przez baniol22 07 Kwi 2010, 22:05
Hej, zamieszczam logi z gmera. Ostatnio komputer mi strasznie laguje nawet przy włączonej tylko przeglądarce.

- Kod: Zaznacz wszystko
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-07 22:02:32
Windows 5.1.2600 Dodatek Service Pack 3
Running: p4zbdenn.exe; Driver: C:\DOCUME~1\baniol\USTAWI~1\Temp\uwldqpod.sys
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Winamp\winamp.exe[3528] USER32.dll!SetScrollInfo 7E369056 7 Bytes JMP 0424B6F6 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[3528] USER32.dll!GetScrollInfo 7E37DFE2 7 Bytes JMP 0424B67E C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[3528] USER32.dll!ShowScrollBar 7E37F2F2 5 Bytes JMP 0424B77A C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[3528] USER32.dll!GetScrollPos 7E37F704 5 Bytes JMP 0424B6A6 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[3528] USER32.dll!SetScrollPos 7E37F750 5 Bytes JMP 0424B721 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[3528] USER32.dll!GetScrollRange 7E37F787 5 Bytes JMP 0424B6CB C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[3528] USER32.dll!SetScrollRange 7E37F99B 5 Bytes JMP 0424B74C C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[3528] USER32.dll!EnableScrollBar 7E3B8005 7 Bytes JMP 0424B656 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xCC 0xAC 0x6D 0xBE ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xFE 0x6A 0x06 0xB3 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xBC 0xFF 0xE5 0xE7 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xCC 0xAC 0x6D 0xBE ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xFE 0x6A 0x06 0xB3 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xBC 0xFF 0xE5 0xE7 ...
---- Files - GMER 1.0.15 ----
File C:\Documents and Settings\baniol\Ustawienia lokalne\Temp\WLZEA4B.tmp 0 bytes
File C:\Documents and Settings\baniol\Ustawienia lokalne\Temp\WLZEA4B.tmp\in_swf.lng 0 bytes
File C:\Documents and Settings\baniol\Ustawienia lokalne\Temp\WLZEA4B.tmp\burnlib.lng 0 bytes
File C:\Documents and Settings\baniol\Ustawienia lokalne\Temp\WLZEA4B.tmp\CddbLangPL.dll 0 bytes
File C:\Documents and Settings\baniol\Ustawienia lokalne\Temp\WLZEA4B.tmp\dsp_sps.lng 0 bytes
File C:\Documents and Settings\baniol\Ustawienia lokalne\Temp\WLZEA4B.tmp\enc_aacplus.lng 0 bytes
File C:\Documents and Settings\baniol\Ustawienia lokalne\Temp\WLZEA4B.tmp\enc_flac.lng 0 bytes
File C:\Documents and Settings\baniol\Ustawienia lokalne\Temp\WLZEA4B.tmp\enc_flake.lng 0 bytes
File C:\Documents and Settings\baniol\Ustawienia lokalne\Temp\WLZEA4B.tmp\enc_lame.lng 0 bytes
File C:\Documents and Settings\baniol\Ustawienia lokalne\Temp\WLZEA4B.tmp\enc_vorbis.lng 0 bytes
File C:\Documents and Settings\baniol\Ustawienia lokalne\Temp\WLZEA4B.tmp\enc_wav.lng 0 bytes
File C:\Documents and Settings\baniol\Ustawienia lokalne\Temp\WLZEA4B.tmp\enc_wma.lng 0 bytes
File C:\Documents and Settings\baniol\Ustawienia lokalne\Temp\WLZEA4B.tmp\enqplay_auto.ini 0 bytes
File C:\Documents and Settings\baniol\Ustawienia lokalne\Temp\WLZEA4B.tmp\freeform 0 bytes
---- EOF - GMER 1.0.15 ----