Stránka 1 z 1

log z UPM

Napsal: 20 říj 2010 13:44
od gerry2
Zdravím, včera se mi do PC dostala nějaká havěť a stále se mi nedaří dostat pryč.

V podstatě to funguje tak, že jakmile zapnu pc tak po pár minutách začnou mikráky praskat jako kdyby v nich lezl chroust, obrazovka pak několikrát zeleně problikne a vyskočí mi (podle mě falešná) hláška že mám v PC vir. Když se tu hlášku snažím vypnout tak mě to pokaždé přesměruje na nějaký program který si mám údajně stáhnout a tu hlášku nelze nijak vypnout. viz. http://img2.wz.cz/obrazky/vir2.jpg

Když jsem spouštěl avast s důkladným testem tak vůbec nic nanašel, přesto celý den nedělá nic jiného než že blokuje trojské koně a malwary. viz. toto http://img2.wz.cz/obrazky/vir1.jpg

Toto je log z programu UPM který jsem stáhl z těchto stránek. Jak bych měl dál postupovat?

Kód: Vybrat vše

Windows Vista SP 1 (build 6001)
Boot Mode: Normal
Ověření souborů Microsoftu: Ano
Whitelist: Ano
Internet Explorer v7.00.6000.16386 (vista_rtm.061101-2205)
Log vygenerován: 20.10.2010 14:11:36
================================================================

Běžící procesy
================================================================

C:\WINDOWS\SYSTEM32\NVVSVC.EXE
(rootkit?) audiodg.exe
C:\PROGRAM FILES\ASUS\ATK HOTKEY\ASLDRSRV.EXE
C:\PROGRAM FILES\ATKGFNEX\GFNEXSRV.EXE
C:\WINDOWS\SYSTEM32\AGRSMSVC.EXE
C:\PROGRAM FILES\COMMON FILES\LIGHTSCRIBE\LSSRVC.EXE
C:\PROGRAM FILES\COMMON FILES\MOTIVE\MCCICMSERVICE.EXE
C:\PROGRAM FILES\POSTGRESQL\8.3\BIN\PG_CTL.EXE
C:\PROGRAM FILES\POSTGRESQL\8.3\BIN\POSTGRES.EXE
C:\PROGRAM FILES\POSTGRESQL\8.3\BIN\POSTGRES.EXE
C:\PROGRAM FILES\POSTGRESQL\8.3\BIN\POSTGRES.EXE
C:\PROGRAM FILES\POSTGRESQL\8.3\BIN\POSTGRES.EXE
C:\PROGRAM FILES\POSTGRESQL\8.3\BIN\POSTGRES.EXE
C:\PROGRAM FILES\POSTGRESQL\8.3\BIN\POSTGRES.EXE
C:\PROGRAM FILES\ASUS SECURITY CENTER\ASUS SECURITY PROTECT MANAGER\BIN\ASGHOST.EXE
C:\PROGRAM FILES\ASUS\ATK HOTKEY\HCONTROLUSER.EXE
C:\PROGRAM FILES\ASUS\ATK HOTKEY\MSGTRANAGT.EXE
C:\PROGRAM FILES\ASUS\ATK HOTKEY\HCONTROL.EXE
C:\PROGRAM FILES\WIRELESS CONSOLE 2\WCOURIER.EXE
C:\PROGRAM FILES\ASUS\SPLENDID\ACMON.EXE
C:\PROGRAM FILES\ASUS\ATKOSD2\ATKOSD2.EXE
C:\PROGRAM FILES\ASUS\ATK MEDIA\DMEDIA.EXE
C:\PROGRAM FILES\ASUS\ATK HOTKEY\ATKOSD.EXE
C:\PROGRAM FILES\COMMON FILES\LIGHTSCRIBE\LIGHTSCRIBECONTROLPANEL.EXE
C:\PROGRAM FILES\ASUS\ATK HOTKEY\KBFILTR.EXE
C:\PROGRAM FILES\ASUS\ATK HOTKEY\WDC.EXE
C:\USERS\HONZA\APPDATA\LOCAL\TEMP\0.25951143129805265.EXE
C:\USERS\HONZA\APPDATA\LOCAL\GOOGLE\CHROME\APPLICATION\CHROMEGOOGLE.EXE
C:\USERS\HONZA\APPDATA\LOCAL\TEMP\M.2AAA.TMP.EXE
C:\USERS\HONZA\APPDATA\LOCAL\GOOGLE\CHROME\APPLICATION\CHROMEGOOGLE.EXE

Scanner
================================================================
[?] nvvsvc.exe                                                                                                             
Non Microsoft v System32:                                                                                                  
Nemá okno                                                                                                                  
                                                                                       
[S] audiodg.exe                                                                                                            
Proces se nepodařilo otevřít                                                                                               
ROOTKIT?                            Skrytá cesta
Spouští se po startu                HKCU Run [Sidebar]
Nelze otevřít                                                                                                              
                                                                                       
[S] SLsvc.exe                                                                                                              
EntryPoint v sekci:                 .TEXT
|_ Celkový počet sekcí:             5
                                                                                       
[?] AsLdrSrv.exe                                                                                                           
Bez výrobce                                                                                                                
Nemá okno                                                                                                                  
Soubor                              12%
                                                                                       
[?] GFNEXSrv.exe                                                                                                           
Bez výrobce                                                                                                                
Nemá okno                                                                                                                  
Soubor                              12%
                                                                                       
[S] rundll32.exe                                                                                                           
Spouští se po startu                HKLM Run [NvCplDaemon]
                                                                                       
[?] agrsmsvc.exe                                                                                                           
Non Microsoft v System32:                                                                                                  
Nemá okno                                                                                                                  
                                                                                       
[?] LSSrvc.exe                                                                                                             
Nemá okno                                                                                                                  
Soubor                              7%
                                                                                       
[?] McciCMService.exe                                                                                                      
Nemá okno                                                                                                                  
Soubor                              7%
                                                                                       
[?] pg_ctl.exe                                                                                                             
Nemá okno                                                                                                                  
Soubor                              7%
                                                                                       
[?] postgres.exe                                                                                                           
Nemá okno                                                                                                                  
Soubor                              7%
                                                                                       
[?] postgres.exe                                                                                                           
Nemá okno                                                                                                                  
Soubor                              7%
                                                                                       
[?] postgres.exe                                                                                                           
Nemá okno                                                                                                                  
Soubor                              7%
                                                                                       
[?] postgres.exe                                                                                                           
Nemá okno                                                                                                                  
Soubor                              7%
                                                                                       
[?] postgres.exe                                                                                                           
Nemá okno                                                                                                                  
Soubor                              7%
                                                                                       
[?] postgres.exe                                                                                                           
Nemá okno                                                                                                                  
Soubor                              7%
                                                                                       
[?] asghost.exe                                                                                                            
Soubor                              7%
                                                                                       
[S] explorer.exe                                                                                                           
Spouští se po startu                HKLM Winlogon [Shell]
                                                                                       
[S] MSASCui.exe                                                                                                            
Spouští se po startu                HKLM Run [Windows Defender]
                                                                                       
[R] CLMLSvc.exe                                                                                                            
Spouští se po startu                HKLM Run [CLMLServer]
                                                                                       
[R] GoogleDesktop.exe                                                                                                      
Spouští se po startu                HKLM Run [Google Desktop Search]
                                                                                       
[?] HControlUser.exe                                                                                                       
Bez výrobce                                                                                                                
Spouští se po startu                HKLM Run [HControlUser]
Soubor                              25%
                                                                                       
[?] MsgTranAgt.exe                                                                                                         
Bez výrobce                                                                                                                
Soubor                              25%
                                                                                       
[?] HControl.exe                                                                                                           
Soubor                              7%
                                                                                       
[?] wcourier.exe                                                                                                           
Bez výrobce                                                                                                                
Soubor                              12%
                                                                                       
[?] ACMON.exe                                                                                                              
Soubor                              7%
                                                                                       
[?] ATKOSD2.exe                                                                                                            
Podobná jména:                      ATKOSD2.EXE X ATKOSD.EXE
Spouští se po startu                HKLM Run [ATKOSD2]
Soubor                              14%
                                                                                       
[S] rundll32.exe                                                                                                           
Spouští se po startu                HKLM Run [NvCplDaemon]
                                                                                       
[R] RtHDVCpl.exe                                                                                                           
Spouští se po startu                HKLM Run [RtHDVCpl]
                                                                                       
[?] DMedia.exe                                                                                                             
Spouští se po startu                HKLM Run [ATKMEDIA]
Soubor                              14%
                                                                                       
[R] AsScrPro.exe                                                                                                           
Spouští se po startu                HKLM Run [ASUS Screen Saver Protector]
                                                                                       
[R] SynTPEnh.exe                                                                                                           
Spouští se po startu                HKLM Run [SynTPEnh]
                                                                                       
[R] GrooveMonitor.exe                                                                                                      
Ověřený Microsoft:                  Ne
Spouští se po startu                HKLM Run [GrooveMonitor]
                                                                                       
[R] jusched.exe                                                                                                            
Spouští se po startu                HKLM Run [SunJavaUpdateSched]
                                                                                       
[R] AvastUI.exe                                                                                                            
Spouští se po startu                HKLM Run [avast5]
                                                                                       
[?] ATKOSD.exe                                                                                                             
Podobná jména:                      ATKOSD.EXE X ATKOSD2.EXE
Soubor                              14%
                                                                                       
[?] LightScribeControlPanel.exe                                                                                            
Spouští se po startu                HKCU Run [LightScribe Control Panel]
Soubor                              14%
                                                                                       
[?] KBFiltr.exe                                                                                                            
Bez výrobce                                                                                                                
Soubor                              25%
                                                                                       
[?] WDC.exe                                                                                                                
Bez výrobce                                                                                                                
Soubor                              12%
                                                                                       
[R] GoogleToolbarNotifier.exe                                                                                              
Spouští se po startu                HKCU Run [swg]
                                                                                       
[?] 0.25951143129805265.exe                                                                                                
Bez výrobce                                                                                                                
Spouští se po startu                HKCU Run [antivirusaswV5Hlp]
Podvržená cesta modulu:             (00400000) C:\Users\Honza\AppData\Local\Temp\0.25951143129805265.exe
Soubor                              100%
                                                                                       
[?] chromeGoogle.exe                                                                                                       
Bez výrobce                                                                                                                
Spouští se po startu                HKCU Run [chromeexeChrome]
Podvržená cesta modulu:             (00400000) C:\Users\Honza\AppData\Local\Google\Chrome\Application\chromeGoogle.exe
Soubor                              100%
                                                                                       
[?] m.2AAA.tmp.exe                                                                                                         
Bez výrobce                                                                                                                
Spouští se po startu                HKCU Run [hskcu0wwuuoa]
Podvržená cesta modulu:             (00400000) C:\Users\Honza\AppData\Local\Temp\m.2AAA.tmp.exe
Soubor                              100%
                                                                                       
[?] chromeGoogle.exe                                                                                                       
Bez výrobce                                                                                                                
Spouští se po startu                HKCU Run [chromeexeChrome]
Podvržená cesta modulu:             (00400000) C:\Users\Honza\AppData\Local\Google\Chrome\Application\chromeGoogle.exe
Soubor                              100%
                                                                                       
[R] BTTray.exe                                                                                                             
Spouští se po startu                Po spuštění []
                                                                                       
[S] TrustedInstaller.exe                                                                                                   
Proces se nepodařilo otevřít                                                                                               
ROOTKIT?                            Skrytá cesta
Spouští se po startu                HKCU Run [Sidebar]
Nelze otevřít                                                                                                              
                                                                                       
[S] SearchProtocolHost.exe                                                                                                 
Proces se nepodařilo otevřít                                                                                               
ROOTKIT?                            Skrytá cesta
Spouští se po startu                HKCU Run [Sidebar]
Nelze otevřít                                                                                                              
                                                                                       
[S] SearchFilterHost.exe                                                                                                   
Proces se nepodařilo otevřít                                                                                               
ROOTKIT?                            Skrytá cesta
Spouští se po startu                HKCU Run [Sidebar]
Nelze otevřít                                                                                                              
                                                                                       

Po spuštění
================================================================

HKCU Run
 |_ [S][Sidebar]                     C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
 |_ [?][LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
 |_ [R][AlcoholAutomount] C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe /automount
 |_ [R][Google Update] C:\Users\Honza\AppData\Local\Google\Update\GoogleUpdate.exe /c
 |_ [R][googletalk]                  C:\Users\Honza\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart
 |_ [X][PicPick Start] C:\Program Files\PicPick\picpick.exe
 |_ [R][msnmsgr]                     C:\Program Files\Windows Live\Messenger\msnmsgr.exe /background
 |_ [?][Mikogo]                      C:\Users\Honza\AppData\Roaming\Mikogo\Mikogo-Host.exe
 |_ [X][antivirusaswV5Hlp] C:\Users\Honza\AppData\Local\Temp\0.25951143129805265.exe
 |_ [X][chromeexeChrome] c:\users\honza\appdata\local\google\chrome\application\chromegoogle.exe
 |_ [X][hskcu0wwuuoa] C:\Users\Honza\AppData\Local\Temp\m.2AAA.tmp.exe
 |_ [X][AntiVirus 2010] C:\Users\Honza\AppData\Roaming\AntiVirus 2010\AntiVirus_Studio_2010.exe /STARTUP (Soubor nenalezen)
 |_ [X][ChromeGoogle] C:\Users\Honza\AppData\Local\Google\Chrome\Application\chromeGoogle.exe
 |_ [X][hledanostidotazu] c:\users\honza\documents\centrum\weby a projekty\mfa\scany keywordů\disney channel\hledanostichannel.exe (Soubor nenalezen)

HKLM Run
 |_ [S][Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe -hide
 |_ [R][P2Go_Menu]                   C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe C:\Program Files\CyberLink\Power2Go UpdateWithCreateOnce SOFTWARE\CyberLink\Power2Go\6.0
 |_ [R][Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe /startup
 |_ [?][HControlUser] C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
 |_ [?][ATKOSD2]                     C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
 |_ [R][NvCplDaemon] C:\Windows\system32\NvCpl.dll ,NvStartup
 |_ [R][NvMediaCenter] C:\Windows\system32\NvMcTray.dll ,NvTaskbarInit
 |_ [?][CognizanceTS] C:\PROGRA~1\ASUSSE~1\ASUSSE~1\Bin\ASTSVCC.dll ,RegisterModule
 |_ [?][ATKMEDIA]                    C:\Program Files\ASUS\ATK Media\DMedia.exe
 |_ [?][TO2SSM_McciTrayApp] C:\Program Files\TO2SSM\McciTrayApp.exe
 |_ [R][avast5]                      C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui

HKCU RunServices
 |_ [X][avastantivirus] C:\Users\Honza\AppData\Local\Temp\0.25951143129805265.exe
 |_ [X][footerfooter] c:\users\honza\documents\centrum\weby a projekty\kérky.cz\ftp\prestashop theme\footerkopie.exe (Soubor nenalezen)
 |_ [X][Statistikyhledanosti22144] c:\users\honza\documents\centrum\weby a projekty\mfa\destinace scany key\lefkáda\seznamczstatistiky9743.exe (Soubor nenalezen)
 |_ [X][Seznamczhledanosti15212] c:\users\honza\documents\centrum\weby a projekty\mfa\scany keywordů\disney channel\hledanostichannel.exe (Soubor nenalezen)
 |_ [X][SmallSmall]                  c:\users\honza\appdata\local\adobe\reader 9.4\setup files\smallsetup.exe
 |_ [X][MicrosoftSetupResources] c:\users\honza\appdata\local\temp\microsoft .net framework 4 setup_4.0.30319\1053\setupresourcesmicrosoft.exe (Soubor nenalezen)
 |_ [X][chromeChrome] C:\Users\Honza\AppData\Local\Google\Chrome\Application\chromeGoogle.exe

HKLM ShellServiceObjectDelayLoad
 |_ [X][WebCheck]                     (Soubor nenalezen)

HKLM IC
 |_ [X][>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP (Soubor nenalezen)
 |_ [?][{89820200-ECBD-11cf-8B85-00AA005B4340}] regsvr32.exe /s /n /i:U shell32.dll

HKLM AppInit_DLLs
 |_ [?][AppInit_DLLs] C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL APSHook.dll

Po spuštění
 |_ C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
 |_ [?][Adobe Gamma Loader.lnk] C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe


HKLM BHO
 |_ [?][{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}] C:\Users\Honza\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll

Služby (Zobraz běžící: True, Zobraz zastavené: False, Zobraz i bezpečné služby: False)
================================================================
[?] Agere Modem Call Progress Audio
 |_ Cesta: C:\Windows\system32\agrsmsvc.exe
 |   |_ Výrobce:  Agere Systems
 |   |_ Popis: Agere Soft Modem Call Progress Service
 |   |_ MD5: EFBC44FBD75E4F80BD927AEBF6E7EADE
 |   
 |_ Jméno:  AgereModemAudio
 |_ StartName: LocalSystem
 |_ Typ spouštění:  Auto Start
 |_ Status: Spuštěno
 |_ Typ:  Win32 Own Process
 |_ Dependency: 

[?] Logon Session Broker
 |_ Cesta: C:\Windows\System32\svchost.exe
 |   |_ Výrobce:  Microsoft Corporation
 |   |_ Popis: Host Process for Windows Services
 |   |_ MD5: 3794B461C45882E06856F282EEF025AF
 |   
 |_ ServiceDLL: C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll
 |   |_ Výrobce:  Cognizance Corporation
 |   |_ Popis: Winlogon notification handler
 |   |_ MD5: 2EEDA27C19259C2340324EF7180D086B
 |   
 |_ Jméno:  ASBroker
 |_ StartName: LocalSystem
 |_ Typ spouštění:  Auto Start
 |_ Status: Spuštěno
 |_ Typ:  Win32 Share Process
 |_ Dependency: 

[?] Local Communication Channel
 |_ Cesta: C:\Windows\System32\svchost.exe
 |   |_ Výrobce:  Microsoft Corporation
 |   |_ Popis: Host Process for Windows Services
 |   |_ MD5: 3794B461C45882E06856F282EEF025AF
 |   
 |_ ServiceDLL: C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsChnl.dll
 |   |_ Výrobce:  Cognizance Corporation
 |   |_ Popis: Secure Communication Channel
 |   |_ MD5: BB3C0521ECCA4BB17AC55EB640DF0FA5
 |   
 |_ Jméno:  ASChannel
 |_ StartName: LocalSystem
 |_ Typ spouštění:  Auto Start
 |_ Status: Spuštěno
 |_ Typ:  Win32 Share Process
 |_ Dependency: 

[?] ASLDR Service
 |_ Cesta: C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe
 |   |_ Výrobce:  ?
 |   |_ Popis: ASLDR Service
 |   |_ MD5: 5A055A4777CBBC8845DD598CB2EEBF69
 |   
 |_ Jméno:  ASLDRService
 |_ StartName: LocalSystem
 |_ Typ spouštění:  Auto Start
 |_ Status: Spuštěno
 |_ Typ:  Win32 Own Process
 |_ Dependency: 

[?] ATKGFNEX Service
 |_ Cesta: C:\Program Files\ATKGFNEX\GFNEXSrv.exe
 |   |_ Výrobce:  ?
 |   |_ Popis: GFNEXSrv
 |   |_ MD5: 7C157574A181B19B9DCF5F339E25337E
 |   
 |_ Jméno:  ATKGFNEXSrv
 |_ StartName: LocalSystem
 |_ Typ spouštění:  Auto Start
 |_ Status: Spuštěno
 |_ Typ:  Win32 Own Process
 |_ Dependency: ASMMAP

[?] LightScribeService Direct Disc Labeling Service
 |_ Cesta: C:\Program Files\Common Files\LightScribe\LSSrvc.exe
 |   |_ Výrobce:  Hewlett-Packard Company
 |   |_ Popis: LightScribe Service
 |   |_ MD5: ABF90FC5A127F481219B873C1B8DFC1C
 |   
 |_ Jméno:  LightScribeService
 |_ StartName: LocalSystem
 |_ Typ spouštění:  Auto Start
 |_ Status: Spuštěno
 |_ Typ:  Win32 Own Process
 |_ Dependency: 

[?] McciCMService
 |_ Cesta: C:\Program Files\Common Files\Motive\McciCMService.exe
 |   |_ Výrobce:  Motive Communications, Inc.
 |   |_ Popis: mcci+McciCMService
 |   |_ MD5: 4F74184920B2D6E33024409B4C5C57C1
 |   
 |_ Jméno:  McciCMService
 |_ StartName: LocalSystem
 |_ Typ spouštění:  Auto Start
 |_ Status: Spuštěno
 |_ Typ:  Win32 Own Process
 |_ Dependency: RPCSS

[?] NVIDIA Display Driver Service
 |_ Cesta: C:\Windows\system32\nvvsvc.exe
 |   |_ Výrobce:  NVIDIA Corporation
 |   |_ Popis: NVIDIA Driver Helper Service, Version 176.23
 |   |_ MD5: C7D36F2077360216D1DB16B1B8F5AEA3
 |   
 |_ Jméno:  nvsvc
 |_ StartName: LocalSystem
 |_ Typ spouštění:  Auto Start
 |_ Status: Spuštěno
 |_ Typ:  Win32 Own Process
 |_ Dependency: nvlddmkm

[X] PostgreSQL Database Server 8.3
 |_ Cesta: C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe runservice -w -N pgsql-8.3 -D C:\Program Files\PostgreSQL\8.3\data\
 |   |_ Výrobce:  
 |   |_ Popis: 
 |   |_ MD5: 
 |   
 |_ Jméno:  pgsql-8.3
 |_ StartName: .\postgres
 |_ Typ spouštění:  Auto Start
 |_ Status: Spuštěno
 |_ Typ:  Win32 Own Process
 |_ Dependency: 


Ovladače (Zobraz běžící: True, Zobraz zastavené: False, Zobraz i bezpečné služby: False)
================================================================
[?] Agere Systems Soft Modem
 |_ Cesta: C:\Windows\system32\DRIVERS\AGRSM.sys
 |   |_ Výrobce:  Agere Systems
 |   |_ Popis: SoftModem Device Driver
 |   |_ MD5: 1CFEBA39FC613E45B49D3EDDFBCDA289
 |   
 |_ Jméno:  AgereSoftModem
 |_ StartName: 
 |_ Typ spouštění:  Ruční spuštění
 |_ Status: Spuštěno
 |_ Typ:  Kernel Driver
 |_ Dependency: 

[?] USB2.0 1.3M UVC WebCam
 |_ Cesta: C:\Windows\system32\DRIVERS\etDevice.sys
 |   |_ Výrobce:  eMPIA Technology, Inc.
 |   |_ Popis: USB 27xx WDM Driver
 |   |_ MD5: 699CE24FE6B5120AF709A0B91582A02D
 |   
 |_ Jméno:  DCamUSBET
 |_ StartName: 
 |_ Typ spouštění:  Ruční spuštění
 |_ Status: Spuštěno
 |_ Typ:  Kernel Driver
 |_ Dependency: 

[?] ET USB Device Lower Filter
 |_ Cesta: C:\Windows\system32\DRIVERS\etFilter.sys
 |   |_ Výrobce:  eMPIA Technology Inc.
 |   |_ Popis: EM27xx / EM28xx Filter Driver
 |   |_ MD5: E50433DFF5E6BF08693FA49A9205DEE6
 |   
 |_ Jméno:  FiltUSBET
 |_ StartName: 
 |_ Typ spouštění:  Ruční spuštění
 |_ Status: Spuštěno
 |_ Typ:  Kernel Driver
 |_ Dependency: 

[?] ITECIR Infrared Receiver
 |_ Cesta: C:\Windows\system32\DRIVERS\itecir.sys
 |   |_ Výrobce:  ITE Tech. Inc. 
 |   |_ Popis: ITE Consumer IR Driver for eHome
 |   |_ MD5: 8BCD857C7932AD005D5F9C89329DA2E1
 |   
 |_ Jméno:  itecir
 |_ StartName: 
 |_ Typ spouštění:  Ruční spuštění
 |_ Status: Spuštěno
 |_ Typ:  Kernel Driver
 |_ Dependency: 

[?] Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit
 |_ Cesta: C:\Windows\system32\DRIVERS\NETw5v32.sys
 |   |_ Výrobce:  Intel Corporation
 |   |_ Popis: Intel® Wireless WiFi Link Driver
 |   |_ MD5: 9CA26DCCF0B84A6FF2B54FBB2A94520B
 |   
 |_ Jméno:  NETw5v32
 |_ StartName: 
 |_ Typ spouštění:  Ruční spuštění
 |_ Status: Spuštěno
 |_ Typ:  Kernel Driver
 |_ Dependency: 

[?] nvlddmkm
 |_ Cesta: C:\Windows\system32\DRIVERS\nvlddmkm.sys
 |   |_ Výrobce:  NVIDIA Corporation
 |   |_ Popis: NVIDIA Compatible Windows Vista Kernel Mode Driver, Version 176.23 
 |   |_ MD5: B5D2B15D3EBA77BEF9392FBEFB3DDDA0
 |   
 |_ Jméno:  nvlddmkm
 |_ StartName: 
 |_ Typ spouštění:  Ruční spuštění
 |_ Status: Spuštěno
 |_ Typ:  Kernel Driver
 |_ Dependency: 

[?] rimmptsk
 |_ Cesta: C:\Windows\system32\DRIVERS\rimmptsk.sys
 |   |_ Výrobce:  REDC
 |   |_ Popis: RICOH SD Driver
 |   |_ MD5: DED01A389926A89540B82373E4C550EE
 |   
 |_ Jméno:  rimmptsk
 |_ StartName: 
 |_ Typ spouštění:  Auto Start
 |_ Status: Spuštěno
 |_ Typ:  Kernel Driver
 |_ Dependency: 

[?] rimsptsk
 |_ Cesta: C:\Windows\system32\DRIVERS\rimsptsk.sys
 |   |_ Výrobce:  REDC
 |   |_ Popis: RICOH MS Driver
 |   |_ MD5: C398BCA91216755B098679A8DA8A2300
 |   
 |_ Jméno:  rimsptsk
 |_ StartName: 
 |_ Typ spouštění:  Auto Start
 |_ Status: Spuštěno
 |_ Typ:  Kernel Driver
 |_ Dependency: 

[?] Ricoh xD-Picture Card Driver
 |_ Cesta: C:\Windows\system32\DRIVERS\rixdptsk.sys
 |   |_ Výrobce:  REDC
 |   |_ Popis: RICOH XD SM Driver
 |   |_ MD5: 2A2554CB24506E0A0508FC395C4A1B42
 |   
 |_ Jméno:  rismxdp
 |_ StartName: 
 |_ Typ spouštění:  Auto Start
 |_ Status: Spuštěno
 |_ Typ:  Kernel Driver
 |_ Dependency: 

[?] Realtek 8169 NT Driver
 |_ Cesta: C:\Windows\system32\DRIVERS\Rtlh86.sys
 |   |_ Výrobce:  Realtek Corporation                                            
 |   |_ Popis: Realtek 8101E/8168/8169 NDIS6 32-bit Driver                    
 |   |_ MD5: ABBE0F54BA3A378262C9CB86CF7D91F8
 |   
 |_ Jméno:  RTL8169
 |_ StartName: 
 |_ Typ spouštění:  Ruční spuštění
 |_ Status: Spuštěno
 |_ Typ:  Kernel Driver
 |_ Dependency: 

[?] ET USB Still Image Capture Device
 |_ Cesta: C:\Windows\system32\DRIVERS\etScan.sys
 |   |_ Výrobce:  eMPIA Technology, Inc.
 |   |_ Popis: USB 27xx WDM Upper Filter
 |   |_ MD5: D4B6A94C007AF4E398E1B78A90F254EA
 |   
 |_ Jméno:  ScanUSBET
 |_ StartName: 
 |_ Typ spouštění:  Ruční spuštění
 |_ Status: Spuštěno
 |_ Typ:  Kernel Driver
 |_ Dependency: 

[?] sptd
 |_ Cesta: C:\Windows\System32\Drivers\sptd.sys
 |   |_ Výrobce:  
 |   |_ Popis: 
 |   |_ MD5: 
 |   
 |_ Jméno:  sptd
 |_ StartName: 
 |_ Typ spouštění:  Boot Start
 |_ Status: Spuštěno
 |_ Typ:  Kernel Driver
 |_ Dependency: 


Moduly (Zobraz i bezpečné DLL: False, Jen bez výrobce: True, Zobraz registrované: False)
================================================================
[?] apshook.dll
 |_ Cesta: C:\Windows\System32\APSHook.dll
 |_ MD5: B0C201537F275CF67BFE81A550C1B073
 |_ Výrobce:  Cognizance Corporation
 |_ Procesy
     |_ wininit.exe (732)
     |_ services.exe (780)
     |_ lsass.exe (796)
     |_ lsm.exe (804)
     |_ svchost.exe (956)
     |_ svchost.exe (1028)
     |_ nvvsvc.exe (1060)
     |_ svchost.exe (1092)
     |_ svchost.exe (1184)
     |_ svchost.exe (1220)
     |_ svchost.exe (1236)
     |_ svchost.exe (1348)
     |_ svchost.exe (1416)
     |_ winlogon.exe (1512)
     |_ svchost.exe (1576)
     |_ AsLdrSrv.exe (1740)
     |_ GFNEXSrv.exe (1776)
     |_ AvastSvc.exe (1792)
     |_ taskeng.exe (2012)
     |_ spoolsv.exe (248)
     |_ svchost.exe (360)
     |_ rundll32.exe (624)
     |_ agrsmsvc.exe (2320)
     |_ AppleMobileDeviceService.exe (2364)
     |_ mDNSResponder.exe (2380)
     |_ svchost.exe (2396)
     |_ btwdins.exe (2408)
     |_ LSSrvc.exe (2464)
     |_ McciCMService.exe (2552)
     |_ pg_ctl.exe (2748)
     |_ svchost.exe (2784)
     |_ spmgr.exe (2800)
     |_ svchost.exe (2836)
     |_ SearchIndexer.exe (2908)
     |_ postgres.exe (2932)
     |_ postgres.exe (3092)
     |_ postgres.exe (3164)
     |_ postgres.exe (3172)
     |_ postgres.exe (3180)
     |_ postgres.exe (3188)
     |_ WmiPrvSE.exe (3680)
     |_ dwm.exe (2764)
     |_ taskeng.exe (3000)
     |_ explorer.exe (2360)
     |_ taskeng.exe (3616)
     |_ MSASCui.exe (3836)
     |_ ALU.exe (2176)
     |_ sensorsrv.exe (2200)
     |_ CLMLSvc.exe (2612)
     |_ GoogleDesktop.exe (776)
     |_ HControlUser.exe (3948)
     |_ MsgTranAgt.exe (3944)
     |_ HControl.exe (2996)
     |_ wcourier.exe (1588)
     |_ ASPG.exe (2192)
     |_ BatteryLife.exe (3676)
     |_ ACMON.exe (3844)
     |_ ATKOSD2.exe (236)
     |_ ACEngSvr.exe (3920)
     |_ rundll32.exe (3596)
     |_ RtHDVCpl.exe (3796)
     |_ AsScrPro.exe (4156)
     |_ SynTPEnh.exe (4188)
     |_ GrooveMonitor.exe (4212)
     |_ jusched.exe (4228)
     |_ AvastUI.exe (4272)
     |_ ATKOSD.exe (4376)
     |_ LightScribeControlPanel.exe (4400)
     |_ KBFiltr.exe (4440)
     |_ WDC.exe (4492)
     |_ 0.25951143129805265.exe (4568)
     |_ chromeGoogle.exe (4584)
     |_ unsecapp.exe (4792)
     |_ m.2AAA.tmp.exe (4968)
     |_ chromeGoogle.exe (5004)
     |_ BTTray.exe (5024)
     |_ GoogleCrashHandler.exe (5444)
     |_ BTStackServer.exe (5744)
     |_ SynTPHelper.exe (3012)
     |_ notepad.exe (5924)
     |_ chrome.exe (1844)
     |_ chrome.exe (4508)
     |_ chrome.exe (3924)
     |_ chrome.exe (5388)
     |_ wuauclt.exe (3404)
     |_ taskeng.exe (6024)
     |_ UPM.exe (3196)

[?] aswlnpkg.dll
 |_ Cesta: C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll
 |_ MD5: 2EEDA27C19259C2340324EF7180D086B
 |_ Výrobce:  Cognizance Corporation
 |_ Procesy
     |_ lsass.exe (796)
     |_ svchost.exe (1028)

[?] itmsg.dll
 |_ Cesta: C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItMsg.dll
 |_ MD5: 2D45936EE6F7EDB9DDB0997F7373B7E3
 |_ Výrobce:  Cognizance Corporation
 |_ Procesy
     |_ lsass.exe (796)
     |_ asghost.exe (2824)

[?] msvcr70.dll
 |_ Cesta: C:\Windows\System32\msvcr70.dll
 |_ MD5: 5A542C4E0F036431D0B7B607FC08758F
 |_ Výrobce:  Microsoft Corporation
 |_ Procesy
     |_ lsass.exe (796)
     |_ svchost.exe (1028)
     |_ asghost.exe (2824)
     |_ explorer.exe (2360)

[?] aschnl.dll
 |_ Cesta: C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASChnl.dll
 |_ MD5: BB3C0521ECCA4BB17AC55EB640DF0FA5
 |_ Výrobce:  Cognizance Corporation
 |_ Procesy
     |_ svchost.exe (1028)
     |_ asghost.exe (2824)

[?] itreports.dll
 |_ Cesta: C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItReports.dll
 |_ MD5: 499D5D393ED5E857E15C698681F88EB1
 |_ Výrobce:  Cognizance Corporation
 |_ Procesy
     |_ svchost.exe (1028)
     |_ asghost.exe (2824)

[?] itdac.dll
 |_ Cesta: C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItDAC.dll
 |_ MD5: 3D6BC61A133F7E0BCE8A402AB6C0BB89
 |_ Výrobce:  Cognizance Corporation
 |_ Procesy
     |_ svchost.exe (1028)
     |_ asghost.exe (2824)

[?] authwiz.dll
 |_ Cesta: C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\AuthWiz.dll
 |_ MD5: 87EDA5B1F79783909E0F8599C665C6DF
 |_ Výrobce:  Cognizance Corporation
 |_ Procesy
     |_ svchost.exe (1028)
     |_ asghost.exe (2824)

[?] bioauthsrv.dll
 |_ Cesta: C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\BioAuthSrv.dll
 |_ MD5: 687238E9301D6014709F37A0CCC8027B
 |_ Výrobce:  Cognizance Corporation
 |_ Procesy
     |_ svchost.exe (1028)

[?] itvcserver.dll
 |_ Cesta: C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItVCServer.dll
 |_ MD5: F0B91ABC28A32C16A7F281BAA1A9EF15
 |_ Výrobce:  Cognizance Corporation
 |_ Procesy
     |_ svchost.exe (1028)

[?] itauth.dll
 |_ Cesta: C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItAuth.dll
 |_ MD5: C380558BF897A1DC4B0E096BF93DEAC0
 |_ Výrobce:  Cognizance Corporation
 |_ Procesy
     |_ svchost.exe (1028)

[?] itvcard.dll
 |_ Cesta: C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItVCard.dll
 |_ MD5: 53DC82B1A5BFE755CB44860EF24E6D16
 |_ Výrobce:  Cognizance Corporation
 |_ Procesy
     |_ svchost.exe (1028)
     |_ asghost.exe (2824)

[?] netadmin.dll
 |_ Cesta: C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\NetAdmin.dll
 |_ MD5: A905DF4631F440D7251FFE5122430A54
 |_ Výrobce:  Cognizance Corporation
 |_ Procesy
     |_ svchost.exe (1028)
     |_ asghost.exe (2824)

[?] petpm.dll
 |_ Cesta: C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\PETpm.dll
 |_ MD5: 430BCA3028C19D8908303FB1E96204B5
 |_ Výrobce:  Cognizance Corporation
 |_ Procesy
     |_ svchost.exe (1028)

[?] pesched.dll
 |_ Cesta: C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\PESched.dll
 |_ MD5: 7249266DFCA14436139E1C1AE9EF0773
 |_ Výrobce:  Cognizance Corporation
 |_ Procesy
     |_ svchost.exe (1028)

[?] peactiverule.dll
 |_ Cesta: C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\PEActiveRule.dll
 |_ MD5: 89BF3E7DD77ECF73BFEF719FC7176670
 |_ Výrobce:  Cognizance Corporation
 |_ Procesy
     |_ svchost.exe (1028)

[?] pecustom.dll
 |_ Cesta: C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\pecustom.dll
 |_ MD5: B101E536D1B97492A8D8BBF6537ED1C7
 |_ Výrobce:  Cognizance Corporation
 |_ Procesy
     |_ svchost.exe (1028)

[?] peauth.dll
 |_ Cesta: C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\PEAuth.dll
 |_ MD5: 15B9544A4322EF665A2D23F325929785
 |_ Výrobce:  Cognizance Corporation
 |_ Procesy
     |_ svchost.exe (1028)

[?] lssproxy.dll
 |_ Cesta: C:\Program Files\Common Files\LightScribe\LSSProxy.dll
 |_ MD5: E56015C72702309F87FA44AC23BA284D
 |_ Výrobce:  Hewlett-Packard Company
 |_ Procesy
     |_ LSSrvc.exe (2464)

[?] lslog.dll
 |_ Cesta: C:\Program Files\Common Files\LightScribe\LSLog.dll
 |_ MD5: 0DEBB0F383C1F71FFF1A5D5F27B8B5F0
 |_ Výrobce:  Hewlett-Packard Company
 |_ Procesy
     |_ LSSrvc.exe (2464)

[?] ssleay32.dll
 |_ Cesta: C:\Program Files\PostgreSQL\8.3\bin\ssleay32.dll
 |_ MD5: 19174858C208FABFA5C79013D0E406CD
 |_ Výrobce:  The OpenSSL Project, http://www.openssl.org/
 |_ Procesy
     |_ pg_ctl.exe (2748)
     |_ postgres.exe (2932)
     |_ postgres.exe (3092)
     |_ postgres.exe (3164)
     |_ postgres.exe (3172)
     |_ postgres.exe (3180)
     |_ postgres.exe (3188)

[?] libeay32.dll
 |_ Cesta: C:\Program Files\PostgreSQL\8.3\bin\libeay32.dll
 |_ MD5: 29B0D8A99C2BD0B6D5093FACE4E5F52C
 |_ Výrobce:  The OpenSSL Project, http://www.openssl.org/
 |_ Procesy
     |_ pg_ctl.exe (2748)
     |_ postgres.exe (2932)
     |_ postgres.exe (3092)
     |_ postgres.exe (3164)
     |_ postgres.exe (3172)
     |_ postgres.exe (3180)
     |_ postgres.exe (3188)

[?] comerr32.dll
 |_ Cesta: C:\Program Files\PostgreSQL\8.3\bin\comerr32.dll
 |_ MD5: D2B96B34A34A9D2E3903C3A978F26857
 |_ Výrobce:  Massachusetts Institute of Technology.
 |_ Procesy
     |_ pg_ctl.exe (2748)

[?] k5sprt32.dll
 |_ Cesta: C:\Program Files\PostgreSQL\8.3\bin\k5sprt32.dll
 |_ MD5: E8F42B0DC3CA94EED0E87E29FC788D21
 |_ Výrobce:  Massachusetts Institute of Technology.
 |_ Procesy
     |_ pg_ctl.exe (2748)
     |_ postgres.exe (2932)
     |_ postgres.exe (3092)
     |_ postgres.exe (3164)
     |_ postgres.exe (3172)
     |_ postgres.exe (3180)
     |_ postgres.exe (3188)

[?] gssapi32.dll
 |_ Cesta: C:\Program Files\PostgreSQL\8.3\bin\gssapi32.dll
 |_ MD5: A1C71790ABF6B7EF920138C5942316AF
 |_ Výrobce:  Massachusetts Institute of Technology.
 |_ Procesy
     |_ pg_ctl.exe (2748)
     |_ postgres.exe (2932)
     |_ postgres.exe (3092)
     |_ postgres.exe (3164)
     |_ postgres.exe (3172)
     |_ postgres.exe (3180)
     |_ postgres.exe (3188)

[?] libiconv2.dll
 |_ Cesta: C:\Program Files\PostgreSQL\8.3\bin\libiconv2.dll
 |_ MD5: 331F570AA7C20BC93DEB7B237B21CC9C
 |_ Výrobce:  GNU <www.gnu.org>
 |_ Procesy
     |_ pg_ctl.exe (2748)
     |_ postgres.exe (2932)
     |_ postgres.exe (3092)
     |_ postgres.exe (3164)
     |_ postgres.exe (3172)
     |_ postgres.exe (3180)
     |_ postgres.exe (3188)

[?] krb5_32.dll
 |_ Cesta: C:\Program Files\PostgreSQL\8.3\bin\krb5_32.dll
 |_ MD5: 249C1B8608B8C73DAC8E6AD7912B1271
 |_ Výrobce:  Massachusetts Institute of Technology.
 |_ Procesy
     |_ pg_ctl.exe (2748)
     |_ postgres.exe (2932)
     |_ postgres.exe (3092)
     |_ postgres.exe (3164)
     |_ postgres.exe (3172)
     |_ postgres.exe (3180)
     |_ postgres.exe (3188)

[?] libintl3.dll
 |_ Cesta: C:\Program Files\PostgreSQL\8.3\bin\libintl3.dll
 |_ MD5: D202BAA425176287017FFE1FB5D1B77C
 |_ Výrobce:  GNU <www.gnu.org>
 |_ Procesy
     |_ pg_ctl.exe (2748)
     |_ postgres.exe (2932)
     |_ postgres.exe (3092)
     |_ postgres.exe (3164)
     |_ postgres.exe (3172)
     |_ postgres.exe (3180)
     |_ postgres.exe (3188)

[?] spdiskex.dll
 |_ Cesta: C:\Program Files\ASUS\NB Probe\SPM\SPDISKEX.dll
 |_ MD5: 89A3FADBE9B26453C71B3B365AB70F9B
 |_ Výrobce:  
 |_ Procesy
     |_ spmgr.exe (2800)

[?] spdmi.dll
 |_ Cesta: C:\Program Files\ASUS\NB Probe\SPM\spdmi.dll
 |_ MD5: DB029472E09F7C5DB7AB05BA2833193B
 |_ Výrobce:  
 |_ Procesy
     |_ spmgr.exe (2800)

[?] libxml2.dll
 |_ Cesta: C:\Program Files\PostgreSQL\8.3\bin\libxml2.dll
 |_ MD5: 096D5E5683819F0D3B3F93428597A29C
 |_ Výrobce:  
 |_ Procesy
     |_ postgres.exe (2932)
     |_ postgres.exe (3092)
     |_ postgres.exe (3164)
     |_ postgres.exe (3172)
     |_ postgres.exe (3180)
     |_ postgres.exe (3188)

[?] iconv.dll
 |_ Cesta: C:\Program Files\PostgreSQL\8.3\bin\iconv.dll
 |_ MD5: 73AF5773BF5627FE771BF6809EC839F9
 |_ Výrobce:  Free Software Foundation
 |_ Procesy
     |_ postgres.exe (2932)
     |_ postgres.exe (3092)
     |_ postgres.exe (3164)
     |_ postgres.exe (3172)
     |_ postgres.exe (3180)
     |_ postgres.exe (3188)

[?] plugin_debugger.dll
 |_ Cesta: C:\Program Files\PostgreSQL\8.3\lib\plugins\plugin_debugger.dll
 |_ MD5: 7609C14BB34922001C005668BB306A43
 |_ Výrobce:  
 |_ Procesy
     |_ postgres.exe (2932)

[?] itclient.dll
 |_ Cesta: C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItClient.dll
 |_ MD5: 09F3739CAA67E693C22E8C3961B23113
 |_ Výrobce:  Cognizance Corporation
 |_ Procesy
     |_ dwm.exe (2764)
     |_ asghost.exe (2824)
     |_ explorer.exe (2360)
     |_ taskeng.exe (3616)
     |_ rundll32.exe (3596)
     |_ RtHDVCpl.exe (3796)
     |_ DMedia.exe (4132)
     |_ GrooveMonitor.exe (4212)
     |_ AvastUI.exe (4272)
     |_ LightScribeControlPanel.exe (4400)
     |_ GoogleToolbarNotifier.exe (4512)
     |_ m.2AAA.tmp.exe (4968)
     |_ BTTray.exe (5024)
     |_ BTStackServer.exe (5744)
     |_ wuauclt.exe (3404)

[?] btmmhook.dll
 |_ Cesta: C:\Windows\System32\BtMmHook.dll
 |_ MD5: 215C6604942A198C679188D0E83AF812
 |_ Výrobce:  Broadcom Corporation.
 |_ Procesy
     |_ dwm.exe (2764)
     |_ explorer.exe (2360)
     |_ AvastUI.exe (4272)
     |_ LightScribeControlPanel.exe (4400)
     |_ m.2AAA.tmp.exe (4968)
     |_ BTTray.exe (5024)
     |_ notepad.exe (5924)
     |_ chrome.exe (1844)

[?] rasadmin.dll
 |_ Cesta: C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\RasAdmin.dll
 |_ MD5: 68586D694F957BB9C96B3EB840D8335C
 |_ Výrobce:  Cognizance Corporation
 |_ Procesy
     |_ asghost.exe (2824)

[?] itsso.dll
 |_ Cesta: C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItSSO.dll
 |_ MD5: 663CCCA76CB493E4E9605EDBC82BFCA9
 |_ Výrobce:  Cognizance Corporation
 |_ Procesy
     |_ asghost.exe (2824)

[?] pkiadmin.dll
 |_ Cesta: C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\PkiAdmin.dll
 |_ MD5: 1B6C774A43709852C2DAC77664B23792
 |_ Výrobce:  Cognizance Corporation
 |_ Procesy
     |_ asghost.exe (2824)

[?] itvcclient.dll
 |_ Cesta: C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItVCClient.dll
 |_ MD5: C4F43529C811B94BA18F6AF1A2A037F4
 |_ Výrobce:  Cognizance Corporation
 |_ Procesy
     |_ asghost.exe (2824)

[?] itaps.dll
 |_ Cesta: C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItAPS.dll
 |_ MD5: 733A886451F373E32E2B7BF67DE218E8
 |_ Výrobce:  Cognizance Corporation
 |_ Procesy
     |_ asghost.exe (2824)

[?] trayicon.dll
 |_ Cesta: C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\TrayIcon.dll
 |_ MD5: FB08BCE79B6C26575C6863E6580CB820
 |_ Výrobce:  Cognizance Corporation
 |_ Procesy
     |_ asghost.exe (2824)

[?] bioauth.dll
 |_ Cesta: C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\BioAuth.dll
 |_ MD5: E43C541A78FD73AD7161465739F524D1
 |_ Výrobce:  Cognizance Corporation
 |_ Procesy
     |_ asghost.exe (2824)

[?] ssomngr.dll
 |_ Cesta: C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\SSOMngr.dll
 |_ MD5: F464B74D0BA8D766F6BACD6C8740E894
 |_ Výrobce:  Cognizance Corporation
 |_ Procesy
     |_ asghost.exe (2824)

[?] ittal.dll
 |_ Cesta: C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ittal.dll
 |_ MD5: 1EE5E81C26E4F15165D81179F8C5712C
 |_ Výrobce:  Cognizance Corporation
 |_ Procesy
     |_ asghost.exe (2824)

[?] atsc70.dll
 |_ Cesta: C:\Windows\System32\ATSC70.dll
 |_ MD5: CFF0732A3C7410A11618D95F03F25046
 |_ Výrobce:  AuthenTec, Inc.
 |_ Procesy
     |_ asghost.exe (2824)

[?] asbioat.dll
 |_ Cesta: C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASBioAT.dll
 |_ MD5: FEDDA1F46E9E902B7870CD7C10AFE1BB
 |_ Výrobce:  Cognizance Corporation
 |_ Procesy
     |_ asghost.exe (2824)

[X] cmdlineext03.dll
 |_ Cesta: C:\Windows\System32\CmdLineExt03.dll
 |_ MD5: 67B70916848C377BFF8733850654460D
 |_ Výrobce:  
 |_ Procesy
     |_ explorer.exe (2360)

[?] btkeyind.dll
 |_ Cesta: C:\Program Files\WIDCOMM\Bluetooth Software\BTKeyInd.dll
 |_ MD5: 1BE828F6C3AFAD7E20F2C4D94424271C
 |_ Výrobce:  
 |_ Procesy
     |_ explorer.exe (2360)
     |_ m.2AAA.tmp.exe (4968)
     |_ BTTray.exe (5024)
     |_ notepad.exe (5924)
     |_ chrome.exe (1844)

[?] atl80.dll
 |_ Cesta: C:\Windows\winsxs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d1c738ec43578ea1\ATL80.dll
 |_ MD5: 3E9A33113D663D8BD5ED38858E669652
 |_ Výrobce:  Microsoft Corporation
 |_ Procesy
     |_ explorer.exe (2360)
     |_ GrooveMonitor.exe (4212)
     |_ chrome.exe (1844)
     |_ UPM.exe (3196)

[?] gzlib.dll
 |_ Cesta: C:\Program Files\Google\Google Desktop Search\gzlib.dll
 |_ MD5: C0D0179784C543BDF297932FAFA2BB20
 |_ Výrobce:  
 |_ Procesy
     |_ GoogleDesktop.exe (776)

[?] googledesktophyper.dll
 |_ Cesta: C:\Program Files\Google\Google Desktop Search\GoogleDesktopHyper.dll
 |_ MD5: 6F3ADA96F3E73D4FF39D0C284D5E0C9D
 |_ Výrobce:  Google
 |_ Procesy
     |_ GoogleDesktop.exe (776)

[?] googleservices.dll
 |_ Cesta: C:\Program Files\Google\Google Desktop Search\GoogleServices.dll
 |_ MD5: 59DAC066B544F434F3EF8FBE52BCF6CF
 |_ Výrobce:  Google
 |_ Procesy
     |_ GoogleDesktop.exe (776)

[?] googledesktopresources_cs.dll
 |_ Cesta: C:\Program Files\Google\Google Desktop Search\GoogleDesktopResources_cs.dll
 |_ MD5: 29CE7718091DB96304A048BB457BA6E4
 |_ Výrobce:  Google
 |_ Procesy
     |_ GoogleDesktop.exe (776)
     |_ chrome.exe (1844)
     |_ chrome.exe (4508)

[?] googledesktopapi2.dll
 |_ Cesta: C:\Program Files\Google\Google Desktop Search\GoogleDesktopAPI2.dll
 |_ MD5: CCA0000B5F9F73ACA4B74D60D590AC48
 |_ Výrobce:  Google
 |_ Procesy
     |_ GoogleDesktop.exe (776)

[?] googledesktopcommon.dll
 |_ Cesta: C:\Program Files\Google\Google Desktop Search\GoogleDesktopCommon.dll
 |_ MD5: DF5F4ECACF6DF29A0738CCAE7E322371
 |_ Výrobce:  Google
 |_ Procesy
     |_ GoogleDesktop.exe (776)
     |_ chrome.exe (1844)

[?] msgtran.dll
 |_ Cesta: C:\Program Files\ASUS\ATK Hotkey\MsgTran.dll
 |_ MD5: FCAA0F8B19F2C9CBA0F60CB4E19D7854
 |_ Výrobce:  ?
 |_ Procesy
     |_ HControlUser.exe (3948)

[?] atkmethod.dll
 |_ Cesta: C:\Program Files\ASUS\ATK Media\ATKMETHOD.dll
 |_ MD5: 69F879DE639049AB5E1DBF6D1DAA3020
 |_ Výrobce:  ASUS
 |_ Procesy
     |_ DMedia.exe (4132)

[?] lameacm.acm
 |_ Cesta: C:\Windows\System32\lameACM.acm
 |_ MD5: 22722B4E887BB95AB071542DE5A42C80
 |_ Výrobce:  http://www.mp3dev.org/
 |_ Procesy
     |_ AvastUI.exe (4272)

[?] btwhidcs.dll
 |_ Cesta: C:\Windows\System32\btwhidcs.dll
 |_ MD5: 0D307F4CF6F6CF984492E794DCF52E0F
 |_ Výrobce:  Broadcom Corporation.
 |_ Procesy
     |_ BTTray.exe (5024)

[?] btballoon.dll
 |_ Cesta: C:\Program Files\WIDCOMM\Bluetooth Software\BtBalloon.dll
 |_ MD5: 50395FE39EBB08EA8A168A3FF0C2BA97
 |_ Výrobce:  Broadcom Corporation.
 |_ Procesy
     |_ BTTray.exe (5024)

[?] btrez.dll
 |_ Cesta: C:\Windows\System32\btrez.dll
 |_ MD5: 11266E957FBCD6EAB1806280EC91B3D1
 |_ Výrobce:  Broadcom Corporation.
 |_ Procesy
     |_ BTTray.exe (5024)

[?] btwapi.dll
 |_ Cesta: C:\Windows\System32\btwapi.dll
 |_ MD5: 2DBACA6458526265DC882A86DB126CF4
 |_ Výrobce:  Broadcom Corporation.
 |_ Procesy
     |_ BTTray.exe (5024)

[?] mfc80u.dll
 |_ Cesta: C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_cbf21254470d8752\MFC80U.DLL
 |_ MD5: 686B224B4987C22B153FBB545FEE9657
 |_ Výrobce:  Microsoft Corporation
 |_ Procesy
     |_ BTTray.exe (5024)

[?] mfc80.dll
 |_ Cesta: C:\Windows\winsxs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_cbf21254470d8752\mfc80.dll
 |_ MD5: 4928AB3A304DDF05C354DE3807A4A66B
 |_ Výrobce:  Microsoft Corporation
 |_ Procesy
     |_ BTTray.exe (5024)
     |_ BTStackServer.exe (5744)

[?] btosif.dll
 |_ Cesta: C:\Windows\System32\btosif.dll
 |_ MD5: A70CE182D6C6325095B9760F046693A4
 |_ Výrobce:  Broadcom Corporation.
 |_ Procesy
     |_ BTStackServer.exe (5744)

[?] goec62~1.dll
 |_ Cesta: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
 |_ MD5: 6434B5F02751B9140DEECF4E4A3BAB47
 |_ Výrobce:  Google
 |_ Procesy
     |_ chrome.exe (1844)
     |_ chrome.exe (4508)



================================================================
Ultimate Process Manager v4.1.3 - [ Lodus Software ]

Re: log z UPM

Napsal: 20 říj 2010 18:54
od Rudy
Dejte log z ComboFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode, pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k nezadoucim kolizim s rezidentem antispyware

Re: log z UPM

Napsal: 20 říj 2010 20:25
od gerry2
Možná se to bude trochu odlišovat od toho předchozího logu, nainstaloval jsem si totiž SpywareTerminator a ten už nějaké věci našel, ale pořád tam ještě nějaká haveť podle mě je. Níže je log z combofixu. Ta složka Antivirus 2010 byla podle mě určitě vir, ale když jsem ji předtím otvíral tak v ní nic nebylo.

Kód: Vybrat vše

ComboFix 10-10-19.04 - Honza 20.10.2010  20:47:20.1.2 - x86
Microsoft® Windows Vista™ Home Premium   6.0.6001.1.1250.420.1029.18.3070.2062 [GMT 2:00]
Spuštěný z: c:\users\Honza\Downloads\ComboFix.exe
SP: Spyware Terminator *disabled* (Updated) {55EE49A8-16BE-4601-BBE6-607B7F7317DE}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

(((((((((((((((((((((((((((((((((((((((   Ostatní výmazy   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Honza\AppData\Roaming\AntiVirus 2010
c:\users\Honza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AntiVirus 2010
c:\users\Honza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AntiVirus 2010.lnk
c:\users\Honza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AntiVirus 2010\Activate AntiVirus 2010.lnk
c:\users\Honza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AntiVirus 2010\AntiVirus 2010.lnk
c:\users\Honza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AntiVirus 2010\Help AntiVirus 2010.lnk
c:\users\Honza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AntiVirus 2010\How to Activate AntiVirus 2010.lnk

.
(((((((((((((((((((((((((   Soubory vytvořené od 2010-09-20 do 2010-10-20  )))))))))))))))))))))))))))))))
.

2010-10-20 19:00 . 2010-10-20 19:04	--------	d-----w-	c:\users\Honza\AppData\Local\temp
2010-10-20 19:00 . 2010-10-20 19:00	--------	d-----w-	c:\users\postgres\AppData\Local\temp
2010-10-20 19:00 . 2010-10-20 19:00	--------	d-----w-	c:\users\Default\AppData\Local\temp
2010-10-20 12:55 . 2010-10-20 15:48	--------	d-----w-	c:\program files\WinClamAVShield
2010-10-20 12:53 . 2010-10-20 12:53	142592	----a-w-	c:\windows\system32\drivers\sp_rsdrv2.sys
2010-10-20 12:53 . 2010-10-20 12:58	--------	d-----w-	c:\users\Honza\AppData\Roaming\Spyware Terminator
2010-10-20 12:53 . 2010-10-20 15:52	--------	d-----w-	c:\programdata\Spyware Terminator
2010-10-20 12:53 . 2010-10-20 15:57	--------	d-----w-	c:\program files\Spyware Terminator
2010-10-20 12:09 . 2010-10-20 12:10	--------	d-----w-	c:\program files\Ultimate Process Manager
2010-10-19 07:11 . 2010-10-07 23:21	6146896	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{EB4B9F27-A723-435C-8ED3-F7A666A89EBC}\mpengine.dll
2010-10-17 11:48 . 2010-10-17 11:49	--------	d-----w-	c:\program files\OPoker.com
2010-10-14 20:57 . 2010-10-14 20:57	--------	d-----w-	c:\program files\Common Files\Adobe AIR
2010-10-14 20:56 . 2010-10-14 20:56	--------	d-----w-	c:\programdata\McAfee
2010-10-14 07:05 . 2010-09-20 09:25	231936	----a-w-	c:\windows\system32\msshsq.dll
2010-10-13 08:08 . 2010-09-10 16:37	8147456	----a-w-	c:\windows\system32\wmploc.DLL
2010-10-13 08:08 . 2010-09-10 16:35	168960	----a-w-	c:\program files\Windows Media Player\wmplayer.exe
2010-10-10 20:28 . 2010-10-10 20:44	--------	d-----w-	c:\program files\BetClic Poker
2010-10-08 19:19 . 2010-10-08 19:19	2829	----a-w-	c:\windows\War3Unin.pif
2010-10-08 19:19 . 2010-10-08 19:19	126976	----a-w-	c:\windows\War3Unin.exe
2010-10-08 19:14 . 2010-10-20 15:51	--------	d-----w-	c:\program files\Warcraft III
2010-09-29 05:20 . 2010-06-22 12:57	2048	----a-w-	c:\windows\system32\tzres.dll
2010-09-28 19:16 . 2010-09-28 19:16	--------	d-----w-	c:\users\Honza\AppData\Local\Broad Intelligence
2010-09-28 18:56 . 2010-09-29 11:47	--------	d-----w-	c:\users\Honza\AppData\Roaming\Broad Intelligence
2010-09-28 18:05 . 2010-09-28 18:05	--------	d-----w-	c:\program files\uTorrent
2010-09-28 18:05 . 2010-09-28 18:12	--------	d-----w-	c:\users\Honza\AppData\Roaming\uTorrent
2010-09-26 16:35 . 2010-10-01 06:34	--------	d-----w-	c:\program files\Microsoft Silverlight
2010-09-22 16:10 . 2010-09-22 16:10	103864	----a-w-	c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2010-09-22 16:10 . 2010-09-22 16:10	103864	----a-w-	c:\program files\Internet Explorer\Plugins\nppdf32.dll

.
((((((((((((((((((((((((((((((((((((((((   Find3M výpis   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-14 19:48 . 2009-01-12 19:42	119808	----a-w-	c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.

((((((((((((((((((((((((((((((((((   Spouštěcí body v registru   )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny. 
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2009-04-24 203928]
"googletalk"="c:\users\Honza\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"PicPick Start"="c:\program files\PicPick\picpick.exe" [2010-06-01 3961344]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-26 39408]
"Mikogo"="c:\users\Honza\AppData\Roaming\Mikogo\Mikogo-Host.exe" [2010-07-15 2748416]
"SpywareTerminatorUpdate"="c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe" [2010-10-20 3037696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"CLMLServer"="c:\program files\CyberLink\Power2Go\CLMLSvc.exe" [2008-07-19 104936]
"P2Go_Menu"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-07-14 30192]
"HControlUser"="c:\program files\ASUS\ATK Hotkey\HControlUser.exe" [2008-01-12 98304]
"ATKOSD2"="c:\program files\ASUS\ATKOSD2\ATKOSD2.exe" [2008-07-15 7651328]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-07-25 13548064]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-07-25 92704]
"RtHDVCpl"="RtHDVCpl.exe" [2008-06-13 6183456]
"CognizanceTS"="c:\progra~1\ASUSSE~1\ASUSSE~1\Bin\ASTSVCC.dll" [2003-12-22 17920]
"ATKMEDIA"="c:\program files\ASUS\ATK Media\DMedia.exe" [2008-08-19 159744]
"ASUS Screen Saver Protector"="c:\windows\AsScrPro.exe" [2008-10-26 3054136]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-07-03 1328424]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"TO2SSM_McciTrayApp"="c:\program files\TO2SSM\McciTrayApp.exe" [2008-08-15 1473536]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-09-07 2838912]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2010-10-20 2183680]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-5-19 113664]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-7-30 752168]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll c:\windows\System32\APSHook.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnk.CommonStartup
backupExtension=.CommonStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-04-23 13:51	691656	----a-w-	c:\program files\DAEMON Tools Lite\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-09-01 06:32	421160	----a-w-	c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mikogo]
2010-07-15 22:06	2748416	----a-w-	c:\users\Honza\AppData\Roaming\Mikogo\Mikogo-Host.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-08-10 03:15	421888	----a-w-	c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-08-24 09:23	1242448	----a-w-	c:\program files\Steam\Steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2008-10-26 22:37	39408	----a-w-	c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2009-07-01 16:37	37888	----a-w-	c:\program files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 Axtmvflt;Axesstel USB Filter Service;c:\windows\system32\DRIVERS\Axtmvflt.sys [2007-09-20 3456]
R3 Axtmvmdm;Axesstel USB Modem;c:\windows\system32\DRIVERS\Axtmvmdm.sys [2007-09-20 40064]
R3 Axtmvprt;Axesstel Diagnostic Port;c:\windows\system32\Drivers\Axtmvprt.sys [2007-06-27 38784]
R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-07-14 30192]
R3 jatmlano;jatmlano;c:\users\Honza\AppData\Local\Temp\jatmlano.sys [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2009-05-11 721904]
S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys [2008-05-29 15416]
S1 aswSP;aswSP; [x]
S1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2010-10-20 142592]
S2 ASBroker;Logon Session Broker;c:\windows\System32\svchost.exe [2008-01-21 21504]
S2 ASChannel;Local Communication Channel;c:\windows\System32\svchost.exe [2008-01-21 21504]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-09-07 50768]
S2 pgsql-8.3;PostgreSQL Database Server 8.3;c:\program files\PostgreSQL\8.3\bin\pg_ctl.exe [2008-09-19 65536]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2008-01-29 29736]
S3 DCamUSBET;USB2.0 1.3M UVC WebCam;c:\windows\system32\DRIVERS\etDevice.sys [2007-09-06 474624]
S3 FiltUSBET;ET USB Device Lower Filter;c:\windows\system32\DRIVERS\etFilter.sys [2007-10-15 206336]
S3 itecir;ITECIR Infrared Receiver;c:\windows\system32\DRIVERS\itecir.sys [2007-12-19 54784]
S3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-06-25 3662848]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-06-25 44064]
S3 ScanUSBET;ET USB Still Image Capture Device;c:\windows\system32\DRIVERS\etScan.sys [2007-09-06 6656]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs	REG_MULTI_SZ   	BthServ
Cognizance	REG_MULTI_SZ   	ASBroker ASChannel

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 17:14	451872	----a-w-	c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'

2010-10-19 c:\windows\Tasks\User_Feed_Synchronization-{08597576-552B-4701-956B-4B59998EFBF9}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:24]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.cz/
uDefault_Search_URL = hxxp://search.qip.ru
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=ASUS&bmod=ASUS
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://search.qip.ru/ie
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Free YouTube to Mp3 Converter - c:\users\Honza\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm
FF - ProfilePath - c:\users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\aptjt242.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=
FF - prefs.js: browser.search.selectedEngine - Winamp Search
FF - prefs.js: browser.startup.homepage - hxxp://google.cz/
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query=
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Opera 10 Beta\program\plugins\NPOFF12.DLL
FF - plugin: c:\program files\Opera 10 Beta\program\plugins\npqtplugin.dll
FF - plugin: c:\program files\Opera 10 Beta\program\plugins\npqtplugin2.dll
FF - plugin: c:\program files\Opera 10 Beta\program\plugins\npqtplugin3.dll
FF - plugin: c:\program files\Opera 10 Beta\program\plugins\npqtplugin4.dll
FF - plugin: c:\program files\Opera 10 Beta\program\plugins\npqtplugin5.dll
FF - plugin: c:\program files\Opera 10 Beta\program\plugins\npqtplugin6.dll
FF - plugin: c:\program files\Opera 10 Beta\program\plugins\npqtplugin7.dll
FF - plugin: c:\program files\Opera 10 Beta\program\plugins\NPSWF32.dll
FF - plugin: c:\program files\Picasa2\npPicasa2.dll
FF - plugin: c:\users\Honza\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

HKCU-Run-chromeexeChrome - c:\users\honza\appdata\local\google\chrome\application\chromegoogle.exe
HKCU-Run-ChromeGoogle - c:\users\Honza\AppData\Local\Google\Chrome\Application\chromeGoogle.exe
HKCU-Run-dotazuSeznamcz3336 - c:\users\honza\documents\centrum\weby a projekty\mfa\scany keywordů\disney channel\hledanostichannel.exe
HKCU-RunServices-avastantivirus - c:\users\Honza\AppData\Local\Temp\0.25951143129805265.exe
HKCU-RunServices-footerfooter - c:\users\honza\documents\centrum\weby a projekty\kérky.cz\ftp\prestashop theme\footerkopie.exe
HKCU-RunServices-Statistikyhledanosti22144 - c:\users\honza\documents\centrum\weby a projekty\mfa\destinace scany key\lefkáda\seznamczstatistiky9743.exe
HKCU-RunServices-Seznamczhledanosti15212 - c:\users\honza\documents\centrum\weby a projekty\mfa\scany keywordů\disney channel\hledanostichannel.exe
HKCU-RunServices-SmallSmall - c:\users\honza\appdata\local\adobe\reader 9.4\setup files\smallsetup.exe
HKCU-RunServices-MicrosoftSetupResources - c:\users\honza\appdata\local\temp\microsoft .net framework 4 setup_4.0.30319\1053\setupresourcesmicrosoft.exe
HKCU-RunServices-chromeChrome - c:\users\Honza\AppData\Local\Google\Chrome\Application\chromeGoogle.exe
MSConfigStartUp-PTimer - c:\program files\SPRINX\PTimer\PTimer.exe
MSConfigStartUp-uTodo - c:\program files\uTodo\uTodo.exe
AddRemove-Expekt Poker - c:\poker\Expekt Poker\_SetupPoker.exe


.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0010\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'lsass.exe'(776)
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItMsg.dll

- - - - - - - > 'Explorer.exe'(2300)
c:\windows\system32\APSHook.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItClient.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\ASUS\ATK Hotkey\ASLDRSrv.exe
c:\program files\ATKGFNEX\GFNEXSrv.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\program files\ASUS\NB Probe\SPM\spmgr.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\program files\Spyware Terminator\sp_rsser.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\program files\PostgreSQL\8.3\bin\postgres.exe
c:\windows\servicing\TrustedInstaller.exe
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsGHost.exe
c:\program files\ASUS\SmartLogon\sensorsrv.exe
c:\windows\system32\conime.exe
c:\program files\ASUS\ATK Hotkey\MsgTranAgt.exe
c:\program files\ASUS\ATK Hotkey\HControl.exe
c:\program files\Wireless Console 2\wcourier.exe
c:\program files\ASUS\ASUS CopyProtect\aspg.exe
c:\program files\P4G\BatteryLife.exe
c:\program files\ASUS\Splendid\ACMON.exe
c:\windows\System32\ACEngSvr.exe
c:\program files\ASUS\ATK Hotkey\ATKOSD.exe
c:\program files\ASUS\ATK Hotkey\KBFiltr.exe
c:\program files\ASUS\ATK Hotkey\WDC.exe
c:\windows\system32\wbem\unsecapp.exe
.
**************************************************************************
.
Celkový čas: 2010-10-20  21:11:41 - počítač byl restartován
ComboFix-quarantined-files.txt  2010-10-20 19:11

Před spuštěním: Volných bajtů: 16 746 979 328
Po spuštění: Volných bajtů: 17 971 593 216

Current=1 Default=1 Failed=0 LastKnownGood=11 Sets=1,2,3,4,5,6,7,8,9,11
- - End Of File - - DC447C85410A9223A3CF10E4A3C835D7

Re: log z UPM

Napsal: 20 říj 2010 21:44
od Rudy
Několik položek bylo smazáno, zbytek logu vypadá čistý. Nastala nějaká změna?

Re: log z UPM

Napsal: 20 říj 2010 22:09
od gerry2
Teď když jsem ještě restartoval PC tak už to vypadá ok. Ta vyskakovací okna s reklamou už zmizely a avast už taky nehlásí nějaké blokování trojanů apod. Takže to vypadá že kombinace SpywareTerminator+combofix pomohla :)

Re: log z UPM

Napsal: 21 říj 2010 18:06
od Rudy
Pokud je vše v pořádku, jsem jen rád, že je další PC čistý. :)