Prosím o kontrolu logu
Napsal: 17 úno 2011 14:46
Asi pred polrokom sa mi do počítača dostal istý zákerný vírus, s ktorým sa trápim už celé mesiace. Vyskúšal som už všetky možné antivírusové programy, ale ani jednému z nich sa ho nepodarilo odstrániť. Ako konečné riešenie som si myslel že postačí formát disku a preinštalovanie windows. Vírus sa ale po preinštalovaní okamžite objavil znova a prejavuje sa tým istým spôsobom ako predtým, teda znefunkčnenie určitých programov, samovoľné reštartovanie PC, modrá obrazovka a pod. Pridávam logfile z hijackthis aj z ultimate process manager. Dúfam, že sa mi s vašou pomocou konečne podarí tento vírus odstrániť.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:08:47, on 22. 1. 2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://zoznam.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Milan Hochla\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Port pro program Symantec Fax Starter Edition.lnk = C:\Program Files\Microsoft Office\Office\1029\OLFSNT40.EXE
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
--
End of file - 4440 bytes
Windows XP SP 3 (build 2600)
Boot Mode: Normal
Overení sůborů Microsoftu: Áno
Whitelist: Áno
Internet Explorer v8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Log vygenerovaný:17. 2. 2011 14:25:30
================================================================
SmallARK
================================================================
[R]NtAllocateVirtualMemory -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtClose -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtCreateKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtDeleteKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtDeleteValueKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtDuplicateObject -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtFreeVirtualMemory -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtOpenKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtOpenProcess -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtOpenThread -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtProtectVirtualMemory -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtQueryValueKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtRenameKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtRestoreKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtSetValueKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
Bežiace procesy
================================================================
C:\PROGRAM FILES\ANALOG DEVICES\SOUNDMAX\SMAGENT.EXE
C:\PROGRAM FILES\VERDICT FREE\VERDICT.EXE
Scanner
================================================================
[S] explorer.exe
Spúšťa sa po štarte HKLM Winlogon [Shell]
[?] SMAgent.exe
Nemá okno
Súbor 7%
[R] hkcmd.exe
Spúšťa sa po štarte HKLM Run [HotKeysCmds]
[R] igfxpers.exe
Spúšťa sa po štarte HKLM Run [Persistence]
[R] AvastUI.exe
Spúšťa sa po štarte HKLM Run [avast5]
[S] ctfmon.exe
Spúšťa sa po štarte HKCU Run [ctfmon.exe]
[?] Verdict.exe
Súbor 7%
Po spustení
================================================================
HKCU Run
|_ [R][Google Update] C:\Documents and Settings\Milan Hochla\Local Settings\Application Data\Google\Update\GoogleUpdate.exe /c
HKLM Run
|_ [R][avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe /nogui
HKLM IC
|_ [X][>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP (Súbor nebol nájdený)
|_ [?][{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] C:\WINDOWS\INF\msnetmtg.inf ,NetMtg.Install.PerUser.NT
|_ [?][{5945c046-1e7d-11d1-bc44-00c04fd912be}] C:\WINDOWS\INF\msmsgs.inf ,BLC.QuietInstall.PerUser
|_ [?][{6BF52A52-394A-11d3-B153-00C04F79FAA6}] C:\WINDOWS\INF\wmp.inf ,PerUserStub
|_ [?][{89820200-ECBD-11cf-8B85-00AA005B4340}] regsvr32.exe /s /n /i:U shell32.dll
HKLM BHO
|_ [?][{E7E6F031-17CE-4C07-BC86-EABFE594F69C}] C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
Služby (Zobraz bežiace: True, Zobraz zastavené: False, Zobraz i bezpečné: False)
================================================================
[X] Služba Google Update (gupdate)
|_ Cesta: C:\Program Files\Google\Update\GoogleUpdate.exe /svc
| |_ Výrobca:
| |_ Popis:
| |_ MD5:
|
|_ Meno: gupdate
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Zastavené
|_ Typ: Win32 Own Process
|_ Dependency: RPCSS
[X] Java Quick Starter
|_ Cesta: C:\Program Files\Java\jre6\bin\jqs.exe -service -config C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf
| |_ Výrobca:
| |_ Popis:
| |_ MD5:
|
|_ Meno: JavaQuickStarterService
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Own Process
|_ Dependency:
[?] SoundMAX Agent Service
|_ Cesta: C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
| |_ Výrobca: Analog Devices, Inc.
| |_ Popis: SoundMAX service agent component
| |_ MD5: 3978F082274F723AD5A0A8058C2417DD
|
|_ Meno: SoundMAX Agent Service (default)
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Own Process
|_ Dependency:
Ovládače (Zobraz bežiace: True, Zobraz zastavené: False, Zobraz i bezpečné: False)
================================================================
[?] aeaudio
|_ Cesta: C:\WINDOWS\system32\drivers\aeaudio.sys
| |_ Výrobca: Andrea Electronics Corporation
| |_ Popis: Andrea Audio Noise Cancellation Driver
| |_ MD5: 3CB6AE5435987B1F8C83FD2730479878
|
|_ Meno: aeaudio
|_ StartName:
|_ Typ spúšťania: Ručné spustenie
|_ Status: Spustené
|_ Typ: Kernel Driver
|_ Dependency:
[?] Team MFP Comm Driver
|_ Cesta: C:\WINDOWS\System32\Drivers\DgiVecp.sys
| |_ Výrobca: DeviceGuys, Inc.
| |_ Popis: Windows NT 4.0 IEEE-1284 parallel class driver for ECP, Byte, and Nibble modes
| |_ MD5: A5034F77B278F07E224FE07CF98A8B76
|
|_ Meno: DgiVecp
|_ StartName:
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Kernel Driver
|_ Dependency: +Parallel Arbitrator
[?] smwdm
|_ Cesta: C:\WINDOWS\system32\drivers\smwdm.sys
| |_ Výrobca: Analog Devices, Inc.
| |_ Popis: SoundMAX Integrated Digital Audio
| |_ MD5: 86D17B6760DD2B09E932FF101714E0DC
|
|_ Meno: smwdm
|_ StartName:
|_ Typ spúšťania: Ručné spustenie
|_ Status: Spustené
|_ Typ: Kernel Driver
|_ Dependency:
lNetStat
================================================================
Typ: PID Proces Local <-> Remote Status
----------------------------------------------------------------------------------------
TCP (808) svchost.exe 0.0.0.0:135 LISTENING
TCP (4) Systém 0.0.0.0:445 LISTENING
TCP (2276) alg.exe 127.0.0.1:1028 LISTENING
TCP (3272) chrome.exe 127.0.0.1:1653 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1655 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1678 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1680 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1682 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1689 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1691 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1704 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1706 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1708 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1710 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1712 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1714 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1716 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1717 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1718 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1719 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1724 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1725 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1726 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1727 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1728 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1729 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1736 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1737 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1740 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1741 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1744 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1746 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1747 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1750 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1752 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1754 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1756 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1757 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1758 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1767 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1769 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1771 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1774 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1776 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1777 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1778 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1779 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1780 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1786 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1787 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1788 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1789 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1797 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1798 <-> 127.0.0.1:12080 ESTABLISHED
TCP (916) jqs.exe 127.0.0.1:5152 LISTENING
TCP (1120) AvastSvc.exe 127.0.0.1:12025 LISTENING
TCP (1120) AvastSvc.exe 127.0.0.1:12080 LISTENING
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1653 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1655 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1678 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1680 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1682 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1689 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1691 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1704 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1706 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1708 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1710 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1712 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1714 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1716 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1717 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1718 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1719 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1724 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1725 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1726 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1727 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1728 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1729 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1736 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1737 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1740 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1741 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1744 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1746 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1747 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1750 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1752 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1754 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1756 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1757 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1758 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1767 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1769 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1771 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1774 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1776 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1777 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1778 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1779 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1780 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1786 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1787 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1788 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1789 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1797 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1798 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12110 LISTENING
TCP (1120) AvastSvc.exe 127.0.0.1:12119 LISTENING
TCP (1120) AvastSvc.exe 127.0.0.1:12143 LISTENING
TCP (1120) AvastSvc.exe 127.0.0.1:12465 LISTENING
TCP (1120) AvastSvc.exe 127.0.0.1:12563 LISTENING
TCP (1120) AvastSvc.exe 127.0.0.1:12993 LISTENING
TCP (1120) AvastSvc.exe 127.0.0.1:12995 LISTENING
TCP (4) Systém 192.168.1.2:139 LISTENING
TCP (1828) UPM.exe 192.168.1.2:1620 CLOSE_WAIT
TCP (3480) UPM.exe 192.168.1.2:1624 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1654 <-> 74.125.87.99:80 ESTABLISHED
TCP (1120) AvastSvc.exe 192.168.1.2:1665 <-> 74.125.43.100:80 ESTABLISHED
TCP (1120) AvastSvc.exe 192.168.1.2:1679 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1681 <-> 74.125.87.155:80 ESTABLISHED
TCP (1120) AvastSvc.exe 192.168.1.2:1683 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1693 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1695 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1705 <-> 212.247.20.9:80 ESTABLISHED
TCP (1120) AvastSvc.exe 192.168.1.2:1707 <-> 74.125.43.101:80 ESTABLISHED
TCP (1120) AvastSvc.exe 192.168.1.2:1738 <-> 8.10.179.165:80 ESTABLISHED
TCP (1120) AvastSvc.exe 192.168.1.2:1739 <-> 8.10.179.165:80 ESTABLISHED
TCP (1120) AvastSvc.exe 192.168.1.2:1745 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1748 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1749 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1751 <-> 74.125.43.101:80 ESTABLISHED
TCP (1120) AvastSvc.exe 192.168.1.2:1753 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1755 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1759 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1760 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1761 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1768 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1770 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1772 <-> 74.125.43.113:80 ESTABLISHED
TCP (1120) AvastSvc.exe 192.168.1.2:1775 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1781 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1782 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1783 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1784 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1785 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1799 <-> 66.220.158.18:80 ESTABLISHED
TCP (1120) AvastSvc.exe 192.168.1.2:1800 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1801 <-> 212.247.20.8:80 ESTABLISHED
TCP (1120) AvastSvc.exe 192.168.1.2:1802 <-> 212.247.20.8:80 ESTABLISHED
TCP (1120) AvastSvc.exe 192.168.1.2:1803 <-> 212.247.20.10:80 ESTABLISHED
UDP (4) Systém 0.0.0.0:445 <-> 212.247.20.10:80 ESTABLISHED
UDP (592) lsass.exe 0.0.0.0:500
UDP (592) lsass.exe 0.0.0.0:4500
UDP (876) svchost.exe 127.0.0.1:123
UDP (1004) svchost.exe 127.0.0.1:1900
UDP (876) svchost.exe 192.168.1.2:123
UDP (4) Systém 192.168.1.2:137
UDP (4) Systém 192.168.1.2:138
UDP (1004) svchost.exe 192.168.1.2:1900
Moduly (Zobraz i bezpečné: False, Len bez výrobcu: True, Zobraz registrované: False)
================================================================
[?] syncor11.dll
|_ Cesta: C:\WINDOWS\system32\Syncor11.dll
|_ MD5: BD9B4450D00D4AC891407B8C0E08DE9C
|_ Výrobca: SoundMAX
|_ Procesy
|_ winlogon.exe (536)
|_ lsass.exe (592)
|_ svchost.exe (760)
|_ svchost.exe (808)
|_ svchost.exe (876)
|_ svchost.exe (944)
|_ svchost.exe (1004)
|_ explorer.exe (1364)
|_ spoolsv.exe (1732)
|_ svchost.exe (500)
|_ svchost.exe (1880)
|_ alg.exe (2276)
|_ AvastUI.exe (2932)
|_ ctfmon.exe (2952)
|_ chrome.exe (3272)
|_ chrome.exe (3764)
|_ chrome.exe (3784)
|_ FOXITR~1.EXE (4012)
|_ chrome.exe (196)
|_ chrome.exe (2820)
|_ notepad.exe (2968)
|_ chrome.exe (3232)
|_ UPM.exe (1828)
|_ UPM.exe (3480)
[?] olfmnt40.dll
|_ Cesta: C:\WINDOWS\system32\OLFMNT40.DLL
|_ MD5: D244388C9F0B6360D59B52978B4E2044
|_ Výrobca: Microsoft Corporation
|_ Procesy
|_ spoolsv.exe (1732)
[?] igfxsrvc.dll
|_ Cesta: C:\WINDOWS\system32\igfxsrvc.dll
|_ MD5: 09A350F25D94D18190A8988E25671844
|_ Výrobca: Intel Corporation
|_ Procesy
|_ hkcmd.exe (2908)
|_ igfxpers.exe (2916)
[?] igfxres.dll
|_ Cesta: C:\WINDOWS\system32\igfxres.dll
|_ MD5: DDB76A587FE7B3588E8C480F01B7CAA8
|_ Výrobca: Intel Corporation
|_ Procesy
|_ hkcmd.exe (2908)
[?] hccutils.dll
|_ Cesta: C:\WINDOWS\system32\hccutils.dll
|_ MD5: D0127023AF6070D5B479B1AE65B107A2
|_ Výrobca: Intel Corporation
|_ Procesy
|_ hkcmd.exe (2908)
[?] gcswf32.dll
|_ Cesta: C:\Documents and Settings\Milan Hochla\Local Settings\Application Data\Google\Chrome\Application\9.0.597.98\gcswf32.dll
|_ MD5: AD227F006BE746A054826DA712E4A658
|_ Výrobca: ?
|_ Procesy
|_ chrome.exe (196)
================================================================
Ultimate Process Manager v4.1.3 - [ Lodus Software ] - Not Registered =(
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:08:47, on 22. 1. 2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://zoznam.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Milan Hochla\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Port pro program Symantec Fax Starter Edition.lnk = C:\Program Files\Microsoft Office\Office\1029\OLFSNT40.EXE
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
--
End of file - 4440 bytes
Windows XP SP 3 (build 2600)
Boot Mode: Normal
Overení sůborů Microsoftu: Áno
Whitelist: Áno
Internet Explorer v8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Log vygenerovaný:17. 2. 2011 14:25:30
================================================================
SmallARK
================================================================
[R]NtAllocateVirtualMemory -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtClose -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtCreateKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtDeleteKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtDeleteValueKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtDuplicateObject -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtFreeVirtualMemory -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtOpenKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtOpenProcess -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtOpenThread -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtProtectVirtualMemory -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtQueryValueKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtRenameKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtRestoreKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
[R]NtSetValueKey -> C:\WINDOWS\system32\drivers\aswSP.SYS
Bežiace procesy
================================================================
C:\PROGRAM FILES\ANALOG DEVICES\SOUNDMAX\SMAGENT.EXE
C:\PROGRAM FILES\VERDICT FREE\VERDICT.EXE
Scanner
================================================================
[S] explorer.exe
Spúšťa sa po štarte HKLM Winlogon [Shell]
[?] SMAgent.exe
Nemá okno
Súbor 7%
[R] hkcmd.exe
Spúšťa sa po štarte HKLM Run [HotKeysCmds]
[R] igfxpers.exe
Spúšťa sa po štarte HKLM Run [Persistence]
[R] AvastUI.exe
Spúšťa sa po štarte HKLM Run [avast5]
[S] ctfmon.exe
Spúšťa sa po štarte HKCU Run [ctfmon.exe]
[?] Verdict.exe
Súbor 7%
Po spustení
================================================================
HKCU Run
|_ [R][Google Update] C:\Documents and Settings\Milan Hochla\Local Settings\Application Data\Google\Update\GoogleUpdate.exe /c
HKLM Run
|_ [R][avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe /nogui
HKLM IC
|_ [X][>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP (Súbor nebol nájdený)
|_ [?][{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] C:\WINDOWS\INF\msnetmtg.inf ,NetMtg.Install.PerUser.NT
|_ [?][{5945c046-1e7d-11d1-bc44-00c04fd912be}] C:\WINDOWS\INF\msmsgs.inf ,BLC.QuietInstall.PerUser
|_ [?][{6BF52A52-394A-11d3-B153-00C04F79FAA6}] C:\WINDOWS\INF\wmp.inf ,PerUserStub
|_ [?][{89820200-ECBD-11cf-8B85-00AA005B4340}] regsvr32.exe /s /n /i:U shell32.dll
HKLM BHO
|_ [?][{E7E6F031-17CE-4C07-BC86-EABFE594F69C}] C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
Služby (Zobraz bežiace: True, Zobraz zastavené: False, Zobraz i bezpečné: False)
================================================================
[X] Služba Google Update (gupdate)
|_ Cesta: C:\Program Files\Google\Update\GoogleUpdate.exe /svc
| |_ Výrobca:
| |_ Popis:
| |_ MD5:
|
|_ Meno: gupdate
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Zastavené
|_ Typ: Win32 Own Process
|_ Dependency: RPCSS
[X] Java Quick Starter
|_ Cesta: C:\Program Files\Java\jre6\bin\jqs.exe -service -config C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf
| |_ Výrobca:
| |_ Popis:
| |_ MD5:
|
|_ Meno: JavaQuickStarterService
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Own Process
|_ Dependency:
[?] SoundMAX Agent Service
|_ Cesta: C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
| |_ Výrobca: Analog Devices, Inc.
| |_ Popis: SoundMAX service agent component
| |_ MD5: 3978F082274F723AD5A0A8058C2417DD
|
|_ Meno: SoundMAX Agent Service (default)
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Own Process
|_ Dependency:
Ovládače (Zobraz bežiace: True, Zobraz zastavené: False, Zobraz i bezpečné: False)
================================================================
[?] aeaudio
|_ Cesta: C:\WINDOWS\system32\drivers\aeaudio.sys
| |_ Výrobca: Andrea Electronics Corporation
| |_ Popis: Andrea Audio Noise Cancellation Driver
| |_ MD5: 3CB6AE5435987B1F8C83FD2730479878
|
|_ Meno: aeaudio
|_ StartName:
|_ Typ spúšťania: Ručné spustenie
|_ Status: Spustené
|_ Typ: Kernel Driver
|_ Dependency:
[?] Team MFP Comm Driver
|_ Cesta: C:\WINDOWS\System32\Drivers\DgiVecp.sys
| |_ Výrobca: DeviceGuys, Inc.
| |_ Popis: Windows NT 4.0 IEEE-1284 parallel class driver for ECP, Byte, and Nibble modes
| |_ MD5: A5034F77B278F07E224FE07CF98A8B76
|
|_ Meno: DgiVecp
|_ StartName:
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Kernel Driver
|_ Dependency: +Parallel Arbitrator
[?] smwdm
|_ Cesta: C:\WINDOWS\system32\drivers\smwdm.sys
| |_ Výrobca: Analog Devices, Inc.
| |_ Popis: SoundMAX Integrated Digital Audio
| |_ MD5: 86D17B6760DD2B09E932FF101714E0DC
|
|_ Meno: smwdm
|_ StartName:
|_ Typ spúšťania: Ručné spustenie
|_ Status: Spustené
|_ Typ: Kernel Driver
|_ Dependency:
lNetStat
================================================================
Typ: PID Proces Local <-> Remote Status
----------------------------------------------------------------------------------------
TCP (808) svchost.exe 0.0.0.0:135 LISTENING
TCP (4) Systém 0.0.0.0:445 LISTENING
TCP (2276) alg.exe 127.0.0.1:1028 LISTENING
TCP (3272) chrome.exe 127.0.0.1:1653 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1655 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1678 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1680 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1682 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1689 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1691 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1704 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1706 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1708 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1710 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1712 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1714 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1716 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1717 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1718 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1719 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1724 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1725 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1726 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1727 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1728 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1729 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1736 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1737 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1740 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1741 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1744 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1746 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1747 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1750 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1752 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1754 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1756 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1757 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1758 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1767 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1769 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1771 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1774 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1776 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1777 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1778 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1779 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1780 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1786 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1787 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1788 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1789 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1797 <-> 127.0.0.1:12080 ESTABLISHED
TCP (3272) chrome.exe 127.0.0.1:1798 <-> 127.0.0.1:12080 ESTABLISHED
TCP (916) jqs.exe 127.0.0.1:5152 LISTENING
TCP (1120) AvastSvc.exe 127.0.0.1:12025 LISTENING
TCP (1120) AvastSvc.exe 127.0.0.1:12080 LISTENING
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1653 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1655 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1678 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1680 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1682 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1689 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1691 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1704 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1706 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1708 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1710 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1712 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1714 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1716 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1717 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1718 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1719 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1724 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1725 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1726 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1727 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1728 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1729 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1736 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1737 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1740 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1741 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1744 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1746 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1747 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1750 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1752 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1754 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1756 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1757 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1758 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1767 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1769 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1771 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1774 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1776 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1777 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1778 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1779 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1780 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1786 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1787 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1788 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1789 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1797 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12080 <-> 127.0.0.1:1798 ESTABLISHED
TCP (1120) AvastSvc.exe 127.0.0.1:12110 LISTENING
TCP (1120) AvastSvc.exe 127.0.0.1:12119 LISTENING
TCP (1120) AvastSvc.exe 127.0.0.1:12143 LISTENING
TCP (1120) AvastSvc.exe 127.0.0.1:12465 LISTENING
TCP (1120) AvastSvc.exe 127.0.0.1:12563 LISTENING
TCP (1120) AvastSvc.exe 127.0.0.1:12993 LISTENING
TCP (1120) AvastSvc.exe 127.0.0.1:12995 LISTENING
TCP (4) Systém 192.168.1.2:139 LISTENING
TCP (1828) UPM.exe 192.168.1.2:1620 CLOSE_WAIT
TCP (3480) UPM.exe 192.168.1.2:1624 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1654 <-> 74.125.87.99:80 ESTABLISHED
TCP (1120) AvastSvc.exe 192.168.1.2:1665 <-> 74.125.43.100:80 ESTABLISHED
TCP (1120) AvastSvc.exe 192.168.1.2:1679 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1681 <-> 74.125.87.155:80 ESTABLISHED
TCP (1120) AvastSvc.exe 192.168.1.2:1683 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1693 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1695 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1705 <-> 212.247.20.9:80 ESTABLISHED
TCP (1120) AvastSvc.exe 192.168.1.2:1707 <-> 74.125.43.101:80 ESTABLISHED
TCP (1120) AvastSvc.exe 192.168.1.2:1738 <-> 8.10.179.165:80 ESTABLISHED
TCP (1120) AvastSvc.exe 192.168.1.2:1739 <-> 8.10.179.165:80 ESTABLISHED
TCP (1120) AvastSvc.exe 192.168.1.2:1745 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1748 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1749 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1751 <-> 74.125.43.101:80 ESTABLISHED
TCP (1120) AvastSvc.exe 192.168.1.2:1753 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1755 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1759 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1760 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1761 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1768 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1770 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1772 <-> 74.125.43.113:80 ESTABLISHED
TCP (1120) AvastSvc.exe 192.168.1.2:1775 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1781 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1782 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1783 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1784 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1785 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1799 <-> 66.220.158.18:80 ESTABLISHED
TCP (1120) AvastSvc.exe 192.168.1.2:1800 CLOSE_WAIT
TCP (1120) AvastSvc.exe 192.168.1.2:1801 <-> 212.247.20.8:80 ESTABLISHED
TCP (1120) AvastSvc.exe 192.168.1.2:1802 <-> 212.247.20.8:80 ESTABLISHED
TCP (1120) AvastSvc.exe 192.168.1.2:1803 <-> 212.247.20.10:80 ESTABLISHED
UDP (4) Systém 0.0.0.0:445 <-> 212.247.20.10:80 ESTABLISHED
UDP (592) lsass.exe 0.0.0.0:500
UDP (592) lsass.exe 0.0.0.0:4500
UDP (876) svchost.exe 127.0.0.1:123
UDP (1004) svchost.exe 127.0.0.1:1900
UDP (876) svchost.exe 192.168.1.2:123
UDP (4) Systém 192.168.1.2:137
UDP (4) Systém 192.168.1.2:138
UDP (1004) svchost.exe 192.168.1.2:1900
Moduly (Zobraz i bezpečné: False, Len bez výrobcu: True, Zobraz registrované: False)
================================================================
[?] syncor11.dll
|_ Cesta: C:\WINDOWS\system32\Syncor11.dll
|_ MD5: BD9B4450D00D4AC891407B8C0E08DE9C
|_ Výrobca: SoundMAX
|_ Procesy
|_ winlogon.exe (536)
|_ lsass.exe (592)
|_ svchost.exe (760)
|_ svchost.exe (808)
|_ svchost.exe (876)
|_ svchost.exe (944)
|_ svchost.exe (1004)
|_ explorer.exe (1364)
|_ spoolsv.exe (1732)
|_ svchost.exe (500)
|_ svchost.exe (1880)
|_ alg.exe (2276)
|_ AvastUI.exe (2932)
|_ ctfmon.exe (2952)
|_ chrome.exe (3272)
|_ chrome.exe (3764)
|_ chrome.exe (3784)
|_ FOXITR~1.EXE (4012)
|_ chrome.exe (196)
|_ chrome.exe (2820)
|_ notepad.exe (2968)
|_ chrome.exe (3232)
|_ UPM.exe (1828)
|_ UPM.exe (3480)
[?] olfmnt40.dll
|_ Cesta: C:\WINDOWS\system32\OLFMNT40.DLL
|_ MD5: D244388C9F0B6360D59B52978B4E2044
|_ Výrobca: Microsoft Corporation
|_ Procesy
|_ spoolsv.exe (1732)
[?] igfxsrvc.dll
|_ Cesta: C:\WINDOWS\system32\igfxsrvc.dll
|_ MD5: 09A350F25D94D18190A8988E25671844
|_ Výrobca: Intel Corporation
|_ Procesy
|_ hkcmd.exe (2908)
|_ igfxpers.exe (2916)
[?] igfxres.dll
|_ Cesta: C:\WINDOWS\system32\igfxres.dll
|_ MD5: DDB76A587FE7B3588E8C480F01B7CAA8
|_ Výrobca: Intel Corporation
|_ Procesy
|_ hkcmd.exe (2908)
[?] hccutils.dll
|_ Cesta: C:\WINDOWS\system32\hccutils.dll
|_ MD5: D0127023AF6070D5B479B1AE65B107A2
|_ Výrobca: Intel Corporation
|_ Procesy
|_ hkcmd.exe (2908)
[?] gcswf32.dll
|_ Cesta: C:\Documents and Settings\Milan Hochla\Local Settings\Application Data\Google\Chrome\Application\9.0.597.98\gcswf32.dll
|_ MD5: AD227F006BE746A054826DA712E4A658
|_ Výrobca: ?
|_ Procesy
|_ chrome.exe (196)
================================================================
Ultimate Process Manager v4.1.3 - [ Lodus Software ] - Not Registered =(