Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Olmarik.ZC

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
15tomasp15
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 07 dub 2009 06:21

Olmarik.ZC

#1 Příspěvek od 15tomasp15 »

Zdravím, ESET Smart Security mi ukazuje že súbor partmgr.sys je infikovaný - Olmarik.ZC a nedá sa liečiť, keď som ho chcel testunúť na virustotale tak keď som ten súbor vybral mi vyhodilo že nemám dostatočné oprávnenia, skúšal som ich aj meniť ale nejde to(mám konto z plnými admin právami), išiel som do núdzového režimu a cez to to ide:

Kód: Vybrat vše

http://www.virustotal.com/file-scan/report.html?id=3030e8d369e423b590199320ed86b7925b50be4c8e3db43aa57abba6dd13e2f1-1296475667
Je v umiestnení C:\Windows\winsxs\x86_microsoft-windows-partitionmanager_31bf3856ad364e35_6.1.7600.16385_none_e17269af1bc32604

a tu je log z RSIT, prosím o kontrolu a zároveň aj ďakujem vopred :)

Logfile of random's system information tool 1.08 (written by random/random)
Run by Paťo at 2011-01-31 13:15:25
Microsoft Windows 7 Ultimate
System drive C: has 62 GB (30%) free of 206 GB
Total RAM: 2559 MB (70% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:15:39, on 31. 1. 2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16700)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Paťo\Desktop\Download\RSIT.exe
C:\Program Files\trend micro\Paťo.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [reset] regedit /s reset.reg
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDow ... ab_nvd.cab
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDow ... rtScan.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/f ... wflash.cab
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} - http://content.systemrequirementslab.co ... 4.16.0.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: lxddCATSCustConnectService - Lexmark International, Inc. - C:\Windows\system32\spool\DRIVERS\W32X86\3\\lxddserv.exe
O23 - Service: lxdd_device - - C:\Windows\system32\lxddcoms.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: O&O Defrag Agent (OODefragAgent) - O&O Software GmbH - C:\Program Files\OO Software\Defrag\oodag.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

--
End of file - 5606 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 501400]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2010-08-12 2215064]
"reset"=regedit /s reset.reg []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1173504]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files\ICQ7.2\ICQ.exe [2011-01-05 133432]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2010-12-06 1910152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxddamon]
C:\Program Files\Lexmark 2500 Series\lxddamon.exe [2009-04-27 25256]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxddmon.exe]
C:\Program Files\Lexmark 2500 Series\lxddmon.exe [2009-04-27 291496]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
C:\Program Files\OO Software\Defrag\oodtray.exe [2010-09-30 2773320]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PAC7302_Monitor]
C:\Windows\PixArt\PAC7302\Monitor.exe [2006-11-03 319488]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe [2007-03-14 83608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2011-01-31 13:15:25 ----D---- C:\rsit
2011-01-31 13:15:25 ----D---- C:\Program Files\trend micro
2011-01-31 13:06:20 ----A---- C:\Windows\ntbtlog.txt
2011-01-31 11:29:28 ----A---- C:\Windows\system32\OpenCL.dll
2011-01-31 11:29:28 ----A---- C:\Windows\system32\nvoglv32.dll
2011-01-31 11:29:28 ----A---- C:\Windows\system32\nvgenco322040.dll
2011-01-31 11:29:28 ----A---- C:\Windows\system32\nvdispco322090.dll
2011-01-31 11:29:28 ----A---- C:\Windows\system32\nvcuvid.dll
2011-01-31 11:29:28 ----A---- C:\Windows\system32\nvcuvenc.dll
2011-01-31 11:29:28 ----A---- C:\Windows\system32\nvcuda.dll
2011-01-31 11:29:28 ----A---- C:\Windows\system32\nvcompiler.dll
2011-01-31 11:29:28 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2011-01-31 01:07:05 ----D---- C:\Program Files\SystemRequirementsLab
2011-01-30 20:50:09 ----D---- C:\Users\Paťo\AppData\Roaming\GetRightToGo
2011-01-30 15:11:20 ----D---- C:\ProgramData\SUPERAntiSpyware.com
2011-01-30 12:23:29 ----D---- C:\Program Files\Yamicsoft
2011-01-24 21:35:29 ----D---- C:\Program Files\FinalWire
2011-01-23 17:17:18 ----D---- C:\Program Files\FlatOut2
2011-01-11 22:30:24 ----A---- C:\Windows\system32\odbc32.dll
2011-01-11 22:30:22 ----A---- C:\Windows\system32\d3d10warp.dll
2011-01-11 22:30:22 ----A---- C:\Windows\system32\d2d1.dll
2011-01-11 22:30:21 ----A---- C:\Windows\system32\DWrite.dll
2011-01-11 22:30:20 ----A---- C:\Windows\system32\XpsPrint.dll
2011-01-11 22:30:20 ----A---- C:\Windows\system32\mf.dll
2011-01-11 22:30:20 ----A---- C:\Windows\system32\FntCache.dll
2011-01-11 22:30:19 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-01-11 22:30:19 ----A---- C:\Windows\system32\WMVDECOD.DLL
2011-01-11 22:30:19 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-01-11 22:30:19 ----A---- C:\Windows\system32\d3d10_1core.dll
2011-01-11 22:30:18 ----A---- C:\Windows\system32\XpsRasterService.dll
2011-01-11 22:30:18 ----A---- C:\Windows\system32\mfreadwrite.dll
2011-01-11 22:30:18 ----A---- C:\Windows\system32\ExplorerFrame.dll
2011-01-11 22:30:18 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-01-11 22:30:18 ----A---- C:\Windows\system32\cdd.dll
2011-01-11 22:30:17 ----A---- C:\Windows\system32\d3d10_1.dll
2011-01-07 23:42:42 ----D---- C:\Users\Paťo\AppData\Roaming\VitySoft
2011-01-07 22:19:21 ----A---- C:\Windows\IsUninst.exe
2011-01-07 22:16:11 ----D---- C:\Program Files\Sports Interactive
2011-01-07 21:06:44 ----A---- C:\Windows\system32\easyUpdatusAPIU.dll
2011-01-07 21:06:34 ----A---- C:\Windows\system32\nvcpl.dll
2011-01-07 21:06:14 ----A---- C:\Windows\system32\nvsvc.dll
2011-01-07 21:06:02 ----A---- C:\Windows\system32\nvvsvc.exe
2011-01-07 21:06:02 ----A---- C:\Windows\system32\nvmctray.dll
2011-01-07 02:43:34 ----D---- C:\Program Files\LogMeIn Hamachi
2011-01-05 20:13:40 ----D---- C:\Program Files\THQ
2011-01-05 15:13:01 ----D---- C:\Program Files\Google
2011-01-05 12:56:49 ----D---- C:\Users\Paťo\AppData\Roaming\HandBrake

======List of files/folders modified in the last 1 months======

2011-01-31 13:15:26 ----D---- C:\Windows\Temp
2011-01-31 13:15:25 ----AD---- C:\Program Files
2011-01-31 13:12:10 ----D---- C:\Windows
2011-01-31 13:11:42 ----D---- C:\Windows\system32\config
2011-01-31 13:11:35 ----D---- C:\ProgramData\NVIDIA
2011-01-31 13:06:19 ----D---- C:\Windows\System32
2011-01-31 13:04:46 ----D---- C:\Users\Paťo\AppData\Roaming\AIMP
2011-01-31 11:53:54 ----D---- C:\Users\Paťo\AppData\Roaming\Winamp
2011-01-31 11:31:16 ----SHD---- C:\Windows\Installer
2011-01-31 11:30:43 ----D---- C:\Windows\inf
2011-01-31 11:30:20 ----D---- C:\Program Files\NVIDIA Corporation
2011-01-31 11:29:43 ----D---- C:\Windows\system32\drivers
2011-01-31 11:29:40 ----D---- C:\Windows\system32\catroot
2011-01-31 11:29:39 ----D---- C:\Windows\system32\DriverStore
2011-01-31 10:38:17 ----D---- C:\Program Files\Czech Soccer Manager 2002 FE
2011-01-31 01:09:47 ----D---- C:\Users\Paťo\AppData\Roaming\uTorrent
2011-01-31 01:07:03 ----D---- C:\Windows\Downloaded Program Files
2011-01-30 16:43:22 ----D---- C:\Windows\debug
2011-01-30 16:42:34 ----SHD---- C:\System Volume Information
2011-01-30 15:11:20 ----HD---- C:\ProgramData
2011-01-30 14:55:05 ----D---- C:\Users\Paťo\AppData\Roaming\Skype
2011-01-30 14:16:49 ----D---- C:\Users\Paťo\AppData\Roaming\skypePM
2011-01-30 13:12:25 ----D---- C:\Windows\Prefetch
2011-01-29 12:09:05 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-01-29 01:37:13 ----D---- C:\Users\Paťo\AppData\Roaming\ICQ
2011-01-27 07:04:34 ----D---- C:\Windows\system32\catroot2
2011-01-26 19:58:13 ----D---- C:\Program Files\Lx_cats
2011-01-23 18:01:26 ----A---- C:\Windows\win.ini
2011-01-21 06:56:22 ----D---- C:\Windows\system32\oodag
2011-01-17 19:42:00 ----D---- C:\Windows\system32\Tasks
2011-01-11 22:36:41 ----D---- C:\Windows\winsxs
2011-01-11 22:34:15 ----A---- C:\Windows\system32\MRT.exe
2011-01-11 22:34:02 ----D---- C:\ProgramData\Microsoft Help
2011-01-09 08:45:12 ----D---- C:\Program Files\Microsoft Games for Windows - LIVE
2011-01-09 08:45:01 ----D---- C:\Program Files\Common Files\microsoft shared
2011-01-08 23:50:47 ----D---- C:\Program Files\Activision
2011-01-08 21:35:23 ----D---- C:\Program Files\Rockstar Games
2011-01-08 04:27:00 ----A---- C:\Windows\system32\nvwgf2um.dll
2011-01-08 04:27:00 ----A---- C:\Windows\system32\nvd3dum.dll
2011-01-08 04:27:00 ----A---- C:\Windows\system32\nvapi.dll
2011-01-07 22:20:47 ----A---- C:\Windows\system.ini
2011-01-07 22:18:36 ----SD---- C:\Users\Paťo\AppData\Roaming\Microsoft
2011-01-07 19:57:17 ----D---- C:\Program Files\ICQ7.2
2011-01-05 15:13:06 ----D---- C:\Windows\Tasks

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 BtHidBus;Bluetooth HID Bus Service; C:\Windows\System32\Drivers\BtHidBus.sys [2010-04-06 20104]
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-10-16 691696]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-07-29 115008]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-07-29 136632]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2010-07-29 134512]
R2 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2010-07-29 41336]
R2 irda;IrDA Protocol; C:\Windows\system32\DRIVERS\irda.sys [2009-07-14 96768]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys [2010-07-29 32608]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
R3 irsir;Microsoft Serial Infrared Driver; C:\Windows\system32\DRIVERS\irsir.sys [2008-01-19 20992]
R3 nvmpu401;Service for NVIDIA(R) nForce(TM) MIDI UART; C:\Windows\system32\drivers\nvmpu401.sys [2005-04-13 10240]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-03-01 139776]
S3 ahftufz1;ahftufz1; C:\Windows\system32\drivers\ahftufz1.sys []
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BT;Bluetooth PAN Network Adapter; C:\Windows\system32\DRIVERS\btnetdrv.sys []
S3 BTCOM;Bluetooth Serial port driver; C:\Windows\system32\DRIVERS\btcomport.sys []
S3 BTCOMBUS;Bluetooth Serial Port Bus Service; C:\Windows\System32\Drivers\btcombus.sys []
S3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\Windows\System32\Drivers\btcusb.sys []
S3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 392704]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 58880]
S3 btnetBUs;Bluetooth PAN Bus Service; C:\Windows\System32\Drivers\btnetBus.sys [2010-04-06 25864]
S3 IvtBtBUs;IVT Bluetooth Bus Service; C:\Windows\System32\Drivers\IvtBtBus.sys [2010-04-06 23048]
S3 PAC7302;PC Camera; C:\Windows\system32\DRIVERS\PAC7302.SYS [2007-11-08 458752]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 s116bus;Sony Ericsson Device 116 driver (WDM); C:\Windows\system32\DRIVERS\s116bus.sys [2007-04-03 83336]
S3 s116nd5;Sony Ericsson Device 116 USB Ethernet Emulation SEMC116 (NDIS); C:\Windows\system32\DRIVERS\s116nd5.sys [2007-04-03 23176]
S3 s116obex;Sony Ericsson Device 116 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s116obex.sys [2007-04-03 98696]
S3 s116unic;Sony Ericsson Device 116 USB Ethernet Emulation SEMC116 (WDM); C:\Windows\system32\DRIVERS\s116unic.sys [2007-04-03 99080]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 SCREAMINGBDRIVER;Screaming Bee Audio; C:\Windows\system32\drivers\ScreamingBAudio.sys [2009-11-26 34384]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 VComm;Virtual Serial port driver; C:\Windows\system32\DRIVERS\VComm.sys []
S3 VcommMgr;Bluetooth VComm Manager Service; C:\Windows\System32\Drivers\VcommMgr.sys []
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2010-08-12 810144]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2010-12-06 1238408]
R2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 lxdd_device;lxdd_device; C:\Windows\system32\lxddcoms.exe [2007-05-25 537520]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2011-01-07 608872]
R2 OODefragAgent;O&O Defrag Agent; C:\Program Files\OO Software\Defrag\oodag.exe [2010-09-30 2397512]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-01-07 378984]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 1529728]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-01-05 136176]
S2 lxddCATSCustConnectService;lxddCATSCustConnectService; C:\Windows\system32\spool\DRIVERS\W32X86\3\\lxddserv.exe [2007-05-25 99248]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2010-08-12 33584]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-11-10 774144]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-09-08 575488]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-10-16 1343400]

-----------------EOF-----------------

15tomasp15
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 07 dub 2009 06:21

Re: Olmarik.ZC

#2 Příspěvek od 15tomasp15 »

Skúšal som aj samostatný nástroj od ESETu na odstránenie Olmarika(na stránke majú na nejaké 2 verzie) a obydve mi ukázali že v systéme nič nieje :/

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Olmarik.ZC

#3 Příspěvek od motji »

Ahoj,
máš docela slušnej problém, Mbr rootkit je pěkná mrška :) .
Takže se spolu domluvíme - ty odinstaluješ ten nelegální Eset, a já Ti pomůžu, oki? :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

15tomasp15
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 07 dub 2009 06:21

Re: Olmarik.ZC

#4 Příspěvek od 15tomasp15 »

Ciao,

:O ale ja nepoužívam (už) žiadny aktivátor/cracker alebo čo na antivírus, mám tam normálne licenciu - normálne meno a heslo nie žiadny crack alebo čo...

/EDIT - je možné že keď som preinštaloval windows bez formátu že tam niečo zostalo čo vidíš na logu? :O

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Olmarik.ZC

#5 Příspěvek od motji »

Nezlob se na mě, ale to Ti nevěřím. Dívala jsem se, že Nod jsi měl už dřív, i Eset, ten jsi už mohl mít dřív nelegální.
Takže ho prosím odstran. Pokud si trváš na svém, že je legální, piš si, že si na Tě dám pozor a budu Tě pěkně hlídat :evil: :D

:!: Zazálohuj důležitá data, pro jistotu.

:arrow: Spusťcombofix podle tohoto návodu
http://www.bleepingcomputer.com/combofi ... t-combofix
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

15tomasp15
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 07 dub 2009 06:21

Re: Olmarik.ZC

#6 Příspěvek od 15tomasp15 »

Niečo sme si povedali cez SS :D niečo teraz tu :) :

keď som spustil CF tak ukázalo že sú spustené rootkity(alebo niečo v tom zmysle :D ) a tu je ich zoznam: ntos, oembios, twext, twex, sdra64, intel64, wsnpoema, swin32, localsys64, 64dlls, sdra73 a kernel32 - všetko exe súbory, tak sa to resťartovalo a začal sken počas ktorého mi dvakrát vyhodilo že PEV.cfxxe prestal pracovať a raz PEV.exe prestal pracovať - keď som klikol na Ukončiť(jediná možnosť ktorá tam bola) tak sken pokračoval ďalej, tu je log, ďakujem :) :

ComboFix 11-01-31.01 - Paťo . 01. 2011 22:14:07.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.421.1033.18.2559.1806 [GMT 1:00]
Running from: c:\users\Paťo\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Paťo\AppData\Roaming\WindowsApplication1
c:\users\Paťo\AppData\Roaming\WindowsApplication1\WindowsApplication1.config
c:\users\Pato\AppData\Roaming\64dlls.exe
c:\users\Pato\AppData\Roaming\intel64.exe
c:\users\Pato\AppData\Roaming\Kernel32.exe
c:\users\Pato\AppData\Roaming\localsys64.exe
c:\users\Pato\AppData\Roaming\ntos.exe
c:\users\Pato\AppData\Roaming\oembios.exe
c:\users\Pato\AppData\Roaming\sdra64.exe
c:\users\Pato\AppData\Roaming\sdra73.exe
c:\users\Pato\AppData\Roaming\swin32.exe
c:\users\Pato\AppData\Roaming\twex.exe
c:\users\Pato\AppData\Roaming\twext.exe
c:\users\Pato\AppData\Roaming\wsnpoema.exe

.
((((((((((((((((((((((((( Files Created from 2010-12-28 to 2011-01-31 )))))))))))))))))))))))))))))))
.

2011-01-31 21:20 . 2011-01-31 21:21 -------- d-----w- c:\users\Paťo\AppData\Local\temp
2011-01-31 21:20 . 2011-01-31 21:20 -------- d-----w- c:\users\Zorka\AppData\Local\temp
2011-01-31 21:20 . 2011-01-31 21:20 -------- d-----w- c:\users\eL_Lucho\AppData\Local\temp
2011-01-31 21:20 . 2011-01-31 21:20 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-01-31 21:17 . 2011-01-31 21:17 -------- d-----w- c:\users\Pato
2011-01-31 12:15 . 2011-01-31 12:15 -------- d-----w- C:\rsit
2011-01-31 12:15 . 2011-01-31 12:15 -------- d-----w- c:\program files\trend micro
2011-01-31 10:29 . 2011-01-08 03:27 941160 ----a-w- c:\windows\system32\nvdispco322090.dll
2011-01-31 10:29 . 2011-01-08 03:27 837736 ----a-w- c:\windows\system32\nvgenco322040.dll
2011-01-31 10:29 . 2011-01-08 03:27 57960 ----a-w- c:\windows\system32\OpenCL.dll
2011-01-31 10:29 . 2011-01-08 03:27 4941928 ----a-w- c:\windows\system32\nvcuda.dll
2011-01-31 10:29 . 2011-01-08 03:27 2895976 ----a-w- c:\windows\system32\nvcuvid.dll
2011-01-31 10:29 . 2011-01-08 03:27 2251368 ----a-w- c:\windows\system32\nvcuvenc.dll
2011-01-31 10:29 . 2011-01-08 03:27 15047272 ----a-w- c:\windows\system32\nvoglv32.dll
2011-01-31 10:29 . 2011-01-08 03:27 13011560 ----a-w- c:\windows\system32\nvcompiler.dll
2011-01-31 10:29 . 2011-01-08 03:27 10467656 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2011-01-31 00:07 . 2011-01-31 00:07 -------- d-----w- c:\program files\SystemRequirementsLab
2011-01-30 19:50 . 2011-01-30 19:58 -------- d-----w- c:\users\Paťo\AppData\Roaming\GetRightToGo
2011-01-30 14:57 . 2009-09-02 09:20 652 ----a-w- c:\windows\FIX.reg
2011-01-30 14:57 . 2008-11-01 12:23 280 ----a-w- c:\windows\reset.reg
2011-01-30 14:11 . 2011-01-30 14:11 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-01-30 11:23 . 2011-01-30 11:23 -------- d-----w- c:\program files\Yamicsoft
2011-01-26 21:07 . 2011-01-26 23:07 -------- d-----w- c:\users\eL_Lucho\AppData\Local\LogMeIn Hamachi
2011-01-24 21:26 . 2011-01-24 21:26 -------- d-----w- c:\users\Paťo\AppData\Local\BuildAGadget Content
2011-01-24 20:35 . 2011-01-24 20:35 -------- d-----w- c:\program files\FinalWire
2011-01-24 16:33 . 2011-01-24 16:34 -------- d-----w- c:\users\eL_Lucho\AppData\Roaming\GetRightToGo
2011-01-23 16:17 . 2011-01-23 16:19 -------- d-----w- c:\program files\FlatOut2
2011-01-07 22:42 . 2011-01-07 22:42 -------- d-----w- c:\users\Paťo\AppData\Roaming\VitySoft
2011-01-07 21:19 . 1998-10-02 18:00 327168 ----a-w- c:\windows\IsUninst.exe
2011-01-07 21:18 . 2011-01-07 21:18 49152 ----a-r- c:\users\Paťo\AppData\Roaming\Microsoft\Installer\{EC0AB585-B279-4A77-8BB5-64C403E43EE7}\fm2005segatest1_EC0AB585B2794A778BB564C403E43EE7.exe
2011-01-07 21:18 . 2011-01-07 21:18 49152 ----a-r- c:\users\Paťo\AppData\Roaming\Microsoft\Installer\{EC0AB585-B279-4A77-8BB5-64C403E43EE7}\editor_EC0AB585B2794A778BB564C403E43EE7.exe
2011-01-07 21:16 . 2011-01-07 21:16 -------- d-----w- c:\program files\Sports Interactive
2011-01-07 20:06 . 2011-01-07 20:06 580200 ----a-w- c:\windows\system32\easyUpdatusAPIU.dll
2011-01-07 20:06 . 2011-01-07 20:06 3597416 ----a-w- c:\windows\system32\nvcpl.dll
2011-01-07 20:06 . 2011-01-07 20:06 2620520 ----a-w- c:\windows\system32\nvsvc.dll
2011-01-07 20:06 . 2011-01-07 20:06 608872 ----a-w- c:\windows\system32\nvvsvc.exe
2011-01-07 20:06 . 2011-01-07 20:06 111208 ----a-w- c:\windows\system32\nvmctray.dll
2011-01-07 10:30 . 2011-01-07 10:30 -------- d-----w- c:\users\eL_Lucho\AppData\Roaming\AIMP
2011-01-07 10:28 . 2011-01-07 10:28 -------- d-----w- c:\users\eL_Lucho\AppData\Local\4A Games
2011-01-07 10:27 . 2011-01-07 10:27 -------- d-----w- c:\users\eL_Lucho\AppData\Roaming\HandBrake
2011-01-07 10:27 . 2011-01-07 10:27 -------- d-----w- c:\users\eL_Lucho\AppData\Local\HandBrake
2011-01-07 01:44 . 2011-01-07 01:47 -------- d-----w- c:\users\Paťo\AppData\Local\LogMeIn Hamachi
2011-01-07 01:43 . 2011-01-07 01:47 -------- d-----w- c:\program files\LogMeIn Hamachi
2011-01-05 19:44 . 2011-01-05 19:44 -------- d-----w- c:\users\Paťo\AppData\Local\4A Games
2011-01-05 19:13 . 2011-01-05 19:13 -------- d-----w- c:\program files\THQ
2011-01-05 14:13 . 2011-01-05 14:14 -------- d-----w- c:\program files\Google
2011-01-05 14:13 . 2011-01-05 14:13 -------- d-----w- c:\users\Paťo\AppData\Local\Google
2011-01-05 11:56 . 2011-01-05 11:59 -------- d-----w- c:\users\Paťo\AppData\Roaming\HandBrake
2011-01-05 11:56 . 2011-01-05 11:56 -------- d-----w- c:\users\Paťo\AppData\Local\HandBrake

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-08 03:27 . 2011-01-31 10:29 10920 ----a-w- c:\windows\system32\drivers\nvBridge.kmd
2011-01-08 03:27 . 2010-10-16 09:55 10078312 ----a-w- c:\windows\system32\nvd3dum.dll
2011-01-08 03:27 . 2010-10-16 09:55 1965672 ----a-w- c:\windows\system32\nvapi.dll
2011-01-08 03:27 . 2009-07-13 22:09 5653096 ----a-w- c:\windows\system32\nvwgf2um.dll
2010-12-19 22:21 . 2009-07-13 23:11 56912 ----a-w- c:\windows\system32\drivers\partmgr.sys
2010-12-19 22:21 . 2009-07-13 23:11 56912 ------w- c:\windows\system32\drivers\partmgr.sys.copy
2010-11-29 15:28 . 2010-11-29 15:28 348160 ----a-w- c:\windows\system32\Msvcr71.dll
2010-11-29 15:28 . 2010-11-29 15:28 1700352 ----a-w- c:\windows\system32\gdiplus.dll
2010-11-29 15:28 . 2010-11-29 15:28 1060864 ----a-w- c:\windows\system32\mfc71.dll
2010-11-29 15:26 . 2010-11-29 15:26 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-11-19 14:55 . 2010-11-19 14:55 292696 ----a-w- c:\windows\system32\XceedFtp.dll
2010-11-10 15:02 . 2010-11-10 15:02 56912 ----a-w- c:\windows\system32\drivers\mcvhpstw.sys
2010-11-04 05:52 . 2010-12-14 21:24 978944 ----a-w- c:\windows\system32\wininet.dll
2010-11-04 05:48 . 2010-12-14 21:24 44544 ----a-w- c:\windows\system32\licmgr10.dll
2010-11-04 04:41 . 2010-12-14 21:24 386048 ----a-w- c:\windows\system32\html.iec
2010-11-04 04:08 . 2010-12-14 21:24 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2010-09-28 19:44 . 2010-09-28 19:44 1196032 ----a-w- c:\program files\Game CD Key List 3.90.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"reset"="regedit" [X]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-20 21:07 932288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-09-23 02:47 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
2010-03-13 12:54 91520 ----a-w- c:\program files\Microsoft Office\Office14\BCSSync.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
2011-01-05 08:18 133432 ----a-w- c:\program files\ICQ7.2\ICQ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
2010-12-06 07:31 1910152 ----a-w- c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxddamon]
2009-04-27 11:37 25256 ----a-w- c:\program files\Lexmark 2500 Series\lxddamon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxddmon.exe]
2009-04-27 11:37 291496 ----a-w- c:\program files\Lexmark 2500 Series\lxddmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 13:40 155648 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
2010-09-30 10:27 2773320 ----a-w- c:\program files\OO Software\Defrag\oodtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PAC7302_Monitor]
2006-11-03 10:01 319488 ----a-w- c:\windows\PixArt\PAC7302\Monitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2007-03-14 01:43 83608 ----a-w- c:\program files\Java\jre1.6.0_01\bin\jusched.exe

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-01-05 136176]
R2 lxddCATSCustConnectService;lxddCATSCustConnectService;c:\windows\system32\spool\DRIVERS\W32X86\3\\lxddserv.exe [2007-05-25 99248]
R3 BTCOM;Bluetooth Serial port driver;c:\windows\system32\DRIVERS\btcomport.sys [x]
R3 BTCOMBUS;Bluetooth Serial Port Bus Service;c:\windows\system32\Drivers\btcombus.sys [x]
R3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\Drivers\btnetBus.sys [2010-04-06 25864]
R3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\Drivers\IvtBtBus.sys [2010-04-06 23048]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
R3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [2009-11-25 34384]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2010-10-16 1343400]
S0 BtHidBus;Bluetooth HID Bus Service;c:\windows\System32\Drivers\BtHidBus.sys [2010-04-06 20104]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-10-16 691696]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-07-29 136632]
S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [2010-12-06 1238408]
S2 lxdd_device;lxdd_device;c:\windows\system32\lxddcoms.exe [2007-05-25 537520]
S2 OODefragAgent;O&O Defrag Agent;c:\program files\OO Software\Defrag\oodag.exe [2010-09-30 2397512]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-01-07 378984]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-03-01 139776]

.
Contents of the 'Scheduled Tasks' folder

2011-01-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-01-05 14:13]

2011-01-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-01-05 14:13]
.
.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
FF - ProfilePath -
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG14.00.00.01PROFESSIONAL"="2DDF99B0A265651BE2FC288B710F88AD330F126E68CE4A8E1F0B983F553C67820265C51AB56DF0CD8241F4BC7145668D1860E3412A934CD618F4E0AC8D07D92F5FB27BCC486B404B7FB949607B3C6F2E82D14797C7867A00BE6F32DEE89481CEB70D06FA5FF1368B145385772C3DE6619713C86098439959C00F6BD095F6C2CF640EBC4E212A7A3860CA0DF74224D3AFE028807D17FDB468323C72F068D747D31F24F2E25AD077AE6AB347C9A5E30455CCE804445F7C186307B232A3D6EF7E2E87FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808A2D97226D213B555BA7FD869164D6794C038D530D6EB345206143E4279F2A95E231FCE890899B1E9DD234444A953F4773B52D1F8EA9C8E81719499B1D4CA2136B2AF365C63B75293477C1CB1BA81879F71A940ADC25C7CAA2B1A1A9D00E7AD1EA945EAB9CA2904E33C31DFD1C780DF53ED757A7F3EBA6BB98154CBFBB8313DE53BE108F172F6D1D2F6B5596C989549D20FB915CFDB6080579AF8336651CEF63FF0099BF4A1697E3C838043ED09CD41C3877E99A3ABBB9992ECBFC39AAEAD32402845295BB20FFEDDC68B4EE50B777AABDF4E062452F844DBC4E569FACDFD7C638E25275F963A7CDB73D49D08A1A5DC79703AC91D0B10450942AC810D3A381587AC3A02E1CE02563E15E04AACE4B001FB69D54A7FA1B59353D7575EFA9791F06E599897E2F3BE1C6F0935DF4F02B136694D36E1E1F7695AD7CE2FC4929B8A38BE42DB3B8BB0109340815C5F1038890057F27A5CFA83E87998C101EFC612E1C80367A0B425C4D6B7E203653A345D5A934584407AA94CB9057B219D8E2BD69D32299D88BDA082BAB4EDE8E1DA21D70B5B12012C72ED71A2C3C73059C07B5E07B9848D39060FD2A46C5FDF6A9DE425C877013CE46CEBA2B032AC070D9D95ADABD5CB35DC31282F43F394E998CF2D5580B8BCDB1785ED26B4FDBA1195307ADFDB3697E32154C5280916D15D0B38500DE526D05B714F6055C08C6810D274D0232D38E73F377D6860ABCE3E62648EC383F07AAD89284DD39C30750E15A9DDE23878729DBFD3A8B10FA551E4794B7C26855CA42708727B7D7D9C82E90883D21DF65B2C8132B3CA69803482B571EAA4B5732746764E0DC3368EE5341D274C2B91C936E3BA38904A7A12DA7A8372F09956C1933738A737097A77323FAB00F4B6F72E2F47DAC4AF82F3B85E0886F411E490F82B806B32B39FEBF5E80981F77237A837AF3D53A15441077BC9AD5AC602018F353761F461CA50CF5B352E6A453CE22289635E79EBC84B0C75EA1F7C0BFC5EA3A547CB9DFA48D80D8C88FD18F450E206E13BF48714DA577D55D446D13542E0C08F2EE7929A7BE9328495FC20E42FD61A8C6E839D5F5C8EFADEDCC1"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-01-31 22:22:33
ComboFix-quarantined-files.txt 2011-01-31 21:22

Pre-Run: 65 132 859 392 bytes free
Post-Run: 66 563 706 880 bytes free

- - End Of File - - BF98FB0CF0FB40E23D54DB205708B3D6

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Olmarik.ZC

#7 Příspěvek od motji »

Nejspíš sis to tou přeinstalací vyléčil.
Ale s tím Nodem jsi mi opravdu lhal :?:
2011-01-30 14:57 . 2009-09-02 09:20 652 ----a-w- c:\windows\FIX.reg
2011-01-30 14:57 . 2008-11-01 12:23 280 ----a-w- c:\windows\reset.reg
tohle Ti v pc nemohlo zůstat z dřívějška, takže si na mě dávej pozor, jak uvidím v Tvém logu Nod, tak píši moderátorovi, ať topic zamkne :) .

Otestuj na www.virustotal.com
c:\windows\system32\drivers\mcvhpstw.sys
c:\windows\system32\drivers\partmgr.sys

-Do okénka zkopírujte cestu k souboru , pokud napíše, že soubor byl už testován, dejte otestovat znovu.
-Sem vložte link s výsledky.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

15tomasp15
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 07 dub 2009 06:21

Re: Olmarik.ZC

#8 Příspěvek od 15tomasp15 »

Niečo v PM, zvyšok tu....

Kód: Vybrat vše

http://www.virustotal.com/file-scan/reanalysis.html?id=871e4f8300afe2ae770b8f00c12911a08d8bbd8e07c37a11aff67ca92607a602-1296574989
http://www.virustotal.com/file-scan/reanalysis.html?id=871e4f8300afe2ae770b8f00c12911a08d8bbd8e07c37a11aff67ca92607a602-1296575013
Obydva sú čisté, čo ďalej? :)

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Olmarik.ZC

#9 Příspěvek od motji »

Dej reanalyse
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

15tomasp15
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 07 dub 2009 06:21

Re: Olmarik.ZC

#10 Příspěvek od 15tomasp15 »

Kód: Vybrat vše

http://www.virustotal.com/file-scan/report.html?id=871e4f8300afe2ae770b8f00c12911a08d8bbd8e07c37a11aff67ca92607a602-1296653610
http://www.virustotal.com/file-scan/report.html?id=871e4f8300afe2ae770b8f00c12911a08d8bbd8e07c37a11aff67ca92607a602-1296653774
Čo ďalej? :)


/CF môžem odinštalovať?

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Olmarik.ZC

#11 Příspěvek od motji »

Můžu Ti tento driver smazat? I když je na virustotalu čistý, nelíbí se mi
c:\windows\system32\drivers\mcvhpstw.sys
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

15tomasp15
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 07 dub 2009 06:21

Re: Olmarik.ZC

#12 Příspěvek od 15tomasp15 »

No ja neviem čo to je :D pokial to nič nepokazí tak áno :)

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Olmarik.ZC

#13 Příspěvek od motji »

:arrow: Pokud nemáte, přesuňte Combofix na plochu
-otevřete si Poznámkový blok
-Do něj zkopírujte text z tohoto okénka

Kód: Vybrat vše


Collect::
c:\windows\system32\drivers\mcvhpstw.sys

File::
c:\windows\FIX.reg
c:\windows\reset.reg

registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"reset"=-

-uložte Vámi vytvořený TXT soubor jako CFScript.txt na plochu
-po uložení uchopte vámi vytvořený skript levým myšítkem a -přesuňte ho nad ikonu Combofixu, kde ho upustíte:

Obrázek


-po aplikaci na Vás vypadne další log,vložte ho sem

Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou, v tom případě znovu restartujte a přitom mačkejte F8, pak zvolte Poslední známou funkční konfiguraci



:arrow: stahněte na plochu CKScanner.exe
http://downloads.malwareremoval.com/CKScanner.exe
-uložte na plochu a spusťte
-klikněte na "Search For Files"
-spustí se sken, až skončí klikněte na "Save List To File" a potvrdte Ok
-na ploše se objeví textový soubor CKFiles.txt, obsah sem vložte :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

15tomasp15
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 07 dub 2009 06:21

Re: Olmarik.ZC

#14 Příspěvek od 15tomasp15 »

Tak mi to znova vyhodilo tie súbory(keď sa predtým zmazali prečo sú tam znova? :) ) čo aj predtým(pred skenom) - reštartoval sa PC a potom sken:

ComboFix 11-01-31.02 - Paťo . 02. 2011 13:59:02.2.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.421.1033.18.2559.1658 [GMT 1:00]
Running from: c:\users\Paťo\Desktop\ComboFix.exe
Command switches used :: c:\users\Paťo\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

FILE ::
"c:\windows\FIX.reg"
"c:\windows\reset.reg"

file zipped: c:\windows\system32\drivers\mcvhpstw.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Pato\AppData\Roaming\64dlls.exe
c:\users\Pato\AppData\Roaming\intel64.exe
c:\users\Pato\AppData\Roaming\Kernel32.exe
c:\users\Pato\AppData\Roaming\localsys64.exe
c:\users\Pato\AppData\Roaming\ntos.exe
c:\users\Pato\AppData\Roaming\oembios.exe
c:\users\Pato\AppData\Roaming\sdra64.exe
c:\users\Pato\AppData\Roaming\sdra73.exe
c:\users\Pato\AppData\Roaming\swin32.exe
c:\users\Pato\AppData\Roaming\twex.exe
c:\users\Pato\AppData\Roaming\twext.exe
c:\users\Pato\AppData\Roaming\wsnpoema.exe
c:\windows\FIX.reg
c:\windows\reset.reg
c:\windows\system32\drivers\mcvhpstw.sys

.
((((((((((((((((((((((((( Files Created from 2011-01-03 to 2011-02-03 )))))))))))))))))))))))))))))))
.

2011-02-03 13:06 . 2011-02-03 13:06 -------- d-----w- c:\users\Paťo\AppData\Local\temp
2011-02-03 13:06 . 2011-02-03 13:06 -------- d-----w- c:\users\Zorka\AppData\Local\temp
2011-02-03 13:06 . 2011-02-03 13:06 -------- d-----w- c:\users\eL_Lucho\AppData\Local\temp
2011-02-03 13:06 . 2011-02-03 13:06 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-02-03 13:06 . 2011-02-03 13:06 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2011-02-02 13:55 . 2011-01-13 00:41 5890896 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-02-02 13:54 . 2011-01-13 00:41 5890896 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3006171E-D593-4857-ACFF-C9FF1660938B}\mpengine.dll
2011-02-01 20:09 . 2011-02-01 20:09 5322 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2011-02-01 16:41 . 2011-02-01 16:40 439632 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D624405D-E533-4F9D-8C61-1F2DA4C57242}\gapaengine.dll
2011-02-01 16:38 . 2011-02-01 16:39 -------- d-----w- c:\program files\Microsoft Security Client
2011-02-01 16:38 . 2010-04-09 07:24 240008 ----a-w- c:\windows\system32\drivers\netio.sys
2011-01-31 21:17 . 2011-01-31 21:17 -------- d-----w- c:\users\Pato\AppData\Local\Microsoft
2011-01-31 21:17 . 2011-01-31 21:17 -------- d-----w- c:\users\Pato
2011-01-31 12:15 . 2011-01-31 12:15 -------- d-----w- C:\rsit
2011-01-31 12:15 . 2011-01-31 12:15 -------- d-----w- c:\program files\trend micro
2011-01-31 10:29 . 2011-01-08 03:27 941160 ----a-w- c:\windows\system32\nvdispco322090.dll
2011-01-31 10:29 . 2011-01-08 03:27 837736 ----a-w- c:\windows\system32\nvgenco322040.dll
2011-01-31 10:29 . 2011-01-08 03:27 57960 ----a-w- c:\windows\system32\OpenCL.dll
2011-01-31 10:29 . 2011-01-08 03:27 4941928 ----a-w- c:\windows\system32\nvcuda.dll
2011-01-31 10:29 . 2011-01-08 03:27 2895976 ----a-w- c:\windows\system32\nvcuvid.dll
2011-01-31 10:29 . 2011-01-08 03:27 2251368 ----a-w- c:\windows\system32\nvcuvenc.dll
2011-01-31 10:29 . 2011-01-08 03:27 15047272 ----a-w- c:\windows\system32\nvoglv32.dll
2011-01-31 10:29 . 2011-01-08 03:27 13011560 ----a-w- c:\windows\system32\nvcompiler.dll
2011-01-31 10:29 . 2011-01-08 03:27 10467656 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2011-01-31 00:07 . 2011-01-31 00:07 -------- d-----w- c:\program files\SystemRequirementsLab
2011-01-30 19:50 . 2011-01-30 19:58 -------- d-----w- c:\users\Paťo\AppData\Roaming\GetRightToGo
2011-01-30 14:11 . 2011-01-30 14:11 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-01-30 11:23 . 2011-01-30 11:23 -------- d-----w- c:\program files\Yamicsoft
2011-01-26 21:07 . 2011-01-26 23:07 -------- d-----w- c:\users\eL_Lucho\AppData\Local\LogMeIn Hamachi
2011-01-24 21:26 . 2011-01-24 21:26 -------- d-----w- c:\users\Paťo\AppData\Local\BuildAGadget Content
2011-01-24 20:35 . 2011-01-24 20:35 -------- d-----w- c:\program files\FinalWire
2011-01-24 16:33 . 2011-01-24 16:34 -------- d-----w- c:\users\eL_Lucho\AppData\Roaming\GetRightToGo
2011-01-23 16:17 . 2011-01-23 16:19 -------- d-----w- c:\program files\FlatOut2
2011-01-07 22:42 . 2011-01-07 22:42 -------- d-----w- c:\users\Paťo\AppData\Roaming\VitySoft
2011-01-07 21:19 . 1998-10-02 18:00 327168 ----a-w- c:\windows\IsUninst.exe
2011-01-07 21:18 . 2011-01-07 21:18 49152 ----a-r- c:\users\Paťo\AppData\Roaming\Microsoft\Installer\{EC0AB585-B279-4A77-8BB5-64C403E43EE7}\fm2005segatest1_EC0AB585B2794A778BB564C403E43EE7.exe
2011-01-07 21:18 . 2011-01-07 21:18 49152 ----a-r- c:\users\Paťo\AppData\Roaming\Microsoft\Installer\{EC0AB585-B279-4A77-8BB5-64C403E43EE7}\editor_EC0AB585B2794A778BB564C403E43EE7.exe
2011-01-07 21:16 . 2011-01-07 21:16 -------- d-----w- c:\program files\Sports Interactive
2011-01-07 20:06 . 2011-01-07 20:06 580200 ----a-w- c:\windows\system32\easyUpdatusAPIU.dll
2011-01-07 20:06 . 2011-01-07 20:06 3597416 ----a-w- c:\windows\system32\nvcpl.dll
2011-01-07 20:06 . 2011-01-07 20:06 2620520 ----a-w- c:\windows\system32\nvsvc.dll
2011-01-07 20:06 . 2011-01-07 20:06 608872 ----a-w- c:\windows\system32\nvvsvc.exe
2011-01-07 20:06 . 2011-01-07 20:06 111208 ----a-w- c:\windows\system32\nvmctray.dll
2011-01-07 10:30 . 2011-01-07 10:30 -------- d-----w- c:\users\eL_Lucho\AppData\Roaming\AIMP
2011-01-07 10:28 . 2011-01-07 10:28 -------- d-----w- c:\users\eL_Lucho\AppData\Local\4A Games
2011-01-07 10:27 . 2011-01-07 10:27 -------- d-----w- c:\users\eL_Lucho\AppData\Roaming\HandBrake
2011-01-07 10:27 . 2011-01-07 10:27 -------- d-----w- c:\users\eL_Lucho\AppData\Local\HandBrake
2011-01-07 01:44 . 2011-01-07 01:47 -------- d-----w- c:\users\Paťo\AppData\Local\LogMeIn Hamachi
2011-01-07 01:43 . 2011-01-07 01:47 -------- d-----w- c:\program files\LogMeIn Hamachi
2011-01-05 19:44 . 2011-01-05 19:44 -------- d-----w- c:\users\Paťo\AppData\Local\4A Games
2011-01-05 19:13 . 2011-01-05 19:13 -------- d-----w- c:\program files\THQ
2011-01-05 14:13 . 2011-01-05 14:14 -------- d-----w- c:\program files\Google
2011-01-05 14:13 . 2011-01-05 14:13 -------- d-----w- c:\users\Paťo\AppData\Local\Google
2011-01-05 11:56 . 2011-01-05 11:59 -------- d-----w- c:\users\Paťo\AppData\Roaming\HandBrake
2011-01-05 11:56 . 2011-01-05 11:56 -------- d-----w- c:\users\Paťo\AppData\Local\HandBrake

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-08 03:27 . 2011-01-31 10:29 10920 ----a-w- c:\windows\system32\drivers\nvBridge.kmd
2011-01-08 03:27 . 2010-10-16 09:55 10078312 ----a-w- c:\windows\system32\nvd3dum.dll
2011-01-08 03:27 . 2010-10-16 09:55 1965672 ----a-w- c:\windows\system32\nvapi.dll
2011-01-08 03:27 . 2009-07-13 22:09 5653096 ----a-w- c:\windows\system32\nvwgf2um.dll
2010-12-19 22:21 . 2009-07-13 23:11 56912 ----a-w- c:\windows\system32\drivers\partmgr.sys
2010-12-19 22:21 . 2009-07-13 23:11 56912 ------w- c:\windows\system32\drivers\partmgr.sys.copy
2010-11-29 15:28 . 2010-11-29 15:28 348160 ----a-w- c:\windows\system32\Msvcr71.dll
2010-11-29 15:28 . 2010-11-29 15:28 1700352 ----a-w- c:\windows\system32\gdiplus.dll
2010-11-29 15:28 . 2010-11-29 15:28 1060864 ----a-w- c:\windows\system32\mfc71.dll
2010-11-29 15:26 . 2010-11-29 15:26 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-11-19 14:55 . 2010-11-19 14:55 292696 ----a-w- c:\windows\system32\XceedFtp.dll
2010-09-28 19:44 . 2010-09-28 19:44 1196032 ----a-w- c:\program files\Game CD Key List 3.90.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-20 21:07 932288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-09-23 02:47 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
2010-03-13 12:54 91520 ----a-w- c:\program files\Microsoft Office\Office14\BCSSync.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
2011-01-05 08:18 133432 ----a-w- c:\program files\ICQ7.2\ICQ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
2010-12-06 07:31 1910152 ----a-w- c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxddamon]
2009-04-27 11:37 25256 ----a-w- c:\program files\Lexmark 2500 Series\lxddamon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxddmon.exe]
2009-04-27 11:37 291496 ----a-w- c:\program files\Lexmark 2500 Series\lxddmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 13:40 155648 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
2010-09-30 10:27 2773320 ----a-w- c:\program files\OO Software\Defrag\oodtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PAC7302_Monitor]
2006-11-03 10:01 319488 ----a-w- c:\windows\PixArt\PAC7302\Monitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2007-03-14 01:43 83608 ----a-w- c:\program files\Java\jre1.6.0_01\bin\jusched.exe

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-01-05 136176]
R2 lxddCATSCustConnectService;lxddCATSCustConnectService;c:\windows\system32\spool\DRIVERS\W32X86\3\\lxddserv.exe [2007-05-25 99248]
R3 BTCOM;Bluetooth Serial port driver;c:\windows\system32\DRIVERS\btcomport.sys [x]
R3 BTCOMBUS;Bluetooth Serial Port Bus Service;c:\windows\system32\Drivers\btcombus.sys [x]
R3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\Drivers\btnetBus.sys [2010-04-06 25864]
R3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\Drivers\IvtBtBus.sys [2010-04-06 23048]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-24 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-24 54144]
R3 NisSrv;Kontrola siete od spoločnosti Microsoft;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
R3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [2009-11-25 34384]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2010-10-16 1343400]
S0 BtHidBus;Bluetooth HID Bus Service;c:\windows\System32\Drivers\BtHidBus.sys [2010-04-06 20104]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-10-16 691696]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-07-29 136632]
S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [2010-12-06 1238408]
S2 lxdd_device;lxdd_device;c:\windows\system32\lxddcoms.exe [2007-05-25 537520]
S2 OODefragAgent;O&O Defrag Agent;c:\program files\OO Software\Defrag\oodag.exe [2010-09-30 2397512]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-01-07 378984]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-03-01 139776]


--- Other Services/Drivers In Memory ---

*NewlyCreated* - CFCATCHME
*Deregistered* - CFcatchme
.
Contents of the 'Scheduled Tasks' folder

2011-02-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-01-05 14:13]

2011-02-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-01-05 14:13]
.
.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
FF - ProfilePath -
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG14.00.00.01PROFESSIONAL"="2DDF99B0A265651BE2FC288B710F88AD330F126E68CE4A8E1F0B983F553C67820265C51AB56DF0CD8241F4BC7145668D1860E3412A934CD618F4E0AC8D07D92F5FB27BCC486B404B7FB949607B3C6F2E82D14797C7867A00BE6F32DEE89481CEB70D06FA5FF1368B145385772C3DE6619713C86098439959C00F6BD095F6C2CF640EBC4E212A7A3860CA0DF74224D3AFE028807D17FDB468323C72F068D747D31F24F2E25AD077AE6AB347C9A5E30455CCE804445F7C186307B232A3D6EF7E2E87FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808A2D97226D213B555BA7FD869164D6794C038D530D6EB345206143E4279F2A95E231FCE890899B1E9DD234444A953F4773B52D1F8EA9C8E81719499B1D4CA2136B2AF365C63B75293477C1CB1BA81879F71A940ADC25C7CAA2B1A1A9D00E7AD1EA945EAB9CA2904E33C31DFD1C780DF53ED757A7F3EBA6BB98154CBFBB8313DE53BE108F172F6D1D2F6B5596C989549D20FB915CFDB6080579AF8336651CEF63FF0099BF4A1697E3C838043ED09CD41C3877E99A3ABBB9992ECBFC39AAEAD32402845295BB20FFEDDC68B4EE50B777AABDF4E062452F844DBC4E569FACDFD7C638E25275F963A7CDB73D49D08A1A5DC79703AC91D0B10450942AC810D3A381587AC3A02E1CE02563E15E04AACE4B001FB69D54A7FA1B59353D7575EFA9791F06E599897E2F3BE1C6F0935DF4F02B136694D36E1E1F7695AD7CE2FC4929B8A38BE42DB3B8BB0109340815C5F1038890057F27A5CFA83E87998C101EFC612E1C80367A0B425C4D6B7E203653A345D5A934584407AA94CB9057B219D8E2BD69D32299D88BDA082BAB4EDE8E1DA21D70B5B12012C72ED71A2C3C73059C07B5E07B9848D39060FD2A46C5FDF6A9DE425C877013CE46CEBA2B032AC070D9D95ADABD5CB35DC31282F43F394E998CF2D5580B8BCDB1785ED26B4FDBA1195307ADFDB3697E32154C5280916D15D0B38500DE526D05B714F6055C08C6810D274D0232D38E73F377D6860ABCE3E62648EC383F07AAD89284DD39C30750E15A9DDE23878729DBFD3A8B10FA551E4794B7C26855CA42708727B7D7D9C82E90883D21DF65B2C8132B3CA69803482B571EAA4B5732746764E0DC3368EE5341D274C2B91C936E3BA38904A7A12DA7A8372F09956C1933738A737097A77323FAB00F4B6F72E2F47DAC4AF82F3B85E0886F411E490F82B806B32B39FEBF5E80981F77237A837AF3D53A15441077BC9AD5AC602018F353761F461CA50CF5B352E6A453CE22289635E79EBC84B0C75EA1F7C0BFC5EA3A547CB9DFA48D80D8C88FD18F450E206E13BF48714DA577D55D446D13542E0C08F2EE7929A7BE9328495FC20E42FD61A8C6E839D5F5C8EFADEDCC1"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-02-03 14:07:50
ComboFix-quarantined-files.txt 2011-02-03 13:07
ComboFix2.txt 2011-01-31 21:22

Pre-Run: 52 850 888 704 bytes free
Post-Run: 52 786 294 784 bytes free

- - End Of File - - 045D5007F1B8BD401A1129CBFCDCFDC2


Potom to napísalo že to chce odoslať nejaký súbor na bližšiu analýzu - dal som ok ale potom že je server dočasne nedostupný alebo také niečo a že to mám potom odoslať ručne - pozeral som čo je v tom zip archíve a je tam ten .sys súbor

Kód: Vybrat vše

http://i53.tinypic.com/nohegi.png
Inak znova mi naskakovalo že pev.exe a pev.cfxxe prestal pracovať(každé zvlásť) ......idem na CKScanner, potom pošlem log...

Tak tu je log, som myslel že to bude niečo dlhšie :D

CKScanner - Additional Security Risks - These are not necessarily bad
scanner sequence 3.RP.11
----- EOF -----

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Olmarik.ZC

#15 Příspěvek od motji »

Fajn, spust ten combofix znovu.
Jinak jak to vypadá s počítačem?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Odpovědět