Prosím o kontrolu logu
Napsal: 10 črc 2011 19:10
Predom ďakujem
Windows Vista SP 1 (build 7601)
Boot Mode: Normal
Overení sůborů Microsoftu: Nie
Whitelist: Nie
Internet Explorer v9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)
Log vygenerovaný:10. 7. 2011 20:04:41
================================================================
Bežiace procesy
================================================================
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WININIT.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\WINDOWS\SYSTEM32\LSM.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\MICROSOFT SECURITY CLIENT\ANTIMALWARE\MSMPENG.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\WIDCOMM\BLUETOOTH SOFTWARE\BTWDINS.EXE
C:\PROGRAM FILES (X86)\LAUNCH MANAGER\DSIWMIS.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES (X86)\ACER\REGISTRATION\GREGHSRW.EXE
C:\PROGRAM FILES (X86)\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\MDM.EXE
C:\PROGRAM FILES (X86)\NEWTECH INFOSYSTEMS\ACER BACKUP MANAGER\ISCHEDULESVC.EXE
C:\PROGRAM FILES (X86)\ACER\ACER VCM\RS_SERVICE.EXE
C:\PROGRAM FILES (X86)\SPYWARE TERMINATOR\SP_RSSER.EXE
C:\PROGRAM FILES (X86)\TEAMVIEWER\VERSION5\TEAMVIEWER_SERVICE.EXE
C:\PROGRAM FILES (X86)\TEAMVIEWER\VERSION6\TEAMVIEWER_SERVICE.EXE
C:\PROGRAM FILES (X86)\COMMON FILES\ULEAD SYSTEMS\DVD\ULCDRSVR.EXE
C:\PROGRAM FILES\ACER\ACER UPDATER\UPDATERSERVICE.EXE
C:\WINDOWS\SYSWOW64\UTSCSI.EXE
C:\PROGRAM FILES (X86)\COMMON FILES\VMWARE\USB\VMWARE-USBARBITRATOR.EXE
C:\WINDOWS\SYSWOW64\VMNAT.EXE
C:\WINDOWS\SYSWOW64\VMNETDHCP.EXE
C:\PROGRAM FILES (X86)\INTEL\INTEL MATRIX STORAGE MANAGER\IAANTMON.EXE
C:\PROGRAM FILES (X86)\VMWARE\VMWARE PLAYER\VMWARE-AUTHD.EXE
C:\PROGRAM FILES (X86)\SPYBOT - SEARCH & DESTROY\SDWINSEC.EXE
C:\PROGRAM FILES\MICROSOFT SECURITY CLIENT\ANTIMALWARE\NISSRV.EXE
C:\WINDOWS\SYSTEM32\TASKHOST.EXE
C:\WINDOWS\SYSTEM32\DWM.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPENH.EXE
C:\WINDOWS\PLFSETI.EXE
C:\WINDOWS\SYSTEM32\IGFXTRAY.EXE
C:\WINDOWS\SYSTEM32\HKCMD.EXE
C:\WINDOWS\SYSTEM32\IGFXPERS.EXE
C:\PROGRAM FILES\MICROSOFT SECURITY CLIENT\MSSECES.EXE
C:\PROGRAM FILES (X86)\NEWTECH INFOSYSTEMS\ACER BACKUP MANAGER\BACKUPMANAGERTRAY.EXE
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\PROGRAM FILES (X86)\LAUNCH MANAGER\LMANAGER.EXE
C:\WINDOWS\SYSTEM32\IGFXSRVC.EXE
C:\PROGRAM FILES (X86)\COMMON FILES\JAVA\JAVA UPDATE\JUSCHED.EXE
C:\PROGRAM FILES (X86)\VMWARE\VMWARE PLAYER\HQTRAY.EXE
C:\WINDOWS\SYSTEM32\SEARCHINDEXER.EXE
C:\PROGRAM FILES\WINDOWS MEDIA PLAYER\WMPNETWK.EXE
C:\TOTALCMD\TOTALCMD.EXE
C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE
C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\PLUGIN-CONTAINER.EXE
C:\PROGRAM FILES (X86)\ULTIMATE PROCESS MANAGER\UPM.EXE
Scanner
================================================================
[S, novf!] smss.exe
Non Microsoft v System32:
Overený Microsoft: Nie
Iná ImageBase 00000000h
EntryPoint v sekcii:
|_ Celkový počet sekcií: 5
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (47950000) C:\Windows\System32\smss.exe
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Nemá okno
[S, novf!] csrss.exe
Non Microsoft v System32:
Overený Microsoft: Nie
Iná ImageBase 00000000h
EntryPoint v sekcii:
|_ Celkový počet sekcií: 5
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (4A350000) C:\Windows\System32\csrss.exe
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Nemá okno
[S] wininit.exe
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[S, novf!] csrss.exe
Non Microsoft v System32:
Overený Microsoft: Nie
Iná ImageBase 00000000h
EntryPoint v sekcii:
|_ Celkový počet sekcií: 5
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (4A350000) C:\Windows\System32\csrss.exe
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Nemá okno
[S, novf!] winlogon.exe
Non Microsoft v System32:
Overený Microsoft: Nie
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Nemá okno
[S, novf!] services.exe
Non Microsoft v System32:
Overený Microsoft: Nie
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Nemá okno
[S, novf!] lsass.exe
Non Microsoft v System32:
Overený Microsoft: Nie
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (74710000) C:\Windows\System32\msprivs.dll
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Nemá okno
[S, novf!] lsm.exe
Non Microsoft v System32:
Overený Microsoft: Nie
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Nemá okno
[S] svchost.exe
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[S] svchost.exe
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] MsMpEng.exe
Overený Microsoft: Nie
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76780000) C:\Windows\System32\iertutil.dll
Podvrhnutá cesta modulu: (76990000) C:\Windows\System32\urlmon.dll
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76BE0000) C:\Windows\System32\wininet.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Podvrhnutá cesta modulu: (77020000) C:\Windows\System32\psapi.dll
Podvrhnutá cesta modulu: (77030000) C:\Windows\System32\normaliz.dll
[S] svchost.exe
Iná ImageBase 00000000h
EntryPoint v sekcii:
|_ Celkový počet sekcií: 6
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (013D0000) C:\Windows\System32\winlogon.exe
Podvrhnutá cesta modulu: (71DE0000) C:\Windows\System32\wbem\WinMgmtR.dll
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[S] svchost.exe
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (72690000) C:\Windows\System32\sfc.dll
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Podvrhnutá cesta modulu: (77020000) C:\Windows\System32\psapi.dll
[S] svchost.exe
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Podvrhnutá cesta modulu: (77020000) C:\Windows\System32\psapi.dll
[S] svchost.exe
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (72690000) C:\Windows\System32\sfc.dll
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[S] svchost.exe
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Podvrhnutá cesta modulu: (77020000) C:\Windows\System32\psapi.dll
[S, novf!] spoolsv.exe
Non Microsoft v System32:
Overený Microsoft: Nie
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Nemá okno
[S] svchost.exe
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] btwdins.exe
Iná ImageBase 00000000h
EntryPoint v sekcii:
|_ Celkový počet sekcií: 5
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] dsiwmis.exe
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[S] svchost.exe
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] GregHSRW.exe
EntryPoint v sekcii: CODE
|_ Celkový počet sekcií: 8
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] MDM.EXE
Overený Microsoft: Nie
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] IScheduleSvc.exe
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[?] RS_Service.exe
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Nemá okno
Súbor 7%
[?] sp_rsser.exe
Iná ImageBase 00000000h
EntryPoint v sekcii:
|_ Celkový počet sekcií: 6
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Podvrhnutá cesta modulu: (77020000) C:\Windows\System32\psapi.dll
Nemá okno
Súbor 63%
[R] TeamViewer_Service.exe
Rovnaké mená, iná cesta: TEAMVIEWER_SERVICE.EXE X TEAMVIEWER_SERVICE.EXE
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] TeamViewer_Service.exe
Rovnaké mená, iná cesta: TEAMVIEWER_SERVICE.EXE X TEAMVIEWER_SERVICE.EXE
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[?] ULCDRSvr.exe
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Nemá okno
Súbor 7%
[R] UpdaterService.exe
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[?] UTSCSI.EXE
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Nemá okno
Súbor 7%
[R] vmware-usbarbitrator.exe
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] vmnat.exe
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] vmnetdhcp.exe
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] IAANTmon.exe
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] vmware-authd.exe
Podvrhnutá cesta modulu: (72750000) C:\Windows\SysWOW64\atl.dll
Podvrhnutá cesta modulu: (72D50000) C:\Windows\SysWOW64\ktmw32.dll
Podvrhnutá cesta modulu: (740B0000) C:\Windows\SysWOW64\wtsapi32.dll
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] SDWinSec.exe
EntryPoint v sekcii: .ITEXT
|_ Celkový počet sekcií: 9
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] NisSrv.exe
Overený Microsoft: Nie
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[S, novf!] taskhost.exe
Non Microsoft v System32:
Overený Microsoft: Nie
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (74460000) C:\Windows\System32\ksuser.dll
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[S, novf!] dwm.exe
Non Microsoft v System32:
Overený Microsoft: Nie
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Podvrhnutá cesta modulu: (77020000) C:\Windows\System32\psapi.dll
[S] explorer.exe
Spúšťa sa po štarte HKLM Winlogon [Shell]
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (73BF0000) C:\Windows\System32\FXSRESM.dll
Podvrhnutá cesta modulu: (74460000) C:\Windows\System32\ksuser.dll
Podvrhnutá cesta modulu: (76780000) C:\Windows\System32\iertutil.dll
Podvrhnutá cesta modulu: (76990000) C:\Windows\System32\urlmon.dll
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76BE0000) C:\Windows\System32\wininet.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Podvrhnutá cesta modulu: (77020000) C:\Windows\System32\psapi.dll
Podvrhnutá cesta modulu: (77030000) C:\Windows\System32\normaliz.dll
[R] SynTPEnh.exe
Iná ImageBase 00000000h
EntryPoint v sekcii:
|_ Celkový počet sekcií: 5
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (10000000) C:\Windows\System32\SynCOM.dll
Podvrhnutá cesta modulu: (63010000) C:\Windows\System32\SynTPAPI.dll
Podvrhnutá cesta modulu: (76780000) C:\Windows\System32\iertutil.dll
Podvrhnutá cesta modulu: (76990000) C:\Windows\System32\urlmon.dll
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76BE0000) C:\Windows\System32\wininet.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Podvrhnutá cesta modulu: (77020000) C:\Windows\System32\psapi.dll
Podvrhnutá cesta modulu: (77030000) C:\Windows\System32\normaliz.dll
[R] PLFSetI.exe
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[?] igfxtray.exe
Non Microsoft v System32:
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (01B80000) C:\Windows\System32\igfxrsky.lrc
Podvrhnutá cesta modulu: (028D0000) C:\Windows\System32\igfxress.dll
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[?] hkcmd.exe
Non Microsoft v System32:
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (02A00000) C:\Windows\System32\igfxrsky.lrc
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[?] igfxpers.exe
Non Microsoft v System32:
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] msseces.exe
Overený Microsoft: Nie
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76780000) C:\Windows\System32\iertutil.dll
Podvrhnutá cesta modulu: (76990000) C:\Windows\System32\urlmon.dll
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76BE0000) C:\Windows\System32\wininet.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Podvrhnutá cesta modulu: (77020000) C:\Windows\System32\psapi.dll
Podvrhnutá cesta modulu: (77030000) C:\Windows\System32\normaliz.dll
[R] BackupManagerTray.exe
Spúšťa sa po štarte HKLM Run [BackupManagerTray]
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] SynTPHelper.exe
Iná ImageBase 00000000h
EntryPoint v sekcii:
|_ Celkový počet sekcií: 5
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Podvrhnutá cesta modulu: (77020000) C:\Windows\System32\psapi.dll
[R] LManager.exe
Spúšťa sa po štarte HKLM Run [LManager]
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[?] igfxsrvc.exe
Non Microsoft v System32:
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (00320000) C:\Windows\System32\igfxdev.dll
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Nemá okno
[R] jusched.exe
Spúšťa sa po štarte HKLM Run [SunJavaUpdateSched]
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] hqtray.exe
Spúšťa sa po štarte HKLM Run [VMware hqtray]
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[S] SearchIndexer.exe
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Podvrhnutá cesta modulu: (77020000) C:\Windows\System32\psapi.dll
[S] wmpnetwk.exe
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (6FE60000) C:\Windows\System32\wmploc.DLL
Podvrhnutá cesta modulu: (73150000) [DLL] ?
Podvrhnutá cesta modulu: (76780000) C:\Windows\System32\iertutil.dll
Podvrhnutá cesta modulu: (76990000) C:\Windows\System32\urlmon.dll
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76BE0000) C:\Windows\System32\wininet.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Podvrhnutá cesta modulu: (77030000) C:\Windows\System32\normaliz.dll
[R] TOTALCMD.EXE
EntryPoint v sekcii: CODE
|_ Celkový počet sekcií: 8
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] firefox.exe
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] plugin-container.exe
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[?] UPM.exe
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Súbor 7%
Po spustení
================================================================
Služby (Zobraz bežiace: True, Zobraz zastavené: False, Zobraz i bezpečné: False)
================================================================
[X] Application Experience
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\aelupsvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Application Experience Service
| |_ MD5:
|
|_ Meno: AeLookupSvc
|_ StartName: localSystem
|_ Typ spúšťania: Ručné spustenie
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency:
[X] Windows Audio Endpoint Builder
|_ Cesta: C:\Windows\System32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\Audiosrv.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Windows Audio Service
| |_ MD5:
|
|_ Meno: AudioEndpointBuilder
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: PlugPlay
[X] Windows Audio
|_ Cesta: C:\Windows\System32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\Audiosrv.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Windows Audio Service
| |_ MD5:
|
|_ Meno: AudioSrv
|_ StartName: NT AUTHORITY\LocalService
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: AudioEndpointBuilder
[X] Base Filtering Engine
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\bfe.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Base Filtering Engine
| |_ MD5:
|
|_ Meno: BFE
|_ StartName: NT AUTHORITY\LocalService
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: RpcSs
[X] Computer Browser
|_ Cesta: C:\Windows\System32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\browser.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Computer Browser Service DLL
| |_ MD5:
|
|_ Meno: Browser
|_ StartName: LocalSystem
|_ Typ spúšťania: Ručné spustenie
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: LanmanWorkstation
[X] DNS Client
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\dnsrslvr.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: DNS Caching Resolver Service
| |_ MD5:
|
|_ Meno: Dnscache
|_ StartName: NT AUTHORITY\NetworkService
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: Tdx
[X] Function Discovery Provider Host
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\fdPHost.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Function Discovery Provider host service
| |_ MD5:
|
|_ Meno: fdPHost
|_ StartName: NT AUTHORITY\LocalService
|_ Typ spúšťania: Ručné spustenie
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: RpcSs
[X] Function Discovery Resource Publication
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\fdrespub.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Function Discovery Resource Publication Service
| |_ MD5:
|
|_ Meno: FDResPub
|_ StartName: NT AUTHORITY\LocalService
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: RpcSs
[X] Windows Font Cache Service
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\FntCache.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Windows Font Cache Service
| |_ MD5:
|
|_ Meno: FontCache
|_ StartName: NT AUTHORITY\LocalService
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency:
[X] IKE and AuthIP IPsec Keying Modules
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\ikeext.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: IKE extension
| |_ MD5:
|
|_ Meno: IKEEXT
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: BFE
[X] IP Helper
|_ Cesta: C:\Windows\System32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\iphlpsvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Service that offers IPv6 connectivity over an IPv4 network.
| |_ MD5:
|
|_ Meno: iphlpsvc
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: RpcSS
[X] CNG Key Isolation
|_ Cesta: C:\Windows\system32\lsass.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Local Security Authority Process
| |_ MD5:
|
|_ Meno: KeyIso
|_ StartName: LocalSystem
|_ Typ spúšťania: Ručné spustenie
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: RpcSs
[X] Server
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\srvsvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Server Service DLL
| |_ MD5:
|
|_ Meno: LanmanServer
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: SamSS
[X] Workstation
|_ Cesta: C:\Windows\System32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\wkssvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Workstation Service DLL
| |_ MD5:
|
|_ Meno: LanmanWorkstation
|_ StartName: NT AUTHORITY\NetworkService
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: Bowser
[X] TCP/IP NetBIOS Helper
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\lmhsvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: TCPIP NetBios Transport Services DLL
| |_ MD5:
|
|_ Meno: lmhosts
|_ StartName: NT AUTHORITY\LocalService
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: NetBT
[X] Multimedia Class Scheduler
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\mmcss.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Multimedia Class Scheduler Service
| |_ MD5:
|
|_ Meno: MMCSS
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Zastavené
|_ Typ: Win32 Share Process
|_ Dependency:
[X] Brána Windows Firewall
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\mpssvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Služba MPS (Microsoft Protection Service)
| |_ MD5:
|
|_ Meno: MpsSvc
|_ StartName: NT Authority\LocalService
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: mpsdrv
[X] Sieťové pripojenia
|_ Cesta: C:\Windows\System32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\netman.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Network Connections Manager
| |_ MD5:
|
|_ Meno: Netman
|_ StartName: LocalSystem
|_ Typ spúšťania: Ručné spustenie
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: RpcSs
[X] Network Location Awareness
|_ Cesta: C:\Windows\System32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\nlasvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Network Location Awareness 2
| |_ MD5:
|
|_ Meno: NlaSvc
|_ StartName: NT AUTHORITY\NetworkService
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: NSI
[X] Network Store Interface Service
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\nsisvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Network Store Interface RPC server
| |_ MD5:
|
|_ Meno: nsi
|_ StartName: NT Authority\LocalService
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: nsiproxy
[X] Program Compatibility Assistant Service
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\pcasvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Program Compatibility Assistant Service
| |_ MD5:
|
|_ Meno: PcaSvc
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: RpcSs
[X] Plug and Play
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\umpnpmgr.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: User-mode Plug-and-Play Service
| |_ MD5:
|
|_ Meno: PlugPlay
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency:
[X] Power
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\umpo.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: User-mode Power Service
| |_ MD5:
|
|_ Meno: Power
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency:
[X] User Profile Service
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\profsvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: ProfSvc
| |_ MD5:
|
|_ Meno: ProfSvc
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: RpcSs
[X] Remote Access Connection Manager
|_ Cesta: C:\Windows\System32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\rasmans.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Remote Access Connection Manager
| |_ MD5:
|
|_ Meno: RasMan
|_ StartName: localSystem
|_ Typ spúšťania: Ručné spustenie
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: Tapisrv
[X] RPC Endpoint Mapper
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\RpcEpMap.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: RPC Endpoint Mapper
| |_ MD5:
|
|_ Meno: RpcEptMapper
|_ StartName: NT AUTHORITY\NetworkService
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency:
[?] Raw Socket Service
|_ Cesta: C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe
| |_ Výrobca: Acer Incorporated
| |_ Popis: Raw Socket Service
| |_ MD5: B5A4B7D779CF4070DF408DE18BD33B02
|
|_ Meno: RS_Service
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Own Process
|_ Dependency:
[X] Security Accounts Manager
|_ Cesta: C:\Windows\system32\lsass.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Local Security Authority Process
| |_ MD5:
|
|_ Meno: SamSs
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: RPCSS
[X] Plánovač úloh
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\schedsvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Task Scheduler Service
| |_ MD5:
|
|_ Meno: Schedule
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: RPCSS
[X] Print Spooler
|_ Cesta: C:\Windows\System32\spoolsv.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Spooler SubSystem App
| |_ MD5:
|
|_ Meno: Spooler
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ:
|_ Dependency: RPCSS
[X] Software Protection
|_ Cesta: C:\Windows\system32\sppsvc.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Microsoft Software Protection Platform Service
| |_ MD5:
|
|_ Meno: sppsvc
|_ StartName: NT AUTHORITY\NetworkService
|_ Typ spúšťania: Auto Start
|_ Status: Zastavené
|_ Typ: Win32 Own Process
|_ Dependency: RpcSs
[!] Spyware Terminator Realtime Shield Service
|_ Cesta: C:\Program Files (x86)\Spyware Terminator\sp_rsser.exe
| |_ Výrobca: Xacti LLC
| |_ Popis:
| |_ MD5: C7F6DBE915AF3A17772690135A9DD5E0
|
|_ Meno: sp_rssrv
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Own Process
|_ Dependency:
[X] SSDP Discovery
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\ssdpsrv.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: SSDP Service DLL
| |_ MD5:
|
|_ Meno: SSDPSRV
|_ StartName: NT AUTHORITY\LocalService
|_ Typ spúšťania: Ručné spustenie
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: HTTP
[X] Secure Socket Tunneling Protocol Service
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\sstpsvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Provides the facility of using Secure Socket Tunneling Protocol (SSTP) to connect to remote computers (using VPN).
| |_ MD5:
|
|_ Meno: SstpSvc
|_ StartName: NT Authority\LocalService
|_ Typ spúšťania: Ručné spustenie
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency:
[X] Rýchle načítanie
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\sysmain.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Hostiteľ služby rýchleho načítania
| |_ MD5:
|
|_ Meno: SysMain
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: rpcss
[X] Themes
|_ Cesta: C:\Windows\System32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\themeservice.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Windows Shell Theme Service Dll
| |_ MD5:
|
|_ Meno: Themes
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency:
[?] Ulead Burning Helper
|_ Cesta: C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
| |_ Výrobca: Ulead Systems, Inc.
| |_ Popis: ULCDRSvr
| |_ MD5: 332D341D92B933600D41953B08360DFB
|
|_ Meno: UleadBurningHelper
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Own Process
|_ Dependency:
[?] CLCV0
|_ Cesta: C:\Windows\system32\UTSCSI.EXE
| |_ Výrobca:
| |_ Popis: UTSCSI Application
| |_ MD5: 8AFFFDA081CFF3057391FEDBBB483601
|
|_ Meno: UTSCSI
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Own Process
|_ Dependency:
[X] Správca relácie Správcu okien na pracovnej ploche
|_ Cesta: C:\Windows\System32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\uxsms.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Microsoft User Experience Session Management Service
| |_ MD5:
|
|_ Meno: UxSms
|_ StartName: localSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency:
[X] Windows Management Instrumentation
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\wbem\WMIsvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: WMI
| |_ MD5:
|
|_ Meno: Winmgmt
|_ StartName: localSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: RPCSS
[X] WLAN AutoConfig
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\wlansvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Windows WLAN AutoConfig Service DLL
| |_ MD5:
|
|_ Meno: Wlansvc
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: nativewifip
[X] Security Center
|_ Cesta: C:\Windows\System32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\wscsvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Windows Security Center Service
| |_ MD5:
|
|_ Meno: wscsvc
|_ StartName: NT AUTHORITY\LocalService
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: RpcSs
[X] Windows Update
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\wuaueng.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Windows Update Agent
| |_ MD5:
|
|_ Meno: wuauserv
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: rpcss
[X] Windows Driver Foundation - User-mode Driver Framework
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\WUDFSvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Windows Driver Foundation - User-mode Driver Framework Service
| |_ MD5:
|
|_ Meno: wudfsvc
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: PlugPlay
Moduly (Zobraz i bezpečné: False, Len bez výrobcu: True, Zobraz registrované: False)
================================================================
[?] msdbg2.dll
|_ Cesta: C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\MSDBG2.DLL
|_ MD5: 39DCDEF85186EEB902AF449D0C6CB6E4
|_ Výrobca: Microsoft Corporation
|_ Procesy
|_ MDM.EXE (1676)
[?] vssagent.dll
|_ Cesta: C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\VssAgent.dll
|_ MD5: F672257134F8045A7B0D66A0833D472F
|_ Výrobca: NewTech Infosystems, Inc.
|_ Procesy
|_ IScheduleSvc.exe (1712)
[?] ishadows3.dll
|_ Cesta: C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IShadowS3.dll
|_ MD5: 14810D7E49716579D1EDC8497CFB1971
|_ Výrobca: NewTech Infosystems, Inc.
|_ Procesy
|_ IScheduleSvc.exe (1712)
[?] pehook.dll
|_ Cesta: C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\Pehook.dll
|_ MD5: 7E6C97FB645C2925DF60228959E10551
|_ Výrobca: NewTech Infosystems, Inc.
|_ Procesy
|_ IScheduleSvc.exe (1712)
[?] ace.dll
|_ Cesta: C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\ACE.dll
|_ MD5: 484B0D16F7D2A1BF51E84D6A9636E0B1
|_ Výrobca: ?
|_ Procesy
|_ IScheduleSvc.exe (1712)
[?] ischedule.dll
|_ Cesta: C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\ISchedule.dll
|_ MD5: B3C57558A2FFB99BD5FFD0941B8B4115
|_ Výrobca: NewTech Infosystems, Inc.
|_ Procesy
|_ IScheduleSvc.exe (1712)
[?] sqlite3.dll
|_ Cesta: C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\sqlite3.dll
|_ MD5: BD8146312FFE5F51DA66E7725E989E36
|_ Výrobca:
|_ Procesy
|_ IScheduleSvc.exe (1712)
|_ BackupManagerTray.exe (2676)
[?] wirelessdll.dll
|_ Cesta: C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\WirelessDll.dll
|_ MD5: C2F7BDB29D6399593A7DD0E91FAC818A
|_ Výrobca: NewTech Infosystems, Inc.
|_ Procesy
|_ IScheduleSvc.exe (1712)
[?] agent_stub.dll
|_ Cesta: C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\agent_stub.dll
|_ MD5: 9CFCFE18966B3D9F4682FC6990F96F55
|_ Výrobca: NewTech Infosystems, Inc.
|_ Procesy
|_ IScheduleSvc.exe (1712)
[?] pluginraid_enu.dll
|_ Cesta: C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\ENU\PlugInRAID_ENU.dll
|_ MD5: 15C42334805B711FBF0C788A1D751528
|_ Výrobca: Intel Corporation
|_ Procesy
|_ IAANTmon.exe (1108)
[?] isdi.dll
|_ Cesta: C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\ISDI.dll
|_ MD5: 984BDAC9F4FC9993CE8D3A7D7DA3E9A5
|_ Výrobca: Intel Corporation
|_ Procesy
|_ IAANTmon.exe (1108)
[?] upm.dll
|_ Cesta: C:\Program Files (x86)\Ultimate Process Manager\upm.dll
|_ MD5: 9D9AA74910EE283E95214ABEADC779BD
|_ Výrobca: Lodus Software
|_ Procesy
|_ UPM.exe (2648)
[!] prjxtab.ocx
|_ Cesta: C:\Program Files (x86)\Ultimate Process Manager\prjXTab.ocx
|_ MD5: DE745F09FC7C607841519AD559C33AC3
|_ Výrobca: xyz
|_ Procesy
|_ UPM.exe (2648)
================================================================
Ultimate Process Manager v4.1.3 - [ Lodus Software ]
Windows Vista SP 1 (build 7601)
Boot Mode: Normal
Overení sůborů Microsoftu: Nie
Whitelist: Nie
Internet Explorer v9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)
Log vygenerovaný:10. 7. 2011 20:04:41
================================================================
Bežiace procesy
================================================================
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WININIT.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\WINDOWS\SYSTEM32\LSM.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\MICROSOFT SECURITY CLIENT\ANTIMALWARE\MSMPENG.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\WIDCOMM\BLUETOOTH SOFTWARE\BTWDINS.EXE
C:\PROGRAM FILES (X86)\LAUNCH MANAGER\DSIWMIS.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES (X86)\ACER\REGISTRATION\GREGHSRW.EXE
C:\PROGRAM FILES (X86)\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\MDM.EXE
C:\PROGRAM FILES (X86)\NEWTECH INFOSYSTEMS\ACER BACKUP MANAGER\ISCHEDULESVC.EXE
C:\PROGRAM FILES (X86)\ACER\ACER VCM\RS_SERVICE.EXE
C:\PROGRAM FILES (X86)\SPYWARE TERMINATOR\SP_RSSER.EXE
C:\PROGRAM FILES (X86)\TEAMVIEWER\VERSION5\TEAMVIEWER_SERVICE.EXE
C:\PROGRAM FILES (X86)\TEAMVIEWER\VERSION6\TEAMVIEWER_SERVICE.EXE
C:\PROGRAM FILES (X86)\COMMON FILES\ULEAD SYSTEMS\DVD\ULCDRSVR.EXE
C:\PROGRAM FILES\ACER\ACER UPDATER\UPDATERSERVICE.EXE
C:\WINDOWS\SYSWOW64\UTSCSI.EXE
C:\PROGRAM FILES (X86)\COMMON FILES\VMWARE\USB\VMWARE-USBARBITRATOR.EXE
C:\WINDOWS\SYSWOW64\VMNAT.EXE
C:\WINDOWS\SYSWOW64\VMNETDHCP.EXE
C:\PROGRAM FILES (X86)\INTEL\INTEL MATRIX STORAGE MANAGER\IAANTMON.EXE
C:\PROGRAM FILES (X86)\VMWARE\VMWARE PLAYER\VMWARE-AUTHD.EXE
C:\PROGRAM FILES (X86)\SPYBOT - SEARCH & DESTROY\SDWINSEC.EXE
C:\PROGRAM FILES\MICROSOFT SECURITY CLIENT\ANTIMALWARE\NISSRV.EXE
C:\WINDOWS\SYSTEM32\TASKHOST.EXE
C:\WINDOWS\SYSTEM32\DWM.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPENH.EXE
C:\WINDOWS\PLFSETI.EXE
C:\WINDOWS\SYSTEM32\IGFXTRAY.EXE
C:\WINDOWS\SYSTEM32\HKCMD.EXE
C:\WINDOWS\SYSTEM32\IGFXPERS.EXE
C:\PROGRAM FILES\MICROSOFT SECURITY CLIENT\MSSECES.EXE
C:\PROGRAM FILES (X86)\NEWTECH INFOSYSTEMS\ACER BACKUP MANAGER\BACKUPMANAGERTRAY.EXE
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\PROGRAM FILES (X86)\LAUNCH MANAGER\LMANAGER.EXE
C:\WINDOWS\SYSTEM32\IGFXSRVC.EXE
C:\PROGRAM FILES (X86)\COMMON FILES\JAVA\JAVA UPDATE\JUSCHED.EXE
C:\PROGRAM FILES (X86)\VMWARE\VMWARE PLAYER\HQTRAY.EXE
C:\WINDOWS\SYSTEM32\SEARCHINDEXER.EXE
C:\PROGRAM FILES\WINDOWS MEDIA PLAYER\WMPNETWK.EXE
C:\TOTALCMD\TOTALCMD.EXE
C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE
C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\PLUGIN-CONTAINER.EXE
C:\PROGRAM FILES (X86)\ULTIMATE PROCESS MANAGER\UPM.EXE
Scanner
================================================================
[S, novf!] smss.exe
Non Microsoft v System32:
Overený Microsoft: Nie
Iná ImageBase 00000000h
EntryPoint v sekcii:
|_ Celkový počet sekcií: 5
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (47950000) C:\Windows\System32\smss.exe
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Nemá okno
[S, novf!] csrss.exe
Non Microsoft v System32:
Overený Microsoft: Nie
Iná ImageBase 00000000h
EntryPoint v sekcii:
|_ Celkový počet sekcií: 5
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (4A350000) C:\Windows\System32\csrss.exe
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Nemá okno
[S] wininit.exe
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[S, novf!] csrss.exe
Non Microsoft v System32:
Overený Microsoft: Nie
Iná ImageBase 00000000h
EntryPoint v sekcii:
|_ Celkový počet sekcií: 5
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (4A350000) C:\Windows\System32\csrss.exe
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Nemá okno
[S, novf!] winlogon.exe
Non Microsoft v System32:
Overený Microsoft: Nie
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Nemá okno
[S, novf!] services.exe
Non Microsoft v System32:
Overený Microsoft: Nie
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Nemá okno
[S, novf!] lsass.exe
Non Microsoft v System32:
Overený Microsoft: Nie
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (74710000) C:\Windows\System32\msprivs.dll
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Nemá okno
[S, novf!] lsm.exe
Non Microsoft v System32:
Overený Microsoft: Nie
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Nemá okno
[S] svchost.exe
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[S] svchost.exe
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] MsMpEng.exe
Overený Microsoft: Nie
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76780000) C:\Windows\System32\iertutil.dll
Podvrhnutá cesta modulu: (76990000) C:\Windows\System32\urlmon.dll
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76BE0000) C:\Windows\System32\wininet.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Podvrhnutá cesta modulu: (77020000) C:\Windows\System32\psapi.dll
Podvrhnutá cesta modulu: (77030000) C:\Windows\System32\normaliz.dll
[S] svchost.exe
Iná ImageBase 00000000h
EntryPoint v sekcii:
|_ Celkový počet sekcií: 6
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (013D0000) C:\Windows\System32\winlogon.exe
Podvrhnutá cesta modulu: (71DE0000) C:\Windows\System32\wbem\WinMgmtR.dll
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[S] svchost.exe
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (72690000) C:\Windows\System32\sfc.dll
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Podvrhnutá cesta modulu: (77020000) C:\Windows\System32\psapi.dll
[S] svchost.exe
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Podvrhnutá cesta modulu: (77020000) C:\Windows\System32\psapi.dll
[S] svchost.exe
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (72690000) C:\Windows\System32\sfc.dll
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[S] svchost.exe
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Podvrhnutá cesta modulu: (77020000) C:\Windows\System32\psapi.dll
[S, novf!] spoolsv.exe
Non Microsoft v System32:
Overený Microsoft: Nie
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Nemá okno
[S] svchost.exe
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] btwdins.exe
Iná ImageBase 00000000h
EntryPoint v sekcii:
|_ Celkový počet sekcií: 5
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] dsiwmis.exe
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[S] svchost.exe
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] GregHSRW.exe
EntryPoint v sekcii: CODE
|_ Celkový počet sekcií: 8
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] MDM.EXE
Overený Microsoft: Nie
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] IScheduleSvc.exe
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[?] RS_Service.exe
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Nemá okno
Súbor 7%
[?] sp_rsser.exe
Iná ImageBase 00000000h
EntryPoint v sekcii:
|_ Celkový počet sekcií: 6
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Podvrhnutá cesta modulu: (77020000) C:\Windows\System32\psapi.dll
Nemá okno
Súbor 63%
[R] TeamViewer_Service.exe
Rovnaké mená, iná cesta: TEAMVIEWER_SERVICE.EXE X TEAMVIEWER_SERVICE.EXE
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] TeamViewer_Service.exe
Rovnaké mená, iná cesta: TEAMVIEWER_SERVICE.EXE X TEAMVIEWER_SERVICE.EXE
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[?] ULCDRSvr.exe
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Nemá okno
Súbor 7%
[R] UpdaterService.exe
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[?] UTSCSI.EXE
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Nemá okno
Súbor 7%
[R] vmware-usbarbitrator.exe
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] vmnat.exe
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] vmnetdhcp.exe
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] IAANTmon.exe
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] vmware-authd.exe
Podvrhnutá cesta modulu: (72750000) C:\Windows\SysWOW64\atl.dll
Podvrhnutá cesta modulu: (72D50000) C:\Windows\SysWOW64\ktmw32.dll
Podvrhnutá cesta modulu: (740B0000) C:\Windows\SysWOW64\wtsapi32.dll
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] SDWinSec.exe
EntryPoint v sekcii: .ITEXT
|_ Celkový počet sekcií: 9
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] NisSrv.exe
Overený Microsoft: Nie
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[S, novf!] taskhost.exe
Non Microsoft v System32:
Overený Microsoft: Nie
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (74460000) C:\Windows\System32\ksuser.dll
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[S, novf!] dwm.exe
Non Microsoft v System32:
Overený Microsoft: Nie
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Podvrhnutá cesta modulu: (77020000) C:\Windows\System32\psapi.dll
[S] explorer.exe
Spúšťa sa po štarte HKLM Winlogon [Shell]
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (73BF0000) C:\Windows\System32\FXSRESM.dll
Podvrhnutá cesta modulu: (74460000) C:\Windows\System32\ksuser.dll
Podvrhnutá cesta modulu: (76780000) C:\Windows\System32\iertutil.dll
Podvrhnutá cesta modulu: (76990000) C:\Windows\System32\urlmon.dll
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76BE0000) C:\Windows\System32\wininet.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Podvrhnutá cesta modulu: (77020000) C:\Windows\System32\psapi.dll
Podvrhnutá cesta modulu: (77030000) C:\Windows\System32\normaliz.dll
[R] SynTPEnh.exe
Iná ImageBase 00000000h
EntryPoint v sekcii:
|_ Celkový počet sekcií: 5
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (10000000) C:\Windows\System32\SynCOM.dll
Podvrhnutá cesta modulu: (63010000) C:\Windows\System32\SynTPAPI.dll
Podvrhnutá cesta modulu: (76780000) C:\Windows\System32\iertutil.dll
Podvrhnutá cesta modulu: (76990000) C:\Windows\System32\urlmon.dll
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76BE0000) C:\Windows\System32\wininet.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Podvrhnutá cesta modulu: (77020000) C:\Windows\System32\psapi.dll
Podvrhnutá cesta modulu: (77030000) C:\Windows\System32\normaliz.dll
[R] PLFSetI.exe
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[?] igfxtray.exe
Non Microsoft v System32:
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (01B80000) C:\Windows\System32\igfxrsky.lrc
Podvrhnutá cesta modulu: (028D0000) C:\Windows\System32\igfxress.dll
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[?] hkcmd.exe
Non Microsoft v System32:
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (02A00000) C:\Windows\System32\igfxrsky.lrc
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[?] igfxpers.exe
Non Microsoft v System32:
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] msseces.exe
Overený Microsoft: Nie
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76780000) C:\Windows\System32\iertutil.dll
Podvrhnutá cesta modulu: (76990000) C:\Windows\System32\urlmon.dll
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76BE0000) C:\Windows\System32\wininet.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Podvrhnutá cesta modulu: (77020000) C:\Windows\System32\psapi.dll
Podvrhnutá cesta modulu: (77030000) C:\Windows\System32\normaliz.dll
[R] BackupManagerTray.exe
Spúšťa sa po štarte HKLM Run [BackupManagerTray]
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] SynTPHelper.exe
Iná ImageBase 00000000h
EntryPoint v sekcii:
|_ Celkový počet sekcií: 5
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Podvrhnutá cesta modulu: (77020000) C:\Windows\System32\psapi.dll
[R] LManager.exe
Spúšťa sa po štarte HKLM Run [LManager]
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[?] igfxsrvc.exe
Non Microsoft v System32:
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (00320000) C:\Windows\System32\igfxdev.dll
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Nemá okno
[R] jusched.exe
Spúšťa sa po štarte HKLM Run [SunJavaUpdateSched]
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] hqtray.exe
Spúšťa sa po štarte HKLM Run [VMware hqtray]
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[S] SearchIndexer.exe
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Podvrhnutá cesta modulu: (77020000) C:\Windows\System32\psapi.dll
[S] wmpnetwk.exe
Iná ImageBase 00000000h
BaseAddress
Skrytá cesta EXE:
Podvrhnutá cesta modulu: (6FE60000) C:\Windows\System32\wmploc.DLL
Podvrhnutá cesta modulu: (73150000) [DLL] ?
Podvrhnutá cesta modulu: (76780000) C:\Windows\System32\iertutil.dll
Podvrhnutá cesta modulu: (76990000) C:\Windows\System32\urlmon.dll
Podvrhnutá cesta modulu: (76AE0000) C:\Windows\System32\user32.dll
Podvrhnutá cesta modulu: (76BE0000) C:\Windows\System32\wininet.dll
Podvrhnutá cesta modulu: (76D40000) C:\Windows\System32\kernel32.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Podvrhnutá cesta modulu: (77030000) C:\Windows\System32\normaliz.dll
[R] TOTALCMD.EXE
EntryPoint v sekcii: CODE
|_ Celkový počet sekcií: 8
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] firefox.exe
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[R] plugin-container.exe
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
[?] UPM.exe
Podvrhnutá cesta modulu: (74140000) C:\Windows\System32\wow64cpu.dll
Podvrhnutá cesta modulu: (74150000) C:\Windows\System32\wow64win.dll
Podvrhnutá cesta modulu: (741B0000) C:\Windows\System32\wow64.dll
Podvrhnutá cesta modulu: (76E60000) C:\Windows\System32\ntdll.dll
Súbor 7%
Po spustení
================================================================
Služby (Zobraz bežiace: True, Zobraz zastavené: False, Zobraz i bezpečné: False)
================================================================
[X] Application Experience
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\aelupsvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Application Experience Service
| |_ MD5:
|
|_ Meno: AeLookupSvc
|_ StartName: localSystem
|_ Typ spúšťania: Ručné spustenie
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency:
[X] Windows Audio Endpoint Builder
|_ Cesta: C:\Windows\System32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\Audiosrv.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Windows Audio Service
| |_ MD5:
|
|_ Meno: AudioEndpointBuilder
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: PlugPlay
[X] Windows Audio
|_ Cesta: C:\Windows\System32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\Audiosrv.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Windows Audio Service
| |_ MD5:
|
|_ Meno: AudioSrv
|_ StartName: NT AUTHORITY\LocalService
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: AudioEndpointBuilder
[X] Base Filtering Engine
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\bfe.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Base Filtering Engine
| |_ MD5:
|
|_ Meno: BFE
|_ StartName: NT AUTHORITY\LocalService
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: RpcSs
[X] Computer Browser
|_ Cesta: C:\Windows\System32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\browser.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Computer Browser Service DLL
| |_ MD5:
|
|_ Meno: Browser
|_ StartName: LocalSystem
|_ Typ spúšťania: Ručné spustenie
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: LanmanWorkstation
[X] DNS Client
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\dnsrslvr.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: DNS Caching Resolver Service
| |_ MD5:
|
|_ Meno: Dnscache
|_ StartName: NT AUTHORITY\NetworkService
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: Tdx
[X] Function Discovery Provider Host
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\fdPHost.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Function Discovery Provider host service
| |_ MD5:
|
|_ Meno: fdPHost
|_ StartName: NT AUTHORITY\LocalService
|_ Typ spúšťania: Ručné spustenie
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: RpcSs
[X] Function Discovery Resource Publication
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\fdrespub.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Function Discovery Resource Publication Service
| |_ MD5:
|
|_ Meno: FDResPub
|_ StartName: NT AUTHORITY\LocalService
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: RpcSs
[X] Windows Font Cache Service
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\FntCache.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Windows Font Cache Service
| |_ MD5:
|
|_ Meno: FontCache
|_ StartName: NT AUTHORITY\LocalService
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency:
[X] IKE and AuthIP IPsec Keying Modules
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\ikeext.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: IKE extension
| |_ MD5:
|
|_ Meno: IKEEXT
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: BFE
[X] IP Helper
|_ Cesta: C:\Windows\System32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\iphlpsvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Service that offers IPv6 connectivity over an IPv4 network.
| |_ MD5:
|
|_ Meno: iphlpsvc
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: RpcSS
[X] CNG Key Isolation
|_ Cesta: C:\Windows\system32\lsass.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Local Security Authority Process
| |_ MD5:
|
|_ Meno: KeyIso
|_ StartName: LocalSystem
|_ Typ spúšťania: Ručné spustenie
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: RpcSs
[X] Server
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\srvsvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Server Service DLL
| |_ MD5:
|
|_ Meno: LanmanServer
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: SamSS
[X] Workstation
|_ Cesta: C:\Windows\System32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\wkssvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Workstation Service DLL
| |_ MD5:
|
|_ Meno: LanmanWorkstation
|_ StartName: NT AUTHORITY\NetworkService
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: Bowser
[X] TCP/IP NetBIOS Helper
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\lmhsvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: TCPIP NetBios Transport Services DLL
| |_ MD5:
|
|_ Meno: lmhosts
|_ StartName: NT AUTHORITY\LocalService
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: NetBT
[X] Multimedia Class Scheduler
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\mmcss.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Multimedia Class Scheduler Service
| |_ MD5:
|
|_ Meno: MMCSS
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Zastavené
|_ Typ: Win32 Share Process
|_ Dependency:
[X] Brána Windows Firewall
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\mpssvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Služba MPS (Microsoft Protection Service)
| |_ MD5:
|
|_ Meno: MpsSvc
|_ StartName: NT Authority\LocalService
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: mpsdrv
[X] Sieťové pripojenia
|_ Cesta: C:\Windows\System32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\netman.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Network Connections Manager
| |_ MD5:
|
|_ Meno: Netman
|_ StartName: LocalSystem
|_ Typ spúšťania: Ručné spustenie
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: RpcSs
[X] Network Location Awareness
|_ Cesta: C:\Windows\System32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\nlasvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Network Location Awareness 2
| |_ MD5:
|
|_ Meno: NlaSvc
|_ StartName: NT AUTHORITY\NetworkService
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: NSI
[X] Network Store Interface Service
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\nsisvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Network Store Interface RPC server
| |_ MD5:
|
|_ Meno: nsi
|_ StartName: NT Authority\LocalService
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: nsiproxy
[X] Program Compatibility Assistant Service
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\pcasvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Program Compatibility Assistant Service
| |_ MD5:
|
|_ Meno: PcaSvc
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: RpcSs
[X] Plug and Play
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\umpnpmgr.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: User-mode Plug-and-Play Service
| |_ MD5:
|
|_ Meno: PlugPlay
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency:
[X] Power
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\umpo.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: User-mode Power Service
| |_ MD5:
|
|_ Meno: Power
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency:
[X] User Profile Service
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\profsvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: ProfSvc
| |_ MD5:
|
|_ Meno: ProfSvc
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: RpcSs
[X] Remote Access Connection Manager
|_ Cesta: C:\Windows\System32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\rasmans.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Remote Access Connection Manager
| |_ MD5:
|
|_ Meno: RasMan
|_ StartName: localSystem
|_ Typ spúšťania: Ručné spustenie
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: Tapisrv
[X] RPC Endpoint Mapper
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\RpcEpMap.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: RPC Endpoint Mapper
| |_ MD5:
|
|_ Meno: RpcEptMapper
|_ StartName: NT AUTHORITY\NetworkService
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency:
[?] Raw Socket Service
|_ Cesta: C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe
| |_ Výrobca: Acer Incorporated
| |_ Popis: Raw Socket Service
| |_ MD5: B5A4B7D779CF4070DF408DE18BD33B02
|
|_ Meno: RS_Service
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Own Process
|_ Dependency:
[X] Security Accounts Manager
|_ Cesta: C:\Windows\system32\lsass.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Local Security Authority Process
| |_ MD5:
|
|_ Meno: SamSs
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: RPCSS
[X] Plánovač úloh
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\schedsvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Task Scheduler Service
| |_ MD5:
|
|_ Meno: Schedule
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: RPCSS
[X] Print Spooler
|_ Cesta: C:\Windows\System32\spoolsv.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Spooler SubSystem App
| |_ MD5:
|
|_ Meno: Spooler
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ:
|_ Dependency: RPCSS
[X] Software Protection
|_ Cesta: C:\Windows\system32\sppsvc.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Microsoft Software Protection Platform Service
| |_ MD5:
|
|_ Meno: sppsvc
|_ StartName: NT AUTHORITY\NetworkService
|_ Typ spúšťania: Auto Start
|_ Status: Zastavené
|_ Typ: Win32 Own Process
|_ Dependency: RpcSs
[!] Spyware Terminator Realtime Shield Service
|_ Cesta: C:\Program Files (x86)\Spyware Terminator\sp_rsser.exe
| |_ Výrobca: Xacti LLC
| |_ Popis:
| |_ MD5: C7F6DBE915AF3A17772690135A9DD5E0
|
|_ Meno: sp_rssrv
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Own Process
|_ Dependency:
[X] SSDP Discovery
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\ssdpsrv.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: SSDP Service DLL
| |_ MD5:
|
|_ Meno: SSDPSRV
|_ StartName: NT AUTHORITY\LocalService
|_ Typ spúšťania: Ručné spustenie
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: HTTP
[X] Secure Socket Tunneling Protocol Service
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\sstpsvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Provides the facility of using Secure Socket Tunneling Protocol (SSTP) to connect to remote computers (using VPN).
| |_ MD5:
|
|_ Meno: SstpSvc
|_ StartName: NT Authority\LocalService
|_ Typ spúšťania: Ručné spustenie
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency:
[X] Rýchle načítanie
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\sysmain.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Hostiteľ služby rýchleho načítania
| |_ MD5:
|
|_ Meno: SysMain
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: rpcss
[X] Themes
|_ Cesta: C:\Windows\System32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\themeservice.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Windows Shell Theme Service Dll
| |_ MD5:
|
|_ Meno: Themes
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency:
[?] Ulead Burning Helper
|_ Cesta: C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
| |_ Výrobca: Ulead Systems, Inc.
| |_ Popis: ULCDRSvr
| |_ MD5: 332D341D92B933600D41953B08360DFB
|
|_ Meno: UleadBurningHelper
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Own Process
|_ Dependency:
[?] CLCV0
|_ Cesta: C:\Windows\system32\UTSCSI.EXE
| |_ Výrobca:
| |_ Popis: UTSCSI Application
| |_ MD5: 8AFFFDA081CFF3057391FEDBBB483601
|
|_ Meno: UTSCSI
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Own Process
|_ Dependency:
[X] Správca relácie Správcu okien na pracovnej ploche
|_ Cesta: C:\Windows\System32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\uxsms.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Microsoft User Experience Session Management Service
| |_ MD5:
|
|_ Meno: UxSms
|_ StartName: localSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency:
[X] Windows Management Instrumentation
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\wbem\WMIsvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: WMI
| |_ MD5:
|
|_ Meno: Winmgmt
|_ StartName: localSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: RPCSS
[X] WLAN AutoConfig
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\wlansvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Windows WLAN AutoConfig Service DLL
| |_ MD5:
|
|_ Meno: Wlansvc
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: nativewifip
[X] Security Center
|_ Cesta: C:\Windows\System32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\wscsvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Windows Security Center Service
| |_ MD5:
|
|_ Meno: wscsvc
|_ StartName: NT AUTHORITY\LocalService
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: RpcSs
[X] Windows Update
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\system32\wuaueng.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Windows Update Agent
| |_ MD5:
|
|_ Meno: wuauserv
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: rpcss
[X] Windows Driver Foundation - User-mode Driver Framework
|_ Cesta: C:\Windows\system32\svchost.exe
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Host Process for Windows Services
| |_ MD5: 54A47F6B5E09A77E61649109C6A08866
|
|_ ServiceDLL: C:\Windows\System32\WUDFSvc.dll
| |_ Výrobca: Microsoft Corporation
| |_ Popis: Windows Driver Foundation - User-mode Driver Framework Service
| |_ MD5:
|
|_ Meno: wudfsvc
|_ StartName: LocalSystem
|_ Typ spúšťania: Auto Start
|_ Status: Spustené
|_ Typ: Win32 Share Process
|_ Dependency: PlugPlay
Moduly (Zobraz i bezpečné: False, Len bez výrobcu: True, Zobraz registrované: False)
================================================================
[?] msdbg2.dll
|_ Cesta: C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\MSDBG2.DLL
|_ MD5: 39DCDEF85186EEB902AF449D0C6CB6E4
|_ Výrobca: Microsoft Corporation
|_ Procesy
|_ MDM.EXE (1676)
[?] vssagent.dll
|_ Cesta: C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\VssAgent.dll
|_ MD5: F672257134F8045A7B0D66A0833D472F
|_ Výrobca: NewTech Infosystems, Inc.
|_ Procesy
|_ IScheduleSvc.exe (1712)
[?] ishadows3.dll
|_ Cesta: C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IShadowS3.dll
|_ MD5: 14810D7E49716579D1EDC8497CFB1971
|_ Výrobca: NewTech Infosystems, Inc.
|_ Procesy
|_ IScheduleSvc.exe (1712)
[?] pehook.dll
|_ Cesta: C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\Pehook.dll
|_ MD5: 7E6C97FB645C2925DF60228959E10551
|_ Výrobca: NewTech Infosystems, Inc.
|_ Procesy
|_ IScheduleSvc.exe (1712)
[?] ace.dll
|_ Cesta: C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\ACE.dll
|_ MD5: 484B0D16F7D2A1BF51E84D6A9636E0B1
|_ Výrobca: ?
|_ Procesy
|_ IScheduleSvc.exe (1712)
[?] ischedule.dll
|_ Cesta: C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\ISchedule.dll
|_ MD5: B3C57558A2FFB99BD5FFD0941B8B4115
|_ Výrobca: NewTech Infosystems, Inc.
|_ Procesy
|_ IScheduleSvc.exe (1712)
[?] sqlite3.dll
|_ Cesta: C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\sqlite3.dll
|_ MD5: BD8146312FFE5F51DA66E7725E989E36
|_ Výrobca:
|_ Procesy
|_ IScheduleSvc.exe (1712)
|_ BackupManagerTray.exe (2676)
[?] wirelessdll.dll
|_ Cesta: C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\WirelessDll.dll
|_ MD5: C2F7BDB29D6399593A7DD0E91FAC818A
|_ Výrobca: NewTech Infosystems, Inc.
|_ Procesy
|_ IScheduleSvc.exe (1712)
[?] agent_stub.dll
|_ Cesta: C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\agent_stub.dll
|_ MD5: 9CFCFE18966B3D9F4682FC6990F96F55
|_ Výrobca: NewTech Infosystems, Inc.
|_ Procesy
|_ IScheduleSvc.exe (1712)
[?] pluginraid_enu.dll
|_ Cesta: C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\ENU\PlugInRAID_ENU.dll
|_ MD5: 15C42334805B711FBF0C788A1D751528
|_ Výrobca: Intel Corporation
|_ Procesy
|_ IAANTmon.exe (1108)
[?] isdi.dll
|_ Cesta: C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\ISDI.dll
|_ MD5: 984BDAC9F4FC9993CE8D3A7D7DA3E9A5
|_ Výrobca: Intel Corporation
|_ Procesy
|_ IAANTmon.exe (1108)
[?] upm.dll
|_ Cesta: C:\Program Files (x86)\Ultimate Process Manager\upm.dll
|_ MD5: 9D9AA74910EE283E95214ABEADC779BD
|_ Výrobca: Lodus Software
|_ Procesy
|_ UPM.exe (2648)
[!] prjxtab.ocx
|_ Cesta: C:\Program Files (x86)\Ultimate Process Manager\prjXTab.ocx
|_ MD5: DE745F09FC7C607841519AD559C33AC3
|_ Výrobca: xyz
|_ Procesy
|_ UPM.exe (2648)
================================================================
Ultimate Process Manager v4.1.3 - [ Lodus Software ]