Prosím o kontrolu logu
Napsal: 04 dub 2011 19:03
Prosím o kontrolu logu.je tam někde trojan Generic2_c.KLQ a nejde ven.Dik
Windows XP SP 3 (build 2600)
Boot Mode: Normal
Ověření souborů Microsoftu: Ano
Whitelist: Ano
Internet Explorer v8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Log vygenerován: 4.4.2011 19:53:03
================================================================
SmallARK
================================================================
[?]NtClose -> C:\WINDOWS\system32\drivers\a347bus.sys
[?]NtCreateKey -> C:\WINDOWS\system32\drivers\a347bus.sys
[?]NtCreatePagingFile -> C:\WINDOWS\system32\drivers\a347bus.sys
[?]NtEnumerateKey -> C:\WINDOWS\system32\drivers\a347bus.sys
[?]NtEnumerateValueKey -> C:\WINDOWS\system32\drivers\a347bus.sys
[?]NtOpenFile -> C:\WINDOWS\system32\drivers\a347bus.sys
[?]NtOpenKey -> C:\WINDOWS\system32\drivers\a347bus.sys
[R]NtOpenProcess -> C:\WINDOWS\system32\drivers\AVGIDSShim.Sys
[?]NtQueryKey -> C:\WINDOWS\system32\drivers\a347bus.sys
[?]NtQueryValueKey -> C:\WINDOWS\system32\drivers\a347bus.sys
[?]NtSetSystemPowerState -> C:\WINDOWS\system32\drivers\a347bus.sys
[R]NtTerminateProcess -> C:\WINDOWS\system32\drivers\AVGIDSShim.Sys
[R]NtTerminateThread -> C:\WINDOWS\system32\drivers\AVGIDSShim.Sys
[R]NtWriteVirtualMemory -> C:\WINDOWS\system32\drivers\AVGIDSShim.Sys
Běžící procesy
================================================================
C:\PROGRAM FILES\NEC ELECTRONICS\USB 3.0 HOST CONTROLLER DRIVER\APPLICATION\NUSB3MON.EXE
C:\PROGRAM FILES\WINAMP\WINAMPA.EXE
C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQSTE08.EXE
C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQBAM08.EXE
C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQGPC01.EXE
C:\PROGRAM FILES\NEC ELECTRONICS\USB 3.0 HOST CONTROLLER DRIVER\APPLICATION\NUSB3MON.EXE
C:\PROGRAM FILES\WINAMP\WINAMPA.EXE
C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQSTE08.EXE
C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQBAM08.EXE
C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQGPC01.EXE
Scanner
================================================================
[S] explorer.exe
Spouští se po startu HKLM Winlogon [Shell]
[R] jusched.exe
Spouští se po startu HKLM Run [SunJavaUpdateSched]
[R] HDeck.exe
Spouští se po startu HKLM Run [HDAudDeck]
[R] FourEngine.exe
Spouští se po startu HKLM Run [Six Engine]
[R] BCU.exe
Spouští se po startu HKLM Run [BCU]
[?] nusb3mon.exe
Spouští se po startu HKLM Run [NUSB3MON]
Soubor 7%
[S] rundll32.exe
Spouští se po startu HKLM Run [NvMediaCenter]
[R] GrooveMonitor.exe
Ověřený Microsoft: Ne
Spouští se po startu HKLM Run [GrooveMonitor]
[R] avgtray.exe
Spouští se po startu HKLM Run [AVG_TRAY]
[?] winampa.exe
Spouští se po startu HKLM Run [WinampAgent]
Soubor 14%
[R] hpwuSchd2.exe
Spouští se po startu HKLM Run [HP Software Update]
[R] AdobeARM.exe
Spouští se po startu HKLM Run [Adobe ARM]
[S] ctfmon.exe
Spouští se po startu HKCU Run [CTFMON.EXE]
[R] hpqtra08.exe
Spouští se po startu Po spuštění []
[?] hpqste08.exe
Soubor 7%
[?] hpqbam08.exe
Soubor 14%
[?] hpqgpc01.exe
Soubor 7%
[S] explorer.exe
Spouští se po startu HKLM Winlogon [Shell]
[R] jusched.exe
Spouští se po startu HKLM Run [SunJavaUpdateSched]
[R] HDeck.exe
Spouští se po startu HKLM Run [HDAudDeck]
[R] FourEngine.exe
Spouští se po startu HKLM Run [Six Engine]
[R] BCU.exe
Spouští se po startu HKLM Run [BCU]
[?] nusb3mon.exe
Spouští se po startu HKLM Run [NUSB3MON]
Nemá okno
Soubor 7%
[S] rundll32.exe
Spouští se po startu HKLM Run [NvMediaCenter]
[R] GrooveMonitor.exe
Ověřený Microsoft: Ne
Spouští se po startu HKLM Run [GrooveMonitor]
[R] avgtray.exe
Spouští se po startu HKLM Run [AVG_TRAY]
[?] winampa.exe
Spouští se po startu HKLM Run [WinampAgent]
Nemá okno
Soubor 14%
[R] hpwuSchd2.exe
Spouští se po startu HKLM Run [HP Software Update]
[S] ctfmon.exe
Spouští se po startu HKCU Run [CTFMON.EXE]
[R] Skype.exe
Podvržená cesta modulu: (00400000) C:\Program Files\Skype\Phone\Skype.exe
[R] hpqtra08.exe
Spouští se po startu Po spuštění []
[?] hpqste08.exe
Nemá okno
Soubor 7%
[?] hpqbam08.exe
Nemá okno
Soubor 14%
[?] hpqgpc01.exe
Nemá okno
Soubor 7%
[R] mscorsvw.exe
Ověřený Microsoft: Ne
Po spuštění
================================================================
HKLM Run
|_ [R][HDAudDeck] C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
|_ [R][Six Engine] C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe -b
|_ [?][NUSB3MON] C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
|_ [?][WinampAgent] C:\Program Files\Winamp\winampa.exe
|_ [R][NvMediaCenter] C:\WINDOWS\system32\NvMcTray.dll ,NvTaskbarInit
|_ [R][NvCplDaemon] C:\WINDOWS\system32\NvCpl.dll ,NvStartup
|_ [R][nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
|_ [R][DWQueuedReporting] C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe -t
HKLM IC
|_ [X][>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] RunDLL32 IEDKCS32.DLL,BrandIEActiveSetup SIGNUP (Soubor nenalezen)
|_ [?][>{99820200-ECBD-11cf-8B85-00AA005B4340}] regsvr32.exe /s /n /i:U shell32.dll
|_ [?][{6BF52A52-394A-11d3-B153-00C04F79FAA6}] C:\WINDOWS\INF\wmp.inf ,PerUserStub
|_ [?][{89820200-ECBD-11cf-8B85-00AA005B4340}] regsvr32.exe /s /n /i:U shell32.dll
HKLM BHO
|_ [?][{E7E6F031-17CE-4C07-BC86-EABFE594F69C}] C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
Služby (Zobraz běžící: True, Zobraz zastavené: False, Zobraz i bezpečné služby: False)
================================================================
[?] hpqcxs08
|_ Cesta: C:\WINDOWS\system32\svchost.exe
| |_ Výrobce: Microsoft Corporation
| |_ Popis: Generic Host Process for Win32 Services
| |_ MD5: BE4A520E29B6391F49E79CCC52044D93
|
|_ ServiceDLL: C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll
| |_ Výrobce: Hewlett-Packard Co.
| |_ Popis: HP CUE Context Manager Objects
| |_ MD5: 0A3C6AA4A9FC38C20BA4EAC2C3351C05
|
|_ Jméno: hpqcxs08
|_ StartName: LocalSystem
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Win32 Share Process
|_ Dependency: RPCSS
[?] Služba HP CUE DeviceDiscovery
|_ Cesta: C:\WINDOWS\system32\svchost.exe
| |_ Výrobce: Microsoft Corporation
| |_ Popis: Generic Host Process for Win32 Services
| |_ MD5: BE4A520E29B6391F49E79CCC52044D93
|
|_ ServiceDLL: C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll
| |_ Výrobce: Hewlett-Packard Co.
| |_ Popis: HP CUE DeviceDiscovery Service
| |_ MD5: F3F72A2A86C22610BCA5439FA789DD52
|
|_ Jméno: hpqddsvc
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Share Process
|_ Dependency: RPCSS
[?] HP Network Devices Support
|_ Cesta: C:\WINDOWS\system32\svchost.exe
| |_ Výrobce: Microsoft Corporation
| |_ Popis: Generic Host Process for Win32 Services
| |_ MD5: BE4A520E29B6391F49E79CCC52044D93
|
|_ ServiceDLL: C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL
| |_ Výrobce: Hewlett-Packard Co.
| |_ Popis: HP Network Devices Support
| |_ MD5: 79737E0F7D25DE8405CB34D4C9882253
|
|_ Jméno: HPSLPSVC
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ:
|_ Dependency: RPCSS
[?] Net Driver HPZ12
|_ Cesta: C:\WINDOWS\System32\svchost.exe
| |_ Výrobce: Microsoft Corporation
| |_ Popis: Generic Host Process for Win32 Services
| |_ MD5: BE4A520E29B6391F49E79CCC52044D93
|
|_ ServiceDLL: C:\WINDOWS\system32\HPZinw12.dll
| |_ Výrobce: Hewlett-Packard
| |_ Popis: Dot4Net Module
| |_ MD5: 510C138564486FF926A3F773205C63D1
|
|_ Jméno: Net Driver HPZ12
|_ StartName: NT AUTHORITY\LocalService
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Own Process
|_ Dependency:
[?] Pml Driver HPZ12
|_ Cesta: C:\WINDOWS\System32\svchost.exe
| |_ Výrobce: Microsoft Corporation
| |_ Popis: Generic Host Process for Win32 Services
| |_ MD5: BE4A520E29B6391F49E79CCC52044D93
|
|_ ServiceDLL: C:\WINDOWS\system32\HPZipm12.dll
| |_ Výrobce: Hewlett-Packard
| |_ Popis: PmlDrv Module
| |_ MD5: 37E5E8FFBAD35605DAEEC3224EA0E465
|
|_ Jméno: Pml Driver HPZ12
|_ StartName: NT AUTHORITY\LocalService
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Own Process
|_ Dependency:
[R] TuneUp Theme Extension
|_ Cesta: C:\WINDOWS\System32\svchost.exe
| |_ Výrobce: Microsoft Corporation
| |_ Popis: Generic Host Process for Win32 Services
| |_ MD5: BE4A520E29B6391F49E79CCC52044D93
|
|_ ServiceDLL: C:\WINDOWS\System32\uxtuneup.dll
| |_ Výrobce: TuneUp Software
| |_ Popis: TuneUp Theme Extension
| |_ MD5: 3A335BB79F9D93F1D33CA07F8986E004
|
|_ Jméno: UxTuneUp
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Share Process
|_ Dependency: Themes
Ovladače (Zobraz běžící: True, Zobraz zastavené: False, Zobraz i bezpečné služby: False)
================================================================
[?] a347bus
|_ Cesta: C:\WINDOWS\system32\DRIVERS\a347bus.sys
| |_ Výrobce:
| |_ Popis: Plug and Play BIOS Extension
| |_ MD5: 1F61CACACB521215F39061789147968C
|
|_ Jméno: a347bus
|_ StartName:
|_ Typ spouštění: Boot Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] a347scsi
|_ Cesta: C:\WINDOWS\System32\Drivers\a347scsi.sys
| |_ Výrobce:
| |_ Popis: SCSI miniport
| |_ MD5: 113E4B318BBAA7483CA4E582A4D63F49
|
|_ Jméno: a347scsi
|_ StartName:
|_ Typ spouštění: Boot Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Ovladač procesoru HwPState AMD
|_ Cesta: C:\WINDOWS\system32\DRIVERS\AmdPPM.sys
| |_ Výrobce: Advanced Micro Devices
| |_ Popis: AMD Processor Driver
| |_ MD5: 033448D435E65C4BD72E70521FD05C76
|
|_ Jméno: AmdPPM
|_ StartName:
|_ Typ spouštění: System Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Standardní řadič disku IDE/ESDI
|_ Cesta: C:\WINDOWS\system32\DRIVERS\atapi.sys
| |_ Výrobce:
| |_ Popis:
| |_ MD5:
|
|_ Jméno: atapi
|_ StartName:
|_ Typ spouštění: Boot Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] NEC Electronics USB 3.0 Hub Driver
|_ Cesta: C:\WINDOWS\system32\DRIVERS\nusb3hub.sys
| |_ Výrobce: NEC Electronics Corporation
| |_ Popis: USB 3.0 Hub Driver
| |_ MD5: 9A3879B890F395EF8007A69543B56E8D
|
|_ Jméno: nusb3hub
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] NEC Electronics USB 3.0 Host Controller Driver
|_ Cesta: C:\WINDOWS\system32\DRIVERS\nusb3xhc.sys
| |_ Výrobce: NEC Electronics Corporation
| |_ Popis: USB 3.0 Host Controller Driver
| |_ MD5: 61C3A3C6B35F596831358D954D20712F
|
|_ Jméno: nusb3xhc
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] nv
|_ Cesta: C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
| |_ Výrobce: NVIDIA Corporation
| |_ Popis: NVIDIA Compatible Windows 2000 Miniport Driver, Version 266.58
| |_ MD5: 18C9B152DA7BEA76B2F9E4B6412E0AAF
|
|_ Jméno: nv
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver
|_ Cesta: C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
| |_ Výrobce: Realtek Semiconductor Corporation
| |_ Popis: Realtek 10/100/1000 NDIS 5.1 Driver
| |_ MD5: CB9310A5A910648D359C99A857E22A54
|
|_ Jméno: RTLE8023xp
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
lNetStat
================================================================
Typ: PID Proces Local <-> Remote Status
-----------------------------------------------------------------------------------------
TCP (2008) svchost.exe 0.0.0.0:135 LISTENING
TCP (4) Systém 0.0.0.0:445 LISTENING
TCP (3272) alg.exe 127.0.0.1:1030 LISTENING
TCP (664) firefox.exe 127.0.0.1:3193 <-> 127.0.0.1:3194 ESTABLISHED
TCP (664) firefox.exe 127.0.0.1:3194 <-> 127.0.0.1:3193 ESTABLISHED
TCP (664) firefox.exe 127.0.0.1:3195 <-> 127.0.0.1:3196 ESTABLISHED
TCP (664) firefox.exe 127.0.0.1:3196 <-> 127.0.0.1:3195 ESTABLISHED
TCP (0) 127.0.0.1:3408 TIME_WAIT
TCP (0) 127.0.0.1:3409 TIME_WAIT
TCP (2336) firefox.exe 127.0.0.1:3410 <-> 127.0.0.1:3411 ESTABLISHED
TCP (2336) firefox.exe 127.0.0.1:3411 <-> 127.0.0.1:3410 ESTABLISHED
TCP (2336) firefox.exe 127.0.0.1:3416 <-> 127.0.0.1:3417 ESTABLISHED
TCP (2336) firefox.exe 127.0.0.1:3417 <-> 127.0.0.1:3416 ESTABLISHED
TCP (4) Systém 192.168.1.2:139 LISTENING
TCP (5392) jucheck.exe 192.168.1.2:1235 CLOSE_WAIT
TCP (3432) jucheck.exe 192.168.1.2:1371 CLOSE_WAIT
TCP (2288) opera.exe 192.168.1.2:2878 <-> 95.168.207.36:80 ESTABLISHED
TCP (2336) firefox.exe 192.168.1.2:3414 <-> 74.125.43.105:80 ESTABLISHED
TCP (2336) firefox.exe 192.168.1.2:3418 <-> 74.125.43.147:80 ESTABLISHED
TCP (2336) firefox.exe 192.168.1.2:3419 <-> 74.125.43.103:80 ESTABLISHED
TCP (2336) firefox.exe 192.168.1.2:3420 <-> 74.125.43.103:80 ESTABLISHED
TCP (2336) firefox.exe 192.168.1.2:3421 <-> 74.125.43.190:443 ESTABLISHED
TCP (0) 192.168.1.2:3422 TIME_WAIT
TCP (2336) firefox.exe 192.168.1.2:3432 <-> 74.125.43.113:80 ESTABLISHED
TCP (2336) firefox.exe 192.168.1.2:3434 <-> 74.125.43.91:443 ESTABLISHED
TCP (2336) firefox.exe 192.168.1.2:3437 <-> 74.125.43.91:443 ESTABLISHED
TCP (2336) firefox.exe 192.168.1.2:3438 <-> 74.125.43.91:443 ESTABLISHED
TCP (2336) firefox.exe 192.168.1.2:3439 <-> 74.125.43.132:443 ESTABLISHED
TCP (2336) firefox.exe 192.168.1.2:3440 <-> 74.125.43.132:443 ESTABLISHED
TCP (2336) firefox.exe 192.168.1.2:3441 <-> 74.125.43.132:443 ESTABLISHED
TCP (2336) firefox.exe 192.168.1.2:3442 <-> 74.125.43.132:443 ESTABLISHED
TCP (2336) firefox.exe 192.168.1.2:3443 <-> 74.125.43.132:443 ESTABLISHED
TCP (2336) firefox.exe 192.168.1.2:3444 <-> 74.125.43.132:443 ESTABLISHED
TCP (2336) firefox.exe 192.168.1.2:3445 <-> 74.125.43.132:443 ESTABLISHED
TCP (4916) UPM.exe 192.168.1.2:3458 <-> 109.123.209.238:80 ESTABLISHED
TCP (4916) UPM.exe 192.168.1.2:3459 <-> 95.100.248.11:80 ESTABLISHED
TCP (4916) UPM.exe 192.168.1.2:3460 <-> 194.7.155.81:80 ESTABLISHED
TCP (4916) UPM.exe 192.168.1.2:3461 <-> 199.7.71.190:80 ESTABLISHED
TCP (664) firefox.exe 192.168.1.2:3462 <-> 74.125.43.102:80 ESTABLISHED
TCP (664) firefox.exe 192.168.1.2:3463 <-> 74.125.43.102:80 ESTABLISHED
UDP (152) svchost.exe 0.0.0.0:427 <-> 199.7.52.190:80 ESTABLISHED
UDP (4) Systém 0.0.0.0:445
UDP (1696) lsass.exe 0.0.0.0:500
UDP (1696) lsass.exe 0.0.0.0:4500
UDP (4268) Skype.exe 127.0.0.1:1078
UDP (612) svchost.exe 127.0.0.1:1900
UDP (4) Systém 192.168.1.2:137
UDP (4) Systém 192.168.1.2:138
UDP (152) svchost.exe 192.168.1.2:427
UDP (2288) opera.exe 192.168.1.2:1079
UDP (2288) opera.exe 192.168.1.2:1900
UDP (612) svchost.exe 192.168.1.2:1900
Moduly (Zobraz i bezpečné DLL: False, Jen bez výrobce: True, Zobraz registrované: False)
================================================================
[?] uxtheme.dll
|_ Cesta: C:\WINDOWS\system32\uxtheme.dll
|_ MD5: AA5837459D8C7B54710EC41641FA8513
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ winlogon.exe (1588)
|_ lsass.exe (1696)
|_ svchost.exe (1920)
|_ svchost.exe (2008)
|_ svchost.exe (264)
|_ svchost.exe (436)
|_ svchost.exe (612)
|_ spoolsv.exe (868)
|_ avgwdsvc.exe (968)
|_ explorer.exe (1640)
|_ svchost.exe (1648)
|_ svchost.exe (152)
|_ svchost.exe (464)
|_ svchost.exe (824)
|_ jusched.exe (896)
|_ HDeck.exe (1068)
|_ svchost.exe (1208)
|_ FourEngine.exe (1268)
|_ BCU.exe (1364)
|_ nusb3mon.exe (1372)
|_ rundll32.exe (1488)
|_ TuneUpUtilitiesService32.exe (1500)
|_ GrooveMonitor.exe (136)
|_ avgtray.exe (1560)
|_ winampa.exe (1604)
|_ hpwuSchd2.exe (156)
|_ AdobeARM.exe (1616)
|_ ctfmon.exe (2144)
|_ hpqtra08.exe (2240)
|_ wmiprvse.exe (2248)
|_ TuneUpUtilitiesApp32.exe (1000)
|_ alg.exe (3272)
|_ unsecapp.exe (3280)
|_ wmiprvse.exe (3428)
|_ hpqste08.exe (3756)
|_ hpqbam08.exe (512)
|_ hpqgpc01.exe (648)
|_ winlogon.exe (1760)
|_ explorer.exe (2704)
|_ jusched.exe (3324)
|_ HDeck.exe (2904)
|_ FourEngine.exe (2872)
|_ BCU.exe (3236)
|_ nusb3mon.exe (3136)
|_ rundll32.exe (2760)
|_ GrooveMonitor.exe (2692)
|_ avgtray.exe (3452)
|_ winampa.exe (2092)
|_ hpwuSchd2.exe (2436)
|_ ctfmon.exe (284)
|_ Skype.exe (4268)
|_ DTLite.exe (4436)
|_ unsecapp.exe (5404)
|_ hpqtra08.exe (5448)
|_ wmiapsrv.exe (5332)
|_ hpqste08.exe (5544)
|_ hpqbam08.exe (5656)
|_ hpqgpc01.exe (6024)
|_ opera.exe (2288)
|_ jucheck.exe (5392)
|_ jucheck.exe (3432)
|_ mmc.exe (568)
|_ mscorsvw.exe (5128)
|_ firefox.exe (664)
|_ wuauclt.exe (2752)
|_ firefox.exe (2336)
|_ UPM.exe (4916)
[?] sfc_os.dll
|_ Cesta: C:\WINDOWS\system32\sfc_os.dll
|_ MD5: 04E297298C682F2E8415868F724C6D91
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ winlogon.exe (1588)
|_ svchost.exe (264)
|_ spoolsv.exe (868)
|_ UPM.exe (4916)
[?] hpqddsvc.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll
|_ MD5: F3F72A2A86C22610BCA5439FA789DD52
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ svchost.exe (1648)
[?] hpocxi08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpocxi08.dll
|_ MD5: 20009970E46FF07E74A1D1AF1B5E3530
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ svchost.exe (1648)
[?] hpqcob08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqcob08.dll
|_ MD5: A6D91E8682CF74A68486F2B9886418BD
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ svchost.exe (1648)
|_ hpqtra08.exe (2240)
|_ hpqste08.exe (3756)
|_ hpqtra08.exe (5448)
|_ hpqste08.exe (5544)
[?] hpqcxs08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll
|_ MD5: 0A3C6AA4A9FC38C20BA4EAC2C3351C05
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ svchost.exe (1648)
[?] hpqddcmn.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqddcmn.dll
|_ MD5: 7E53957E73BFB209D49932A9DDEBEDE4
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ svchost.exe (1648)
|_ hpqtra08.exe (2240)
|_ hpqtra08.exe (5448)
[?] hpslpsvc32.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL
|_ MD5: 79737E0F7D25DE8405CB34D4C9882253
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ svchost.exe (152)
[?] aigear.dll
|_ Cesta: C:\Program Files\ASUS\EPU-4 Engine\AiGear.dll
|_ MD5: FA5CF5CC82D4E39103DEC713E3790FF9
|_ Výrobce: AsusTek Inc.
|_ Procesy
|_ FourEngine.exe (1268)
|_ FourEngine.exe (2872)
[?] ainap.dll
|_ Cesta: C:\Program Files\ASUS\EPU-4 Engine\AiNap.dll
|_ MD5: 97C9AEF1C6DB6E3E5994B139AA3B2FAC
|_ Výrobce: ?
|_ Procesy
|_ FourEngine.exe (1268)
|_ FourEngine.exe (2872)
[?] pngio.dll
|_ Cesta: C:\Program Files\ASUS\EPU-4 Engine\pngio.dll
|_ MD5: 5BBC951150E738F108C6D3D325BD4029
|_ Výrobce:
|_ Procesy
|_ FourEngine.exe (1268)
|_ FourEngine.exe (2872)
[?] asio.dll
|_ Cesta: C:\WINDOWS\system32\AsIO.dll
|_ MD5: B6296A1E765612688E7E9800CEBF2AC8
|_ Výrobce: Copyright (C) 2010
|_ Procesy
|_ FourEngine.exe (1268)
|_ FourEngine.exe (2872)
[?] asspindowntimeout.dll
|_ Cesta: C:\Program Files\ASUS\EPU-4 Engine\AsSpindownTimeout.dll
|_ MD5: 2730BC63D4896F7976D9D31BC9786EBA
|_ Výrobce: ?
|_ Procesy
|_ FourEngine.exe (1268)
[?] asacpi.dll
|_ Cesta: C:\Program Files\ASUS\EPU-4 Engine\AsAcpi.dll
|_ MD5: 60C44E5B40F1845800494001464CD627
|_ Výrobce: ASUS
|_ Procesy
|_ FourEngine.exe (1268)
|_ FourEngine.exe (2872)
[?] sqlite3.dll
|_ Cesta: C:\Program Files\DeviceVM\Browser Configuration Utility\sqlite3.dll
|_ MD5: 7C2DC40E725BCBB3B5F2757EB1443325
|_ Výrobce:
|_ Procesy
|_ BCU.exe (1364)
|_ BCU.exe (3236)
[?] nusb3mon.dll
|_ Cesta: C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.dll
|_ MD5: 83ECB3325F8A7BF3E810D9E2156C2A8A
|_ Výrobce: NEC Electronics Corporation
|_ Procesy
|_ nusb3mon.exe (1372)
|_ nusb3mon.exe (3136)
[?] 771fa7.rbf
|_ Cesta: C:\Config.Msi\771fa7.rbf
|_ MD5: 39FF1BD0E33F1936AEFCB4936D9D8536
|_ Výrobce: NVIDIA Corporation
|_ Procesy
|_ rundll32.exe (1488)
|_ rundll32.exe (2760)
[?] hpqrif08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqrif08.dll
|_ MD5: 3C69CE161C7007E9AD53A325492D446A
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2240)
|_ hpqtra08.exe (5448)
[?] hpqmif08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqmif08.dll
|_ MD5: B0A41262968DD6FCE3933527892D4A24
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2240)
|_ hpqtra08.exe (5448)
[?] hpodio08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpodio08.dll
|_ MD5: 248C42A72B2D5D14114566B0CF3F8076
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2240)
|_ hpqste08.exe (3756)
|_ hpqtra08.exe (5448)
|_ hpqste08.exe (5544)
[?] hpqddusr.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqddusr.dll
|_ MD5: 03211597018F96769F7F731039F692E1
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2240)
|_ hpqtra08.exe (5448)
[?] hpqusg.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqusg.dll
|_ MD5: B4FEBBAC47297242F04EF7F14FE6DF99
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2240)
|_ hpqtra08.exe (5448)
[?] hpotradd.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpotradd.dll
|_ MD5: 5FD3B3E2F6EC82889C9ACD52C7A80E6B
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2240)
|_ hpqtra08.exe (5448)
[?] hpquio08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpquio08.dll
|_ MD5: C0E1D09C01019F27F2B06BBA152CDB07
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2240)
|_ hpqtra08.exe (5448)
[?] hpqtra08.rsc
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.rsc
|_ MD5: 87814D70ADAB6837817BC6FB4DBEDDDD
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2240)
|_ hpqtra08.exe (5448)
[?] hpqtao08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqtao08.dll
|_ MD5: DD1173E82083162858D1D4EAF43EC69B
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2240)
|_ hpqtra08.exe (5448)
[?] hpotra08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpotra08.dll
|_ MD5: EEEB27E29B3B9C1F49B89EF31326135B
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2240)
|_ hpqtra08.exe (5448)
[?] hpotra08.rsc
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpotra08.rsc
|_ MD5: 720088D0FD9B0FFA1E23973BE0C21C39
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2240)
|_ hpqtra08.exe (5448)
[?] hpzipr12.dll
|_ Cesta: C:\WINDOWS\system32\HPZipr12.dll
|_ MD5: B1C979C02FE013B2B9C0717C26AE1485
|_ Výrobce: Hewlett-Packard
|_ Procesy
|_ hpqste08.exe (3756)
|_ hpqste08.exe (5544)
[?] hpqgpb01.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqgpb01.dll
|_ MD5: 347A39B69AC03B8F56D8807B989F5CA8
|_ Výrobce: Hewlett-Packard
|_ Procesy
|_ hpqste08.exe (3756)
|_ hpqste08.exe (5544)
[?] hpqstp08.rsc
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqstp08.rsc
|_ MD5: A516D2C3AD3837E0B3168C85F239E23D
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqste08.exe (3756)
|_ hpqste08.exe (5544)
[?] hpqssm08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqssm08.dll
|_ MD5: 9E438543222120696C04A39BFAC56FB6
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqste08.exe (3756)
|_ hpqste08.exe (5544)
[?] hpqsplh08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\HpqSplh08.dll
|_ MD5: 55CF0A197DC8972AC829B30ACAE00E5E
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqste08.exe (3756)
|_ hpqste08.exe (5544)
[?] hpqsem08.rsc
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqsem08.rsc
|_ MD5: CA7AC8091046956DF8510F5EABA6F9BE
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqste08.exe (3756)
|_ hpqste08.exe (5544)
[?] hpqwso08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqwso08.dll
|_ MD5: F0842CF3C0B33C07B2CA1692900F21B4
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqste08.exe (3756)
|_ hpqste08.exe (5544)
[?] hpqsti08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqsti08.dll
|_ MD5: 9F6258F4166AB24B4B681EB1ED44534C
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqste08.exe (3756)
|_ hpqste08.exe (5544)
[?] hpqstp08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqstp08.dll
|_ MD5: 0EE03D901B5DCD3941686B95FCC98C89
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqste08.exe (3756)
|_ hpqste08.exe (5544)
[?] hpqgpreh.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqgpreh.dll
|_ MD5: CC190B07E357BCD40C2AFB57B9A67B7F
|_ Výrobce: Hewlett-Packard
|_ Procesy
|_ hpqgpc01.exe (648)
|_ hpqgpc01.exe (6024)
[?] hprbevst.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprbevst.dll
|_ MD5: CBBAF06C2AC8882D239C8DC5BFA197FD
|_ Výrobce: Hewlett Packard
|_ Procesy
|_ hpqgpc01.exe (648)
|_ hpqgpc01.exe (6024)
[?] aspnet_isapi.dll
|_ Cesta: C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
|_ MD5: 056E6BFD6314BBB84D5DFB1CA529CD60
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ Skype.exe (4268)
[?] softokn3.dll
|_ Cesta: C:\Program Files\Mozilla Firefox\softokn3.dll
|_ MD5: 02A8B0BAC1CA35CB450F5EACC93641A9
|_ Výrobce: Mozilla Foundation
|_ Procesy
|_ firefox.exe (664)
|_ firefox.exe (2336)
[?] freebl3.dll
|_ Cesta: C:\Program Files\Mozilla Firefox\freebl3.dll
|_ MD5: 1EB2951F37C03280E701C536B9F694CB
|_ Výrobce: Mozilla Foundation
|_ Procesy
|_ firefox.exe (664)
|_ firefox.exe (2336)
[?] hpxrestub.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\smart web printing\MozillaAddOn3\components\hpXREStub.dll
|_ MD5: 27F87473C96FE9EC6A71CD1F1BD2DCD3
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ firefox.exe (664)
|_ firefox.exe (2336)
[?] hpxre.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\smart web printing\MozillaAddOn3\xre\components\hpXRE.dll
|_ MD5: 4F0600DD0D8E9FA742654931B3D00925
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ firefox.exe (664)
|_ firefox.exe (2336)
[?] hpxpmtl.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\smart web printing\MozillaAddOn3\components\hpXPMTL.dll
|_ MD5: 151092A6AC1D654EF5733C657FE84DC5
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ firefox.exe (664)
|_ firefox.exe (2336)
[?] hpxpmtc.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\smart web printing\MozillaAddOn3\components\hpXPMTC.dll
|_ MD5: B154750A0BB6F7605596D1552E204032
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ firefox.exe (664)
|_ firefox.exe (2336)
[?] hpswpoperation.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\smart web printing\MozillaAddOn3\components\hpSWPOperation.dll
|_ MD5: DDE8E0F31B5806F24D728B11778E4D6F
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ firefox.exe (664)
|_ firefox.exe (2336)
[?] hpneologging.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\smart web printing\MozillaAddOn3\xre\components\hpNeoLogging.dll
|_ MD5: 32D8BE1860EFA6C2F5570D217CA75BEF
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ firefox.exe (664)
|_ firefox.exe (2336)
[?] hpseymour.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\smart web printing\MozillaAddOn3\components\hpSeymour.dll
|_ MD5: BD54A5700752F578EB9395010BA2A030
|_ Výrobce: Mozilla Foundation
|_ Procesy
|_ firefox.exe (2336)
Výpis souborů
================================================================
\System32:
[?] AsIO.dll 7 no vrfy, {021C954E}
[?] atl70.dll 12 ncmpny, {6B2F353B}
[?] atl71.dll 12 ncmpny, {A711E96B}
[X] BDEADMIN.CPL 100 ncmpny, cx (CODE)?, {399B5A57}
[!] cmdow.exe 63 no vrfy, cx (.data)?, {5DEF173A}
[?] cook3260.dll 7 no vrfy, {359B6201}
[X] DBCLIENT.DLL 100 ncmpny, cx (CODE)?, time mism., {EA8F6D0A}
[?] drv23260.dll 7 no vrfy, {E7EE1610}
[?] drv33260.dll 7 no vrfy, {FC54A40B}
[?] drv43260.dll 7 no vrfy, {20CB648E}
[?] hpbmiapi.dll 7 no vrfy, {3BF4E0F2}
[?] hpboid.dll 7 no vrfy, {5263A32D}
[?] hpboidps.dll 7 no vrfy, {178F49E8}
[?] hpbpro.dll 7 no vrfy, {E90C9B2E}
[?] hpbprops.dll 7 no vrfy, {CE10638C}
[?] hplbdchn.dll 7 no vrfy, {D33FC3DA}
[?] HPZidr12.dll 7 no vrfy, {3EA6BDE3}
[?] HPZinw12.dll 7 no vrfy, {D09A6C11}
[?] HPZipm12.dll 7 no vrfy, {377721D4}
[?] HPZipr12.dll 7 no vrfy, {D88CFEC5}
[?] hpzipt12.dll 7 no vrfy, {D599556A}
[?] hpzisn12.dll 7 no vrfy, {AEDEE07E}
[?] javacpl.cpl 14 no vrfy, {87FAB590}
[?] mfc70.dll 12 ncmpny, {3085DC5A}
[?] mfc70u.dll 12 ncmpny, {7CE2471B}
[?] mfc71.dll 12 ncmpny, {56A4B392}
[?] mfc71u.dll 12 ncmpny, {DA9A541A}
[?] msvci70.dll 12 ncmpny, {839A3260}
[?] msvcp71.dll 12 ncmpny, {2D00678D}
[?] msvcr70.dll 12 ncmpny, {44C2575C}
[?] msvcr71.dll 12 ncmpny, {25B399E8}
[?] nvdisps.dll 14 no vrfy, {8899C6FC}
[?] nvgames.dll 7 no vrfy, {976BDC9A}
[?] nvmccss.dll 7 no vrfy, {CA499D2A}
[?] nvmobls.dll 14 no vrfy, {DFDC6853}
[?] nvviddec.ax 7 no vrfy, {8DB649CE}
[?] nvvitvs.dll 14 no vrfy, {44B1EE74}
[?] nvwddi.dll 7 no vrfy, {77878C59}
[?] nvwss.dll 14 no vrfy, {AF9DDBEE}
[?] Pncrt.dll 7 no vrfy, {E234DFAD}
[?] setup.exe 12 ncmpny, {089DD0BA}
[?] setupold.exe 12 ncmpny, {41070263}
[?] sfc_os.dll 12 ncmpny, {1730E4D7}
[?] sipr3260.dll 7 no vrfy, {1B5FB9A7}
[?] TsWpfWrp.exe 12 ncmpny, {12E02F67}
[?] uxtheme.dll 12 ncmpny, {75A9D244}
[?] VCdRom.sys 25 ncmpny, {F53FD1E7}
[?] viahdcpl.cpl 14 no vrfy, {F44E368C}
[?] xvidcore.dll 12 ncmpny, {F02B0B26}
[?] xvidvfw.dll 12 ncmpny, {AD6B3A5E}
================================================================
Ultimate Process Manager v4.1.3 - [ Lodus Software ]
Windows XP SP 3 (build 2600)
Boot Mode: Normal
Ověření souborů Microsoftu: Ano
Whitelist: Ano
Internet Explorer v8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Log vygenerován: 4.4.2011 19:53:03
================================================================
SmallARK
================================================================
[?]NtClose -> C:\WINDOWS\system32\drivers\a347bus.sys
[?]NtCreateKey -> C:\WINDOWS\system32\drivers\a347bus.sys
[?]NtCreatePagingFile -> C:\WINDOWS\system32\drivers\a347bus.sys
[?]NtEnumerateKey -> C:\WINDOWS\system32\drivers\a347bus.sys
[?]NtEnumerateValueKey -> C:\WINDOWS\system32\drivers\a347bus.sys
[?]NtOpenFile -> C:\WINDOWS\system32\drivers\a347bus.sys
[?]NtOpenKey -> C:\WINDOWS\system32\drivers\a347bus.sys
[R]NtOpenProcess -> C:\WINDOWS\system32\drivers\AVGIDSShim.Sys
[?]NtQueryKey -> C:\WINDOWS\system32\drivers\a347bus.sys
[?]NtQueryValueKey -> C:\WINDOWS\system32\drivers\a347bus.sys
[?]NtSetSystemPowerState -> C:\WINDOWS\system32\drivers\a347bus.sys
[R]NtTerminateProcess -> C:\WINDOWS\system32\drivers\AVGIDSShim.Sys
[R]NtTerminateThread -> C:\WINDOWS\system32\drivers\AVGIDSShim.Sys
[R]NtWriteVirtualMemory -> C:\WINDOWS\system32\drivers\AVGIDSShim.Sys
Běžící procesy
================================================================
C:\PROGRAM FILES\NEC ELECTRONICS\USB 3.0 HOST CONTROLLER DRIVER\APPLICATION\NUSB3MON.EXE
C:\PROGRAM FILES\WINAMP\WINAMPA.EXE
C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQSTE08.EXE
C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQBAM08.EXE
C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQGPC01.EXE
C:\PROGRAM FILES\NEC ELECTRONICS\USB 3.0 HOST CONTROLLER DRIVER\APPLICATION\NUSB3MON.EXE
C:\PROGRAM FILES\WINAMP\WINAMPA.EXE
C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQSTE08.EXE
C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQBAM08.EXE
C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQGPC01.EXE
Scanner
================================================================
[S] explorer.exe
Spouští se po startu HKLM Winlogon [Shell]
[R] jusched.exe
Spouští se po startu HKLM Run [SunJavaUpdateSched]
[R] HDeck.exe
Spouští se po startu HKLM Run [HDAudDeck]
[R] FourEngine.exe
Spouští se po startu HKLM Run [Six Engine]
[R] BCU.exe
Spouští se po startu HKLM Run [BCU]
[?] nusb3mon.exe
Spouští se po startu HKLM Run [NUSB3MON]
Soubor 7%
[S] rundll32.exe
Spouští se po startu HKLM Run [NvMediaCenter]
[R] GrooveMonitor.exe
Ověřený Microsoft: Ne
Spouští se po startu HKLM Run [GrooveMonitor]
[R] avgtray.exe
Spouští se po startu HKLM Run [AVG_TRAY]
[?] winampa.exe
Spouští se po startu HKLM Run [WinampAgent]
Soubor 14%
[R] hpwuSchd2.exe
Spouští se po startu HKLM Run [HP Software Update]
[R] AdobeARM.exe
Spouští se po startu HKLM Run [Adobe ARM]
[S] ctfmon.exe
Spouští se po startu HKCU Run [CTFMON.EXE]
[R] hpqtra08.exe
Spouští se po startu Po spuštění []
[?] hpqste08.exe
Soubor 7%
[?] hpqbam08.exe
Soubor 14%
[?] hpqgpc01.exe
Soubor 7%
[S] explorer.exe
Spouští se po startu HKLM Winlogon [Shell]
[R] jusched.exe
Spouští se po startu HKLM Run [SunJavaUpdateSched]
[R] HDeck.exe
Spouští se po startu HKLM Run [HDAudDeck]
[R] FourEngine.exe
Spouští se po startu HKLM Run [Six Engine]
[R] BCU.exe
Spouští se po startu HKLM Run [BCU]
[?] nusb3mon.exe
Spouští se po startu HKLM Run [NUSB3MON]
Nemá okno
Soubor 7%
[S] rundll32.exe
Spouští se po startu HKLM Run [NvMediaCenter]
[R] GrooveMonitor.exe
Ověřený Microsoft: Ne
Spouští se po startu HKLM Run [GrooveMonitor]
[R] avgtray.exe
Spouští se po startu HKLM Run [AVG_TRAY]
[?] winampa.exe
Spouští se po startu HKLM Run [WinampAgent]
Nemá okno
Soubor 14%
[R] hpwuSchd2.exe
Spouští se po startu HKLM Run [HP Software Update]
[S] ctfmon.exe
Spouští se po startu HKCU Run [CTFMON.EXE]
[R] Skype.exe
Podvržená cesta modulu: (00400000) C:\Program Files\Skype\Phone\Skype.exe
[R] hpqtra08.exe
Spouští se po startu Po spuštění []
[?] hpqste08.exe
Nemá okno
Soubor 7%
[?] hpqbam08.exe
Nemá okno
Soubor 14%
[?] hpqgpc01.exe
Nemá okno
Soubor 7%
[R] mscorsvw.exe
Ověřený Microsoft: Ne
Po spuštění
================================================================
HKLM Run
|_ [R][HDAudDeck] C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
|_ [R][Six Engine] C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe -b
|_ [?][NUSB3MON] C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
|_ [?][WinampAgent] C:\Program Files\Winamp\winampa.exe
|_ [R][NvMediaCenter] C:\WINDOWS\system32\NvMcTray.dll ,NvTaskbarInit
|_ [R][NvCplDaemon] C:\WINDOWS\system32\NvCpl.dll ,NvStartup
|_ [R][nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
|_ [R][DWQueuedReporting] C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe -t
HKLM IC
|_ [X][>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] RunDLL32 IEDKCS32.DLL,BrandIEActiveSetup SIGNUP (Soubor nenalezen)
|_ [?][>{99820200-ECBD-11cf-8B85-00AA005B4340}] regsvr32.exe /s /n /i:U shell32.dll
|_ [?][{6BF52A52-394A-11d3-B153-00C04F79FAA6}] C:\WINDOWS\INF\wmp.inf ,PerUserStub
|_ [?][{89820200-ECBD-11cf-8B85-00AA005B4340}] regsvr32.exe /s /n /i:U shell32.dll
HKLM BHO
|_ [?][{E7E6F031-17CE-4C07-BC86-EABFE594F69C}] C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
Služby (Zobraz běžící: True, Zobraz zastavené: False, Zobraz i bezpečné služby: False)
================================================================
[?] hpqcxs08
|_ Cesta: C:\WINDOWS\system32\svchost.exe
| |_ Výrobce: Microsoft Corporation
| |_ Popis: Generic Host Process for Win32 Services
| |_ MD5: BE4A520E29B6391F49E79CCC52044D93
|
|_ ServiceDLL: C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll
| |_ Výrobce: Hewlett-Packard Co.
| |_ Popis: HP CUE Context Manager Objects
| |_ MD5: 0A3C6AA4A9FC38C20BA4EAC2C3351C05
|
|_ Jméno: hpqcxs08
|_ StartName: LocalSystem
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Win32 Share Process
|_ Dependency: RPCSS
[?] Služba HP CUE DeviceDiscovery
|_ Cesta: C:\WINDOWS\system32\svchost.exe
| |_ Výrobce: Microsoft Corporation
| |_ Popis: Generic Host Process for Win32 Services
| |_ MD5: BE4A520E29B6391F49E79CCC52044D93
|
|_ ServiceDLL: C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll
| |_ Výrobce: Hewlett-Packard Co.
| |_ Popis: HP CUE DeviceDiscovery Service
| |_ MD5: F3F72A2A86C22610BCA5439FA789DD52
|
|_ Jméno: hpqddsvc
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Share Process
|_ Dependency: RPCSS
[?] HP Network Devices Support
|_ Cesta: C:\WINDOWS\system32\svchost.exe
| |_ Výrobce: Microsoft Corporation
| |_ Popis: Generic Host Process for Win32 Services
| |_ MD5: BE4A520E29B6391F49E79CCC52044D93
|
|_ ServiceDLL: C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL
| |_ Výrobce: Hewlett-Packard Co.
| |_ Popis: HP Network Devices Support
| |_ MD5: 79737E0F7D25DE8405CB34D4C9882253
|
|_ Jméno: HPSLPSVC
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ:
|_ Dependency: RPCSS
[?] Net Driver HPZ12
|_ Cesta: C:\WINDOWS\System32\svchost.exe
| |_ Výrobce: Microsoft Corporation
| |_ Popis: Generic Host Process for Win32 Services
| |_ MD5: BE4A520E29B6391F49E79CCC52044D93
|
|_ ServiceDLL: C:\WINDOWS\system32\HPZinw12.dll
| |_ Výrobce: Hewlett-Packard
| |_ Popis: Dot4Net Module
| |_ MD5: 510C138564486FF926A3F773205C63D1
|
|_ Jméno: Net Driver HPZ12
|_ StartName: NT AUTHORITY\LocalService
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Own Process
|_ Dependency:
[?] Pml Driver HPZ12
|_ Cesta: C:\WINDOWS\System32\svchost.exe
| |_ Výrobce: Microsoft Corporation
| |_ Popis: Generic Host Process for Win32 Services
| |_ MD5: BE4A520E29B6391F49E79CCC52044D93
|
|_ ServiceDLL: C:\WINDOWS\system32\HPZipm12.dll
| |_ Výrobce: Hewlett-Packard
| |_ Popis: PmlDrv Module
| |_ MD5: 37E5E8FFBAD35605DAEEC3224EA0E465
|
|_ Jméno: Pml Driver HPZ12
|_ StartName: NT AUTHORITY\LocalService
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Own Process
|_ Dependency:
[R] TuneUp Theme Extension
|_ Cesta: C:\WINDOWS\System32\svchost.exe
| |_ Výrobce: Microsoft Corporation
| |_ Popis: Generic Host Process for Win32 Services
| |_ MD5: BE4A520E29B6391F49E79CCC52044D93
|
|_ ServiceDLL: C:\WINDOWS\System32\uxtuneup.dll
| |_ Výrobce: TuneUp Software
| |_ Popis: TuneUp Theme Extension
| |_ MD5: 3A335BB79F9D93F1D33CA07F8986E004
|
|_ Jméno: UxTuneUp
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Share Process
|_ Dependency: Themes
Ovladače (Zobraz běžící: True, Zobraz zastavené: False, Zobraz i bezpečné služby: False)
================================================================
[?] a347bus
|_ Cesta: C:\WINDOWS\system32\DRIVERS\a347bus.sys
| |_ Výrobce:
| |_ Popis: Plug and Play BIOS Extension
| |_ MD5: 1F61CACACB521215F39061789147968C
|
|_ Jméno: a347bus
|_ StartName:
|_ Typ spouštění: Boot Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] a347scsi
|_ Cesta: C:\WINDOWS\System32\Drivers\a347scsi.sys
| |_ Výrobce:
| |_ Popis: SCSI miniport
| |_ MD5: 113E4B318BBAA7483CA4E582A4D63F49
|
|_ Jméno: a347scsi
|_ StartName:
|_ Typ spouštění: Boot Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Ovladač procesoru HwPState AMD
|_ Cesta: C:\WINDOWS\system32\DRIVERS\AmdPPM.sys
| |_ Výrobce: Advanced Micro Devices
| |_ Popis: AMD Processor Driver
| |_ MD5: 033448D435E65C4BD72E70521FD05C76
|
|_ Jméno: AmdPPM
|_ StartName:
|_ Typ spouštění: System Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Standardní řadič disku IDE/ESDI
|_ Cesta: C:\WINDOWS\system32\DRIVERS\atapi.sys
| |_ Výrobce:
| |_ Popis:
| |_ MD5:
|
|_ Jméno: atapi
|_ StartName:
|_ Typ spouštění: Boot Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] NEC Electronics USB 3.0 Hub Driver
|_ Cesta: C:\WINDOWS\system32\DRIVERS\nusb3hub.sys
| |_ Výrobce: NEC Electronics Corporation
| |_ Popis: USB 3.0 Hub Driver
| |_ MD5: 9A3879B890F395EF8007A69543B56E8D
|
|_ Jméno: nusb3hub
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] NEC Electronics USB 3.0 Host Controller Driver
|_ Cesta: C:\WINDOWS\system32\DRIVERS\nusb3xhc.sys
| |_ Výrobce: NEC Electronics Corporation
| |_ Popis: USB 3.0 Host Controller Driver
| |_ MD5: 61C3A3C6B35F596831358D954D20712F
|
|_ Jméno: nusb3xhc
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] nv
|_ Cesta: C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
| |_ Výrobce: NVIDIA Corporation
| |_ Popis: NVIDIA Compatible Windows 2000 Miniport Driver, Version 266.58
| |_ MD5: 18C9B152DA7BEA76B2F9E4B6412E0AAF
|
|_ Jméno: nv
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver
|_ Cesta: C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
| |_ Výrobce: Realtek Semiconductor Corporation
| |_ Popis: Realtek 10/100/1000 NDIS 5.1 Driver
| |_ MD5: CB9310A5A910648D359C99A857E22A54
|
|_ Jméno: RTLE8023xp
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
lNetStat
================================================================
Typ: PID Proces Local <-> Remote Status
-----------------------------------------------------------------------------------------
TCP (2008) svchost.exe 0.0.0.0:135 LISTENING
TCP (4) Systém 0.0.0.0:445 LISTENING
TCP (3272) alg.exe 127.0.0.1:1030 LISTENING
TCP (664) firefox.exe 127.0.0.1:3193 <-> 127.0.0.1:3194 ESTABLISHED
TCP (664) firefox.exe 127.0.0.1:3194 <-> 127.0.0.1:3193 ESTABLISHED
TCP (664) firefox.exe 127.0.0.1:3195 <-> 127.0.0.1:3196 ESTABLISHED
TCP (664) firefox.exe 127.0.0.1:3196 <-> 127.0.0.1:3195 ESTABLISHED
TCP (0) 127.0.0.1:3408 TIME_WAIT
TCP (0) 127.0.0.1:3409 TIME_WAIT
TCP (2336) firefox.exe 127.0.0.1:3410 <-> 127.0.0.1:3411 ESTABLISHED
TCP (2336) firefox.exe 127.0.0.1:3411 <-> 127.0.0.1:3410 ESTABLISHED
TCP (2336) firefox.exe 127.0.0.1:3416 <-> 127.0.0.1:3417 ESTABLISHED
TCP (2336) firefox.exe 127.0.0.1:3417 <-> 127.0.0.1:3416 ESTABLISHED
TCP (4) Systém 192.168.1.2:139 LISTENING
TCP (5392) jucheck.exe 192.168.1.2:1235 CLOSE_WAIT
TCP (3432) jucheck.exe 192.168.1.2:1371 CLOSE_WAIT
TCP (2288) opera.exe 192.168.1.2:2878 <-> 95.168.207.36:80 ESTABLISHED
TCP (2336) firefox.exe 192.168.1.2:3414 <-> 74.125.43.105:80 ESTABLISHED
TCP (2336) firefox.exe 192.168.1.2:3418 <-> 74.125.43.147:80 ESTABLISHED
TCP (2336) firefox.exe 192.168.1.2:3419 <-> 74.125.43.103:80 ESTABLISHED
TCP (2336) firefox.exe 192.168.1.2:3420 <-> 74.125.43.103:80 ESTABLISHED
TCP (2336) firefox.exe 192.168.1.2:3421 <-> 74.125.43.190:443 ESTABLISHED
TCP (0) 192.168.1.2:3422 TIME_WAIT
TCP (2336) firefox.exe 192.168.1.2:3432 <-> 74.125.43.113:80 ESTABLISHED
TCP (2336) firefox.exe 192.168.1.2:3434 <-> 74.125.43.91:443 ESTABLISHED
TCP (2336) firefox.exe 192.168.1.2:3437 <-> 74.125.43.91:443 ESTABLISHED
TCP (2336) firefox.exe 192.168.1.2:3438 <-> 74.125.43.91:443 ESTABLISHED
TCP (2336) firefox.exe 192.168.1.2:3439 <-> 74.125.43.132:443 ESTABLISHED
TCP (2336) firefox.exe 192.168.1.2:3440 <-> 74.125.43.132:443 ESTABLISHED
TCP (2336) firefox.exe 192.168.1.2:3441 <-> 74.125.43.132:443 ESTABLISHED
TCP (2336) firefox.exe 192.168.1.2:3442 <-> 74.125.43.132:443 ESTABLISHED
TCP (2336) firefox.exe 192.168.1.2:3443 <-> 74.125.43.132:443 ESTABLISHED
TCP (2336) firefox.exe 192.168.1.2:3444 <-> 74.125.43.132:443 ESTABLISHED
TCP (2336) firefox.exe 192.168.1.2:3445 <-> 74.125.43.132:443 ESTABLISHED
TCP (4916) UPM.exe 192.168.1.2:3458 <-> 109.123.209.238:80 ESTABLISHED
TCP (4916) UPM.exe 192.168.1.2:3459 <-> 95.100.248.11:80 ESTABLISHED
TCP (4916) UPM.exe 192.168.1.2:3460 <-> 194.7.155.81:80 ESTABLISHED
TCP (4916) UPM.exe 192.168.1.2:3461 <-> 199.7.71.190:80 ESTABLISHED
TCP (664) firefox.exe 192.168.1.2:3462 <-> 74.125.43.102:80 ESTABLISHED
TCP (664) firefox.exe 192.168.1.2:3463 <-> 74.125.43.102:80 ESTABLISHED
UDP (152) svchost.exe 0.0.0.0:427 <-> 199.7.52.190:80 ESTABLISHED
UDP (4) Systém 0.0.0.0:445
UDP (1696) lsass.exe 0.0.0.0:500
UDP (1696) lsass.exe 0.0.0.0:4500
UDP (4268) Skype.exe 127.0.0.1:1078
UDP (612) svchost.exe 127.0.0.1:1900
UDP (4) Systém 192.168.1.2:137
UDP (4) Systém 192.168.1.2:138
UDP (152) svchost.exe 192.168.1.2:427
UDP (2288) opera.exe 192.168.1.2:1079
UDP (2288) opera.exe 192.168.1.2:1900
UDP (612) svchost.exe 192.168.1.2:1900
Moduly (Zobraz i bezpečné DLL: False, Jen bez výrobce: True, Zobraz registrované: False)
================================================================
[?] uxtheme.dll
|_ Cesta: C:\WINDOWS\system32\uxtheme.dll
|_ MD5: AA5837459D8C7B54710EC41641FA8513
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ winlogon.exe (1588)
|_ lsass.exe (1696)
|_ svchost.exe (1920)
|_ svchost.exe (2008)
|_ svchost.exe (264)
|_ svchost.exe (436)
|_ svchost.exe (612)
|_ spoolsv.exe (868)
|_ avgwdsvc.exe (968)
|_ explorer.exe (1640)
|_ svchost.exe (1648)
|_ svchost.exe (152)
|_ svchost.exe (464)
|_ svchost.exe (824)
|_ jusched.exe (896)
|_ HDeck.exe (1068)
|_ svchost.exe (1208)
|_ FourEngine.exe (1268)
|_ BCU.exe (1364)
|_ nusb3mon.exe (1372)
|_ rundll32.exe (1488)
|_ TuneUpUtilitiesService32.exe (1500)
|_ GrooveMonitor.exe (136)
|_ avgtray.exe (1560)
|_ winampa.exe (1604)
|_ hpwuSchd2.exe (156)
|_ AdobeARM.exe (1616)
|_ ctfmon.exe (2144)
|_ hpqtra08.exe (2240)
|_ wmiprvse.exe (2248)
|_ TuneUpUtilitiesApp32.exe (1000)
|_ alg.exe (3272)
|_ unsecapp.exe (3280)
|_ wmiprvse.exe (3428)
|_ hpqste08.exe (3756)
|_ hpqbam08.exe (512)
|_ hpqgpc01.exe (648)
|_ winlogon.exe (1760)
|_ explorer.exe (2704)
|_ jusched.exe (3324)
|_ HDeck.exe (2904)
|_ FourEngine.exe (2872)
|_ BCU.exe (3236)
|_ nusb3mon.exe (3136)
|_ rundll32.exe (2760)
|_ GrooveMonitor.exe (2692)
|_ avgtray.exe (3452)
|_ winampa.exe (2092)
|_ hpwuSchd2.exe (2436)
|_ ctfmon.exe (284)
|_ Skype.exe (4268)
|_ DTLite.exe (4436)
|_ unsecapp.exe (5404)
|_ hpqtra08.exe (5448)
|_ wmiapsrv.exe (5332)
|_ hpqste08.exe (5544)
|_ hpqbam08.exe (5656)
|_ hpqgpc01.exe (6024)
|_ opera.exe (2288)
|_ jucheck.exe (5392)
|_ jucheck.exe (3432)
|_ mmc.exe (568)
|_ mscorsvw.exe (5128)
|_ firefox.exe (664)
|_ wuauclt.exe (2752)
|_ firefox.exe (2336)
|_ UPM.exe (4916)
[?] sfc_os.dll
|_ Cesta: C:\WINDOWS\system32\sfc_os.dll
|_ MD5: 04E297298C682F2E8415868F724C6D91
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ winlogon.exe (1588)
|_ svchost.exe (264)
|_ spoolsv.exe (868)
|_ UPM.exe (4916)
[?] hpqddsvc.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll
|_ MD5: F3F72A2A86C22610BCA5439FA789DD52
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ svchost.exe (1648)
[?] hpocxi08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpocxi08.dll
|_ MD5: 20009970E46FF07E74A1D1AF1B5E3530
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ svchost.exe (1648)
[?] hpqcob08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqcob08.dll
|_ MD5: A6D91E8682CF74A68486F2B9886418BD
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ svchost.exe (1648)
|_ hpqtra08.exe (2240)
|_ hpqste08.exe (3756)
|_ hpqtra08.exe (5448)
|_ hpqste08.exe (5544)
[?] hpqcxs08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll
|_ MD5: 0A3C6AA4A9FC38C20BA4EAC2C3351C05
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ svchost.exe (1648)
[?] hpqddcmn.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqddcmn.dll
|_ MD5: 7E53957E73BFB209D49932A9DDEBEDE4
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ svchost.exe (1648)
|_ hpqtra08.exe (2240)
|_ hpqtra08.exe (5448)
[?] hpslpsvc32.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL
|_ MD5: 79737E0F7D25DE8405CB34D4C9882253
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ svchost.exe (152)
[?] aigear.dll
|_ Cesta: C:\Program Files\ASUS\EPU-4 Engine\AiGear.dll
|_ MD5: FA5CF5CC82D4E39103DEC713E3790FF9
|_ Výrobce: AsusTek Inc.
|_ Procesy
|_ FourEngine.exe (1268)
|_ FourEngine.exe (2872)
[?] ainap.dll
|_ Cesta: C:\Program Files\ASUS\EPU-4 Engine\AiNap.dll
|_ MD5: 97C9AEF1C6DB6E3E5994B139AA3B2FAC
|_ Výrobce: ?
|_ Procesy
|_ FourEngine.exe (1268)
|_ FourEngine.exe (2872)
[?] pngio.dll
|_ Cesta: C:\Program Files\ASUS\EPU-4 Engine\pngio.dll
|_ MD5: 5BBC951150E738F108C6D3D325BD4029
|_ Výrobce:
|_ Procesy
|_ FourEngine.exe (1268)
|_ FourEngine.exe (2872)
[?] asio.dll
|_ Cesta: C:\WINDOWS\system32\AsIO.dll
|_ MD5: B6296A1E765612688E7E9800CEBF2AC8
|_ Výrobce: Copyright (C) 2010
|_ Procesy
|_ FourEngine.exe (1268)
|_ FourEngine.exe (2872)
[?] asspindowntimeout.dll
|_ Cesta: C:\Program Files\ASUS\EPU-4 Engine\AsSpindownTimeout.dll
|_ MD5: 2730BC63D4896F7976D9D31BC9786EBA
|_ Výrobce: ?
|_ Procesy
|_ FourEngine.exe (1268)
[?] asacpi.dll
|_ Cesta: C:\Program Files\ASUS\EPU-4 Engine\AsAcpi.dll
|_ MD5: 60C44E5B40F1845800494001464CD627
|_ Výrobce: ASUS
|_ Procesy
|_ FourEngine.exe (1268)
|_ FourEngine.exe (2872)
[?] sqlite3.dll
|_ Cesta: C:\Program Files\DeviceVM\Browser Configuration Utility\sqlite3.dll
|_ MD5: 7C2DC40E725BCBB3B5F2757EB1443325
|_ Výrobce:
|_ Procesy
|_ BCU.exe (1364)
|_ BCU.exe (3236)
[?] nusb3mon.dll
|_ Cesta: C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.dll
|_ MD5: 83ECB3325F8A7BF3E810D9E2156C2A8A
|_ Výrobce: NEC Electronics Corporation
|_ Procesy
|_ nusb3mon.exe (1372)
|_ nusb3mon.exe (3136)
[?] 771fa7.rbf
|_ Cesta: C:\Config.Msi\771fa7.rbf
|_ MD5: 39FF1BD0E33F1936AEFCB4936D9D8536
|_ Výrobce: NVIDIA Corporation
|_ Procesy
|_ rundll32.exe (1488)
|_ rundll32.exe (2760)
[?] hpqrif08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqrif08.dll
|_ MD5: 3C69CE161C7007E9AD53A325492D446A
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2240)
|_ hpqtra08.exe (5448)
[?] hpqmif08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqmif08.dll
|_ MD5: B0A41262968DD6FCE3933527892D4A24
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2240)
|_ hpqtra08.exe (5448)
[?] hpodio08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpodio08.dll
|_ MD5: 248C42A72B2D5D14114566B0CF3F8076
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2240)
|_ hpqste08.exe (3756)
|_ hpqtra08.exe (5448)
|_ hpqste08.exe (5544)
[?] hpqddusr.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqddusr.dll
|_ MD5: 03211597018F96769F7F731039F692E1
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2240)
|_ hpqtra08.exe (5448)
[?] hpqusg.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqusg.dll
|_ MD5: B4FEBBAC47297242F04EF7F14FE6DF99
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2240)
|_ hpqtra08.exe (5448)
[?] hpotradd.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpotradd.dll
|_ MD5: 5FD3B3E2F6EC82889C9ACD52C7A80E6B
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2240)
|_ hpqtra08.exe (5448)
[?] hpquio08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpquio08.dll
|_ MD5: C0E1D09C01019F27F2B06BBA152CDB07
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2240)
|_ hpqtra08.exe (5448)
[?] hpqtra08.rsc
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.rsc
|_ MD5: 87814D70ADAB6837817BC6FB4DBEDDDD
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2240)
|_ hpqtra08.exe (5448)
[?] hpqtao08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqtao08.dll
|_ MD5: DD1173E82083162858D1D4EAF43EC69B
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2240)
|_ hpqtra08.exe (5448)
[?] hpotra08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpotra08.dll
|_ MD5: EEEB27E29B3B9C1F49B89EF31326135B
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2240)
|_ hpqtra08.exe (5448)
[?] hpotra08.rsc
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpotra08.rsc
|_ MD5: 720088D0FD9B0FFA1E23973BE0C21C39
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqtra08.exe (2240)
|_ hpqtra08.exe (5448)
[?] hpzipr12.dll
|_ Cesta: C:\WINDOWS\system32\HPZipr12.dll
|_ MD5: B1C979C02FE013B2B9C0717C26AE1485
|_ Výrobce: Hewlett-Packard
|_ Procesy
|_ hpqste08.exe (3756)
|_ hpqste08.exe (5544)
[?] hpqgpb01.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqgpb01.dll
|_ MD5: 347A39B69AC03B8F56D8807B989F5CA8
|_ Výrobce: Hewlett-Packard
|_ Procesy
|_ hpqste08.exe (3756)
|_ hpqste08.exe (5544)
[?] hpqstp08.rsc
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqstp08.rsc
|_ MD5: A516D2C3AD3837E0B3168C85F239E23D
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqste08.exe (3756)
|_ hpqste08.exe (5544)
[?] hpqssm08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqssm08.dll
|_ MD5: 9E438543222120696C04A39BFAC56FB6
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqste08.exe (3756)
|_ hpqste08.exe (5544)
[?] hpqsplh08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\HpqSplh08.dll
|_ MD5: 55CF0A197DC8972AC829B30ACAE00E5E
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqste08.exe (3756)
|_ hpqste08.exe (5544)
[?] hpqsem08.rsc
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqsem08.rsc
|_ MD5: CA7AC8091046956DF8510F5EABA6F9BE
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqste08.exe (3756)
|_ hpqste08.exe (5544)
[?] hpqwso08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqwso08.dll
|_ MD5: F0842CF3C0B33C07B2CA1692900F21B4
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqste08.exe (3756)
|_ hpqste08.exe (5544)
[?] hpqsti08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqsti08.dll
|_ MD5: 9F6258F4166AB24B4B681EB1ED44534C
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqste08.exe (3756)
|_ hpqste08.exe (5544)
[?] hpqstp08.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqstp08.dll
|_ MD5: 0EE03D901B5DCD3941686B95FCC98C89
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ hpqste08.exe (3756)
|_ hpqste08.exe (5544)
[?] hpqgpreh.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\bin\hpqgpreh.dll
|_ MD5: CC190B07E357BCD40C2AFB57B9A67B7F
|_ Výrobce: Hewlett-Packard
|_ Procesy
|_ hpqgpc01.exe (648)
|_ hpqgpc01.exe (6024)
[?] hprbevst.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprbevst.dll
|_ MD5: CBBAF06C2AC8882D239C8DC5BFA197FD
|_ Výrobce: Hewlett Packard
|_ Procesy
|_ hpqgpc01.exe (648)
|_ hpqgpc01.exe (6024)
[?] aspnet_isapi.dll
|_ Cesta: C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
|_ MD5: 056E6BFD6314BBB84D5DFB1CA529CD60
|_ Výrobce: Microsoft Corporation
|_ Procesy
|_ Skype.exe (4268)
[?] softokn3.dll
|_ Cesta: C:\Program Files\Mozilla Firefox\softokn3.dll
|_ MD5: 02A8B0BAC1CA35CB450F5EACC93641A9
|_ Výrobce: Mozilla Foundation
|_ Procesy
|_ firefox.exe (664)
|_ firefox.exe (2336)
[?] freebl3.dll
|_ Cesta: C:\Program Files\Mozilla Firefox\freebl3.dll
|_ MD5: 1EB2951F37C03280E701C536B9F694CB
|_ Výrobce: Mozilla Foundation
|_ Procesy
|_ firefox.exe (664)
|_ firefox.exe (2336)
[?] hpxrestub.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\smart web printing\MozillaAddOn3\components\hpXREStub.dll
|_ MD5: 27F87473C96FE9EC6A71CD1F1BD2DCD3
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ firefox.exe (664)
|_ firefox.exe (2336)
[?] hpxre.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\smart web printing\MozillaAddOn3\xre\components\hpXRE.dll
|_ MD5: 4F0600DD0D8E9FA742654931B3D00925
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ firefox.exe (664)
|_ firefox.exe (2336)
[?] hpxpmtl.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\smart web printing\MozillaAddOn3\components\hpXPMTL.dll
|_ MD5: 151092A6AC1D654EF5733C657FE84DC5
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ firefox.exe (664)
|_ firefox.exe (2336)
[?] hpxpmtc.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\smart web printing\MozillaAddOn3\components\hpXPMTC.dll
|_ MD5: B154750A0BB6F7605596D1552E204032
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ firefox.exe (664)
|_ firefox.exe (2336)
[?] hpswpoperation.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\smart web printing\MozillaAddOn3\components\hpSWPOperation.dll
|_ MD5: DDE8E0F31B5806F24D728B11778E4D6F
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ firefox.exe (664)
|_ firefox.exe (2336)
[?] hpneologging.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\smart web printing\MozillaAddOn3\xre\components\hpNeoLogging.dll
|_ MD5: 32D8BE1860EFA6C2F5570D217CA75BEF
|_ Výrobce: Hewlett-Packard Co.
|_ Procesy
|_ firefox.exe (664)
|_ firefox.exe (2336)
[?] hpseymour.dll
|_ Cesta: C:\Program Files\HP\Digital Imaging\smart web printing\MozillaAddOn3\components\hpSeymour.dll
|_ MD5: BD54A5700752F578EB9395010BA2A030
|_ Výrobce: Mozilla Foundation
|_ Procesy
|_ firefox.exe (2336)
Výpis souborů
================================================================
\System32:
[?] AsIO.dll 7 no vrfy, {021C954E}
[?] atl70.dll 12 ncmpny, {6B2F353B}
[?] atl71.dll 12 ncmpny, {A711E96B}
[X] BDEADMIN.CPL 100 ncmpny, cx (CODE)?, {399B5A57}
[!] cmdow.exe 63 no vrfy, cx (.data)?, {5DEF173A}
[?] cook3260.dll 7 no vrfy, {359B6201}
[X] DBCLIENT.DLL 100 ncmpny, cx (CODE)?, time mism., {EA8F6D0A}
[?] drv23260.dll 7 no vrfy, {E7EE1610}
[?] drv33260.dll 7 no vrfy, {FC54A40B}
[?] drv43260.dll 7 no vrfy, {20CB648E}
[?] hpbmiapi.dll 7 no vrfy, {3BF4E0F2}
[?] hpboid.dll 7 no vrfy, {5263A32D}
[?] hpboidps.dll 7 no vrfy, {178F49E8}
[?] hpbpro.dll 7 no vrfy, {E90C9B2E}
[?] hpbprops.dll 7 no vrfy, {CE10638C}
[?] hplbdchn.dll 7 no vrfy, {D33FC3DA}
[?] HPZidr12.dll 7 no vrfy, {3EA6BDE3}
[?] HPZinw12.dll 7 no vrfy, {D09A6C11}
[?] HPZipm12.dll 7 no vrfy, {377721D4}
[?] HPZipr12.dll 7 no vrfy, {D88CFEC5}
[?] hpzipt12.dll 7 no vrfy, {D599556A}
[?] hpzisn12.dll 7 no vrfy, {AEDEE07E}
[?] javacpl.cpl 14 no vrfy, {87FAB590}
[?] mfc70.dll 12 ncmpny, {3085DC5A}
[?] mfc70u.dll 12 ncmpny, {7CE2471B}
[?] mfc71.dll 12 ncmpny, {56A4B392}
[?] mfc71u.dll 12 ncmpny, {DA9A541A}
[?] msvci70.dll 12 ncmpny, {839A3260}
[?] msvcp71.dll 12 ncmpny, {2D00678D}
[?] msvcr70.dll 12 ncmpny, {44C2575C}
[?] msvcr71.dll 12 ncmpny, {25B399E8}
[?] nvdisps.dll 14 no vrfy, {8899C6FC}
[?] nvgames.dll 7 no vrfy, {976BDC9A}
[?] nvmccss.dll 7 no vrfy, {CA499D2A}
[?] nvmobls.dll 14 no vrfy, {DFDC6853}
[?] nvviddec.ax 7 no vrfy, {8DB649CE}
[?] nvvitvs.dll 14 no vrfy, {44B1EE74}
[?] nvwddi.dll 7 no vrfy, {77878C59}
[?] nvwss.dll 14 no vrfy, {AF9DDBEE}
[?] Pncrt.dll 7 no vrfy, {E234DFAD}
[?] setup.exe 12 ncmpny, {089DD0BA}
[?] setupold.exe 12 ncmpny, {41070263}
[?] sfc_os.dll 12 ncmpny, {1730E4D7}
[?] sipr3260.dll 7 no vrfy, {1B5FB9A7}
[?] TsWpfWrp.exe 12 ncmpny, {12E02F67}
[?] uxtheme.dll 12 ncmpny, {75A9D244}
[?] VCdRom.sys 25 ncmpny, {F53FD1E7}
[?] viahdcpl.cpl 14 no vrfy, {F44E368C}
[?] xvidcore.dll 12 ncmpny, {F02B0B26}
[?] xvidvfw.dll 12 ncmpny, {AD6B3A5E}
================================================================
Ultimate Process Manager v4.1.3 - [ Lodus Software ]