Restart PC (NT Authority System)
Napsal: 13 srp 2011 20:06
Mám problém s PC, které restartuje (odpočítává 1 min jako kdysi virus Blaster). Zkusil jsem pustit jednorazovou utilitu od Symantecu ale bez výsledku. NOD mi našel WIN32/Hack Tool Gendel.B, který odstranil. Potom jsem si ale všiml, že v Procesech je 7x svchost.exe (uživatel někdy SYSTEM, někdy NETWORK SERVICE nebo LOCAL SERVICE). Při pokusu o ukončení to zase končí hláškou a odpočítáváním. Už si nevím rady a tak přikládám log. Dík za každou radu.
Jo ještě jsem zapoměl. PC se sem tam sekne a každou chvíli je výkon CPU na 100%.
Windows XP SP 3 (build 2600)
Boot Mode: Normal
Ověření souborů Microsoftu: Ano
Whitelist: Ano
Internet Explorer v8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Log vygenerován: 13.8.2011 20:48:51
================================================================
SmallARK
================================================================
[?]NtClose -> C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
[?]NtCreateFile -> C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
[?]NtCreateKey -> C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
[?]NtCreateSection -> C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
[?]NtDeleteKey -> C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
[?]NtDeleteValueKey -> C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
[?]NtLoadDriver -> C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
[?]NtOpenFile -> C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
[R]NtOpenProcess -> C:\WINDOWS\system32\drivers\AVGIDSShim.Sys
[?]NtSetInformationFile -> C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
[?]NtSetValueKey -> C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
[?]NtTerminateProcess -> C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
[R]NtTerminateThread -> C:\WINDOWS\system32\drivers\AVGIDSShim.Sys
[?]NtWriteFile -> C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
[R]NtWriteVirtualMemory -> C:\WINDOWS\system32\drivers\AVGIDSShim.Sys
Běžící procesy
================================================================
C:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 6\LAUNCHAPPLICATION.EXE
C:\PROGRAM FILES\LASER MOUSE GL 2400\PANEL.EXE
C:\PROGRAM FILES\CYBERLINK\POWERDVD\PDVDSERV.EXE
C:\WINDOWS\SYSTEM32\HKCMD.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRAM FILES\SPYWARE TERMINATOR\SPYWARETERMINATORSHIELD.EXE
C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\TEATIMER.EXE
C:\PROGRAM FILES\SPYWARE TERMINATOR\SPYWARETERMINATORUPDATE.EXE
C:\PROGRAM FILES\SPYWARE TERMINATOR\SP_RSSER.EXE
C:\PROGRAM FILES\PC CONNECTIVITY SOLUTION\SERVICELAYER.EXE
Scanner
================================================================
[S] explorer.exe
Spouští se po startu HKLM Winlogon [Shell]
[?] LaunchApplication.exe
Spouští se po startu HKLM Run [PCSuiteTrayApplication]
Soubor 7%
[?] Panel.exe
Bez výrobce
Spouští se po startu HKLM Run [Laser mouse]
Soubor 25%
[?] PDVDServ.exe
Spouští se po startu HKLM Run [RemoteControl]
Soubor 7%
[?] hkcmd.exe
Non Microsoft v System32:
Spouští se po startu HKLM Run [HotKeysCmds]
[?] SOUNDMAN.EXE
Spouští se po startu HKLM Run [SoundMan]
[R] avgtray.exe
Spouští se po startu HKLM Run [AVG_TRAY]
[?] SpywareTerminatorShield.Exe
Spouští se po startu HKLM Run [SpywareTerminator]
EntryPoint v sekci: .ITEXT
|_ Celkový počet sekcí: 9
Soubor 70%
[?] TeaTimer.exe
Spouští se po startu HKCU Run [SpybotSD TeaTimer]
EntryPoint v sekci: .ITEXT
|_ Celkový počet sekcí: 9
Soubor 100%
[S] ctfmon.exe
Spouští se po startu HKCU Run [CTFMON.EXE]
[R] wcescomm.exe
Ověřený Microsoft: Ne
Spouští se po startu HKCU Run [H/PC Connection Agent]
[?] SpywareTerminatorUpdate.exe
Spouští se po startu HKCU Run [SpywareTerminatorUpdate]
EntryPoint v sekci: .ITEXT
|_ Celkový počet sekcí: 9
Soubor 70%
[R] rapimgr.exe
Ověřený Microsoft: Ne
Skrytá cesta EXE: C:\PROGRA~1\MICROS~3\rapimgr.exe
[?] sp_rsser.exe
EntryPoint v sekci: .ITEXT
|_ Celkový počet sekcí: 9
Nemá okno
Soubor 70%
[R] avgnsx.exe
Podobná jména: AVGNSX.EXE X AVGRSX.EXE
[?] ServiceLayer.exe
Soubor 7%
[R] avgrsx.exe
Podobná jména: AVGRSX.EXE X AVGNSX.EXE
[R] AcroRd32Info.exe
Proces se nepodařilo otevřít
ROOTKIT? Skrytá cesta
Spouští se po startu HKCU Run [SpybotSD TeaTimer]
Nelze otevřít
Po spuštění
================================================================
HKCU Run
|_ [X][SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
|_ [!][SpywareTerminatorUpdate] C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
HKLM Run
|_ [?][PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
|_ [?][Laser mouse] C:\Program Files\Laser Mouse GL 2400\Panel.exe
|_ [X][PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
|_ [?][RemoteControl] C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
|_ [?][HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
|_ [?][SoundMan] C:\WINDOWS\SOUNDMAN.EXE
|_ [!][SpywareTerminator] C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
HKU Run
|_ [?][Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
HKLM IC
|_ [X][>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP (Soubor nenalezen)
|_ [?][{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] C:\WINDOWS\INF\msnetmtg.inf ,NetMtg.Install.PerUser.NT
|_ [?][{5945c046-1e7d-11d1-bc44-00c04fd912be}] C:\WINDOWS\INF\msmsgs.inf ,BLC.QuietInstall.PerUser
|_ [?][{6BF52A52-394A-11d3-B153-00C04F79FAA6}] C:\WINDOWS\INF\wmp.inf ,PerUserStub
|_ [?][{89820200-ECBD-11cf-8B85-00AA005B4340}] regsvr32.exe /s /n /i:U shell32.dll
HKLM Winlogon Notify
|_ [?][igfxcui] C:\WINDOWS\system32\igfxsrvc.dll
Služby (Zobraz běžící: True, Zobraz zastavené: False, Zobraz i bezpečné služby: False)
================================================================
[?] ServiceLayer
|_ Cesta: C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
| |_ Výrobce: Nokia.
| |_ Popis: ServiceLayer Module
| |_ MD5: 78546CD2ECA6DD6BDCD4B13048621F88
|
|_ Jméno: ServiceLayer
|_ StartName: LocalSystem
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ:
|_ Dependency: RPCSS
[!] Spyware Terminator Realtime Shield Service
|_ Cesta: C:\Program Files\Spyware Terminator\sp_rsser.exe
| |_ Výrobce: Crawler.com
| |_ Popis: Spyware Terminator Realtime Shield 32-bit Service
| |_ MD5: 642180B8F50E7FC1FBAF87C718E259D6
|
|_ Jméno: sp_rssrv
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Own Process
|_ Dependency:
Ovladače (Zobraz běžící: True, Zobraz zastavené: False, Zobraz i bezpečné služby: False)
================================================================
[?] ASAPIW2K
|_ Cesta: C:\WINDOWS\system32\drivers\ASAPIW2k.sys
| |_ Výrobce: Pinnacle Systems GmbH
| |_ Popis: ASAPI
| |_ MD5: 4F9CBBF95E8F7A0D4C0EDCFE3B78102E
|
|_ Jméno: ASAPIW2k
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] NDIS WAN CAPI Treiber
|_ Cesta: C:\WINDOWS\System32\DRIVERS\avmwan.sys
| |_ Výrobce: AVM Berlin
| |_ Popis: AVM NDIS WAN CAPI Driver
| |_ MD5: EB0EF89CCD0191AEC96CD6093FB9770F
|
|_ Jméno: AVMWAN
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] GMFilter Filter
|_ Cesta: C:\WINDOWS\System32\Drivers\GMFilter.sys
| |_ Výrobce: Game
| |_ Popis: Gaming Mouse with 6-Buttuns Plus Turbo-Key
| |_ MD5: 7BF72B220264D94EC78E361F6D19814F
|
|_ Jméno: GMFilter Filter
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] ialm
|_ Cesta: C:\WINDOWS\System32\DRIVERS\ialmnt5.sys
| |_ Výrobce: Intel Corporation
| |_ Popis: Controller Hub for Intel Graphics Driver
| |_ MD5: 1406D6EF4436AEE970EFE13193123965
|
|_ Jméno: ialm
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Pinnacle Marvin Bus
|_ Cesta: C:\WINDOWS\system32\DRIVERS\MarvinBus.sys
| |_ Výrobce: Pinnacle Systems GmbH
| |_ Popis: Pinnacle Marvin/MarvinPro Bus Enumerator
| |_ MD5: D51E16339213898BC20C58670274EC3E
|
|_ Jméno: MarvinBus
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] PCLEPCI
|_ Cesta: C:\WINDOWS\system32\drivers\pclepci.sys
| |_ Výrobce: Pinnacle Systems GmbH
| |_ Popis: PCLEPCI
| |_ MD5: 1BEBE7DE8508A02650CDCE45C664C2A2
|
|_ Jméno: PCLEPCI
|_ StartName:
|_ Typ spouštění: System Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Realtek RTL8139/810x Family Fast Ethernet NIC NT Driver
|_ Cesta: C:\WINDOWS\System32\DRIVERS\R8139n51.SYS
| |_ Výrobce: Realtek Semiconductor Corporation
| |_ Popis: Realtek RTL8139/810x Family NDIS 5.1 Drv
| |_ MD5: 2EF9C0DC26B30B2318B1FC3FAA1F0AE7
|
|_ Jméno: rtl8139
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Spyware Terminator Driver 2
|_ Cesta: C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
| |_ Výrobce: ?
| |_ Popis: ?
| |_ MD5: 8831252BCF05FCFB5ABD116A22E552D8
|
|_ Jméno: sp_rsdrv2
|_ StartName:
|_ Typ spouštění: System Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Intel(R) Graphics Platform (SoftBIOS) Driver
|_ Cesta: C:\WINDOWS\system32\drivers\ialmsbw.sys
| |_ Výrobce: Intel Corporation
| |_ Popis: Intel Graphics Platform (SoftBIOS) Driver for Windows 2000(R) & Windows XP(TM)
| |_ MD5: FD1F4E9CF06C71C8D73A24ACF18D8296
|
|_ Jméno: {6080A529-897E-4629-A488-ABA0C29B635E}
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Intel(R) Graphics Chipset (KCH) Driver
|_ Cesta: C:\WINDOWS\system32\drivers\ialmkchw.sys
| |_ Výrobce: Intel Corporation
| |_ Popis: Intel Graphics Chipset (KCH) Driver for Windows 2000(R) & Windows XP(TM)
| |_ MD5: D4D7331D33D1FA73E588E5CE0D90A4C1
|
|_ Jméno: {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
lNetStat
================================================================
Typ: PID Proces Local <-> Remote Status
-----------------------------------------------------------------------------------------
TCP (940) svchost.exe 0.0.0.0:135 LISTENING
TCP (4) Systém 0.0.0.0:445 LISTENING
TCP (240) rapimgr.exe 0.0.0.0:990 LISTENING
TCP (1984) TerminatorUpdate.exe0.0.0.0:6881 LISTENING
TCP (4) Systém 88.146.162.76:139 LISTENING
TCP (2876) firefox.exe 88.146.162.76:1094 <-> 74.125.79.102:80 ESTABLISHED
TCP (2876) firefox.exe 88.146.162.76:1121 <-> 74.125.79.132:443 ESTABLISHED
TCP (0) 88.146.162.76:1122 TIME_WAIT
TCP (2876) firefox.exe 88.146.162.76:1127 <-> 74.125.79.132:443 ESTABLISHED
TCP (2876) firefox.exe 88.146.162.76:1146 <-> 74.125.79.132:443 ESTABLISHED
TCP (0) 88.146.162.76:1148 TIME_WAIT
TCP (0) 88.146.162.76:1156 TIME_WAIT
TCP (0) 88.146.162.76:1161 TIME_WAIT
TCP (2344) UPM.exe 88.146.162.76:1162 <-> 109.123.209.238:80 ESTABLISHED
TCP (1984) TerminatorUpdate.exe127.0.0.1:1028 <-> 127.0.0.1:1029 ESTABLISHED
TCP (1984) TerminatorUpdate.exe127.0.0.1:1029 <-> 127.0.0.1:1028 ESTABLISHED
TCP (3876) alg.exe 127.0.0.1:1040 LISTENING
TCP (2876) firefox.exe 127.0.0.1:1057 <-> 127.0.0.1:1058 ESTABLISHED
TCP (2876) firefox.exe 127.0.0.1:1058 <-> 127.0.0.1:1057 ESTABLISHED
TCP (2876) firefox.exe 127.0.0.1:1059 <-> 127.0.0.1:1060 ESTABLISHED
TCP (2876) firefox.exe 127.0.0.1:1060 <-> 127.0.0.1:1059 ESTABLISHED
TCP (1968) wcescomm.exe 127.0.0.1:5679 LISTENING
UDP (4) Systém 0.0.0.0:445 LISTENING
UDP (724) lsass.exe 0.0.0.0:500
UDP (1984) TerminatorUpdate.exe0.0.0.0:1026
UDP (1984) TerminatorUpdate.exe0.0.0.0:1900
UDP (724) lsass.exe 0.0.0.0:4500
UDP (1984) TerminatorUpdate.exe0.0.0.0:6771
UDP (1984) TerminatorUpdate.exe0.0.0.0:6881
UDP (1008) svchost.exe 88.146.162.76:123
UDP (4) Systém 88.146.162.76:137
UDP (4) Systém 88.146.162.76:138
UDP (1984) TerminatorUpdate.exe88.146.162.76:1025
UDP (1984) TerminatorUpdate.exe88.146.162.76:1027
UDP (1176) svchost.exe 88.146.162.76:1900
UDP (1008) svchost.exe 127.0.0.1:123
UDP (1008) svchost.exe 127.0.0.1:1047
UDP (1176) svchost.exe 127.0.0.1:1900
Moduly (Zobraz i bezpečné DLL: False, Jen bez výrobce: True, Zobraz registrované: False)
================================================================
[?] shellext7.dll
|_ Cesta: C:\Program Files\Zoner\Photo Studio 7\Program\ShellExt7.dll
|_ MD5: D1D276F5BEF5C4191885A32AC8BB2DA1
|_ Výrobce: ZONER software
|_ Procesy
|_ explorer.exe (1444)
[!] sptcontmenu.dll
|_ Cesta: C:\Program Files\Spyware Terminator\sptcontmenu.dll
|_ MD5: A5E97B2B88CC48FC178E88BF6E02F5EC
|_ Výrobce: Crawler.com
|_ Procesy
|_ explorer.exe (1444)
[?] phonebrowser.dll
|_ Cesta: C:\Program Files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
|_ MD5: 14B7E5CE5AB47CC1D31D67A13D97668E
|_ Výrobce: Nokia
|_ Procesy
|_ explorer.exe (1444)
[?] pcscm.dll
|_ Cesta: C:\Program Files\Nokia\Nokia PC Suite 6\PCSCM.dll
|_ MD5: 5061B30A831CD8F25A9A8DA155276214
|_ Výrobce: Nokia
|_ Procesy
|_ explorer.exe (1444)
|_ LaunchApplication.exe (1656)
[?] hook.dll
|_ Cesta: C:\WINDOWS\system32\Hook.dll
|_ MD5: 83D1E23ED3AB56DD25372BC9BDBC48CA
|_ Výrobce:
|_ Procesy
|_ explorer.exe (1444)
|_ Panel.exe (1688)
|_ taskmgr.exe (2424)
|_ plugin-container.exe (3364)
|_ UPM.exe (2344)
[?] pcssupportsetup.dll
|_ Cesta: C:\Program Files\Nokia\Nokia PC Suite 6\PCSSupportSetup.dll
|_ MD5: A53C7155DBFFFA50FC22C077D63794E3
|_ Výrobce: Nokia
|_ Procesy
|_ LaunchApplication.exe (1656)
[?] connapi.dll
|_ Cesta: C:\Program Files\PC Connectivity Solution\ConnAPI.dll
|_ MD5: 8709C3775781EAE0BB2174796827F018
|_ Výrobce: Nokia.
|_ Procesy
|_ LaunchApplication.exe (1656)
[?] confserver.dll
|_ Cesta: C:\Program Files\PC Connectivity Solution\ConfServer.dll
|_ MD5: E75A0EEB8B4BF1AFF9667CF45A31EB02
|_ Výrobce: Nokia
|_ Procesy
|_ LaunchApplication.exe (1656)
[?] xwheel.dll
|_ Cesta: C:\WINDOWS\system32\XWheel.dll
|_ MD5: 61C4C2C2592A7AB438F8846B0AE04DD3
|_ Výrobce: Copyright (C) 2003
|_ Procesy
|_ Panel.exe (1688)
[?] clrcengine2.dll
|_ Cesta: C:\Program Files\CyberLink\Shared Files\CLRCEngine2.dll
|_ MD5: DAE211D3393343B2FAD71C65B20EC562
|_ Výrobce: CyberLink Corp.
|_ Procesy
|_ PDVDServ.exe (1732)
[?] torentdll.dll
|_ Cesta: C:\Program Files\Spyware Terminator\TorentDll.dll
|_ MD5: 0B0387E70BE085C1842BC7DEB47EE54F
|_ Výrobce:
|_ Procesy
|_ SpywareTerminatorUpdate.exe (1984)
[?] nclirdamm.dll
|_ Cesta: C:\Program Files\PC Connectivity Solution\Transports\NCLIrDAMM.dll
|_ MD5: 3A7A1697830EFBD545203004044BB0B4
|_ Výrobce: Nokia Corp.
|_ Procesy
|_ ServiceLayer.exe (3216)
[?] nclrsmm.dll
|_ Cesta: C:\Program Files\PC Connectivity Solution\Transports\NCLRSMM.dll
|_ MD5: AB5746FA6C4A2D8067C46A0EC91E594A
|_ Výrobce: Nokia Corp.
|_ Procesy
|_ ServiceLayer.exe (3216)
[?] nclusbmm.dll
|_ Cesta: C:\Program Files\PC Connectivity Solution\Transports\NCLUSBMM.dll
|_ MD5: 8AD47DB9012282D26596F7F5637E6D55
|_ Výrobce: Nokia.
|_ Procesy
|_ ServiceLayer.exe (3216)
[?] nclmsbtmm.dll
|_ Cesta: C:\Program Files\PC Connectivity Solution\Transports\NclMSBTMM.dll
|_ MD5: E9F176744FB3D72187B084EF015EAE82
|_ Výrobce: Nokia Corp.
|_ Procesy
|_ ServiceLayer.exe (3216)
[?] ncltools.dll
|_ Cesta: C:\Program Files\PC Connectivity Solution\NclTools.dll
|_ MD5: 01D7C8D66EEE4B436C2B273E977FC1AB
|_ Výrobce: Nokia
|_ Procesy
|_ ServiceLayer.exe (3216)
Výpis souborů
================================================================
\System32:
[!] asapi.dll 63 no vrfy, cx (CODE)?, {16814AA1}
[?] aswBoot.exe 12 ncmpny, {404987C9}
[?] ATL70.DLL 12 ncmpny, {BD6CF416}
[?] AudioDec.dll 7 no vrfy, {90887C13}
[?] AVASTSS.scr 14 no vrfy, {C9D904D0}
[?] Aviprax.dll 7 no vrfy, {7D90C09B}
[?] avmadd32.dll 7 no vrfy, {AC0B9B39}
[?] avmco32.dll 7 no vrfy, {41F8B111}
[?] avmen32.dll 7 no vrfy, {0856AA1D}
[?] AvsAudioCodec.dll AVSAUD~1.DLL 7 no vrfy, {9A11D753}
[?] AvsCodec51.dll AVSCOD~1.DLL 7 no vrfy, {9EC4928F}
[?] Cachex.dll 7 no vrfy, {BF6054F0}
[?] capi2032.dll 7 no vrfy, {44EF8FE4}
[?] CddbCdda.dll 7 no vrfy, {5F212092}
[?] CnAS0MMK.DLL 7 no vrfy, {9FFDE03E}
[?] CNCC3110.DLL 7 no vrfy, {3CF57508}
[?] CNCC3200.DLL 7 no vrfy, {D223C5AA}
[?] CNCI3110.DLL 7 no vrfy, {E044A545}
[?] CNCI3200.DLL 7 no vrfy, {5526C890}
[?] cncilps0.dll 7 no vrfy, {37F268F5}
[?] cncilsc.dll 7 no vrfy, {BCFA076A}
[?] CNCL3110.DLL 7 no vrfy, {2DEDF193}
[?] CNCL3200.DLL 7 no vrfy, {9B4485D1}
[?] CNCLSC11.DLL 7 no vrfy, {97114321}
[?] CNCLSC21.DLL 7 no vrfy, {F7B0718C}
[?] CNCLSD11.DLL 7 no vrfy, {B2BC021F}
[?] CNCLSD21.DLL 7 no vrfy, {B41C4C58}
[?] CNCLSI11.DLL 7 no vrfy, {63DEFDAF}
[?] CNCLSI21.DLL 7 no vrfy, {C9E0818E}
[?] CNCLST11.DLL 7 no vrfy, {EBC13FB4}
[?] CNCLST21.DLL 7 no vrfy, {2C29EC60}
[?] CNCLSU11.DLL 7 no vrfy, {433EB7E5}
[?] CNCLSU21.DLL 7 no vrfy, {7BEFB494}
[?] dbmsadsn.dll 12 ncmpny, {1EB406AC}
[?] dbmsvinn.dLL 12 ncmpny, {3A1B9CCF}
[?] decode.dll 7 no vrfy, {9CA5DEB9}
[?] DiskIO.dll 7 no vrfy, {710F128E}
[?] FM20.DLL 12 ncmpny, {DB160942}
[?] Fridru32.dll 7 no vrfy, {69332968}
[?] FritzColorPort.dll FRITZC~1.DLL 7 no vrfy, {AA6F5DB4}
[?] FritzPort.dll FRITZP~1.DLL 7 no vrfy, {A76571A8}
[?] fxusbase.sys 7 no vrfy, {F22A9DE4}
[?] G723Codec.dll G723CO~1.DLL 7 no vrfy, {6AC7B967}
[?] Hook.dll 12 ncmpny, {C88CDAFF}
[?] i2errCsy.dll 14 no vrfy, {BE09A329}
[?] ijl15.dll 7 no vrfy, {7BF7C420}
[X] Instcodec.exe INSTCO~1.EXE 100 ncmpny, cx (UPX1)?, {00E382FB}
[?] IPCDCore.dll 12 ncmpny, {FC045B52}
[?] IPCHD10.dll 7 no vrfy, {1CDC6625}
[?] IPCJD20.dll 49 no vrfy, time mism., {C6518D36}
[?] IPCMD10.dll 7 no vrfy, {C2DF6374}
[?] IPCXD10.dll 7 no vrfy, {C61EFC69}
[?] java.exe 7 no vrfy, {CC202D61}
[?] javacpl.cpl 14 no vrfy, {8CE328B6}
[?] javaw.exe 7 no vrfy, {5B8FBA2E}
[?] javaws.exe 7 no vrfy, {11CD9E2A}
[?] langserv.dll 7 no vrfy, {7275A6ED}
[?] lfbmp13n.dll 7 no vrfy, {41D5FF24}
[?] LFCMP13n.DLL 7 no vrfy, {B18DD5EC}
[?] lffax13n.dll 7 no vrfy, {B43074AB}
[?] LFJ2K13n.dll 7 no vrfy, {ED93E1BE}
[?] Lfpct13n.dll 7 no vrfy, {35E4D44B}
[?] lftga13n.dll 7 no vrfy, {0C7DC9C4}
[?] lftif13n.dll 7 no vrfy, {0C9A5332}
[?] Lfwmf13n.dll 7 no vrfy, {673D9097}
[?] libmmd.dll 12 ncmpny, {1D797317}
[?] LTCLR13n.dll 14 no vrfy, {5A927A2F}
[?] ltfil13n.DLL 7 no vrfy, {1AC6CCCC}
[?] ltkrn13n.dll 7 no vrfy, {CAF265D9}
[?] ltremove.exe 7 no vrfy, {D4F98423}
[?] mindex.dll 12 ncmpny, {321B69FF}
[?] MLPagAx.dll 7 no vrfy, {A2CA61C9}
[?] MMAviAx.dll 7 no vrfy, {C652CDFD}
[?] MousePage.dll MOUSEP~1.DLL 14 no vrfy, {B56AE5C8}
[?] msisam11.dll 12 ncmpny, {B599D894}
[?] MSLDBUSR.DLL 12 ncmpny, {C910A67F}
[?] MSRDO20.DLL 12 ncmpny, {17058418}
[?] msuni11.dll 12 ncmpny, {4838DFF3}
[?] NetworkAPI.dll NETWOR~1.DLL 7 no vrfy, {2C1CA00F}
[?] Ntaccess.sys 14 no vrfy, {147C8BB0}
[?] NVDHE50.dll 7 no vrfy, {2760E3CB}
[?] NVDME50.dll 7 no vrfy, {6823D550}
[?] OUTLWAB.DLL 12 ncmpny, {1832171B}
[?] PCLEGetGuid.dll PCLEGE~1.DLL 7 no vrfy, {04576B32}
[?] postprocess.dll POSTPR~1.DLL 7 no vrfy, {526634B8}
[X] PSDrvCheck.CHS PSDRVC~1.CHS 100 ncmpny, cx (CODE)?, {6EB8960F}
[X] PSDrvCheck.CHT PSDRVC~1.CHT 100 ncmpny, cx (CODE)?, {7D5846F7}
[X] PSDrvCheck.DE PSDRVC~1.DE 100 ncmpny, cx (CODE)?, {193CA392}
[X] PSDrvCheck.DEU PSDRVC~1.DEU 100 ncmpny, cx (CODE)?, {193CA392}
[X] PSDrvCheck.ES PSDRVC~1.ES 100 ncmpny, cx (CODE)?, {2B9F0505}
[X] PSDrvCheck.ESP PSDRVC~1.ESP 100 ncmpny, cx (CODE)?, {2B9F0505}
[X] PSDrvCheck.exe PSDRVC~1.EXE 100 ncmpny, cx (CODE)?, {C0655735}
[X] PSDrvCheck.FR PSDRVC~1.FR 100 ncmpny, cx (CODE)?, {463B960E}
[X] PSDrvCheck.FRA PSDRVC~1.FRA 100 ncmpny, cx (CODE)?, {463B960E}
[X] PSDrvCheck.IT PSDRVC~1.IT 100 ncmpny, cx (CODE)?, {EC437E0F}
[X] PSDrvCheck.ITA PSDRVC~1.ITA 100 ncmpny, cx (CODE)?, {EC437E0F}
[X] PSDrvCheck.JP PSDRVC~1.JP 100 ncmpny, cx (CODE)?, {CC8D5B16}
[X] PSDrvCheck.JPN PSDRVC~1.JPN 100 ncmpny, cx (CODE)?, {CC8D5B16}
[X] PSDrvCheck.KO PSDRVC~1.KO 100 ncmpny, cx (CODE)?, {5EF9D637}
[X] PSDrvCheck.KOR PSDRVC~1.KOR 100 ncmpny, cx (CODE)?, {FD0C89A2}
[X] PSDrvCheck.NL PSDRVC~1.NL 100 ncmpny, cx (CODE)?, {DE1F7773}
[X] PSDrvCheck.NLD PSDRVC~1.NLD 100 ncmpny, cx (CODE)?, {DE1F7773}
[?] pvmjpg21.dll 14 no vrfy, {45E9532D}
[?] RALMain.dll 7 no vrfy, {871EDDC8}
[?] RDOCURS.DLL 12 ncmpny, {4D094B02}
[?] RTClientSDK71.dll RTCLIE~1.DLL 7 no vrfy, {8A89613C}
[?] UCS32P.DLL 7 no vrfy, {3C231252}
[?] vdrmux.dll 7 no vrfy, {82F11A7C}
[?] wmidx.ocx 12 ncmpny, {22DE4980}
[?] wmpstub.exe 25 ncmpny, {8D6131AE}
[?] wmv8dmod.dll 12 ncmpny, {AAA13CAA}
[?] wmvcore2.dll 12 ncmpny, {D95FD06C}
[?] wmvdmoe.dll 12 ncmpny, {6E06840B}
[?] xpsp1hfm.exe 12 ncmpny, {98A44F1B}
[?] Xrypassd.dll 7 no vrfy, {D59582EB}
[?] xvidvfw.dll 12 ncmpny, {F8FDCF29}
[?] XWheel.dll 14 no vrfy, {075C6039}
\Drivers:
[?] asapiW2k.sys 14 no vrfy, {076C2F7F}
[?] aswRdr.sys 7 no vrfy, {5F5489E5}
[?] avmwan.sys 7 no vrfy, {7ECB2B4C}
[?] Camd905c.sys 7 no vrfy, {816F96E2}
[?] Capt905c.sys 7 no vrfy, {6CD1302F}
[?] FlashSys.sys 25 ncmpny, {89B88EB8}
[?] fxusbase.sys 7 no vrfy, {F22A9DE4}
[?] GMFilter.sys 14 no vrfy, {5ABF26CF}
[?] Pclepci.sys 14 no vrfy, {FDAED5C7}
[?] sp_rsdrv2.sys SP_RSD~1.SYS 25 ncmpny, {0FB6D88F}
================================================================
Ultimate Process Manager v4.1.3 - [ Lodus Software ]
Jo ještě jsem zapoměl. PC se sem tam sekne a každou chvíli je výkon CPU na 100%.
Windows XP SP 3 (build 2600)
Boot Mode: Normal
Ověření souborů Microsoftu: Ano
Whitelist: Ano
Internet Explorer v8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Log vygenerován: 13.8.2011 20:48:51
================================================================
SmallARK
================================================================
[?]NtClose -> C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
[?]NtCreateFile -> C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
[?]NtCreateKey -> C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
[?]NtCreateSection -> C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
[?]NtDeleteKey -> C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
[?]NtDeleteValueKey -> C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
[?]NtLoadDriver -> C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
[?]NtOpenFile -> C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
[R]NtOpenProcess -> C:\WINDOWS\system32\drivers\AVGIDSShim.Sys
[?]NtSetInformationFile -> C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
[?]NtSetValueKey -> C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
[?]NtTerminateProcess -> C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
[R]NtTerminateThread -> C:\WINDOWS\system32\drivers\AVGIDSShim.Sys
[?]NtWriteFile -> C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
[R]NtWriteVirtualMemory -> C:\WINDOWS\system32\drivers\AVGIDSShim.Sys
Běžící procesy
================================================================
C:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 6\LAUNCHAPPLICATION.EXE
C:\PROGRAM FILES\LASER MOUSE GL 2400\PANEL.EXE
C:\PROGRAM FILES\CYBERLINK\POWERDVD\PDVDSERV.EXE
C:\WINDOWS\SYSTEM32\HKCMD.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRAM FILES\SPYWARE TERMINATOR\SPYWARETERMINATORSHIELD.EXE
C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\TEATIMER.EXE
C:\PROGRAM FILES\SPYWARE TERMINATOR\SPYWARETERMINATORUPDATE.EXE
C:\PROGRAM FILES\SPYWARE TERMINATOR\SP_RSSER.EXE
C:\PROGRAM FILES\PC CONNECTIVITY SOLUTION\SERVICELAYER.EXE
Scanner
================================================================
[S] explorer.exe
Spouští se po startu HKLM Winlogon [Shell]
[?] LaunchApplication.exe
Spouští se po startu HKLM Run [PCSuiteTrayApplication]
Soubor 7%
[?] Panel.exe
Bez výrobce
Spouští se po startu HKLM Run [Laser mouse]
Soubor 25%
[?] PDVDServ.exe
Spouští se po startu HKLM Run [RemoteControl]
Soubor 7%
[?] hkcmd.exe
Non Microsoft v System32:
Spouští se po startu HKLM Run [HotKeysCmds]
[?] SOUNDMAN.EXE
Spouští se po startu HKLM Run [SoundMan]
[R] avgtray.exe
Spouští se po startu HKLM Run [AVG_TRAY]
[?] SpywareTerminatorShield.Exe
Spouští se po startu HKLM Run [SpywareTerminator]
EntryPoint v sekci: .ITEXT
|_ Celkový počet sekcí: 9
Soubor 70%
[?] TeaTimer.exe
Spouští se po startu HKCU Run [SpybotSD TeaTimer]
EntryPoint v sekci: .ITEXT
|_ Celkový počet sekcí: 9
Soubor 100%
[S] ctfmon.exe
Spouští se po startu HKCU Run [CTFMON.EXE]
[R] wcescomm.exe
Ověřený Microsoft: Ne
Spouští se po startu HKCU Run [H/PC Connection Agent]
[?] SpywareTerminatorUpdate.exe
Spouští se po startu HKCU Run [SpywareTerminatorUpdate]
EntryPoint v sekci: .ITEXT
|_ Celkový počet sekcí: 9
Soubor 70%
[R] rapimgr.exe
Ověřený Microsoft: Ne
Skrytá cesta EXE: C:\PROGRA~1\MICROS~3\rapimgr.exe
[?] sp_rsser.exe
EntryPoint v sekci: .ITEXT
|_ Celkový počet sekcí: 9
Nemá okno
Soubor 70%
[R] avgnsx.exe
Podobná jména: AVGNSX.EXE X AVGRSX.EXE
[?] ServiceLayer.exe
Soubor 7%
[R] avgrsx.exe
Podobná jména: AVGRSX.EXE X AVGNSX.EXE
[R] AcroRd32Info.exe
Proces se nepodařilo otevřít
ROOTKIT? Skrytá cesta
Spouští se po startu HKCU Run [SpybotSD TeaTimer]
Nelze otevřít
Po spuštění
================================================================
HKCU Run
|_ [X][SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
|_ [!][SpywareTerminatorUpdate] C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
HKLM Run
|_ [?][PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
|_ [?][Laser mouse] C:\Program Files\Laser Mouse GL 2400\Panel.exe
|_ [X][PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
|_ [?][RemoteControl] C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
|_ [?][HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
|_ [?][SoundMan] C:\WINDOWS\SOUNDMAN.EXE
|_ [!][SpywareTerminator] C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
HKU Run
|_ [?][Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
HKLM IC
|_ [X][>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP (Soubor nenalezen)
|_ [?][{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] C:\WINDOWS\INF\msnetmtg.inf ,NetMtg.Install.PerUser.NT
|_ [?][{5945c046-1e7d-11d1-bc44-00c04fd912be}] C:\WINDOWS\INF\msmsgs.inf ,BLC.QuietInstall.PerUser
|_ [?][{6BF52A52-394A-11d3-B153-00C04F79FAA6}] C:\WINDOWS\INF\wmp.inf ,PerUserStub
|_ [?][{89820200-ECBD-11cf-8B85-00AA005B4340}] regsvr32.exe /s /n /i:U shell32.dll
HKLM Winlogon Notify
|_ [?][igfxcui] C:\WINDOWS\system32\igfxsrvc.dll
Služby (Zobraz běžící: True, Zobraz zastavené: False, Zobraz i bezpečné služby: False)
================================================================
[?] ServiceLayer
|_ Cesta: C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
| |_ Výrobce: Nokia.
| |_ Popis: ServiceLayer Module
| |_ MD5: 78546CD2ECA6DD6BDCD4B13048621F88
|
|_ Jméno: ServiceLayer
|_ StartName: LocalSystem
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ:
|_ Dependency: RPCSS
[!] Spyware Terminator Realtime Shield Service
|_ Cesta: C:\Program Files\Spyware Terminator\sp_rsser.exe
| |_ Výrobce: Crawler.com
| |_ Popis: Spyware Terminator Realtime Shield 32-bit Service
| |_ MD5: 642180B8F50E7FC1FBAF87C718E259D6
|
|_ Jméno: sp_rssrv
|_ StartName: LocalSystem
|_ Typ spouštění: Auto Start
|_ Status: Spuštěno
|_ Typ: Win32 Own Process
|_ Dependency:
Ovladače (Zobraz běžící: True, Zobraz zastavené: False, Zobraz i bezpečné služby: False)
================================================================
[?] ASAPIW2K
|_ Cesta: C:\WINDOWS\system32\drivers\ASAPIW2k.sys
| |_ Výrobce: Pinnacle Systems GmbH
| |_ Popis: ASAPI
| |_ MD5: 4F9CBBF95E8F7A0D4C0EDCFE3B78102E
|
|_ Jméno: ASAPIW2k
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] NDIS WAN CAPI Treiber
|_ Cesta: C:\WINDOWS\System32\DRIVERS\avmwan.sys
| |_ Výrobce: AVM Berlin
| |_ Popis: AVM NDIS WAN CAPI Driver
| |_ MD5: EB0EF89CCD0191AEC96CD6093FB9770F
|
|_ Jméno: AVMWAN
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] GMFilter Filter
|_ Cesta: C:\WINDOWS\System32\Drivers\GMFilter.sys
| |_ Výrobce: Game
| |_ Popis: Gaming Mouse with 6-Buttuns Plus Turbo-Key
| |_ MD5: 7BF72B220264D94EC78E361F6D19814F
|
|_ Jméno: GMFilter Filter
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] ialm
|_ Cesta: C:\WINDOWS\System32\DRIVERS\ialmnt5.sys
| |_ Výrobce: Intel Corporation
| |_ Popis: Controller Hub for Intel Graphics Driver
| |_ MD5: 1406D6EF4436AEE970EFE13193123965
|
|_ Jméno: ialm
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Pinnacle Marvin Bus
|_ Cesta: C:\WINDOWS\system32\DRIVERS\MarvinBus.sys
| |_ Výrobce: Pinnacle Systems GmbH
| |_ Popis: Pinnacle Marvin/MarvinPro Bus Enumerator
| |_ MD5: D51E16339213898BC20C58670274EC3E
|
|_ Jméno: MarvinBus
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] PCLEPCI
|_ Cesta: C:\WINDOWS\system32\drivers\pclepci.sys
| |_ Výrobce: Pinnacle Systems GmbH
| |_ Popis: PCLEPCI
| |_ MD5: 1BEBE7DE8508A02650CDCE45C664C2A2
|
|_ Jméno: PCLEPCI
|_ StartName:
|_ Typ spouštění: System Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Realtek RTL8139/810x Family Fast Ethernet NIC NT Driver
|_ Cesta: C:\WINDOWS\System32\DRIVERS\R8139n51.SYS
| |_ Výrobce: Realtek Semiconductor Corporation
| |_ Popis: Realtek RTL8139/810x Family NDIS 5.1 Drv
| |_ MD5: 2EF9C0DC26B30B2318B1FC3FAA1F0AE7
|
|_ Jméno: rtl8139
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Spyware Terminator Driver 2
|_ Cesta: C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
| |_ Výrobce: ?
| |_ Popis: ?
| |_ MD5: 8831252BCF05FCFB5ABD116A22E552D8
|
|_ Jméno: sp_rsdrv2
|_ StartName:
|_ Typ spouštění: System Start
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Intel(R) Graphics Platform (SoftBIOS) Driver
|_ Cesta: C:\WINDOWS\system32\drivers\ialmsbw.sys
| |_ Výrobce: Intel Corporation
| |_ Popis: Intel Graphics Platform (SoftBIOS) Driver for Windows 2000(R) & Windows XP(TM)
| |_ MD5: FD1F4E9CF06C71C8D73A24ACF18D8296
|
|_ Jméno: {6080A529-897E-4629-A488-ABA0C29B635E}
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
[?] Intel(R) Graphics Chipset (KCH) Driver
|_ Cesta: C:\WINDOWS\system32\drivers\ialmkchw.sys
| |_ Výrobce: Intel Corporation
| |_ Popis: Intel Graphics Chipset (KCH) Driver for Windows 2000(R) & Windows XP(TM)
| |_ MD5: D4D7331D33D1FA73E588E5CE0D90A4C1
|
|_ Jméno: {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}
|_ StartName:
|_ Typ spouštění: Ruční spuštění
|_ Status: Spuštěno
|_ Typ: Kernel Driver
|_ Dependency:
lNetStat
================================================================
Typ: PID Proces Local <-> Remote Status
-----------------------------------------------------------------------------------------
TCP (940) svchost.exe 0.0.0.0:135 LISTENING
TCP (4) Systém 0.0.0.0:445 LISTENING
TCP (240) rapimgr.exe 0.0.0.0:990 LISTENING
TCP (1984) TerminatorUpdate.exe0.0.0.0:6881 LISTENING
TCP (4) Systém 88.146.162.76:139 LISTENING
TCP (2876) firefox.exe 88.146.162.76:1094 <-> 74.125.79.102:80 ESTABLISHED
TCP (2876) firefox.exe 88.146.162.76:1121 <-> 74.125.79.132:443 ESTABLISHED
TCP (0) 88.146.162.76:1122 TIME_WAIT
TCP (2876) firefox.exe 88.146.162.76:1127 <-> 74.125.79.132:443 ESTABLISHED
TCP (2876) firefox.exe 88.146.162.76:1146 <-> 74.125.79.132:443 ESTABLISHED
TCP (0) 88.146.162.76:1148 TIME_WAIT
TCP (0) 88.146.162.76:1156 TIME_WAIT
TCP (0) 88.146.162.76:1161 TIME_WAIT
TCP (2344) UPM.exe 88.146.162.76:1162 <-> 109.123.209.238:80 ESTABLISHED
TCP (1984) TerminatorUpdate.exe127.0.0.1:1028 <-> 127.0.0.1:1029 ESTABLISHED
TCP (1984) TerminatorUpdate.exe127.0.0.1:1029 <-> 127.0.0.1:1028 ESTABLISHED
TCP (3876) alg.exe 127.0.0.1:1040 LISTENING
TCP (2876) firefox.exe 127.0.0.1:1057 <-> 127.0.0.1:1058 ESTABLISHED
TCP (2876) firefox.exe 127.0.0.1:1058 <-> 127.0.0.1:1057 ESTABLISHED
TCP (2876) firefox.exe 127.0.0.1:1059 <-> 127.0.0.1:1060 ESTABLISHED
TCP (2876) firefox.exe 127.0.0.1:1060 <-> 127.0.0.1:1059 ESTABLISHED
TCP (1968) wcescomm.exe 127.0.0.1:5679 LISTENING
UDP (4) Systém 0.0.0.0:445 LISTENING
UDP (724) lsass.exe 0.0.0.0:500
UDP (1984) TerminatorUpdate.exe0.0.0.0:1026
UDP (1984) TerminatorUpdate.exe0.0.0.0:1900
UDP (724) lsass.exe 0.0.0.0:4500
UDP (1984) TerminatorUpdate.exe0.0.0.0:6771
UDP (1984) TerminatorUpdate.exe0.0.0.0:6881
UDP (1008) svchost.exe 88.146.162.76:123
UDP (4) Systém 88.146.162.76:137
UDP (4) Systém 88.146.162.76:138
UDP (1984) TerminatorUpdate.exe88.146.162.76:1025
UDP (1984) TerminatorUpdate.exe88.146.162.76:1027
UDP (1176) svchost.exe 88.146.162.76:1900
UDP (1008) svchost.exe 127.0.0.1:123
UDP (1008) svchost.exe 127.0.0.1:1047
UDP (1176) svchost.exe 127.0.0.1:1900
Moduly (Zobraz i bezpečné DLL: False, Jen bez výrobce: True, Zobraz registrované: False)
================================================================
[?] shellext7.dll
|_ Cesta: C:\Program Files\Zoner\Photo Studio 7\Program\ShellExt7.dll
|_ MD5: D1D276F5BEF5C4191885A32AC8BB2DA1
|_ Výrobce: ZONER software
|_ Procesy
|_ explorer.exe (1444)
[!] sptcontmenu.dll
|_ Cesta: C:\Program Files\Spyware Terminator\sptcontmenu.dll
|_ MD5: A5E97B2B88CC48FC178E88BF6E02F5EC
|_ Výrobce: Crawler.com
|_ Procesy
|_ explorer.exe (1444)
[?] phonebrowser.dll
|_ Cesta: C:\Program Files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
|_ MD5: 14B7E5CE5AB47CC1D31D67A13D97668E
|_ Výrobce: Nokia
|_ Procesy
|_ explorer.exe (1444)
[?] pcscm.dll
|_ Cesta: C:\Program Files\Nokia\Nokia PC Suite 6\PCSCM.dll
|_ MD5: 5061B30A831CD8F25A9A8DA155276214
|_ Výrobce: Nokia
|_ Procesy
|_ explorer.exe (1444)
|_ LaunchApplication.exe (1656)
[?] hook.dll
|_ Cesta: C:\WINDOWS\system32\Hook.dll
|_ MD5: 83D1E23ED3AB56DD25372BC9BDBC48CA
|_ Výrobce:
|_ Procesy
|_ explorer.exe (1444)
|_ Panel.exe (1688)
|_ taskmgr.exe (2424)
|_ plugin-container.exe (3364)
|_ UPM.exe (2344)
[?] pcssupportsetup.dll
|_ Cesta: C:\Program Files\Nokia\Nokia PC Suite 6\PCSSupportSetup.dll
|_ MD5: A53C7155DBFFFA50FC22C077D63794E3
|_ Výrobce: Nokia
|_ Procesy
|_ LaunchApplication.exe (1656)
[?] connapi.dll
|_ Cesta: C:\Program Files\PC Connectivity Solution\ConnAPI.dll
|_ MD5: 8709C3775781EAE0BB2174796827F018
|_ Výrobce: Nokia.
|_ Procesy
|_ LaunchApplication.exe (1656)
[?] confserver.dll
|_ Cesta: C:\Program Files\PC Connectivity Solution\ConfServer.dll
|_ MD5: E75A0EEB8B4BF1AFF9667CF45A31EB02
|_ Výrobce: Nokia
|_ Procesy
|_ LaunchApplication.exe (1656)
[?] xwheel.dll
|_ Cesta: C:\WINDOWS\system32\XWheel.dll
|_ MD5: 61C4C2C2592A7AB438F8846B0AE04DD3
|_ Výrobce: Copyright (C) 2003
|_ Procesy
|_ Panel.exe (1688)
[?] clrcengine2.dll
|_ Cesta: C:\Program Files\CyberLink\Shared Files\CLRCEngine2.dll
|_ MD5: DAE211D3393343B2FAD71C65B20EC562
|_ Výrobce: CyberLink Corp.
|_ Procesy
|_ PDVDServ.exe (1732)
[?] torentdll.dll
|_ Cesta: C:\Program Files\Spyware Terminator\TorentDll.dll
|_ MD5: 0B0387E70BE085C1842BC7DEB47EE54F
|_ Výrobce:
|_ Procesy
|_ SpywareTerminatorUpdate.exe (1984)
[?] nclirdamm.dll
|_ Cesta: C:\Program Files\PC Connectivity Solution\Transports\NCLIrDAMM.dll
|_ MD5: 3A7A1697830EFBD545203004044BB0B4
|_ Výrobce: Nokia Corp.
|_ Procesy
|_ ServiceLayer.exe (3216)
[?] nclrsmm.dll
|_ Cesta: C:\Program Files\PC Connectivity Solution\Transports\NCLRSMM.dll
|_ MD5: AB5746FA6C4A2D8067C46A0EC91E594A
|_ Výrobce: Nokia Corp.
|_ Procesy
|_ ServiceLayer.exe (3216)
[?] nclusbmm.dll
|_ Cesta: C:\Program Files\PC Connectivity Solution\Transports\NCLUSBMM.dll
|_ MD5: 8AD47DB9012282D26596F7F5637E6D55
|_ Výrobce: Nokia.
|_ Procesy
|_ ServiceLayer.exe (3216)
[?] nclmsbtmm.dll
|_ Cesta: C:\Program Files\PC Connectivity Solution\Transports\NclMSBTMM.dll
|_ MD5: E9F176744FB3D72187B084EF015EAE82
|_ Výrobce: Nokia Corp.
|_ Procesy
|_ ServiceLayer.exe (3216)
[?] ncltools.dll
|_ Cesta: C:\Program Files\PC Connectivity Solution\NclTools.dll
|_ MD5: 01D7C8D66EEE4B436C2B273E977FC1AB
|_ Výrobce: Nokia
|_ Procesy
|_ ServiceLayer.exe (3216)
Výpis souborů
================================================================
\System32:
[!] asapi.dll 63 no vrfy, cx (CODE)?, {16814AA1}
[?] aswBoot.exe 12 ncmpny, {404987C9}
[?] ATL70.DLL 12 ncmpny, {BD6CF416}
[?] AudioDec.dll 7 no vrfy, {90887C13}
[?] AVASTSS.scr 14 no vrfy, {C9D904D0}
[?] Aviprax.dll 7 no vrfy, {7D90C09B}
[?] avmadd32.dll 7 no vrfy, {AC0B9B39}
[?] avmco32.dll 7 no vrfy, {41F8B111}
[?] avmen32.dll 7 no vrfy, {0856AA1D}
[?] AvsAudioCodec.dll AVSAUD~1.DLL 7 no vrfy, {9A11D753}
[?] AvsCodec51.dll AVSCOD~1.DLL 7 no vrfy, {9EC4928F}
[?] Cachex.dll 7 no vrfy, {BF6054F0}
[?] capi2032.dll 7 no vrfy, {44EF8FE4}
[?] CddbCdda.dll 7 no vrfy, {5F212092}
[?] CnAS0MMK.DLL 7 no vrfy, {9FFDE03E}
[?] CNCC3110.DLL 7 no vrfy, {3CF57508}
[?] CNCC3200.DLL 7 no vrfy, {D223C5AA}
[?] CNCI3110.DLL 7 no vrfy, {E044A545}
[?] CNCI3200.DLL 7 no vrfy, {5526C890}
[?] cncilps0.dll 7 no vrfy, {37F268F5}
[?] cncilsc.dll 7 no vrfy, {BCFA076A}
[?] CNCL3110.DLL 7 no vrfy, {2DEDF193}
[?] CNCL3200.DLL 7 no vrfy, {9B4485D1}
[?] CNCLSC11.DLL 7 no vrfy, {97114321}
[?] CNCLSC21.DLL 7 no vrfy, {F7B0718C}
[?] CNCLSD11.DLL 7 no vrfy, {B2BC021F}
[?] CNCLSD21.DLL 7 no vrfy, {B41C4C58}
[?] CNCLSI11.DLL 7 no vrfy, {63DEFDAF}
[?] CNCLSI21.DLL 7 no vrfy, {C9E0818E}
[?] CNCLST11.DLL 7 no vrfy, {EBC13FB4}
[?] CNCLST21.DLL 7 no vrfy, {2C29EC60}
[?] CNCLSU11.DLL 7 no vrfy, {433EB7E5}
[?] CNCLSU21.DLL 7 no vrfy, {7BEFB494}
[?] dbmsadsn.dll 12 ncmpny, {1EB406AC}
[?] dbmsvinn.dLL 12 ncmpny, {3A1B9CCF}
[?] decode.dll 7 no vrfy, {9CA5DEB9}
[?] DiskIO.dll 7 no vrfy, {710F128E}
[?] FM20.DLL 12 ncmpny, {DB160942}
[?] Fridru32.dll 7 no vrfy, {69332968}
[?] FritzColorPort.dll FRITZC~1.DLL 7 no vrfy, {AA6F5DB4}
[?] FritzPort.dll FRITZP~1.DLL 7 no vrfy, {A76571A8}
[?] fxusbase.sys 7 no vrfy, {F22A9DE4}
[?] G723Codec.dll G723CO~1.DLL 7 no vrfy, {6AC7B967}
[?] Hook.dll 12 ncmpny, {C88CDAFF}
[?] i2errCsy.dll 14 no vrfy, {BE09A329}
[?] ijl15.dll 7 no vrfy, {7BF7C420}
[X] Instcodec.exe INSTCO~1.EXE 100 ncmpny, cx (UPX1)?, {00E382FB}
[?] IPCDCore.dll 12 ncmpny, {FC045B52}
[?] IPCHD10.dll 7 no vrfy, {1CDC6625}
[?] IPCJD20.dll 49 no vrfy, time mism., {C6518D36}
[?] IPCMD10.dll 7 no vrfy, {C2DF6374}
[?] IPCXD10.dll 7 no vrfy, {C61EFC69}
[?] java.exe 7 no vrfy, {CC202D61}
[?] javacpl.cpl 14 no vrfy, {8CE328B6}
[?] javaw.exe 7 no vrfy, {5B8FBA2E}
[?] javaws.exe 7 no vrfy, {11CD9E2A}
[?] langserv.dll 7 no vrfy, {7275A6ED}
[?] lfbmp13n.dll 7 no vrfy, {41D5FF24}
[?] LFCMP13n.DLL 7 no vrfy, {B18DD5EC}
[?] lffax13n.dll 7 no vrfy, {B43074AB}
[?] LFJ2K13n.dll 7 no vrfy, {ED93E1BE}
[?] Lfpct13n.dll 7 no vrfy, {35E4D44B}
[?] lftga13n.dll 7 no vrfy, {0C7DC9C4}
[?] lftif13n.dll 7 no vrfy, {0C9A5332}
[?] Lfwmf13n.dll 7 no vrfy, {673D9097}
[?] libmmd.dll 12 ncmpny, {1D797317}
[?] LTCLR13n.dll 14 no vrfy, {5A927A2F}
[?] ltfil13n.DLL 7 no vrfy, {1AC6CCCC}
[?] ltkrn13n.dll 7 no vrfy, {CAF265D9}
[?] ltremove.exe 7 no vrfy, {D4F98423}
[?] mindex.dll 12 ncmpny, {321B69FF}
[?] MLPagAx.dll 7 no vrfy, {A2CA61C9}
[?] MMAviAx.dll 7 no vrfy, {C652CDFD}
[?] MousePage.dll MOUSEP~1.DLL 14 no vrfy, {B56AE5C8}
[?] msisam11.dll 12 ncmpny, {B599D894}
[?] MSLDBUSR.DLL 12 ncmpny, {C910A67F}
[?] MSRDO20.DLL 12 ncmpny, {17058418}
[?] msuni11.dll 12 ncmpny, {4838DFF3}
[?] NetworkAPI.dll NETWOR~1.DLL 7 no vrfy, {2C1CA00F}
[?] Ntaccess.sys 14 no vrfy, {147C8BB0}
[?] NVDHE50.dll 7 no vrfy, {2760E3CB}
[?] NVDME50.dll 7 no vrfy, {6823D550}
[?] OUTLWAB.DLL 12 ncmpny, {1832171B}
[?] PCLEGetGuid.dll PCLEGE~1.DLL 7 no vrfy, {04576B32}
[?] postprocess.dll POSTPR~1.DLL 7 no vrfy, {526634B8}
[X] PSDrvCheck.CHS PSDRVC~1.CHS 100 ncmpny, cx (CODE)?, {6EB8960F}
[X] PSDrvCheck.CHT PSDRVC~1.CHT 100 ncmpny, cx (CODE)?, {7D5846F7}
[X] PSDrvCheck.DE PSDRVC~1.DE 100 ncmpny, cx (CODE)?, {193CA392}
[X] PSDrvCheck.DEU PSDRVC~1.DEU 100 ncmpny, cx (CODE)?, {193CA392}
[X] PSDrvCheck.ES PSDRVC~1.ES 100 ncmpny, cx (CODE)?, {2B9F0505}
[X] PSDrvCheck.ESP PSDRVC~1.ESP 100 ncmpny, cx (CODE)?, {2B9F0505}
[X] PSDrvCheck.exe PSDRVC~1.EXE 100 ncmpny, cx (CODE)?, {C0655735}
[X] PSDrvCheck.FR PSDRVC~1.FR 100 ncmpny, cx (CODE)?, {463B960E}
[X] PSDrvCheck.FRA PSDRVC~1.FRA 100 ncmpny, cx (CODE)?, {463B960E}
[X] PSDrvCheck.IT PSDRVC~1.IT 100 ncmpny, cx (CODE)?, {EC437E0F}
[X] PSDrvCheck.ITA PSDRVC~1.ITA 100 ncmpny, cx (CODE)?, {EC437E0F}
[X] PSDrvCheck.JP PSDRVC~1.JP 100 ncmpny, cx (CODE)?, {CC8D5B16}
[X] PSDrvCheck.JPN PSDRVC~1.JPN 100 ncmpny, cx (CODE)?, {CC8D5B16}
[X] PSDrvCheck.KO PSDRVC~1.KO 100 ncmpny, cx (CODE)?, {5EF9D637}
[X] PSDrvCheck.KOR PSDRVC~1.KOR 100 ncmpny, cx (CODE)?, {FD0C89A2}
[X] PSDrvCheck.NL PSDRVC~1.NL 100 ncmpny, cx (CODE)?, {DE1F7773}
[X] PSDrvCheck.NLD PSDRVC~1.NLD 100 ncmpny, cx (CODE)?, {DE1F7773}
[?] pvmjpg21.dll 14 no vrfy, {45E9532D}
[?] RALMain.dll 7 no vrfy, {871EDDC8}
[?] RDOCURS.DLL 12 ncmpny, {4D094B02}
[?] RTClientSDK71.dll RTCLIE~1.DLL 7 no vrfy, {8A89613C}
[?] UCS32P.DLL 7 no vrfy, {3C231252}
[?] vdrmux.dll 7 no vrfy, {82F11A7C}
[?] wmidx.ocx 12 ncmpny, {22DE4980}
[?] wmpstub.exe 25 ncmpny, {8D6131AE}
[?] wmv8dmod.dll 12 ncmpny, {AAA13CAA}
[?] wmvcore2.dll 12 ncmpny, {D95FD06C}
[?] wmvdmoe.dll 12 ncmpny, {6E06840B}
[?] xpsp1hfm.exe 12 ncmpny, {98A44F1B}
[?] Xrypassd.dll 7 no vrfy, {D59582EB}
[?] xvidvfw.dll 12 ncmpny, {F8FDCF29}
[?] XWheel.dll 14 no vrfy, {075C6039}
\Drivers:
[?] asapiW2k.sys 14 no vrfy, {076C2F7F}
[?] aswRdr.sys 7 no vrfy, {5F5489E5}
[?] avmwan.sys 7 no vrfy, {7ECB2B4C}
[?] Camd905c.sys 7 no vrfy, {816F96E2}
[?] Capt905c.sys 7 no vrfy, {6CD1302F}
[?] FlashSys.sys 25 ncmpny, {89B88EB8}
[?] fxusbase.sys 7 no vrfy, {F22A9DE4}
[?] GMFilter.sys 14 no vrfy, {5ABF26CF}
[?] Pclepci.sys 14 no vrfy, {FDAED5C7}
[?] sp_rsdrv2.sys SP_RSD~1.SYS 25 ncmpny, {0FB6D88F}
================================================================
Ultimate Process Manager v4.1.3 - [ Lodus Software ]