Hey,
Ik heb hier een AlienWare laptop die Windows XP Pro SP2 draait. Probleem is dat na het opstarten explorer.exe crasht (zonder foutmeldingen), herstart, een paar seconden goed draait, dan weer crasht en reboot, en zo een stuk of 15 keer aan een stuk tot hij uiteindelijk crasht en het uiteindelijk voor bekeken houdt. Ctrl+Alt+Del geeft de melding "Task Manager has been disabled by your Administrator".
Het probleem van de Task Manager heb ik kunnen oplossen via gpedit.msc, maar het explorer.exe probleem blijft. Ook na een Diagnostic Startup (via msconfig) blijft het probleem bestaan. Zelfs in Safe Mode is het probleem er nog steeds. Hij is er nu om een of andere reden voor de eerste keer mee opgehouden (in een Diagnostic Startup via msconfig), en daar heb ik gebruik van gemaakt om HijackThis, Ad-Aware en RootkitRevealer te draaien.
Hieronder m'n HijackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:07:20, on 19/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\mmc.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Grisoft\AVG7\avgwb.dat
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Aware2007.exe
C:\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: qtvglped - {74E5E4E8-79DD-49AC-B64B-E74822D5F3CD} - (no file)
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKLM\..\Policies\Explorer\Run: [BEz0kS8N1M] C:\Documents and Settings\All Users\Application Data\czyxilqx\stkxoxsd.exe
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User '?')
O4 - HKUS\S-1-5-21-1085031214-515967899-839522115-500\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User '?')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O21 - SSODL: PrxComponent - {b32a9929-e79f-466b-80d5-e1b8ecc3985c} - (no file)
O21 - SSODL: zip - {57c0c0ee-767a-4eae-ba33-c13a8914543f} - (no file)
O21 - SSODL: omlbpkaw - {BBCCD338-97D5-4807-8864-DC8688BB15B7} - (no file)
O21 - SSODL: pmsoarbf - {93E20A40-1EBA-442D-9511-486DB37E8045} - (no file)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
--
End of file - 3712 bytes
En hier de resultaten van RootkitRevealer:
HKU\S-1-5-21-1085031214-515967899-839522115-500\Software\SecuROM\!CAUTION! NEVER DELETE OR CHANGE ANY KEY* 10/5/2007 9:54 PM 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAC* 4/14/2005 12:06 AM 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI* 4/14/2005 12:06 AM 0 bytes Key name contains embedded nulls (*)
C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware 2007\logs\aaw2007log.xsl 6/21/2007 3:32 PM 13.11 KB Visible in Windows API, MFT, but not in directory index.
C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware 2007\logs\AdAware event.log 4/19/2008 4:06 PM 40 bytes Visible in Windows API, MFT, but not in directory index.
Een scan met Ad-Aware levert vervolgens 6 hits:
<?xml version="1.0" encoding="UTF-16"?>
<Infections Comment="Created with Ad-Aware 2007">
<Family:Adware.Agent>
<Item ="Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{be2ed590-ca49-46b5-8cce-244fb2e0d1aa}"/>
<Item ="Root: HKCR Path: msvps.msvpsapp"/>
<Item ="Root: HKCR Path: msvps.msvpsapp"/>
<Item ="Root: HKLM Path: software\microsoft\videoplugin Value: at"/>
<Item ="Root: HKLM Path: software\microsoft\videoplugin"/>
<Item ="Root: HKLM Path: software\microsoft\windows\currentversion\uninstall\webvideo"/>
<Item ="Root: HKCR Path: appid\dlp.dll"/>
<Item ="File: C:\Documents and Settings\Administrator\Favorites\Error Cleaner.url"/>
<Item ="File: C:\Documents and Settings\Administrator\Favorites\Privacy Protector.url"/>
<Item ="File: C:\Documents and Settings\Administrator\Favorites\Spyware&Malware Protection.url"/>
</Family:Adware.Agent>
<Family:CoolWebSearch>
<Item ="Root: HKCR Path: clsid\{0e1230f8-ea50-42a9-983c-d22abc2eeb4c}"/>
<Item ="Root: HKU Path: S-1-5-21-1085031214-515967899-839522115-500_Classes\clsid\{0e1230f8-ea50-42a9-983c-d22abc2eeb4c}"/>
<Item ="Root: HKU Path: S-1-5-21-1085031214-515967899-839522115-500\software\microsoft\internet explorer\main Value: Use Search Asst Data: no"/>
<Item ="Root: HKU Path: S-1-5-21-1085031214-515967899-839522115-500\software\microsoft\windows\currentversion\internet settings\zonemap\domains\i--search.com"/>
</Family:CoolWebSearch>
<Family:Holystic-Dialer>
<Item ="Root: HKCR Path: clsid\{0b682cc1-fb40-4006-a5dd-99edd3c9095d}"/>
<Item ="Root: HKU Path: S-1-5-21-1085031214-515967899-839522115-500_Classes\clsid\{0b682cc1-fb40-4006-a5dd-99edd3c9095d}"/>
<Item ="Root: HKU Path: S-1-5-21-1085031214-515967899-839522115-500_Classes\hol5_vxiewer.full.1"/>
</Family:Holystic-Dialer>
<Family:JRaun>
<Item ="Root: HKCR Path: clsid\{5c7f15e1-f31a-44fd-aa1a-2ec63aaffd3a}"/>
</Family:JRaun>
<Family:TIBBrowser>
<Item ="Root: HKCR Path: clsid\{0656a137-b161-cadd-9777-e37a75727e78}"/>
<Item ="Root: HKU Path: S-1-5-21-1085031214-515967899-839522115-500_Classes\clsid\{0656a137-b161-cadd-9777-e37a75727e78}"/>
<Item ="Root: HKU Path: S-1-5-21-1085031214-515967899-839522115-500\software\classes\clsid\{0656a137-b161-cadd-9777-e37a75727e78}"/>
</Family:TIBBrowser>
<Family:Win32.TrojanClicker>
<Item ="Root: HKCR Path: clsid\{54645654-2225-4455-44a1-9f4543d34545}"/>
</Family:Win32.TrojanClicker>
</Infections>
Volstaat de ingeboude removal van Ad-Aware hiervoor of gebruik ik best gespecialiseerde tools?
Ik heb hier een AlienWare laptop die Windows XP Pro SP2 draait. Probleem is dat na het opstarten explorer.exe crasht (zonder foutmeldingen), herstart, een paar seconden goed draait, dan weer crasht en reboot, en zo een stuk of 15 keer aan een stuk tot hij uiteindelijk crasht en het uiteindelijk voor bekeken houdt. Ctrl+Alt+Del geeft de melding "Task Manager has been disabled by your Administrator".
Het probleem van de Task Manager heb ik kunnen oplossen via gpedit.msc, maar het explorer.exe probleem blijft. Ook na een Diagnostic Startup (via msconfig) blijft het probleem bestaan. Zelfs in Safe Mode is het probleem er nog steeds. Hij is er nu om een of andere reden voor de eerste keer mee opgehouden (in een Diagnostic Startup via msconfig), en daar heb ik gebruik van gemaakt om HijackThis, Ad-Aware en RootkitRevealer te draaien.
Hieronder m'n HijackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:07:20, on 19/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\mmc.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Grisoft\AVG7\avgwb.dat
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Aware2007.exe
C:\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: qtvglped - {74E5E4E8-79DD-49AC-B64B-E74822D5F3CD} - (no file)
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKLM\..\Policies\Explorer\Run: [BEz0kS8N1M] C:\Documents and Settings\All Users\Application Data\czyxilqx\stkxoxsd.exe
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User '?')
O4 - HKUS\S-1-5-21-1085031214-515967899-839522115-500\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User '?')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O21 - SSODL: PrxComponent - {b32a9929-e79f-466b-80d5-e1b8ecc3985c} - (no file)
O21 - SSODL: zip - {57c0c0ee-767a-4eae-ba33-c13a8914543f} - (no file)
O21 - SSODL: omlbpkaw - {BBCCD338-97D5-4807-8864-DC8688BB15B7} - (no file)
O21 - SSODL: pmsoarbf - {93E20A40-1EBA-442D-9511-486DB37E8045} - (no file)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
--
End of file - 3712 bytes
En hier de resultaten van RootkitRevealer:
HKU\S-1-5-21-1085031214-515967899-839522115-500\Software\SecuROM\!CAUTION! NEVER DELETE OR CHANGE ANY KEY* 10/5/2007 9:54 PM 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAC* 4/14/2005 12:06 AM 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI* 4/14/2005 12:06 AM 0 bytes Key name contains embedded nulls (*)
C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware 2007\logs\aaw2007log.xsl 6/21/2007 3:32 PM 13.11 KB Visible in Windows API, MFT, but not in directory index.
C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware 2007\logs\AdAware event.log 4/19/2008 4:06 PM 40 bytes Visible in Windows API, MFT, but not in directory index.
Een scan met Ad-Aware levert vervolgens 6 hits:
<?xml version="1.0" encoding="UTF-16"?>
<Infections Comment="Created with Ad-Aware 2007">
<Family:Adware.Agent>
<Item ="Root: HKLM Path: software\microsoft\windows\currentversion\explorer\browser helper objects\{be2ed590-ca49-46b5-8cce-244fb2e0d1aa}"/>
<Item ="Root: HKCR Path: msvps.msvpsapp"/>
<Item ="Root: HKCR Path: msvps.msvpsapp"/>
<Item ="Root: HKLM Path: software\microsoft\videoplugin Value: at"/>
<Item ="Root: HKLM Path: software\microsoft\videoplugin"/>
<Item ="Root: HKLM Path: software\microsoft\windows\currentversion\uninstall\webvideo"/>
<Item ="Root: HKCR Path: appid\dlp.dll"/>
<Item ="File: C:\Documents and Settings\Administrator\Favorites\Error Cleaner.url"/>
<Item ="File: C:\Documents and Settings\Administrator\Favorites\Privacy Protector.url"/>
<Item ="File: C:\Documents and Settings\Administrator\Favorites\Spyware&Malware Protection.url"/>
</Family:Adware.Agent>
<Family:CoolWebSearch>
<Item ="Root: HKCR Path: clsid\{0e1230f8-ea50-42a9-983c-d22abc2eeb4c}"/>
<Item ="Root: HKU Path: S-1-5-21-1085031214-515967899-839522115-500_Classes\clsid\{0e1230f8-ea50-42a9-983c-d22abc2eeb4c}"/>
<Item ="Root: HKU Path: S-1-5-21-1085031214-515967899-839522115-500\software\microsoft\internet explorer\main Value: Use Search Asst Data: no"/>
<Item ="Root: HKU Path: S-1-5-21-1085031214-515967899-839522115-500\software\microsoft\windows\currentversion\internet settings\zonemap\domains\i--search.com"/>
</Family:CoolWebSearch>
<Family:Holystic-Dialer>
<Item ="Root: HKCR Path: clsid\{0b682cc1-fb40-4006-a5dd-99edd3c9095d}"/>
<Item ="Root: HKU Path: S-1-5-21-1085031214-515967899-839522115-500_Classes\clsid\{0b682cc1-fb40-4006-a5dd-99edd3c9095d}"/>
<Item ="Root: HKU Path: S-1-5-21-1085031214-515967899-839522115-500_Classes\hol5_vxiewer.full.1"/>
</Family:Holystic-Dialer>
<Family:JRaun>
<Item ="Root: HKCR Path: clsid\{5c7f15e1-f31a-44fd-aa1a-2ec63aaffd3a}"/>
</Family:JRaun>
<Family:TIBBrowser>
<Item ="Root: HKCR Path: clsid\{0656a137-b161-cadd-9777-e37a75727e78}"/>
<Item ="Root: HKU Path: S-1-5-21-1085031214-515967899-839522115-500_Classes\clsid\{0656a137-b161-cadd-9777-e37a75727e78}"/>
<Item ="Root: HKU Path: S-1-5-21-1085031214-515967899-839522115-500\software\classes\clsid\{0656a137-b161-cadd-9777-e37a75727e78}"/>
</Family:TIBBrowser>
<Family:Win32.TrojanClicker>
<Item ="Root: HKCR Path: clsid\{54645654-2225-4455-44a1-9f4543d34545}"/>
</Family:Win32.TrojanClicker>
</Infections>
Volstaat de ingeboude removal van Ad-Aware hiervoor of gebruik ik best gespecialiseerde tools?
Comment