Prosim o kontrolu logu.dekuji
Napsal: 26 lis 2010 15:23
Windows XP SP 2 (build 2600)
Boot Mode: Normal
Ověření souborů Microsoftu: Ano
Whitelist: Ano
Internet Explorer v6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
Log vygenerován: 26.11.2010 9:09:21
================================================================
SmallARK
================================================================
[?]NtCreateKey -> spyr.sys
[?]NtEnumerateKey -> spyr.sys
[?]NtEnumerateValueKey -> spyr.sys
[?]NtOpenKey -> spyr.sys
[?]NtQueryKey -> spyr.sys
[?]NtQueryValueKey -> spyr.sys
[?]NtSetValueKey -> spyr.sys
Běžící procesy
================================================================
C:\PROGRAM FILES\ESRI\LICENSE\ARCGIS9X\ARCGIS.EXE
C:\WINDOWS\SYSTEM32\NVSVC32.EXE
C:\PROGRAM FILES\ATKOSD2\ATKOSD2.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRAM FILES\COMMON FILES\AHEAD\LIB\NMBGMONITOR.EXE
Scanner
================================================================
[S] csrss.exe
Podvržená cesta modulu: (00270000) [DLL] ?
[S] explorer.exe
Spouští se po startu HKLM Winlogon [Shell]
Podvržená cesta modulu: (001A0000) [DLL] ?
[?] ARCGIS.EXE
Bez výrobce
Nemá okno
Soubor 12%
[?] nvsvc32.exe
Non Microsoft v System32:
[?] ATKOSD2.exe
Bez výrobce
Spouští se po startu HKLM Run [ATKOSD2]
Soubor 25%
[S] rundll32.exe
Spouští se po startu HKLM Run [NvCplDaemon]
[R] nod32kui.exe
Spouští se po startu HKLM Run [nod32kui]
[R] jusched.exe
Spouští se po startu HKLM Run [SunJavaUpdateSched]
[?] RTHDCPL.exe
Spouští se po startu HKLM Run [RTHDCPL]
[R] ACDaemon.exe
Spouští se po startu HKLM Run [ArcSoft Connection Service]
[S] ctfmon.exe
Spouští se po startu HKCU Run [CTFMON.EXE]
[?] NMBgMonitor.exe
Spouští se po startu HKCU Run [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
Soubor 7%
[R] TOTALCMD.EXE
EntryPoint v sekci: UPX1
|_ Celkový počet sekcí: 3
[R] firefox.exe
Podvržená cesta modulu: (001A0000) [DLL] ?
[R] SpyEmergency.exe
Spouští se po startu HKCU Run [SpyEmergency]
[S] svchost.exe
Podvržená cesta modulu: (001A0000) [DLL] ?
Po spuštění
================================================================
HKCU Run
|_ [?][BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
HKLM Run
|_ [?][ATKOSD2] C:\Program Files\ATKOSD2\ATKOSD2.exe
|_ [?][NvCplDaemon] C:\WINDOWS\system32\NvCpl.dll ,NvStartup
|_ [?][nwiz] nwiz.exe /install
|_ [?][NvMediaCenter] C:\WINDOWS\system32\NvMcTray.dll ,NvTaskbarInit
|_ [R][nod32kui] C:\Program Files\Eset\nod32kui.exe /WAITSERVICE
|_ [?][RTHDCPL] C:\WINDOWS\RTHDCPL.EXE
|_ [?][SkyTel] C:\WINDOWS\SkyTel.EXE
|_ [?][Alcmtr] C:\WINDOWS\ALCMTR.EXE
HKLM IC
|_ [X][>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP (Soubor nenalezen)
|_ [?][{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] C:\WINDOWS\INF\msnetmtg.inf ,NetMtg.Install.PerUser.NT
|_ [?][{5945c046-1e7d-11d1-bc44-00c04fd912be}] C:\WINDOWS\INF\msmsgs.inf ,BLC.QuietInstall.PerUser
|_ [?][{6BF52A52-394A-11d3-B153-00C04F79FAA6}] C:\WINDOWS\INF\wmp.inf ,PerUserStub
|_ [?][{89820200-ECBD-11cf-8B85-00AA005B4340}] regsvr32.exe /s /n /i:U shell32.dll
HKLM Winlogon Notify
|_ [?][wingew32] C:\WINDOWS\system32\wingew32.dll
Po spuštění
|_ C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
HKLM BHO
|_ [?][{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}] C:\TRANSLAT\WEBIE.DLL
HKLM IE Toolbar
|_ [?][{BFC32E1D-EE75-4A48-BC60-104E11EE2431}] C:\TRANSLAT\WEBIE.DLL
Služby (Zobraz běžící: True, Zobraz zastavené: False, Zobraz i bezpečné služby: False)
================================================================
[X] Java Quick Starter
|_ Cesta: C:\Program Files\Java\jre6\bin\jqs.exe -service -config C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf
| |_ Výrobce:
| |_ Popis:
| |_ MD5:
|
|_ Jméno: JavaQuickStarterService
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Own Process
|_ Dependency:
[?] NVIDIA Display Driver Service
|_ Cesta: C:\WINDOWS\system32\nvsvc32.exe
| |_ Výrobce: NVIDIA Corporation
| |_ Popis: NVIDIA Driver Helper Service, Version 156.54
| |_ MD5: 681FE96144FE19F5691869D55B92CFE0
|
|_ Jméno: NVSvc
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Own Process
|_ Dependency:
Ovladače (Zobraz běžící: True, Zobraz zastavené: False, Zobraz i bezpečné služby: False)
================================================================
[?] Atheros AR5008 Wireless Network Adapter Service
|_ Cesta: C:\WINDOWS\system32\DRIVERS\athw.sys
| |_ Výrobce: Atheros Communications, Inc.
| |_ Popis: Driver for Atheros AR5008 Wireless Network Adapter
| |_ MD5: D3E782AD9DCA4D6215222A43345F43B0
|
|_ Jméno: AR5416
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Service for Realtek HD Audio (WDM)
|_ Cesta: C:\WINDOWS\system32\drivers\RtkHDAud.sys
| |_ Výrobce: Realtek Semiconductor Corp.
| |_ Popis: Realtek(r) High Definition Audio Function Driver
| |_ MD5: B1A809E7FE19BECD5ACA61F0E7088C8C
|
|_ Jméno: IntcAzAudAddService
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] nv
|_ Cesta: C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
| |_ Výrobce: NVIDIA Corporation
| |_ Popis: NVIDIA Compatible Windows 2000 Miniport Driver, Version 156.54
| |_ MD5: 38D848323B440E20550129A7858365B6
|
|_ Jméno: nv
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] NVIDIA nForce Networking Controller Driver
|_ Cesta: C:\WINDOWS\system32\DRIVERS\NVENETFD.sys
| |_ Výrobce: NVIDIA Corporation
| |_ Popis: NVIDIA Networking Function Driver.
| |_ MD5: 89FA84C4887EC984A002A518258499FE
|
|_ Jméno: NVENETFD
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] NVIDIA Network Bus Enumerator
|_ Cesta: C:\WINDOWS\system32\DRIVERS\nvnetbus.sys
| |_ Výrobce: NVIDIA Corporation
| |_ Popis: NVIDIA Networking Bus Driver.
| |_ MD5: AA91A32A36E2CB3F06223056F6668E8F
|
|_ Jméno: nvnetbus
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] nvsmu
|_ Cesta: C:\WINDOWS\system32\DRIVERS\nvsmu.sys
| |_ Výrobce: NVIDIA Corporation
| |_ Popis: NVIDIA® nForce(TM) SMU Microcontroller Driver
| |_ MD5: 9AEBC32F9D6E02EBEE0369AB296FE7C8
|
|_ Jméno: nvsmu
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] PxHelp20
|_ Cesta: C:\WINDOWS\system32\DRIVERS\PxHelp20.sys
| |_ Výrobce: Sonic Solutions
| |_ Popis: Px Engine Device Driver for Windows 2000/XP
| |_ MD5: B572ED0C3E6165643FA116AF20425A54
|
|_ Jméno: PxHelp20
|_ StartName:
|_ Typ spouštění: Boot Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] sptd
|_ Cesta: C:\WINDOWS\System32\Drivers\sptd.sys
| |_ Výrobce:
| |_ Popis:
| |_ MD5:
|
|_ Jméno: sptd
|_ StartName:
|_ Typ spouštění: Boot Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] USB2.0 1.3M WebCam
|_ Cesta: C:\WINDOWS\System32\Drivers\SynMini.sys
| |_ Výrobce:
| |_ Popis:
| |_ MD5: 472B9E75DDAB952F0CD37BD9AA3E81F8
|
|_ Jméno: SynMini
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] USB2.0 1.3M WebCam Still Image
|_ Cesta: C:\WINDOWS\System32\Drivers\SynScan.sys
| |_ Výrobce:
| |_ Popis:
| |_ MD5: BED9A41E66E9F038AF6D2E487A3F2757
|
|_ Jméno: SynScan
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
lNetStat
================================================================
Typ: PID Proces Local <-> Remote Status
-----------------------------------------------------------------------------------------
TCP (1084) svchost.exe 0.0.0.0:135 LISTENING
TCP (4) Systém 0.0.0.0:445 LISTENING
TCP (604) ARCGIS.EXE 0.0.0.0:1026 LISTENING
TCP (968) spnsrvnt.exe 0.0.0.0:6002 LISTENING
TCP (3052) SpyEmergencySrv.exe 0.0.0.0:8211 LISTENING
TCP (3052) SpyEmergencySrv.exe 0.0.0.0:8212 LISTENING
TCP (3052) SpyEmergencySrv.exe 0.0.0.0:8213 LISTENING
TCP (3052) SpyEmergencySrv.exe 0.0.0.0:8214 LISTENING
TCP (332) lmgrd.exe 0.0.0.0:27001 LISTENING
TCP (604) ARCGIS.EXE 127.0.0.1:1028 <-> 127.0.0.1:1029 ESTABLISHED
TCP (604) ARCGIS.EXE 127.0.0.1:1029 <-> 127.0.0.1:1028 ESTABLISHED
TCP (604) ARCGIS.EXE 127.0.0.1:1030 <-> 127.0.0.1:27001 ESTABLISHED
TCP (2384) alg.exe 127.0.0.1:1034 LISTENING
TCP (280) firefox.exe 127.0.0.1:1052 <-> 127.0.0.1:1053 ESTABLISHED
TCP (280) firefox.exe 127.0.0.1:1053 <-> 127.0.0.1:1052 ESTABLISHED
TCP (280) firefox.exe 127.0.0.1:1060 <-> 127.0.0.1:1061 ESTABLISHED
TCP (280) firefox.exe 127.0.0.1:1061 <-> 127.0.0.1:1060 ESTABLISHED
TCP (544) jqs.exe 127.0.0.1:5152 LISTENING
TCP (544) jqs.exe 127.0.0.1:5152 CLOSE_WAIT
TCP (356) mDNSResponder.exe 127.0.0.1:5354 LISTENING
TCP (332) lmgrd.exe 127.0.0.1:27001 <-> 127.0.0.1:1030 ESTABLISHED
TCP (4) Systém 192.168.1.103:139 LISTENING
TCP (0) 192.168.1.103:1327 TIME_WAIT
TCP (0) 192.168.1.103:1384 TIME_WAIT
TCP (0) 192.168.1.103:1472 TIME_WAIT
TCP (260) UPM.exe 192.168.1.103:1521 <-> 199.7.52.190:80 ESTABLISHED
UDP (4) Systém 0.0.0.0:445 <-> 199.7.51.190:80 ESTABLISHED
UDP (880) lsass.exe 0.0.0.0:500
UDP (356) mDNSResponder.exe 0.0.0.0:1025
UDP (880) lsass.exe 0.0.0.0:4500
UDP (968) spnsrvnt.exe 127.0.0.1:6001
UDP (4) Systém 192.168.1.103:137
UDP (4) Systém 192.168.1.103:138
UDP (356) mDNSResponder.exe 192.168.1.103:5353
UDP (968) spnsrvnt.exe 192.168.1.103:6001
Moduly (Zobraz i bezpečné DLL: False, Jen bez výrobce: True, Zobraz registrované: False)
================================================================
[?] wingew32.dll
|_ Cesta: C:\WINDOWS\system32\wingew32.dll
|_ MD5: 4793C209B8B246E2BC7696A1F4AF4D5C
|_ Výrobce:
|_ Procesy
|_ winlogon.exe (824)
[?] pr_imon.dll
|_ Cesta: C:\Program Files\ESET\pr_imon.dll
|_ MD5: E367058BB58A44B817A1C26A98A472C8
|_ Výrobce:
|_ Procesy
|_ lsass.exe (880)
|_ svchost.exe (1084)
|_ svchost.exe (1184)
|_ explorer.exe (1488)
|_ lmgrd.exe (332)
|_ mDNSResponder.exe (356)
|_ jqs.exe (544)
|_ nod32krn.exe (596)
|_ ARCGIS.EXE (604)
|_ spnsrvnt.exe (968)
|_ nod32kui.exe (2216)
|_ alg.exe (2384)
|_ firefox.exe (280)
|_ SpyEmergencySrv.exe (3052)
|_ SpyEmergency.exe (2828)
|_ UPM.exe (260)
|_ svchost.exe (3464)
[?] mdnsnsp.dll
|_ Cesta: C:\Program Files\Bonjour\mdnsNSP.dll
|_ MD5: 1F5A570AD942DFCFE4500326ABDD72B2
|_ Výrobce: Apple Computer, Inc.
|_ Procesy
|_ svchost.exe (1084)
|_ spoolsv.exe (1744)
|_ lmgrd.exe (332)
|_ ARCGIS.EXE (604)
|_ spnsrvnt.exe (968)
|_ firefox.exe (280)
|_ SpyEmergency.exe (2828)
|_ UPM.exe (260)
|_ svchost.exe (3464)
[?] nod32krr.dll
|_ Cesta: C:\Program Files\ESET\nod32krr.dll
|_ MD5: EE05D8FB21CDC4F0939B75BFC3F1B3B9
|_ Výrobce: Eset
|_ Procesy
|_ nod32krn.exe (596)
[?] pr_upd.dll
|_ Cesta: C:\Program Files\ESET\pr_upd.dll
|_ MD5: CED01516B7F726874595CAA8F16E0E0A
|_ Výrobce:
|_ Procesy
|_ nod32krn.exe (596)
|_ nod32kui.exe (2216)
[?] pr_amon.dll
|_ Cesta: C:\Program Files\ESET\pr_amon.dll
|_ MD5: DD2EA02F095981652DF66D2AF9A69094
|_ Výrobce: Eset
|_ Procesy
|_ nod32krn.exe (596)
|_ nod32kui.exe (2216)
[?] pr_nod32.dll
|_ Cesta: C:\Program Files\ESET\pr_nod32.dll
|_ MD5: CD0D69080FD066D56E3FF328319131AC
|_ Výrobce: Eset
|_ Procesy
|_ nod32krn.exe (596)
|_ nod32kui.exe (2216)
[?] pr_dmon.dll
|_ Cesta: C:\Program Files\ESET\pr_dmon.dll
|_ MD5: E440C26F795C58BD53A9DAF9C89249D6
|_ Výrobce:
|_ Procesy
|_ nod32krn.exe (596)
|_ nod32kui.exe (2216)
[?] pr_emon.dll
|_ Cesta: C:\Program Files\ESET\pr_emon.dll
|_ MD5: F17588F8BDB8EDA20257598847144A36
|_ Výrobce:
|_ Procesy
|_ nod32krn.exe (596)
|_ nod32kui.exe (2216)
[?] nod32rui.dll
|_ Cesta: C:\Program Files\ESET\nod32rui.dll
|_ MD5: 4655C9716D8781609CAAA1C0473A69D8
|_ Výrobce:
|_ Procesy
|_ nod32kui.exe (2216)
[?] nmindexstoresvrps.dll
|_ Cesta: C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvrPS.dll
|_ MD5: 2257589EF50B9F2ACCB7BC9C058447ED
|_ Výrobce: Nero AG
|_ Procesy
|_ NMBgMonitor.exe (2280)
[?] nmdataservices.dll
|_ Cesta: C:\Program Files\Common Files\Ahead\Lib\NMDataServices.dll
|_ MD5: 5E49990CAF2BF1AE9A421BB2FCC3769A
|_ Výrobce: Nero AG
|_ Procesy
|_ NMBgMonitor.exe (2280)
[?] advrcntr2.dll
|_ Cesta: C:\Program Files\Common Files\Ahead\Lib\AdvrCntr2.dll
|_ MD5: 806BF193896D664594023DDEBB6AC812
|_ Výrobce: Nero AG
|_ Procesy
|_ NMBgMonitor.exe (2280)
[?] msvcp60.dll
|_ Cesta: C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\msvcp60.dll
|_ MD5: 59A6413FB2CC89FD8651B1D2962FB8B9
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ ArcCon.ac (2484)
|_ wmiapsrv.exe (2520)
[?] nssdbm3.dll
|_ Cesta: C:\Program Files\Mozilla Firefox\nssdbm3.dll
|_ MD5: CBF614A2EA4FDAE7A45FB98097002F3B
|_ Výrobce: Mozilla Foundation
|_ Procesy
|_ firefox.exe (280)
[?] freebl3.dll
|_ Cesta: C:\Program Files\Mozilla Firefox\freebl3.dll
|_ MD5: A67137616BB9668F46F595CE4C861AF4
|_ Výrobce: Mozilla Foundation
|_ Procesy
|_ firefox.exe (280)
[?] softokn3.dll
|_ Cesta: C:\Program Files\Mozilla Firefox\softokn3.dll
|_ MD5: CC579E1A88C865C880CE32D8B46C4734
|_ Výrobce: Mozilla Foundation
|_ Procesy
|_ firefox.exe (280)
[?] libeay32.dll
|_ Cesta: C:\Program Files\NETGATE\Spy Emergency 2008\libeay32.dll
|_ MD5: 061DAE89B309A98382DEDC04942BD8A2
|_ Výrobce: The OpenSSL Project, http://www.openssl.org/
|_ Procesy
|_ SpyEmergencySrv.exe (3052)
[?] ssleay32.dll
|_ Cesta: C:\Program Files\NETGATE\Spy Emergency 2008\ssleay32.dll
|_ MD5: D522127B19938F0F9E127AF60D8E678E
|_ Výrobce: The OpenSSL Project, http://www.openssl.org/
|_ Procesy
|_ SpyEmergencySrv.exe (3052)
================================================================
Ultimate Process Manager v4.1.3 - [ Lodus Software ]
Boot Mode: Normal
Ověření souborů Microsoftu: Ano
Whitelist: Ano
Internet Explorer v6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
Log vygenerován: 26.11.2010 9:09:21
================================================================
SmallARK
================================================================
[?]NtCreateKey -> spyr.sys
[?]NtEnumerateKey -> spyr.sys
[?]NtEnumerateValueKey -> spyr.sys
[?]NtOpenKey -> spyr.sys
[?]NtQueryKey -> spyr.sys
[?]NtQueryValueKey -> spyr.sys
[?]NtSetValueKey -> spyr.sys
Běžící procesy
================================================================
C:\PROGRAM FILES\ESRI\LICENSE\ARCGIS9X\ARCGIS.EXE
C:\WINDOWS\SYSTEM32\NVSVC32.EXE
C:\PROGRAM FILES\ATKOSD2\ATKOSD2.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRAM FILES\COMMON FILES\AHEAD\LIB\NMBGMONITOR.EXE
Scanner
================================================================
[S] csrss.exe
Podvržená cesta modulu: (00270000) [DLL] ?
[S] explorer.exe
Spouští se po startu HKLM Winlogon [Shell]
Podvržená cesta modulu: (001A0000) [DLL] ?
[?] ARCGIS.EXE
Bez výrobce
Nemá okno
Soubor 12%
[?] nvsvc32.exe
Non Microsoft v System32:
[?] ATKOSD2.exe
Bez výrobce
Spouští se po startu HKLM Run [ATKOSD2]
Soubor 25%
[S] rundll32.exe
Spouští se po startu HKLM Run [NvCplDaemon]
[R] nod32kui.exe
Spouští se po startu HKLM Run [nod32kui]
[R] jusched.exe
Spouští se po startu HKLM Run [SunJavaUpdateSched]
[?] RTHDCPL.exe
Spouští se po startu HKLM Run [RTHDCPL]
[R] ACDaemon.exe
Spouští se po startu HKLM Run [ArcSoft Connection Service]
[S] ctfmon.exe
Spouští se po startu HKCU Run [CTFMON.EXE]
[?] NMBgMonitor.exe
Spouští se po startu HKCU Run [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
Soubor 7%
[R] TOTALCMD.EXE
EntryPoint v sekci: UPX1
|_ Celkový počet sekcí: 3
[R] firefox.exe
Podvržená cesta modulu: (001A0000) [DLL] ?
[R] SpyEmergency.exe
Spouští se po startu HKCU Run [SpyEmergency]
[S] svchost.exe
Podvržená cesta modulu: (001A0000) [DLL] ?
Po spuštění
================================================================
HKCU Run
|_ [?][BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
HKLM Run
|_ [?][ATKOSD2] C:\Program Files\ATKOSD2\ATKOSD2.exe
|_ [?][NvCplDaemon] C:\WINDOWS\system32\NvCpl.dll ,NvStartup
|_ [?][nwiz] nwiz.exe /install
|_ [?][NvMediaCenter] C:\WINDOWS\system32\NvMcTray.dll ,NvTaskbarInit
|_ [R][nod32kui] C:\Program Files\Eset\nod32kui.exe /WAITSERVICE
|_ [?][RTHDCPL] C:\WINDOWS\RTHDCPL.EXE
|_ [?][SkyTel] C:\WINDOWS\SkyTel.EXE
|_ [?][Alcmtr] C:\WINDOWS\ALCMTR.EXE
HKLM IC
|_ [X][>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP (Soubor nenalezen)
|_ [?][{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] C:\WINDOWS\INF\msnetmtg.inf ,NetMtg.Install.PerUser.NT
|_ [?][{5945c046-1e7d-11d1-bc44-00c04fd912be}] C:\WINDOWS\INF\msmsgs.inf ,BLC.QuietInstall.PerUser
|_ [?][{6BF52A52-394A-11d3-B153-00C04F79FAA6}] C:\WINDOWS\INF\wmp.inf ,PerUserStub
|_ [?][{89820200-ECBD-11cf-8B85-00AA005B4340}] regsvr32.exe /s /n /i:U shell32.dll
HKLM Winlogon Notify
|_ [?][wingew32] C:\WINDOWS\system32\wingew32.dll
Po spuštění
|_ C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
HKLM BHO
|_ [?][{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}] C:\TRANSLAT\WEBIE.DLL
HKLM IE Toolbar
|_ [?][{BFC32E1D-EE75-4A48-BC60-104E11EE2431}] C:\TRANSLAT\WEBIE.DLL
Služby (Zobraz běžící: True, Zobraz zastavené: False, Zobraz i bezpečné služby: False)
================================================================
[X] Java Quick Starter
|_ Cesta: C:\Program Files\Java\jre6\bin\jqs.exe -service -config C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf
| |_ Výrobce:
| |_ Popis:
| |_ MD5:
|
|_ Jméno: JavaQuickStarterService
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Own Process
|_ Dependency:
[?] NVIDIA Display Driver Service
|_ Cesta: C:\WINDOWS\system32\nvsvc32.exe
| |_ Výrobce: NVIDIA Corporation
| |_ Popis: NVIDIA Driver Helper Service, Version 156.54
| |_ MD5: 681FE96144FE19F5691869D55B92CFE0
|
|_ Jméno: NVSvc
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Own Process
|_ Dependency:
Ovladače (Zobraz běžící: True, Zobraz zastavené: False, Zobraz i bezpečné služby: False)
================================================================
[?] Atheros AR5008 Wireless Network Adapter Service
|_ Cesta: C:\WINDOWS\system32\DRIVERS\athw.sys
| |_ Výrobce: Atheros Communications, Inc.
| |_ Popis: Driver for Atheros AR5008 Wireless Network Adapter
| |_ MD5: D3E782AD9DCA4D6215222A43345F43B0
|
|_ Jméno: AR5416
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Service for Realtek HD Audio (WDM)
|_ Cesta: C:\WINDOWS\system32\drivers\RtkHDAud.sys
| |_ Výrobce: Realtek Semiconductor Corp.
| |_ Popis: Realtek(r) High Definition Audio Function Driver
| |_ MD5: B1A809E7FE19BECD5ACA61F0E7088C8C
|
|_ Jméno: IntcAzAudAddService
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] nv
|_ Cesta: C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
| |_ Výrobce: NVIDIA Corporation
| |_ Popis: NVIDIA Compatible Windows 2000 Miniport Driver, Version 156.54
| |_ MD5: 38D848323B440E20550129A7858365B6
|
|_ Jméno: nv
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] NVIDIA nForce Networking Controller Driver
|_ Cesta: C:\WINDOWS\system32\DRIVERS\NVENETFD.sys
| |_ Výrobce: NVIDIA Corporation
| |_ Popis: NVIDIA Networking Function Driver.
| |_ MD5: 89FA84C4887EC984A002A518258499FE
|
|_ Jméno: NVENETFD
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] NVIDIA Network Bus Enumerator
|_ Cesta: C:\WINDOWS\system32\DRIVERS\nvnetbus.sys
| |_ Výrobce: NVIDIA Corporation
| |_ Popis: NVIDIA Networking Bus Driver.
| |_ MD5: AA91A32A36E2CB3F06223056F6668E8F
|
|_ Jméno: nvnetbus
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] nvsmu
|_ Cesta: C:\WINDOWS\system32\DRIVERS\nvsmu.sys
| |_ Výrobce: NVIDIA Corporation
| |_ Popis: NVIDIA® nForce(TM) SMU Microcontroller Driver
| |_ MD5: 9AEBC32F9D6E02EBEE0369AB296FE7C8
|
|_ Jméno: nvsmu
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] PxHelp20
|_ Cesta: C:\WINDOWS\system32\DRIVERS\PxHelp20.sys
| |_ Výrobce: Sonic Solutions
| |_ Popis: Px Engine Device Driver for Windows 2000/XP
| |_ MD5: B572ED0C3E6165643FA116AF20425A54
|
|_ Jméno: PxHelp20
|_ StartName:
|_ Typ spouštění: Boot Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] sptd
|_ Cesta: C:\WINDOWS\System32\Drivers\sptd.sys
| |_ Výrobce:
| |_ Popis:
| |_ MD5:
|
|_ Jméno: sptd
|_ StartName:
|_ Typ spouštění: Boot Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] USB2.0 1.3M WebCam
|_ Cesta: C:\WINDOWS\System32\Drivers\SynMini.sys
| |_ Výrobce:
| |_ Popis:
| |_ MD5: 472B9E75DDAB952F0CD37BD9AA3E81F8
|
|_ Jméno: SynMini
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] USB2.0 1.3M WebCam Still Image
|_ Cesta: C:\WINDOWS\System32\Drivers\SynScan.sys
| |_ Výrobce:
| |_ Popis:
| |_ MD5: BED9A41E66E9F038AF6D2E487A3F2757
|
|_ Jméno: SynScan
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
lNetStat
================================================================
Typ: PID Proces Local <-> Remote Status
-----------------------------------------------------------------------------------------
TCP (1084) svchost.exe 0.0.0.0:135 LISTENING
TCP (4) Systém 0.0.0.0:445 LISTENING
TCP (604) ARCGIS.EXE 0.0.0.0:1026 LISTENING
TCP (968) spnsrvnt.exe 0.0.0.0:6002 LISTENING
TCP (3052) SpyEmergencySrv.exe 0.0.0.0:8211 LISTENING
TCP (3052) SpyEmergencySrv.exe 0.0.0.0:8212 LISTENING
TCP (3052) SpyEmergencySrv.exe 0.0.0.0:8213 LISTENING
TCP (3052) SpyEmergencySrv.exe 0.0.0.0:8214 LISTENING
TCP (332) lmgrd.exe 0.0.0.0:27001 LISTENING
TCP (604) ARCGIS.EXE 127.0.0.1:1028 <-> 127.0.0.1:1029 ESTABLISHED
TCP (604) ARCGIS.EXE 127.0.0.1:1029 <-> 127.0.0.1:1028 ESTABLISHED
TCP (604) ARCGIS.EXE 127.0.0.1:1030 <-> 127.0.0.1:27001 ESTABLISHED
TCP (2384) alg.exe 127.0.0.1:1034 LISTENING
TCP (280) firefox.exe 127.0.0.1:1052 <-> 127.0.0.1:1053 ESTABLISHED
TCP (280) firefox.exe 127.0.0.1:1053 <-> 127.0.0.1:1052 ESTABLISHED
TCP (280) firefox.exe 127.0.0.1:1060 <-> 127.0.0.1:1061 ESTABLISHED
TCP (280) firefox.exe 127.0.0.1:1061 <-> 127.0.0.1:1060 ESTABLISHED
TCP (544) jqs.exe 127.0.0.1:5152 LISTENING
TCP (544) jqs.exe 127.0.0.1:5152 CLOSE_WAIT
TCP (356) mDNSResponder.exe 127.0.0.1:5354 LISTENING
TCP (332) lmgrd.exe 127.0.0.1:27001 <-> 127.0.0.1:1030 ESTABLISHED
TCP (4) Systém 192.168.1.103:139 LISTENING
TCP (0) 192.168.1.103:1327 TIME_WAIT
TCP (0) 192.168.1.103:1384 TIME_WAIT
TCP (0) 192.168.1.103:1472 TIME_WAIT
TCP (260) UPM.exe 192.168.1.103:1521 <-> 199.7.52.190:80 ESTABLISHED
UDP (4) Systém 0.0.0.0:445 <-> 199.7.51.190:80 ESTABLISHED
UDP (880) lsass.exe 0.0.0.0:500
UDP (356) mDNSResponder.exe 0.0.0.0:1025
UDP (880) lsass.exe 0.0.0.0:4500
UDP (968) spnsrvnt.exe 127.0.0.1:6001
UDP (4) Systém 192.168.1.103:137
UDP (4) Systém 192.168.1.103:138
UDP (356) mDNSResponder.exe 192.168.1.103:5353
UDP (968) spnsrvnt.exe 192.168.1.103:6001
Moduly (Zobraz i bezpečné DLL: False, Jen bez výrobce: True, Zobraz registrované: False)
================================================================
[?] wingew32.dll
|_ Cesta: C:\WINDOWS\system32\wingew32.dll
|_ MD5: 4793C209B8B246E2BC7696A1F4AF4D5C
|_ Výrobce:
|_ Procesy
|_ winlogon.exe (824)
[?] pr_imon.dll
|_ Cesta: C:\Program Files\ESET\pr_imon.dll
|_ MD5: E367058BB58A44B817A1C26A98A472C8
|_ Výrobce:
|_ Procesy
|_ lsass.exe (880)
|_ svchost.exe (1084)
|_ svchost.exe (1184)
|_ explorer.exe (1488)
|_ lmgrd.exe (332)
|_ mDNSResponder.exe (356)
|_ jqs.exe (544)
|_ nod32krn.exe (596)
|_ ARCGIS.EXE (604)
|_ spnsrvnt.exe (968)
|_ nod32kui.exe (2216)
|_ alg.exe (2384)
|_ firefox.exe (280)
|_ SpyEmergencySrv.exe (3052)
|_ SpyEmergency.exe (2828)
|_ UPM.exe (260)
|_ svchost.exe (3464)
[?] mdnsnsp.dll
|_ Cesta: C:\Program Files\Bonjour\mdnsNSP.dll
|_ MD5: 1F5A570AD942DFCFE4500326ABDD72B2
|_ Výrobce: Apple Computer, Inc.
|_ Procesy
|_ svchost.exe (1084)
|_ spoolsv.exe (1744)
|_ lmgrd.exe (332)
|_ ARCGIS.EXE (604)
|_ spnsrvnt.exe (968)
|_ firefox.exe (280)
|_ SpyEmergency.exe (2828)
|_ UPM.exe (260)
|_ svchost.exe (3464)
[?] nod32krr.dll
|_ Cesta: C:\Program Files\ESET\nod32krr.dll
|_ MD5: EE05D8FB21CDC4F0939B75BFC3F1B3B9
|_ Výrobce: Eset
|_ Procesy
|_ nod32krn.exe (596)
[?] pr_upd.dll
|_ Cesta: C:\Program Files\ESET\pr_upd.dll
|_ MD5: CED01516B7F726874595CAA8F16E0E0A
|_ Výrobce:
|_ Procesy
|_ nod32krn.exe (596)
|_ nod32kui.exe (2216)
[?] pr_amon.dll
|_ Cesta: C:\Program Files\ESET\pr_amon.dll
|_ MD5: DD2EA02F095981652DF66D2AF9A69094
|_ Výrobce: Eset
|_ Procesy
|_ nod32krn.exe (596)
|_ nod32kui.exe (2216)
[?] pr_nod32.dll
|_ Cesta: C:\Program Files\ESET\pr_nod32.dll
|_ MD5: CD0D69080FD066D56E3FF328319131AC
|_ Výrobce: Eset
|_ Procesy
|_ nod32krn.exe (596)
|_ nod32kui.exe (2216)
[?] pr_dmon.dll
|_ Cesta: C:\Program Files\ESET\pr_dmon.dll
|_ MD5: E440C26F795C58BD53A9DAF9C89249D6
|_ Výrobce:
|_ Procesy
|_ nod32krn.exe (596)
|_ nod32kui.exe (2216)
[?] pr_emon.dll
|_ Cesta: C:\Program Files\ESET\pr_emon.dll
|_ MD5: F17588F8BDB8EDA20257598847144A36
|_ Výrobce:
|_ Procesy
|_ nod32krn.exe (596)
|_ nod32kui.exe (2216)
[?] nod32rui.dll
|_ Cesta: C:\Program Files\ESET\nod32rui.dll
|_ MD5: 4655C9716D8781609CAAA1C0473A69D8
|_ Výrobce:
|_ Procesy
|_ nod32kui.exe (2216)
[?] nmindexstoresvrps.dll
|_ Cesta: C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvrPS.dll
|_ MD5: 2257589EF50B9F2ACCB7BC9C058447ED
|_ Výrobce: Nero AG
|_ Procesy
|_ NMBgMonitor.exe (2280)
[?] nmdataservices.dll
|_ Cesta: C:\Program Files\Common Files\Ahead\Lib\NMDataServices.dll
|_ MD5: 5E49990CAF2BF1AE9A421BB2FCC3769A
|_ Výrobce: Nero AG
|_ Procesy
|_ NMBgMonitor.exe (2280)
[?] advrcntr2.dll
|_ Cesta: C:\Program Files\Common Files\Ahead\Lib\AdvrCntr2.dll
|_ MD5: 806BF193896D664594023DDEBB6AC812
|_ Výrobce: Nero AG
|_ Procesy
|_ NMBgMonitor.exe (2280)
[?] msvcp60.dll
|_ Cesta: C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\msvcp60.dll
|_ MD5: 59A6413FB2CC89FD8651B1D2962FB8B9
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ ArcCon.ac (2484)
|_ wmiapsrv.exe (2520)
[?] nssdbm3.dll
|_ Cesta: C:\Program Files\Mozilla Firefox\nssdbm3.dll
|_ MD5: CBF614A2EA4FDAE7A45FB98097002F3B
|_ Výrobce: Mozilla Foundation
|_ Procesy
|_ firefox.exe (280)
[?] freebl3.dll
|_ Cesta: C:\Program Files\Mozilla Firefox\freebl3.dll
|_ MD5: A67137616BB9668F46F595CE4C861AF4
|_ Výrobce: Mozilla Foundation
|_ Procesy
|_ firefox.exe (280)
[?] softokn3.dll
|_ Cesta: C:\Program Files\Mozilla Firefox\softokn3.dll
|_ MD5: CC579E1A88C865C880CE32D8B46C4734
|_ Výrobce: Mozilla Foundation
|_ Procesy
|_ firefox.exe (280)
[?] libeay32.dll
|_ Cesta: C:\Program Files\NETGATE\Spy Emergency 2008\libeay32.dll
|_ MD5: 061DAE89B309A98382DEDC04942BD8A2
|_ Výrobce: The OpenSSL Project, http://www.openssl.org/
|_ Procesy
|_ SpyEmergencySrv.exe (3052)
[?] ssleay32.dll
|_ Cesta: C:\Program Files\NETGATE\Spy Emergency 2008\ssleay32.dll
|_ MD5: D522127B19938F0F9E127AF60D8E678E
|_ Výrobce: The OpenSSL Project, http://www.openssl.org/
|_ Procesy
|_ SpyEmergencySrv.exe (3052)
================================================================
Ultimate Process Manager v4.1.3 - [ Lodus Software ]