zavirované PC
Napsal: 11 pro 2010 15:29
Mám v počítači několik virů, antivir avast byl vyřazen, žádám tímto o
odbornou pomoc podle návodu na tomto serveru.
Zde je můj log:
[code]Windows XP SP 3 (build 2600)
Boot Mode: Normal
Ověření souborů Microsoftu: Ano
Whitelist: Ano
Internet Explorer v8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Log vygenerován: 11.12.2010 15:07:22
================================================================
SmallARK
================================================================
[?]NtClose -> C:\WINDOWS\system32\drivers\aswSP.SYS
[?]NtCreateFile -> C:\WINDOWS\system32\drivers\SbFw.sys
[?]NtCreateKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[?]NtCreateProcess -> C:\WINDOWS\system32\drivers\SbFw.sys
[?]NtCreateProcessEx -> C:\WINDOWS\system32\drivers\SbFw.sys
[?]NtCreateThread -> C:\WINDOWS\system32\drivers\SbFw.sys
[?]NtDeleteFile -> C:\WINDOWS\system32\drivers\SbFw.sys
[?]NtDeleteKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[?]NtDeleteValueKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[?]NtDuplicateObject -> C:\WINDOWS\system32\drivers\aswSP.SYS
[?]NtEnumerateKey -> spit.sys
[?]NtEnumerateValueKey -> spit.sys
[?]NtLoadDriver -> C:\WINDOWS\system32\drivers\sbhips.sys
[?]NtMapViewOfSection -> C:\WINDOWS\system32\drivers\sbhips.sys
[?]NtOpenFile -> C:\WINDOWS\system32\drivers\SbFw.sys
[?]NtOpenKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[?]NtOpenProcess -> C:\WINDOWS\system32\drivers\aswSP.SYS
[?]NtOpenThread -> C:\WINDOWS\system32\drivers\aswSP.SYS
[?]NtQueryKey -> spit.sys
[?]NtQueryValueKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[?]NtRenameKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[?]NtRestoreKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[?]NtResumeThread -> C:\WINDOWS\system32\drivers\SbFw.sys
[?]NtSetInformationFile -> C:\WINDOWS\system32\drivers\SbFw.sys
[?]NtSetValueKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[?]NtWriteFile -> C:\WINDOWS\system32\drivers\SbFw.sys
Běžící procesy
================================================================
C:\PROGRAM FILES\ICQ6TOOLBAR\ICQ SERVICE.EXE
|_ MD5: 5C7D72EAB04B1DF8C5D2ACC6551FDE49
|_Výrobce: ?
C:\WINDOWS\SOUNDMAN.EXE
|_ MD5: 254CF75C7550C33830B8B851B9621215
|_Výrobce: Realtek Semiconductor Corp.
C:\PROGRAM FILES\CYBERLINK\POWERDVD8\PDVD8SERV.EXE
|_ MD5: 0A80BED61A1729DAB9499BC5A9B515A9
|_Výrobce: Cyberlink Corp.
C:\PROGRAM FILES\CYBERLINK\SHARED FILES\BRS.EXE
|_ MD5: 04C40F2EFB9F333E16CE33A2D283829F
|_Výrobce: cyberlink
C:\PROGRAM FILES\ADOBE\READER 9.0\READER\READER_SL.EXE
|_ MD5: 12673BCF7B32087DF63F0CFF550EA40B
|_Výrobce: Adobe Systems Incorporated
C:\PROGRAM FILES\OPENOFFICE.ORG 3\PROGRAM\SOFFICE.EXE
|_ MD5: DB9F8DBE8C9A5AE7A27C2C02E1FEC9EB
|_Výrobce: OpenOffice.org
C:\PROGRAM FILES\OPENOFFICE.ORG 3\PROGRAM\SOFFICE.BIN
|_ MD5: A1130EE690868B4B2C2F70B18F45185F
|_Výrobce: OpenOffice.org
C:\WINDOWS\SYSTEM32\PNKBSTRA.EXE
|_ MD5: 0E01D7EEBADA0B324DB0CA1EE73440BA
|_Výrobce:
C:\WINDOWS\SYSTEM32\PNKBSTRB.EXE
|_ MD5: 1428E6CC1458A36CBFC1F2E304C7C42D
|_Výrobce:
C:\PROGRAM FILES\SUNBELT SOFTWARE\PERSONAL FIREWALL\SBPFLNCH.EXE
|_ MD5: 56C92289535834AA26144B4368932DCB
|_Výrobce: Sunbelt Software, Inc.
C:\PROGRAM FILES\SUNBELT SOFTWARE\PERSONAL FIREWALL\SBPFSVC.EXE
|_ MD5: B3C9D712962DB83C280D0C4AAC8963A8
|_Výrobce: Sunbelt Software, Inc.
C:\PROGRAM FILES\SUNBELT SOFTWARE\PERSONAL FIREWALL\SBPFCL.EXE
|_ MD5: 3CAADDDA144B326B0111C07E0FEE56F3
|_Výrobce: Sunbelt Software, Inc.
C:\DOCUMENTS AND SETTINGS\ALL USERS\DATA APLIKACÍ\E8FB4F\ISE8F_2121.EXE
|_ MD5: 21CE1989C7188CC2B8DB186F547DFB05
|_Výrobce: Smpnsb
Scanner
================================================================
[S] svchost.exe
Spouští se po startu HKLM IFEO [a.exe]
[S] svchost.exe
Spouští se po startu HKLM IFEO [a.exe]
[S] svchost.exe
Spouští se po startu HKLM IFEO [a.exe]
[S] svchost.exe
Spouští se po startu HKLM IFEO [a.exe]
[S] svchost.exe
Spouští se po startu HKLM IFEO [a.exe]
[S] svchost.exe
Spouští se po startu HKLM IFEO [a.exe]
[S] explorer.exe
Spouští se po startu HKLM Winlogon [Shell]
[S] svchost.exe
Spouští se po startu HKLM IFEO [a.exe]
[?] ICQ Service.exe
Bez výrobce
Nemá okno
Soubor 12%
[?] SOUNDMAN.EXE
Spouští se po startu HKLM Run [SoundMan]
Soubor 7%
[S] rundll32.exe
Spouští se po startu HKLM Run [NvCplDaemon]
[?] PDVD8Serv.exe
Spouští se po startu HKLM Run [RemoteControl8]
Soubor 7%
[?] brs.exe
Spouští se po startu HKLM Run [BDRegion]
EntryPoint v sekci:
|_ Celkový počet sekcí: 7
Soubor 70%
[?] reader_sl.exe
Spouští se po startu HKLM Run [Adobe Reader Speed Launcher]
Soubor 7%
[S] ctfmon.exe
Spouští se po startu HKCU Run [CTFMON.EXE]
[S] WindowsSearch.exe
Spouští se po startu Po spuštění []
[?] soffice.exe
Nemá okno
Soubor 14%
[?] soffice.bin
Soubor 14%
[?] PnkBstrA.exe
Bez výrobce v System32
Podobná jména: PNKBSTRA.EXE X PNKBSTRB.EXE
Nemá okno
Soubor 12%
[?] PnkBstrB.exe
Bez výrobce v System32
Podobná jména: PNKBSTRB.EXE X PNKBSTRA.EXE
Nemá okno
Soubor 12%
[?] SbPFLnch.exe
Nemá okno
Soubor 14%
[?] SbPFSvc.exe
Nemá okno
Soubor 7%
[?] SbPFCl.exe
Soubor 14%
[?] ISe8f_2121.exe
Spouští se po startu HKCU Run [Internet Security Suite]
EntryPoint v sekci:
|_ Celkový počet sekcí: 4
Podvržená cesta modulu: (00D90000) [DLL] ?
Podvržená cesta modulu: (13140000) C:\Documents and Settings\All Users\Data aplikací\e8fb4f\ISe8f_2121.exe
Soubor 14%
Po spuštění
================================================================
HKCU Run
|_ [?][Internet Security Suite] C:\Documents and Settings\All Users\Data aplikací\e8fb4f\ISe8f_2121.exe /s /d
|_ MD5: 21CE1989C7188CC2B8DB186F547DFB05
|_ Výrobce: Smpnsb
HKLM Run
|_ [?][SoundMan] C:\WINDOWS\SOUNDMAN.EXE
| |_ MD5: 254CF75C7550C33830B8B851B9621215
| |_ Výrobce: Realtek Semiconductor Corp.
|
|_ [?][NvCplDaemon] C:\WINDOWS\system32\NvCpl.dll ,NvStartup
| |_ MD5: 4D8E9C2FB7E234A7FDFA6EC54794217F
| |_ Výrobce: NVIDIA Corporation
|
|_ [?][nwiz] nwiz.exe /install
| |_ MD5:
| |_ Výrobce: ?
|
|_ [?][NvMediaCenter] C:\WINDOWS\system32\NvMcTray.dll ,NvTaskbarInit
| |_ MD5: 3BC7B677094A2EF0BDDC3A9375E1F8A2
| |_ Výrobce: NVIDIA Corporation
|
|_ [?][RemoteControl8] C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
| |_ MD5: 0A80BED61A1729DAB9499BC5A9B515A9
| |_ Výrobce: Cyberlink Corp.
|
|_ [?][PDVD8LanguageShortcut] C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe
| |_ MD5: AA62A9A6CE962107761775C66F49AD53
| |_ Výrobce: ?
|
|_ [!][BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe
| |_ MD5: 04C40F2EFB9F333E16CE33A2D283829F
| |_ Výrobce: cyberlink
|
|_ [?][Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
| |_ MD5: 12673BCF7B32087DF63F0CFF550EA40B
| |_ Výrobce: Adobe Systems Incorporated
|
|_ [?][Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
| |_ MD5: BAD6BEA0DE1F69C82BDB74378CE0C20A
| |_ Výrobce: Adobe Systems Incorporated
|
|_ [?][Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe -hide
| |_ MD5: 77C03BF23AE56B0A31AE4D5BB4B3D0AC
| |_ Výrobce: Microsoft Corporation
|
|_ [?][avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe /nogui
|_ MD5: 6C1B31F5C16E03153F0037AC6C451FFD
|_ Výrobce: AVAST Software
HKLM IC
|_ [X][>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP (Soubor nenalezen)
|_ [?][{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] C:\WINDOWS\INF\msnetmtg.inf ,NetMtg.Install.PerUser.NT
| |_ MD5: F8995D4274D3D7E32BE7812B872BCC13
| |_ Výrobce:
|
|_ [?][{5945c046-1e7d-11d1-bc44-00c04fd912be}] C:\WINDOWS\INF\msmsgs.inf ,BLC.QuietInstall.PerUser
| |_ MD5: 97BF5E6CB8D2498286096D35644517C5
| |_ Výrobce:
|
|_ [?][{6BF52A52-394A-11d3-B153-00C04F79FAA6}] C:\WINDOWS\INF\wmp11.inf ,PerUserStub
| |_ MD5: C50E7DA8003BF4B222248B9DB4104290
| |_ Výrobce:
|
|_ [?][{89820200-ECBD-11cf-8B85-00AA005B4340}] regsvr32.exe /s /n /i:U shell32.dll
|_ MD5:
|_ Výrobce: Microsoft Corporation
Po spuštění
|_ [?][OpenOffice.org 3.0.lnk] C:\Program Files\OpenOffice.org 3\program\quickstart.exe
|_ MD5: A08920D9BE346EEAA85EE0339D21BF86
|_ Výrobce:
Job
|_ [?][MPSCHE~1.JOB] C:\Program Files\Windows Defender\MpCmdRun.exe
|_ MD5: 08AD1CD68D68711C75C15BF42A11892B
|_ Výrobce: Microsoft Corporation
HKLM BHO
|_ [?][{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
| |_ MD5: 203A74767EB81F96A5166B1933DB46D0
| |_ Výrobce: Adobe Systems Incorporated
|
|_ [X][{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}] (Soubor nenalezen)
|_ [X][{DBC80044-A445-435b-BC74-9C25C1C588A9}] (Soubor nenalezen)
HKLM IE Toolbar
|_ [?][{855F3B16-6D32-4FE6-8A56-BBB695989046}] C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
|_ MD5: 2A21B1EBEFE3A69D1E071F93DF95E0AC
|_ Výrobce: ICQ
Služby (Zobraz běžící: True, Zobraz zastavené: False, Zobraz i bezpečné služby: False)
================================================================
[?] avast! Antivirus
|_ Cesta: C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
| |_ Výrobce: AVAST Software
| |_ Popis: avast! Service
| |_ MD5: ACB544D7254F366DFB48F380BC36CD25
|
|_ Jméno: avast! Antivirus
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Zastaveno
|_ Typ: Win32 Share Process
|_ Dependency: aswMon2
[?] ICQ Service
|_ Cesta: C:\Program Files\ICQ6Toolbar\ICQ Service.exe
| |_ Výrobce: ?
| |_ Popis: ICQIEUpdater Module
| |_ MD5: 5C7D72EAB04B1DF8C5D2ACC6551FDE49
|
|_ Jméno: ICQ Service
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ:
|_ Dependency: RPCSS
[?] PnkBstrA
|_ Cesta: C:\WINDOWS\system32\PnkBstrA.exe
| |_ Výrobce:
| |_ Popis:
| |_ MD5: 0E01D7EEBADA0B324DB0CA1EE73440BA
|
|_ Jméno: PnkBstrA
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Own Process
|_ Dependency:
[?] PnkBstrB
|_ Cesta: C:\WINDOWS\system32\PnkBstrB.exe
| |_ Výrobce:
| |_ Popis:
| |_ MD5: 1428E6CC1458A36CBFC1F2E304C7C42D
|
|_ Jméno: PnkBstrB
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Own Process
|_ Dependency:
[?] SbPF.Launcher
|_ Cesta: C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
| |_ Výrobce: Sunbelt Software, Inc.
| |_ Popis: Sunbelt Personal Firewall SbPFLnch
| |_ MD5: 56C92289535834AA26144B4368932DCB
|
|_ Jméno: SbPF.Launcher
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Own Process
|_ Dependency:
[?] Sunbelt Personal Firewall 4
|_ Cesta: C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
| |_ Výrobce: Sunbelt Software, Inc.
| |_ Popis: Sunbelt Firewall Service
| |_ MD5: B3C9D712962DB83C280D0C4AAC8963A8
|
|_ Jméno: SPF4
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Own Process
|_ Dependency:
[?] Windows Defender
|_ Cesta: C:\Program Files\Windows Defender\MsMpEng.exe
| |_ Výrobce: Microsoft Corporation
| |_ Popis: Service Executable
| |_ MD5: F45DD1E1365D857DD08BC23563370D0E
|
|_ Jméno: WinDefend
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Zastaveno
|_ Typ: Win32 Own Process
|_ Dependency: RpcSs
Ovladače (Zobraz běžící: True, Zobraz zastavené: False, Zobraz i bezpečné služby: False)
================================================================
[?] avast! Asynchronous Virus Monitor
|_ Cesta: C:\WINDOWS\system32\drivers\Aavmker4.sys
| |_ Výrobce: AVAST Software
| |_ Popis: avast! Base Kernel-Mode Device Driver for Windows NT/2000/XP
| |_ MD5: 8D488938E2F7048906F1FBD3AF394887
|
|_ Jméno: Aavmker4
|_ StartName:
|_ Typ spouštění: System Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Service for Realtek AC97 Audio (WDM)
|_ Cesta: C:\WINDOWS\system32\drivers\ALCXWDM.SYS
| |_ Výrobce: Realtek Semiconductor Corp.
| |_ Popis: Realtek AC'97 Audio Driver (WDM)
| |_ MD5: A73C58F6214795044E49D4B120C89D9D
|
|_ Jméno: ALCXWDM
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] aswFsBlk
|_ Cesta: C:\WINDOWS\system32\drivers\aswFsBlk.sys
| |_ Výrobce: AVAST Software
| |_ Popis: avast! File System Access Blocking Driver
| |_ MD5: A0D86B8AC93EF95620420C7A24AC5344
|
|_ Jméno: aswFsBlk
|_ StartName:
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: File System Driver
|_ Dependency: FltMgr
[?] aswMon2
|_ Cesta: C:\WINDOWS\system32\drivers\aswMon2.sys
| |_ Výrobce: AVAST Software
| |_ Popis: avast! File System Filter Driver for Windows XP
| |_ MD5: 7D880C76A285A41284D862E2D798EC0D
|
|_ Jméno: aswMon2
|_ StartName:
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: File System Driver
|_ Dependency:
[?] aswSP
|_ Cesta: C:\WINDOWS\system32\drivers\aswSP.sys
| |_ Výrobce: AVAST Software
| |_ Popis: avast! self protection module
| |_ MD5: 7ECC2776638B04553F9A85BD684C3ABF
|
|_ Jméno: aswSP
|_ StartName:
|_ Typ spouštění: System Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] avast! Network Shield Support
|_ Cesta: C:\WINDOWS\system32\drivers\aswTdi.sys
| |_ Výrobce: AVAST Software
| |_ Popis: avast! TDI Filter Driver
| |_ MD5: 095ED820A926AA8189180B305E1BCFC9
|
|_ Jméno: aswTdi
|_ StartName:
|_ Typ spouštění: System Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency: tcpip
[?] BIOS
|_ Cesta: C:\WINDOWS\system32\drivers\BIOS.sys
| |_ Výrobce: BIOSTAR Group
| |_ Popis: I/O Interface driver file
| |_ MD5: BE5D50529799B9BAB6BE879EC768B6CF
|
|_ Jméno: BIOS
|_ StartName:
|_ Typ spouštění: System Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] NVIDIA nForce Networking Controller Driver
|_ Cesta: C:\WINDOWS\system32\DRIVERS\NVENETFD.sys
| |_ Výrobce: NVIDIA Corporation
| |_ Popis: NVIDIA Networking Function Driver.
| |_ MD5: 23297B3C2FF3510E2E760714FC6F094E
|
|_ Jméno: NVENETFD
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] NVIDIA Network Bus Enumerator
|_ Cesta: C:\WINDOWS\system32\DRIVERS\nvnetbus.sys
| |_ Výrobce: NVIDIA Corporation
| |_ Popis: NVIDIA Networking Bus Driver.
| |_ MD5: BCC3722A2DB99AD6F367344997C26654
|
|_ Jméno: nvnetbus
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] NVIDIA PCI to PCI Bridge Filter
|_ Cesta: C:\WINDOWS\system32\DRIVERS\nvp2p.sys
| |_ Výrobce: NVIDIA Corporation
| |_ Popis: NVIDIA® nForce(TM) PCI to PCI Bridge Driver
| |_ MD5: 63E148FB550EE6F3280BDC7B13E0005A
|
|_ Jméno: nvp2p
|_ StartName:
|_ Typ spouštění: Boot Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] NVIDIA nForce AGP Bus Filter
|_ Cesta: C:\WINDOWS\system32\DRIVERS\nv_agp.sys
| |_ Výrobce: NVIDIA Corporation
| |_ Popis: NVIDIA nForce AGP Filter
| |_ MD5: C0FCD544A1C4EEA6D11A0AE6A07DAC9D
|
|_ Jméno: nv_agp
|_ StartName:
|_ Typ spouštění: Boot Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] SbFw
|_ Cesta: C:\WINDOWS\system32\drivers\SbFw.sys
| |_ Výrobce: Sunbelt Software, Inc.
| |_ Popis: Sunbelt Personal Firewall driver
| |_ MD5: 419883201CA9AD697CCFB8FC46DD6F78
|
|_ Jméno: SbFw
|_ StartName:
|_ Typ spouštění: System Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Sunbelt Software Firewall NDIS IM Filter Miniport
|_ Cesta: C:\WINDOWS\system32\DRIVERS\sbfwim.sys
| |_ Výrobce: Sunbelt Software, Inc.
| |_ Popis: Sunbelt Personal Firewall NDIS Intermediate driver
| |_ MD5: F01B8409A11C319E3C5B9DD418676D2C
|
|_ Jméno: SBFWIMCL
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Sunbelt HIPS Driver
|_ Cesta: C:\WINDOWS\system32\drivers\sbhips.sys
| |_ Výrobce: Sunbelt Software, Inc.
| |_ Popis: Sunbelt Personal Firewall Host Intrusion Prevention Driver
| |_ MD5: 31CA701F26EA66468AD3C3C6498755CE
|
|_ Jméno: sbhips
|_ StartName:
|_ Typ spouštění: System Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] sptd
|_ Cesta: C:\WINDOWS\System32\Drivers\sptd.sys
| |_ Výrobce:
| |_ Popis:
| |_ MD5:
|
|_ Jméno: sptd
|_ StartName:
|_ Typ spouštění: Boot Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}
|_ Cesta: C:\Program Files\CyberLink\PowerDVD8\000.fcl
| |_ Výrobce: Cyberlink Corp.
| |_ Popis: FCL Driver
| |_ MD5: 5867CE254625645345C833510D24F124
|
|_ Jméno: {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}
|_ StartName:
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
lNetStat
================================================================
Typ: PID Proces Local <-> Remote Status
-----------------------------------------------------------------------------------------
TCP (1204) svchost.exe 0.0.0.0:135 LISTENING
TCP (4) Systém 0.0.0.0:445 LISTENING
TCP (580) SbPFCl.exe 0.0.0.0:1027 LISTENING
TCP (3040) ISe8f_2121.exe 0.0.0.0:25455 LISTENING
TCP (880) SbPFSvc.exe 0.0.0.0:44334 LISTENING
TCP (880) SbPFSvc.exe 0.0.0.0:44501 LISTENING
TCP (580) SbPFCl.exe 127.0.0.1:1025 <-> 127.0.0.1:44334 ESTABLISHED
TCP (580) SbPFCl.exe 127.0.0.1:1027 <-> 127.0.0.1:1029 ESTABLISHED
TCP (880) SbPFSvc.exe 127.0.0.1:1029 <-> 127.0.0.1:1027 ESTABLISHED
TCP (2452) alg.exe 127.0.0.1:1033 LISTENING
TCP (0) 127.0.0.1:1054 TIME_WAIT
TCP (0) 127.0.0.1:1075 TIME_WAIT
TCP (880) SbPFSvc.exe 127.0.0.1:44334 <-> 127.0.0.1:1025 ESTABLISHED
TCP (4) Systém 192.168.1.29:139 LISTENING
TCP (0) 192.168.1.29:1040 TIME_WAIT
TCP (0) 192.168.1.29:1041 TIME_WAIT
TCP (0) 192.168.1.29:1042 TIME_WAIT
TCP (0) 192.168.1.29:1043 TIME_WAIT
TCP (0) 192.168.1.29:1044 TIME_WAIT
TCP (0) 192.168.1.29:1045 TIME_WAIT
TCP (0) 192.168.1.29:1046 TIME_WAIT
TCP (0) 192.168.1.29:1047 TIME_WAIT
TCP (0) 192.168.1.29:1048 TIME_WAIT
TCP (0) 192.168.1.29:1049 TIME_WAIT
TCP (0) 192.168.1.29:1050 TIME_WAIT
TCP (0) 192.168.1.29:1051 TIME_WAIT
TCP (0) 192.168.1.29:1052 TIME_WAIT
TCP (0) 192.168.1.29:1053 TIME_WAIT
TCP (0) 192.168.1.29:1056 TIME_WAIT
TCP (0) 192.168.1.29:1059 TIME_WAIT
TCP (0) 192.168.1.29:1060 TIME_WAIT
TCP (0) 192.168.1.29:1062 TIME_WAIT
TCP (0) 192.168.1.29:1063 TIME_WAIT
TCP (0) 192.168.1.29:1064 TIME_WAIT
TCP (0) 192.168.1.29:1065 TIME_WAIT
TCP (0) 192.168.1.29:1066 TIME_WAIT
TCP (0) 192.168.1.29:1067 TIME_WAIT
TCP (0) 192.168.1.29:1068 TIME_WAIT
TCP (0) 192.168.1.29:1069 TIME_WAIT
TCP (0) 192.168.1.29:1070 TIME_WAIT
TCP (3040) ISe8f_2121.exe 192.168.1.29:1071 <-> 95.211.2.55:80 ESTABLISHED
TCP (0) 192.168.1.29:1072 TIME_WAIT
TCP (0) 192.168.1.29:1073 TIME_WAIT
UDP (4) Systém 0.0.0.0:445 TIME_WAIT
UDP (988) lsass.exe 0.0.0.0:500
UDP (580) SbPFCl.exe 0.0.0.0:1026
UDP (580) SbPFCl.exe 0.0.0.0:1028
UDP (988) lsass.exe 0.0.0.0:4500
UDP (880) SbPFSvc.exe 0.0.0.0:44334
UDP (1336) svchost.exe 127.0.0.1:123
UDP (1636) svchost.exe 127.0.0.1:1900
UDP (756) PnkBstrA.exe 127.0.0.1:44301
UDP (768) PnkBstrB.exe 127.0.0.1:45301
UDP (1336) svchost.exe 192.168.1.29:123
UDP (4) Systém 192.168.1.29:137
UDP (4) Systém 192.168.1.29:138
UDP (1636) svchost.exe 192.168.1.29:1900
Moduly (Zobraz i bezpečné DLL: False, Jen bez výrobce: True, Zobraz registrované: False)
================================================================
[?] msnlnamespacemgr.dll
|_ Cesta: C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll
|_ MD5: 994AD0D8550B8B26990A6E3AA0791502
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ explorer.exe (200)
|_ ISe8f_2121.exe (3040)
[?] mpshhook.dll
|_ Cesta: C:\PROGRA~1\WIFD1F~1\MpShHook.dll
|_ MD5: F9D82B82F1B7C0B2D2606A987073F58C
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ explorer.exe (200)
|_ ISe8f_2121.exe (3040)
[?] clrcengine3.dll
|_ Cesta: C:\Program Files\CyberLink\PowerDVD8\CLRCEngine3.dll
|_ MD5: 5295757E598BCA6358FB28B7C6B6D5B5
|_ Výrobce: CyberLink Corp.
|_ Procesy
|_ PDVD8Serv.exe (608)
[?] msvcr71.dll
|_ Cesta: C:\WINDOWS\system32\msvcr71.dll
|_ MD5: 1020C0C4BAC624DAF56712EA6D5865CE
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ brs.exe (624)
|_ soffice.exe (728)
|_ soffice.bin (744)
|_ SbPFLnch.exe (828)
|_ SbPFSvc.exe (880)
|_ SbPFCl.exe (580)
[?] mssph.dll
|_ Cesta: C:\WINDOWS\system32\mssph.dll
|_ MD5: 6E914EEDD145C5ACCE56F4D5F3D606FC
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ WindowsSearch.exe (684)
|_ searchprotocolhost.exe (3200)
[?] xcrmi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\xcrmi.dll
|_ MD5: BB17DC8859D971C52A90FBF895A997D1
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] vos3msc.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\vos3MSC.dll
|_ MD5: F80103D75F406572DE58874E14C3CA3A
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] vclmi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\vclmi.dll
|_ MD5: 0D9D690160F33EA77F24F9EF0B57B84B
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] uwinapi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\URE\bin\uwinapi.dll
|_ MD5: 4CD6B190312A5E363A1D865760C366D6
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] utlmi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\utlmi.dll
|_ MD5: B4DDA85B294A7679D359CA5882FFE6C4
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] unsafe_uno_uno.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\URE\bin\unsafe_uno_uno.dll
|_ MD5: E450AA12BB5F13B69FF563AB5132767A
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] ucpfile1.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\ucpfile1.dll
|_ MD5: 33B30976C30347F1DE09050E2BA0CB90
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] ucbhelper4msc.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\ucbhelper4MSC.dll
|_ MD5: 57575A57B123CB53B9D02ED5BA40B0E7
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] ucb1.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\ucb1.dll
|_ MD5: 54CAE90F8C2F8A705DD9BC7F25A166B3
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] tlmi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\tlmi.dll
|_ MD5: A0B188429089D00521E5871A6015C04D
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] tkmi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\tkmi.dll
|_ MD5: 036805EB09F91E2D0323961C2EE92B30
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] sysmgr1.uno.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\sysmgr1.uno.dll
|_ MD5: CAB93284E3C713813BB004102E785673
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] svtmi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\svtmi.dll
|_ MD5: E4C0F406AB4D30ED799CE382FB511A6F
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] svlmi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\svlmi.dll
|_ MD5: 6BA29812A3D05DA4EC2C19ED3E7E7E5A
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] store3.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\URE\bin\store3.dll
|_ MD5: 449830C75FA2C914DDF4EFB2E58F282A
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] stocservices.uno.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\URE\bin\stocservices.uno.dll
|_ MD5: 79C4E71B8FFDB9BBCD216B92C25C7533
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] stlport_vc7145.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\URE\bin\stlport_vc7145.dll
|_ MD5: D3762F465A52A734E1EF5808A9704202
|_ Výrobce: STLport Consulting, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] sotmi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\sotmi.dll
|_ MD5: E0EC047B8B4F661A7F0DEF67990B895B
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] sofficeapp.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\sofficeapp.dll
|_ MD5: 72E642E42F72725EE64BAB0CA1EC0652
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] sfxmi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\sfxmi.dll
|_ MD5: 945A299FFE6002B1F938D4D0F8DF58D0
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] sbmi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\sbmi.dll
|_ MD5: 13512637FF7C2BABF764EA80B8C3F19C
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] saxmi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\saxmi.dll
|_ MD5: 0E5A0A7D6771157DA4B90C115261473F
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] sax.uno.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\sax.uno.dll
|_ MD5: C1DB3670BD0A5C4267348D27DD66B9A3
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] salhelper3msc.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\URE\bin\salhelper3MSC.dll
|_ MD5: 1B9F1AA9D75B085F046A1649AFA781BF
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] sal3.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\URE\bin\sal3.dll
|_ MD5: AA8C288FF07C3C22954E7202C6993C27
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] reg3.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\URE\bin\reg3.dll
|_ MD5: B31F351DAA9146386C10153263BC7857
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] purpenvhelper3msc.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\URE\bin\purpenvhelper3MSC.dll
|_ MD5: D6BC0CDDE784B8B20B7772C968A6DF66
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] oleautobridge.uno.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\oleautobridge.uno.dll
|_ MD5: C31B30CE688870213EF76332617DAE31
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] msci_uno.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\URE\bin\msci_uno.dll
|_ MD5: 5BE669B2A300A153D529E45EFB0F4DA4
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] localebe1.uno.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\localebe1.uno.dll
|_ MD5: C9CD9386DB8706AAE2B9611A9F8C5619
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] libxml2.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\program\libxml2.dll
|_ MD5: 954B86D38F1DCDFE408C51AC0A9596D5
|_ Výrobce:
|_ Procesy
|_ soffice.bin (744)
[?] jvmfwk3.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\URE\bin\jvmfwk3.dll
|_ MD5: D61425AED51238B70B1CBE436286DF4B
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] jvmaccess3msc.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\URE\bin\jvmaccess3MSC.dll
|_ MD5: AE7E9B7515B46FE6BE0E4003A5A522F5
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] jmi_g.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\jmi_g.dll
|_ MD5: ADEAEB78463A74C89A74573EB96188B3
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] icuuc36.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\icuuc36.dll
|_ MD5: 8CB8FC0250C8CF5B45709118A6975C48
|_ Výrobce: IBM Corporation and others
|_ Procesy
|_ soffice.bin (744)
[?] i18nutilmsc.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\i18nutilMSC.dll
|_ MD5: EB45B90AAE08187893805BE9E39BDB41
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] i18nisolang1msc.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\i18nisolang1MSC.dll
|_ MD5: 7EBCB01DEEF7DAD792B08C70A3B8B323
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] fwlmi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\fwlmi.dll
|_ MD5: 392E439F904571BCB8F51624A28370CC
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] fwkmi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\fwkmi.dll
|_ MD5: 115E0059E36D9994E13A1B9CBDDDE82F
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] fwimi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\fwimi.dll
|_ MD5: 899991C8D63BDAD9EBAF2054FD051F09
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] fwemi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\fwemi.dll
|_ MD5: 10C9494FC55CBEFF167A7F3ACED2DD63
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] emsermi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\emsermi.dll
|_ MD5: 5A9F2B5731E5F03D7311E88C80882C7B
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] cppuhelper3msc.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\URE\bin\cppuhelper3MSC.dll
|_ MD5: 9C8C933B27EF926C3F2E1A7F2D6F594B
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] cppu3.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\URE\bin\cppu3.dll
|_ MD5: A1CA217DEACC2CC526FACE232E88900C
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] configmgr2.uno.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\configmgr2.uno.dll
|_ MD5: FE9F113B43AEFFA4F43C9CE45218860F
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] comphelp4msc.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\comphelp4MSC.dll
|_ MD5: EFF715CE04B59F2A6F6F25A148D11494
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] bootstrap.uno.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\URE\bin\bootstrap.uno.dll
|_ MD5: 48FF352083DDE391FCE64D65A31107FD
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] behelper.uno.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\behelper.uno.dll
|_ MD5: 56DCB74B26BEDA7F00EBEAE2DC50C137
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] basegfxmi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\basegfxmi.dll
|_ MD5: 4D870DE685AB57C3726A89B5DB88F2A9
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] msvcp71.dll
|_ Cesta: C:\WINDOWS\system32\msvcp71.dll
|_ MD5: 7333E3C6FB7F18E5663B53E1F6DBF4C6
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ soffice.bin (744)
|_ SbPFLnch.exe (828)
|_ SbPFSvc.exe (880)
|_ SbPFCl.exe (580)
[?] sbpfwsc.dll
|_ Cesta: C:\Program Files\Sunbelt Software\Personal Firewall\SbPFWsc.dll
|_ MD5: 78180FEE4510AE88EE558A5D67CA957E
|_ Výrobce: Sunbelt Software, Inc.
|_ Procesy
|_ SbPFSvc.exe (880)
[?] sbfwe.dll
|_ Cesta: C:\Program Files\Sunbelt Software\Personal Firewall\SbFwe.dll
|_ MD5: E58310A15907E796EFBAD656C8AF8FE1
|_ Výrobce: Sunbelt Software, Inc.
|_ Procesy
|_ SbPFSvc.exe (880)
[?] sbfw.dll
|_ Cesta: C:\Program Files\Sunbelt Software\Personal Firewall\SbFw.dll
|_ MD5: FBF764810E93B65F30A9BA35FBAB39DF
|_ Výrobce: Sunbelt Software, Inc.
|_ Procesy
|_ SbPFSvc.exe (880)
[?] sbfwim.dll
|_ Cesta: C:\Program Files\Sunbelt Software\Personal Firewall\SbFwIm.dll
|_ MD5: 749D918F3CF8783BD632ADD82761D0DB
|_ Výrobce: Sunbelt Software, Inc.
|_ Procesy
|_ SbPFSvc.exe (880)
[?] mscomctl.ocx
|_ Cesta: C:\Program Files\Ultimate Process Manager\MSCOMCTL.OCX
|_ MD5: D9578FF8B495DC575E848C6670BE85CC
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ UPM.exe (3012)
Výpis souborů
================================================================
\System32:
[?] ALSNDMGR.CPL 14 no vrfy, {A13440C9}
[?] aswBoot.exe 7 no vrfy, {A54865FB}
[?] AvastSS.scr 14 no vrfy, {80EEA296}
[?] bdco1ins.dll 7 no vrfy, {240E738F}
[?] ChCfg.exe 12 ncmpny, {E0AF3E6B}
[?] D3DCompiler_33.dll D3DCOM~1.DLL 12 ncmpny, {3643F195}
[?] D3DCompiler_34.dll D3DCOM~2.DLL 12 ncmpny, {3D652F77}
[?] d3dx10_33.dll D3DX10~1.DLL 12 ncmpny, {6B35033F}
[?] d3dx10_34.dll D3DX10~2.DLL 12 ncmpny, {D5987E3E}
[?] d3dx9_33.dll 12 ncmpny, {A9975507}
[?] d3dx9_34.dll 12 ncmpny, {D937437C}
[?] deployJava1.dll DEPLOY~1.DLL 14 no vrfy, {46453EA4}
[!] divx.dll 70 no vrfy, infected? {0BD99A36}
[?] ff_vfw.dll 12 ncmpny, {A9D90134}
[?] keystone.exe 12 ncmpny, {FCC0F422}
[?] lameACM.acm 7 no vrfy, {3DB1D192}
[?] LegitCheckControl.dll LEGITC~1.DLL 12 ncmpny, {A3DA1FF7}
[?] MpSigStub.exe MPSIGS~1.EXE 12 ncmpny, {FC80F819}
[?] MRT.exe 25 ncmpny, {267D1720}
[?] msdelta.dll 12 ncmpny, {31109132}
[?] msi.dll 25 ncmpny, {1C4D0C2B}
[?] msihnd.dll 12 ncmpny, {957DFC0F}
[?] msisip.dll 12 ncmpny, {1793D70A}
[?] mssph.dll 12 ncmpny, {1B5B3D66}
[?] msvcp71.dll 12 ncmpny, {E4243F1F}
[?] msvcr71.dll 12 ncmpny, {82C5CE07}
[?] nvappbar.exe 25 ncmpny, {063F9911}
[?] nvcolor.exe 7 no vrfy, {E6D868F7}
[?] nvcpl.cpl 14 no vrfy, {8A58D18C}
[?] nvcplui.exe 7 no vrfy, {D091AEAB}
[?] nvdspsch.exe 25 ncmpny, {7AA319CC}
[?] nvexpbar.dll 7 no vrfy, {98B95497}
[?] nview.dll 12 ncmpny, {5D230EB0}
[?] nvshell.dll 25 ncmpny, {B3D09403}
[?] nvudisp.exe 14 no vrfy, {C4E24DB4}
[?] nvugart.exe 14 no vrfy, {EDFD2A87}
[?] nvunrm.exe 14 no vrfy, {68D51725}
[?] nvusmb.exe 14 no vrfy, {EDFD2A87}
[?] nvwdmcpl.dll 25 ncmpny, {647A9520}
[?] nwiz.exe 25 ncmpny, {B434F7EB}
[?] PnkBstrA.exe 12 ncmpny, {353A540B}
[?] PnkBstrB.exe 12 ncmpny, {540F86EF}
[?] RTLCPL.EXE 14 no vrfy, {C356E656}
[?] spupdsvc.exe 12 ncmpny, {9C3299D3}
[?] x3daudio1_2.dll X3DAUD~3.DLL 12 ncmpny, {527053FD}
[?] xactengine2_7.dll XA3466~1.DLL 12 ncmpny, {E1662632}
[?] xactengine2_8.dll XA3866~1.DLL 12 ncmpny, {158D9824}
[?] xinput1_3.dll XINPUT~4.DLL 12 ncmpny, {F18D8B9B}
\Drivers:
[?] aavmker4.sys 14 no vrfy, {32C4A970}
[?] ALCXWDM.SYS 14 no vrfy, {05F1E0DD}
[?] aswFsBlk.sys 14 no vrfy, {23A34AAC}
[?] aswmon.sys 14 no vrfy, {0F15F888}
[?] aswmon2.sys 14 no vrfy, {4AC4EB8D}
[?] aswRdr.sys 14 no vrfy, {B3E9818F}
[?] aswSP.sys 14 no vrfy, {FB5DF16D}
[?] aswTdi.sys 14 no vrfy, {80D2B6C4}
[?] BIOS.sys 14 no vrfy, {6B4E7158}
[?] GVTDrv.sys 25 ncmpny, {A862445B}
[?] nvp2p.sys 7 no vrfy, {7AE3F622}
[?] PnkBstrK.sys 12 ncmpny, {86CE91C8}
[?] SbFw.sys 14 no vrfy, {82A54725}
[?] sbhips.sys 14 no vrfy, {931B747C}
Access violations - HKCU
================================================================
================================================================
Ultimate Process Manager v4.1.3 - [ Lodus Software ][/code]
odbornou pomoc podle návodu na tomto serveru.
Zde je můj log:
[code]Windows XP SP 3 (build 2600)
Boot Mode: Normal
Ověření souborů Microsoftu: Ano
Whitelist: Ano
Internet Explorer v8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Log vygenerován: 11.12.2010 15:07:22
================================================================
SmallARK
================================================================
[?]NtClose -> C:\WINDOWS\system32\drivers\aswSP.SYS
[?]NtCreateFile -> C:\WINDOWS\system32\drivers\SbFw.sys
[?]NtCreateKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[?]NtCreateProcess -> C:\WINDOWS\system32\drivers\SbFw.sys
[?]NtCreateProcessEx -> C:\WINDOWS\system32\drivers\SbFw.sys
[?]NtCreateThread -> C:\WINDOWS\system32\drivers\SbFw.sys
[?]NtDeleteFile -> C:\WINDOWS\system32\drivers\SbFw.sys
[?]NtDeleteKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[?]NtDeleteValueKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[?]NtDuplicateObject -> C:\WINDOWS\system32\drivers\aswSP.SYS
[?]NtEnumerateKey -> spit.sys
[?]NtEnumerateValueKey -> spit.sys
[?]NtLoadDriver -> C:\WINDOWS\system32\drivers\sbhips.sys
[?]NtMapViewOfSection -> C:\WINDOWS\system32\drivers\sbhips.sys
[?]NtOpenFile -> C:\WINDOWS\system32\drivers\SbFw.sys
[?]NtOpenKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[?]NtOpenProcess -> C:\WINDOWS\system32\drivers\aswSP.SYS
[?]NtOpenThread -> C:\WINDOWS\system32\drivers\aswSP.SYS
[?]NtQueryKey -> spit.sys
[?]NtQueryValueKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[?]NtRenameKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[?]NtRestoreKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[?]NtResumeThread -> C:\WINDOWS\system32\drivers\SbFw.sys
[?]NtSetInformationFile -> C:\WINDOWS\system32\drivers\SbFw.sys
[?]NtSetValueKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[?]NtWriteFile -> C:\WINDOWS\system32\drivers\SbFw.sys
Běžící procesy
================================================================
C:\PROGRAM FILES\ICQ6TOOLBAR\ICQ SERVICE.EXE
|_ MD5: 5C7D72EAB04B1DF8C5D2ACC6551FDE49
|_Výrobce: ?
C:\WINDOWS\SOUNDMAN.EXE
|_ MD5: 254CF75C7550C33830B8B851B9621215
|_Výrobce: Realtek Semiconductor Corp.
C:\PROGRAM FILES\CYBERLINK\POWERDVD8\PDVD8SERV.EXE
|_ MD5: 0A80BED61A1729DAB9499BC5A9B515A9
|_Výrobce: Cyberlink Corp.
C:\PROGRAM FILES\CYBERLINK\SHARED FILES\BRS.EXE
|_ MD5: 04C40F2EFB9F333E16CE33A2D283829F
|_Výrobce: cyberlink
C:\PROGRAM FILES\ADOBE\READER 9.0\READER\READER_SL.EXE
|_ MD5: 12673BCF7B32087DF63F0CFF550EA40B
|_Výrobce: Adobe Systems Incorporated
C:\PROGRAM FILES\OPENOFFICE.ORG 3\PROGRAM\SOFFICE.EXE
|_ MD5: DB9F8DBE8C9A5AE7A27C2C02E1FEC9EB
|_Výrobce: OpenOffice.org
C:\PROGRAM FILES\OPENOFFICE.ORG 3\PROGRAM\SOFFICE.BIN
|_ MD5: A1130EE690868B4B2C2F70B18F45185F
|_Výrobce: OpenOffice.org
C:\WINDOWS\SYSTEM32\PNKBSTRA.EXE
|_ MD5: 0E01D7EEBADA0B324DB0CA1EE73440BA
|_Výrobce:
C:\WINDOWS\SYSTEM32\PNKBSTRB.EXE
|_ MD5: 1428E6CC1458A36CBFC1F2E304C7C42D
|_Výrobce:
C:\PROGRAM FILES\SUNBELT SOFTWARE\PERSONAL FIREWALL\SBPFLNCH.EXE
|_ MD5: 56C92289535834AA26144B4368932DCB
|_Výrobce: Sunbelt Software, Inc.
C:\PROGRAM FILES\SUNBELT SOFTWARE\PERSONAL FIREWALL\SBPFSVC.EXE
|_ MD5: B3C9D712962DB83C280D0C4AAC8963A8
|_Výrobce: Sunbelt Software, Inc.
C:\PROGRAM FILES\SUNBELT SOFTWARE\PERSONAL FIREWALL\SBPFCL.EXE
|_ MD5: 3CAADDDA144B326B0111C07E0FEE56F3
|_Výrobce: Sunbelt Software, Inc.
C:\DOCUMENTS AND SETTINGS\ALL USERS\DATA APLIKACÍ\E8FB4F\ISE8F_2121.EXE
|_ MD5: 21CE1989C7188CC2B8DB186F547DFB05
|_Výrobce: Smpnsb
Scanner
================================================================
[S] svchost.exe
Spouští se po startu HKLM IFEO [a.exe]
[S] svchost.exe
Spouští se po startu HKLM IFEO [a.exe]
[S] svchost.exe
Spouští se po startu HKLM IFEO [a.exe]
[S] svchost.exe
Spouští se po startu HKLM IFEO [a.exe]
[S] svchost.exe
Spouští se po startu HKLM IFEO [a.exe]
[S] svchost.exe
Spouští se po startu HKLM IFEO [a.exe]
[S] explorer.exe
Spouští se po startu HKLM Winlogon [Shell]
[S] svchost.exe
Spouští se po startu HKLM IFEO [a.exe]
[?] ICQ Service.exe
Bez výrobce
Nemá okno
Soubor 12%
[?] SOUNDMAN.EXE
Spouští se po startu HKLM Run [SoundMan]
Soubor 7%
[S] rundll32.exe
Spouští se po startu HKLM Run [NvCplDaemon]
[?] PDVD8Serv.exe
Spouští se po startu HKLM Run [RemoteControl8]
Soubor 7%
[?] brs.exe
Spouští se po startu HKLM Run [BDRegion]
EntryPoint v sekci:
|_ Celkový počet sekcí: 7
Soubor 70%
[?] reader_sl.exe
Spouští se po startu HKLM Run [Adobe Reader Speed Launcher]
Soubor 7%
[S] ctfmon.exe
Spouští se po startu HKCU Run [CTFMON.EXE]
[S] WindowsSearch.exe
Spouští se po startu Po spuštění []
[?] soffice.exe
Nemá okno
Soubor 14%
[?] soffice.bin
Soubor 14%
[?] PnkBstrA.exe
Bez výrobce v System32
Podobná jména: PNKBSTRA.EXE X PNKBSTRB.EXE
Nemá okno
Soubor 12%
[?] PnkBstrB.exe
Bez výrobce v System32
Podobná jména: PNKBSTRB.EXE X PNKBSTRA.EXE
Nemá okno
Soubor 12%
[?] SbPFLnch.exe
Nemá okno
Soubor 14%
[?] SbPFSvc.exe
Nemá okno
Soubor 7%
[?] SbPFCl.exe
Soubor 14%
[?] ISe8f_2121.exe
Spouští se po startu HKCU Run [Internet Security Suite]
EntryPoint v sekci:
|_ Celkový počet sekcí: 4
Podvržená cesta modulu: (00D90000) [DLL] ?
Podvržená cesta modulu: (13140000) C:\Documents and Settings\All Users\Data aplikací\e8fb4f\ISe8f_2121.exe
Soubor 14%
Po spuštění
================================================================
HKCU Run
|_ [?][Internet Security Suite] C:\Documents and Settings\All Users\Data aplikací\e8fb4f\ISe8f_2121.exe /s /d
|_ MD5: 21CE1989C7188CC2B8DB186F547DFB05
|_ Výrobce: Smpnsb
HKLM Run
|_ [?][SoundMan] C:\WINDOWS\SOUNDMAN.EXE
| |_ MD5: 254CF75C7550C33830B8B851B9621215
| |_ Výrobce: Realtek Semiconductor Corp.
|
|_ [?][NvCplDaemon] C:\WINDOWS\system32\NvCpl.dll ,NvStartup
| |_ MD5: 4D8E9C2FB7E234A7FDFA6EC54794217F
| |_ Výrobce: NVIDIA Corporation
|
|_ [?][nwiz] nwiz.exe /install
| |_ MD5:
| |_ Výrobce: ?
|
|_ [?][NvMediaCenter] C:\WINDOWS\system32\NvMcTray.dll ,NvTaskbarInit
| |_ MD5: 3BC7B677094A2EF0BDDC3A9375E1F8A2
| |_ Výrobce: NVIDIA Corporation
|
|_ [?][RemoteControl8] C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
| |_ MD5: 0A80BED61A1729DAB9499BC5A9B515A9
| |_ Výrobce: Cyberlink Corp.
|
|_ [?][PDVD8LanguageShortcut] C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe
| |_ MD5: AA62A9A6CE962107761775C66F49AD53
| |_ Výrobce: ?
|
|_ [!][BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe
| |_ MD5: 04C40F2EFB9F333E16CE33A2D283829F
| |_ Výrobce: cyberlink
|
|_ [?][Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
| |_ MD5: 12673BCF7B32087DF63F0CFF550EA40B
| |_ Výrobce: Adobe Systems Incorporated
|
|_ [?][Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
| |_ MD5: BAD6BEA0DE1F69C82BDB74378CE0C20A
| |_ Výrobce: Adobe Systems Incorporated
|
|_ [?][Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe -hide
| |_ MD5: 77C03BF23AE56B0A31AE4D5BB4B3D0AC
| |_ Výrobce: Microsoft Corporation
|
|_ [?][avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe /nogui
|_ MD5: 6C1B31F5C16E03153F0037AC6C451FFD
|_ Výrobce: AVAST Software
HKLM IC
|_ [X][>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP (Soubor nenalezen)
|_ [?][{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] C:\WINDOWS\INF\msnetmtg.inf ,NetMtg.Install.PerUser.NT
| |_ MD5: F8995D4274D3D7E32BE7812B872BCC13
| |_ Výrobce:
|
|_ [?][{5945c046-1e7d-11d1-bc44-00c04fd912be}] C:\WINDOWS\INF\msmsgs.inf ,BLC.QuietInstall.PerUser
| |_ MD5: 97BF5E6CB8D2498286096D35644517C5
| |_ Výrobce:
|
|_ [?][{6BF52A52-394A-11d3-B153-00C04F79FAA6}] C:\WINDOWS\INF\wmp11.inf ,PerUserStub
| |_ MD5: C50E7DA8003BF4B222248B9DB4104290
| |_ Výrobce:
|
|_ [?][{89820200-ECBD-11cf-8B85-00AA005B4340}] regsvr32.exe /s /n /i:U shell32.dll
|_ MD5:
|_ Výrobce: Microsoft Corporation
Po spuštění
|_ [?][OpenOffice.org 3.0.lnk] C:\Program Files\OpenOffice.org 3\program\quickstart.exe
|_ MD5: A08920D9BE346EEAA85EE0339D21BF86
|_ Výrobce:
Job
|_ [?][MPSCHE~1.JOB] C:\Program Files\Windows Defender\MpCmdRun.exe
|_ MD5: 08AD1CD68D68711C75C15BF42A11892B
|_ Výrobce: Microsoft Corporation
HKLM BHO
|_ [?][{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
| |_ MD5: 203A74767EB81F96A5166B1933DB46D0
| |_ Výrobce: Adobe Systems Incorporated
|
|_ [X][{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}] (Soubor nenalezen)
|_ [X][{DBC80044-A445-435b-BC74-9C25C1C588A9}] (Soubor nenalezen)
HKLM IE Toolbar
|_ [?][{855F3B16-6D32-4FE6-8A56-BBB695989046}] C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
|_ MD5: 2A21B1EBEFE3A69D1E071F93DF95E0AC
|_ Výrobce: ICQ
Služby (Zobraz běžící: True, Zobraz zastavené: False, Zobraz i bezpečné služby: False)
================================================================
[?] avast! Antivirus
|_ Cesta: C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
| |_ Výrobce: AVAST Software
| |_ Popis: avast! Service
| |_ MD5: ACB544D7254F366DFB48F380BC36CD25
|
|_ Jméno: avast! Antivirus
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Zastaveno
|_ Typ: Win32 Share Process
|_ Dependency: aswMon2
[?] ICQ Service
|_ Cesta: C:\Program Files\ICQ6Toolbar\ICQ Service.exe
| |_ Výrobce: ?
| |_ Popis: ICQIEUpdater Module
| |_ MD5: 5C7D72EAB04B1DF8C5D2ACC6551FDE49
|
|_ Jméno: ICQ Service
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ:
|_ Dependency: RPCSS
[?] PnkBstrA
|_ Cesta: C:\WINDOWS\system32\PnkBstrA.exe
| |_ Výrobce:
| |_ Popis:
| |_ MD5: 0E01D7EEBADA0B324DB0CA1EE73440BA
|
|_ Jméno: PnkBstrA
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Own Process
|_ Dependency:
[?] PnkBstrB
|_ Cesta: C:\WINDOWS\system32\PnkBstrB.exe
| |_ Výrobce:
| |_ Popis:
| |_ MD5: 1428E6CC1458A36CBFC1F2E304C7C42D
|
|_ Jméno: PnkBstrB
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Own Process
|_ Dependency:
[?] SbPF.Launcher
|_ Cesta: C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
| |_ Výrobce: Sunbelt Software, Inc.
| |_ Popis: Sunbelt Personal Firewall SbPFLnch
| |_ MD5: 56C92289535834AA26144B4368932DCB
|
|_ Jméno: SbPF.Launcher
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Own Process
|_ Dependency:
[?] Sunbelt Personal Firewall 4
|_ Cesta: C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
| |_ Výrobce: Sunbelt Software, Inc.
| |_ Popis: Sunbelt Firewall Service
| |_ MD5: B3C9D712962DB83C280D0C4AAC8963A8
|
|_ Jméno: SPF4
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Own Process
|_ Dependency:
[?] Windows Defender
|_ Cesta: C:\Program Files\Windows Defender\MsMpEng.exe
| |_ Výrobce: Microsoft Corporation
| |_ Popis: Service Executable
| |_ MD5: F45DD1E1365D857DD08BC23563370D0E
|
|_ Jméno: WinDefend
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Zastaveno
|_ Typ: Win32 Own Process
|_ Dependency: RpcSs
Ovladače (Zobraz běžící: True, Zobraz zastavené: False, Zobraz i bezpečné služby: False)
================================================================
[?] avast! Asynchronous Virus Monitor
|_ Cesta: C:\WINDOWS\system32\drivers\Aavmker4.sys
| |_ Výrobce: AVAST Software
| |_ Popis: avast! Base Kernel-Mode Device Driver for Windows NT/2000/XP
| |_ MD5: 8D488938E2F7048906F1FBD3AF394887
|
|_ Jméno: Aavmker4
|_ StartName:
|_ Typ spouštění: System Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Service for Realtek AC97 Audio (WDM)
|_ Cesta: C:\WINDOWS\system32\drivers\ALCXWDM.SYS
| |_ Výrobce: Realtek Semiconductor Corp.
| |_ Popis: Realtek AC'97 Audio Driver (WDM)
| |_ MD5: A73C58F6214795044E49D4B120C89D9D
|
|_ Jméno: ALCXWDM
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] aswFsBlk
|_ Cesta: C:\WINDOWS\system32\drivers\aswFsBlk.sys
| |_ Výrobce: AVAST Software
| |_ Popis: avast! File System Access Blocking Driver
| |_ MD5: A0D86B8AC93EF95620420C7A24AC5344
|
|_ Jméno: aswFsBlk
|_ StartName:
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: File System Driver
|_ Dependency: FltMgr
[?] aswMon2
|_ Cesta: C:\WINDOWS\system32\drivers\aswMon2.sys
| |_ Výrobce: AVAST Software
| |_ Popis: avast! File System Filter Driver for Windows XP
| |_ MD5: 7D880C76A285A41284D862E2D798EC0D
|
|_ Jméno: aswMon2
|_ StartName:
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: File System Driver
|_ Dependency:
[?] aswSP
|_ Cesta: C:\WINDOWS\system32\drivers\aswSP.sys
| |_ Výrobce: AVAST Software
| |_ Popis: avast! self protection module
| |_ MD5: 7ECC2776638B04553F9A85BD684C3ABF
|
|_ Jméno: aswSP
|_ StartName:
|_ Typ spouštění: System Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] avast! Network Shield Support
|_ Cesta: C:\WINDOWS\system32\drivers\aswTdi.sys
| |_ Výrobce: AVAST Software
| |_ Popis: avast! TDI Filter Driver
| |_ MD5: 095ED820A926AA8189180B305E1BCFC9
|
|_ Jméno: aswTdi
|_ StartName:
|_ Typ spouštění: System Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency: tcpip
[?] BIOS
|_ Cesta: C:\WINDOWS\system32\drivers\BIOS.sys
| |_ Výrobce: BIOSTAR Group
| |_ Popis: I/O Interface driver file
| |_ MD5: BE5D50529799B9BAB6BE879EC768B6CF
|
|_ Jméno: BIOS
|_ StartName:
|_ Typ spouštění: System Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] NVIDIA nForce Networking Controller Driver
|_ Cesta: C:\WINDOWS\system32\DRIVERS\NVENETFD.sys
| |_ Výrobce: NVIDIA Corporation
| |_ Popis: NVIDIA Networking Function Driver.
| |_ MD5: 23297B3C2FF3510E2E760714FC6F094E
|
|_ Jméno: NVENETFD
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] NVIDIA Network Bus Enumerator
|_ Cesta: C:\WINDOWS\system32\DRIVERS\nvnetbus.sys
| |_ Výrobce: NVIDIA Corporation
| |_ Popis: NVIDIA Networking Bus Driver.
| |_ MD5: BCC3722A2DB99AD6F367344997C26654
|
|_ Jméno: nvnetbus
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] NVIDIA PCI to PCI Bridge Filter
|_ Cesta: C:\WINDOWS\system32\DRIVERS\nvp2p.sys
| |_ Výrobce: NVIDIA Corporation
| |_ Popis: NVIDIA® nForce(TM) PCI to PCI Bridge Driver
| |_ MD5: 63E148FB550EE6F3280BDC7B13E0005A
|
|_ Jméno: nvp2p
|_ StartName:
|_ Typ spouštění: Boot Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] NVIDIA nForce AGP Bus Filter
|_ Cesta: C:\WINDOWS\system32\DRIVERS\nv_agp.sys
| |_ Výrobce: NVIDIA Corporation
| |_ Popis: NVIDIA nForce AGP Filter
| |_ MD5: C0FCD544A1C4EEA6D11A0AE6A07DAC9D
|
|_ Jméno: nv_agp
|_ StartName:
|_ Typ spouštění: Boot Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] SbFw
|_ Cesta: C:\WINDOWS\system32\drivers\SbFw.sys
| |_ Výrobce: Sunbelt Software, Inc.
| |_ Popis: Sunbelt Personal Firewall driver
| |_ MD5: 419883201CA9AD697CCFB8FC46DD6F78
|
|_ Jméno: SbFw
|_ StartName:
|_ Typ spouštění: System Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Sunbelt Software Firewall NDIS IM Filter Miniport
|_ Cesta: C:\WINDOWS\system32\DRIVERS\sbfwim.sys
| |_ Výrobce: Sunbelt Software, Inc.
| |_ Popis: Sunbelt Personal Firewall NDIS Intermediate driver
| |_ MD5: F01B8409A11C319E3C5B9DD418676D2C
|
|_ Jméno: SBFWIMCL
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Sunbelt HIPS Driver
|_ Cesta: C:\WINDOWS\system32\drivers\sbhips.sys
| |_ Výrobce: Sunbelt Software, Inc.
| |_ Popis: Sunbelt Personal Firewall Host Intrusion Prevention Driver
| |_ MD5: 31CA701F26EA66468AD3C3C6498755CE
|
|_ Jméno: sbhips
|_ StartName:
|_ Typ spouštění: System Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] sptd
|_ Cesta: C:\WINDOWS\System32\Drivers\sptd.sys
| |_ Výrobce:
| |_ Popis:
| |_ MD5:
|
|_ Jméno: sptd
|_ StartName:
|_ Typ spouštění: Boot Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}
|_ Cesta: C:\Program Files\CyberLink\PowerDVD8\000.fcl
| |_ Výrobce: Cyberlink Corp.
| |_ Popis: FCL Driver
| |_ MD5: 5867CE254625645345C833510D24F124
|
|_ Jméno: {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}
|_ StartName:
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
lNetStat
================================================================
Typ: PID Proces Local <-> Remote Status
-----------------------------------------------------------------------------------------
TCP (1204) svchost.exe 0.0.0.0:135 LISTENING
TCP (4) Systém 0.0.0.0:445 LISTENING
TCP (580) SbPFCl.exe 0.0.0.0:1027 LISTENING
TCP (3040) ISe8f_2121.exe 0.0.0.0:25455 LISTENING
TCP (880) SbPFSvc.exe 0.0.0.0:44334 LISTENING
TCP (880) SbPFSvc.exe 0.0.0.0:44501 LISTENING
TCP (580) SbPFCl.exe 127.0.0.1:1025 <-> 127.0.0.1:44334 ESTABLISHED
TCP (580) SbPFCl.exe 127.0.0.1:1027 <-> 127.0.0.1:1029 ESTABLISHED
TCP (880) SbPFSvc.exe 127.0.0.1:1029 <-> 127.0.0.1:1027 ESTABLISHED
TCP (2452) alg.exe 127.0.0.1:1033 LISTENING
TCP (0) 127.0.0.1:1054 TIME_WAIT
TCP (0) 127.0.0.1:1075 TIME_WAIT
TCP (880) SbPFSvc.exe 127.0.0.1:44334 <-> 127.0.0.1:1025 ESTABLISHED
TCP (4) Systém 192.168.1.29:139 LISTENING
TCP (0) 192.168.1.29:1040 TIME_WAIT
TCP (0) 192.168.1.29:1041 TIME_WAIT
TCP (0) 192.168.1.29:1042 TIME_WAIT
TCP (0) 192.168.1.29:1043 TIME_WAIT
TCP (0) 192.168.1.29:1044 TIME_WAIT
TCP (0) 192.168.1.29:1045 TIME_WAIT
TCP (0) 192.168.1.29:1046 TIME_WAIT
TCP (0) 192.168.1.29:1047 TIME_WAIT
TCP (0) 192.168.1.29:1048 TIME_WAIT
TCP (0) 192.168.1.29:1049 TIME_WAIT
TCP (0) 192.168.1.29:1050 TIME_WAIT
TCP (0) 192.168.1.29:1051 TIME_WAIT
TCP (0) 192.168.1.29:1052 TIME_WAIT
TCP (0) 192.168.1.29:1053 TIME_WAIT
TCP (0) 192.168.1.29:1056 TIME_WAIT
TCP (0) 192.168.1.29:1059 TIME_WAIT
TCP (0) 192.168.1.29:1060 TIME_WAIT
TCP (0) 192.168.1.29:1062 TIME_WAIT
TCP (0) 192.168.1.29:1063 TIME_WAIT
TCP (0) 192.168.1.29:1064 TIME_WAIT
TCP (0) 192.168.1.29:1065 TIME_WAIT
TCP (0) 192.168.1.29:1066 TIME_WAIT
TCP (0) 192.168.1.29:1067 TIME_WAIT
TCP (0) 192.168.1.29:1068 TIME_WAIT
TCP (0) 192.168.1.29:1069 TIME_WAIT
TCP (0) 192.168.1.29:1070 TIME_WAIT
TCP (3040) ISe8f_2121.exe 192.168.1.29:1071 <-> 95.211.2.55:80 ESTABLISHED
TCP (0) 192.168.1.29:1072 TIME_WAIT
TCP (0) 192.168.1.29:1073 TIME_WAIT
UDP (4) Systém 0.0.0.0:445 TIME_WAIT
UDP (988) lsass.exe 0.0.0.0:500
UDP (580) SbPFCl.exe 0.0.0.0:1026
UDP (580) SbPFCl.exe 0.0.0.0:1028
UDP (988) lsass.exe 0.0.0.0:4500
UDP (880) SbPFSvc.exe 0.0.0.0:44334
UDP (1336) svchost.exe 127.0.0.1:123
UDP (1636) svchost.exe 127.0.0.1:1900
UDP (756) PnkBstrA.exe 127.0.0.1:44301
UDP (768) PnkBstrB.exe 127.0.0.1:45301
UDP (1336) svchost.exe 192.168.1.29:123
UDP (4) Systém 192.168.1.29:137
UDP (4) Systém 192.168.1.29:138
UDP (1636) svchost.exe 192.168.1.29:1900
Moduly (Zobraz i bezpečné DLL: False, Jen bez výrobce: True, Zobraz registrované: False)
================================================================
[?] msnlnamespacemgr.dll
|_ Cesta: C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll
|_ MD5: 994AD0D8550B8B26990A6E3AA0791502
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ explorer.exe (200)
|_ ISe8f_2121.exe (3040)
[?] mpshhook.dll
|_ Cesta: C:\PROGRA~1\WIFD1F~1\MpShHook.dll
|_ MD5: F9D82B82F1B7C0B2D2606A987073F58C
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ explorer.exe (200)
|_ ISe8f_2121.exe (3040)
[?] clrcengine3.dll
|_ Cesta: C:\Program Files\CyberLink\PowerDVD8\CLRCEngine3.dll
|_ MD5: 5295757E598BCA6358FB28B7C6B6D5B5
|_ Výrobce: CyberLink Corp.
|_ Procesy
|_ PDVD8Serv.exe (608)
[?] msvcr71.dll
|_ Cesta: C:\WINDOWS\system32\msvcr71.dll
|_ MD5: 1020C0C4BAC624DAF56712EA6D5865CE
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ brs.exe (624)
|_ soffice.exe (728)
|_ soffice.bin (744)
|_ SbPFLnch.exe (828)
|_ SbPFSvc.exe (880)
|_ SbPFCl.exe (580)
[?] mssph.dll
|_ Cesta: C:\WINDOWS\system32\mssph.dll
|_ MD5: 6E914EEDD145C5ACCE56F4D5F3D606FC
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ WindowsSearch.exe (684)
|_ searchprotocolhost.exe (3200)
[?] xcrmi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\xcrmi.dll
|_ MD5: BB17DC8859D971C52A90FBF895A997D1
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] vos3msc.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\vos3MSC.dll
|_ MD5: F80103D75F406572DE58874E14C3CA3A
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] vclmi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\vclmi.dll
|_ MD5: 0D9D690160F33EA77F24F9EF0B57B84B
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] uwinapi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\URE\bin\uwinapi.dll
|_ MD5: 4CD6B190312A5E363A1D865760C366D6
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] utlmi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\utlmi.dll
|_ MD5: B4DDA85B294A7679D359CA5882FFE6C4
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] unsafe_uno_uno.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\URE\bin\unsafe_uno_uno.dll
|_ MD5: E450AA12BB5F13B69FF563AB5132767A
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] ucpfile1.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\ucpfile1.dll
|_ MD5: 33B30976C30347F1DE09050E2BA0CB90
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] ucbhelper4msc.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\ucbhelper4MSC.dll
|_ MD5: 57575A57B123CB53B9D02ED5BA40B0E7
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] ucb1.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\ucb1.dll
|_ MD5: 54CAE90F8C2F8A705DD9BC7F25A166B3
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] tlmi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\tlmi.dll
|_ MD5: A0B188429089D00521E5871A6015C04D
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] tkmi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\tkmi.dll
|_ MD5: 036805EB09F91E2D0323961C2EE92B30
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] sysmgr1.uno.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\sysmgr1.uno.dll
|_ MD5: CAB93284E3C713813BB004102E785673
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] svtmi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\svtmi.dll
|_ MD5: E4C0F406AB4D30ED799CE382FB511A6F
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] svlmi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\svlmi.dll
|_ MD5: 6BA29812A3D05DA4EC2C19ED3E7E7E5A
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] store3.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\URE\bin\store3.dll
|_ MD5: 449830C75FA2C914DDF4EFB2E58F282A
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] stocservices.uno.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\URE\bin\stocservices.uno.dll
|_ MD5: 79C4E71B8FFDB9BBCD216B92C25C7533
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] stlport_vc7145.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\URE\bin\stlport_vc7145.dll
|_ MD5: D3762F465A52A734E1EF5808A9704202
|_ Výrobce: STLport Consulting, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] sotmi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\sotmi.dll
|_ MD5: E0EC047B8B4F661A7F0DEF67990B895B
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] sofficeapp.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\sofficeapp.dll
|_ MD5: 72E642E42F72725EE64BAB0CA1EC0652
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] sfxmi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\sfxmi.dll
|_ MD5: 945A299FFE6002B1F938D4D0F8DF58D0
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] sbmi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\sbmi.dll
|_ MD5: 13512637FF7C2BABF764EA80B8C3F19C
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] saxmi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\saxmi.dll
|_ MD5: 0E5A0A7D6771157DA4B90C115261473F
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] sax.uno.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\sax.uno.dll
|_ MD5: C1DB3670BD0A5C4267348D27DD66B9A3
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] salhelper3msc.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\URE\bin\salhelper3MSC.dll
|_ MD5: 1B9F1AA9D75B085F046A1649AFA781BF
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] sal3.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\URE\bin\sal3.dll
|_ MD5: AA8C288FF07C3C22954E7202C6993C27
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] reg3.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\URE\bin\reg3.dll
|_ MD5: B31F351DAA9146386C10153263BC7857
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] purpenvhelper3msc.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\URE\bin\purpenvhelper3MSC.dll
|_ MD5: D6BC0CDDE784B8B20B7772C968A6DF66
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] oleautobridge.uno.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\oleautobridge.uno.dll
|_ MD5: C31B30CE688870213EF76332617DAE31
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] msci_uno.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\URE\bin\msci_uno.dll
|_ MD5: 5BE669B2A300A153D529E45EFB0F4DA4
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] localebe1.uno.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\localebe1.uno.dll
|_ MD5: C9CD9386DB8706AAE2B9611A9F8C5619
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] libxml2.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\program\libxml2.dll
|_ MD5: 954B86D38F1DCDFE408C51AC0A9596D5
|_ Výrobce:
|_ Procesy
|_ soffice.bin (744)
[?] jvmfwk3.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\URE\bin\jvmfwk3.dll
|_ MD5: D61425AED51238B70B1CBE436286DF4B
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] jvmaccess3msc.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\URE\bin\jvmaccess3MSC.dll
|_ MD5: AE7E9B7515B46FE6BE0E4003A5A522F5
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] jmi_g.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\jmi_g.dll
|_ MD5: ADEAEB78463A74C89A74573EB96188B3
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] icuuc36.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\icuuc36.dll
|_ MD5: 8CB8FC0250C8CF5B45709118A6975C48
|_ Výrobce: IBM Corporation and others
|_ Procesy
|_ soffice.bin (744)
[?] i18nutilmsc.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\i18nutilMSC.dll
|_ MD5: EB45B90AAE08187893805BE9E39BDB41
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] i18nisolang1msc.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\i18nisolang1MSC.dll
|_ MD5: 7EBCB01DEEF7DAD792B08C70A3B8B323
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] fwlmi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\fwlmi.dll
|_ MD5: 392E439F904571BCB8F51624A28370CC
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] fwkmi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\fwkmi.dll
|_ MD5: 115E0059E36D9994E13A1B9CBDDDE82F
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] fwimi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\fwimi.dll
|_ MD5: 899991C8D63BDAD9EBAF2054FD051F09
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] fwemi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\fwemi.dll
|_ MD5: 10C9494FC55CBEFF167A7F3ACED2DD63
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] emsermi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\emsermi.dll
|_ MD5: 5A9F2B5731E5F03D7311E88C80882C7B
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] cppuhelper3msc.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\URE\bin\cppuhelper3MSC.dll
|_ MD5: 9C8C933B27EF926C3F2E1A7F2D6F594B
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] cppu3.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\URE\bin\cppu3.dll
|_ MD5: A1CA217DEACC2CC526FACE232E88900C
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] configmgr2.uno.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\configmgr2.uno.dll
|_ MD5: FE9F113B43AEFFA4F43C9CE45218860F
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] comphelp4msc.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\comphelp4MSC.dll
|_ MD5: EFF715CE04B59F2A6F6F25A148D11494
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] bootstrap.uno.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\URE\bin\bootstrap.uno.dll
|_ MD5: 48FF352083DDE391FCE64D65A31107FD
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] behelper.uno.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\behelper.uno.dll
|_ MD5: 56DCB74B26BEDA7F00EBEAE2DC50C137
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] basegfxmi.dll
|_ Cesta: C:\Program Files\OpenOffice.org 3\Basis\program\basegfxmi.dll
|_ MD5: 4D870DE685AB57C3726A89B5DB88F2A9
|_ Výrobce: Sun Microsystems, Inc.
|_ Procesy
|_ soffice.bin (744)
[?] msvcp71.dll
|_ Cesta: C:\WINDOWS\system32\msvcp71.dll
|_ MD5: 7333E3C6FB7F18E5663B53E1F6DBF4C6
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ soffice.bin (744)
|_ SbPFLnch.exe (828)
|_ SbPFSvc.exe (880)
|_ SbPFCl.exe (580)
[?] sbpfwsc.dll
|_ Cesta: C:\Program Files\Sunbelt Software\Personal Firewall\SbPFWsc.dll
|_ MD5: 78180FEE4510AE88EE558A5D67CA957E
|_ Výrobce: Sunbelt Software, Inc.
|_ Procesy
|_ SbPFSvc.exe (880)
[?] sbfwe.dll
|_ Cesta: C:\Program Files\Sunbelt Software\Personal Firewall\SbFwe.dll
|_ MD5: E58310A15907E796EFBAD656C8AF8FE1
|_ Výrobce: Sunbelt Software, Inc.
|_ Procesy
|_ SbPFSvc.exe (880)
[?] sbfw.dll
|_ Cesta: C:\Program Files\Sunbelt Software\Personal Firewall\SbFw.dll
|_ MD5: FBF764810E93B65F30A9BA35FBAB39DF
|_ Výrobce: Sunbelt Software, Inc.
|_ Procesy
|_ SbPFSvc.exe (880)
[?] sbfwim.dll
|_ Cesta: C:\Program Files\Sunbelt Software\Personal Firewall\SbFwIm.dll
|_ MD5: 749D918F3CF8783BD632ADD82761D0DB
|_ Výrobce: Sunbelt Software, Inc.
|_ Procesy
|_ SbPFSvc.exe (880)
[?] mscomctl.ocx
|_ Cesta: C:\Program Files\Ultimate Process Manager\MSCOMCTL.OCX
|_ MD5: D9578FF8B495DC575E848C6670BE85CC
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ UPM.exe (3012)
Výpis souborů
================================================================
\System32:
[?] ALSNDMGR.CPL 14 no vrfy, {A13440C9}
[?] aswBoot.exe 7 no vrfy, {A54865FB}
[?] AvastSS.scr 14 no vrfy, {80EEA296}
[?] bdco1ins.dll 7 no vrfy, {240E738F}
[?] ChCfg.exe 12 ncmpny, {E0AF3E6B}
[?] D3DCompiler_33.dll D3DCOM~1.DLL 12 ncmpny, {3643F195}
[?] D3DCompiler_34.dll D3DCOM~2.DLL 12 ncmpny, {3D652F77}
[?] d3dx10_33.dll D3DX10~1.DLL 12 ncmpny, {6B35033F}
[?] d3dx10_34.dll D3DX10~2.DLL 12 ncmpny, {D5987E3E}
[?] d3dx9_33.dll 12 ncmpny, {A9975507}
[?] d3dx9_34.dll 12 ncmpny, {D937437C}
[?] deployJava1.dll DEPLOY~1.DLL 14 no vrfy, {46453EA4}
[!] divx.dll 70 no vrfy, infected? {0BD99A36}
[?] ff_vfw.dll 12 ncmpny, {A9D90134}
[?] keystone.exe 12 ncmpny, {FCC0F422}
[?] lameACM.acm 7 no vrfy, {3DB1D192}
[?] LegitCheckControl.dll LEGITC~1.DLL 12 ncmpny, {A3DA1FF7}
[?] MpSigStub.exe MPSIGS~1.EXE 12 ncmpny, {FC80F819}
[?] MRT.exe 25 ncmpny, {267D1720}
[?] msdelta.dll 12 ncmpny, {31109132}
[?] msi.dll 25 ncmpny, {1C4D0C2B}
[?] msihnd.dll 12 ncmpny, {957DFC0F}
[?] msisip.dll 12 ncmpny, {1793D70A}
[?] mssph.dll 12 ncmpny, {1B5B3D66}
[?] msvcp71.dll 12 ncmpny, {E4243F1F}
[?] msvcr71.dll 12 ncmpny, {82C5CE07}
[?] nvappbar.exe 25 ncmpny, {063F9911}
[?] nvcolor.exe 7 no vrfy, {E6D868F7}
[?] nvcpl.cpl 14 no vrfy, {8A58D18C}
[?] nvcplui.exe 7 no vrfy, {D091AEAB}
[?] nvdspsch.exe 25 ncmpny, {7AA319CC}
[?] nvexpbar.dll 7 no vrfy, {98B95497}
[?] nview.dll 12 ncmpny, {5D230EB0}
[?] nvshell.dll 25 ncmpny, {B3D09403}
[?] nvudisp.exe 14 no vrfy, {C4E24DB4}
[?] nvugart.exe 14 no vrfy, {EDFD2A87}
[?] nvunrm.exe 14 no vrfy, {68D51725}
[?] nvusmb.exe 14 no vrfy, {EDFD2A87}
[?] nvwdmcpl.dll 25 ncmpny, {647A9520}
[?] nwiz.exe 25 ncmpny, {B434F7EB}
[?] PnkBstrA.exe 12 ncmpny, {353A540B}
[?] PnkBstrB.exe 12 ncmpny, {540F86EF}
[?] RTLCPL.EXE 14 no vrfy, {C356E656}
[?] spupdsvc.exe 12 ncmpny, {9C3299D3}
[?] x3daudio1_2.dll X3DAUD~3.DLL 12 ncmpny, {527053FD}
[?] xactengine2_7.dll XA3466~1.DLL 12 ncmpny, {E1662632}
[?] xactengine2_8.dll XA3866~1.DLL 12 ncmpny, {158D9824}
[?] xinput1_3.dll XINPUT~4.DLL 12 ncmpny, {F18D8B9B}
\Drivers:
[?] aavmker4.sys 14 no vrfy, {32C4A970}
[?] ALCXWDM.SYS 14 no vrfy, {05F1E0DD}
[?] aswFsBlk.sys 14 no vrfy, {23A34AAC}
[?] aswmon.sys 14 no vrfy, {0F15F888}
[?] aswmon2.sys 14 no vrfy, {4AC4EB8D}
[?] aswRdr.sys 14 no vrfy, {B3E9818F}
[?] aswSP.sys 14 no vrfy, {FB5DF16D}
[?] aswTdi.sys 14 no vrfy, {80D2B6C4}
[?] BIOS.sys 14 no vrfy, {6B4E7158}
[?] GVTDrv.sys 25 ncmpny, {A862445B}
[?] nvp2p.sys 7 no vrfy, {7AE3F622}
[?] PnkBstrK.sys 12 ncmpny, {86CE91C8}
[?] SbFw.sys 14 no vrfy, {82A54725}
[?] sbhips.sys 14 no vrfy, {931B747C}
Access violations - HKCU
================================================================
================================================================
Ultimate Process Manager v4.1.3 - [ Lodus Software ][/code]