Skocz do zawartości

problem z działaniem systemu-po oczyszczaniu dysku


kamil87

Rekomendowane odpowiedzi

Pomoc jest darmowa, ale proszę rozważ przekazanie dotacji na utrzymanie serwisu: klik.
Jak próbuje zaś ręcznie zresetować ten plik- tez nic z tego gdyż u mnie nie ma takich plików/folderów jak Hosts czy %WinDir%\System32\Drivers\Etc

 

Jest plik. Tylko ukryty. Musisz właczyć pokazywanie ukrytych plików systemowych.

 

O1 HOSTS File: ([2011/02/05 23:25:10 | 000,429,816 | R--- | M]) - C:\Windows\SysNative\drivers\etc\hosts

 

I zrób to ręcznie zgodnie z opisem.

 

Szukasz w takiej lokalizacji c:\Windows\System32\drivers\etc\

Odnośnik do komentarza

mam tylko takie pliki skasować backup? czy nie?

 

ale niestety problem dalej się pojawia- przeglądarka ciągle się wiesza( co chwila brak odpowiedzi) i powrót do normalnego stanu

 

 

To który plik mam skasować- nie chciałbym skasować potrzebnego

 

 

dodam jeszcze gmer:

 

GMER 2.1.19357 - http://www.gmer.net
Rootkit scan 2014-02-06 00:59:40
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Intel___ rev.1.0. 931.52GB
Running: wrpu8ni0.exe; Driver: C:\Users\Kamil\AppData\Local\Temp\pfddqpod.sys


---- Kernel code sections - GMER 2.1 ----

INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528                                                                                                                           fffff800031b2000 16 bytes [8B, E3, 41, 5F, 41, 5E, 41, ...]
INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 545                                                                                                                           fffff800031b2011 35 bytes {LEA ECX, [RSP+0x70]; CALL 0x3d64f}
.text     C:\Windows\system32\DRIVERS\USBPORT.SYS!DllUnload                                                                                                                                            fffff88005d1fd8c 12 bytes {MOV RAX, 0xfffffa80072362a0; JMP RAX}

---- User code sections - GMER 2.1 ----

.text     C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe[1648] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter                                                                    0000000075268769 4 bytes [C2, 04, 00, 00]

---- Kernel IAT/EAT - GMER 2.1 ----

IAT       C:\Windows\system32\drivers\pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack]                                                                                                                [fffff88001076650] \SystemRoot\System32\Drivers\spwn.sys [unknown section]
IAT       C:\Windows\system32\drivers\pci.sys[ntoskrnl.exe!IoDetachDevice]                                                                                                                             [fffff880010765dc] \SystemRoot\System32\Drivers\spwn.sys [unknown section]
IAT       C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort]                                                                                                               [fffff8800104135c] \SystemRoot\System32\Drivers\spwn.sys [unknown section]
IAT       C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar]                                                                                                                      [fffff88001041224] \SystemRoot\System32\Drivers\spwn.sys [unknown section]
IAT       C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar]                                                                                                                     [fffff88001041a24] \SystemRoot\System32\Drivers\spwn.sys [unknown section]
IAT       C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort]                                                                                                              [fffff88001041ba0] \SystemRoot\System32\Drivers\spwn.sys [unknown section]

---- User IAT/EAT - GMER 2.1 ----

IAT       C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2444] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmAddToStreamDWord]      [7fef705741c] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT       C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2444] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSet]                   [7fef7055f10] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT       C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2444] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmEndSession]            [7fef7055674] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT       C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2444] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmStartSession]          [7fef7055e2c] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT       C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2444] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmStartUpload]           [7fef7057f48] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT       C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2444] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetAppVersion]         [7fef7056a38] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT       C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2444] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetMachineId]          [7fef7056ee8] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT       C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2444] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmWriteSharedMachineId]  [7fef7057b58] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT       C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2444] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmCreateNewId]           [7fef7057ea0] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT       C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2444] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmReadSharedMachineId]   [7fef70578b0] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT       C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2444] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmGetSession]            [7fef7054fb4] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT       C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2444] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetAppId]              [7fef7055d38] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT       C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2444] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmAddToStreamString]     [7fef7057584] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll

---- Devices - GMER 2.1 ----

Device    \FileSystem\Ntfs \Ntfs                                                                                                                                                                       fffffa8005c402c0
Device    \Driver\usbehci \Device\USBFDO-7                                                                                                                                                             fffffa80072da2c0
Device    \Driver\usbuhci \Device\USBPDO-5                                                                                                                                                             fffffa80072b82c0
Device    \Driver\usbehci \Device\USBFDO-3                                                                                                                                                             fffffa80072da2c0
Device    \Driver\usbuhci \Device\USBPDO-1                                                                                                                                                             fffffa80072b82c0
Device    \Driver\cdrom \Device\CdRom0                                                                                                                                                                 fffffa80061522c0
Device    \Driver\usbuhci \Device\USBPDO-6                                                                                                                                                             fffffa80072b82c0
Device    \Driver\usbuhci \Device\USBFDO-4                                                                                                                                                             fffffa80072b82c0
Device    \Driver\usbuhci \Device\USBFDO-0                                                                                                                                                             fffffa80072b82c0
Device    \Driver\usbuhci \Device\USBPDO-2                                                                                                                                                             fffffa80072b82c0
Device    \Driver\usbehci \Device\USBPDO-7                                                                                                                                                             fffffa80072da2c0
Device    \Driver\usbuhci \Device\USBFDO-5                                                                                                                                                             fffffa80072b82c0
Device    \Driver\usbehci \Device\USBPDO-3                                                                                                                                                             fffffa80072da2c0
Device    \Driver\usbuhci \Device\USBFDO-1                                                                                                                                                             fffffa80072b82c0
Device    \Driver\volmgr \Device\HarddiskVolume1                                                                                                                                                       fffffa8005c342c0
Device    \Driver\NetBT \Device\NetBT_Tcpip_{078E7E47-28A6-405C-B019-72549CA89D9F}                                                                                                                     fffffa800714e2c0
Device    \Driver\volmgr \Device\FtControl                                                                                                                                                             fffffa8005c342c0
Device    \Driver\volmgr \Device\VolMgrControl                                                                                                                                                         fffffa8005c342c0
Device    \Driver\volmgr \Device\HarddiskVolume2                                                                                                                                                       fffffa8005c342c0
Device    \Driver\volmgr \Device\HarddiskVolume3                                                                                                                                                       fffffa8005c342c0
Device    \Driver\volmgr \Device\HarddiskVolume4                                                                                                                                                       fffffa8005c342c0
Device    \Driver\NetBT \Device\NetBt_Wins_Export                                                                                                                                                      fffffa800714e2c0
Device    \Driver\usbuhci \Device\USBFDO-6                                                                                                                                                             fffffa80072b82c0
Device    \Driver\usbuhci \Device\USBPDO-4                                                                                                                                                             fffffa80072b82c0
Device    \Driver\usbuhci \Device\USBFDO-2                                                                                                                                                             fffffa80072b82c0
Device    \Driver\usbuhci \Device\USBPDO-0                                                                                                                                                             fffffa80072b82c0

---- Threads - GMER 2.1 ----

Thread    C:\Windows\System32\svchost.exe [328:4756]                                                                                                                                                   000007fef0966b8c
Thread    C:\Windows\System32\svchost.exe [328:4764]                                                                                                                                                   000007fef0961d88
Thread    C:\Windows\system32\svchost.exe [780:3012]                                                                                                                                                   000007fefad884d8
Thread    C:\Windows\system32\svchost.exe [780:2788]                                                                                                                                                   000007fefac023a8
Thread    C:\Windows\system32\svchost.exe [780:1280]                                                                                                                                                   000007fefac60d00
Thread    C:\Windows\system32\svchost.exe [780:656]                                                                                                                                                    000007fef59d9498
Thread    C:\Windows\system32\svchost.exe [780:4144]                                                                                                                                                   000007fef260506c
Thread    C:\Windows\system32\svchost.exe [780:4148]                                                                                                                                                   000007fefa431c20
Thread    C:\Windows\system32\svchost.exe [780:4160]                                                                                                                                                   000007fefa431c20
Thread    C:\Windows\system32\svchost.exe [780:4844]                                                                                                                                                   000007fef8bf5124
Thread    C:\Windows\system32\svchost.exe [780:6084]                                                                                                                                                   000007fef8b74164
Thread    C:\Windows\system32\svchost.exe [780:2636]                                                                                                                                                   000007fef079cb70
Thread    C:\Windows\system32\svchost.exe [780:2824]                                                                                                                                                   000007fef7281ab0
Thread    C:\Windows\system32\svchost.exe [1232:1272]                                                                                                                                                  000007fef920bd88
Thread    C:\Windows\system32\svchost.exe [1232:2356]                                                                                                                                                  000007fef74983d8
Thread    C:\Windows\system32\svchost.exe [1232:2360]                                                                                                                                                  000007fef74983d8
Thread    C:\Windows\system32\svchost.exe [1232:2364]                                                                                                                                                  000007fef74983d8
Thread    C:\Windows\system32\svchost.exe [1232:2368]                                                                                                                                                  000007fef74983d8
Thread    C:\Windows\system32\svchost.exe [1232:2372]                                                                                                                                                  000007fef74983d8
Thread    C:\Windows\system32\svchost.exe [1232:2376]                                                                                                                                                  000007fef74983d8
Thread    C:\Windows\system32\svchost.exe [1232:2380]                                                                                                                                                  000007fef74983d8
Thread    C:\Windows\system32\svchost.exe [1232:2384]                                                                                                                                                  000007fef74983d8
Thread    C:\Windows\system32\svchost.exe [1232:2404]                                                                                                                                                  000007fef5b03f1c
Thread    C:\Windows\system32\svchost.exe [1232:1252]                                                                                                                                                  000007fefa3b1a38
Thread    C:\Windows\system32\svchost.exe [1232:1540]                                                                                                                                                  000007fef5a55388
Thread    C:\Windows\system32\svchost.exe [1232:2344]                                                                                                                                                  000007fef5a37738
Thread    C:\Windows\system32\svchost.exe [1232:2572]                                                                                                                                                  000007fef5a21f90
Thread    C:\Windows\system32\svchost.exe [1232:3504]                                                                                                                                                  000007fef8bf5124
Thread    C:\Windows\system32\svchost.exe [1232:4092]                                                                                                                                                  000007fef7da5170
Thread    C:\Windows\system32\svchost.exe [1232:3496]                                                                                                                                                  000007fef72c341c
Thread    C:\Windows\system32\svchost.exe [1232:4392]                                                                                                                                                  000007fef72c3a2c
Thread    C:\Windows\system32\svchost.exe [1232:5904]                                                                                                                                                  000007fef72c5c20
Thread    C:\Windows\System32\spoolsv.exe [1440:1840]                                                                                                                                                  000007fef96710c8
Thread    C:\Windows\System32\spoolsv.exe [1440:1844]                                                                                                                                                  000007fef9636144
Thread    C:\Windows\System32\spoolsv.exe [1440:1848]                                                                                                                                                  000007fef9425fd0
Thread    C:\Windows\System32\spoolsv.exe [1440:1852]                                                                                                                                                  000007fef9413438
Thread    C:\Windows\System32\spoolsv.exe [1440:1856]                                                                                                                                                  000007fef94263ec
Thread    C:\Windows\System32\spoolsv.exe [1440:1864]                                                                                                                                                  000007fef9715e5c
Thread    C:\Windows\system32\taskhost.exe [1740:2088]                                                                                                                                                 000007fef7a31010
Thread    C:\Windows\system32\taskhost.exe [1740:3512]                                                                                                                                                 000007fef7da5170
Thread    C:\Program Files\Windows Media Player\wmpnetwk.exe [3612:3720]                                                                                                                               000007fefb6b2a7c
Thread    C:\Windows\System32\svchost.exe [4684:4828]                                                                                                                                                  000007fef05f9688
Thread    C:\Windows\system32\AUDIODG.EXE [3780:1404]                                                                                                                                                  000007fef5f957c4

---- Registry - GMER 2.1 ----

Reg       HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1                                                                                                                                           771343423
Reg       HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2                                                                                                                                           285507792
Reg       HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0                                                                                                                                           1
Reg       HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC                                                                                                             
Reg       HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0                                                                                                          0x00 0x00 0x00 0x00 ...
Reg       HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                                                                                          0
Reg       HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                                                                                                       0x9D 0x5B 0x70 0x86 ...
Reg       HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)                                                                                         
Reg       HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0                                                                                                              0x00 0x00 0x00 0x00 ...
Reg       HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                                                                                              0
Reg       HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                                                                                                           0x9D 0x5B 0x70 0x86 ...
Reg       HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{CD5AC7E3-0CA1-3EC0-0811-4989870DF975}                                                                              
Reg       HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{CD5AC7E3-0CA1-3EC0-0811-4989870DF975}@mampochjoedkmanlgpepipinoi                                                   0x6F 0x61 0x6E 0x6A ...
Reg       HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{CD5AC7E3-0CA1-3EC0-0811-4989870DF975}@abnpnedhfoifhoilpcdnmkjfbpbdalpdeo                                           0x70 0x61 0x70 0x70 ...
Reg       HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted@C:\Users\Kamil\AppData\Local\Temp\JREInstall\x3031\x3237.exe                              1

---- EOF - GMER 2.1 ----
 

post-12635-0-95312500-1391610579_thumb.jpg

Odnośnik do komentarza

Jeśli chcesz dodać odpowiedź, zaloguj się lub zarejestruj nowe konto

Jedynie zarejestrowani użytkownicy mogą komentować zawartość tej strony.

Zarejestruj nowe konto

Załóż nowe konto. To bardzo proste!

Zarejestruj się

Zaloguj się

Posiadasz już konto? Zaloguj się poniżej.

Zaloguj się
  • Ostatnio przeglądający   0 użytkowników

    • Brak zarejestrowanych użytkowników przeglądających tę stronę.
×
×
  • Dodaj nową pozycję...