Prosim o kontrolu logu - zavazne podezreni na brouka
Napsal: 29 čer 2010 22:32
Dobry den,vecer,
prosim o kontrolu logu. Zrejme se v nem skryva neco, co by nemelo. Uz tri dny mi pocitac samovolne vypina zvuk. Dnes dokonce zacal samovolne vyskakovat IE a to uz bylo i na me moc. Tak jsem aktualizoval, stahnul Avast. Ten nic nenasel. Nasadil jsem spyterminator, ktery nasel 4 veci, nejzavaznejsi bylo asi smss.exe, ktere se mi jak doufam podarilo odstranit. Nicmene problem se stale vyskytuje a nic jineho mi to nenaslo. Kdyz budete mit nekdo chvilku, tak se na to podivejte, neb pro me je to srozumitelne asi jako indian mluvici mandarinsky. Dik
prikladam logy u UPM a RSIT
Logfile of random's system information tool 1.07 (written by random/random)
Run by Administrator at 2010-06-29 23:28:53
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 34 GB (56%) free of 60 GB
Total RAM: 2046 MB (68% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:28:57, on 29.6.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\vsnp2uvc.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\TO2SSM\McciTrayApp.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Crawler\Toolbar\CToolbar.exe
C:\Program Files\Miranda IM\miranda32.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
E:\Ondra\Filmy\RSIT.exe
C:\Program Files\trend micro\Administrator.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cz.o2.com/welcome/cz/index.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Crawler lišta - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [snp2uvc] C:\WINDOWS\vsnp2uvc.exe
O4 - HKLM\..\Run: [tsnp2uvc] C:\WINDOWS\tsnp2uvc.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [TO2SSM_McciTrayApp] C:\Program Files\TO2SSM\McciTrayApp.exe
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://lnpha1.cdtel.cz/iNotes6W.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
--
End of file - 6751 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2010-06-25 1241552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-03-07 35840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-03-07 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{4B3803EA-5230-4DC3-A7FC-33638F3D3542} - &Crawler lišta - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2010-06-25 1241552]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2003-04-07 155648]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2003-04-07 114688]
"snp2uvc"=C:\WINDOWS\vsnp2uvc.exe [2007-05-15 675840]
"tsnp2uvc"=C:\WINDOWS\tsnp2uvc.exe [2007-04-24 237568]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-03-07 148888]
"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2003-10-31 32768]
"TO2SSM_McciTrayApp"=C:\Program Files\TO2SSM\McciTrayApp.exe [2008-08-15 1473536]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-06-28 2837864]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"PC Suite Tray"=C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2009-11-11 1451520]
"SpywareTerminatorUpdate"=C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2010-06-29 3037696]
C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\Po spuštění
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE
VPN Client.lnk - C:\WINDOWS\Installer\{A7091E1D-36A4-47F1-A739-173CC341414F}\Icon3E5562ED7.ico
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxsrvc.dll [2003-04-07 315392]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Miranda IM\miranda32.exe"="C:\Program Files\Miranda IM\miranda32.exe:*:Enabled:Miranda IM"
"C:\Program Files\Swapper\swapper.exe"="C:\Program Files\Swapper\swapper.exe:*:Enabled:swapper"
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Soldat\Soldat.exe"="C:\Soldat\Soldat.exe:*:Enabled:http://soldat.pl"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe"="C:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe:*:Enabled:Nokia Software Updater"
"C:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe"="C:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe:*:Enabled:Nokia Service Layer Host Process "
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"="C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe:*:Enabled:Crawler Spyware Terminator"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4484d7a0-3850-11df-9039-000f1f8c0c9b}]
shell\AutoRun\command - H:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4484d7a1-3850-11df-9039-000f1f8c0c9b}]
shell\AutoRun\command - H:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{46d483b8-3b52-11df-903f-000f1f8c0c9b}]
shell\AutoRun\command - I:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fad44db2-9f06-11de-8f59-000f1f8c0c9b}]
shell\AutoRun\command - H:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fad44db5-9f06-11de-8f59-000f1f8c0c9b}]
shell\AutoRun\command - H:\AutoRun.exe
======List of files/folders created in the last 1 months======
2010-06-29 23:18:44 ----D---- C:\Program Files\trend micro
2010-06-29 23:18:43 ----D---- C:\rsit
2010-06-29 22:45:25 ----D---- C:\Program Files\Ultimate Process Manager
2010-06-29 20:41:52 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2010-06-29 20:37:36 ----HDC---- C:\WINDOWS\$NtUninstallKB980195$
2010-06-29 20:37:18 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2010-06-29 20:34:28 ----SHD---- C:\Config.Msi
2010-06-29 20:31:45 ----HDC---- C:\WINDOWS\$NtUninstallKB981793$
2010-06-29 20:31:39 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2010-06-29 20:31:16 ----D---- C:\Program Files\Crawler
2010-06-29 20:30:56 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Spyware Terminator
2010-06-29 20:30:52 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Spyware Terminator
2010-06-29 20:30:50 ----D---- C:\Program Files\Spyware Terminator
2010-06-29 20:28:27 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2010-06-29 20:28:19 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2010-06-29 20:28:11 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2010-06-29 20:21:04 ----HDC---- C:\WINDOWS\$NtUninstallKB982381$
2010-06-29 19:01:31 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-06-29 18:49:37 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Alwil Software
======List of files/folders modified in the last 1 months======
2010-06-29 23:18:44 ----RD---- C:\Program Files
2010-06-29 23:05:32 ----D---- C:\WINDOWS\Temp
2010-06-29 22:46:10 ----D---- C:\WINDOWS\system32\CatRoot2
2010-06-29 22:31:32 ----D---- C:\RP6
2010-06-29 22:31:28 ----D---- C:\WINDOWS\Prefetch
2010-06-29 21:38:42 ----RSD---- C:\WINDOWS\assembly
2010-06-29 21:38:42 ----D---- C:\WINDOWS\Microsoft.NET
2010-06-29 21:06:30 ----D---- C:\Program Files\Mozilla Firefox
2010-06-29 21:04:01 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Skype
2010-06-29 21:02:49 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-06-29 20:44:58 ----D---- C:\WINDOWS
2010-06-29 20:44:03 ----D---- C:\WINDOWS\system32
2010-06-29 20:41:57 ----HD---- C:\WINDOWS\inf
2010-06-29 20:41:55 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-06-29 20:41:48 ----SHD---- C:\WINDOWS\Installer
2010-06-29 20:41:32 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-06-29 20:41:07 ----D---- C:\WINDOWS\WinSxS
2010-06-29 20:39:18 ----D---- C:\WINDOWS\system32\CatRoot
2010-06-29 20:37:40 ----A---- C:\WINDOWS\imsins.BAK
2010-06-29 20:37:35 ----HD---- C:\WINDOWS\$hf_mig$
2010-06-29 20:31:13 ----D---- C:\WINDOWS\system32\drivers
2010-06-29 20:04:24 ----A---- C:\WINDOWS\NeroDigital.ini
2010-06-29 18:53:10 ----D---- C:\Documents and Settings\Administrator\Data aplikací\skypePM
2010-06-29 18:52:30 ----D---- C:\Program Files\Alwil Software
2010-06-29 18:37:40 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Dofus 2
2010-06-28 20:21:55 ----D---- C:\Documents and Settings
2010-06-10 23:42:58 ----SD---- C:\Documents and Settings\Administrator\Data aplikací\Microsoft
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-06-28 28880]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-06-28 165456]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-06-28 46672]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 OMCI;OMCI; C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS [2001-08-22 13632]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2009-03-22 5632]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-06-28 17744]
R2 aswMon2;aswMon2; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-06-28 100176]
R2 CVPNDRVA;Cisco Systems Inc. IPSec Driver; \??\C:\WINDOWS\system32\Drivers\CVPNDRVA.sys []
R3 {6080A529-897E-4629-A488-ABA0C29B635E};Intel(R) Graphics Platform (SoftBIOS) Driver; C:\WINDOWS\system32\drivers\ialmsbw.sys [2003-04-15 113504]
R3 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91};Intel(R) Graphics Chipset (KCH) Driver; C:\WINDOWS\system32\drivers\ialmkchw.sys [2003-04-15 78752]
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2002-04-01 4816]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-06-28 23376]
R3 DNE;Deterministic Network Enhancer Miniport; C:\WINDOWS\system32\DRIVERS\dne2000.sys [2008-03-29 125328]
R3 Dot4;Ovladač MS IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2008-04-14 206976]
R3 Dot4Print;Ovladač třídy tiskárny standardu IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys [2001-08-17 12928]
R3 E1000;Intel(R) PRO/1000 Adapter Driver; C:\WINDOWS\system32\DRIVERS\e1000325.sys [2003-03-08 121344]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2003-04-15 90907]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2003-02-28 545024]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S2 BT848;bt848 tweaked WDM Video Capture; C:\WINDOWS\system32\drivers\BT848.sys [2001-10-08 208191]
S2 BTTUNER;bt848 tweaked WDM TvTuner; C:\WINDOWS\system32\drivers\BTTUNER.sys [2001-10-08 9187]
S2 BTXBAR;bt848 tweaked TV WDM Crossbar; C:\WINDOWS\system32\drivers\BTXBAR.sys [2001-10-08 8193]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 CVirtA;Cisco Systems VPN Adapter; C:\WINDOWS\system32\DRIVERS\CVirtA.sys [2007-01-18 5275]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys [2008-09-26 101376]
S3 MREMP50;MREMP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS []
S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS []
S3 MREMPR5;MREMPR5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS []
S3 MRENDIS5;MRENDIS5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS []
S3 MRESP50;MRESP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS []
S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 nm;Ovladač programu Sledování sítě; C:\WINDOWS\system32\DRIVERS\NMnt.sys [2008-04-14 40320]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2010-02-26 18176]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2010-02-26 22528]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; C:\WINDOWS\system32\drivers\nmwcdnsu.sys [2010-02-26 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic; C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2010-02-26 8320]
S3 NPF;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2007-11-06 34064]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\WINDOWS\system32\DRIVERS\snp2uvc.sys [2007-06-06 9604864]
S3 sscdbus;SAMSUNG USB Composite Device driver (WDM); C:\WINDOWS\system32\DRIVERS\sscdbus.sys [2008-02-22 87936]
S3 sscdmdfl;SAMSUNG Mobile Modem Filter; C:\WINDOWS\system32\DRIVERS\sscdmdfl.sys [2008-02-22 14976]
S3 sscdmdm;SAMSUNG Mobile Modem Drivers; C:\WINDOWS\system32\DRIVERS\sscdmdm.sys [2008-02-22 114304]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2010-02-26 8192]
S3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-14 60032]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-14 26112]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2010-02-26 8192]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-14 121984]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-06-28 40384]
R2 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
R2 CVPND;Cisco Systems, Inc. VPN Service; C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe [2008-06-19 1528608]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-01-17 61440]
R2 McciCMService;McciCMService; C:\Program Files\Common Files\Motive\McciCMService.exe [2007-10-15 303104]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2001-02-23 270336]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2010-06-29 488960]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-06-28 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-06-28 40384]
R3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-04-27 611840]
S2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe -service -config C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf []
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-03-26 779824]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-03-26 267824]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe [2007-11-06 92792]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
====================================================================
UPM:
Windows XP SP 3 (build 2600)
Boot Mode: Normal
Ověření souborů Microsoftu: Ne
Whitelist: Ne
Internet Explorer v6.00.2900.5512 (xpsp.080413-2105)
Log vygenerován: 29.6.2010 22:46:02
================================================================
SmallARK
================================================================
[R]NtClose -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtCreateKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtDeleteKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtDeleteValueKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtDuplicateObject -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtOpenKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtOpenProcess -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtOpenThread -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtQueryValueKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtRenameKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtRestoreKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtSetValueKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
MBR ROOTKIT DETECTED!
Běžící procesy
================================================================
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST5\AVASTSVC.EXE
C:\WINDOWS\SYSTEM32\IGFXTRAY.EXE
C:\WINDOWS\SYSTEM32\HKCMD.EXE
C:\WINDOWS\VSNP2UVC.EXE
C:\PROGRAM FILES\JAVA\JRE6\BIN\JUSCHED.EXE
C:\PROGRAM FILES\CYBERLINK\POWERDVD\PDVDSERV.EXE
C:\PROGRAM FILES\TO2SSM\MCCITRAYAPP.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST5\AVASTUI.EXE
C:\WINDOWS\SYSTEM32\CTFMON.EXE
C:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 7\PCSUITE.EXE
C:\PROGRAM FILES\SPYWARE TERMINATOR\SPYWARETERMINATORUPDATE.EXE
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V2.0.50727\MSCORSVW.EXE
C:\PROGRAM FILES\CISCO SYSTEMS\VPN CLIENT\CVPND.EXE
C:\PROGRAM FILES\JAVA\JRE6\BIN\JQS.EXE
C:\PROGRAM FILES\COMMON FILES\LIGHTSCRIBE\LSSRVC.EXE
C:\PROGRAM FILES\COMMON FILES\MOTIVE\MCCICMSERVICE.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\MDM.EXE
C:\PROGRAM FILES\SPYWARE TERMINATOR\SP_RSSER.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\WDFMGR.EXE
C:\PROGRAM FILES\PC CONNECTIVITY SOLUTION\SERVICELAYER.EXE
C:\WINDOWS\SYSTEM32\ALG.EXE
C:\PROGRAM FILES\PC CONNECTIVITY SOLUTION\TRANSPORTS\NCLUSBSRV.EXE
C:\PROGRAM FILES\PC CONNECTIVITY SOLUTION\TRANSPORTS\NCLRSSRV.EXE
C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE
C:\PROGRA~1\CRAWLER\TOOLBAR\CTOOLBAR.EXE
C:\PROGRAM FILES\MIRANDA IM\MIRANDA32.EXE
C:\PROGRA~1\CRAWLER\TOOLBAR\CTOOLBAR.EXE
C:\WINDOWS\SYSTEM32\TASKMGR.EXE
C:\PROGRAM FILES\DOFUS 2\APP\DOFUSMOD.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\ULTIMATE PROCESS MANAGER\UPM.EXE
Scanner
================================================================
[S] explorer.exe
Spouští se po startu HKLM Winlogon [Shell]
[?] igfxtray.exe
Non Microsoft v System32:
Spouští se po startu HKLM Run [IgfxTray]
[?] hkcmd.exe
Non Microsoft v System32:
Spouští se po startu HKLM Run [HotKeysCmds]
[?] vsnp2uvc.exe
Spouští se po startu HKLM Run [snp2uvc]
[R] jusched.exe
Spouští se po startu HKLM Run [SunJavaUpdateSched]
[?] PDVDServ.exe
Spouští se po startu HKLM Run [RemoteControl]
Soubor 7%
[?] McciTrayApp.exe
Spouští se po startu HKLM Run [TO2SSM_McciTrayApp]
Soubor 7%
[R] AvastUI.exe
Spouští se po startu HKLM Run [avast5]
Skrytá cesta EXE: C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
[S] ctfmon.exe
Spouští se po startu HKCU Run [CTFMON.EXE]
[?] PCSuite.exe
Spouští se po startu HKCU Run [PC Suite Tray]
Soubor 7%
[?] SpywareTerminatorUpdate.exe
Spouští se po startu HKCU Run [SpywareTerminatorUpdate]
EntryPoint v sekci: .ITEXT
|_ Celkový počet sekcí: 9
Soubor 70%
[R] mscorsvw.exe
Ověřený Microsoft: Ne
[?] LSSrvc.exe
Nemá okno
Soubor 7%
[?] McciCMService.exe
Nemá okno
Soubor 7%
[?] mdm.exe
Ověřený Microsoft: Ne
Nemá okno
Soubor 12%
[?] sp_rsser.exe
EntryPoint v sekci: .ITEXT
|_ Celkový počet sekcí: 9
Nemá okno
Soubor 70%
[?] ServiceLayer.exe
Soubor 7%
[?] NclUSBSrv.exe
Soubor 7%
[?] NclRSSrv.exe
Soubor 7%
[R] CToolbar.exe
EntryPoint v sekci: .ITEXT
|_ Celkový počet sekcí: 9
[?] miranda32.exe
Bez výrobce
Soubor 12%
[R] CToolbar.exe
EntryPoint v sekci: .ITEXT
|_ Celkový počet sekcí: 9
[?] DofusMod.exe
Bez výrobce
Soubor 25%
[?] UPM.exe
Soubor 7%
Po spuštění
================================================================
Moduly (Zobraz i bezpečné DLL: False, Jen bez výrobce: True, Zobraz registrované: False)
================================================================
[?] implode.dll
|_ Cesta: C:\Program Files\Corel\Shared\versions\implode.dll
|_ MD5: 6889755A917AA3C736B61842FBD3DA73
|_ Výrobce:
|_ Procesy
|_ explorer.exe (256)
[?] msvcr71.dll
|_ Cesta: C:\Program Files\Nero\Nero 7\Nero BackItUp\msvcr71.dll
|_ MD5: 86F1895AE8C5E8B17D99ECE768A70732
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ explorer.exe (256)
|_ jqs.exe (3084)
[?] rarext.dll
|_ Cesta: C:\Program Files\WinRAR\RarExt.dll
|_ MD5: A070B8C38CEB3A30CC18D1B7C433144C
|_ Výrobce: ?
|_ Procesy
|_ explorer.exe (256)
[?] vers232.dll
|_ Cesta: C:\Program Files\Corel\Shared\versions\vers232.dll
|_ MD5: 8693A9DD4A864ACF03F486707285C8A5
|_ Výrobce:
|_ Procesy
|_ explorer.exe (256)
[!] sptcontmenu.dll
|_ Cesta: C:\Program Files\Spyware Terminator\sptcontmenu.dll
|_ MD5: A5E97B2B88CC48FC178E88BF6E02F5EC
|_ Výrobce: Crawler.com
|_ Procesy
|_ explorer.exe (256)
[?] phonebrowser.dll
|_ Cesta: C:\Program Files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
|_ MD5: F0CBAF724FF71D400FF45FBCEC4F3898
|_ Výrobce: Nokia
|_ Procesy
|_ explorer.exe (256)
[?] ngscm.dll
|_ Cesta: C:\Program Files\Nokia\Nokia PC Suite 7\NGSCM.dll
|_ MD5: 83AB0FCCF90A395AE71B7EA931C90529
|_ Výrobce: Nokia
|_ Procesy
|_ explorer.exe (256)
[?] cversion.dll
|_ Cesta: C:\Program Files\Corel\Shared\versions\cversion.dll
|_ MD5: 4D291442F6FCF6495A51AFA22C1D1E7D
|_ Výrobce: Corel Corporation Limited
|_ Procesy
|_ explorer.exe (256)
[?] mccicontexthook_6-1-0_dsr.dll
|_ Cesta: C:\Program Files\Common Files\Motive\McciContextHook_6-1-0_DSR.dll
|_ MD5: D8B25453BD74930000E5A7AF1AE139A4
|_ Výrobce: Motive Communications, Inc.
|_ Procesy
|_ explorer.exe (256)
|_ igfxtray.exe (448)
|_ hkcmd.exe (456)
|_ McciTrayApp.exe (504)
|_ AvastUI.exe (528)
|_ ctfmon.exe (540)
|_ PCSuite.exe (596)
|_ SpywareTerminatorUpdate.exe (644)
|_ firefox.exe (1276)
|_ CToolbar.exe (3704)
|_ miranda32.exe (884)
|_ taskmgr.exe (3548)
|_ DofusMod.exe (3624)
|_ UPM.exe (2648)
[?] mfc71u.dll
|_ Cesta: C:\Program Files\Nero\Nero 7\Nero BackItUp\mfc71u.dll
|_ MD5: 7B93C623333F121DC9E689CCB1B7A733
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ explorer.exe (256)
[?] msvcp71.dll
|_ Cesta: C:\Program Files\Nero\Nero 7\Nero BackItUp\msvcp71.dll
|_ MD5: 561FA2ABB31DFA8FAB762145F81667C2
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ explorer.exe (256)
[?] arpot.dll
|_ Cesta: C:\Program Files\Alwil Software\Avast5\defs\10062900\ArPot.dll
|_ MD5: 14F84A5D3ED36D6C7269A496319BD5AF
|_ Výrobce: ALWIL Software
|_ Procesy
|_ AvastSvc.exe (288)
[?] clrcengine2.dll
|_ Cesta: C:\Program Files\CyberLink\Shared Files\CLRCEngine2.dll
|_ MD5: DAE211D3393343B2FAD71C65B20EC562
|_ Výrobce: CyberLink Corp.
|_ Procesy
|_ PDVDServ.exe (496)
[?] mccicontextdetectoremail_6-1-0_dsr.dll
|_ Cesta: C:\Program Files\Common Files\Motive\McciContextDetectorEmail_6-1-0_DSR.dll
|_ MD5: 408F0FEE14F7A93A9A5741D8BA5C83C1
|_ Výrobce: Motive Communications, Inc.
|_ Procesy
|_ McciTrayApp.exe (504)
[?] mccicontextx.dll
|_ Cesta: C:\Program Files\Common Files\Motive\McciContextX.dll
|_ MD5: 7F600419A94A1F175FABE0F15275583B
|_ Výrobce: Motive Communications, Inc.
|_ Procesy
|_ McciTrayApp.exe (504)
[?] mccicontextdetectorwin32_6-1-0_dsr.dll
|_ Cesta: C:\Program Files\Common Files\Motive\McciContextDetectorWin32_6-1-0_DSR.dll
|_ MD5: 6113EE7CB182422F21849B170CFBEB5B
|_ Výrobce: Motive Communications, Inc.
|_ Procesy
|_ McciTrayApp.exe (504)
[?] connapi.dll
|_ Cesta: C:\Program Files\PC Connectivity Solution\ConnAPI.dll
|_ MD5: 9BB2ED345B38157E8B2DB84E3EEB40E1
|_ Výrobce: Nokia.
|_ Procesy
|_ PCSuite.exe (596)
[?] daapi.dll
|_ Cesta: C:\Program Files\PC Connectivity Solution\DAAPI.dll
|_ MD5: F79194B03CBF2B52D5BD645BC76A5A62
|_ Výrobce: Nokia
|_ Procesy
|_ PCSuite.exe (596)
[?] pccs_abapi.dll
|_ Cesta: C:\Program Files\PC Connectivity Solution\PCCS_ABAPI.dll
|_ MD5: E7E98B1F8C0107E4B5BC0A83F39D64D5
|_ Výrobce: Nokia
|_ Procesy
|_ PCSuite.exe (596)
[?] confserver.dll
|_ Cesta: C:\Program Files\PC Connectivity Solution\ConfServer.dll
|_ MD5: CF7D4E7093E3EBDA24BEB8369F8823DB
|_ Výrobce: Nokia
|_ Procesy
|_ PCSuite.exe (596)
[?] qjpeg4.dll
|_ Cesta: C:\Program Files\Nokia\Nokia PC Suite 7\imageformats\qjpeg4.dll
|_ MD5: B6FAD59C92D1381D986CD7368A5291F4
|_ Výrobce:
|_ Procesy
|_ PCSuite.exe (596)
[?] qsvg4.dll
|_ Cesta: C:\Program Files\Nokia\Nokia PC Suite 7\imageformats\qsvg4.dll
|_ MD5: CB3B04A1D5E1F32D5E38974B5E077EA6
|_ Výrobce:
|_ Procesy
|_ PCSuite.exe (596)
[?] nglstyle.dll
|_ Cesta: C:\Program Files\Nokia\Nokia PC Suite 7\Styles\NGLStyle.dll
|_ MD5: 0435B351C4BBD710EFB2925966DB160F
|_ Výrobce: Nokia
|_ Procesy
|_ PCSuite.exe (596)
[?] cdc.dll
|_ Cesta: C:\Program Files\Nokia\Nokia PC Suite 7\CDC.dll
|_ MD5: D39835D21F82CEC4BCC0DC92A99C4B7E
|_ Výrobce: Nokia
|_ Procesy
|_ PCSuite.exe (596)
[?] qtxml4.dll
|_ Cesta: C:\Program Files\Nokia\Nokia PC Suite 7\QtXml4.dll
|_ MD5: B7AC803CF0DF5FF872DD45D48BBBDA6A
|_ Výrobce:
|_ Procesy
|_ PCSuite.exe (596)
[?] qtgui4.dll
|_ Cesta: C:\Program Files\Nokia\Nokia PC Suite 7\QtGUI4.dll
|_ MD5: 1CA1F99D167BB19F785F2D8582579CFB
|_ Výrobce:
|_ Procesy
|_ PCSuite.exe (596)
[?] qtsvg4.dll
|_ Cesta: C:\Program Files\Nokia\Nokia PC Suite 7\QtSvg4.dll
|_ MD5: 958BE76750B8B10750FB3DE7419588C1
|_ Výrobce:
|_ Procesy
|_ PCSuite.exe (596)
[?] qtcore4.dll
|_ Cesta: C:\Program Files\Nokia\Nokia PC Suite 7\QtCore4.dll
|_ MD5: 285A5075F1973E9BEB8A12EE3641EEA4
|_ Výrobce:
|_ Procesy
|_ PCSuite.exe (596)
[?] torentdll.dll
|_ Cesta: C:\Program Files\Spyware Terminator\TorentDll.dll
|_ MD5: 0B0387E70BE085C1842BC7DEB47EE54F
|_ Výrobce:
|_ Procesy
|_ SpywareTerminatorUpdate.exe (644)
[?] lssproxy.dll
|_ Cesta: C:\Program Files\Common Files\LightScribe\LSSProxy.dll
|_ MD5: D7EB32B51B7472FBEE86BFA47B3C4BC5
|_ Výrobce: Hewlett-Packard Company
|_ Procesy
|_ LSSrvc.exe (3104)
[?] lslog.dll
|_ Cesta: C:\Program Files\Common Files\LightScribe\LSLog.dll
|_ MD5: 0EE266A90D43E82A07CF33755D6DE1CC
|_ Výrobce: Hewlett-Packard Company
|_ Procesy
|_ LSSrvc.exe (3104)
[?] msdbg2.dll
|_ Cesta: C:\Program Files\Common Files\Microsoft Shared\VS7Debug\msdbg2.dll
|_ MD5: 882EAB3108383692506D32F637485C77
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ mdm.exe (3152)
|_ CToolbar.exe (3704)
[?] pccs_dbengine.dll
|_ Cesta: C:\Program Files\PC Connectivity Solution\PCCS_DBEngine.dll
|_ MD5: 27DD9CEA7B4C8EFAD06B55AED94AAAD7
|_ Výrobce: Nokia
|_ Procesy
|_ ServiceLayer.exe (3644)
[!] xcomm.dll
|_ Cesta: C:\Program Files\Crawler\Toolbar\firefox\components\xcomm.dll
|_ MD5: 25431E2DC58A422CE27C9F29D904E003
|_ Výrobce: Crawler.com
|_ Procesy
|_ firefox.exe (1276)
[?] xsupport.dll
|_ Cesta: C:\Program Files\Crawler\Toolbar\firefox\components\xsupport.dll
|_ MD5: 4C20A7877F340BE462807935C8013251
|_ Výrobce: Crawler.com
|_ Procesy
|_ firefox.exe (1276)
[!] xshared.dll
|_ Cesta: C:\Program Files\Crawler\Toolbar\firefox\components\xshared.dll
|_ MD5: B0170A9F1F0D9A668D815B3ECE135CB6
|_ Výrobce: Crawler.com
|_ Procesy
|_ firefox.exe (1276)
[!] xwsg.dll
|_ Cesta: C:\Program Files\Crawler\Toolbar\firefox\components\xwsg.dll
|_ MD5: DD248D5444448BC5182441922F3910C9
|_ Výrobce: Crawler.com
|_ Procesy
|_ firefox.exe (1276)
[?] softokn3.dll
|_ Cesta: C:\Program Files\Mozilla Firefox\softokn3.dll
|_ MD5: 35CF3FB481638306CA1A6A1A2F816D84
|_ Výrobce: Mozilla Foundation
|_ Procesy
|_ firefox.exe (1276)
[?] nssdbm3.dll
|_ Cesta: C:\Program Files\Mozilla Firefox\nssdbm3.dll
|_ MD5: F349B437ABE573013A673F0A82B1B08C
|_ Výrobce: Mozilla Foundation
|_ Procesy
|_ firefox.exe (1276)
[?] freebl3.dll
|_ Cesta: C:\Program Files\Mozilla Firefox\freebl3.dll
|_ MD5: 7ECFB8FFF406A664E35F36BDF915DFB9
|_ Výrobce: Mozilla Foundation
|_ Procesy
|_ firefox.exe (1276)
[!] ctbcomm.dll
|_ Cesta: C:\PROGRA~1\Crawler\Toolbar\ctbcomm.dll
|_ MD5: 562939F188B53D068834D0F6ACFC93F6
|_ Výrobce: Crawler.com
|_ Procesy
|_ CToolbar.exe (3704)
|_ CToolbar.exe (2404)
[!] websec~1.dll
|_ Cesta: C:\PROGRA~1\Crawler\Toolbar\WEBSEC~1.DLL
|_ MD5: 16042425E6BDF6AA012AFF5B851A16BC
|_ Výrobce: Crawler.com
|_ Procesy
|_ CToolbar.exe (3704)
|_ CToolbar.exe (2404)
[?] pdm.dll
|_ Cesta: C:\Program Files\Common Files\Microsoft Shared\VS7Debug\pdm.dll
|_ MD5: 349475945AA64B2992B2C35E5DDE5CAB
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ CToolbar.exe (3704)
[?] advaimg.dll
|_ Cesta: C:\Program Files\Miranda IM\Plugins\advaimg.dll
|_ MD5: AB2D0752C3A9268B117B27A97538660E
|_ Výrobce: Miranda IM and FreeImage
|_ Procesy
|_ miranda32.exe (884)
[?] aim.dll
|_ Cesta: C:\Program Files\Miranda IM\Plugins\Aim.dll
|_ MD5: EB561F92EC71A1AE811411DEDCE95DE1
|_ Výrobce:
|_ Procesy
|_ miranda32.exe (884)
[?] avs.dll
|_ Cesta: C:\Program Files\Miranda IM\Plugins\avs.dll
|_ MD5: 039838DA4A4D5E9EB94B4E312945F505
|_ Výrobce:
|_ Procesy
|_ miranda32.exe (884)
[?] chat.dll
|_ Cesta: C:\Program Files\Miranda IM\Plugins\chat.dll
|_ MD5: AB9ACA1DE13ED08561183F94479AD7D8
|_ Výrobce:
|_ Procesy
|_ miranda32.exe (884)
[?] icq.dll
|_ Cesta: C:\Program Files\Miranda IM\Plugins\ICQ.dll
|_ MD5: 6F45E63364B1D0783121EA22A29314B1
|_ Výrobce: ?
|_ Procesy
|_ miranda32.exe (884)
[?] jabber.dll
|_ Cesta: C:\Program Files\Miranda IM\Plugins\jabber.dll
|_ MD5: 90DCF1A753A024306CDF8EB21576F757
|_ Výrobce: Miranda
|_ Procesy
|_ miranda32.exe (884)
[?] srmm.dll
|_ Cesta: C:\Program Files\Miranda IM\Plugins\srmm.dll
|_ MD5: FEFE4200173A7EB6407C20B1A23785A7
|_ Výrobce:
|_ Procesy
|_ miranda32.exe (884)
[?] yahoo.dll
|_ Cesta: C:\Program Files\Miranda IM\Plugins\Yahoo.dll
|_ MD5: A5B9948D511F18D2A9D58F062A424FA1
|_ Výrobce: Gennady Feldman
|_ Procesy
|_ miranda32.exe (884)
[?] dbx_mmap.dll
|_ Cesta: C:\Program Files\Miranda IM\Plugins\dbx_mmap.dll
|_ MD5: 76DA4B6BAC25968E7D0EE599FAE269D4
|_ Výrobce: ?
|_ Procesy
|_ miranda32.exe (884)
[?] clist_classic.dll
|_ Cesta: C:\Program Files\Miranda IM\Plugins\clist_classic.dll
|_ MD5: 09CF9316D642B03FC7CF92D094D1F01D
|_ Výrobce:
|_ Procesy
|_ miranda32.exe (884)
[?] zlib.dll
|_ Cesta: C:\Program Files\Miranda IM\zlib.dll
|_ MD5: 0D353FF49982ACEC60924FEA5779C8A6
|_ Výrobce: ?
|_ Procesy
|_ miranda32.exe (884)
[?] msn.dll
|_ Cesta: C:\Program Files\Miranda IM\Plugins\msn.dll
|_ MD5: E3ECDE1731344CEA70052724E7F23500
|_ Výrobce: Boris Krasnovskiy, George Hazan, Richard Hughes
|_ Procesy
|_ miranda32.exe (884)
[?] import.dll
|_ Cesta: C:\Program Files\Miranda IM\Plugins\import.dll
|_ MD5: C2CF0EF83F17151DD2E89D9FF875A82F
|_ Výrobce:
|_ Procesy
|_ miranda32.exe (884)
[?] gg.dll
|_ Cesta: C:\Program Files\Miranda IM\Plugins\GG.dll
|_ MD5: 73399E24884D5144072C309B6A4ECA93
|_ Výrobce:
|_ Procesy
|_ miranda32.exe (884)
[?] irc.dll
|_ Cesta: C:\Program Files\Miranda IM\Plugins\IRC.dll
|_ MD5: 0C0E0A54DEAF97E706A44EBD5BAF1822
|_ Výrobce: ?
|_ Procesy
|_ miranda32.exe (884)
[?] adobe air.dll
|_ Cesta: C:\Program Files\Dofus 2\app\.runtime\1.5\Adobe AIR.dll
|_ MD5: CB68681427F01419941264F1A01B1608
|_ Výrobce:
|_ Procesy
|_ DofusMod.exe (3624)
[X] lde.dll
|_ Cesta: C:\Program Files\Ultimate Process Manager\LDE.dll
|_ MD5: 0F13A4173A599AAA15E3B270E5E27A7F
|_ Výrobce:
|_ Procesy
|_ UPM.exe (2648)
[?] upm.dll
|_ Cesta: C:\Program Files\Ultimate Process Manager\upm.dll
|_ MD5: 9D9AA74910EE283E95214ABEADC779BD
|_ Výrobce: Lodus Software
|_ Procesy
|_ UPM.exe (2648)
[!] prjxtab.ocx
|_ Cesta: C:\Program Files\Ultimate Process Manager\prjXTab.ocx
|_ MD5: DE745F09FC7C607841519AD559C33AC3
|_ Výrobce: xyz
|_ Procesy
|_ UPM.exe (2648)
================================================================
Ultimate Process Manager v4.1.3 - [ Lodus Software ]
---------------------------------------------------------------------------------------------------------------
prosim o kontrolu logu. Zrejme se v nem skryva neco, co by nemelo. Uz tri dny mi pocitac samovolne vypina zvuk. Dnes dokonce zacal samovolne vyskakovat IE a to uz bylo i na me moc. Tak jsem aktualizoval, stahnul Avast. Ten nic nenasel. Nasadil jsem spyterminator, ktery nasel 4 veci, nejzavaznejsi bylo asi smss.exe, ktere se mi jak doufam podarilo odstranit. Nicmene problem se stale vyskytuje a nic jineho mi to nenaslo. Kdyz budete mit nekdo chvilku, tak se na to podivejte, neb pro me je to srozumitelne asi jako indian mluvici mandarinsky. Dik
prikladam logy u UPM a RSIT
Logfile of random's system information tool 1.07 (written by random/random)
Run by Administrator at 2010-06-29 23:28:53
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 34 GB (56%) free of 60 GB
Total RAM: 2046 MB (68% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:28:57, on 29.6.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\vsnp2uvc.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\TO2SSM\McciTrayApp.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Crawler\Toolbar\CToolbar.exe
C:\Program Files\Miranda IM\miranda32.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
E:\Ondra\Filmy\RSIT.exe
C:\Program Files\trend micro\Administrator.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cz.o2.com/welcome/cz/index.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Crawler lišta - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [snp2uvc] C:\WINDOWS\vsnp2uvc.exe
O4 - HKLM\..\Run: [tsnp2uvc] C:\WINDOWS\tsnp2uvc.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [TO2SSM_McciTrayApp] C:\Program Files\TO2SSM\McciTrayApp.exe
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://lnpha1.cdtel.cz/iNotes6W.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
--
End of file - 6751 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2010-06-25 1241552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-03-07 35840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-03-07 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{4B3803EA-5230-4DC3-A7FC-33638F3D3542} - &Crawler lišta - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2010-06-25 1241552]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2003-04-07 155648]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2003-04-07 114688]
"snp2uvc"=C:\WINDOWS\vsnp2uvc.exe [2007-05-15 675840]
"tsnp2uvc"=C:\WINDOWS\tsnp2uvc.exe [2007-04-24 237568]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-03-07 148888]
"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2003-10-31 32768]
"TO2SSM_McciTrayApp"=C:\Program Files\TO2SSM\McciTrayApp.exe [2008-08-15 1473536]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-06-28 2837864]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"PC Suite Tray"=C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2009-11-11 1451520]
"SpywareTerminatorUpdate"=C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2010-06-29 3037696]
C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\Po spuštění
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE
VPN Client.lnk - C:\WINDOWS\Installer\{A7091E1D-36A4-47F1-A739-173CC341414F}\Icon3E5562ED7.ico
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxsrvc.dll [2003-04-07 315392]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Miranda IM\miranda32.exe"="C:\Program Files\Miranda IM\miranda32.exe:*:Enabled:Miranda IM"
"C:\Program Files\Swapper\swapper.exe"="C:\Program Files\Swapper\swapper.exe:*:Enabled:swapper"
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Soldat\Soldat.exe"="C:\Soldat\Soldat.exe:*:Enabled:http://soldat.pl"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe"="C:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe:*:Enabled:Nokia Software Updater"
"C:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe"="C:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe:*:Enabled:Nokia Service Layer Host Process "
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"="C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe:*:Enabled:Crawler Spyware Terminator"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4484d7a0-3850-11df-9039-000f1f8c0c9b}]
shell\AutoRun\command - H:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4484d7a1-3850-11df-9039-000f1f8c0c9b}]
shell\AutoRun\command - H:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{46d483b8-3b52-11df-903f-000f1f8c0c9b}]
shell\AutoRun\command - I:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fad44db2-9f06-11de-8f59-000f1f8c0c9b}]
shell\AutoRun\command - H:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fad44db5-9f06-11de-8f59-000f1f8c0c9b}]
shell\AutoRun\command - H:\AutoRun.exe
======List of files/folders created in the last 1 months======
2010-06-29 23:18:44 ----D---- C:\Program Files\trend micro
2010-06-29 23:18:43 ----D---- C:\rsit
2010-06-29 22:45:25 ----D---- C:\Program Files\Ultimate Process Manager
2010-06-29 20:41:52 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2010-06-29 20:37:36 ----HDC---- C:\WINDOWS\$NtUninstallKB980195$
2010-06-29 20:37:18 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2010-06-29 20:34:28 ----SHD---- C:\Config.Msi
2010-06-29 20:31:45 ----HDC---- C:\WINDOWS\$NtUninstallKB981793$
2010-06-29 20:31:39 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2010-06-29 20:31:16 ----D---- C:\Program Files\Crawler
2010-06-29 20:30:56 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Spyware Terminator
2010-06-29 20:30:52 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Spyware Terminator
2010-06-29 20:30:50 ----D---- C:\Program Files\Spyware Terminator
2010-06-29 20:28:27 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2010-06-29 20:28:19 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2010-06-29 20:28:11 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2010-06-29 20:21:04 ----HDC---- C:\WINDOWS\$NtUninstallKB982381$
2010-06-29 19:01:31 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-06-29 18:49:37 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Alwil Software
======List of files/folders modified in the last 1 months======
2010-06-29 23:18:44 ----RD---- C:\Program Files
2010-06-29 23:05:32 ----D---- C:\WINDOWS\Temp
2010-06-29 22:46:10 ----D---- C:\WINDOWS\system32\CatRoot2
2010-06-29 22:31:32 ----D---- C:\RP6
2010-06-29 22:31:28 ----D---- C:\WINDOWS\Prefetch
2010-06-29 21:38:42 ----RSD---- C:\WINDOWS\assembly
2010-06-29 21:38:42 ----D---- C:\WINDOWS\Microsoft.NET
2010-06-29 21:06:30 ----D---- C:\Program Files\Mozilla Firefox
2010-06-29 21:04:01 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Skype
2010-06-29 21:02:49 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-06-29 20:44:58 ----D---- C:\WINDOWS
2010-06-29 20:44:03 ----D---- C:\WINDOWS\system32
2010-06-29 20:41:57 ----HD---- C:\WINDOWS\inf
2010-06-29 20:41:55 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-06-29 20:41:48 ----SHD---- C:\WINDOWS\Installer
2010-06-29 20:41:32 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-06-29 20:41:07 ----D---- C:\WINDOWS\WinSxS
2010-06-29 20:39:18 ----D---- C:\WINDOWS\system32\CatRoot
2010-06-29 20:37:40 ----A---- C:\WINDOWS\imsins.BAK
2010-06-29 20:37:35 ----HD---- C:\WINDOWS\$hf_mig$
2010-06-29 20:31:13 ----D---- C:\WINDOWS\system32\drivers
2010-06-29 20:04:24 ----A---- C:\WINDOWS\NeroDigital.ini
2010-06-29 18:53:10 ----D---- C:\Documents and Settings\Administrator\Data aplikací\skypePM
2010-06-29 18:52:30 ----D---- C:\Program Files\Alwil Software
2010-06-29 18:37:40 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Dofus 2
2010-06-28 20:21:55 ----D---- C:\Documents and Settings
2010-06-10 23:42:58 ----SD---- C:\Documents and Settings\Administrator\Data aplikací\Microsoft
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-06-28 28880]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-06-28 165456]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-06-28 46672]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 OMCI;OMCI; C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS [2001-08-22 13632]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2009-03-22 5632]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-06-28 17744]
R2 aswMon2;aswMon2; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-06-28 100176]
R2 CVPNDRVA;Cisco Systems Inc. IPSec Driver; \??\C:\WINDOWS\system32\Drivers\CVPNDRVA.sys []
R3 {6080A529-897E-4629-A488-ABA0C29B635E};Intel(R) Graphics Platform (SoftBIOS) Driver; C:\WINDOWS\system32\drivers\ialmsbw.sys [2003-04-15 113504]
R3 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91};Intel(R) Graphics Chipset (KCH) Driver; C:\WINDOWS\system32\drivers\ialmkchw.sys [2003-04-15 78752]
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2002-04-01 4816]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-06-28 23376]
R3 DNE;Deterministic Network Enhancer Miniport; C:\WINDOWS\system32\DRIVERS\dne2000.sys [2008-03-29 125328]
R3 Dot4;Ovladač MS IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2008-04-14 206976]
R3 Dot4Print;Ovladač třídy tiskárny standardu IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys [2001-08-17 12928]
R3 E1000;Intel(R) PRO/1000 Adapter Driver; C:\WINDOWS\system32\DRIVERS\e1000325.sys [2003-03-08 121344]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2003-04-15 90907]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2003-02-28 545024]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S2 BT848;bt848 tweaked WDM Video Capture; C:\WINDOWS\system32\drivers\BT848.sys [2001-10-08 208191]
S2 BTTUNER;bt848 tweaked WDM TvTuner; C:\WINDOWS\system32\drivers\BTTUNER.sys [2001-10-08 9187]
S2 BTXBAR;bt848 tweaked TV WDM Crossbar; C:\WINDOWS\system32\drivers\BTXBAR.sys [2001-10-08 8193]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 CVirtA;Cisco Systems VPN Adapter; C:\WINDOWS\system32\DRIVERS\CVirtA.sys [2007-01-18 5275]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys [2008-09-26 101376]
S3 MREMP50;MREMP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS []
S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS []
S3 MREMPR5;MREMPR5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS []
S3 MRENDIS5;MRENDIS5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS []
S3 MRESP50;MRESP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS []
S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 nm;Ovladač programu Sledování sítě; C:\WINDOWS\system32\DRIVERS\NMnt.sys [2008-04-14 40320]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2010-02-26 18176]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2010-02-26 22528]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; C:\WINDOWS\system32\drivers\nmwcdnsu.sys [2010-02-26 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic; C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2010-02-26 8320]
S3 NPF;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2007-11-06 34064]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\WINDOWS\system32\DRIVERS\snp2uvc.sys [2007-06-06 9604864]
S3 sscdbus;SAMSUNG USB Composite Device driver (WDM); C:\WINDOWS\system32\DRIVERS\sscdbus.sys [2008-02-22 87936]
S3 sscdmdfl;SAMSUNG Mobile Modem Filter; C:\WINDOWS\system32\DRIVERS\sscdmdfl.sys [2008-02-22 14976]
S3 sscdmdm;SAMSUNG Mobile Modem Drivers; C:\WINDOWS\system32\DRIVERS\sscdmdm.sys [2008-02-22 114304]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2010-02-26 8192]
S3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-14 60032]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-14 26112]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2010-02-26 8192]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-14 121984]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-06-28 40384]
R2 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
R2 CVPND;Cisco Systems, Inc. VPN Service; C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe [2008-06-19 1528608]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-01-17 61440]
R2 McciCMService;McciCMService; C:\Program Files\Common Files\Motive\McciCMService.exe [2007-10-15 303104]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2001-02-23 270336]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2010-06-29 488960]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-06-28 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-06-28 40384]
R3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-04-27 611840]
S2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe -service -config C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf []
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-03-26 779824]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-03-26 267824]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe [2007-11-06 92792]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
====================================================================
UPM:
Windows XP SP 3 (build 2600)
Boot Mode: Normal
Ověření souborů Microsoftu: Ne
Whitelist: Ne
Internet Explorer v6.00.2900.5512 (xpsp.080413-2105)
Log vygenerován: 29.6.2010 22:46:02
================================================================
SmallARK
================================================================
[R]NtClose -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtCreateKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtDeleteKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtDeleteValueKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtDuplicateObject -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtOpenKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtOpenProcess -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtOpenThread -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtQueryValueKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtRenameKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtRestoreKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtSetValueKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
MBR ROOTKIT DETECTED!
Běžící procesy
================================================================
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST5\AVASTSVC.EXE
C:\WINDOWS\SYSTEM32\IGFXTRAY.EXE
C:\WINDOWS\SYSTEM32\HKCMD.EXE
C:\WINDOWS\VSNP2UVC.EXE
C:\PROGRAM FILES\JAVA\JRE6\BIN\JUSCHED.EXE
C:\PROGRAM FILES\CYBERLINK\POWERDVD\PDVDSERV.EXE
C:\PROGRAM FILES\TO2SSM\MCCITRAYAPP.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST5\AVASTUI.EXE
C:\WINDOWS\SYSTEM32\CTFMON.EXE
C:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 7\PCSUITE.EXE
C:\PROGRAM FILES\SPYWARE TERMINATOR\SPYWARETERMINATORUPDATE.EXE
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V2.0.50727\MSCORSVW.EXE
C:\PROGRAM FILES\CISCO SYSTEMS\VPN CLIENT\CVPND.EXE
C:\PROGRAM FILES\JAVA\JRE6\BIN\JQS.EXE
C:\PROGRAM FILES\COMMON FILES\LIGHTSCRIBE\LSSRVC.EXE
C:\PROGRAM FILES\COMMON FILES\MOTIVE\MCCICMSERVICE.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\MDM.EXE
C:\PROGRAM FILES\SPYWARE TERMINATOR\SP_RSSER.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\WDFMGR.EXE
C:\PROGRAM FILES\PC CONNECTIVITY SOLUTION\SERVICELAYER.EXE
C:\WINDOWS\SYSTEM32\ALG.EXE
C:\PROGRAM FILES\PC CONNECTIVITY SOLUTION\TRANSPORTS\NCLUSBSRV.EXE
C:\PROGRAM FILES\PC CONNECTIVITY SOLUTION\TRANSPORTS\NCLRSSRV.EXE
C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE
C:\PROGRA~1\CRAWLER\TOOLBAR\CTOOLBAR.EXE
C:\PROGRAM FILES\MIRANDA IM\MIRANDA32.EXE
C:\PROGRA~1\CRAWLER\TOOLBAR\CTOOLBAR.EXE
C:\WINDOWS\SYSTEM32\TASKMGR.EXE
C:\PROGRAM FILES\DOFUS 2\APP\DOFUSMOD.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\ULTIMATE PROCESS MANAGER\UPM.EXE
Scanner
================================================================
[S] explorer.exe
Spouští se po startu HKLM Winlogon [Shell]
[?] igfxtray.exe
Non Microsoft v System32:
Spouští se po startu HKLM Run [IgfxTray]
[?] hkcmd.exe
Non Microsoft v System32:
Spouští se po startu HKLM Run [HotKeysCmds]
[?] vsnp2uvc.exe
Spouští se po startu HKLM Run [snp2uvc]
[R] jusched.exe
Spouští se po startu HKLM Run [SunJavaUpdateSched]
[?] PDVDServ.exe
Spouští se po startu HKLM Run [RemoteControl]
Soubor 7%
[?] McciTrayApp.exe
Spouští se po startu HKLM Run [TO2SSM_McciTrayApp]
Soubor 7%
[R] AvastUI.exe
Spouští se po startu HKLM Run [avast5]
Skrytá cesta EXE: C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
[S] ctfmon.exe
Spouští se po startu HKCU Run [CTFMON.EXE]
[?] PCSuite.exe
Spouští se po startu HKCU Run [PC Suite Tray]
Soubor 7%
[?] SpywareTerminatorUpdate.exe
Spouští se po startu HKCU Run [SpywareTerminatorUpdate]
EntryPoint v sekci: .ITEXT
|_ Celkový počet sekcí: 9
Soubor 70%
[R] mscorsvw.exe
Ověřený Microsoft: Ne
[?] LSSrvc.exe
Nemá okno
Soubor 7%
[?] McciCMService.exe
Nemá okno
Soubor 7%
[?] mdm.exe
Ověřený Microsoft: Ne
Nemá okno
Soubor 12%
[?] sp_rsser.exe
EntryPoint v sekci: .ITEXT
|_ Celkový počet sekcí: 9
Nemá okno
Soubor 70%
[?] ServiceLayer.exe
Soubor 7%
[?] NclUSBSrv.exe
Soubor 7%
[?] NclRSSrv.exe
Soubor 7%
[R] CToolbar.exe
EntryPoint v sekci: .ITEXT
|_ Celkový počet sekcí: 9
[?] miranda32.exe
Bez výrobce
Soubor 12%
[R] CToolbar.exe
EntryPoint v sekci: .ITEXT
|_ Celkový počet sekcí: 9
[?] DofusMod.exe
Bez výrobce
Soubor 25%
[?] UPM.exe
Soubor 7%
Po spuštění
================================================================
Moduly (Zobraz i bezpečné DLL: False, Jen bez výrobce: True, Zobraz registrované: False)
================================================================
[?] implode.dll
|_ Cesta: C:\Program Files\Corel\Shared\versions\implode.dll
|_ MD5: 6889755A917AA3C736B61842FBD3DA73
|_ Výrobce:
|_ Procesy
|_ explorer.exe (256)
[?] msvcr71.dll
|_ Cesta: C:\Program Files\Nero\Nero 7\Nero BackItUp\msvcr71.dll
|_ MD5: 86F1895AE8C5E8B17D99ECE768A70732
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ explorer.exe (256)
|_ jqs.exe (3084)
[?] rarext.dll
|_ Cesta: C:\Program Files\WinRAR\RarExt.dll
|_ MD5: A070B8C38CEB3A30CC18D1B7C433144C
|_ Výrobce: ?
|_ Procesy
|_ explorer.exe (256)
[?] vers232.dll
|_ Cesta: C:\Program Files\Corel\Shared\versions\vers232.dll
|_ MD5: 8693A9DD4A864ACF03F486707285C8A5
|_ Výrobce:
|_ Procesy
|_ explorer.exe (256)
[!] sptcontmenu.dll
|_ Cesta: C:\Program Files\Spyware Terminator\sptcontmenu.dll
|_ MD5: A5E97B2B88CC48FC178E88BF6E02F5EC
|_ Výrobce: Crawler.com
|_ Procesy
|_ explorer.exe (256)
[?] phonebrowser.dll
|_ Cesta: C:\Program Files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
|_ MD5: F0CBAF724FF71D400FF45FBCEC4F3898
|_ Výrobce: Nokia
|_ Procesy
|_ explorer.exe (256)
[?] ngscm.dll
|_ Cesta: C:\Program Files\Nokia\Nokia PC Suite 7\NGSCM.dll
|_ MD5: 83AB0FCCF90A395AE71B7EA931C90529
|_ Výrobce: Nokia
|_ Procesy
|_ explorer.exe (256)
[?] cversion.dll
|_ Cesta: C:\Program Files\Corel\Shared\versions\cversion.dll
|_ MD5: 4D291442F6FCF6495A51AFA22C1D1E7D
|_ Výrobce: Corel Corporation Limited
|_ Procesy
|_ explorer.exe (256)
[?] mccicontexthook_6-1-0_dsr.dll
|_ Cesta: C:\Program Files\Common Files\Motive\McciContextHook_6-1-0_DSR.dll
|_ MD5: D8B25453BD74930000E5A7AF1AE139A4
|_ Výrobce: Motive Communications, Inc.
|_ Procesy
|_ explorer.exe (256)
|_ igfxtray.exe (448)
|_ hkcmd.exe (456)
|_ McciTrayApp.exe (504)
|_ AvastUI.exe (528)
|_ ctfmon.exe (540)
|_ PCSuite.exe (596)
|_ SpywareTerminatorUpdate.exe (644)
|_ firefox.exe (1276)
|_ CToolbar.exe (3704)
|_ miranda32.exe (884)
|_ taskmgr.exe (3548)
|_ DofusMod.exe (3624)
|_ UPM.exe (2648)
[?] mfc71u.dll
|_ Cesta: C:\Program Files\Nero\Nero 7\Nero BackItUp\mfc71u.dll
|_ MD5: 7B93C623333F121DC9E689CCB1B7A733
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ explorer.exe (256)
[?] msvcp71.dll
|_ Cesta: C:\Program Files\Nero\Nero 7\Nero BackItUp\msvcp71.dll
|_ MD5: 561FA2ABB31DFA8FAB762145F81667C2
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ explorer.exe (256)
[?] arpot.dll
|_ Cesta: C:\Program Files\Alwil Software\Avast5\defs\10062900\ArPot.dll
|_ MD5: 14F84A5D3ED36D6C7269A496319BD5AF
|_ Výrobce: ALWIL Software
|_ Procesy
|_ AvastSvc.exe (288)
[?] clrcengine2.dll
|_ Cesta: C:\Program Files\CyberLink\Shared Files\CLRCEngine2.dll
|_ MD5: DAE211D3393343B2FAD71C65B20EC562
|_ Výrobce: CyberLink Corp.
|_ Procesy
|_ PDVDServ.exe (496)
[?] mccicontextdetectoremail_6-1-0_dsr.dll
|_ Cesta: C:\Program Files\Common Files\Motive\McciContextDetectorEmail_6-1-0_DSR.dll
|_ MD5: 408F0FEE14F7A93A9A5741D8BA5C83C1
|_ Výrobce: Motive Communications, Inc.
|_ Procesy
|_ McciTrayApp.exe (504)
[?] mccicontextx.dll
|_ Cesta: C:\Program Files\Common Files\Motive\McciContextX.dll
|_ MD5: 7F600419A94A1F175FABE0F15275583B
|_ Výrobce: Motive Communications, Inc.
|_ Procesy
|_ McciTrayApp.exe (504)
[?] mccicontextdetectorwin32_6-1-0_dsr.dll
|_ Cesta: C:\Program Files\Common Files\Motive\McciContextDetectorWin32_6-1-0_DSR.dll
|_ MD5: 6113EE7CB182422F21849B170CFBEB5B
|_ Výrobce: Motive Communications, Inc.
|_ Procesy
|_ McciTrayApp.exe (504)
[?] connapi.dll
|_ Cesta: C:\Program Files\PC Connectivity Solution\ConnAPI.dll
|_ MD5: 9BB2ED345B38157E8B2DB84E3EEB40E1
|_ Výrobce: Nokia.
|_ Procesy
|_ PCSuite.exe (596)
[?] daapi.dll
|_ Cesta: C:\Program Files\PC Connectivity Solution\DAAPI.dll
|_ MD5: F79194B03CBF2B52D5BD645BC76A5A62
|_ Výrobce: Nokia
|_ Procesy
|_ PCSuite.exe (596)
[?] pccs_abapi.dll
|_ Cesta: C:\Program Files\PC Connectivity Solution\PCCS_ABAPI.dll
|_ MD5: E7E98B1F8C0107E4B5BC0A83F39D64D5
|_ Výrobce: Nokia
|_ Procesy
|_ PCSuite.exe (596)
[?] confserver.dll
|_ Cesta: C:\Program Files\PC Connectivity Solution\ConfServer.dll
|_ MD5: CF7D4E7093E3EBDA24BEB8369F8823DB
|_ Výrobce: Nokia
|_ Procesy
|_ PCSuite.exe (596)
[?] qjpeg4.dll
|_ Cesta: C:\Program Files\Nokia\Nokia PC Suite 7\imageformats\qjpeg4.dll
|_ MD5: B6FAD59C92D1381D986CD7368A5291F4
|_ Výrobce:
|_ Procesy
|_ PCSuite.exe (596)
[?] qsvg4.dll
|_ Cesta: C:\Program Files\Nokia\Nokia PC Suite 7\imageformats\qsvg4.dll
|_ MD5: CB3B04A1D5E1F32D5E38974B5E077EA6
|_ Výrobce:
|_ Procesy
|_ PCSuite.exe (596)
[?] nglstyle.dll
|_ Cesta: C:\Program Files\Nokia\Nokia PC Suite 7\Styles\NGLStyle.dll
|_ MD5: 0435B351C4BBD710EFB2925966DB160F
|_ Výrobce: Nokia
|_ Procesy
|_ PCSuite.exe (596)
[?] cdc.dll
|_ Cesta: C:\Program Files\Nokia\Nokia PC Suite 7\CDC.dll
|_ MD5: D39835D21F82CEC4BCC0DC92A99C4B7E
|_ Výrobce: Nokia
|_ Procesy
|_ PCSuite.exe (596)
[?] qtxml4.dll
|_ Cesta: C:\Program Files\Nokia\Nokia PC Suite 7\QtXml4.dll
|_ MD5: B7AC803CF0DF5FF872DD45D48BBBDA6A
|_ Výrobce:
|_ Procesy
|_ PCSuite.exe (596)
[?] qtgui4.dll
|_ Cesta: C:\Program Files\Nokia\Nokia PC Suite 7\QtGUI4.dll
|_ MD5: 1CA1F99D167BB19F785F2D8582579CFB
|_ Výrobce:
|_ Procesy
|_ PCSuite.exe (596)
[?] qtsvg4.dll
|_ Cesta: C:\Program Files\Nokia\Nokia PC Suite 7\QtSvg4.dll
|_ MD5: 958BE76750B8B10750FB3DE7419588C1
|_ Výrobce:
|_ Procesy
|_ PCSuite.exe (596)
[?] qtcore4.dll
|_ Cesta: C:\Program Files\Nokia\Nokia PC Suite 7\QtCore4.dll
|_ MD5: 285A5075F1973E9BEB8A12EE3641EEA4
|_ Výrobce:
|_ Procesy
|_ PCSuite.exe (596)
[?] torentdll.dll
|_ Cesta: C:\Program Files\Spyware Terminator\TorentDll.dll
|_ MD5: 0B0387E70BE085C1842BC7DEB47EE54F
|_ Výrobce:
|_ Procesy
|_ SpywareTerminatorUpdate.exe (644)
[?] lssproxy.dll
|_ Cesta: C:\Program Files\Common Files\LightScribe\LSSProxy.dll
|_ MD5: D7EB32B51B7472FBEE86BFA47B3C4BC5
|_ Výrobce: Hewlett-Packard Company
|_ Procesy
|_ LSSrvc.exe (3104)
[?] lslog.dll
|_ Cesta: C:\Program Files\Common Files\LightScribe\LSLog.dll
|_ MD5: 0EE266A90D43E82A07CF33755D6DE1CC
|_ Výrobce: Hewlett-Packard Company
|_ Procesy
|_ LSSrvc.exe (3104)
[?] msdbg2.dll
|_ Cesta: C:\Program Files\Common Files\Microsoft Shared\VS7Debug\msdbg2.dll
|_ MD5: 882EAB3108383692506D32F637485C77
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ mdm.exe (3152)
|_ CToolbar.exe (3704)
[?] pccs_dbengine.dll
|_ Cesta: C:\Program Files\PC Connectivity Solution\PCCS_DBEngine.dll
|_ MD5: 27DD9CEA7B4C8EFAD06B55AED94AAAD7
|_ Výrobce: Nokia
|_ Procesy
|_ ServiceLayer.exe (3644)
[!] xcomm.dll
|_ Cesta: C:\Program Files\Crawler\Toolbar\firefox\components\xcomm.dll
|_ MD5: 25431E2DC58A422CE27C9F29D904E003
|_ Výrobce: Crawler.com
|_ Procesy
|_ firefox.exe (1276)
[?] xsupport.dll
|_ Cesta: C:\Program Files\Crawler\Toolbar\firefox\components\xsupport.dll
|_ MD5: 4C20A7877F340BE462807935C8013251
|_ Výrobce: Crawler.com
|_ Procesy
|_ firefox.exe (1276)
[!] xshared.dll
|_ Cesta: C:\Program Files\Crawler\Toolbar\firefox\components\xshared.dll
|_ MD5: B0170A9F1F0D9A668D815B3ECE135CB6
|_ Výrobce: Crawler.com
|_ Procesy
|_ firefox.exe (1276)
[!] xwsg.dll
|_ Cesta: C:\Program Files\Crawler\Toolbar\firefox\components\xwsg.dll
|_ MD5: DD248D5444448BC5182441922F3910C9
|_ Výrobce: Crawler.com
|_ Procesy
|_ firefox.exe (1276)
[?] softokn3.dll
|_ Cesta: C:\Program Files\Mozilla Firefox\softokn3.dll
|_ MD5: 35CF3FB481638306CA1A6A1A2F816D84
|_ Výrobce: Mozilla Foundation
|_ Procesy
|_ firefox.exe (1276)
[?] nssdbm3.dll
|_ Cesta: C:\Program Files\Mozilla Firefox\nssdbm3.dll
|_ MD5: F349B437ABE573013A673F0A82B1B08C
|_ Výrobce: Mozilla Foundation
|_ Procesy
|_ firefox.exe (1276)
[?] freebl3.dll
|_ Cesta: C:\Program Files\Mozilla Firefox\freebl3.dll
|_ MD5: 7ECFB8FFF406A664E35F36BDF915DFB9
|_ Výrobce: Mozilla Foundation
|_ Procesy
|_ firefox.exe (1276)
[!] ctbcomm.dll
|_ Cesta: C:\PROGRA~1\Crawler\Toolbar\ctbcomm.dll
|_ MD5: 562939F188B53D068834D0F6ACFC93F6
|_ Výrobce: Crawler.com
|_ Procesy
|_ CToolbar.exe (3704)
|_ CToolbar.exe (2404)
[!] websec~1.dll
|_ Cesta: C:\PROGRA~1\Crawler\Toolbar\WEBSEC~1.DLL
|_ MD5: 16042425E6BDF6AA012AFF5B851A16BC
|_ Výrobce: Crawler.com
|_ Procesy
|_ CToolbar.exe (3704)
|_ CToolbar.exe (2404)
[?] pdm.dll
|_ Cesta: C:\Program Files\Common Files\Microsoft Shared\VS7Debug\pdm.dll
|_ MD5: 349475945AA64B2992B2C35E5DDE5CAB
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ CToolbar.exe (3704)
[?] advaimg.dll
|_ Cesta: C:\Program Files\Miranda IM\Plugins\advaimg.dll
|_ MD5: AB2D0752C3A9268B117B27A97538660E
|_ Výrobce: Miranda IM and FreeImage
|_ Procesy
|_ miranda32.exe (884)
[?] aim.dll
|_ Cesta: C:\Program Files\Miranda IM\Plugins\Aim.dll
|_ MD5: EB561F92EC71A1AE811411DEDCE95DE1
|_ Výrobce:
|_ Procesy
|_ miranda32.exe (884)
[?] avs.dll
|_ Cesta: C:\Program Files\Miranda IM\Plugins\avs.dll
|_ MD5: 039838DA4A4D5E9EB94B4E312945F505
|_ Výrobce:
|_ Procesy
|_ miranda32.exe (884)
[?] chat.dll
|_ Cesta: C:\Program Files\Miranda IM\Plugins\chat.dll
|_ MD5: AB9ACA1DE13ED08561183F94479AD7D8
|_ Výrobce:
|_ Procesy
|_ miranda32.exe (884)
[?] icq.dll
|_ Cesta: C:\Program Files\Miranda IM\Plugins\ICQ.dll
|_ MD5: 6F45E63364B1D0783121EA22A29314B1
|_ Výrobce: ?
|_ Procesy
|_ miranda32.exe (884)
[?] jabber.dll
|_ Cesta: C:\Program Files\Miranda IM\Plugins\jabber.dll
|_ MD5: 90DCF1A753A024306CDF8EB21576F757
|_ Výrobce: Miranda
|_ Procesy
|_ miranda32.exe (884)
[?] srmm.dll
|_ Cesta: C:\Program Files\Miranda IM\Plugins\srmm.dll
|_ MD5: FEFE4200173A7EB6407C20B1A23785A7
|_ Výrobce:
|_ Procesy
|_ miranda32.exe (884)
[?] yahoo.dll
|_ Cesta: C:\Program Files\Miranda IM\Plugins\Yahoo.dll
|_ MD5: A5B9948D511F18D2A9D58F062A424FA1
|_ Výrobce: Gennady Feldman
|_ Procesy
|_ miranda32.exe (884)
[?] dbx_mmap.dll
|_ Cesta: C:\Program Files\Miranda IM\Plugins\dbx_mmap.dll
|_ MD5: 76DA4B6BAC25968E7D0EE599FAE269D4
|_ Výrobce: ?
|_ Procesy
|_ miranda32.exe (884)
[?] clist_classic.dll
|_ Cesta: C:\Program Files\Miranda IM\Plugins\clist_classic.dll
|_ MD5: 09CF9316D642B03FC7CF92D094D1F01D
|_ Výrobce:
|_ Procesy
|_ miranda32.exe (884)
[?] zlib.dll
|_ Cesta: C:\Program Files\Miranda IM\zlib.dll
|_ MD5: 0D353FF49982ACEC60924FEA5779C8A6
|_ Výrobce: ?
|_ Procesy
|_ miranda32.exe (884)
[?] msn.dll
|_ Cesta: C:\Program Files\Miranda IM\Plugins\msn.dll
|_ MD5: E3ECDE1731344CEA70052724E7F23500
|_ Výrobce: Boris Krasnovskiy, George Hazan, Richard Hughes
|_ Procesy
|_ miranda32.exe (884)
[?] import.dll
|_ Cesta: C:\Program Files\Miranda IM\Plugins\import.dll
|_ MD5: C2CF0EF83F17151DD2E89D9FF875A82F
|_ Výrobce:
|_ Procesy
|_ miranda32.exe (884)
[?] gg.dll
|_ Cesta: C:\Program Files\Miranda IM\Plugins\GG.dll
|_ MD5: 73399E24884D5144072C309B6A4ECA93
|_ Výrobce:
|_ Procesy
|_ miranda32.exe (884)
[?] irc.dll
|_ Cesta: C:\Program Files\Miranda IM\Plugins\IRC.dll
|_ MD5: 0C0E0A54DEAF97E706A44EBD5BAF1822
|_ Výrobce: ?
|_ Procesy
|_ miranda32.exe (884)
[?] adobe air.dll
|_ Cesta: C:\Program Files\Dofus 2\app\.runtime\1.5\Adobe AIR.dll
|_ MD5: CB68681427F01419941264F1A01B1608
|_ Výrobce:
|_ Procesy
|_ DofusMod.exe (3624)
[X] lde.dll
|_ Cesta: C:\Program Files\Ultimate Process Manager\LDE.dll
|_ MD5: 0F13A4173A599AAA15E3B270E5E27A7F
|_ Výrobce:
|_ Procesy
|_ UPM.exe (2648)
[?] upm.dll
|_ Cesta: C:\Program Files\Ultimate Process Manager\upm.dll
|_ MD5: 9D9AA74910EE283E95214ABEADC779BD
|_ Výrobce: Lodus Software
|_ Procesy
|_ UPM.exe (2648)
[!] prjxtab.ocx
|_ Cesta: C:\Program Files\Ultimate Process Manager\prjXTab.ocx
|_ MD5: DE745F09FC7C607841519AD559C33AC3
|_ Výrobce: xyz
|_ Procesy
|_ UPM.exe (2648)
================================================================
Ultimate Process Manager v4.1.3 - [ Lodus Software ]
---------------------------------------------------------------------------------------------------------------