

Cóż ja mam z tym począć?
Komputer nieźle mi muli dlatego daję też logi:
Gmer
- Kod: Zaznacz wszystko
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-14 15:47:24
Windows 5.1.2600 Dodatek Service Pack 3
Running: sgzj9fqv.exe; Driver: C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\kwqoqpod.sys
---- Kernel code sections - GMER 1.0.15 ----
PAGE ntoskrnl.exe!ExAcquireRundownProtection + 1AF 80570108 7 Bytes JMP 8AB8C150
.text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xB72A3000, 0x1BDE76, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Java\jre6\bin\jqs.exe[332] WS2_32.dll!socket 71A54211 9 Bytes [B8, 40, 18, 00, 10, FF, E0, ...] {MOV EAX, 0x10001840; JMP EAX; NOP ; NOP }
.text C:\Program Files\Java\jre6\bin\jqs.exe[332] WS2_32.dll!connect 71A54A07 8 Bytes [B8, A8, 29, 00, 10, FF, E0, ...] {MOV EAX, 0x100029a8; JMP EAX; NOP }
.text C:\Program Files\Java\jre6\bin\jqs.exe[332] C:\WINDOWS\system32\WS2_32.dll section is writeable [0x71A51000, 0x12153, 0xE0000020]
.reloc C:\Program Files\Java\jre6\bin\jqs.exe[332] C:\WINDOWS\system32\WS2_32.dll section is executable [0x71A66000, 0x1DC8, 0xE0000040]
.text C:\WINDOWS\system32\HPZipm12.exe[504] WS2_32.dll!socket 71A54211 9 Bytes [B8, 40, 18, 00, 10, FF, E0, ...] {MOV EAX, 0x10001840; JMP EAX; NOP ; NOP }
.text C:\WINDOWS\system32\HPZipm12.exe[504] C:\WINDOWS\system32\WS2_32.dll section is writeable [0x71A51000, 0x12153, 0xE0000020]
.reloc C:\WINDOWS\system32\HPZipm12.exe[504] C:\WINDOWS\system32\WS2_32.dll section is executable [0x71A66000, 0x1DC8, 0xE0000040]
.text C:\WINDOWS\system32\PnkBstrA.exe[516] WS2_32.dll!socket 71A54211 9 Bytes [B8, 40, 18, 00, 10, FF, E0, ...] {MOV EAX, 0x10001840; JMP EAX; NOP ; NOP }
.text C:\WINDOWS\system32\PnkBstrA.exe[516] WS2_32.dll!connect 71A54A07 8 Bytes [B8, A8, 29, 00, 10, FF, E0, ...] {MOV EAX, 0x100029a8; JMP EAX; NOP }
.text C:\WINDOWS\system32\PnkBstrA.exe[516] C:\WINDOWS\system32\WS2_32.dll section is writeable [0x71A51000, 0x12153, 0xE0000020]
.reloc C:\WINDOWS\system32\PnkBstrA.exe[516] C:\WINDOWS\system32\WS2_32.dll section is executable [0x71A66000, 0x1DC8, 0xE0000040]
.text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe[556] WS2_32.dll!socket 71A54211 9 Bytes [B8, 40, 18, 00, 10, FF, E0, ...] {MOV EAX, 0x10001840; JMP EAX; NOP ; NOP }
.text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe[556] WS2_32.dll!connect 71A54A07 8 Bytes [B8, A8, 29, 00, 10, FF, E0, ...] {MOV EAX, 0x100029a8; JMP EAX; NOP }
.text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe[556] C:\WINDOWS\system32\WS2_32.dll section is writeable [0x71A51000, 0x12153, 0xE0000020]
.reloc C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe[556] C:\WINDOWS\system32\WS2_32.dll section is executable [0x71A66000, 0x1DC8, 0xE0000040]
.text C:\WINDOWS\system32\winlogon.exe[872] WS2_32.dll!socket 71A54211 9 Bytes [B8, 40, 18, 00, 10, FF, E0, ...] {MOV EAX, 0x10001840; JMP EAX; NOP ; NOP }
.text C:\WINDOWS\system32\winlogon.exe[872] C:\WINDOWS\system32\WS2_32.dll section is writeable [0x71A51000, 0x12153, 0xE0000020]
.reloc C:\WINDOWS\system32\winlogon.exe[872] C:\WINDOWS\system32\WS2_32.dll section is executable [0x71A66000, 0x1DC8, 0xE0000040]
.text C:\WINDOWS\system32\services.exe[916] WS2_32.dll!socket 71A54211 9 Bytes [B8, 40, 18, 00, 10, FF, E0, ...] {MOV EAX, 0x10001840; JMP EAX; NOP ; NOP }
.text C:\WINDOWS\system32\services.exe[916] C:\WINDOWS\system32\WS2_32.dll section is writeable [0x71A51000, 0x12153, 0xE0000020]
.reloc C:\WINDOWS\system32\services.exe[916] C:\WINDOWS\system32\WS2_32.dll section is executable [0x71A66000, 0x1DC8, 0xE0000040]
.text C:\WINDOWS\system32\lsass.exe[932] WS2_32.dll!socket 71A54211 9 Bytes [B8, 40, 18, 00, 10, FF, E0, ...] {MOV EAX, 0x10001840; JMP EAX; NOP ; NOP }
.text C:\WINDOWS\system32\lsass.exe[932] C:\WINDOWS\system32\WS2_32.dll section is writeable [0x71A51000, 0x12153, 0xE0000020]
.reloc C:\WINDOWS\system32\lsass.exe[932] C:\WINDOWS\system32\WS2_32.dll section is executable [0x71A66000, 0x1DC8, 0xE0000040]
.text C:\WINDOWS\system32\svchost.exe[1120] WS2_32.dll!socket 71A54211 9 Bytes [B8, 40, 18, 00, 10, FF, E0, ...] {MOV EAX, 0x10001840; JMP EAX; NOP ; NOP }
.text C:\WINDOWS\system32\svchost.exe[1120] c:\windows\system32\WS2_32.dll section is writeable [0x71A51000, 0x12153, 0xE0000020]
.reloc C:\WINDOWS\system32\svchost.exe[1120] c:\windows\system32\WS2_32.dll section is executable [0x71A66000, 0x1DC8, 0xE0000040]
.text C:\WINDOWS\system32\svchost.exe[1192] WS2_32.dll!socket 71A54211 9 Bytes [B8, 40, 18, 00, 10, FF, E0, ...] {MOV EAX, 0x10001840; JMP EAX; NOP ; NOP }
.text C:\WINDOWS\system32\svchost.exe[1192] WS2_32.dll!connect 71A54A07 8 Bytes [B8, A8, 29, 00, 10, FF, E0, ...] {MOV EAX, 0x100029a8; JMP EAX; NOP }
.text C:\WINDOWS\system32\svchost.exe[1192] c:\windows\system32\WS2_32.dll section is writeable [0x71A51000, 0x12153, 0xE0000020]
.reloc C:\WINDOWS\system32\svchost.exe[1192] c:\windows\system32\WS2_32.dll section is executable [0x71A66000, 0x1DC8, 0xE0000040]
.text C:\WINDOWS\System32\svchost.exe[1248] WS2_32.dll!socket 71A54211 9 Bytes [B8, 40, 18, 00, 10, FF, E0, ...] {MOV EAX, 0x10001840; JMP EAX; NOP ; NOP }
.text C:\WINDOWS\System32\svchost.exe[1248] WS2_32.dll!connect 71A54A07 8 Bytes [B8, A8, 29, 00, 10, FF, E0, ...] {MOV EAX, 0x100029a8; JMP EAX; NOP }
.text C:\WINDOWS\System32\svchost.exe[1248] c:\windows\system32\WS2_32.dll section is writeable [0x71A51000, 0x12153, 0xE0000020]
.reloc C:\WINDOWS\System32\svchost.exe[1248] c:\windows\system32\WS2_32.dll section is executable [0x71A66000, 0x1DC8, 0xE0000040]
.text C:\WINDOWS\System32\svchost.exe[1432] WS2_32.dll!socket 71A54211 9 Bytes [B8, 40, 18, 00, 10, FF, E0, ...] {MOV EAX, 0x10001840; JMP EAX; NOP ; NOP }
.text C:\WINDOWS\System32\svchost.exe[1432] c:\windows\system32\WS2_32.dll section is writeable [0x71A51000, 0x12153, 0xE0000020]
.reloc C:\WINDOWS\System32\svchost.exe[1432] c:\windows\system32\WS2_32.dll section is executable [0x71A66000, 0x1DC8, 0xE0000040]
.text C:\WINDOWS\system32\svchost.exe[1444] WS2_32.dll!socket 71A54211 9 Bytes [B8, 40, 18, 00, 10, FF, E0, ...] {MOV EAX, 0x10001840; JMP EAX; NOP ; NOP }
.text C:\WINDOWS\system32\svchost.exe[1444] WS2_32.dll!connect 71A54A07 8 Bytes [B8, A8, 29, 00, 10, FF, E0, ...] {MOV EAX, 0x100029a8; JMP EAX; NOP }
.text C:\WINDOWS\system32\svchost.exe[1444] c:\windows\system32\WS2_32.dll section is writeable [0x71A51000, 0x12153, 0xE0000020]
.reloc C:\WINDOWS\system32\svchost.exe[1444] c:\windows\system32\WS2_32.dll section is executable [0x71A66000, 0x1DC8, 0xE0000040]
.text C:\WINDOWS\system32\spoolsv.exe[1696] WS2_32.dll!socket 71A54211 9 Bytes [B8, 40, 18, 00, 10, FF, E0, ...] {MOV EAX, 0x10001840; JMP EAX; NOP ; NOP }
.text C:\WINDOWS\system32\spoolsv.exe[1696] WS2_32.dll!connect 71A54A07 8 Bytes [B8, A8, 29, 00, 10, FF, E0, ...] {MOV EAX, 0x100029a8; JMP EAX; NOP }
.text C:\WINDOWS\system32\spoolsv.exe[1696] C:\WINDOWS\system32\WS2_32.dll section is writeable [0x71A51000, 0x12153, 0xE0000020]
.reloc C:\WINDOWS\system32\spoolsv.exe[1696] C:\WINDOWS\system32\WS2_32.dll section is executable [0x71A66000, 0x1DC8, 0xE0000040]
.text C:\WINDOWS\System32\svchost.exe[1768] WS2_32.dll!socket 71A54211 9 Bytes [B8, 40, 18, 00, 10, FF, E0, ...] {MOV EAX, 0x10001840; JMP EAX; NOP ; NOP }
.text C:\WINDOWS\System32\svchost.exe[1768] c:\windows\system32\WS2_32.dll section is writeable [0x71A51000, 0x12153, 0xE0000020]
.reloc C:\WINDOWS\System32\svchost.exe[1768] c:\windows\system32\WS2_32.dll section is executable [0x71A66000, 0x1DC8, 0xE0000040]
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[1776] WS2_32.dll!socket 71A54211 9 Bytes [B8, 40, 18, 00, 10, FF, E0, ...] {MOV EAX, 0x10001840; JMP EAX; NOP ; NOP }
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[1776] C:\WINDOWS\system32\WS2_32.dll section is writeable [0x71A51000, 0x12153, 0xE0000020]
.reloc C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[1776] C:\WINDOWS\system32\WS2_32.dll section is executable [0x71A66000, 0x1DC8, 0xE0000040]
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[1956] WS2_32.dll!socket 71A54211 9 Bytes [B8, 40, 18, 3A, 00, FF, E0, ...] {MOV EAX, 0x3a1840; JMP EAX; NOP ; NOP }
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[1956] C:\WINDOWS\system32\WS2_32.dll section is writeable [0x71A51000, 0x12153, 0xE0000020]
.reloc C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[1956] C:\WINDOWS\system32\WS2_32.dll section is executable [0x71A66000, 0x1DC8, 0xE0000040]
.text C:\Program Files\Ovislink\Common\TurboG-UI.exe[1992] WS2_32.dll!socket 71A54211 9 Bytes [B8, 40, 18, 39, 00, FF, E0, ...] {MOV EAX, 0x391840; JMP EAX; NOP ; NOP }
.text C:\Program Files\Ovislink\Common\TurboG-UI.exe[1992] C:\WINDOWS\system32\WS2_32.dll section is writeable [0x71A51000, 0x12153, 0xE0000020]
.reloc C:\Program Files\Ovislink\Common\TurboG-UI.exe[1992] C:\WINDOWS\system32\WS2_32.dll section is executable [0x71A66000, 0x1DC8, 0xE0000040]
.text C:\WINDOWS\Explorer.EXE[2004] WS2_32.dll!socket 71A54211 9 Bytes [B8, 40, 18, 00, 10, FF, E0, ...] {MOV EAX, 0x10001840; JMP EAX; NOP ; NOP }
.text C:\WINDOWS\Explorer.EXE[2004] C:\WINDOWS\system32\WS2_32.dll section is writeable [0x71A51000, 0x12153, 0xE0000020]
.reloc C:\WINDOWS\Explorer.EXE[2004] C:\WINDOWS\system32\WS2_32.dll section is executable [0x71A66000, 0x1DC8, 0xE0000040]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2504] WS2_32.dll!socket 71A54211 9 Bytes [B8, 40, 18, 00, 10, FF, E0, ...] {MOV EAX, 0x10001840; JMP EAX; NOP ; NOP }
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2504] C:\WINDOWS\system32\WS2_32.dll section is writeable [0x71A51000, 0x12153, 0xE0000020]
.reloc C:\WINDOWS\system32\wbem\wmiprvse.exe[2504] C:\WINDOWS\system32\WS2_32.dll section is executable [0x71A66000, 0x1DC8, 0xE0000040]
.text C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe[2808] WS2_32.dll!socket 71A54211 9 Bytes [B8, 40, 18, 00, 10, FF, E0, ...] {MOV EAX, 0x10001840; JMP EAX; NOP ; NOP }
.text C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe[2808] C:\WINDOWS\system32\WS2_32.dll section is writeable [0x71A51000, 0x12153, 0xE0000020]
.reloc C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe[2808] C:\WINDOWS\system32\WS2_32.dll section is executable [0x71A66000, 0x1DC8, 0xE0000040]
.text C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2932] WS2_32.dll!socket 71A54211 9 Bytes [B8, 40, 18, 39, 00, FF, E0, ...] {MOV EAX, 0x391840; JMP EAX; NOP ; NOP }
.text C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2932] C:\WINDOWS\system32\WS2_32.dll section is writeable [0x71A51000, 0x12153, 0xE0000020]
.reloc C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2932] C:\WINDOWS\system32\WS2_32.dll section is executable [0x71A66000, 0x1DC8, 0xE0000040]
.text C:\WINDOWS\System32\alg.exe[2972] WS2_32.dll!socket 71A54211 9 Bytes [B8, 40, 18, 00, 10, FF, E0, ...] {MOV EAX, 0x10001840; JMP EAX; NOP ; NOP }
.text C:\WINDOWS\System32\alg.exe[2972] C:\WINDOWS\System32\WS2_32.dll section is writeable [0x71A51000, 0x12153, 0xE0000020]
.reloc C:\WINDOWS\System32\alg.exe[2972] C:\WINDOWS\System32\WS2_32.dll section is executable [0x71A66000, 0x1DC8, 0xE0000040]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3964] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[3964] WS2_32.dll!socket 71A54211 9 Bytes [B8, 40, 18, 39, 00, FF, E0, ...] {MOV EAX, 0x391840; JMP EAX; NOP ; NOP }
.text C:\Program Files\Mozilla Firefox\firefox.exe[3964] WS2_32.dll!connect 71A54A07 8 Bytes [B8, A8, 29, 39, 00, FF, E0, ...] {MOV EAX, 0x3929a8; JMP EAX; NOP }
.text C:\Program Files\Mozilla Firefox\firefox.exe[3964] C:\WINDOWS\system32\WS2_32.dll section is writeable [0x71A51000, 0x12153, 0xE0000020]
.reloc C:\Program Files\Mozilla Firefox\firefox.exe[3964] C:\WINDOWS\system32\WS2_32.dll section is executable [0x71A66000, 0x1DC8, 0xE0000040]
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x42 0x77 0xCF 0xB3 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x5D 0x1E 0xCA 0xBC ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xDD 0xBB 0x53 0xDF ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x5A 0xBB 0x3E 0x96 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x42 0x77 0xCF 0xB3 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x5D 0x1E 0xCA 0xBC ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xDD 0xBB 0x53 0xDF ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x5A 0xBB 0x3E 0x96 ...
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000
---- EOF - GMER 1.0.15 ----
OTL
- Kod: Zaznacz wszystko
OTL.Txt - http://www.wklej.org/id/376740/
- Kod: Zaznacz wszystko
Extras.Txt - http://www.wklej.org/id/376742/
DDS
- Kod: Zaznacz wszystko
DDS.txt - http://www.wklej.org/id/376745/
- Kod: Zaznacz wszystko
Attach.txt - http://www.wklej.org/id/376746/
Hijackthis
- Kod: Zaznacz wszystko
http://www.wklej.org/id/376750/
Z góry ślicznie dziękuję jakby ktoś zechciał mi pomóc
