Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Win32/Olmarik

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Kn1gu4
Návštěvník
Návštěvník
Příspěvky: 136
Registrován: 20 črc 2010 20:37

Re: Win32/Olmarik

#31 Příspěvek od Kn1gu4 »

tak som zapol combofix , ale naskočilo mi tam že complete_stage 1 až po 50 a potom deleting files , reštartoval sa notebook ale žiadny log nenaskočil :?:

Kn1gu4
Návštěvník
Návštěvník
Příspěvky: 136
Registrován: 20 črc 2010 20:37

Re: Win32/Olmarik

#32 Příspěvek od Kn1gu4 »

hmmm tak sa mi nejako podarilo ziskať ten log až na to že v nom absolutne nič nebolo :o

Uživatelský avatar
riffman
VIP
VIP
Příspěvky: 3203
Registrován: 20 říj 2004 07:00
Bydliště: České Budějovice
Kontaktovat uživatele:

Re: Win32/Olmarik

#33 Příspěvek od riffman »

zkuste to v nouzovem rezimu :)
Give us a chance to live
Give us a chance to die
Give us a chance to be free
Without fire from the sky
Give us a chance to love
Give us a chance to hate
Give us a chance, before you kill us all

Kn1gu4
Návštěvník
Návštěvník
Příspěvky: 136
Registrován: 20 črc 2010 20:37

Re: Win32/Olmarik

#34 Příspěvek od Kn1gu4 »

dobre ale bohužial až večer teraz musím odísť :)

Uživatelský avatar
riffman
VIP
VIP
Příspěvky: 3203
Registrován: 20 říj 2004 07:00
Bydliště: České Budějovice
Kontaktovat uživatele:

Re: Win32/Olmarik

#35 Příspěvek od riffman »

v pohode, budu tady prubezne opruzovat ;)
Give us a chance to live
Give us a chance to die
Give us a chance to be free
Without fire from the sky
Give us a chance to love
Give us a chance to hate
Give us a chance, before you kill us all

Kn1gu4
Návštěvník
Návštěvník
Příspěvky: 136
Registrován: 20 črc 2010 20:37

Re: Win32/Olmarik

#36 Příspěvek od Kn1gu4 »

Tak som to skusil v tom nudzovom režime , normalne sa reštartoval PC ale log nenaskočil ...

Uživatelský avatar
riffman
VIP
VIP
Příspěvky: 3203
Registrován: 20 říj 2004 07:00
Bydliště: České Budějovice
Kontaktovat uživatele:

Re: Win32/Olmarik

#37 Příspěvek od riffman »

stahnete a aplikujte D.D.S.


v operacnich systemech Windows Vista a Windows 7 spoustejte aplikaci jako spravce (kliknutim pravym mysitkem na ikonu aplikace a volbou "Spustit jako spravce"
:!:

stazenou aplikaci spustte a vyckejte ukonceni skenu

po ukonceni vam aplikace vytvori dva logy - DDS.txt; jehoz obsah zkopirujte sem, Attach.txt, ktery zatim ponechte ulozeny
Give us a chance to live
Give us a chance to die
Give us a chance to be free
Without fire from the sky
Give us a chance to love
Give us a chance to hate
Give us a chance, before you kill us all

Kn1gu4
Návštěvník
Návštěvník
Příspěvky: 136
Registrován: 20 črc 2010 20:37

Re: Win32/Olmarik

#38 Příspěvek od Kn1gu4 »

DDS (Ver_10-03-17.01) - NTFSx86
Run by Acer at 20:35:52,56 on so 24. 07. 2010
Internet Explorer: 8.0.6001.18828 BrowserJavaVersion: 1.6.0_20
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.421.1051.18.2525.1608 [GMT 2:00]

SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaDeviceMgmt.exe
C:\Program Files\Common Files\Sony Ericsson\Emma Core\Services\EmmaUpdateMgmt.exe
C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
C:\Program Files\ICQ6Toolbar\ICQ Service.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Acer\Mobility Center\MobilityService.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
C:\Windows\system32\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Cyberlink\Shared files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
C:\Windows\System32\TUProgSt.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\System32\alg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Winamp\winampa.exe
C:\Users\Acer\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe
C:\Users\Acer\AppData\Local\Temp\RtkBtMnt.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Zuzka\Desktop\Moje Rádio\MP3\dds.com
C:\Windows\system32\conime.exe
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://search.mywebsearch.com/mywebsearch/default.jhtml?ptnrS=ZJman000&ptb=n5n8wHhLry0R8Gq7_UZVOA
mStart Page = hxxp://home.sweetim.com
uInternet Settings,ProxyOverride = plimus.com,www.plimus.com,regnow.com,www.regnow.com,;*.local
uURLSearchHooks: H - No File
uURLSearchHooks: ICQToolBar: {855f3b16-6d32-4fe6-8a56-bbb695989046} - c:\program files\icq6toolbar\ICQToolBar.dll
uURLSearchHooks: SweetIM ToolbarURLSearchHook Class: {eee6c35d-6118-11dc-9c72-001320c79847} - c:\program files\sweetim\toolbars\internet explorer\mgHelper.dll
mURLSearchHooks: PageRage Toolbar: {9565115d-c7d6-46d3-bd63-b67b481a4368} - c:\program files\pagerage\tbPage.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: PC Tools Browser Guard BHO: {2a0f3d1b-0909-4ff4-b272-609cce6054e7} - c:\program files\spyware doctor\bdt\PCTBrowserDefender.dll
BHO: FGCatchUrl: {2f364306-aa45-47b5-9f9d-39a8b94e7ef7} - c:\progra~1\flashget\Jccatch.dll
BHO: PageRage Toolbar: {9565115d-c7d6-46d3-bd63-b67b481a4368} - c:\program files\pagerage\tbPage.dll
BHO: GdfrDUEn Class: {a3cf7606-e683-4375-a372-96b75da0aef7} - c:\program files\get styles\enlbrdr.dll
BHO: IeMonitorBho Class: {bf00e119-21a3-4fd1-b178-3b8537e75c92} - c:\program files\megaupload\mega manager\MegaIEMn.dll
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: FlashFXP Helper for Internet Explorer: {e5a1691b-d188-4419-ad02-90002030b8ee} - c:\progra~1\flashfxp\IEFlash.dll
BHO: SweetIM Toolbar Helper: {eee6c35c-6118-11dc-9c72-001320c79847} - c:\program files\sweetim\toolbars\internet explorer\mgToolbarIE.dll
BHO: Yontoo Layers: {fd72061e-9fde-484d-a58a-0bab4151cad8} - c:\program files\yontoo layers client\YontooIEClient.dll
BHO: {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - No File
TB: {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File
TB: Acer eDataSecurity Management: {5cbe3b7c-1e47-477e-a7dd-396db0476e29} - c:\program files\acer\empowering technology\edatasecurity\x86\eDStoolbar.dll
TB: {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - No File
TB: ICQToolBar: {855f3b16-6d32-4fe6-8a56-bbb695989046} - c:\program files\icq6toolbar\ICQToolBar.dll
TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - c:\program files\daemon tools toolbar\DTToolbar.dll
TB: {E0E899AB-F487-11D5-8D29-0050BA6940E3} - No File
TB: PageRage Toolbar: {9565115d-c7d6-46d3-bd63-b67b481a4368} - c:\program files\pagerage\tbPage.dll
TB: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - c:\program files\spyware doctor\bdt\PCTBrowserDefender.dll
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: {A057A204-BACC-4D26-C39E-35F1D2A32EC8} - No File
TB: SweetIM Toolbar for Internet Explorer: {eee6c35b-6118-11dc-9c72-001320c79847} - c:\program files\sweetim\toolbars\internet explorer\mgToolbarIE.dll
uRun: [Steam] c:\program files\steam\Steam.exe -silent
uRun: [Google Update] "c:\users\acer\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [Sony Ericsson PC Companion] "c:\program files\sony ericsson\sony ericsson pc companion\PCCompanion.exe" /systray /nologon
uRun: [DAEMON Tools Pro Agent] "c:\program files\daemon tools pro\DTAgent.exe" -autorun
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [PhilipsDM\SA1916] c:\program files\philips\sa19xx\philips device manager\bin\LaunchDM.exe OS_STARTUP
mRun: [egui] "c:\program files\eset\eset smart security\egui.exe" /hide /waitservice
mRun: [WinampAgent] "c:\program files\winamp\winampa.exe"
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Download Link Using Mega Manager... - c:\program files\megaupload\mega manager\mm_file.htm
IE: Download Using &BitSpirit
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: ÓñČĚŘľ«ÁéĎÂÔŘ(&B)
IE: {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - c:\program files\get styles\ct.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {E59EB121-F339-4851-A3BA-FE49C35617C2} - c:\program files\icq6.5\ICQ.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Filter: text/html - {574940E0-1B7A-4881-8FA3-1E809714B156} - c:\users\acer\appdata\locallow\microńoft\redir.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\Skype4COM.dll

============= SERVICES / DRIVERS ===============

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2010-5-7 218592]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-9-11 108792]
R1 FDCENT;FDCENT;c:\windows\system32\drivers\FDCENT.SYS [2009-1-12 47854]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\acer arcade deluxe\playmovie\000.fcl [2008-12-23 61424]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\spyware doctor\bdt\BDTUpdateService.exe [2010-5-7 112592]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\newtech infosystems\nti backup now 5\client\Agentsvc.exe [2008-3-3 16384]
R2 CAMTHWDM;WebcamMax, WDM Video Capture;c:\windows\system32\drivers\CamthWDM.sys [2008-2-9 1053056]
R2 CLHNService;CLHNService;c:\program files\acer arcade deluxe\homemedia\kernel\dmp\CLHNService.exe [2010-1-10 75048]
R2 ekrn;ESET Service;c:\program files\eset\eset smart security\ekrn.exe [2009-9-11 735960]
R2 EmmaDevMgmtSvc;Emma Device Management;c:\program files\common files\sony ericsson\emma core\services\EmmaDeviceMgmt.exe [2010-4-27 306296]
R2 EmmaUpdMgmtSvc;Emma Update Management;c:\program files\common files\sony ericsson\emma core\services\EmmaUpdateMgmt.exe [2010-4-27 162936]
R2 epfwwfp;epfwwfp;c:\windows\system32\drivers\epfwwfp.sys [2009-9-11 38240]
R2 ETService;Empowering Technology Service;c:\program files\acer\empowering technology\service\ETService.exe [2008-5-26 24576]
R2 ICQ Service;ICQ Service;c:\program files\icq6toolbar\ICQ Service.exe [2008-12-27 222456]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\newtech infosystems\nti backup now 5\BackupSvc.exe [2008-4-25 45056]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\newtech infosystems\nti backup now 5\SchedulerSvc.exe [2008-4-25 131072]
R2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\sony ericsson\sony ericsson pc suite\SupServ.exe [2010-5-20 90112]
R2 TeamViewer5;TeamViewer 5;c:\program files\teamviewer\version4\TeamViewer_Service.exe [2010-6-21 173352]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2008-5-27 210432]
R3 enecir;ENE CIR Receiver;c:\windows\system32\drivers\enecir.sys [2008-5-27 54784]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [2008-1-14 21632]
R3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys [2008-12-23 22072]
S2 gupdate1c9906be3877692;Služba Google Update (gupdate1c9906be3877692);c:\program files\google\update\GoogleUpdate.exe [2009-2-16 133104]
S3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [2008-5-26 93968]
S3 PSPRSERV;PSPR Control Service;c:\program files\elcomsoft\proactive system password recovery\psprserv.exe [2009-5-19 69632]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [2010-5-20 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\drivers\s0016mdfl.sys [2010-5-20 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\drivers\s0016mdm.sys [2010-5-20 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0016mgmt.sys [2010-5-20 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\drivers\s0016nd5.sys [2010-5-20 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\drivers\s0016obex.sys [2010-5-20 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\drivers\s0016unic.sys [2010-5-20 115752]
S3 s1029bus;Sony Ericsson Device 1029 driver (WDM);c:\windows\system32\drivers\s1029bus.sys [2010-5-20 90280]
S3 s1029mdfl;Sony Ericsson Device 1029 USB WMC Modem Filter;c:\windows\system32\drivers\s1029mdfl.sys [2010-5-20 15016]
S3 s1029mdm;Sony Ericsson Device 1029 USB WMC Modem Driver;c:\windows\system32\drivers\s1029mdm.sys [2010-5-20 122280]
S3 s1029mgmt;Sony Ericsson Device 1029 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s1029mgmt.sys [2010-5-20 115880]
S3 s1029nd5;Sony Ericsson Device 1029 USB Ethernet Emulation (NDIS);c:\windows\system32\drivers\s1029nd5.sys [2010-5-20 26024]
S3 s1029obex;Sony Ericsson Device 1029 USB WMC OBEX Interface;c:\windows\system32\drivers\s1029obex.sys [2010-5-20 111912]
S3 s1029unic;Sony Ericsson Device 1029 USB Ethernet Emulation (WDM);c:\windows\system32\drivers\s1029unic.sys [2010-5-20 116904]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2010-5-7 366840]
S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2010-5-7 1142224]

=============== Created Last 30 ================

2010-07-24 16:16:50 0 d-----w- c:\program files\Get Styles
2010-07-24 12:53:06 0 d-s---w- C:\ComboFix
2010-07-21 10:22:14 0 d-----w- c:\program files\DAEMON Tools Pro
2010-07-21 10:20:42 0 d-----w- c:\programdata\DAEMON Tools Pro
2010-07-21 09:31:03 0 d-----w- c:\program files\AMR to MP3 Converter
2010-07-20 20:34:02 77312 ----a-w- c:\windows\MBR.exe
2010-07-20 20:05:16 0 d-----w- c:\program files\trend micro
2010-07-20 15:07:48 0 d-----w- c:\program files\Winamp Detect
2010-07-12 13:16:32 0 d-----w- c:\program files\softendo.com
2010-07-06 09:11:55 0 d-----w- c:\users\acer\appdata\roaming\BSplayer Pro
2010-07-06 09:11:55 0 d-----w- c:\users\acer\appdata\roaming\BSplayer
2010-07-06 09:11:33 0 d-----w- c:\program files\Webteh
2010-07-02 14:11:24 0 d-----w- c:\program files\common files\Microsoft Games
2010-07-01 17:43:31 0 d-----w- c:\programdata\Age of Empires 3
2010-06-26 20:25:08 0 d-----w- c:\program files\PowerISO

==================== Find3M ====================

2010-07-21 10:22:51 697328 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-07-21 09:27:51 91576 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2010-06-24 08:15:50 86016 ----a-w- c:\windows\inf\infpub.dat
2010-06-24 08:15:50 143360 ----a-w- c:\windows\inf\infstrng.dat
2010-06-24 08:15:49 86016 ----a-w- c:\windows\inf\infstor.dat
2010-06-17 19:37:21 112 ----a-w- c:\programdata\1fDE886P2.dat
2010-06-16 11:25:03 360192 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2010-06-15 14:48:03 138384 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-06-15 14:45:44 215128 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-06-09 10:10:58 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-06-08 02:16:01 763832 ----a-w- c:\windows\BDTSupport.dll
2010-06-08 00:21:02 1652664 ----a-w- c:\windows\PCTBDCore.dll
2010-05-27 18:53:23 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-05-11 18:15:03 16608 ----a-w- c:\windows\gdrv.sys
2010-04-26 13:58:12 256512 ----a-w- c:\windows\PEV.exe
2008-12-23 16:34:09 665600 ----a-w- c:\windows\inf\drvindex.dat
2008-01-21 05:29:10 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2008-01-21 05:29:10 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2008-01-21 05:29:10 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2008-01-21 05:29:10 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2008-01-21 02:43:21 174 --sha-w- c:\program files\desktop.ini
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-12-29 11:03:45 16384 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2009-12-29 22:03:32 32768 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2009-12-29 22:03:32 16384 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\cookies\index.dat
2009-12-29 22:03:32 16384 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\history\history.ie5\index.dat
2009-12-29 22:03:32 32768 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\temporary internet files\content.ie5\index.dat
2009-12-29 11:03:45 16384 --sha-w- c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\cookies\index.dat
2009-12-29 22:01:45 16384 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2009-12-29 22:03:29 32768 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2009-12-29 22:03:29 16384 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\local\temp\cookies\index.dat
2009-12-29 22:03:29 16384 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\local\temp\history\history.ie5\index.dat
2009-12-29 22:03:29 32768 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\local\temp\temporary internet files\content.ie5\index.dat
2009-12-29 22:01:45 16384 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\cookies\index.dat
2009-10-19 16:05:12 245760 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat

============= FINISH: 20:37:03,51 ===============

Uživatelský avatar
riffman
VIP
VIP
Příspěvky: 3203
Registrován: 20 říj 2004 07:00
Bydliště: České Budějovice
Kontaktovat uživatele:

Re: Win32/Olmarik

#39 Příspěvek od riffman »

c:\users\acer\appdata\locallow\microńoft\redir.dll otestujte na VIRUSTOTALu

(navod prosty: po nacteni stranky kliknete na tlacitko Prochazet, najdete cestu k vyse zminenemu souboru a kliknete na tlacitko Odeslat soubor, ignorujte pripadne hlasky, ze soubor byl jiz testovan a provedte sken znova; dejte skenerum nejakych deset minut; vysledek sem vlozte at uz zkopirovanim textu, nebo pripadne vlozenim odkazu po ukonceni skenu)
Give us a chance to live
Give us a chance to die
Give us a chance to be free
Without fire from the sky
Give us a chance to love
Give us a chance to hate
Give us a chance, before you kill us all

Kn1gu4
Návštěvník
Návštěvník
Příspěvky: 136
Registrován: 20 črc 2010 20:37

Re: Win32/Olmarik

#40 Příspěvek od Kn1gu4 »

prosim vas a kde najdem ten subor , žiadne appdata tam nemam ..

Uživatelský avatar
riffman
VIP
VIP
Příspěvky: 3203
Registrován: 20 říj 2004 07:00
Bydliště: České Budějovice
Kontaktovat uživatele:

Re: Win32/Olmarik

#41 Příspěvek od riffman »

zapnete si zobrazovani skrytych a systemovych souboru ;)
Give us a chance to live
Give us a chance to die
Give us a chance to be free
Without fire from the sky
Give us a chance to love
Give us a chance to hate
Give us a chance, before you kill us all

Kn1gu4
Návštěvník
Návštěvník
Příspěvky: 136
Registrován: 20 črc 2010 20:37

Re: Win32/Olmarik

#42 Příspěvek od Kn1gu4 »

Soubor redir.dll přijatý 2010.07.25 09:42:06 (UTC)
Současný stav: Dokončeno
Výsledek: 1/42 (2.39%)
Formátované
Vytisknout výsledky Antivirus Verze Poslední aktualizace Výsledek
AhnLab-V3 2010.07.24.01 2010.07.23 -
AntiVir 8.2.4.26 2010.07.23 -
Antiy-AVL 2.0.3.7 2010.07.23 -
Authentium 5.2.0.5 2010.07.24 -
Avast 4.8.1351.0 2010.07.25 -
Avast5 5.0.332.0 2010.07.25 -
AVG 9.0.0.851 2010.07.25 -
BitDefender 7.2 2010.07.25 -
CAT-QuickHeal 11.00 2010.07.24 -
ClamAV 0.96.0.3-git 2010.07.24 -
Comodo 5533 2010.07.25 -
DrWeb 5.0.2.03300 2010.07.25 -
Emsisoft 5.0.0.34 2010.07.25 -
eSafe 7.0.17.0 2010.07.22 -
eTrust-Vet 36.1.7734 2010.07.24 -
F-Prot 4.6.1.107 2010.07.24 -
F-Secure 9.0.15370.0 2010.07.25 -
Fortinet 4.1.143.0 2010.07.24 -
GData 21 2010.07.24 -
Ikarus T3.1.1.84.0 2010.07.25 -
Jiangmin 13.0.900 2010.07.25 -
Kaspersky 7.0.0.125 2010.07.25 -
McAfee 5.400.0.1158 2010.07.25 -
McAfee-GW-Edition 2010.1 2010.07.25 Heuristic.BehavesLike.Win32.Worm.H
Microsoft 1.6004 2010.07.25 -
NOD32 5309 2010.07.24 -
Norman 6.05.11 2010.07.25 -
nProtect 2010-07-25.02 2010.07.25 -
Panda 10.0.2.7 2010.07.25 -
PCTools 7.0.3.5 2010.07.25 -
Prevx 3.0 2010.07.25 -
Rising 22.57.03.08 2010.07.23 -
Sophos 4.55.0 2010.07.25 -
Sunbelt 6634 2010.07.25 -
SUPERAntiSpyware 4.40.0.1006 2010.07.25 -
Symantec 20101.1.1.7 2010.07.25 -
TheHacker 6.5.2.1.324 2010.07.25 -
TrendMicro 9.120.0.1004 2010.07.25 -
TrendMicro-HouseCall 9.120.0.1004 2010.07.25 -
VBA32 3.12.12.6 2010.07.23 -
ViRobot 2010.7.23.3956 2010.07.24 -
VirusBuster 5.0.27.0 2010.07.24 -
Rozšiřující informace
File size: 221184 bytes
MD5...: 2bf21b1c00605b267225bca446c9f5d6
SHA1..: f608101ad5581ec3c4f0b9864862538c58fc3675
SHA256: 068547a5541bc2e89ae10a9baea5143dce8adfddc66891c01f71659db529e1c2
ssdeep: 3072:1Fw/nhRtaM2EHqOB0yBOpazNghs1Rn25inT4KdzBLjytIybbx8uy4QcM9gA
MUhR:AvZ2EKW0g2sP25iTpjLutZx8Jl6U
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x1560c
timedatestamp.....: 0x4b6ac3f0 (Thu Feb 04 12:56:16 2010)
machinetype.......: 0x14c (I386)

( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x254ed 0x25600 6.65 ca5b87440407eec76601a5dbd7883bcc
.rdata 0x27000 0x9927 0x9a00 4.79 3b09d12d692590a4537dcf1f83d463e3
.data 0x31000 0x3b7c 0x1e00 3.92 fde2a2c7a385e9d98a96902a40d81364
.rsrc 0x35000 0x1078 0x1200 4.51 13dc338190055cecd8e2844010cd9f83
.reloc 0x37000 0x3b14 0x3c00 5.06 a6f8ae49de5180169e259e636517c9ec

( 10 imports )
> WININET.dll: HttpOpenRequestA, InternetConnectW, InternetConnectA
> KERNEL32.dll: TerminateProcess, CloseHandle, OpenProcess, HeapAlloc, HeapFree, WideCharToMultiByte, GetLastError, WaitForSingleObject, GetProcessHeap, InitializeCriticalSection, DeleteCriticalSection, MultiByteToWideChar, lstrlenA, lstrlenW, LoadResource, SizeofResource, LockResource, ExpandEnvironmentStringsW, CreateDirectoryW, FindResourceW, FreeResource, GetVolumeInformationW, FindResourceExW, HeapReAlloc, GetVersion, GetModuleHandleW, InterlockedIncrement, InterlockedDecrement, GetCurrentThread, GetModuleFileNameW, DisableThreadLibraryCalls, FreeLibrary, LoadLibraryExW, GetThreadLocale, SetThreadLocale, VirtualQuery, GetModuleHandleA, VirtualProtect, InterlockedCompareExchange, ResumeThread, GetThreadContext, SetThreadContext, SuspendThread, VirtualAlloc, SetHandleCount, GetConsoleMode, GetConsoleCP, LCMapStringA, LCMapStringW, IsValidCodePage, GetOEMCP, GetACP, GetCPInfo, TlsFree, TlsSetValue, TlsAlloc, TlsGetValue, GetModuleFileNameA, GetStdHandle, WriteFile, ExitProcess, GetProcAddress, LoadLibraryA, GetCurrentProcessId, GetCurrentThreadId, FlushInstructionCache, RaiseException, LeaveCriticalSection, EnterCriticalSection, CreateThread, GetCurrentProcess, SetLastError, GetEnvironmentStrings, GetFileType, GetStartupInfoA, FreeEnvironmentStringsA, lstrcmpiW, Sleep, HeapCreate, CreateFileA, ReadFile, SetEndOfFile, FlushFileBuffers, SetStdHandle, WriteConsoleW, RtlUnwind, GetCommandLineA, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, HeapSize, HeapDestroy, VirtualFree, IsProcessorFeaturePresent, FreeEnvironmentStringsW, GetEnvironmentStringsW, QueryPerformanceCounter, GetTickCount, GetSystemTimeAsFileTime, InitializeCriticalSectionAndSpinCount, SetFilePointer, GetConsoleOutputCP, WriteConsoleA, CreateFileW, GetStringTypeW, GetStringTypeA, GetLocaleInfoA
> USER32.dll: SetWindowLongW, CharNextW, PostQuitMessage, MessageBoxW, CreateWindowExW, LoadCursorW, GetClassInfoExW, RegisterClassExW, FindWindowExW, SendMessageW, DispatchMessageW, TranslateMessage, GetMessageW, CallWindowProcW, DefWindowProcW, GetWindowLongW, UnregisterClassA
> ADVAPI32.dll: RegEnumKeyExW, RegDeleteValueW, RegQueryInfoKeyW, RegOpenKeyExW, RegDeleteKeyW, RegSetValueExW, RegQueryValueExW, RegCreateKeyExW, RegCloseKey, GetSidSubAuthority, GetSidSubAuthorityCount, GetSidIdentifierAuthority, IsValidSid, GetTokenInformation, OpenProcessToken
> SHELL32.dll: ShellExecuteW
> ole32.dll: StringFromGUID2, CoTaskMemAlloc, CoTaskMemRealloc, CoTaskMemFree, CoMarshalInterThreadInterfaceInStream, CoGetInterfaceAndReleaseStream, CoCreateInstance, CoUninitialize, CoInitialize, CLSIDFromProgID
> OLEAUT32.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -
> SHLWAPI.dll: PathStripPathW, StrDupW
> WS2_32.dll: -, -, WSAEventSelect, WSASetEvent, WSACreateEvent, WSARecv, WSAGetOverlappedResult, WSASend, WSAResetEvent, WSAEnumNetworkEvents, WSAConnect, -, WSASocketW, WSACloseEvent, -, FreeAddrInfoW, GetAddrInfoW, -
> detoured.dll: Detoured

( 5 exports )
DllCanUnloadNow, DllGetClassObject, DllInstall, DllRegisterServer, DllUnregisterServer
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: DirectShow filter (59.7%)
Windows OCX File (36.5%)
Win32 Executable Generic (2.5%)
Generic Win/DOS Executable (0.5%)
DOS Executable Generic (0.5%)
sigcheck:
publisher....: n/a
copyright....: Copyright (C) 2010
product......: redir Dynamic Link Library
description..: redir Dynamic Link Library
original name: redir.dll
internal name: redir
file version.: 1, 0, 0, 1
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned

Uživatelský avatar
riffman
VIP
VIP
Příspěvky: 3203
Registrován: 20 říj 2004 07:00
Bydliště: České Budějovice
Kontaktovat uživatele:

Re: Win32/Olmarik

#43 Příspěvek od riffman »

stahnete si OTL


v operacnich systemech Windows Vista a Windows 7 spoustejte aplikaci jako spravce (kliknutim pravym mysitkem na ikonu aplikace a volbou "Spustit jako spravce"
:!:

po stazeni kliknete na tlacitko Prohledat, nechte to makat, az to dobehne, vysype to log, jeho obsah sem :)
Give us a chance to live
Give us a chance to die
Give us a chance to be free
Without fire from the sky
Give us a chance to love
Give us a chance to hate
Give us a chance, before you kill us all

Kn1gu4
Návštěvník
Návštěvník
Příspěvky: 136
Registrován: 20 črc 2010 20:37

Re: Win32/Olmarik

#44 Příspěvek od Kn1gu4 »

ktore mam dať ? Obrázek

Uživatelský avatar
riffman
VIP
VIP
Příspěvky: 3203
Registrován: 20 říj 2004 07:00
Bydliště: České Budějovice
Kontaktovat uživatele:

Re: Win32/Olmarik

#45 Příspěvek od riffman »

oba ;)
Give us a chance to live
Give us a chance to die
Give us a chance to be free
Without fire from the sky
Give us a chance to love
Give us a chance to hate
Give us a chance, before you kill us all

Odpovědět