Nie otwierają się programy


(Mir Jab) #1

mój problem z komputerem polega na tym, że nie chcą się uruchamiać programy np. CorelDraw, FotoOffice i inne. Jeżeli w Gmer-ze przywrócę SSDT wszystko jest OK. Nie potrafię na podstawie logów znaleźć przyczyny, czy moglibyście spojrzeć na nie i mi pomóc!

GMER 1.0.12.12027 - http://www.gmer.net 

Rootkit scan 2007-02-21 15:49:09 

Windows 5.0.2195 Service Pack 4 



---- System - GMER 1.0.12 ---- 


SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwClose 

SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwCreateDirectoryObject 

SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwCreateFile 

SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwCreateProcess 

SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwCreateSection 

SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwOpenFile 

SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwSetInformationFile 

SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwWriteFile 


---- EOF - GMER 1.0.12 ---- 



Logfile of HijackThis v1.99.1 

Scan saved at 15:52:10, on 2007-02-21 

Platform: Windows 2000 SP4 (WinNT 5.00.2195) 

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) 


Running processes: 

C:\WINNT\System32\smss.exe 

C:\WINNT\system32\winlogon.exe 

C:\WINNT\system32\services.exe 

C:\WINNT\system32\lsass.exe 

C:\WINNT\system32\svchost.exe 

C:\WINNT\system32\spoolsv.exe 

C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe 

C:\Program Files\Alwil Software\Avast4\ashServ.exe 

C:\WINNT\System32\svchost.exe 

C:\WINNT\system32\regsvc.exe 

C:\WINNT\system32\MSTask.exe 

C:\WINNT\System32\WBEM\WinMgmt.exe 

C:\WINNT\system32\svchost.exe 

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe 

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe 

C:\WINNT\Explorer.EXE 

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe 

C:\WINNT\gmer.exe 

C:\Program Files\Internet Explorer\IEXPLORE.EXE 

C:\Program Files\Corel\Graphics9\Programs\coreldrw.exe 

C:\Program Files\G DATA Software\FotoOffice 2007 HOME\FotoOffice.exe 

C:\Documents and Settings\Mirosław Jabłoński\Moje dokumenty\Download\hijackthis\hijackthis.com 


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lodz.naszemiasto.pl/ 

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza 

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll 

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx 

O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - C:\PROGRA~1\DAP\DAPIEBar.dll 

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe 

O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon 

O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm 

O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm 

O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm 

O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll 

O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.pl/resources/virusscanner/kavwebscan_unicode.cab 

O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab 

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1151312695609 

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab 

O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - http://www.mks.com.pl/skaner/SkanerOnline.cab 

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1160564628218 

O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://217.113.236.251/activex/AxisCamControl.cab 

O16 - DPF: {E36C5562-C4E0-4220-BCB2-1C671E3A5916} - http://www.seagate.com/support/disc/asp/tools/en/bin/npseatools.cab 

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe 

O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe 

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) 

O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) 

O23 - Service: Usługa administracyjna Menedżera dysków logicznych (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe 

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe 


"Silent Runners.vbs", revision R50, http://www.silentrunners.org/ 

Operating System: Windows 2000 

Output limited to non-default values, except where indicated by "{++}" 



Startup items buried in registry: 

--------------------------------- 


HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++} 

"avast!" = "C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [null data] 

"Synchronization Manager" = "mobsync.exe /logon" [MS] 


HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ 

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided) 

  -> {HKLM...CLSID} = "AcroIEHlprObj Class" 

                   \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"] 


HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ 

"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania" 

  -> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania" 

                   \InProcServer32\(Default) = "deskpan.dll" [file not found] 

"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu" 

  -> {HKLM...CLSID} = "HyperTerminal Icon Ext" 

                   \InProcServer32\(Default) = "C:\WINNT\System32\hticons.dll" ["Hilgraeve, Inc."] 

"{A7B1D2E1-5E71-4975-B8D9-FC4A1FB6B0A6}" = "Matrox PowerDesk Page" 

  -> {HKLM...CLSID} = "Matrox PowerDesk Page" 

                   \InProcServer32\(Default) = "C:\WINNT\system32\PowerDesk8\Matrox.PowerDesk.PDeskPage.dll" ["Matrox Graphics Inc."] 

"{FEB7DAE0-E111-11D0-BFD7-444553540000}" = "ICEOWS" 

  -> {HKLM...CLSID} = "Folder Iceows" 

                   \InProcServer32\(Default) = "C:\WINNT\system32\ShellExt\IceGUI.dll" ["Raphaël MOUNIER"] 

"{79BC0345-1015-11D2-A299-006008312725}" = "blue.shell" 

  -> {HKLM...CLSID} = "Edition.Project" 

                   \InProcServer32\(Default) = "C:\Program Files\Pinnacle\Edition 5\Program\BlueShellExt.dll" [null data] 

"{F5D92341-0A64-11D0-9956-0000E8096023}" = "CD Copy Shell Extension" 

  -> {HKLM...CLSID} = "CD Copy Shell Extension" 

                   \InProcServer32\(Default) = "C:\WINNT\system32\Shellext\CDWshext.dll" ["Pinnacle Systems, Inc."] 

"{F5D92342-0A64-11D0-9956-0000E8096023}" = "CD Wizard Shell Extension" 

  -> {HKLM...CLSID} = "CD Wizard Shell Extension" 

                   \InProcServer32\(Default) = "C:\WINNT\system32\Shellext\CDWshext.dll" ["Pinnacle Systems, Inc."] 

"{F5D92344-0A64-11D0-9956-0000E8096023}" = "InstantWrite Shellextension" 

  -> {HKLM...CLSID} = "InstantWrite Shellextension" 

                   \InProcServer32\(Default) = "C:\WINNT\system32\ShellExt\iwshex.dll" ["VOB Computersysteme GmbH"] 

"{472083B0-C522-11CF-8763-00608CC02F24}" = "avast" 

  -> {HKLM...CLSID} = "avast" 

                   \InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"] 

"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler" 

  -> {HKLM...CLSID} = "Rozszerzenie ikon plików programu Outlook" 

                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office\OLKFSTUB.DLL" [MS] 


HKLM\Software\Classes\Folder\shellex\ColumnHandlers\ 

{F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info" 

  -> {HKLM...CLSID} = "PDF Shell Extension" 

                   \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."] 


HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ 

avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}" 

  -> {HKLM...CLSID} = "avast" 

                   \InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"] 

DAP_Menu\(Default) = "{BED4C38B-F765-45AC-8C56-613F76BBF43E}" 

  -> {HKLM...CLSID} = "DAPMenuShellExt Class" 

                   \InProcServer32\(Default) = "C:\PROGRA~1\DAP\PRIVAC~1\DAPCTX~1.DLL" ["Speedbit Ltd."] 

ICEOWS\(Default) = "{FEB7DAE0-E111-11D0-BFD7-444553540000}" 

  -> {HKLM...CLSID} = "Folder Iceows" 

                   \InProcServer32\(Default) = "C:\WINNT\system32\ShellExt\IceGUI.dll" ["Raphaël MOUNIER"] 

MkS_Vir\(Default) = "{E64226E0-9DA1-479E-8265-8D65BA327BD4}" 

  -> {HKLM...CLSID} = "MkS_Vir Shell Extension" 

                   \InProcServer32\(Default) = "/u\mksshell.dll" [file not found] 


HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ 

ICEOWS\(Default) = "{FEB7DAE0-E111-11D0-BFD7-444553540000}" 

  -> {HKLM...CLSID} = "Folder Iceows" 

                   \InProcServer32\(Default) = "C:\WINNT\system32\ShellExt\IceGUI.dll" ["Raphaël MOUNIER"] 


HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ 

avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}" 

  -> {HKLM...CLSID} = "avast" 

                   \InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"] 

MkS_Vir\(Default) = "{E64226E0-9DA1-479E-8265-8D65BA327BD4}" 

  -> {HKLM...CLSID} = "MkS_Vir Shell Extension" 

                   \InProcServer32\(Default) = "/u\mksshell.dll" [file not found] 



Group Policies {GPedit.msc branch and setting}: 

----------------------------------------------- 


Note: detected settings may not have any effect. 


HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ 


"CDRAutoRun" = (REG_DWORD) hex:0x00000000 

{unrecognized setting} 


HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\ 


"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001 

{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| 

Shutdown: Allow system to be shut down without having to log on} 



Active Desktop and Wallpaper: 

----------------------------- 


Active Desktop may be disabled at this entry: 

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState 


Active Desktop web content (hidden if disabled): 


HKCU\Software\Microsoft\Internet Explorer\Desktop\Components\0\ 

"FriendlyName" = "Moja bieżąca strona główna" 

"Source" = "About:Home" 

"SubscribedURL" = "About:Home" 



Enabled Scheduled Tasks: 

------------------------ 


"AppleSoftwareUpdate" -> launches: "C:\Program Files\Apple Software Update\SoftwareUpdate.exe -Task" ["Apple Computer, Inc."] 



Winsock2 Service Provider DLLs: 

------------------------------- 


Namespace Service Providers 


HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} 

000000000001\LibraryPath = "%SystemRoot%\System32\rnr20.dll" [MS] 

000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS] 


Transport Service Providers 


HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++} 

0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: 

%SystemRoot%\system32\msafd.dll [MS], 01 - 03, 06 - 15 

%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05 



Toolbars, Explorer Bars, Extensions: 

------------------------------------ 


Toolbars 


HKLM\Software\Microsoft\Internet Explorer\Toolbar\ 

"{62999427-33FC-4BAF-9C9C-BCE6BD127F08}" = "DAP Bar" 

  -> {HKLM...CLSID} = "DAP Bar" 

                   \InProcServer32\(Default) = "C:\PROGRA~1\DAP\DAPIEBar.dll" [empty string] 



Running Services (Display Name, Service Name, Path {Service DLL}): 

------------------------------------------------------------------ 


avast! Antivirus, avast! Antivirus, ""C:\Program Files\Alwil Software\Avast4\ashServ.exe"" [null data] 

avast! iAVS4 Control Service, aswUpdSv, ""C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"" [null data] 

avast! Mail Scanner, avast! Mail Scanner, ""C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service" ["ALWIL Software"] 

avast! Web Scanner, avast! Web Scanner, ""C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service" ["ALWIL Software"] 

System zdarzeń COM+, EventSystem, "C:\WINNT\System32\svchost.exe -k netsvcs" {"C:\WINNT\System32\es.dll" [null data]} 



Print Monitors: 

--------------- 


HKLM\System\CurrentControlSet\Control\Print\Monitors\ 

PDF Port\Driver = "C:\WINNT\system32\pdfports.dll" ["Adobe Systems Inc."] 



---------- 

+ This report excludes default entries except where indicated. 

+ To see *everywhere* the script checks and *everything* it finds, 

  launch it from a command prompt or a shortcut with the -all parameter. 

+ The search for DESKTOP.INI DLL launch points on all local fixed drives 

  took 12 seconds. 

---------- (total run time: 32 seconds)

ponieważ aswMon.SYS to jest: avast! File System Filter Driver for Windows NT/2000 [za] to odinstalowałem avast'a, zapuściłem Gmer'a - wszystko OK, ściągnąłem avast'a zainstalowałem wszystko wróciło do poprzedniego stanu tzn Gmer wskazuje na plik aswMon.sys - programy oczywiście nie otwierają się. Możliwości widzę trzy: 1."Coś" infekuje avasta, albo 2.Ściągam już zainfekowanego Avasta, albo 3.Gmer błędnie informuje, bo to nie jest rootkit (tylko dlaczego nie działają programy?). Stawiam na tą pierwszą możliwość bo w obecnej konfiguracji (programy teraz niedziałające + avast) pracuje od dłuższego czasu i wszystko było OK - tylko co może infekować avasta?

Możecie coś zasugerować, pomóc!

Jeszcze jedną rzecz zrobiłem, ściągnąłem ten plik avasta od kolegi, zapuściłem Gmer'a - wszystko OK, ponowny start systemu i wszystko wraca do początku


(JNJN) #2

Proszę zmienić temat postu na konkretny,opcja zmień i popraw.JNJN


(adam9870) #3

Możesz otworzyć notatnik i wkleić w nim to:

Plik >>> Zapisz jako >>> Zmień rozszerzenie z TXT na Wszystkie pliki >>> Zapisz pod nazwą FIX.REG >>> kliknij dwa razy na utworzony plik FIX.REG i potwierdź dodanie do rejestru >>> restart.

Proponuję przeczyścić rejestr ponieważ masz kilka pustych kluczy. opis.

Tak, w Gmerze są pokazane tylko hooki typu SSDT Avasta. Są one jak najbardziej w porządku ponieważ często programy tego typu tworzą własne hooki. Po kliknięciu opcji Przywróć SSDT w Gmerze po ponownym uruchomieniu systemu hooki powracają, tak powinno być i tak również u Ciebie jest.

Aby wykluczyć obecność rootkita pokaż dwa logi z Gmer'a ale wykonane przy takich ustawieniach:

  1. Zakładka Rootkit >>> zaznaczone wszystko oprócz Pokazuj wszystko >>> kliknij Szukaj >>> czekaj cierpliwie aż skończy >>> Kopiuj >>> wklej do posta

  2. Zakładka Rootkit >>> zaznaczone tylko Usługi i Pokazuj wszystko >>> kliknij Szukaj >>> czekaj cierpliwie aż skończy >>> Kopiuj >>> wklej do posta

Jeśli wszystkie logi nie zmieszczą się bezpośrednio do posta, to umieść je w jakimś serwisie hostingowym jako pliki *.txt, a tu tylko zlinkuj.

http://forum.dobreprogramy.pl/viewtopic.php?t=96929


(Mir Jab) #4
GMER 1.0.12.12027 - http://www.gmer.net

Rootkit scan 2007-02-21 22:52:15

Windows 5.0.2195 Service Pack 4



---- System - GMER 1.0.12 ----


SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwClose

SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwCreateDirectoryObject

SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwCreateFile

SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwCreateProcess

SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwCreateSection

SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwOpenFile

SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwSetInformationFile

SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwWriteFile


---- EOF - GMER 1.0.12 ----

GMER 1.0.12.12027 - http://www.gmer.net

Rootkit scan 2007-02-21 22:54:03

Windows 5.0.2195 Service Pack 4



---- Services - GMER 1.0.12 ----


Service .NET CLR Data

Service .NET CLR Networking

Service .NET Data Provider for Oracle

Service .NET Data Provider for SqlServer

Service .NETFramework

Service system32\drivers\02620.SYS [BOOT] 02620

Service C:\WINNT\system32\drivers\38922.SYS [AUTO] 38922

Service C:\Documents and Settings\Mirosław Jabłoński\Ustawienia lokalne\Temp\718A.sys [MANUAL] 718A

Service C:\Documents and Settings\Mirosław Jabłoński\Ustawienia lokalne\Temp\9322.sys [MANUAL] 9322

Service [SYSTEM] Aavmker4

Service [DISABLED] Abiosdsk

Service [DISABLED] abp480n5

Service C:\WINNT\System32\DRIVERS\ACPI.sys [BOOT] ACPI

Service [DISABLED] ACPIEC

Service [DISABLED] adpu160m

Service C:\Documents and Settings\Mirosław Jabłoński\Ustawienia lokalne\Temp\af37.sys [MANUAL] af37

Service C:\WINNT\System32\drivers\afd.sys [AUTO] AFD

Service [DISABLED] Aha154x

Service [DISABLED] aic116x

Service [DISABLED] aic78u2

Service [DISABLED] aic78xx

Service C:\WINNT\System32\services.exe [MANUAL] Alerter

Service [DISABLED] ami0nt

Service C:\WINNT\system32\DRIVERS\Amps2prt.sys [MANUAL] Amps2prt

Service [DISABLED] amsint

Service C:\WINNT\system32\services.exe [MANUAL] AppMgmt

Service [AUTO] Asapi

Service C:\WINNT\System32\Drivers\ASAPIW2K.sys [MANUAL] ASAPIW2k

Service [DISABLED] asc

Service [DISABLED] asc3350p

Service [DISABLED] asc3550

Service ASP.NET

Service ASP.NET_1.1.4322

Service ASP.NET_2.0.50727

Service C:\WINNT\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [MANUAL] aspnet_state

Service [AUTO] aswMon

Service [MANUAL] aswRdr

Service [SYSTEM] aswTdi

Service C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [AUTO] aswUpdSv

Service C:\WINNT\System32\DRIVERS\asyncmac.sys [MANUAL] AsyncMac

Service C:\WINNT\System32\DRIVERS\atapi.sys [BOOT] atapi

Service [DISABLED] Atdisk

Service C:\WINNT\System32\DRIVERS\atmarpc.sys [MANUAL] Atmarpc

Service C:\WINNT\System32\ATMsrvc.exe [DISABLED] ATMsrvc

Service C:\WINNT\System32\DRIVERS\audstub.sys [MANUAL] audstub

Service C:\Program Files\Alwil Software\Avast4\ashServ.exe [AUTO] avast! Antivirus

Service C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [MANUAL] avast! Mail Scanner

Service C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [MANUAL] avast! Web Scanner

Service C:\WINNT\system32\drivers\b7721.SYS [SYSTEM] b7721

Service [SYSTEM] Beep

Service C:\WINNT\System32\svchost.exe [MANUAL] BITS

Service C:\WINNT\System32\services.exe [AUTO] Browser

Service [DISABLED] BusLogic

Service C:\WINNT\system32\DRIVERS\CCDECODE.sys [MANUAL] CCDECODE

Service [DISABLED] cd20xrnt

Service [SYSTEM] Cdaudio

Service [DISABLED] Cdfs

Service C:\WINNT\System32\Drivers\Cdrdrv.sys [MANUAL] cdrdrv

Service C:\WINNT\System32\DRIVERS\cdrom.sys [SYSTEM] Cdrom

Service [SYSTEM] Changer

Service C:\WINNT\System32\cisvc.exe [MANUAL] cisvc

Service C:\WINNT\system32\clipsrv.exe [MANUAL] ClipSrv

Service C:\WINNT\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [MANUAL] clr_optimization_v2.0.50727_32

Service ContentFilter

Service ContentIndex

Service C:\WINNT\system32\Drivers\CO_Mon.sys [MANUAL] CO_Mon

Service [DISABLED] Cpqarray

Service [DISABLED] cpqarry2

Service [DISABLED] cpqfcalm

Service [DISABLED] cpqfws2e

Service [DISABLED] dac960nt

Service [DISABLED] deckzpsx

Service C:\WINNT\System32\services.exe [AUTO] Dhcp

Service C:\WINNT\System32\DRIVERS\disk.sys [BOOT] Disk

Service [BOOT] Diskperf

Service C:\WINNT\System32\dmadmin.exe [MANUAL] dmadmin

Service C:\WINNT\System32\drivers\dmboot.sys [DISABLED] dmboot

Service C:\WINNT\System32\drivers\dmio.sys [BOOT] dmio

Service C:\WINNT\System32\drivers\dmload.sys [BOOT] dmload

Service C:\WINNT\System32\services.exe [AUTO] dmserver

Service C:\WINNT\system32\drivers\DMusic.sys [MANUAL] DMusic

Service C:\WINNT\System32\services.exe [AUTO] Dnscache

Service C:\WINNT\system32\DRIVERS\e1e5032.sys [MANUAL] e1express

Service [DISABLED] EFS

Service C:\WINNT\system32\services.exe [AUTO] Eventlog

Service C:\WINNT\System32\svchost.exe [MANUAL] EventSystem

Service [DISABLED] Fastfat

Service C:\WINNT\system32\faxsvc.exe [MANUAL] Fax

Service [DISABLED] Fd16_700

Service C:\WINNT\System32\DRIVERS\fdc.sys [MANUAL] Fdc

Service [AUTO] Fips

Service [DISABLED] fireport

Service [DISABLED] flashpnt

Service C:\WINNT\System32\DRIVERS\flpydisk.sys [MANUAL] Flpydisk

Service C:\WINNT\system32\drivers\fltmgr.sys [BOOT] FltMgr

Service [SYSTEM] Fs_Rec

Service C:\WINNT\System32\DRIVERS\ftdisk.sys [BOOT] Ftdisk

Service C:\WINNT\System32\DRIVERS\gmer.sys [MANUAL] gmer

Service C:\WINNT\System32\DRIVERS\msgpc.sys [MANUAL] Gpc

Service C:\WINNT\system32\DRIVERS\HDAudBus.sys [MANUAL] HDAudBus

Service C:\WINNT\System32\Drivers\Hlp.Sys [SYSTEM] hlp

Service C:\WINNT\System32\DRIVERS\i8042prt.sys [SYSTEM] i8042prt

Service IAS

Service C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [MANUAL] IDriverT

Service inetaccs

Service [DISABLED] ini910u

Service Inport

Service C:\WINNT\system32\drivers\RtkHDAud.sys [MANUAL] IntcAzAudAddService

Service [DISABLED] IntelIde

Service C:\WINNT\System32\DRIVERS\ipfltdrv.sys [MANUAL] IpFilterDriver

Service C:\WINNT\System32\DRIVERS\ipinip.sys [MANUAL] IpInIp

Service C:\WINNT\System32\DRIVERS\ipnat.sys [MANUAL] IpNat

Service C:\WINNT\System32\DRIVERS\ipsec.sys [MANUAL] IPSEC

Service [DISABLED] ipsraidn

Service C:\WINNT\System32\DRIVERS\irenum.sys [MANUAL] IRENUM

Service ISAPISearch

Service C:\WINNT\System32\DRIVERS\isapnp.sys [BOOT] isapnp

Service C:\WINNT\System32\DRIVERS\iteatapi.sys [BOOT] iteatapi

Service C:\WINNT\System32\DRIVERS\kbdclass.sys [SYSTEM] Kbdclass

Service C:\WINNT\system32\drivers\kmixer.sys [MANUAL] kmixer

Service [BOOT] KSecDD

Service C:\WINNT\System32\services.exe [AUTO] lanmanserver

Service C:\WINNT\System32\services.exe [AUTO] lanmanworkstation

Service [SYSTEM] lbrtfdc

Service C:\WINNT\System32\services.exe [AUTO] LmHosts

Service [DISABLED] lp6nds35

Service C:\WINNT\system32\2D.tmp [MANUAL] MEMSWEEP2

Service C:\WINNT\System32\services.exe [AUTO] Messenger

Service [SYSTEM] mnmdd

Service C:\WINNT\System32\mnmsrvc.exe [MANUAL] mnmsrvc

Service [MANUAL] Modem

Service C:\WINNT\System32\DRIVERS\mouclass.sys [SYSTEM] Mouclass

Service [BOOT] MountMgr

Service C:\WINNT\system32\DRIVERS\MPE.sys [MANUAL] MPE

Service [DISABLED] mraid35x

Service C:\WINNT\System32\DRIVERS\mrxsmb.sys [SYSTEM] MRxSmb

Service C:\WINNT\System32\msdtc.exe [MANUAL] MSDTC

Service C:\WINNT\System32\DRIVERS\msdv.sys [MANUAL] MSDV

Service [SYSTEM] Msfs

Service C:\WINNT\system32\msiexec.exe [MANUAL] MSIServer

Service C:\WINNT\system32\drivers\MSKSSRV.sys [MANUAL] MSKSSRV

Service C:\WINNT\system32\drivers\MSPCLOCK.sys [MANUAL] MSPCLOCK

Service C:\WINNT\system32\drivers\MSPQM.sys [MANUAL] MSPQM

Service C:\WINNT\system32\drivers\MSTEE.sys [MANUAL] MSTEE

Service C:\WINNT\system32\DRIVERS\mtdv2ku2.sys [MANUAL] MTDVC2

Service C:\WINNT\system32\DRIVERS\mtdv2ks2.sys [MANUAL] MTDVC2_ENUM

Service C:\WINNT\System32\DRIVERS\ASACPI.sys [MANUAL] MTsensor

Service C:\WINNT\system32\DRIVERS\MTXPARHM.sys [MANUAL] MTXPARH

Service [BOOT] Mup

Service C:\WINNT\system32\DRIVERS\NABTSFEC.sys [MANUAL] NABTSFEC

Service [DISABLED] Ncrc710

Service [BOOT] NDIS

Service C:\WINNT\system32\DRIVERS\NdisIP.sys [MANUAL] NdisIP

Service C:\WINNT\System32\DRIVERS\ndistapi.sys [MANUAL] NdisTapi

Service C:\WINNT\System32\DRIVERS\ndisuio.sys [MANUAL] Ndisuio

Service C:\WINNT\System32\DRIVERS\ndiswan.sys [MANUAL] NdisWan

Service [MANUAL] NDProxy

Service C:\WINNT\System32\DRIVERS\netbios.sys [SYSTEM] NetBIOS

Service C:\WINNT\System32\DRIVERS\netbt.sys [SYSTEM] NetBT

Service C:\WINNT\system32\netdde.exe [MANUAL] NetDDE

Service C:\WINNT\system32\netdde.exe [MANUAL] NetDDEdsdm

Service C:\WINNT\system32\drivers\netdtect.sys [MANUAL] NetDetect

Service C:\WINNT\System32\lsass.exe [MANUAL] Netlogon

Service C:\WINNT\System32\svchost.exe [MANUAL] Netman

Service nm

Service [SYSTEM] Npfs

Service [DISABLED] Ntfs

Service C:\WINNT\System32\lsass.exe [MANUAL] NtLmSsp

Service C:\WINNT\System32\svchost.exe [AUTO] NtmsSvc

Service [SYSTEM] Null

Service C:\WINNT\System32\DRIVERS\nwlnkflt.sys [MANUAL] NwlnkFlt

Service C:\WINNT\System32\DRIVERS\nwlnkfwd.sys [MANUAL] NwlnkFwd

Service C:\WINNT\System32\DRIVERS\ohci1394.sys [BOOT] ohci1394

Service C:\WINNT\system32\drivers\oreans32.sys [SYSTEM] oreans32

Service C:\WINNT\System32\DRIVERS\parallel.sys [MANUAL] Parallel

Service C:\WINNT\System32\DRIVERS\parport.sys [SYSTEM] Parport

Service [BOOT] PartMgr

Service [AUTO] ParVdm

Service C:\WINNT\System32\DRIVERS\pci.sys [BOOT] PCI

Service [SYSTEM] PCIDump

Service C:\WINNT\System32\DRIVERS\pciide.sys [BOOT] PCIIde

Service [AUTO] PCLEPCI

Service [DISABLED] Pcmcia

Service PerfDisk

Service PerfNet

Service PerfOS

Service PerfProc

Service C:\WINNT\system32\drivers\pfc.sys [MANUAL] pfc

Service C:\WINNT\system32\services.exe [AUTO] PlugPlay

Service C:\WINNT\System32\lsass.exe [AUTO] PolicyAgent

Service C:\WINNT\System32\DRIVERS\raspptp.sys [MANUAL] PptpMiniport

Service C:\WINNT\system32\services.exe [AUTO] ProtectedStorage

Service C:\WINNT\System32\DRIVERS\ptilink.sys [MANUAL] Ptilink

Service C:\WINNT\System32\Drivers\PxHelp20.sys [BOOT] PxHelp20

Service [DISABLED] ql1080

Service [DISABLED] Ql10wnt

Service [DISABLED] ql1240

Service [DISABLED] ql2100

Service C:\WINNT\System32\DRIVERS\rasacd.sys [SYSTEM] RasAcd

Service C:\WINNT\System32\svchost.exe [MANUAL] RasAuto

Service C:\WINNT\System32\DRIVERS\rasl2tp.sys [MANUAL] Rasl2tp

Service C:\WINNT\System32\svchost.exe [MANUAL] RasMan

Service C:\WINNT\System32\DRIVERS\raspti.sys [MANUAL] Raspti

Service C:\WINNT\system32\drivers\RCA.sys [MANUAL] RCA

Service C:\WINNT\System32\DRIVERS\rdbss.sys [SYSTEM] Rdbss

Service C:\WINNT\System32\DRIVERS\redbook.sys [SYSTEM] redbook

Service C:\WINNT\System32\svchost.exe [DISABLED] RemoteAccess

Service C:\WINNT\system32\regsvc.exe [AUTO] RemoteRegistry

Service C:\WINNT\System32\locator.exe [MANUAL] RpcLocator

Service C:\WINNT\system32\svchost.exe [AUTO] RpcSs

Service C:\WINNT\System32\rsvp.exe [MANUAL] RSVP

Service C:\WINNT\system32\lsass.exe [AUTO] SamSs

Service C:\WINNT\System32\SCardSvr.exe [MANUAL] SCardDrv

Service C:\WINNT\System32\SCardSvr.exe [MANUAL] SCardSvr

Service C:\WINNT\system32\MSTask.exe [AUTO] Schedule

Service [AUTO] SchedulingAgent

Service C:\WINNT\system32\services.exe [AUTO] seclogon

Service C:\WINNT\system32\svchost.exe [AUTO] SENS

Service C:\WINNT\System32\DRIVERS\serenum.sys [MANUAL] serenum

Service C:\WINNT\System32\DRIVERS\serial.sys [SYSTEM] Serial

Service C:\WINNT\System32\drivers\SFC4.sys [MANUAL] SFC4

Service [SYSTEM] Sfloppy

Service [SYSTEM] sglfb

Service C:\WINNT\System32\svchost.exe [MANUAL] SharedAccess

Service C:\WINNT\System32\DRIVERS\SI3132.sys [BOOT] SI3132

Service [DISABLED] Simbad

Service C:\WINNT\system32\DRIVERS\SLIP.sys [MANUAL] SLIP

Service [DISABLED] Sparrow

Service C:\WINNT\system32\spoolsv.exe [AUTO] Spooler

Service C:\WINNT\System32\DRIVERS\srv.sys [MANUAL] Srv

Service C:\WINNT\system32\drivers\SSHDRV5C.sys [SYSTEM] SSHDRV5C

Service C:\WINNT\system32\drivers\SSHDRV76.sys [SYSTEM] SSHDRV76

Service StarOpen

Service C:\WINNT\system32\DRIVERS\StreamIP.sys [MANUAL] streamip

Service C:\WINNT\System32\DRIVERS\swenum.sys [MANUAL] swenum

Service C:\WINNT\system32\drivers\swmidi.sys [MANUAL] swmidi

Service [DISABLED] symc810

Service [DISABLED] symc8xx

Service [DISABLED] sym_hi

Service C:\WINNT\system32\drivers\sysaudio.sys [MANUAL] sysaudio

Service C:\WINNT\system32\smlogsvc.exe [MANUAL] SysmonLog

Service C:\WINNT\System32\svchost.exe [MANUAL] TapiSrv

Service C:\WINNT\System32\DRIVERS\tcpip.sys [SYSTEM] Tcpip

Service [SYSTEM] tga

Service C:\WINNT\system32\tlntsvr.exe [MANUAL] TlntSvr

Service C:\WINNT\system32\services.exe [AUTO] TrkWks

Service [DISABLED] Udfs

Service C:\WINNT\System32\DRIVERS\uhcd.sys [MANUAL] uhcd

Service [DISABLED] ultra66

Service C:\WINNT\System32\DRIVERS\update.sys [MANUAL] Update

Service C:\WINNT\System32\ups.exe [MANUAL] UPS

Service C:\WINNT\System32\DRIVERS\usbehci.sys [MANUAL] usbehci

Service C:\WINNT\System32\DRIVERS\usbhub.sys [MANUAL] usbhub

Service C:\WINNT\System32\DRIVERS\usbhub20.sys [MANUAL] usbhub20

Service C:\WINNT\System32\DRIVERS\USBSTOR.SYS [MANUAL] USBSTOR

Service C:\WINNT\System32\UtilMan.exe [MANUAL] UtilMan

Service C:\WINNT\System32\drivers\vga.sys [SYSTEM] VgaSave

Service vobcom

Service [SYSTEM] vobfat

Service C:\WINNT\system32\DRIVERS\vobid.sys [BOOT] VOBID

Service [SYSTEM] vobiw

Service VxD

Service C:\WINNT\System32\services.exe [MANUAL] W32Time

Service W3SVC

Service C:\WINNT\System32\DRIVERS\wanarp.sys [MANUAL] Wanarp

Service C:\WINNT\system32\drivers\wdmaud.sys [MANUAL] wdmaud

Service C:\WINNT\System32\WBEM\WinMgmt.exe [AUTO] WinMgmt

Service [MANUAL] Winsock

Service WinSock2

Service WinTrust

Service C:\WINNT\System32\svchost.exe [MANUAL] WmdmPmSN

Service C:\WINNT\system32\Services.exe [MANUAL] Wmi

Service C:\WINNT\system32\DRIVERS\WSTCODEC.SYS [MANUAL] WSTCODEC

Service C:\WINNT\system32\svchost.exe [AUTO] wuauserv

Service C:\WINNT\System32\svchost.exe [MANUAL] WZCSVC

Service C:\WINNT\System32\DRIVERS\yk50x86.sys [MANUAL] yukonw2k

Service {45FE445C-732E-4994-9E0C-D76B4311EA06}

Service {C6529564-A4B6-4813-9FA9-003FA30E6A25}

Service {DF37D2CC-5537-47DA-970C-2395D0762535}


---- EOF - GMER 1.0.12 ----

(Gutek) #5

Użyj Pocket Killbox. Zaznaczasz opcję Delete on Reboot i w polu Full Path of File to Delete wklejasz ścieżkę

C:\WINDOWS\System32\2D.tmp

i naciskasz X czerwony. Program poprosi o reset kompa ... czyli resetujesz.

Użyj ATF-Cleaner - http://www.atribune.org/ccount/click.php?id=1 ponieważ


(Mir Jab) #6

wpisy zostały usnięte, ale nie wiele to pomogło. Np. Corel nadal przy próbie otwarcia dokumentu dochodzi do 5% ... i kończy komunikatem "Nie można utworzyć nowego dokumentu". Nie wiem co dalej?


(adam9870) #7

Proszę wkleić nowe logi z Gmer'a.


(Mir Jab) #8
GMER 1.0.12.12027 - http://www.gmer.net

Rootkit scan 2007-02-23 18:15:41

Windows 5.0.2195 Service Pack 4



---- System - GMER 1.0.12 ----


SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwClose

SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwCreateDirectoryObject

SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwCreateFile

SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwCreateProcess

SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwCreateSection

SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwOpenFile

SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwSetInformationFile

SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwWriteFile


---- EOF - GMER 1.0.12 ----

GMER 1.0.12.12027 - http://www.gmer.net

Rootkit scan 2007-02-23 18:20:09

Windows 5.0.2195 Service Pack 4



---- Services - GMER 1.0.12 ----


Service .NET CLR Data

Service .NET CLR Networking

Service .NET Data Provider for Oracle

Service .NET Data Provider for SqlServer

Service .NETFramework

Service system32\drivers\02620.SYS [BOOT] 02620

Service C:\WINNT\system32\drivers\38922.SYS [AUTO] 38922

Service [SYSTEM] Aavmker4

Service [DISABLED] Abiosdsk

Service [DISABLED] abp480n5

Service C:\WINNT\System32\DRIVERS\ACPI.sys [BOOT] ACPI

Service [DISABLED] ACPIEC

Service [DISABLED] adpu160m

Service C:\DOCUME~1\MIROSA~1\USTAWI~1\Temp\af37.sys [MANUAL] af37

Service C:\WINNT\System32\drivers\afd.sys [AUTO] AFD

Service [DISABLED] Aha154x

Service [DISABLED] aic116x

Service [DISABLED] aic78u2

Service [DISABLED] aic78xx

Service C:\WINNT\System32\services.exe [MANUAL] Alerter

Service [DISABLED] ami0nt

Service C:\WINNT\system32\DRIVERS\Amps2prt.sys [MANUAL] Amps2prt

Service [DISABLED] amsint

Service C:\WINNT\system32\services.exe [MANUAL] AppMgmt

Service [AUTO] Asapi

Service C:\WINNT\System32\Drivers\ASAPIW2K.sys [MANUAL] ASAPIW2k

Service [DISABLED] asc

Service [DISABLED] asc3350p

Service [DISABLED] asc3550

Service ASP.NET

Service ASP.NET_1.1.4322

Service ASP.NET_2.0.50727

Service C:\WINNT\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [MANUAL] aspnet_state

Service [AUTO] aswMon

Service [MANUAL] aswRdr

Service [SYSTEM] aswTdi

Service C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [AUTO] aswUpdSv

Service C:\WINNT\System32\DRIVERS\asyncmac.sys [MANUAL] AsyncMac

Service C:\WINNT\System32\DRIVERS\atapi.sys [BOOT] atapi

Service [DISABLED] Atdisk

Service C:\WINNT\System32\DRIVERS\atmarpc.sys [MANUAL] Atmarpc

Service C:\WINNT\System32\ATMsrvc.exe [DISABLED] ATMsrvc

Service C:\WINNT\System32\DRIVERS\audstub.sys [MANUAL] audstub

Service C:\Program Files\Alwil Software\Avast4\ashServ.exe [AUTO] avast! Antivirus

Service C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [MANUAL] avast! Mail Scanner

Service C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [MANUAL] avast! Web Scanner

Service C:\WINNT\system32\drivers\b7721.SYS [SYSTEM] b7721

Service [SYSTEM] Beep

Service C:\WINNT\System32\svchost.exe [MANUAL] BITS

Service C:\WINNT\System32\services.exe [AUTO] Browser

Service [DISABLED] BusLogic

Service C:\WINNT\system32\DRIVERS\CCDECODE.sys [MANUAL] CCDECODE

Service [DISABLED] cd20xrnt

Service [SYSTEM] Cdaudio

Service [DISABLED] Cdfs

Service C:\WINNT\System32\Drivers\Cdrdrv.sys [MANUAL] cdrdrv

Service C:\WINNT\System32\DRIVERS\cdrom.sys [SYSTEM] Cdrom

Service [SYSTEM] Changer

Service C:\WINNT\System32\cisvc.exe [MANUAL] cisvc

Service C:\WINNT\system32\clipsrv.exe [MANUAL] ClipSrv

Service C:\WINNT\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [MANUAL] clr_optimization_v2.0.50727_32

Service ContentFilter

Service ContentIndex

Service C:\WINNT\system32\Drivers\CO_Mon.sys [MANUAL] CO_Mon

Service [DISABLED] Cpqarray

Service [DISABLED] cpqarry2

Service [DISABLED] cpqfcalm

Service [DISABLED] cpqfws2e

Service [DISABLED] dac960nt

Service [DISABLED] deckzpsx

Service C:\WINNT\System32\services.exe [AUTO] Dhcp

Service C:\WINNT\System32\DRIVERS\disk.sys [BOOT] Disk

Service [BOOT] Diskperf

Service C:\WINNT\System32\dmadmin.exe [MANUAL] dmadmin

Service C:\WINNT\System32\drivers\dmboot.sys [DISABLED] dmboot

Service C:\WINNT\System32\drivers\dmio.sys [BOOT] dmio

Service C:\WINNT\System32\drivers\dmload.sys [BOOT] dmload

Service C:\WINNT\System32\services.exe [AUTO] dmserver

Service C:\WINNT\system32\drivers\DMusic.sys [MANUAL] DMusic

Service C:\WINNT\System32\services.exe [AUTO] Dnscache

Service C:\WINNT\system32\DRIVERS\e1e5032.sys [MANUAL] e1express

Service [DISABLED] EFS

Service C:\WINNT\system32\services.exe [AUTO] Eventlog

Service C:\WINNT\System32\svchost.exe [MANUAL] EventSystem

Service [DISABLED] Fastfat

Service C:\WINNT\system32\faxsvc.exe [MANUAL] Fax

Service [DISABLED] Fd16_700

Service C:\WINNT\System32\DRIVERS\fdc.sys [MANUAL] Fdc

Service [AUTO] Fips

Service [DISABLED] fireport

Service [DISABLED] flashpnt

Service C:\WINNT\System32\DRIVERS\flpydisk.sys [MANUAL] Flpydisk

Service C:\WINNT\system32\drivers\fltmgr.sys [BOOT] FltMgr

Service [SYSTEM] Fs_Rec

Service C:\WINNT\System32\DRIVERS\ftdisk.sys [BOOT] Ftdisk

Service C:\WINNT\System32\DRIVERS\gmer.sys [MANUAL] gmer

Service C:\WINNT\System32\DRIVERS\msgpc.sys [MANUAL] Gpc

Service C:\WINNT\system32\DRIVERS\HDAudBus.sys [MANUAL] HDAudBus

Service C:\WINNT\System32\Drivers\Hlp.Sys [SYSTEM] hlp

Service C:\WINNT\System32\DRIVERS\i8042prt.sys [SYSTEM] i8042prt

Service IAS

Service C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [MANUAL] IDriverT

Service inetaccs

Service [DISABLED] ini910u

Service Inport

Service C:\WINNT\system32\drivers\RtkHDAud.sys [MANUAL] IntcAzAudAddService

Service [DISABLED] IntelIde

Service C:\WINNT\System32\DRIVERS\ipfltdrv.sys [MANUAL] IpFilterDriver

Service C:\WINNT\System32\DRIVERS\ipinip.sys [MANUAL] IpInIp

Service C:\WINNT\System32\DRIVERS\ipnat.sys [MANUAL] IpNat

Service C:\WINNT\System32\DRIVERS\ipsec.sys [MANUAL] IPSEC

Service [DISABLED] ipsraidn

Service C:\WINNT\System32\DRIVERS\irenum.sys [MANUAL] IRENUM

Service ISAPISearch

Service C:\WINNT\System32\DRIVERS\isapnp.sys [BOOT] isapnp

Service C:\WINNT\System32\DRIVERS\iteatapi.sys [BOOT] iteatapi

Service C:\WINNT\System32\DRIVERS\kbdclass.sys [SYSTEM] Kbdclass

Service C:\WINNT\system32\drivers\kmixer.sys [MANUAL] kmixer

Service [BOOT] KSecDD

Service C:\WINNT\System32\services.exe [AUTO] lanmanserver

Service C:\WINNT\System32\services.exe [AUTO] lanmanworkstation

Service [SYSTEM] lbrtfdc

Service C:\WINNT\System32\services.exe [AUTO] LmHosts

Service [DISABLED] lp6nds35

Service C:\WINNT\System32\services.exe [AUTO] Messenger

Service [SYSTEM] mnmdd

Service C:\WINNT\System32\mnmsrvc.exe [MANUAL] mnmsrvc

Service [MANUAL] Modem

Service C:\WINNT\System32\DRIVERS\mouclass.sys [SYSTEM] Mouclass

Service [BOOT] MountMgr

Service C:\WINNT\system32\DRIVERS\MPE.sys [MANUAL] MPE

Service [DISABLED] mraid35x

Service C:\WINNT\System32\DRIVERS\mrxsmb.sys [SYSTEM] MRxSmb

Service C:\WINNT\System32\msdtc.exe [MANUAL] MSDTC

Service C:\WINNT\System32\DRIVERS\msdv.sys [MANUAL] MSDV

Service [SYSTEM] Msfs

Service C:\WINNT\system32\msiexec.exe [MANUAL] MSIServer

Service C:\WINNT\system32\drivers\MSKSSRV.sys [MANUAL] MSKSSRV

Service C:\WINNT\system32\drivers\MSPCLOCK.sys [MANUAL] MSPCLOCK

Service C:\WINNT\system32\drivers\MSPQM.sys [MANUAL] MSPQM

Service C:\WINNT\system32\drivers\MSTEE.sys [MANUAL] MSTEE

Service C:\WINNT\system32\DRIVERS\mtdv2ku2.sys [MANUAL] MTDVC2

Service C:\WINNT\system32\DRIVERS\mtdv2ks2.sys [MANUAL] MTDVC2_ENUM

Service C:\WINNT\System32\DRIVERS\ASACPI.sys [MANUAL] MTsensor

Service C:\WINNT\system32\DRIVERS\MTXPARHM.sys [MANUAL] MTXPARH

Service [BOOT] Mup

Service C:\WINNT\system32\DRIVERS\NABTSFEC.sys [MANUAL] NABTSFEC

Service [DISABLED] Ncrc710

Service [BOOT] NDIS

Service C:\WINNT\system32\DRIVERS\NdisIP.sys [MANUAL] NdisIP

Service C:\WINNT\System32\DRIVERS\ndistapi.sys [MANUAL] NdisTapi

Service C:\WINNT\System32\DRIVERS\ndisuio.sys [MANUAL] Ndisuio

Service C:\WINNT\System32\DRIVERS\ndiswan.sys [MANUAL] NdisWan

Service [MANUAL] NDProxy

Service C:\WINNT\System32\DRIVERS\netbios.sys [SYSTEM] NetBIOS

Service C:\WINNT\System32\DRIVERS\netbt.sys [SYSTEM] NetBT

Service C:\WINNT\system32\netdde.exe [MANUAL] NetDDE

Service C:\WINNT\system32\netdde.exe [MANUAL] NetDDEdsdm

Service C:\WINNT\system32\drivers\netdtect.sys [MANUAL] NetDetect

Service C:\WINNT\System32\lsass.exe [MANUAL] Netlogon

Service C:\WINNT\System32\svchost.exe [MANUAL] Netman

Service nm

Service [SYSTEM] Npfs

Service [DISABLED] Ntfs

Service C:\WINNT\System32\lsass.exe [MANUAL] NtLmSsp

Service C:\WINNT\System32\svchost.exe [AUTO] NtmsSvc

Service [SYSTEM] Null

Service C:\WINNT\System32\DRIVERS\nwlnkflt.sys [MANUAL] NwlnkFlt

Service C:\WINNT\System32\DRIVERS\nwlnkfwd.sys [MANUAL] NwlnkFwd

Service C:\WINNT\System32\DRIVERS\ohci1394.sys [BOOT] ohci1394

Service C:\WINNT\system32\drivers\oreans32.sys [SYSTEM] oreans32

Service C:\WINNT\System32\DRIVERS\parallel.sys [MANUAL] Parallel

Service C:\WINNT\System32\DRIVERS\parport.sys [SYSTEM] Parport

Service [BOOT] PartMgr

Service [AUTO] ParVdm

Service C:\WINNT\System32\DRIVERS\pci.sys [BOOT] PCI

Service [SYSTEM] PCIDump

Service C:\WINNT\System32\DRIVERS\pciide.sys [BOOT] PCIIde

Service [AUTO] PCLEPCI

Service [DISABLED] Pcmcia

Service PerfDisk

Service PerfNet

Service PerfOS

Service PerfProc

Service C:\WINNT\system32\drivers\pfc.sys [MANUAL] pfc

Service C:\WINNT\system32\services.exe [AUTO] PlugPlay

Service C:\WINNT\System32\lsass.exe [AUTO] PolicyAgent

Service C:\WINNT\System32\DRIVERS\raspptp.sys [MANUAL] PptpMiniport

Service C:\WINNT\system32\services.exe [AUTO] ProtectedStorage

Service C:\WINNT\System32\DRIVERS\ptilink.sys [MANUAL] Ptilink

Service C:\WINNT\System32\Drivers\PxHelp20.sys [BOOT] PxHelp20

Service [DISABLED] ql1080

Service [DISABLED] Ql10wnt

Service [DISABLED] ql1240

Service [DISABLED] ql2100

Service C:\WINNT\System32\DRIVERS\rasacd.sys [SYSTEM] RasAcd

Service C:\WINNT\System32\svchost.exe [MANUAL] RasAuto

Service C:\WINNT\System32\DRIVERS\rasl2tp.sys [MANUAL] Rasl2tp

Service C:\WINNT\System32\svchost.exe [MANUAL] RasMan

Service C:\WINNT\System32\DRIVERS\raspti.sys [MANUAL] Raspti

Service C:\WINNT\system32\drivers\RCA.sys [MANUAL] RCA

Service C:\WINNT\System32\DRIVERS\rdbss.sys [SYSTEM] Rdbss

Service C:\WINNT\System32\DRIVERS\redbook.sys [SYSTEM] redbook

Service C:\WINNT\System32\svchost.exe [DISABLED] RemoteAccess

Service C:\WINNT\system32\regsvc.exe [AUTO] RemoteRegistry

Service C:\WINNT\System32\locator.exe [MANUAL] RpcLocator

Service C:\WINNT\system32\svchost.exe [AUTO] RpcSs

Service C:\WINNT\System32\rsvp.exe [MANUAL] RSVP

Service C:\WINNT\system32\lsass.exe [AUTO] SamSs

Service C:\WINNT\System32\SCardSvr.exe [MANUAL] SCardDrv

Service C:\WINNT\System32\SCardSvr.exe [MANUAL] SCardSvr

Service C:\WINNT\system32\MSTask.exe [AUTO] Schedule

Service [AUTO] SchedulingAgent

Service C:\WINNT\system32\services.exe [AUTO] seclogon

Service C:\WINNT\system32\svchost.exe [AUTO] SENS

Service C:\WINNT\System32\DRIVERS\serenum.sys [MANUAL] serenum

Service C:\WINNT\System32\DRIVERS\serial.sys [SYSTEM] Serial

Service C:\WINNT\System32\drivers\SFC4.sys [MANUAL] SFC4

Service [SYSTEM] Sfloppy

Service [SYSTEM] sglfb

Service C:\WINNT\System32\svchost.exe [MANUAL] SharedAccess

Service C:\WINNT\System32\DRIVERS\SI3132.sys [BOOT] SI3132

Service [DISABLED] Simbad

Service C:\WINNT\system32\DRIVERS\SLIP.sys [MANUAL] SLIP

Service [DISABLED] Sparrow

Service C:\WINNT\system32\spoolsv.exe [AUTO] Spooler

Service C:\WINNT\System32\DRIVERS\srv.sys [MANUAL] Srv

Service C:\WINNT\system32\drivers\SSHDRV5C.sys [SYSTEM] SSHDRV5C

Service C:\WINNT\system32\drivers\SSHDRV76.sys [SYSTEM] SSHDRV76

Service StarOpen

Service C:\WINNT\system32\DRIVERS\StreamIP.sys [MANUAL] streamip

Service C:\WINNT\System32\DRIVERS\swenum.sys [MANUAL] swenum

Service C:\WINNT\system32\drivers\swmidi.sys [MANUAL] swmidi

Service [DISABLED] symc810

Service [DISABLED] symc8xx

Service [DISABLED] sym_hi

Service C:\WINNT\system32\drivers\sysaudio.sys [MANUAL] sysaudio

Service C:\WINNT\system32\smlogsvc.exe [MANUAL] SysmonLog

Service C:\WINNT\System32\svchost.exe [MANUAL] TapiSrv

Service C:\WINNT\System32\DRIVERS\tcpip.sys [SYSTEM] Tcpip

Service [SYSTEM] tga

Service C:\WINNT\system32\tlntsvr.exe [MANUAL] TlntSvr

Service C:\WINNT\system32\services.exe [AUTO] TrkWks

Service [DISABLED] Udfs

Service C:\WINNT\System32\DRIVERS\uhcd.sys [MANUAL] uhcd

Service [DISABLED] ultra66

Service C:\WINNT\System32\DRIVERS\update.sys [MANUAL] Update

Service C:\WINNT\System32\ups.exe [MANUAL] UPS

Service C:\WINNT\System32\DRIVERS\usbehci.sys [MANUAL] usbehci

Service C:\WINNT\System32\DRIVERS\usbhub.sys [MANUAL] usbhub

Service C:\WINNT\System32\DRIVERS\usbhub20.sys [MANUAL] usbhub20

Service C:\WINNT\System32\DRIVERS\USBSTOR.SYS [MANUAL] USBSTOR

Service C:\WINNT\System32\UtilMan.exe [MANUAL] UtilMan

Service C:\WINNT\System32\drivers\vga.sys [SYSTEM] VgaSave

Service vobcom

Service [SYSTEM] vobfat

Service C:\WINNT\system32\DRIVERS\vobid.sys [BOOT] VOBID

Service [SYSTEM] vobiw

Service VxD

Service C:\WINNT\System32\services.exe [MANUAL] W32Time

Service W3SVC

Service C:\WINNT\System32\DRIVERS\wanarp.sys [MANUAL] Wanarp

Service C:\WINNT\system32\drivers\wdmaud.sys [MANUAL] wdmaud

Service C:\WINNT\System32\WBEM\WinMgmt.exe [AUTO] WinMgmt

Service [MANUAL] Winsock

Service WinSock2

Service WinTrust

Service C:\WINNT\System32\svchost.exe [MANUAL] WmdmPmSN

Service C:\WINNT\system32\Services.exe [MANUAL] Wmi

Service C:\WINNT\system32\DRIVERS\WSTCODEC.SYS [MANUAL] WSTCODEC

Service C:\WINNT\system32\svchost.exe [AUTO] wuauserv

Service C:\WINNT\System32\svchost.exe [MANUAL] WZCSVC

Service C:\WINNT\System32\DRIVERS\yk50x86.sys [MANUAL] yukonw2k

Service {45FE445C-732E-4994-9E0C-D76B4311EA06}

Service {C6529564-A4B6-4813-9FA9-003FA30E6A25}

Service {DF37D2CC-5537-47DA-970C-2395D0762535}


---- EOF - GMER 1.0.12 ----

(adam9870) #9

W Gmerze w zakładce CMD z zaznaczoną opcją CMD.EXE wklej:

I kliknij Uruchom.


(Mir Jab) #10

po uruchomieniu wyświetliły się dwa komunikaty

i

Wpis oczywiście nie został skasowany


(adam9870) #11

Otwórz notatnik i wklej:

Plik >>> Zapisz jako >>> Zmień rozszerzenie z TXT na Wszystkie pliki >>> Zapisz pod nazwą FIX.BAT

  1. Uruchom Gmer'a

  2. Wybierz Gmer awaryjny

  3. Komputer się zrestartuje i zostaniesz spytany czy chcesz zabić wszystkie procesy na co oczywiście się zgódź.

  4. W Gmerze w zakładce Procesy przez trzy kropki wskaż FIX.BAT i po chwilce komputer się zrestartuje.


(Mir Jab) #12

niestety tak jak poprzednio wyświetliły się błędy przy kasowaniu i nic nie usunęło