Od kilku dni komputer zaczął mi wolniej chodzić
W menedżerze zadań ani procek ani pamięć nie przekraczają 50 % wykorzystania.
Miałem Kasperskiego ale po przenosinach na Windows 10 akurat licencja straciła ważność. Wyczytałem, że antywirek Windowsa jest dobry więc niczego już nie odnawiałem.
Logi w załącznikach
Dzięki za pomoc.
gmer nie chciał się dodać
- Kod: Zaznacz wszystko
GMER 2.2.19882 - http://www.gmer.net
Rootkit scan 2016-04-29 10:41:44
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 Crucial_CT120M500SSD1 rev.MU05 111,79GB
Running: 03wb7r58.exe; Driver: C:\Users\Bartek\AppData\Local\Temp\pwddqpog.sys
---- User code sections - GMER 2.2 ----
.text C:\Program Files\Microsoft Office 15\Root\Office15\WINWORD.EXE[9100] C:\Program Files\Microsoft Office 15\Root\Office15\WINWORD.EXE!wdGetApplicationObject + 18 00000000010f1950 2 bytes [0F, 01]
.text C:\Program Files\Microsoft Office 15\Root\Office15\WINWORD.EXE[9100] C:\Program Files\Microsoft Office 15\Root\Office15\WINWORD.EXE!wdGetApplicationObject + 202 00000000010f1a08 2 bytes [0F, 01]
.text C:\Program Files\Microsoft Office 15\Root\Office15\WINWORD.EXE[9100] C:\Program Files\Microsoft Office 15\Root\Office15\WINWORD.EXE!wdGetApplicationObject + 920 00000000010f1cd6 2 bytes [0F, 01]
---- Threads - GMER 2.2 ----
Thread C:\WINDOWS\system32\csrss.exe [13048:12312] fffff96130024060
Thread C:\WINDOWS\system32\csrss.exe [13048:19424] fffff96130024060
Thread C:\WINDOWS\Explorer.EXE [9568:19096] 00007ffab5530250
Thread C:\WINDOWS\Explorer.EXE [9568:5588] 00007ffaadfe0250
Thread C:\WINDOWS\Explorer.EXE [9568:12316] 00007ffaa6270250
Thread C:\WINDOWS\Explorer.EXE [9568:11096] 00007ffabbc10250
Thread C:\WINDOWS\Explorer.EXE [9568:19092] 00007ffabbc10250
Thread C:\WINDOWS\Explorer.EXE [9568:11092] 00007ffabbc10250
Thread C:\WINDOWS\Explorer.EXE [9568:8680] 00007ffabbc10250
Thread C:\WINDOWS\Explorer.EXE [9568:16800] 00007ffabbc10250
Thread C:\WINDOWS\Explorer.EXE [9568:10940] 00007ffabbc60250
---- Processes - GMER 2.2 ----
Library C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\mso.dll (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\WINWORD.EXE [9100] 000000000f520000
Library C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\MSPTLS.DLL (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\WINWORD.EXE [9100] 0000000061930000
Library C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\riched20.dll (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\WINWORD.EXE [9100] 00000000617a0000
Library C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\MSOIDCLIL.DLL (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\WINWORD.EXE [9100] 00000000611d0000
Library C:\Program Files (x86)\Common Files\Microsoft Shared\PROOF\MSLID.DLL (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\WINWORD.EXE [9100] 00000000514c0000
Library C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\mso.dll (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE [3712] 000000000f520000
Library C:\Program Files (x86)\Common Files\Microsoft Shared\Office15\riched20.dll (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE [3712] 00000000617a0000
Library C:\Program Files (x86)\Common Files\Microsoft Shared\VBA\VBA7.1\VBE7.DLL (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE [3712] 0000000051200000
Library C:\Program Files (x86)\Common Files\Microsoft Shared\VBA\VBA7.1\VBEUI.DLL (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE [3712] 0000000050fd0000
Library C:\Program Files (x86)\Common Files\Microsoft Shared\VBA\VBA7.1\1033\VBE7INTL.DLL (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE [3712] 000000000f160000
Library C:\Windows\SYSTEM32\FM20.DLL (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE [3712] 0000000050e90000
Library C:\Program Files (x86)\Common Files\Microsoft Shared\VBA\VBA7.1\VBEUIRES.DLL (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE [3712] 0000000009340000
Library C:\Program Files (x86)\Common Files\Microsoft Shared\VBA\VBA7.1\1033\VBEUIINTL.DLL (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE [3712] 0000000009870000
Library C:\Windows\SYSTEM32\fm20ENU.DLL (*** suspicious ***) @ C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE [3712] 0000000009bf0000
---- Registry - GMER 2.2 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\kernel\RNG@RNGAuxiliarySeed -1893497531
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001b1000131c
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001b1000131c@2073ab47e253 0x2F 0x82 0xF9 0xB7 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0000
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0000@BackupContext 0x02 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0000@COD Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0000@DeviceSelectiveSuspended 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0000@Scans Before Out of Range 8
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0000@SCO Max Channels 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0000@Store Link Key COD Masks 0x00 0x00 0x1F 0x43 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0000@SymbolicLinkName \??\USB#VID_0A12&PID_0001#6&2c24ce2e&0&2#{0850302a-b344-4fda-9be9-90576b8d46f0}
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0000@SymbolicName \??\USB#VID_0A12&PID_0001#6&2c24ce2e&0&2#{a5dcbf10-6530-11d2-901f-00c04fb951ed}
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0001
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0001@BackupContext 0x02 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0001@COD Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0001@Scans Before Out of Range 8
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0001@SCO Max Channels 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0001@Store Link Key COD Masks 0x00 0x00 0x1F 0x43 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0001@SymbolicLinkName \??\USB#VID_0A12&PID_0001#6&2c24ce2e&0&3#{0850302a-b344-4fda-9be9-90576b8d46f0}
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0001@SymbolicName \??\USB#VID_0A12&PID_0001#6&2c24ce2e&0&3#{a5dcbf10-6530-11d2-901f-00c04fb951ed}
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0004
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0004@BackupContext 0x02 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0004@COD Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0004@DeviceRemoteWakeSupported 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0004@DeviceSelectiveSuspended 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0004@RemoteWakeEnabled 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0004@Scans Before Out of Range 8
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0004@SCO Max Channels 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0004@Store Link Key COD Masks 0x00 0x00 0x1F 0x43 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0004@SymbolicLinkName \??\USB#VID_0A12&PID_0001#6&2c24ce2e&0&1#{0850302a-b344-4fda-9be9-90576b8d46f0}
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Upgrade\LocalRadioSettings\0004@SymbolicName \??\USB#VID_0A12&PID_0001#6&2c24ce2e&0&1#{a5dcbf10-6530-11d2-901f-00c04fb951ed}
Reg HKLM\SYSTEM\CurrentControlSet\Services\iphlpsvc\Teredo\PreviousState\00-12-2a-bb-46-e1@AddressCreationTimestamp 0x53 0x89 0x33 0x0D ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\iphlpsvc\Teredo\PreviousState\00-12-2a-bb-46-e1@ClientLocalPort 61261
Reg HKLM\SYSTEM\CurrentControlSet\Services\iphlpsvc\Teredo\PreviousState\00-12-2a-bb-46-e1@UPnPExternalPort 61261
Reg HKLM\SYSTEM\CurrentControlSet\Services\iphlpsvc\Teredo\PreviousState\00-12-2a-bb-46-e1@TeredoAddress 2001:0:5ef5:79fb:388f:10b2:b201:b53e
Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch2@Epoch 681
Reg HKLM\SYSTEM\CurrentControlSet\Services\W32Time\SecureTimeLimits@SecureTimeEstimated 0x8B 0xB4 0x13 0x21 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\W32Time\SecureTimeLimits@SecureTimeHigh 0x8B 0x1C 0xD8 0x82 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\W32Time\SecureTimeLimits@SecureTimeLow 0x8B 0x4C 0x4F 0xBF ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\W32Time\SecureTimeLimits@SecureTimeTickCount 0x03 0x06 0x13 0x0D ...
---- Files - GMER 2.2 ----
File C:\Users\Bartek\AppData\Roaming\HoldemManager\Database\HoldemManager2\Players\2\Vitaly66606 0 bytes
File C:\Users\Bartek\AppData\Roaming\HoldemManager\Database\HoldemManager2\Players\2\Vitaly66606\20160429 1123 bytes
File C:\Users\Bartek\AppData\Roaming\HoldemManager\Database\HoldemManager2\Players\2\NoRiverRager 0 bytes
File C:\Users\Bartek\AppData\Roaming\HoldemManager\Database\HoldemManager2\Players\2\NoRiverRager\20160429 1077 bytes
File C:\Users\Bartek\AppData\Roaming\HoldemManager\Database\HoldemManager2\Players\2\walhal 62 0 bytes
File C:\Users\Bartek\AppData\Roaming\HoldemManager\Database\HoldemManager2\Players\2\walhal 62\20160429 2715 bytes
---- EOF - GMER 2.2 ----