někde jsem na netu jsem do noťase nabral nějaké nedobroty. Nepsalo mi to háčky, čárky a noťas se choval nějak podezřele. Pojel jsem ho ComboFixem, CCleanerem, Avengerem, Spywarem terminatorem, většinu hnusu jsem odstranil, nicméně stále po nastartování bůku se nějak divně chová HDD. Stále chroupe, něco načítá. Pak chvíli nic, pak zase chroupe atd... pro jistotu sem házím UPM logfile a prosím o kontrolu.
Díky moc
Kód: Vybrat vše
Windows XP SP 3 (build 2600)
Boot Mode: Normal
Ověření souborů Microsoftu: Ano
Whitelist: Ano
Internet Explorer v8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Log vygenerován: 23.9.2010 16:37:47
================================================================
SmallARK
================================================================
[R]NtAssignProcessToJobObject -> C:\WINDOWS\system32\drivers\ehdrv.sys
[R]NtDebugActiveProcess -> C:\WINDOWS\system32\drivers\ehdrv.sys
[R]NtDuplicateObject -> C:\WINDOWS\system32\drivers\ehdrv.sys
[R]NtOpenProcess -> C:\WINDOWS\system32\drivers\ehdrv.sys
[R]NtOpenThread -> C:\WINDOWS\system32\drivers\ehdrv.sys
[R]NtProtectVirtualMemory -> C:\WINDOWS\system32\drivers\ehdrv.sys
[R]NtSetContextThread -> C:\WINDOWS\system32\drivers\ehdrv.sys
[R]NtSetInformationThread -> C:\WINDOWS\system32\drivers\ehdrv.sys
[R]NtSetSecurityObject -> C:\WINDOWS\system32\drivers\ehdrv.sys
[R]NtSuspendProcess -> C:\WINDOWS\system32\drivers\ehdrv.sys
[R]NtSuspendThread -> C:\WINDOWS\system32\drivers\ehdrv.sys
[R]NtTerminateProcess -> C:\WINDOWS\system32\drivers\ehdrv.sys
[R]NtTerminateThread -> C:\WINDOWS\system32\drivers\ehdrv.sys
[R]NtWriteVirtualMemory -> C:\WINDOWS\system32\drivers\ehdrv.sys
Běžící procesy
================================================================
C:\PROGRAM FILES\INTEL\WIFI\BIN\S24EVMON.EXE
|_ MD5: 0FCB7EEB0E81A777735A5AF185F56C2B
|_Výrobce: Intel(R) Corporation
C:\PROGRAM FILES\INTEL\WIFI\BIN\ZCFGSVC.EXE
|_ MD5: 4F5562F8C92EEDA83761244AC3655ADA
|_Výrobce: Intel(R) Corporation
C:\PROGRAM FILES\TOSHIBA\BLUETOOTH TOSHIBA STACK\ITSECMNG.EXE
|_ MD5: F7D6537B64A5527C1E7F5A70526F1B54
|_Výrobce: TOSHIBA CORPORATION
C:\PROGRAM FILES\DELLTPAD\APOINT.EXE
|_ MD5: 5EF24621ABCE6965E32A365CA613A544
|_Výrobce: Alps Electric Co., Ltd.
C:\PROGRAM FILES\SYNCROSOFT\POS\H2O\CLEDX.EXE
|_ MD5: A71EA5CB05DE4AEF2E9AEC97B7E00ED7
|_Výrobce: Team H2O
C:\PROGRAM FILES\SIGMATEL\C-MAJOR AUDIO\WDM\STSYSTRA.EXE
|_ MD5: 012844A8E13BE3941C9CAF1F91F47DF2
|_Výrobce: SigmaTel, Inc.
C:\WINDOWS\SYSTEM32\STACSV.EXE
|_ MD5: 6F855B5625A47F3AC731A262FDC379A6
|_Výrobce: SigmaTel, Inc.
C:\PROGRAM FILES\COMMON FILES\AHEAD\LIB\NMBGMONITOR.EXE
|_ MD5: 15A1A88D97D440C735058CCF3F74A6EE
|_Výrobce: Nero AG
C:\PROGRAM FILES\TOSHIBA\BLUETOOTH TOSHIBA STACK\TOSBTMNG.EXE
|_ MD5: E7540F17691410CC5DD673E212CC83B7
|_Výrobce: TOSHIBA CORPORATION.
C:\PROGRAM FILES\DELLTPAD\APNTEX.EXE
|_ MD5: 8D78BE3690DB07A2FD03D2A6B61E3DCD
|_Výrobce: Alps Electric Co., Ltd.
C:\PROGRAM FILES\DELLTPAD\HIDFIND.EXE
|_ MD5: C574C551637734B13278898FE2D12D15
|_Výrobce: Alps Electric Co., Ltd.
C:\PROGRAM FILES\TOSHIBA\BLUETOOTH TOSHIBA STACK\TOSA2DP.EXE
|_ MD5: 101495E2863382E534EFC0C5D6251B0F
|_Výrobce: TOSHIBA CORPORATION.
C:\PROGRAM FILES\TOSHIBA\BLUETOOTH TOSHIBA STACK\TOSBTHID.EXE
|_ MD5: 2C92B17E820094F37037B6CE114BEB69
|_Výrobce: TOSHIBA CORPORATION.
C:\PROGRAM FILES\TOSHIBA\BLUETOOTH TOSHIBA STACK\TOSBTHSP.EXE
|_ MD5: 8C35DB52F07A78E8DF230D76F141FD29
|_Výrobce: TOSHIBA CORPORATION.
C:\PROGRAM FILES\TOSHIBA\BLUETOOTH TOSHIBA STACK\TOSAVRC.EXE
|_ MD5: 93FA8AD0F0B1466C80D38DE3361B0EA2
|_Výrobce: TOSHIBA CORPORATION.
C:\PROGRAM FILES\TOSHIBA\BLUETOOTH TOSHIBA STACK\TOSOBEX.EXE
|_ MD5: 33A70D93626303792B8CC1B6136814C6
|_Výrobce: TOSHIBA CORPORATION.
C:\PROGRAM FILES\ALCOHOL SOFT\ALCOHOL 120\STARWIND\STARWINDSERVICE.EXE
|_ MD5: AB2B9349ADA4AC5EC74B622B8303FE23
|_Výrobce: Rocket Division Software
C:\PROGRAM FILES\INTEL\WIFI\BIN\WLKEEPER.EXE
|_ MD5: C9B9942EECA0B82E35D60627E365510A
|_Výrobce: Intel(R) Corporation
C:\PROGRAM FILES\TOSHIBA\BLUETOOTH TOSHIBA STACK\TOSBTPROC.EXE
|_ MD5: 0473335B3071C6B831EF966300956A46
|_Výrobce: TOSHIBA CORPORATION.
C:\DOCUMENTS AND SETTINGS\PAAX\DOKUMENTY\STA~ENÉ SOUBORY\SPYWARETERMINATOR.EXE
C:\DOCUME~1\PAAX\LOCALS~1\TEMP\IS-TFMMU.TMP\SPYWARETERMINATOR.TMP
|_ MD5: 072D4FB6E256487DC05F750BCBAC16D9
|_Výrobce:
C:\PROGRAM FILES\COMMON FILES\AHEAD\LIB\NMINDEXSTORESVR.EXE
|_ MD5: E61DA2531099C26C79426D4305A12934
|_Výrobce: Nero AG
Scanner
================================================================
[?] S24EvMon.exe
Soubor 7%
[S] explorer.exe
Spouští se po startu HKLM Winlogon [Shell]
[R] hkcmd.exe
Spouští se po startu HKLM Run [HotKeysCmds]
[R] igfxpers.exe
Spouští se po startu HKLM Run [Persistence]
[?] ZCfgSvc.exe
Spouští se po startu HKLM Run [IntelZeroConfig]
Soubor 7%
[R] iFrmewrk.exe
Spouští se po startu HKLM Run [IntelWireless]
[?] ItSecMng.exe
Spouští se po startu HKLM Run [ITSecMng]
Soubor 7%
[?] Apoint.exe
Spouští se po startu HKLM Run [Apoint]
[?] cledx.exe
Spouští se po startu HKLM Run [H2O]
EntryPoint v sekci:
|_ Celkový počet sekcí: 5
Soubor 70%
[R] egui.exe
Spouští se po startu HKLM Run [egui]
[?] stsystra.exe
Spouští se po startu HKLM Run [SigmatelSysTrayApp]
[?] stacsv.exe
Non Microsoft v System32:
Nemá okno
[?] NMBgMonitor.exe
Spouští se po startu HKCU Run [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
Soubor 7%
[?] TosBtMng.exe
Spouští se po startu Po spuštění []
Soubor 14%
[?] TosA2dp.exe
Soubor 7%
[?] TosBtHid.exe
Soubor 7%
[?] TosBtHSP.exe
Soubor 7%
[?] TosAVRC.exe
Soubor 7%
[?] TosOBEX.exe
Soubor 7%
[?] StarWindService.exe
Nemá okno
Soubor 7%
[?] WLKEEPER.exe
Soubor 7%
[?] TosBtProc.exe
Soubor 14%
[?] SpywareTerminator.exe
Bez výrobce
EntryPoint v sekci: CODE
|_ Celkový počet sekcí: 8
Skrytá cesta EXE: C:\Documents and Settings\PaaX\Dokumenty\Stažené soubory\SpywareTerminator.exe
[?] SpywareTerminator.tmp
Bez výrobce
EntryPoint v sekci: CODE
|_ Celkový počet sekcí: 8
Soubor 100%
[?] NMIndexStoreSvr.exe
Proces se nepodařilo otevřít
ROOTKIT? Skrytá cesta
Spouští se po startu HKCU Run [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
Nelze otevřít
Nemá okno
Po spuštění
================================================================
HKCU Run
|_ [?][BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
|_ MD5: 15A1A88D97D440C735058CCF3F74A6EE
|_ Výrobce: Nero AG
HKLM Run
|_ [?][IntelZeroConfig] C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe
| |_ MD5: 4F5562F8C92EEDA83761244AC3655ADA
| |_ Výrobce: Intel(R) Corporation
|
|_ [R][IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe /tf Intel Wireless Tray
| |_ MD5: D21B30A0A07EBB5AD6D5750735D90555
| |_ Výrobce: Intel(R) Corporation
|
|_ [?][ITSecMng] C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
| |_ MD5: F7D6537B64A5527C1E7F5A70526F1B54
| |_ Výrobce: TOSHIBA CORPORATION
|
|_ [?][Apoint] C:\Program Files\DellTPad\Apoint.exe
| |_ MD5: 5EF24621ABCE6965E32A365CA613A544
| |_ Výrobce: Alps Electric Co., Ltd.
|
|_ [!][H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
| |_ MD5: A71EA5CB05DE4AEF2E9AEC97B7E00ED7
| |_ Výrobce: Team H2O
|
|_ [R][egui] C:\Program Files\ESET\ESET Smart Security\egui.exe /hide /waitservice
| |_ MD5: A404A9C9DBF60073424FA62AD71B129F
| |_ Výrobce: ESET
|
|_ [?][SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
|_ MD5: 012844A8E13BE3941C9CAF1F91F47DF2
|_ Výrobce: SigmaTel, Inc.
HKU Run
|_ [S][BrowserChoice] C:\WINDOWS\system32\browserchoice.exe /run
|_ MD5: DA1919D896DBD5895E138932AE9E398B
|_ Výrobce: Microsoft Corporation
HKLM IC
|_ [X][>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP (Soubor nenalezen)
|_ [X][{1569B4BB-7658-00B8-0104-060607070104}] C:\WINDOWS\MICR0S0FT.exe
| |_ MD5: 243818B7C5FDDF986434033705B30FB0
| |_ Výrobce:
|
|_ [?][{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] C:\WINDOWS\INF\msnetmtg.inf ,NetMtg.Install.PerUser.NT
| |_ MD5: F8995D4274D3D7E32BE7812B872BCC13
| |_ Výrobce:
|
|_ [?][{5945c046-1e7d-11d1-bc44-00c04fd912be}] C:\WINDOWS\INF\msmsgs.inf ,BLC.QuietInstall.PerUser
| |_ MD5: 97BF5E6CB8D2498286096D35644517C5
| |_ Výrobce:
|
|_ [?][{6BF52A52-394A-11d3-B153-00C04F79FAA6}] C:\WINDOWS\INF\wmp.inf ,PerUserStub
| |_ MD5: FC5AAC8633F4F1522772177B965F2DC8
| |_ Výrobce:
|
|_ [?][{89820200-ECBD-11cf-8B85-00AA005B4340}] regsvr32.exe /s /n /i:U shell32.dll
|_ MD5:
|_ Výrobce: Microsoft Corporation
HKLM Winlogon Notify
|_ [?][igfxcui] C:\WINDOWS\system32\igfxdev.dll
|_ MD5: 777FD3CAE17D3531A897224F5EDC524F
|_ Výrobce: Intel Corporation
Po spuštění
|_ C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
|_ MD5: E7540F17691410CC5DD673E212CC83B7
|_ Výrobce: TOSHIBA CORPORATION.
Služby (Zobraz běžící: True, Zobraz zastavené: False, Zobraz i bezpečné služby: False)
================================================================
[?] Intel(R) PROSet/Wireless WiFi Service
|_ Cesta: C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
| |_ Výrobce: Intel(R) Corporation
| |_ Popis: Intel(R) Wireless Management Service
| |_ MD5: 0FCB7EEB0E81A777735A5AF185F56C2B
|
|_ Jméno: S24EventMonitor
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ:
|_ Dependency: s24trans
[?] SigmaTel Audio Service
|_ Cesta: C:\WINDOWS\system32\StacSV.exe
| |_ Výrobce: SigmaTel, Inc.
| |_ Popis: STacSV Module
| |_ MD5: 6F855B5625A47F3AC731A262FDC379A6
|
|_ Jméno: STacSV
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Own Process
|_ Dependency:
[?] StarWind iSCSI Service
|_ Cesta: C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
| |_ Výrobce: Rocket Division Software
| |_ Popis: StarWind iSCSI Target (Alcohol Edition)
| |_ MD5: AB2B9349ADA4AC5EC74B622B8303FE23
|
|_ Jméno: StarWindService
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Own Process
|_ Dependency:
[?] Intel(R) PROSet/Wireless SSO Service
|_ Cesta: C:\Program Files\Intel\WiFi\bin\WLKeeper.exe
| |_ Výrobce: Intel(R) Corporation
| |_ Popis: Intel(R) WLANKeeper SSO Service
| |_ MD5: C9B9942EECA0B82E35D60627E365510A
|
|_ Jméno: WLANKEEPER
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ:
|_ Dependency: S24EventMonitor
Ovladače (Zobraz běžící: True, Zobraz zastavené: False, Zobraz i bezpečné služby: False)
================================================================
[?] Alps Touch Pad Filter Driver for Windows 2000/XP/Vista
|_ Cesta: C:\WINDOWS\system32\DRIVERS\Apfiltr.sys
| |_ Výrobce: Alps Electric Co., Ltd.
| |_ Popis: Alps Touch Pad Driver
| |_ MD5: 350F19EB5FE4EC37A2414DF56CDE1AA8
|
|_ Jméno: ApfiltrService
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Broadcom NetXtreme Gigabit Ethernet
|_ Cesta: C:\WINDOWS\system32\DRIVERS\b57xp32.sys
| |_ Výrobce: Broadcom Corporation
| |_ Popis: Broadcom NetXtreme Gigabit Ethernet NDIS5.1 Driver.
| |_ MD5: F96038AA1EC4013A93D2420FC689D1E9
|
|_ Jméno: b57w2k
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Team H2O CLEDX service
|_ Cesta: C:\WINDOWS\system32\DRIVERS\cledx.sys
| |_ Výrobce: Team H2O
| |_ Popis: Team H2O CLEDX DevWhore
| |_ MD5: B53F9635457B56DCFFEF750E18AEC6CB
|
|_ Jméno: CLEDX
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] ialm
|_ Cesta: C:\WINDOWS\system32\DRIVERS\igxpmp32.sys
| |_ Výrobce: Intel Corporation
| |_ Popis: Intel Graphics Miniport Driver
| |_ MD5: 37EB2DC75D8F6451AE55071610DC24E1
|
|_ Jméno: ialm
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[X] mdmxsdk
|_ Cesta: system32\DRIVERS\mdmxsdk.sys
| |_ Výrobce:
| |_ Popis:
| |_ MD5:
|
|_ Jméno: mdmxsdk
|_ StartName:
|_ Typ spouštění: Auto Start
|_ Status: Zastaveno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit
|_ Cesta: C:\WINDOWS\system32\DRIVERS\NETw5x32.sys
| |_ Výrobce: Intel Corporation
| |_ Popis: Intel® Wireless WiFi Link Driver
| |_ MD5: 91F027C242D3FF6E5C09F92A0518297F
|
|_ Jméno: NETw5x32
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] WLAN Transport
|_ Cesta: C:\WINDOWS\system32\DRIVERS\s24trans.sys
| |_ Výrobce: Intel Corporation
| |_ Popis: Intel WLAN Packet Driver
| |_ MD5: 96B4494D4734970F47C566E098C4F527
|
|_ Jméno: s24trans
|_ StartName:
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] SigmaTel High Definition Audio CODEC
|_ Cesta: C:\WINDOWS\system32\drivers\sthda.sys
| |_ Výrobce: SigmaTel, Inc.
| |_ Popis: NDRC
| |_ MD5: 951801DFB54D86F611F0AF47825476F9
|
|_ Jméno: STHDA
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Bluetooth COM Port
|_ Cesta: C:\WINDOWS\system32\DRIVERS\tosporte.sys
| |_ Výrobce: TOSHIBA Corporation
| |_ Popis: TOSHIBA Bluetooth Port Emulation Driver
| |_ MD5: 8D624D3BD1F2D78BD1C01A2D4E954B4E
|
|_ Jméno: tosporte
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Bluetooth RFBUS
|_ Cesta: C:\WINDOWS\system32\DRIVERS\tosrfbd.sys
| |_ Výrobce: TOSHIBA CORPORATION
| |_ Popis: Bluetooth RF Bus Driver
| |_ MD5: 8C3BFAF3FCA90502E6FA35503B8E979E
|
|_ Jméno: tosrfbd
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Bluetooth RFBNEP
|_ Cesta: C:\WINDOWS\System32\Drivers\tosrfbnp.sys
| |_ Výrobce: TOSHIBA Corporation
| |_ Popis: Bluetooth RFBNEP Driver
| |_ MD5: 90C8525BC578AAFFE87C2D0ED4379E9E
|
|_ Jméno: tosrfbnp
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Bluetooth RFCOMM
|_ Cesta: C:\WINDOWS\System32\Drivers\tosrfcom.sys
| |_ Výrobce: TOSHIBA Corporation
| |_ Popis: Bluetooth RFCOMM Driver
| |_ MD5: 4742F0BAD28268AB093ED6F4EA857997
|
|_ Jméno: Tosrfcom
|_ StartName:
|_ Typ spouštění: System Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Bluetooth RFHID
|_ Cesta: C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys
| |_ Výrobce: TOSHIBA Corporation.
| |_ Popis: Bluetooth HID Driver from TOSHIBA
| |_ MD5: 7C807BA9660E2995CC0217A14A24094C
|
|_ Jméno: Tosrfhid
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Bluetooth USB Controller
|_ Cesta: C:\WINDOWS\system32\DRIVERS\tosrfusb.sys
| |_ Výrobce: TOSHIBA CORPORATION
| |_ Popis: Bluetooth USB Miniport Driver
| |_ MD5: 01C90086CD37E7E8D9A827E24167FCB7
|
|_ Jméno: Tosrfusb
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
lNetStat
================================================================
Typ: PID Proces Local <-> Remote Status
-----------------------------------------------------------------------------------------
TCP (1976) svchost.exe 0.0.0.0:135 LISTENING
TCP (4) Systém 0.0.0.0:445 LISTENING
TCP (2648) StarWindService.exe 0.0.0.0:3260 LISTENING
TCP (2648) StarWindService.exe 0.0.0.0:3261 LISTENING
TCP (1644) alg.exe 127.0.0.1:1029 LISTENING
TCP (3472) firefox.exe 127.0.0.1:1043 <-> 127.0.0.1:1044 ESTABLISHED
TCP (3472) firefox.exe 127.0.0.1:1044 <-> 127.0.0.1:1043 ESTABLISHED
TCP (3472) firefox.exe 127.0.0.1:1045 <-> 127.0.0.1:1046 ESTABLISHED
TCP (3472) firefox.exe 127.0.0.1:1046 <-> 127.0.0.1:1045 ESTABLISHED
TCP (0) 127.0.0.1:1103 TIME_WAIT
TCP (0) 127.0.0.1:1147 TIME_WAIT
TCP (0) 127.0.0.1:1153 TIME_WAIT
TCP (0) 127.0.0.1:1159 TIME_WAIT
TCP (2168) pywareTerminator.tmp127.0.0.1:1189 <-> 127.0.0.1:30606 ESTABLISHED
TCP (0) 127.0.0.1:1193 TIME_WAIT
TCP (0) 127.0.0.1:1195 TIME_WAIT
TCP (0) 127.0.0.1:1197 TIME_WAIT
TCP (0) 127.0.0.1:1199 TIME_WAIT
TCP (2604) UPM.exe 127.0.0.1:1201 <-> 127.0.0.1:30606 ESTABLISHED
TCP (2604) UPM.exe 127.0.0.1:1204 <-> 127.0.0.1:30606 ESTABLISHED
TCP (2604) UPM.exe 127.0.0.1:1206 <-> 127.0.0.1:30606 ESTABLISHED
TCP (2604) UPM.exe 127.0.0.1:1209 <-> 127.0.0.1:30606 ESTABLISHED
TCP (1528) ekrn.exe 127.0.0.1:30606 LISTENING
TCP (1528) ekrn.exe 127.0.0.1:30606 <-> 127.0.0.1:1189 ESTABLISHED
TCP (1528) ekrn.exe 127.0.0.1:30606 <-> 127.0.0.1:1201 ESTABLISHED
TCP (1528) ekrn.exe 127.0.0.1:30606 <-> 127.0.0.1:1204 ESTABLISHED
TCP (1528) ekrn.exe 127.0.0.1:30606 <-> 127.0.0.1:1206 ESTABLISHED
TCP (1528) ekrn.exe 127.0.0.1:30606 <-> 127.0.0.1:1209 ESTABLISHED
TCP (0) 127.0.0.1:52552 TIME_WAIT
TCP (0) 127.0.0.1:64321 TIME_WAIT
TCP (4) Systém 192.168.61.86:139 LISTENING
TCP (1528) ekrn.exe 192.168.61.86:1041 CLOSE_WAIT
TCP (0) 192.168.61.86:1104 TIME_WAIT
TCP (0) 192.168.61.86:1148 TIME_WAIT
TCP (0) 192.168.61.86:1154 TIME_WAIT
TCP (0) 192.168.61.86:1160 TIME_WAIT
TCP (1528) ekrn.exe 192.168.61.86:1190 <-> 64.135.77.60:80 ESTABLISHED
TCP (0) 192.168.61.86:1194 TIME_WAIT
TCP (0) 192.168.61.86:1196 TIME_WAIT
TCP (0) 192.168.61.86:1198 TIME_WAIT
TCP (0) 192.168.61.86:1200 TIME_WAIT
TCP (1528) ekrn.exe 192.168.61.86:1202 <-> 81.0.240.216:80 ESTABLISHED
TCP (0) 192.168.61.86:1203 TIME_WAIT
TCP (1528) ekrn.exe 192.168.61.86:1205 <-> 79.140.82.27:80 ESTABLISHED
TCP (1528) ekrn.exe 192.168.61.86:1207 <-> 69.58.183.143:80 ESTABLISHED
TCP (0) 192.168.61.86:1208 TIME_WAIT
UDP (4) Systém 0.0.0.0:445 <-> 78.128.147.25:80 ESTABLISHED
UDP (1748) lsass.exe 0.0.0.0:500
UDP (1748) lsass.exe 0.0.0.0:4500
UDP (272) svchost.exe 127.0.0.1:123
UDP (808) svchost.exe 127.0.0.1:1900
UDP (272) svchost.exe 192.168.61.86:123
UDP (4) Systém 192.168.61.86:137
UDP (4) Systém 192.168.61.86:138
UDP (808) svchost.exe 192.168.61.86:1900
Moduly (Zobraz i bezpečné DLL: False, Jen bez výrobce: True, Zobraz registrované: False)
================================================================
[?] netprovcredman.dll
|_ Cesta: C:\WINDOWS\system32\NetProvCredMan.dll
|_ MD5: 55E7B39D4FE95A0716E1C3E290C8C919
|_ Výrobce: Intel(R) Corporation
|_ Procesy
|_ winlogon.exe (1692)
|_ explorer.exe (1384)
|_ UPM.exe (2604)
[?] uxtheme.dll
|_ Cesta: C:\WINDOWS\system32\uxtheme.dll
|_ MD5: AA5837459D8C7B54710EC41641FA8513
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ winlogon.exe (1692)
|_ lsass.exe (1748)
|_ svchost.exe (1924)
|_ svchost.exe (1976)
|_ svchost.exe (272)
|_ svchost.exe (596)
|_ svchost.exe (808)
|_ spoolsv.exe (1188)
|_ explorer.exe (1384)
|_ scardsvr.exe (1424)
|_ svchost.exe (1480)
|_ cledx.exe (412)
|_ egui.exe (432)
|_ TosBtMng.exe (988)
|_ TosA2dp.exe (1140)
|_ TosAVRC.exe (2016)
|_ TosBtProc.exe (3200)
|_ unsecapp.exe (2656)
|_ wmiprvse.exe (2244)
|_ wmiprvse.exe (3152)
|_ alg.exe (1644)
|_ firefox.exe (3472)
|_ SpywareTerminator.exe (2160)
|_ SpywareTerminator.tmp (2168)
|_ UPM.exe (2604)
[?] psregapi.dll
|_ Cesta: C:\Program Files\Common Files\Intel\WirelessCommon\PsRegApi.dll
|_ MD5: 41C03A40A2038F3AE5046F7A9D2BAE57
|_ Výrobce: Intel(R) Corporation
|_ Procesy
|_ S24EvMon.exe (344)
|_ EvtEng.exe (1596)
|_ ZCfgSvc.exe (1648)
|_ iFrmewrk.exe (1664)
|_ WLKEEPER.exe (2836)
|_ wmiprvse.exe (2244)
[?] traceapi.dll
|_ Cesta: C:\Program Files\Common Files\Intel\WirelessCommon\TraceAPI.dll
|_ MD5: 2DA4B9E658702B414A9DBE701A8B230E
|_ Výrobce: Intel(R) Corporation
|_ Procesy
|_ S24EvMon.exe (344)
|_ EvtEng.exe (1596)
|_ ZCfgSvc.exe (1648)
|_ iFrmewrk.exe (1664)
|_ WLKEEPER.exe (2836)
|_ wmiprvse.exe (2244)
[?] libeay32.dll
|_ Cesta: C:\Program Files\Common Files\Intel\WirelessCommon\libeay32.dll
|_ MD5: 11ADD8816D61A6025844EB5123EC92D3
|_ Výrobce: The OpenSSL Project, http://www.openssl.org/
|_ Procesy
|_ S24EvMon.exe (344)
|_ EvtEng.exe (1596)
|_ ZCfgSvc.exe (1648)
|_ iFrmewrk.exe (1664)
|_ WLKEEPER.exe (2836)
[?] supplicant.dll
|_ Cesta: C:\Program Files\Intel\WiFi\bin\supplicant.dll
|_ MD5: B64224E2F1555C85A20F0370AA0C1FC4
|_ Výrobce: Devicescape Software, Inc.
|_ Procesy
|_ S24EvMon.exe (344)
[?] intstngs.dll
|_ Cesta: C:\Program Files\Intel\WiFi\bin\IntStngs.dll
|_ MD5: 6D436018286F6889CD0BB6ABE99DA0A5
|_ Výrobce: Intel(R) Corporation
|_ Procesy
|_ S24EvMon.exe (344)
|_ EvtEng.exe (1596)
|_ ZCfgSvc.exe (1648)
|_ iFrmewrk.exe (1664)
|_ WLKEEPER.exe (2836)
[?] tosbtapi.dll
|_ Cesta: C:\WINDOWS\system32\TosBtAPI.dll
|_ MD5: 8609C08E3987089D6DBDA2A5C0DB0F9B
|_ Výrobce: TOSHIBA CORPORATION.
|_ Procesy
|_ spoolsv.exe (1188)
|_ TosBtMng.exe (988)
|_ TosA2dp.exe (1140)
|_ TosAVRC.exe (2016)
|_ TosOBEX.exe (2368)
|_ TosBtProc.exe (3200)
[?] tosbdapi.dll
|_ Cesta: C:\WINDOWS\system32\TosBdAPI.dll
|_ MD5: 37CA5D8B73B51EB2C0F44A5E37F07DCC
|_ Výrobce: TOSHIBA CORPORATION.
|_ Procesy
|_ spoolsv.exe (1188)
|_ TosBtMng.exe (988)
|_ TosBtHSP.exe (748)
[?] tosbtext.dll
|_ Cesta: C:\WINDOWS\system32\TosBtExt.dll
|_ MD5: B1596F999DB0EF14B444471946147BBB
|_ Výrobce: TOSHIBA
|_ Procesy
|_ explorer.exe (1384)
[?] murocapi.dll
|_ Cesta: C:\Program Files\Intel\WiFi\bin\MurocApi.dll
|_ MD5: AF0A9D65D0C38447FC5499316705EF35
|_ Výrobce: Intel(R) Corporation
|_ Procesy
|_ EvtEng.exe (1596)
|_ ZCfgSvc.exe (1648)
|_ iFrmewrk.exe (1664)
|_ WLKEEPER.exe (2836)
[?] pfqosmgr.dll
|_ Cesta: C:\Program Files\Intel\WiFi\bin\pfQOSMgr.dll
|_ MD5: 2E47A3A393595161A21969FB5821404B
|_ Výrobce: Intel(R) Corporation
|_ Procesy
|_ EvtEng.exe (1596)
|_ ZCfgSvc.exe (1648)
[?] s24mudll.dll
|_ Cesta: C:\Program Files\Intel\WiFi\bin\S24MUDLL.dll
|_ MD5: 7C0F8B4103945FA2CB695004804D65BB
|_ Výrobce: Intel(R) Corporation
|_ Procesy
|_ EvtEng.exe (1596)
|_ ZCfgSvc.exe (1648)
|_ iFrmewrk.exe (1664)
[?] pfmgrapi.dll
|_ Cesta: C:\Program Files\Intel\WiFi\bin\PfMgrApi.dll
|_ MD5: FDA5B90363233297D7F68B03FD472F16
|_ Výrobce: Intel(R) Corporation
|_ Procesy
|_ EvtEng.exe (1596)
|_ ZCfgSvc.exe (1648)
|_ iFrmewrk.exe (1664)
|_ WLKEEPER.exe (2836)
[?] dbengine.dll
|_ Cesta: C:\Program Files\Intel\WiFi\bin\DbEngine.dll
|_ MD5: 2788FFD617D6FBE7F6407F1F5A6F18B5
|_ Výrobce: Intel(R) Corporation
|_ Procesy
|_ ZCfgSvc.exe (1648)
|_ iFrmewrk.exe (1664)
[?] wiwitray.dll
|_ Cesta: C:\Program Files\Common Files\Intel\WirelessCommon\FrameworkPlugins\WiWiTray.dll
|_ MD5: 0CD9F5C092E218600FF761F05921B180
|_ Výrobce: Intel(R) Corporation
|_ Procesy
|_ iFrmewrk.exe (1664)
[?] connmgr.dll
|_ Cesta: C:\Program Files\Common Files\Intel\WirelessCommon\FrameworkPlugins\ConnMgr.dll
|_ MD5: EBA5A99CE5D25EEB9AD88AF367D47B4D
|_ Výrobce: Intel(R) Corporation
|_ Procesy
|_ iFrmewrk.exe (1664)
[!] emu.dll
|_ Cesta: C:\Program Files\Syncrosoft\POS\H2O\emu.dll
|_ MD5: D6F6D746F162D06DAD89D62067F9047C
|_ Výrobce: Team H2O
|_ Procesy
|_ cledx.exe (412)
[?] mfc80u.dll
|_ Cesta: C:\Program Files\ESET\ESET Smart Security\mfc80u.dll
|_ MD5: 686B224B4987C22B153FBB545FEE9657
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ egui.exe (432)
[?] nmindexstoresvrps.dll
|_ Cesta: C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvrPS.dll
|_ MD5: E37E5981FB304D12D30985A588AC5959
|_ Výrobce: Nero AG
|_ Procesy
|_ NMBgMonitor.exe (752)
[?] nmdataservices.dll
|_ Cesta: C:\Program Files\Common Files\Ahead\Lib\NMDataServices.dll
|_ MD5: 06279A5653B0047B8CC57C39ED2EE56B
|_ Výrobce: Nero AG
|_ Procesy
|_ NMBgMonitor.exe (752)
[?] tosbtmnglang.dll
|_ Cesta: C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMngLang.dll
|_ MD5: FEFA614B9AA8D3191B4539B2C8A8454D
|_ Výrobce: TOSHIBA CORPORATION.
|_ Procesy
|_ TosBtMng.exe (988)
[?] tosbtsddb.dll
|_ Cesta: C:\WINDOWS\system32\TosBtSDDB.dll
|_ MD5: AA6677900A55BD6A72ABB0B30912A55B
|_ Výrobce: TOSHIBA CORPORATION.
|_ Procesy
|_ TosBtMng.exe (988)
[?] lcwizard.dll
|_ Cesta: C:\WINDOWS\system32\LCWizard.dll
|_ MD5: EDDB832EF942CBF91C44172736FB1723
|_ Výrobce: TOSHIBA CORPORATION
|_ Procesy
|_ TosBtMng.exe (988)
|_ TosBtHSP.exe (748)
|_ TosOBEX.exe (2368)
[?] oembtacpiapi.dll
|_ Cesta: C:\Program Files\Toshiba\Bluetooth Toshiba Stack\OemBtAcpiAPI.dll
|_ MD5: B4D8D59E648F43222442AC887779AEC9
|_ Výrobce: TOSHIBA CORPORATION.
|_ Procesy
|_ TosBtMng.exe (988)
[?] tosbtload.dll
|_ Cesta: C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtLoad.dll
|_ MD5: E4BB0288A98D2AD4AFB844A3B0AA3D7C
|_ Výrobce: TOSHIBA
|_ Procesy
|_ TosBtMng.exe (988)
[?] tosbtafh.dll
|_ Cesta: C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtAfh.dll
|_ MD5: FD17972042A2D3A539E6EA3110E92B43
|_ Výrobce:
|_ Procesy
|_ TosBtMng.exe (988)
[?] tosavdtapi.dll
|_ Cesta: C:\WINDOWS\system32\TosAvdtAPI.dll
|_ MD5: 4D3F719141C21E9F4B030B7376CE5234
|_ Výrobce: TOSHIBA CORPORATION.
|_ Procesy
|_ TosA2dp.exe (1140)
[?] tossndplug.dll
|_ Cesta: C:\WINDOWS\system32\TosSndPlug.dll
|_ MD5: 21BE6C134D4A78C1A584768BA8DBC810
|_ Výrobce: TOSHIBA CORPORATION.
|_ Procesy
|_ TosA2dp.exe (1140)
|_ TosBtHSP.exe (748)
[?] tosbteccapi.dll
|_ Cesta: C:\WINDOWS\system32\TosBtECCAPI.dll
|_ MD5: 558C7FE3994FD6269A9170B51D9AB985
|_ Výrobce: TOSHIBA CORPORATION.
|_ Procesy
|_ TosA2dp.exe (1140)
|_ TosBtHSP.exe (748)
[?] tosavctapi.dll
|_ Cesta: C:\WINDOWS\system32\TosAvctAPI.dll
|_ MD5: B6DECF00191ECC239406436BCA0C5401
|_ Výrobce: TOSHIBA CORPORATION.
|_ Procesy
|_ TosAVRC.exe (2016)
[?] tosntfs.dll
|_ Cesta: C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosNtfs.dll
|_ MD5: 7066C4493731D27C69A1EF6B4C9979FB
|_ Výrobce: TOSHIBA Corporation
|_ Procesy
|_ TosOBEX.exe (2368)
[?] tosobex.dll
|_ Cesta: C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosOBEX.dll
|_ MD5: 6B0D4136B16CBDF051BDB7A225A77781
|_ Výrobce: TOSHIBA corporation
|_ Procesy
|_ TosBtProc.exe (3200)
[?] iwmsprov.dll
|_ Cesta: C:\Program Files\Intel\WiFi\bin\iWMSProv.dll
|_ MD5: 1CA64E4EDEA94FDA75212C4BD150658F
|_ Výrobce:
|_ Procesy
|_ wmiprvse.exe (2244)
[?] softokn3.dll
|_ Cesta: C:\Program Files\Mozilla Firefox\softokn3.dll
|_ MD5: 77CA7D5FE15C3C68233017C6FBE87DA0
|_ Výrobce: Mozilla Foundation
|_ Procesy
|_ firefox.exe (3472)
[?] nssdbm3.dll
|_ Cesta: C:\Program Files\Mozilla Firefox\nssdbm3.dll
|_ MD5: 46C963A1468FCDC8729555DACC83CF91
|_ Výrobce: Mozilla Foundation
|_ Procesy
|_ firefox.exe (3472)
[?] freebl3.dll
|_ Cesta: C:\Program Files\Mozilla Firefox\freebl3.dll
|_ MD5: 324A9275A3BA33CF77A2D8D0C67F10CF
|_ Výrobce: Mozilla Foundation
|_ Procesy
|_ firefox.exe (3472)
[!] downlib.dll
|_ Cesta: C:\DOCUME~1\PaaX\LOCALS~1\temp\is-64QU9.tmp\DownLib.dll
|_ MD5: DB25DFDD4C1F2B65C68A230881072695
|_ Výrobce: Xacti
|_ Procesy
|_ SpywareTerminator.tmp (2168)
Výpis souborů
================================================================
\System32:
[?] ac3acm.acm 7 no vrfy, {6C113E42}
[?] ct32.dll 7 no vrfy, {C2216E38}
[?] decdnet.dll 7 no vrfy, {753081D9}
[?] encdnet.dll 7 no vrfy, {56EF60F9}
[?] ff_vfw.dll 12 ncmpny, {07933243}
[?] LCWizard.dll 14 no vrfy, {170152B7}
[?] LocalCOM.cpl 14 no vrfy, {EEE61E66}
[?] mdmxsdk.dll 7 no vrfy, {83AAF901}
[?] NetProvCredMan.dll NETPRO~1.DLL 7 no vrfy, {FDAEE31F}
[?] pnc3250.dll 7 no vrfy, {50607C4C}
[?] pncrt.dll 7 no vrfy, {E234DFAD}
[?] pneng50.dll 7 no vrfy, {F705CB40}
[?] pngu3263.dll 7 no vrfy, {88B39614}
[?] ra3214_4.dll 7 no vrfy, {6DF06AE5}
[?] ra3228_8.dll 7 no vrfy, {B30AAD0C}
[?] ra32dnet.dll 14 no vrfy, {E8AAB6F5}
[?] ra32sipr.dll 7 no vrfy, {66C6CBC1}
[?] rmbe3260.dll 7 no vrfy, {7C71266F}
[?] S24NCfg.dll 7 no vrfy, {EAD57051}
[?] sfcfiles.dll 12 ncmpny, {3B1E57AC}
[?] SYNSOACC.dll 7 no vrfy, {5FDF5408}
[?] SynsoLChk.dll SYNSOL~1.DLL 7 no vrfy, {F5D51898}
[?] Synsopos.exe 7 no vrfy, {EB7348FB}
[?] TosAvctAPI.dll TOSAVC~1.DLL 7 no vrfy, {C8959932}
[?] TosAvdtAPI.dll TOSAVD~1.DLL 7 no vrfy, {0EDC9593}
[?] TosBdAPI.dll 7 no vrfy, {80833070}
[?] TosBtAPI.dll 7 no vrfy, {90C3BB59}
[?] TosBtCapApi.dll TOSBTC~1.DLL 7 no vrfy, {650F3373}
[?] TosBtECCAPI.dll TOSBTE~1.DLL 7 no vrfy, {A6CF3F62}
[?] TosBtExt.dll 14 no vrfy, {87AD51A4}
[?] TosBTHFPAPI.dll TOSBTH~3.DLL 7 no vrfy, {0ECEC16E}
[?] TosBtSDDB.dll TOSBTS~1.DLL 7 no vrfy, {9FDE4C55}
[?] TosSndPlug.dll TOSSND~2.DLL 7 no vrfy, {92ABC4E3}
[?] unrar.dll 12 ncmpny, {22464CF1}
[?] uxtheme.dll 12 ncmpny, {75A9D244}
[?] xvidcore.dll 12 ncmpny, {72602115}
[?] xvidvfw.dll 25 ncmpny, {1E5DD24D}
\Drivers:
[?] cledx.sys 14 no vrfy, {062BD80A}
[?] Oreans.sys 12 ncmpny, {6775316B}
[?] sp_rsdrv2.sys SP_RSD~1.SYS 25 ncmpny, {0FB6D88F}
[?] synasUSB.sys 21 no vrfy, {7F859AA0}
Access violations - HKCU
================================================================
================================================================
Ultimate Process Manager v4.1.3 - [ Lodus Software ]