mam tylko takie pliki skasować backup? czy nie?
ale niestety problem dalej się pojawia- przeglądarka ciągle się wiesza( co chwila brak odpowiedzi) i powrót do normalnego stanu
To który plik mam skasować- nie chciałbym skasować potrzebnego
dodam jeszcze gmer:
GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-02-06 00:59:40 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Intel___ rev.1.0. 931.52GB Running: wrpu8ni0.exe; Driver: C:\Users\Kamil\AppData\Local\Temp\pfddqpod.sys ---- Kernel code sections - GMER 2.1 ---- INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff800031b2000 16 bytes [8B, E3, 41, 5F, 41, 5E, 41, ...] INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 545 fffff800031b2011 35 bytes {LEA ECX, [RSP+0x70]; CALL 0x3d64f} .text C:\Windows\system32\DRIVERS\USBPORT.SYS!DllUnload fffff88005d1fd8c 12 bytes {MOV RAX, 0xfffffa80072362a0; JMP RAX} ---- User code sections - GMER 2.1 ---- .text C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe[1648] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 0000000075268769 4 bytes [C2, 04, 00, 00] ---- Kernel IAT/EAT - GMER 2.1 ---- IAT C:\Windows\system32\drivers\pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [fffff88001076650] \SystemRoot\System32\Drivers\spwn.sys [unknown section] IAT C:\Windows\system32\drivers\pci.sys[ntoskrnl.exe!IoDetachDevice] [fffff880010765dc] \SystemRoot\System32\Drivers\spwn.sys [unknown section] IAT C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [fffff8800104135c] \SystemRoot\System32\Drivers\spwn.sys [unknown section] IAT C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [fffff88001041224] \SystemRoot\System32\Drivers\spwn.sys [unknown section] IAT C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [fffff88001041a24] \SystemRoot\System32\Drivers\spwn.sys [unknown section] IAT C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [fffff88001041ba0] \SystemRoot\System32\Drivers\spwn.sys [unknown section] ---- User IAT/EAT - GMER 2.1 ---- IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2444] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmAddToStreamDWord] [7fef705741c] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2444] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSet] [7fef7055f10] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2444] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmEndSession] [7fef7055674] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2444] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmStartSession] [7fef7055e2c] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2444] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmStartUpload] [7fef7057f48] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2444] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetAppVersion] [7fef7056a38] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2444] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetMachineId] [7fef7056ee8] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2444] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmWriteSharedMachineId] [7fef7057b58] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2444] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmCreateNewId] [7fef7057ea0] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2444] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmReadSharedMachineId] [7fef70578b0] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2444] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmGetSession] [7fef7054fb4] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2444] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetAppId] [7fef7055d38] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2444] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmAddToStreamString] [7fef7057584] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll ---- Devices - GMER 2.1 ---- Device \FileSystem\Ntfs \Ntfs fffffa8005c402c0 Device \Driver\usbehci \Device\USBFDO-7 fffffa80072da2c0 Device \Driver\usbuhci \Device\USBPDO-5 fffffa80072b82c0 Device \Driver\usbehci \Device\USBFDO-3 fffffa80072da2c0 Device \Driver\usbuhci \Device\USBPDO-1 fffffa80072b82c0 Device \Driver\cdrom \Device\CdRom0 fffffa80061522c0 Device \Driver\usbuhci \Device\USBPDO-6 fffffa80072b82c0 Device \Driver\usbuhci \Device\USBFDO-4 fffffa80072b82c0 Device \Driver\usbuhci \Device\USBFDO-0 fffffa80072b82c0 Device \Driver\usbuhci \Device\USBPDO-2 fffffa80072b82c0 Device \Driver\usbehci \Device\USBPDO-7 fffffa80072da2c0 Device \Driver\usbuhci \Device\USBFDO-5 fffffa80072b82c0 Device \Driver\usbehci \Device\USBPDO-3 fffffa80072da2c0 Device \Driver\usbuhci \Device\USBFDO-1 fffffa80072b82c0 Device \Driver\volmgr \Device\HarddiskVolume1 fffffa8005c342c0 Device \Driver\NetBT \Device\NetBT_Tcpip_{078E7E47-28A6-405C-B019-72549CA89D9F} fffffa800714e2c0 Device \Driver\volmgr \Device\FtControl fffffa8005c342c0 Device \Driver\volmgr \Device\VolMgrControl fffffa8005c342c0 Device \Driver\volmgr \Device\HarddiskVolume2 fffffa8005c342c0 Device \Driver\volmgr \Device\HarddiskVolume3 fffffa8005c342c0 Device \Driver\volmgr \Device\HarddiskVolume4 fffffa8005c342c0 Device \Driver\NetBT \Device\NetBt_Wins_Export fffffa800714e2c0 Device \Driver\usbuhci \Device\USBFDO-6 fffffa80072b82c0 Device \Driver\usbuhci \Device\USBPDO-4 fffffa80072b82c0 Device \Driver\usbuhci \Device\USBFDO-2 fffffa80072b82c0 Device \Driver\usbuhci \Device\USBPDO-0 fffffa80072b82c0 ---- Threads - GMER 2.1 ---- Thread C:\Windows\System32\svchost.exe [328:4756] 000007fef0966b8c Thread C:\Windows\System32\svchost.exe [328:4764] 000007fef0961d88 Thread C:\Windows\system32\svchost.exe [780:3012] 000007fefad884d8 Thread C:\Windows\system32\svchost.exe [780:2788] 000007fefac023a8 Thread C:\Windows\system32\svchost.exe [780:1280] 000007fefac60d00 Thread C:\Windows\system32\svchost.exe [780:656] 000007fef59d9498 Thread C:\Windows\system32\svchost.exe [780:4144] 000007fef260506c Thread C:\Windows\system32\svchost.exe [780:4148] 000007fefa431c20 Thread C:\Windows\system32\svchost.exe [780:4160] 000007fefa431c20 Thread C:\Windows\system32\svchost.exe [780:4844] 000007fef8bf5124 Thread C:\Windows\system32\svchost.exe [780:6084] 000007fef8b74164 Thread C:\Windows\system32\svchost.exe [780:2636] 000007fef079cb70 Thread C:\Windows\system32\svchost.exe [780:2824] 000007fef7281ab0 Thread C:\Windows\system32\svchost.exe [1232:1272] 000007fef920bd88 Thread C:\Windows\system32\svchost.exe [1232:2356] 000007fef74983d8 Thread C:\Windows\system32\svchost.exe [1232:2360] 000007fef74983d8 Thread C:\Windows\system32\svchost.exe [1232:2364] 000007fef74983d8 Thread C:\Windows\system32\svchost.exe [1232:2368] 000007fef74983d8 Thread C:\Windows\system32\svchost.exe [1232:2372] 000007fef74983d8 Thread C:\Windows\system32\svchost.exe [1232:2376] 000007fef74983d8 Thread C:\Windows\system32\svchost.exe [1232:2380] 000007fef74983d8 Thread C:\Windows\system32\svchost.exe [1232:2384] 000007fef74983d8 Thread C:\Windows\system32\svchost.exe [1232:2404] 000007fef5b03f1c Thread C:\Windows\system32\svchost.exe [1232:1252] 000007fefa3b1a38 Thread C:\Windows\system32\svchost.exe [1232:1540] 000007fef5a55388 Thread C:\Windows\system32\svchost.exe [1232:2344] 000007fef5a37738 Thread C:\Windows\system32\svchost.exe [1232:2572] 000007fef5a21f90 Thread C:\Windows\system32\svchost.exe [1232:3504] 000007fef8bf5124 Thread C:\Windows\system32\svchost.exe [1232:4092] 000007fef7da5170 Thread C:\Windows\system32\svchost.exe [1232:3496] 000007fef72c341c Thread C:\Windows\system32\svchost.exe [1232:4392] 000007fef72c3a2c Thread C:\Windows\system32\svchost.exe [1232:5904] 000007fef72c5c20 Thread C:\Windows\System32\spoolsv.exe [1440:1840] 000007fef96710c8 Thread C:\Windows\System32\spoolsv.exe [1440:1844] 000007fef9636144 Thread C:\Windows\System32\spoolsv.exe [1440:1848] 000007fef9425fd0 Thread C:\Windows\System32\spoolsv.exe [1440:1852] 000007fef9413438 Thread C:\Windows\System32\spoolsv.exe [1440:1856] 000007fef94263ec Thread C:\Windows\System32\spoolsv.exe [1440:1864] 000007fef9715e5c Thread C:\Windows\system32\taskhost.exe [1740:2088] 000007fef7a31010 Thread C:\Windows\system32\taskhost.exe [1740:3512] 000007fef7da5170 Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [3612:3720] 000007fefb6b2a7c Thread C:\Windows\System32\svchost.exe [4684:4828] 000007fef05f9688 Thread C:\Windows\system32\AUDIODG.EXE [3780:1404] 000007fef5f957c4 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x9D 0x5B 0x70 0x86 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x9D 0x5B 0x70 0x86 ... Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{CD5AC7E3-0CA1-3EC0-0811-4989870DF975} Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{CD5AC7E3-0CA1-3EC0-0811-4989870DF975}@mampochjoedkmanlgpepipinoi 0x6F 0x61 0x6E 0x6A ... Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{CD5AC7E3-0CA1-3EC0-0811-4989870DF975}@abnpnedhfoifhoilpcdnmkjfbpbdalpdeo 0x70 0x61 0x70 0x70 ... Reg HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted@C:\Users\Kamil\AppData\Local\Temp\JREInstall\x3031\x3237.exe 1 ---- EOF - GMER 2.1 ----