Pomalý PC připojené do internetu
Napsal: 12 zář 2010 10:23
Zdravím.
PC po startu zoufale pomalé, když ho odpojím od netu, tak se chová korektně. Zapojím zpět a můžu pracovat. Prosím o kontrolu logu. (Mám trochu zmatek v tom, z čeho je nejlepší generovat log. Dal jsem UPM.)
Díky moc.
Windows XP SP 3 (build 2600)
Boot Mode: Normal
Microsoft files verification: Yes
Whitelist: Yes
Internet Explorer v7.00.6000.17080 (vista_gdr.100616-0452)
Log generated:12.9.2010 10:49:17
================================================================
SmallARK
================================================================
MBR ROOTKIT DETECTED!
Running processes
================================================================
C:\PROGRAM FILES\AVG\AVG9\AVGCHSVX.EXE
C:\PROGRAM FILES\AVG\AVG9\AVGRSX.EXE
C:\PROGRAM FILES\AVG\AVG9\AVGCSRVX.EXE
C:\PROGRAM FILES\AVG\AVG9\AVGWDSVC.EXE
C:\WINXP\SYSTEM32\BGSVCGEN.EXE
C:\PROGRAM FILES\JAVA\JRE6\BIN\JQS.EXE
C:\PROGRAM FILES\CDBURNERXP\NMSACCESSU.EXE
C:\PROGRAM FILES\AVG\AVG9\AVGEMC.EXE
C:\PROGRAM FILES\AVG\AVG9\AVGNSX.EXE
C:\PROGRAM FILES\AVG\AVG9\AVGCSRVX.EXE
C:\WINXP\SOUNDMAN.EXE
C:\PROGRAM FILES\ADOBE\READER 9.0\READER\READER_SL.EXE
C:\PROGRAM FILES\QUICKTIME\QTTASK.EXE
C:\PROGRA~1\AVG\AVG9\AVGTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\JAVA\JAVA UPDATE\JUSCHED.EXE
C:\PROGRAM FILES\OLYMPUS\OLYMPUS MASTER\MONITOR.EXE
C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBARNOTIFIER\GOOGLETOOLBARNOTIFIER.EXE
Scanner
================================================================
[?] avgchsvx.exe
No window
File 7%
[?] avgrsx.exe
Similar names: AVGRSX.EXE X AVGNSX.EXE
No window
File 7%
[?] avgcsrvx.exe
No window
File 7%
[?] avgwdsvc.exe
No window
File 7%
[?] bgsvcgen.exe
Non Microsoft in System32:
No window
File 7%
[?] jqs.exe
No window
File 7%
[?] NMSAccessU.exe
Without manufacturer
No window
File 12%
[?] avgemc.exe
No window
File 7%
[?] avgnsx.exe
Similar names: AVGNSX.EXE X AVGRSX.EXE
No window
File 7%
[?] avgcsrvx.exe
No window
File 7%
[S] explorer.exe
Startup entry HKLM Winlogon [Shell]
[?] soundman.exe
Startup entry HKLM Run [SoundMan]
[?] reader_sl.exe
Startup entry HKLM Run [Adobe Reader Speed Launcher]
File 7%
[?] QTTask.exe
Startup entry HKLM Run [QuickTime Task]
File 7%
[?] avgtray.exe
Startup entry HKLM Run [AVG9_TRAY]
File 7%
[?] jusched.exe
Startup entry HKLM Run [SunJavaUpdateSched]
No window
File 7%
[S] ctfmon.exe
Startup entry HKCU Run [CTFMON.EXE]
[?] Monitor.exe
Startup entry HKCU Run [OM_Monitor]
File 14%
[?] GoogleToolbarNotifier.exe
Startup entry HKCU Run [swg]
File 14%
[S] msmsgs.exe
Startup entry HKCU Run [MSMSGS]
Startup
================================================================
HKCU Run
|_ [?][OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
|_ [?][swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
|_ [S][MSMSGS] C:\Program Files\Messenger\msmsgs.exe /background
|_ [X][ICQ] C:\Program Files\ICQ7.1\ICQ.exe silent loginmode=4 (File not found)
HKLM Run
|_ [?][SoundMan] C:\WINXP\SOUNDMAN.EXE
|_ [?][Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
|_ [?][QuickTime Task] C:\Program Files\QuickTime\QTTask.exe -atboottime
|_ [?][OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
|_ [?][AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
|_ [?][SunJavaUpdateSched] C:\Program Files\Common Files\Java\Java Update\jusched.exe
HKLM ShellServiceObjectDelayLoad
|_ [?][WebCheck] C:\WINXP\system32\webcheck.dll
|_ [?][PostBootReminder] C:\WINXP\system32\SHELL32.dll
|_ [?][CDBurn] C:\WINXP\system32\SHELL32.dll
HKLM IC
|_ [?][<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}] C:\WINXP\system32\ieudinit.exe
|_ [?][>{26923b43-4d38-484f-9b9e-de460746276c}] C:\WINXP\system32\ie4uinit.exe -UserIconConfig
|_ [X][>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP (File not found)
|_ [?][{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] C:\WINXP\INF\msnetmtg.inf ,NetMtg.Install.PerUser.NT
|_ [?][{5945c046-1e7d-11d1-bc44-00c04fd912be}] C:\WINXP\INF\msmsgs.inf ,BLC.QuietInstall.PerUser
|_ [?][{6BF52A52-394A-11d3-B153-00C04F79FAA6}] C:\WINXP\INF\wmp.inf ,PerUserStub
|_ [?][{89820200-ECBD-11cf-8B85-00AA005B4340}] regsvr32.exe /s /n /i:U shell32.dll
|_ [?][{89820200-ECBD-11cf-8B85-00AA005B4383}] C:\WINXP\system32\ie4uinit.exe -BaseSettings
HKLM Winlogon Notify
|_ [?][avgrsstarter] C:\WINXP\system32\avgrsstx.dll
Job
|_ [?][APPLES~1.JOB] C:\Program Files\Apple Software Update\SoftwareUpdate.exe
|_ [?][GOOGLE~2.JOB] C:\Program Files\Google\Update\GoogleUpdate.exe
|_ [?][GOOGLE~3.JOB] C:\Program Files\Google\Update\GoogleUpdate.exe
HKLM BHO
|_ [?][{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
|_ [?][{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}] C:\Program Files\AVG\AVG9\avgssie.dll
|_ [?][{A3BC75A2-1F87-4686-AA43-5347D756017C}] C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
|_ [?][{AA58ED58-01DD-4d91-8333-CF10577473F7}] C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
|_ [?][{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
|_ [?][{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}] C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
|_ [?][{DBC80044-A445-435b-BC74-9C25C1C588A9}] C:\Program Files\Java\jre6\bin\jp2ssv.dll
|_ [?][{E7E6F031-17CE-4C07-BC86-EABFE594F69C}] C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
HKCU IE WebBrowser Toolbar
|_ [?][{CCC7A320-B3CA-4199-B1A6-9F516DD69829}] C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
|_ [?][{2318C2B1-4965-11D4-9B18-009027A5CD4F}] C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
HKLM IE Toolbar
|_ [?][{CCC7A320-B3CA-4199-B1A6-9F516DD69829}] C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
|_ [?][{2318C2B1-4965-11d4-9B18-009027A5CD4F}] C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
Services (Display running: True, Display stopped: False, Display safe: False)
================================================================
[?] AVG Free E-mail Scanner
|_ Path: C:\Program Files\AVG\AVG9\avgemc.exe
| |_ Manufacturer: AVG Technologies CZ, s.r.o.
| |_ Description: AVG E-Mail Scanner
| |_ MD5: AA054CD537357F03D5BA6ABA7562B35F
|
|_ Name: avg9emc
|_ StartName: LocalSystem
|_ Startup type: Auto Start
|_ Status: Running
|_ Type: Win32 Own Process
|_ Dependency: RPCSS
[?] AVG Free WatchDog
|_ Path: C:\Program Files\AVG\AVG9\avgwdsvc.exe
| |_ Manufacturer: AVG Technologies CZ, s.r.o.
| |_ Description: AVG Watchdog Service
| |_ MD5: C4D15594DB5BE042D3346EA58DF87D89
|
|_ Name: avg9wd
|_ StartName: LocalSystem
|_ Startup type: Auto Start
|_ Status: Running
|_ Type: Win32 Own Process
|_ Dependency:
[?] B's Recorder GOLD Library General Service
|_ Path: C:\WINXP\system32\bgsvcgen.exe
| |_ Manufacturer: B.H.A Corporation
| |_ Description: B's Recorder GOLD Service Library
| |_ MD5: 71489FA2C4A238F178E30AE6E4449013
|
|_ Name: bgsvcgen
|_ StartName: LocalSystem
|_ Startup type: Auto Start
|_ Status: Running
|_ Type: Win32 Own Process
|_ Dependency:
[X] Sluba Google Update (gupdate1ca8bc2e3eccd06)
|_ Path: C:\Program Files\Google\Update\GoogleUpdate.exe /svc
| |_ Manufacturer:
| |_ Description:
| |_ MD5:
|
|_ Name: gupdate1ca8bc2e3eccd06
|_ StartName: LocalSystem
|_ Startup type: Auto Start
|_ Status: Stopped
|_ Type: Win32 Own Process
|_ Dependency: RPCSS
[X] Java Quick Starter
|_ Path: C:\Program Files\Java\jre6\bin\jqs.exe -service -config C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf
| |_ Manufacturer:
| |_ Description:
| |_ MD5:
|
|_ Name: JavaQuickStarterService
|_ StartName: LocalSystem
|_ Startup type: Auto Start
|_ Status: Running
|_ Type: Win32 Own Process
|_ Dependency:
[?] Pracovní stanice
|_ Path: C:\WINXP\system32\svchost.exe
| |_ Manufacturer: Microsoft Corporation
| |_ Description: Generic Host Process for Win32 Services
| |_ MD5: BE4A520E29B6391F49E79CCC52044D93
|
|_ ServiceDLL: C:\WINXP\System32\wkssvc.dll
| |_ Manufacturer: Microsoft Corporation
| |_ Description: Workstation Service DLL
| |_ MD5: 936C1D110232D23B621CB0196E4F80F0
|
|_ Name: lanmanworkstation
|_ StartName: LocalSystem
|_ Startup type: Auto Start
|_ Status: Running
|_ Type: Win32 Share Process
|_ Dependency:
[?] NMSAccessU
|_ Path: C:\Program Files\CDBurnerXP\NMSAccessU.exe
| |_ Manufacturer:
| |_ Description:
| |_ MD5: FD306FBCCE7ADB1077B709742E7148E9
|
|_ Name: NMSAccessU
|_ StartName: LocalSystem
|_ Startup type: Auto Start
|_ Status: Running
|_ Type: Win32 Own Process
|_ Dependency:
Drivers (Display running: True, Display stopped: False, Display safe: False)
================================================================
[?] Service for Realtek AC97 Audio (WDM)
|_ Path: C:\WINXP\system32\drivers\ALCXWDM.SYS
| |_ Manufacturer: Realtek Semiconductor Corp.
| |_ Description: Realtek AC'97 Audio Driver (WDM)
| |_ MD5: F3E15607BA53249C765E36388B332C2F
|
|_ Name: ALCXWDM
|_ StartName:
|_ Startup type: Manual startup
|_ Status: Running
|_ Type: Kernel Driver
|_ Dependency:
[?] AVG Free AVI Loader Driver x86
|_ Path: C:\WINXP\System32\Drivers\avgldx86.sys
| |_ Manufacturer: AVG Technologies CZ, s.r.o.
| |_ Description: AVG AVI Loader Driver
| |_ MD5: B8C187439D27ABA430DD69FDCF1FA657
|
|_ Name: AvgLdx86
|_ StartName:
|_ Startup type: System Start
|_ Status: Running
|_ Type: Kernel Driver
|_ Dependency:
[?] AVG Free On-access Scanner Minifilter Driver x86
|_ Path: C:\WINXP\System32\Drivers\avgmfx86.sys
| |_ Manufacturer: AVG Technologies CZ, s.r.o.
| |_ Description: AVG Resident Shield Minifilter Driver
| |_ MD5: 53B3F979930A786A614D29CAFE99F645
|
|_ Name: AvgMfx86
|_ StartName:
|_ Startup type: System Start
|_ Status: Running
|_ Type: File System Driver
|_ Dependency:
[?] AVG Free Network Redirector
|_ Path: C:\WINXP\System32\Drivers\avgtdix.sys
| |_ Manufacturer: AVG Technologies CZ, s.r.o.
| |_ Description: AVG Network connection watcher
| |_ MD5: 22E3B793C3E61720F03D3A22351AF410
|
|_ Name: AvgTdiX
|_ StartName:
|_ Startup type: System Start
|_ Status: Running
|_ Type: Kernel Driver
|_ Dependency:
[?] cdrbsdrv
|_ Path: C:\WINXP\system32\drivers\cdrbsdrv.sys
| |_ Manufacturer: B.H.A Corporation
| |_ Description: CD-ROM Filter Driver for Windows2000/xp
| |_ MD5: 248349293CA42EE5DB61DC1FD85A2F49
|
|_ Name: cdrbsdrv
|_ StartName:
|_ Startup type: System Start
|_ Status: Running
|_ Type: Kernel Driver
|_ Dependency:
[?] HTTP
|_ Path: C:\WINXP\System32\Drivers\HTTP.sys
| |_ Manufacturer: Microsoft Corporation
| |_ Description: HTTP Protocol Stack
| |_ MD5: F80A415EF82CD06FFAF0D971528EAD38
|
|_ Name: HTTP
|_ StartName:
|_ Startup type: Manual startup
|_ Status: Running
|_ Type: Kernel Driver
|_ Dependency:
[?] MRXSMB
|_ Path: C:\WINXP\system32\DRIVERS\mrxsmb.sys
| |_ Manufacturer: Microsoft Corporation
| |_ Description: Windows NT SMB Minirdr
| |_ MD5: F3AEFB11ABC521122B67095044169E98
|
|_ Name: MRxSmb
|_ StartName:
|_ Startup type: System Start
|_ Status: Running
|_ Type: File System Driver
|_ Dependency:
[?] nvatabus
|_ Path: C:\WINXP\system32\DRIVERS\nvatabus.sys
| |_ Manufacturer: NVIDIA Corporation
| |_ Description: NVIDIA® nForce(TM) IDE Performance Driver
| |_ MD5: 46DEED4C6C5FA765F9A2C723BE60348D
|
|_ Name: nvatabus
|_ StartName:
|_ Startup type: Boot Start
|_ Status: Running
|_ Type: Kernel Driver
|_ Dependency:
[?] NVIDIA Network Bus Enumerator
|_ Path: C:\WINXP\system32\DRIVERS\nvnetbus.sys
| |_ Manufacturer: NVIDIA Corporation
| |_ Description: NVIDIA Networking Bus Driver.
| |_ MD5: BCC3722A2DB99AD6F367344997C26654
|
|_ Name: nvnetbus
|_ StartName:
|_ Startup type: Manual startup
|_ Status: Running
|_ Type: Kernel Driver
|_ Dependency:
[?] NVIDIA nForce AGP Bus Filter
|_ Path: C:\WINXP\system32\DRIVERS\nv_agp.sys
| |_ Manufacturer: NVIDIA Corporation
| |_ Description: NVIDIA nForce AGP Filter
| |_ MD5: C0FCD544A1C4EEA6D11A0AE6A07DAC9D
|
|_ Name: nv_agp
|_ StartName:
|_ Startup type: Boot Start
|_ Status: Running
|_ Type: Kernel Driver
|_ Dependency:
[?] PxHelp20
|_ Path: C:\WINXP\System32\Drivers\PxHelp20.sys
| |_ Manufacturer: Sonic Solutions
| |_ Description: Px Engine Device Driver for Windows 2000/XP
| |_ MD5: D86B4A68565E444D76457F14172C875A
|
|_ Name: PxHelp20
|_ StartName:
|_ Startup type: Boot Start
|_ Status: Running
|_ Type: Kernel Driver
|_ Dependency:
[?] Srv
|_ Path: C:\WINXP\system32\DRIVERS\srv.sys
| |_ Manufacturer: Microsoft Corporation
| |_ Description: Server driver
| |_ MD5: DA852E3E0BF1CEA75D756F9866241E57
|
|_ Name: Srv
|_ StartName:
|_ Startup type: Manual startup
|_ Status: Running
|_ Type: File System Driver
|_ Dependency:
lNetStat
================================================================
Type: PID Process Local <-> Remote Status
------------------------------------------------------------------------------------------
TCP (796) svchost.exe 0.0.0.0:135 LISTENING
TCP (4) System 0.0.0.0:445 LISTENING
TCP (1736) alg.exe 127.0.0.1:1025 LISTENING
TCP (1632) jqs.exe 127.0.0.1:5152 LISTENING
UDP (4) System 0.0.0.0:445 LISTENING
UDP (588) lsass.exe 0.0.0.0:500
UDP (588) lsass.exe 0.0.0.0:4500
UDP (836) svchost.exe 127.0.0.1:123
UDP (1008) svchost.exe 127.0.0.1:1900
Modules (Display safe: False, Only without manufacturer: True, Display registered: False)
================================================================
[?] avgrsstx.dll
|_ Path: C:\WINXP\system32\avgrsstx.dll
|_ MD5: D2A2B291414EB3D256B9E49331ED06C3
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ winlogon.exe (532)
[?] avgclitx.dll
|_ Path: C:\Program Files\AVG\AVG9\avgclitx.dll
|_ MD5: 5412B19162D52E9DE9E83534613E664E
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgchsvx.exe (952)
[?] avglogx.dll
|_ Path: C:\Program Files\AVG\AVG9\avglogx.dll
|_ MD5: 4A2FC89ED82ABE547DDE1B7443C5F321
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgchsvx.exe (952)
|_ avgrsx.exe (960)
|_ avgcsrvx.exe (1080)
|_ avgwdsvc.exe (1528)
|_ avgemc.exe (2044)
|_ avgnsx.exe (164)
|_ avgcsrvx.exe (368)
|_ avgtray.exe (2628)
[?] avgcertx.dll
|_ Path: C:\Program Files\AVG\AVG9\avgcertx.dll
|_ MD5: 6ABB7C1BB86021268BFD0DAC655BED2E
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgchsvx.exe (952)
|_ avgcsrvx.exe (1080)
|_ avgcsrvx.exe (368)
[?] avgchjwx.dll
|_ Path: C:\Program Files\AVG\AVG9\avgchjwx.dll
|_ MD5: A0C86DD4ADAD6C115322977159B32E19
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgchsvx.exe (952)
[?] avgcclix.dll
|_ Path: C:\Program Files\AVG\AVG9\avgcclix.dll
|_ MD5: 7F65F6F91690074AC3B02C14A10FCCCE
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgrsx.exe (960)
|_ avgemc.exe (2044)
[?] avgcorex.dll
|_ Path: C:\Program Files\AVG\AVG9\avgcorex.dll
|_ MD5: 48E09D07626921ADDD121725515B5AFD
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgcsrvx.exe (1080)
|_ avgcsrvx.exe (368)
[?] avgchclx.dll
|_ Path: C:\Program Files\AVG\AVG9\avgchclx.dll
|_ MD5: F284AD3887C458312797FD1F1A920498
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgcsrvx.exe (1080)
|_ avgcsrvx.exe (368)
[?] avgamnot.dll
|_ Path: C:\Program Files\AVG\AVG9\avgamnot.dll
|_ MD5: 6045FD764EA16155A7E28895FB442940
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgwdsvc.exe (1528)
[?] avgcfgx.dll
|_ Path: C:\Program Files\AVG\AVG9\avgcfgx.dll
|_ MD5: 37C58F3C25745E83BF5E141C3E7F555E
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgwdsvc.exe (1528)
|_ avgemc.exe (2044)
|_ avgnsx.exe (164)
|_ avgtray.exe (2628)
[?] avglngx.dll
|_ Path: C:\Program Files\AVG\AVG9\avglngx.dll
|_ MD5: 6E369ACB5D93EC872CABB3FB066FE96F
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgwdsvc.exe (1528)
|_ avgemc.exe (2044)
|_ avgtray.exe (2628)
[?] avgsched.dll
|_ Path: C:\Program Files\AVG\AVG9\avgsched.dll
|_ MD5: F34780EC4BA8D315F415D8DDAACA61D9
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgwdsvc.exe (1528)
[?] avgwd.dll
|_ Path: C:\Program Files\AVG\AVG9\avgwd.dll
|_ MD5: EC007398F0E040017965A4AE378477EE
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgwdsvc.exe (1528)
[?] avgwdwsc.dll
|_ Path: C:\Program Files\AVG\AVG9\avgwdwsc.dll
|_ MD5: 1768312EF86F64620ABBCE147BDB764D
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgwdsvc.exe (1528)
[?] aspnet_perf.dll
|_ Path: C:\WINXP\Microsoft.NET\Framework\v2.0.50727\Aspnet_perf.dll
|_ MD5: F1430F5D20F4BB71A003209C3DB3ADDF
|_ Manufacturer: Microsoft Corporation
|_ Processes
|_ jqs.exe (1632)
[?] corperfmonext.dll
|_ Path: C:\WINXP\Microsoft.NET\Framework\v2.0.50727\CORPerfMonExt.dll
|_ MD5: 2E61C409474416CC78D66300F1BCB722
|_ Manufacturer: Microsoft Corporation
|_ Processes
|_ jqs.exe (1632)
[?] netfxperf.dll
|_ Path: C:\WINXP\system32\netfxperf.dll
|_ MD5: 203D5ECB5CCDA683053CDA42DFF03573
|_ Manufacturer: Microsoft Corporation
|_ Processes
|_ jqs.exe (1632)
[?] perfcounter.dll
|_ Path: C:\WINXP\Microsoft.NET\Framework\v2.0.50727\PerfCounter.dll
|_ MD5: C5A9554406507AB2AB341B221D97519D
|_ Manufacturer: Microsoft Corporation
|_ Processes
|_ jqs.exe (1632)
[?] mscoree.dll
|_ Path: C:\WINXP\system32\mscoree.dll
|_ MD5: 08A73B0E7EE6E32983B5F9E540A8E380
|_ Manufacturer: Microsoft Corporation
|_ Processes
|_ jqs.exe (1632)
[?] mscorwks.dll
|_ Path: C:\WINXP\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
|_ MD5: 4ED92DC066A4DF8384A3E34E03F440FC
|_ Manufacturer: Microsoft Corporation
|_ Processes
|_ jqs.exe (1632)
[?] avgapix.dll
|_ Path: C:\Program Files\AVG\AVG9\avgapix.dll
|_ MD5: CCEAE95F3EC435D8C2603BB42CAF41DD
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgemc.exe (2044)
[?] avgmvflx.dll
|_ Path: C:\Program Files\AVG\AVG9\avgmvflx.dll
|_ MD5: 5A7D4F5D293B48584AE2112ED5DB4132
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgemc.exe (2044)
[?] avgscanx.dll
|_ Path: C:\Program Files\AVG\AVG9\avgscanx.dll
|_ MD5: 61C8FAE993D723E19078D4CAE8FC47A3
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgemc.exe (2044)
[?] avgsrmx.dll
|_ Path: C:\Program Files\AVG\AVG9\avgsrmx.dll
|_ MD5: E230DB9A3032E6D2BE44D61285085365
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgemc.exe (2044)
[?] avgvvx.dll
|_ Path: C:\Program Files\AVG\AVG9\avgvvx.dll
|_ MD5: 01C10B077D464FEA240A7B1B71A123BC
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgemc.exe (2044)
[?] libsasl.dll
|_ Path: C:\Program Files\AVG\AVG9\libsasl.dll
|_ MD5: 6BA10DE5FC60333BF2A7AFC94743F8CB
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgemc.exe (2044)
[?] saslplain.dll
|_ Path: C:\Program Files\AVG\AVG9\saslplain.dll
|_ MD5: 6DE53AF6695AA88E5D75C06014D84FA3
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgemc.exe (2044)
[?] sasllogin.dll
|_ Path: C:\Program Files\AVG\AVG9\sasllogin.dll
|_ MD5: 1DA5DAAF359873246D9642C65432B163
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgemc.exe (2044)
[?] saslcrammd5.dll
|_ Path: C:\Program Files\AVG\AVG9\saslcrammd5.dll
|_ MD5: 5A3F5083157788A4952AADB755AF7B1E
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgemc.exe (2044)
[?] sasldigestmd5.dll
|_ Path: C:\Program Files\AVG\AVG9\sasldigestmd5.dll
|_ MD5: FF42698F85DBEFF3729821D8A0E48B20
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgemc.exe (2044)
[?] olyuidrw.dll
|_ Path: C:\Program Files\OLYMPUS\OLYMPUS Master\olyuidrw.dll
|_ MD5: B8A71BCCE88CC6A8B0D821DF18950BB3
|_ Manufacturer: OLYMPUS IMAGING CORP.
|_ Processes
|_ Monitor.exe (2676)
[?] olyplgmgr.dll
|_ Path: C:\Program Files\OLYMPUS\OLYMPUS Master\OlyPlgMgr.dll
|_ MD5: 7E6DD8A6D2619ECBE508154EA7572862
|_ Manufacturer: OLYMPUS IMAGING CORP.
|_ Processes
|_ Monitor.exe (2676)
[?] olycamdetect.dll
|_ Path: C:\Program Files\OLYMPUS\OLYMPUS Master\OlyCamDetect.dll
|_ MD5: D0B850C181B0F80540E6F6138788B518
|_ Manufacturer: OLYMPUS IMAGING CORP.
|_ Processes
|_ Monitor.exe (2676)
[?] olapcevent.dll
|_ Path: C:\Program Files\OLYMPUS\OLYMPUS Master\OlAPCEvent.dll
|_ MD5: 1C69690C5336AFC9653D2A3AF914A2F3
|_ Manufacturer: OLYMPUS IMAGING CORP.
|_ Processes
|_ Monitor.exe (2676)
[?] olygloss.dll
|_ Path: C:\Program Files\OLYMPUS\OLYMPUS Master\OlyGloss.dll
|_ MD5: A843CC6DB39CF0467337F4D65A3C71E5
|_ Manufacturer: OLYMPUS IMAGING CORP.
|_ Processes
|_ Monitor.exe (2676)
[?] olyexiflib.dll
|_ Path: C:\Program Files\OLYMPUS\OLYMPUS Master\OlyExifLib.dll
|_ MD5: FA23A0DF3A062D1648F04718368091DC
|_ Manufacturer: OLYMPUS IMAGING CORP.
|_ Processes
|_ Monitor.exe (2676)
[?] olilevent.dll
|_ Path: C:\Program Files\OLYMPUS\OLYMPUS Master\OlILEvent.dll
|_ MD5: F99212BDFC4A1ACDFE0D991C8048F78E
|_ Manufacturer: OLYMPUS IMAGING CORP.
|_ Processes
|_ Monitor.exe (2676)
[?] olyrum.dll
|_ Path: C:\Program Files\OLYMPUS\OLYMPUS Master\OlyRum.dll
|_ MD5: CE96CF296AD92E5650080FBB0D669677
|_ Manufacturer: OLYMPUS IMAGING CORP.
|_ Processes
|_ Monitor.exe (2676)
[?] ptp-il.dll
|_ Path: C:\Program Files\OLYMPUS\OLYMPUS Master\PTP-IL.dll
|_ MD5: C59202534D7F802C5EE10828914D12EE
|_ Manufacturer: OLYMPUS IMAGING CORP.
|_ Processes
|_ Monitor.exe (2676)
[?] olcamapi.dll
|_ Path: C:\Program Files\OLYMPUS\OLYMPUS Master\Olcamapi.dll
|_ MD5: 79B8774EED4F86607C0AE48FDCC230EC
|_ Manufacturer: OLYMPUS OPTICAL CO.,LTD.
|_ Processes
|_ Monitor.exe (2676)
[?] olyuictl.dll
|_ Path: C:\Program Files\OLYMPUS\OLYMPUS Master\olyuictl.dll
|_ MD5: DCCCC6BEAAF866349F3D09E7FC43A530
|_ Manufacturer: OLYMPUS IMAGING CORP.
|_ Processes
|_ Monitor.exe (2676)
[?] mfc42.dll
|_ Path: C:\Program Files\OLYMPUS\OLYMPUS Master\MFC42.DLL
|_ MD5: F92E518180CF52FB526C7A76BD9AFD7E
|_ Manufacturer: Microsoft Corporation
|_ Processes
|_ Monitor.exe (2676)
[?] swg.dll
|_ Path: C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
|_ MD5: 42CB4EE0B0FC259C8AD20B460FA7D72A
|_ Manufacturer: Google Inc.
|_ Processes
|_ GoogleToolbarNotifier.exe (2708)
[?] gtn.dll
|_ Path: C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\gtn.dll
|_ MD5: EFC5461595187559BB61538143D035ED
|_ Manufacturer: Google Inc.
|_ Processes
|_ GoogleToolbarNotifier.exe (2708)
[?] mscomctl.ocx
|_ Path: C:\WINXP\system32\MSCOMCTL.OCX
|_ MD5: F7BBB7D79ADB9E3ADC13F3B3C33D3D4D
|_ Manufacturer: Microsoft Corporation
|_ Processes
|_ UPM.exe (3492)
================================================================
Ultimate Process Manager v4.1.3 - [ Lodus Software ] - Not Registered =(
PC po startu zoufale pomalé, když ho odpojím od netu, tak se chová korektně. Zapojím zpět a můžu pracovat. Prosím o kontrolu logu. (Mám trochu zmatek v tom, z čeho je nejlepší generovat log. Dal jsem UPM.)
Díky moc.
Windows XP SP 3 (build 2600)
Boot Mode: Normal
Microsoft files verification: Yes
Whitelist: Yes
Internet Explorer v7.00.6000.17080 (vista_gdr.100616-0452)
Log generated:12.9.2010 10:49:17
================================================================
SmallARK
================================================================
MBR ROOTKIT DETECTED!
Running processes
================================================================
C:\PROGRAM FILES\AVG\AVG9\AVGCHSVX.EXE
C:\PROGRAM FILES\AVG\AVG9\AVGRSX.EXE
C:\PROGRAM FILES\AVG\AVG9\AVGCSRVX.EXE
C:\PROGRAM FILES\AVG\AVG9\AVGWDSVC.EXE
C:\WINXP\SYSTEM32\BGSVCGEN.EXE
C:\PROGRAM FILES\JAVA\JRE6\BIN\JQS.EXE
C:\PROGRAM FILES\CDBURNERXP\NMSACCESSU.EXE
C:\PROGRAM FILES\AVG\AVG9\AVGEMC.EXE
C:\PROGRAM FILES\AVG\AVG9\AVGNSX.EXE
C:\PROGRAM FILES\AVG\AVG9\AVGCSRVX.EXE
C:\WINXP\SOUNDMAN.EXE
C:\PROGRAM FILES\ADOBE\READER 9.0\READER\READER_SL.EXE
C:\PROGRAM FILES\QUICKTIME\QTTASK.EXE
C:\PROGRA~1\AVG\AVG9\AVGTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\JAVA\JAVA UPDATE\JUSCHED.EXE
C:\PROGRAM FILES\OLYMPUS\OLYMPUS MASTER\MONITOR.EXE
C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBARNOTIFIER\GOOGLETOOLBARNOTIFIER.EXE
Scanner
================================================================
[?] avgchsvx.exe
No window
File 7%
[?] avgrsx.exe
Similar names: AVGRSX.EXE X AVGNSX.EXE
No window
File 7%
[?] avgcsrvx.exe
No window
File 7%
[?] avgwdsvc.exe
No window
File 7%
[?] bgsvcgen.exe
Non Microsoft in System32:
No window
File 7%
[?] jqs.exe
No window
File 7%
[?] NMSAccessU.exe
Without manufacturer
No window
File 12%
[?] avgemc.exe
No window
File 7%
[?] avgnsx.exe
Similar names: AVGNSX.EXE X AVGRSX.EXE
No window
File 7%
[?] avgcsrvx.exe
No window
File 7%
[S] explorer.exe
Startup entry HKLM Winlogon [Shell]
[?] soundman.exe
Startup entry HKLM Run [SoundMan]
[?] reader_sl.exe
Startup entry HKLM Run [Adobe Reader Speed Launcher]
File 7%
[?] QTTask.exe
Startup entry HKLM Run [QuickTime Task]
File 7%
[?] avgtray.exe
Startup entry HKLM Run [AVG9_TRAY]
File 7%
[?] jusched.exe
Startup entry HKLM Run [SunJavaUpdateSched]
No window
File 7%
[S] ctfmon.exe
Startup entry HKCU Run [CTFMON.EXE]
[?] Monitor.exe
Startup entry HKCU Run [OM_Monitor]
File 14%
[?] GoogleToolbarNotifier.exe
Startup entry HKCU Run [swg]
File 14%
[S] msmsgs.exe
Startup entry HKCU Run [MSMSGS]
Startup
================================================================
HKCU Run
|_ [?][OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
|_ [?][swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
|_ [S][MSMSGS] C:\Program Files\Messenger\msmsgs.exe /background
|_ [X][ICQ] C:\Program Files\ICQ7.1\ICQ.exe silent loginmode=4 (File not found)
HKLM Run
|_ [?][SoundMan] C:\WINXP\SOUNDMAN.EXE
|_ [?][Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
|_ [?][QuickTime Task] C:\Program Files\QuickTime\QTTask.exe -atboottime
|_ [?][OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
|_ [?][AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
|_ [?][SunJavaUpdateSched] C:\Program Files\Common Files\Java\Java Update\jusched.exe
HKLM ShellServiceObjectDelayLoad
|_ [?][WebCheck] C:\WINXP\system32\webcheck.dll
|_ [?][PostBootReminder] C:\WINXP\system32\SHELL32.dll
|_ [?][CDBurn] C:\WINXP\system32\SHELL32.dll
HKLM IC
|_ [?][<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}] C:\WINXP\system32\ieudinit.exe
|_ [?][>{26923b43-4d38-484f-9b9e-de460746276c}] C:\WINXP\system32\ie4uinit.exe -UserIconConfig
|_ [X][>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP (File not found)
|_ [?][{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] C:\WINXP\INF\msnetmtg.inf ,NetMtg.Install.PerUser.NT
|_ [?][{5945c046-1e7d-11d1-bc44-00c04fd912be}] C:\WINXP\INF\msmsgs.inf ,BLC.QuietInstall.PerUser
|_ [?][{6BF52A52-394A-11d3-B153-00C04F79FAA6}] C:\WINXP\INF\wmp.inf ,PerUserStub
|_ [?][{89820200-ECBD-11cf-8B85-00AA005B4340}] regsvr32.exe /s /n /i:U shell32.dll
|_ [?][{89820200-ECBD-11cf-8B85-00AA005B4383}] C:\WINXP\system32\ie4uinit.exe -BaseSettings
HKLM Winlogon Notify
|_ [?][avgrsstarter] C:\WINXP\system32\avgrsstx.dll
Job
|_ [?][APPLES~1.JOB] C:\Program Files\Apple Software Update\SoftwareUpdate.exe
|_ [?][GOOGLE~2.JOB] C:\Program Files\Google\Update\GoogleUpdate.exe
|_ [?][GOOGLE~3.JOB] C:\Program Files\Google\Update\GoogleUpdate.exe
HKLM BHO
|_ [?][{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
|_ [?][{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}] C:\Program Files\AVG\AVG9\avgssie.dll
|_ [?][{A3BC75A2-1F87-4686-AA43-5347D756017C}] C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
|_ [?][{AA58ED58-01DD-4d91-8333-CF10577473F7}] C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
|_ [?][{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
|_ [?][{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}] C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
|_ [?][{DBC80044-A445-435b-BC74-9C25C1C588A9}] C:\Program Files\Java\jre6\bin\jp2ssv.dll
|_ [?][{E7E6F031-17CE-4C07-BC86-EABFE594F69C}] C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
HKCU IE WebBrowser Toolbar
|_ [?][{CCC7A320-B3CA-4199-B1A6-9F516DD69829}] C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
|_ [?][{2318C2B1-4965-11D4-9B18-009027A5CD4F}] C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
HKLM IE Toolbar
|_ [?][{CCC7A320-B3CA-4199-B1A6-9F516DD69829}] C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
|_ [?][{2318C2B1-4965-11d4-9B18-009027A5CD4F}] C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
Services (Display running: True, Display stopped: False, Display safe: False)
================================================================
[?] AVG Free E-mail Scanner
|_ Path: C:\Program Files\AVG\AVG9\avgemc.exe
| |_ Manufacturer: AVG Technologies CZ, s.r.o.
| |_ Description: AVG E-Mail Scanner
| |_ MD5: AA054CD537357F03D5BA6ABA7562B35F
|
|_ Name: avg9emc
|_ StartName: LocalSystem
|_ Startup type: Auto Start
|_ Status: Running
|_ Type: Win32 Own Process
|_ Dependency: RPCSS
[?] AVG Free WatchDog
|_ Path: C:\Program Files\AVG\AVG9\avgwdsvc.exe
| |_ Manufacturer: AVG Technologies CZ, s.r.o.
| |_ Description: AVG Watchdog Service
| |_ MD5: C4D15594DB5BE042D3346EA58DF87D89
|
|_ Name: avg9wd
|_ StartName: LocalSystem
|_ Startup type: Auto Start
|_ Status: Running
|_ Type: Win32 Own Process
|_ Dependency:
[?] B's Recorder GOLD Library General Service
|_ Path: C:\WINXP\system32\bgsvcgen.exe
| |_ Manufacturer: B.H.A Corporation
| |_ Description: B's Recorder GOLD Service Library
| |_ MD5: 71489FA2C4A238F178E30AE6E4449013
|
|_ Name: bgsvcgen
|_ StartName: LocalSystem
|_ Startup type: Auto Start
|_ Status: Running
|_ Type: Win32 Own Process
|_ Dependency:
[X] Sluba Google Update (gupdate1ca8bc2e3eccd06)
|_ Path: C:\Program Files\Google\Update\GoogleUpdate.exe /svc
| |_ Manufacturer:
| |_ Description:
| |_ MD5:
|
|_ Name: gupdate1ca8bc2e3eccd06
|_ StartName: LocalSystem
|_ Startup type: Auto Start
|_ Status: Stopped
|_ Type: Win32 Own Process
|_ Dependency: RPCSS
[X] Java Quick Starter
|_ Path: C:\Program Files\Java\jre6\bin\jqs.exe -service -config C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf
| |_ Manufacturer:
| |_ Description:
| |_ MD5:
|
|_ Name: JavaQuickStarterService
|_ StartName: LocalSystem
|_ Startup type: Auto Start
|_ Status: Running
|_ Type: Win32 Own Process
|_ Dependency:
[?] Pracovní stanice
|_ Path: C:\WINXP\system32\svchost.exe
| |_ Manufacturer: Microsoft Corporation
| |_ Description: Generic Host Process for Win32 Services
| |_ MD5: BE4A520E29B6391F49E79CCC52044D93
|
|_ ServiceDLL: C:\WINXP\System32\wkssvc.dll
| |_ Manufacturer: Microsoft Corporation
| |_ Description: Workstation Service DLL
| |_ MD5: 936C1D110232D23B621CB0196E4F80F0
|
|_ Name: lanmanworkstation
|_ StartName: LocalSystem
|_ Startup type: Auto Start
|_ Status: Running
|_ Type: Win32 Share Process
|_ Dependency:
[?] NMSAccessU
|_ Path: C:\Program Files\CDBurnerXP\NMSAccessU.exe
| |_ Manufacturer:
| |_ Description:
| |_ MD5: FD306FBCCE7ADB1077B709742E7148E9
|
|_ Name: NMSAccessU
|_ StartName: LocalSystem
|_ Startup type: Auto Start
|_ Status: Running
|_ Type: Win32 Own Process
|_ Dependency:
Drivers (Display running: True, Display stopped: False, Display safe: False)
================================================================
[?] Service for Realtek AC97 Audio (WDM)
|_ Path: C:\WINXP\system32\drivers\ALCXWDM.SYS
| |_ Manufacturer: Realtek Semiconductor Corp.
| |_ Description: Realtek AC'97 Audio Driver (WDM)
| |_ MD5: F3E15607BA53249C765E36388B332C2F
|
|_ Name: ALCXWDM
|_ StartName:
|_ Startup type: Manual startup
|_ Status: Running
|_ Type: Kernel Driver
|_ Dependency:
[?] AVG Free AVI Loader Driver x86
|_ Path: C:\WINXP\System32\Drivers\avgldx86.sys
| |_ Manufacturer: AVG Technologies CZ, s.r.o.
| |_ Description: AVG AVI Loader Driver
| |_ MD5: B8C187439D27ABA430DD69FDCF1FA657
|
|_ Name: AvgLdx86
|_ StartName:
|_ Startup type: System Start
|_ Status: Running
|_ Type: Kernel Driver
|_ Dependency:
[?] AVG Free On-access Scanner Minifilter Driver x86
|_ Path: C:\WINXP\System32\Drivers\avgmfx86.sys
| |_ Manufacturer: AVG Technologies CZ, s.r.o.
| |_ Description: AVG Resident Shield Minifilter Driver
| |_ MD5: 53B3F979930A786A614D29CAFE99F645
|
|_ Name: AvgMfx86
|_ StartName:
|_ Startup type: System Start
|_ Status: Running
|_ Type: File System Driver
|_ Dependency:
[?] AVG Free Network Redirector
|_ Path: C:\WINXP\System32\Drivers\avgtdix.sys
| |_ Manufacturer: AVG Technologies CZ, s.r.o.
| |_ Description: AVG Network connection watcher
| |_ MD5: 22E3B793C3E61720F03D3A22351AF410
|
|_ Name: AvgTdiX
|_ StartName:
|_ Startup type: System Start
|_ Status: Running
|_ Type: Kernel Driver
|_ Dependency:
[?] cdrbsdrv
|_ Path: C:\WINXP\system32\drivers\cdrbsdrv.sys
| |_ Manufacturer: B.H.A Corporation
| |_ Description: CD-ROM Filter Driver for Windows2000/xp
| |_ MD5: 248349293CA42EE5DB61DC1FD85A2F49
|
|_ Name: cdrbsdrv
|_ StartName:
|_ Startup type: System Start
|_ Status: Running
|_ Type: Kernel Driver
|_ Dependency:
[?] HTTP
|_ Path: C:\WINXP\System32\Drivers\HTTP.sys
| |_ Manufacturer: Microsoft Corporation
| |_ Description: HTTP Protocol Stack
| |_ MD5: F80A415EF82CD06FFAF0D971528EAD38
|
|_ Name: HTTP
|_ StartName:
|_ Startup type: Manual startup
|_ Status: Running
|_ Type: Kernel Driver
|_ Dependency:
[?] MRXSMB
|_ Path: C:\WINXP\system32\DRIVERS\mrxsmb.sys
| |_ Manufacturer: Microsoft Corporation
| |_ Description: Windows NT SMB Minirdr
| |_ MD5: F3AEFB11ABC521122B67095044169E98
|
|_ Name: MRxSmb
|_ StartName:
|_ Startup type: System Start
|_ Status: Running
|_ Type: File System Driver
|_ Dependency:
[?] nvatabus
|_ Path: C:\WINXP\system32\DRIVERS\nvatabus.sys
| |_ Manufacturer: NVIDIA Corporation
| |_ Description: NVIDIA® nForce(TM) IDE Performance Driver
| |_ MD5: 46DEED4C6C5FA765F9A2C723BE60348D
|
|_ Name: nvatabus
|_ StartName:
|_ Startup type: Boot Start
|_ Status: Running
|_ Type: Kernel Driver
|_ Dependency:
[?] NVIDIA Network Bus Enumerator
|_ Path: C:\WINXP\system32\DRIVERS\nvnetbus.sys
| |_ Manufacturer: NVIDIA Corporation
| |_ Description: NVIDIA Networking Bus Driver.
| |_ MD5: BCC3722A2DB99AD6F367344997C26654
|
|_ Name: nvnetbus
|_ StartName:
|_ Startup type: Manual startup
|_ Status: Running
|_ Type: Kernel Driver
|_ Dependency:
[?] NVIDIA nForce AGP Bus Filter
|_ Path: C:\WINXP\system32\DRIVERS\nv_agp.sys
| |_ Manufacturer: NVIDIA Corporation
| |_ Description: NVIDIA nForce AGP Filter
| |_ MD5: C0FCD544A1C4EEA6D11A0AE6A07DAC9D
|
|_ Name: nv_agp
|_ StartName:
|_ Startup type: Boot Start
|_ Status: Running
|_ Type: Kernel Driver
|_ Dependency:
[?] PxHelp20
|_ Path: C:\WINXP\System32\Drivers\PxHelp20.sys
| |_ Manufacturer: Sonic Solutions
| |_ Description: Px Engine Device Driver for Windows 2000/XP
| |_ MD5: D86B4A68565E444D76457F14172C875A
|
|_ Name: PxHelp20
|_ StartName:
|_ Startup type: Boot Start
|_ Status: Running
|_ Type: Kernel Driver
|_ Dependency:
[?] Srv
|_ Path: C:\WINXP\system32\DRIVERS\srv.sys
| |_ Manufacturer: Microsoft Corporation
| |_ Description: Server driver
| |_ MD5: DA852E3E0BF1CEA75D756F9866241E57
|
|_ Name: Srv
|_ StartName:
|_ Startup type: Manual startup
|_ Status: Running
|_ Type: File System Driver
|_ Dependency:
lNetStat
================================================================
Type: PID Process Local <-> Remote Status
------------------------------------------------------------------------------------------
TCP (796) svchost.exe 0.0.0.0:135 LISTENING
TCP (4) System 0.0.0.0:445 LISTENING
TCP (1736) alg.exe 127.0.0.1:1025 LISTENING
TCP (1632) jqs.exe 127.0.0.1:5152 LISTENING
UDP (4) System 0.0.0.0:445 LISTENING
UDP (588) lsass.exe 0.0.0.0:500
UDP (588) lsass.exe 0.0.0.0:4500
UDP (836) svchost.exe 127.0.0.1:123
UDP (1008) svchost.exe 127.0.0.1:1900
Modules (Display safe: False, Only without manufacturer: True, Display registered: False)
================================================================
[?] avgrsstx.dll
|_ Path: C:\WINXP\system32\avgrsstx.dll
|_ MD5: D2A2B291414EB3D256B9E49331ED06C3
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ winlogon.exe (532)
[?] avgclitx.dll
|_ Path: C:\Program Files\AVG\AVG9\avgclitx.dll
|_ MD5: 5412B19162D52E9DE9E83534613E664E
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgchsvx.exe (952)
[?] avglogx.dll
|_ Path: C:\Program Files\AVG\AVG9\avglogx.dll
|_ MD5: 4A2FC89ED82ABE547DDE1B7443C5F321
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgchsvx.exe (952)
|_ avgrsx.exe (960)
|_ avgcsrvx.exe (1080)
|_ avgwdsvc.exe (1528)
|_ avgemc.exe (2044)
|_ avgnsx.exe (164)
|_ avgcsrvx.exe (368)
|_ avgtray.exe (2628)
[?] avgcertx.dll
|_ Path: C:\Program Files\AVG\AVG9\avgcertx.dll
|_ MD5: 6ABB7C1BB86021268BFD0DAC655BED2E
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgchsvx.exe (952)
|_ avgcsrvx.exe (1080)
|_ avgcsrvx.exe (368)
[?] avgchjwx.dll
|_ Path: C:\Program Files\AVG\AVG9\avgchjwx.dll
|_ MD5: A0C86DD4ADAD6C115322977159B32E19
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgchsvx.exe (952)
[?] avgcclix.dll
|_ Path: C:\Program Files\AVG\AVG9\avgcclix.dll
|_ MD5: 7F65F6F91690074AC3B02C14A10FCCCE
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgrsx.exe (960)
|_ avgemc.exe (2044)
[?] avgcorex.dll
|_ Path: C:\Program Files\AVG\AVG9\avgcorex.dll
|_ MD5: 48E09D07626921ADDD121725515B5AFD
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgcsrvx.exe (1080)
|_ avgcsrvx.exe (368)
[?] avgchclx.dll
|_ Path: C:\Program Files\AVG\AVG9\avgchclx.dll
|_ MD5: F284AD3887C458312797FD1F1A920498
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgcsrvx.exe (1080)
|_ avgcsrvx.exe (368)
[?] avgamnot.dll
|_ Path: C:\Program Files\AVG\AVG9\avgamnot.dll
|_ MD5: 6045FD764EA16155A7E28895FB442940
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgwdsvc.exe (1528)
[?] avgcfgx.dll
|_ Path: C:\Program Files\AVG\AVG9\avgcfgx.dll
|_ MD5: 37C58F3C25745E83BF5E141C3E7F555E
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgwdsvc.exe (1528)
|_ avgemc.exe (2044)
|_ avgnsx.exe (164)
|_ avgtray.exe (2628)
[?] avglngx.dll
|_ Path: C:\Program Files\AVG\AVG9\avglngx.dll
|_ MD5: 6E369ACB5D93EC872CABB3FB066FE96F
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgwdsvc.exe (1528)
|_ avgemc.exe (2044)
|_ avgtray.exe (2628)
[?] avgsched.dll
|_ Path: C:\Program Files\AVG\AVG9\avgsched.dll
|_ MD5: F34780EC4BA8D315F415D8DDAACA61D9
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgwdsvc.exe (1528)
[?] avgwd.dll
|_ Path: C:\Program Files\AVG\AVG9\avgwd.dll
|_ MD5: EC007398F0E040017965A4AE378477EE
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgwdsvc.exe (1528)
[?] avgwdwsc.dll
|_ Path: C:\Program Files\AVG\AVG9\avgwdwsc.dll
|_ MD5: 1768312EF86F64620ABBCE147BDB764D
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgwdsvc.exe (1528)
[?] aspnet_perf.dll
|_ Path: C:\WINXP\Microsoft.NET\Framework\v2.0.50727\Aspnet_perf.dll
|_ MD5: F1430F5D20F4BB71A003209C3DB3ADDF
|_ Manufacturer: Microsoft Corporation
|_ Processes
|_ jqs.exe (1632)
[?] corperfmonext.dll
|_ Path: C:\WINXP\Microsoft.NET\Framework\v2.0.50727\CORPerfMonExt.dll
|_ MD5: 2E61C409474416CC78D66300F1BCB722
|_ Manufacturer: Microsoft Corporation
|_ Processes
|_ jqs.exe (1632)
[?] netfxperf.dll
|_ Path: C:\WINXP\system32\netfxperf.dll
|_ MD5: 203D5ECB5CCDA683053CDA42DFF03573
|_ Manufacturer: Microsoft Corporation
|_ Processes
|_ jqs.exe (1632)
[?] perfcounter.dll
|_ Path: C:\WINXP\Microsoft.NET\Framework\v2.0.50727\PerfCounter.dll
|_ MD5: C5A9554406507AB2AB341B221D97519D
|_ Manufacturer: Microsoft Corporation
|_ Processes
|_ jqs.exe (1632)
[?] mscoree.dll
|_ Path: C:\WINXP\system32\mscoree.dll
|_ MD5: 08A73B0E7EE6E32983B5F9E540A8E380
|_ Manufacturer: Microsoft Corporation
|_ Processes
|_ jqs.exe (1632)
[?] mscorwks.dll
|_ Path: C:\WINXP\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
|_ MD5: 4ED92DC066A4DF8384A3E34E03F440FC
|_ Manufacturer: Microsoft Corporation
|_ Processes
|_ jqs.exe (1632)
[?] avgapix.dll
|_ Path: C:\Program Files\AVG\AVG9\avgapix.dll
|_ MD5: CCEAE95F3EC435D8C2603BB42CAF41DD
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgemc.exe (2044)
[?] avgmvflx.dll
|_ Path: C:\Program Files\AVG\AVG9\avgmvflx.dll
|_ MD5: 5A7D4F5D293B48584AE2112ED5DB4132
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgemc.exe (2044)
[?] avgscanx.dll
|_ Path: C:\Program Files\AVG\AVG9\avgscanx.dll
|_ MD5: 61C8FAE993D723E19078D4CAE8FC47A3
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgemc.exe (2044)
[?] avgsrmx.dll
|_ Path: C:\Program Files\AVG\AVG9\avgsrmx.dll
|_ MD5: E230DB9A3032E6D2BE44D61285085365
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgemc.exe (2044)
[?] avgvvx.dll
|_ Path: C:\Program Files\AVG\AVG9\avgvvx.dll
|_ MD5: 01C10B077D464FEA240A7B1B71A123BC
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgemc.exe (2044)
[?] libsasl.dll
|_ Path: C:\Program Files\AVG\AVG9\libsasl.dll
|_ MD5: 6BA10DE5FC60333BF2A7AFC94743F8CB
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgemc.exe (2044)
[?] saslplain.dll
|_ Path: C:\Program Files\AVG\AVG9\saslplain.dll
|_ MD5: 6DE53AF6695AA88E5D75C06014D84FA3
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgemc.exe (2044)
[?] sasllogin.dll
|_ Path: C:\Program Files\AVG\AVG9\sasllogin.dll
|_ MD5: 1DA5DAAF359873246D9642C65432B163
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgemc.exe (2044)
[?] saslcrammd5.dll
|_ Path: C:\Program Files\AVG\AVG9\saslcrammd5.dll
|_ MD5: 5A3F5083157788A4952AADB755AF7B1E
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgemc.exe (2044)
[?] sasldigestmd5.dll
|_ Path: C:\Program Files\AVG\AVG9\sasldigestmd5.dll
|_ MD5: FF42698F85DBEFF3729821D8A0E48B20
|_ Manufacturer: AVG Technologies CZ, s.r.o.
|_ Processes
|_ avgemc.exe (2044)
[?] olyuidrw.dll
|_ Path: C:\Program Files\OLYMPUS\OLYMPUS Master\olyuidrw.dll
|_ MD5: B8A71BCCE88CC6A8B0D821DF18950BB3
|_ Manufacturer: OLYMPUS IMAGING CORP.
|_ Processes
|_ Monitor.exe (2676)
[?] olyplgmgr.dll
|_ Path: C:\Program Files\OLYMPUS\OLYMPUS Master\OlyPlgMgr.dll
|_ MD5: 7E6DD8A6D2619ECBE508154EA7572862
|_ Manufacturer: OLYMPUS IMAGING CORP.
|_ Processes
|_ Monitor.exe (2676)
[?] olycamdetect.dll
|_ Path: C:\Program Files\OLYMPUS\OLYMPUS Master\OlyCamDetect.dll
|_ MD5: D0B850C181B0F80540E6F6138788B518
|_ Manufacturer: OLYMPUS IMAGING CORP.
|_ Processes
|_ Monitor.exe (2676)
[?] olapcevent.dll
|_ Path: C:\Program Files\OLYMPUS\OLYMPUS Master\OlAPCEvent.dll
|_ MD5: 1C69690C5336AFC9653D2A3AF914A2F3
|_ Manufacturer: OLYMPUS IMAGING CORP.
|_ Processes
|_ Monitor.exe (2676)
[?] olygloss.dll
|_ Path: C:\Program Files\OLYMPUS\OLYMPUS Master\OlyGloss.dll
|_ MD5: A843CC6DB39CF0467337F4D65A3C71E5
|_ Manufacturer: OLYMPUS IMAGING CORP.
|_ Processes
|_ Monitor.exe (2676)
[?] olyexiflib.dll
|_ Path: C:\Program Files\OLYMPUS\OLYMPUS Master\OlyExifLib.dll
|_ MD5: FA23A0DF3A062D1648F04718368091DC
|_ Manufacturer: OLYMPUS IMAGING CORP.
|_ Processes
|_ Monitor.exe (2676)
[?] olilevent.dll
|_ Path: C:\Program Files\OLYMPUS\OLYMPUS Master\OlILEvent.dll
|_ MD5: F99212BDFC4A1ACDFE0D991C8048F78E
|_ Manufacturer: OLYMPUS IMAGING CORP.
|_ Processes
|_ Monitor.exe (2676)
[?] olyrum.dll
|_ Path: C:\Program Files\OLYMPUS\OLYMPUS Master\OlyRum.dll
|_ MD5: CE96CF296AD92E5650080FBB0D669677
|_ Manufacturer: OLYMPUS IMAGING CORP.
|_ Processes
|_ Monitor.exe (2676)
[?] ptp-il.dll
|_ Path: C:\Program Files\OLYMPUS\OLYMPUS Master\PTP-IL.dll
|_ MD5: C59202534D7F802C5EE10828914D12EE
|_ Manufacturer: OLYMPUS IMAGING CORP.
|_ Processes
|_ Monitor.exe (2676)
[?] olcamapi.dll
|_ Path: C:\Program Files\OLYMPUS\OLYMPUS Master\Olcamapi.dll
|_ MD5: 79B8774EED4F86607C0AE48FDCC230EC
|_ Manufacturer: OLYMPUS OPTICAL CO.,LTD.
|_ Processes
|_ Monitor.exe (2676)
[?] olyuictl.dll
|_ Path: C:\Program Files\OLYMPUS\OLYMPUS Master\olyuictl.dll
|_ MD5: DCCCC6BEAAF866349F3D09E7FC43A530
|_ Manufacturer: OLYMPUS IMAGING CORP.
|_ Processes
|_ Monitor.exe (2676)
[?] mfc42.dll
|_ Path: C:\Program Files\OLYMPUS\OLYMPUS Master\MFC42.DLL
|_ MD5: F92E518180CF52FB526C7A76BD9AFD7E
|_ Manufacturer: Microsoft Corporation
|_ Processes
|_ Monitor.exe (2676)
[?] swg.dll
|_ Path: C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
|_ MD5: 42CB4EE0B0FC259C8AD20B460FA7D72A
|_ Manufacturer: Google Inc.
|_ Processes
|_ GoogleToolbarNotifier.exe (2708)
[?] gtn.dll
|_ Path: C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\gtn.dll
|_ MD5: EFC5461595187559BB61538143D035ED
|_ Manufacturer: Google Inc.
|_ Processes
|_ GoogleToolbarNotifier.exe (2708)
[?] mscomctl.ocx
|_ Path: C:\WINXP\system32\MSCOMCTL.OCX
|_ MD5: F7BBB7D79ADB9E3ADC13F3B3C33D3D4D
|_ Manufacturer: Microsoft Corporation
|_ Processes
|_ UPM.exe (3492)
================================================================
Ultimate Process Manager v4.1.3 - [ Lodus Software ] - Not Registered =(