Problem z otwieraniem programów

mój problem z komputerem polega na tym, że nie chcą się uruchamiać programy np. CorelDraw, FotoOffice i inne. Jeżeli w Gmer-ze przywrócę SSDT wszystko jest OK. Nie potrafię na podstawie logów znaleźć przyczyny, czy moglibyście spojrzeć na nie i mi pomóc!

GMER 1.0.12.12027 - http://www.gmer.net

Rootkit scan 2007-02-21 15:49:09

Windows 5.0.2195 Service Pack 4



---- System - GMER 1.0.12 ----


SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwClose

SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwCreateDirectoryObject

SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwCreateFile

SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwCreateProcess

SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwCreateSection

SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwOpenFile

SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwSetInformationFile

SSDT \SystemRoot\System32\Drivers\aswMon.SYS ZwWriteFile


---- EOF - GMER 1.0.12 ----

Logfile of HijackThis v1.99.1

Scan saved at 15:52:10, on 2007-02-21

Platform: Windows 2000 SP4 (WinNT 5.00.2195)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)


Running processes:

C:\WINNT\System32\smss.exe

C:\WINNT\system32\winlogon.exe

C:\WINNT\system32\services.exe

C:\WINNT\system32\lsass.exe

C:\WINNT\system32\svchost.exe

C:\WINNT\system32\spoolsv.exe

C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

C:\Program Files\Alwil Software\Avast4\ashServ.exe

C:\WINNT\System32\svchost.exe

C:\WINNT\system32\regsvc.exe

C:\WINNT\system32\MSTask.exe

C:\WINNT\System32\WBEM\WinMgmt.exe

C:\WINNT\system32\svchost.exe

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

C:\WINNT\Explorer.EXE

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

C:\WINNT\gmer.exe

C:\Program Files\Internet Explorer\IEXPLORE.EXE

C:\Program Files\Corel\Graphics9\Programs\coreldrw.exe

C:\Program Files\G DATA Software\FotoOffice 2007 HOME\FotoOffice.exe

C:\Documents and Settings\Mirosław Jabłoński\Moje dokumenty\Download\hijackthis\hijackthis.com


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lodz.naszemiasto.pl/

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx

O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - C:\PROGRA~1\DAP\DAPIEBar.dll

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon

O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm

O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm

O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm

O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll

O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.pl/resources/virusscanner/kavwebscan_unicode.cab

O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1151312695609

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab

O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - http://www.mks.com.pl/skaner/SkanerOnline.cab

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1160564628218

O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://217.113.236.251/activex/AxisCamControl.cab

O16 - DPF: {E36C5562-C4E0-4220-BCB2-1C671E3A5916} - http://www.seagate.com/support/disc/asp/tools/en/bin/npseatools.cab

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

O23 - Service: Usługa administracyjna Menedżera dysków logicznych (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

"Silent Runners.vbs", revision R50, http://www.silentrunners.org/

Operating System: Windows 2000

Output limited to non-default values, except where indicated by "{++}"



Startup items buried in registry:

---------------------------------


HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}

"avast!" = "C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [null data]

"Synchronization Manager" = "mobsync.exe /logon" [MS]


HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)

  -> {HKLM...CLSID} = "AcroIEHlprObj Class"

                   \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]


HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\

"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"

  -> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"

                   \InProcServer32\(Default) = "deskpan.dll" [file not found]

"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"

  -> {HKLM...CLSID} = "HyperTerminal Icon Ext"

                   \InProcServer32\(Default) = "C:\WINNT\System32\hticons.dll" ["Hilgraeve, Inc."]

"{A7B1D2E1-5E71-4975-B8D9-FC4A1FB6B0A6}" = "Matrox PowerDesk Page"

  -> {HKLM...CLSID} = "Matrox PowerDesk Page"

                   \InProcServer32\(Default) = "C:\WINNT\system32\PowerDesk8\Matrox.PowerDesk.PDeskPage.dll" ["Matrox Graphics Inc."]

"{FEB7DAE0-E111-11D0-BFD7-444553540000}" = "ICEOWS"

  -> {HKLM...CLSID} = "Folder Iceows"

                   \InProcServer32\(Default) = "C:\WINNT\system32\ShellExt\IceGUI.dll" ["Raphaël MOUNIER"]

"{79BC0345-1015-11D2-A299-006008312725}" = "blue.shell"

  -> {HKLM...CLSID} = "Edition.Project"

                   \InProcServer32\(Default) = "C:\Program Files\Pinnacle\Edition 5\Program\BlueShellExt.dll" [null data]

"{F5D92341-0A64-11D0-9956-0000E8096023}" = "CD Copy Shell Extension"

  -> {HKLM...CLSID} = "CD Copy Shell Extension"

                   \InProcServer32\(Default) = "C:\WINNT\system32\Shellext\CDWshext.dll" ["Pinnacle Systems, Inc."]

"{F5D92342-0A64-11D0-9956-0000E8096023}" = "CD Wizard Shell Extension"

  -> {HKLM...CLSID} = "CD Wizard Shell Extension"

                   \InProcServer32\(Default) = "C:\WINNT\system32\Shellext\CDWshext.dll" ["Pinnacle Systems, Inc."]

"{F5D92344-0A64-11D0-9956-0000E8096023}" = "InstantWrite Shellextension"

  -> {HKLM...CLSID} = "InstantWrite Shellextension"

                   \InProcServer32\(Default) = "C:\WINNT\system32\ShellExt\iwshex.dll" ["VOB Computersysteme GmbH"]

"{472083B0-C522-11CF-8763-00608CC02F24}" = "avast"

  -> {HKLM...CLSID} = "avast"

                   \InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]

"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"

  -> {HKLM...CLSID} = "Rozszerzenie ikon plików programu Outlook"

                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office\OLKFSTUB.DLL" [MS]


HKLM\Software\Classes\Folder\shellex\ColumnHandlers\

{F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"

  -> {HKLM...CLSID} = "PDF Shell Extension"

                   \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]


HKLM\Software\Classes\*\shellex\ContextMenuHandlers\

avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"

  -> {HKLM...CLSID} = "avast"

                   \InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]

DAP_Menu\(Default) = "{BED4C38B-F765-45AC-8C56-613F76BBF43E}"

  -> {HKLM...CLSID} = "DAPMenuShellExt Class"

                   \InProcServer32\(Default) = "C:\PROGRA~1\DAP\PRIVAC~1\DAPCTX~1.DLL" ["Speedbit Ltd."]

ICEOWS\(Default) = "{FEB7DAE0-E111-11D0-BFD7-444553540000}"

  -> {HKLM...CLSID} = "Folder Iceows"

                   \InProcServer32\(Default) = "C:\WINNT\system32\ShellExt\IceGUI.dll" ["Raphaël MOUNIER"]

MkS_Vir\(Default) = "{E64226E0-9DA1-479E-8265-8D65BA327BD4}"

  -> {HKLM...CLSID} = "MkS_Vir Shell Extension"

                   \InProcServer32\(Default) = "/u\mksshell.dll" [file not found]


HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\

ICEOWS\(Default) = "{FEB7DAE0-E111-11D0-BFD7-444553540000}"

  -> {HKLM...CLSID} = "Folder Iceows"

                   \InProcServer32\(Default) = "C:\WINNT\system32\ShellExt\IceGUI.dll" ["Raphaël MOUNIER"]


HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\

avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"

  -> {HKLM...CLSID} = "avast"

                   \InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]

MkS_Vir\(Default) = "{E64226E0-9DA1-479E-8265-8D65BA327BD4}"

  -> {HKLM...CLSID} = "MkS_Vir Shell Extension"

                   \InProcServer32\(Default) = "/u\mksshell.dll" [file not found]



Group Policies {GPedit.msc branch and setting}:

-----------------------------------------------


Note: detected settings may not have any effect.


HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\


"CDRAutoRun" = (REG_DWORD) hex:0x00000000

{unrecognized setting}


HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\


"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001

{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|

Shutdown: Allow system to be shut down without having to log on}



Active Desktop and Wallpaper:

-----------------------------


Active Desktop may be disabled at this entry:

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState


Active Desktop web content (hidden if disabled):


HKCU\Software\Microsoft\Internet Explorer\Desktop\Components\0\

"FriendlyName" = "Moja bieżąca strona główna"

"Source" = "About:Home"

"SubscribedURL" = "About:Home"



Enabled Scheduled Tasks:

------------------------


"AppleSoftwareUpdate" -> launches: "C:\Program Files\Apple Software Update\SoftwareUpdate.exe -Task" ["Apple Computer, Inc."]



Winsock2 Service Provider DLLs:

-------------------------------


Namespace Service Providers


HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}

000000000001\LibraryPath = "%SystemRoot%\System32\rnr20.dll" [MS]

000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]


Transport Service Providers


HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}

0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:

%SystemRoot%\system32\msafd.dll [MS], 01 - 03, 06 - 15

%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05



Toolbars, Explorer Bars, Extensions:

------------------------------------


Toolbars


HKLM\Software\Microsoft\Internet Explorer\Toolbar\

"{62999427-33FC-4BAF-9C9C-BCE6BD127F08}" = "DAP Bar"

  -> {HKLM...CLSID} = "DAP Bar"

                   \InProcServer32\(Default) = "C:\PROGRA~1\DAP\DAPIEBar.dll" [empty string]



Running Services (Display Name, Service Name, Path {Service DLL}):

------------------------------------------------------------------


avast! Antivirus, avast! Antivirus, ""C:\Program Files\Alwil Software\Avast4\ashServ.exe"" [null data]

avast! iAVS4 Control Service, aswUpdSv, ""C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"" [null data]

avast! Mail Scanner, avast! Mail Scanner, ""C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service" ["ALWIL Software"]

avast! Web Scanner, avast! Web Scanner, ""C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service" ["ALWIL Software"]

System zdarzeń COM+, EventSystem, "C:\WINNT\System32\svchost.exe -k netsvcs" {"C:\WINNT\System32\es.dll" [null data]}



Print Monitors:

---------------


HKLM\System\CurrentControlSet\Control\Print\Monitors\

PDF Port\Driver = "C:\WINNT\system32\pdfports.dll" ["Adobe Systems Inc."]



----------

+ This report excludes default entries except where indicated.

+ To see *everywhere* the script checks and *everything* it finds,

  launch it from a command prompt or a shortcut with the -all parameter.

+ The search for DESKTOP.INI DLL launch points on all local fixed drives

  took 12 seconds.

---------- (total run time: 32 seconds)

ponieważ aswMon.SYS to jest: avast! File System Filter Driver for Windows NT/2000 [za] to odinstalowałem avast’a, zapuściłem Gmer’a - wszystko OK, ściągnąłem avast’a zainstalowałem wszystko wróciło do poprzedniego stanu tzn Gmer wskazuje na plik aswMon.sys - programy oczywiście nie otwierają się. Możliwości widzę trzy: 1.“Coś” infekuje avasta, albo 2.Ściągam już zainfekowanego Avasta, albo 3.Gmer błędnie informuje, bo to nie jest rootkit (tylko dlaczego nie działają programy?). Stawiam na tą pierwszą możliwość bo w obecnej konfiguracji (programy teraz niedziałające + avast) pracuje od dłuższego czasu i wszystko było OK - tylko co może infekować avasta?

Możecie coś zasugerować, pomóc!

Jeszcze jedną rzecz zrobiłem, ściągnąłem ten plik avasta od kolegi, zapuściłem Gmer’a - wszystko OK, ponowny start systemu i wszystko wraca do początku

Może avast się gryzie z tymi programami mało prawdopodobne by był zainfekowane.Zmień avasta na inny darmowy program anty wirusowy np. avirę:

http://www.dobreprogramy.pl/index.php?dz=2&t=30&id=388

lub AVG

http://www.dobreprogramy.pl/index.php?dz=2&t=30&id=425

Z darmowych te są najlepsze :wink:

Pewnie uruchamia się w GMER jakaś funkcja blokady uruchamiania nowych procesów (programów). Niektóre programy tak mają, że anty spyware’y czy antywiry wykrywają ich procesy jako szkodliwe. Co do procesu avasta to pewnie tak jest w tym konkretnym przypadku. Daj logi z Silent Runners i HijackThis do działu Bezpieczeństwo i tam ci powiedzą czy coś jest nie tak, czy wszystko jest w porządku. Sam piszesz, że jak włączysz w GMER jakąś funkcję to wszystko wraca do normy. Moim zdaniem to GMER blokuje te programy.