18:22:39 ----D---- C:\ProgramData\NVIDIA
2013-02-24 18:21:31 ----D---- C:\Windows\system32\config
2013-02-24 18:20:56 ----RD---- C:\Program Files (x86)
2013-02-24 18:20:56 ----D---- C:\Windows\SYSWOW64\drivers
2013-02-24 13:44:08 ----RD---- C:\Program Files
2013-02-24 13:40:38 ----SHD---- C:\System Volume Information
2013-02-24 06:15:41 ----SHD---- C:\Windows\Installer
2013-02-24 06:15:41 ----HD---- C:\Config.Msi
2013-02-22 23:12:13 ----D---- C:\Windows\system32\Tasks
2013-02-22 21:56:33 ----HD---- C:\ProgramData
2013-02-22 20:32:27 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-02-22 20:32:26 ----D---- C:\Windows\system32\drivers
2013-02-21 20:17:49 ----D---- C:\Windows\system32\DriverStore
2013-02-21 20:17:49 ----D---- C:\Windows\system32\catroot
2013-02-21 08:56:02 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2013-02-15 18:59:54 ----D---- C:\ProgramData\Adobe
2013-02-15 18:59:47 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-02-15 07:31:32 ----D---- C:\Windows\system32\catroot2
2013-02-13 09:33:09 ----RSD---- C:\Windows\assembly
2013-02-13 09:33:09 ----D---- C:\Windows\Microsoft.NET
2013-02-13 09:25:11 ----D---- C:\Windows\winsxs
2013-02-13 09:23:12 ----D---- C:\Windows\SysWOW64
2013-02-13 09:23:12 ----D---- C:\Windows\AppPatch
2013-02-13 09:23:11 ----D---- C:\Windows\SYSWOW64\migration
2013-02-13 09:23:11 ----D---- C:\Windows\system32\migration
2013-02-13 09:23:11 ----D---- C:\Program Files\Internet Explorer
2013-02-13 09:23:11 ----D---- C:\Program Files (x86)\Internet Explorer
2013-02-13 05:46:13 ----D---- C:\ProgramData\Microsoft Help
2013-02-13 05:44:30 ----A---- C:\Windows\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2009-08-04 13440]
R1 AsUpIO;AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [2009-07-06 13368]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2012-12-03 129216]
R1 avkmgr;avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [2012-11-16 27800]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2012-12-03 99912]
R2 npf;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2010-01-27 47632]
R3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 15416]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2010-11-12 155752]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2010-05-15 1327520]
S0 ydad;ydad; C:\Windows\system32\drivers\ovsy.sys []
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2009-07-14 145920]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\drivers\Dot4Prt.sys [2010-11-20 19968]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2009-07-14 43008]
S3 MSICDSetup;MSICDSetup; \??\E:\CDriver64.sys []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2008-08-28 25600]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 Ser2pl;Prolific Serial port WDF driver; C:\Windows\system32\DRIVERS\ser2pl64.sys [2012-07-30 158720]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 WinUsb;Android USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-12-18 65192]
R2 AntiVirService;Avira Real-Time Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2013-02-06 110816]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2013-02-06 86752]
R2 AsSysCtrlService;ASUS System Control Service; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2009-12-28 96896]
R2 DvmMDES;DeviceVM Meta Data Export Service; C:\ASUS.SYS\config\DVMExportService.exe [2009-10-16 319488]
R2 HiSuiteOuc64.exe;HiSuiteOuc64.exe; C:\ProgramData\HiSuiteOuc\HiSuiteOuc64.exe [2012-12-24 138416]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 HuaweiHiSuiteService64.exe;HuaweiHiSuiteService64.exe; C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe [2012-11-21 201608]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 NVSvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2012-10-02 891240]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 2292096]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2010-12-08 628736]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-03-31 136176]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-10-10 1258856]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-02-15 251248]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-03-31 136176]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-02-20 115608]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-03-14 1255736]

-----------------EOF-----------------

Sagitt62
Návštěvník
Návštěvník
Příspěvky: 131
Registrován: 25 kvě 2008 13:40

Re: Problém s odebráním USB flasch,zpomalený PC

#28 Příspěvek od Sagitt62 »

Musím končit,pokračování zítra. Zatím dík a ahoj.

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Problém s odebráním USB flasch,zpomalený PC

#29 Příspěvek od cernohous13 »

Sagitt62 píše:Zkusit celý postup Avengerem znovu? :)
Avenger nezabral, zkus celý návod opakovat :(

Stačí zítra - to nevypustíme :wink:
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Sagitt62
Návštěvník
Návštěvník
Příspěvky: 131
Registrován: 25 kvě 2008 13:40

Re: Problém s odebráním USB flasch,zpomalený PC

#30 Příspěvek od Sagitt62 »

Zdravím.
Tak jsem ten postup s Avengerem zkusik ještě 2x,i s vypnutou Avirou. Je to stejné: po restartu hlásí Avira detekci "BAT/Delplug.A". Je přesunut do karantény,ale při dalším projetí Avengerem se objeví znovu. V logu stále zůstává i soubor "C:\hwevid",který měl být vymazán. Blíží se přeinstalace? :cry:

Zamčeno