Błąd wewnętrzny nie pozwala zmienić tapety
Witam,
mam problem dość banalny... od paru dni mam czarny pulpit i nie mogę zmienić tapety, ponieważ pojawia się błąd wewnętrzny. Sprawdzałem antywirusem i Spybootem i nic.
Proszę o pomoc
Odpowiedzi: 5
Wiec Windows jest oryginalny bo dostalem go wraz z kompem a oto co wykazal program:
ComboFix 09-09-14.02 - terg 2009-09-16 22:30.1.2 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1250.48.1045.18.3036.1617 [GMT 2:00]
Uruchomiony z: c:\users\terg\Downloads\ComboFix.exe
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programdata\Microsoft\Windows\Templates\MyCustomAction.dll
c:\users\terg\AppData\Roaming\EurekaLog
c:\windows\Installer\1fc00.msi
c:\windows\system32\acovcnt.exe
c:\windows\system32\sqlite3.dll
.
((((((((((((((((((((((((( Pliki utworzone od 2009-08-17 do 2009-09-17 )))))))))))))))))))))))))))))))
.
2009-09-16 20:43 . 2009-09-16 20:43 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-09-11 18:28 . 2009-09-12 16:21 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-09-11 18:28 . 2009-09-11 19:35 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-11 15:33 . 2009-09-11 15:33 -------- d-----w- c:\program files\iPhone Configuration Utility
2009-09-11 15:32 . 2009-09-11 15:33 -------- d-----w- c:\program files\Safari
2009-09-11 15:29 . 2009-05-18 12:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-09-11 15:29 . 2008-04-17 11:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-09-11 15:29 . 2009-09-11 15:29 -------- d-----w- c:\program files\iPod
2009-09-11 15:28 . 2009-09-11 15:29 -------- d-----w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-11 15:26 . 2009-09-11 15:26 -------- d-----w- c:\program files\QuickTime
2009-09-09 19:11 . 2009-09-09 19:11 -------- d-----w- c:\users\terg\AppData\Local\vdownloader
2009-09-09 19:11 . 2009-09-09 19:11 -------- d-----w- c:\users\terg\AppData\Roaming\Desktopicon
2009-09-09 19:10 . 2009-09-09 19:11 -------- d-----w- c:\program files\VDOWNLOADER
2009-09-08 19:41 . 2009-08-17 16:04 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-09-08 19:41 . 2009-08-17 16:04 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-09-08 19:41 . 2009-08-17 16:05 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-09-08 19:41 . 2009-08-17 16:05 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-09-08 19:41 . 2009-08-17 16:02 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-09-08 19:41 . 2009-08-17 16:10 1279456 ----a-w- c:\windows\system32\aswBoot.exe
2009-09-08 19:41 . 2009-08-17 16:05 53328 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2009-09-08 19:41 . 2009-09-08 19:41 -------- d-----w- c:\program files\Alwil Software
2009-09-05 15:56 . 2004-05-04 10:53 1645320 ----a-w- c:\windows\system32\gdiplus.dll
2009-09-05 15:56 . 2009-09-05 15:56 -------- d-----w- c:\program files\BurnAware Free
2009-09-04 16:38 . 2009-09-04 16:38 -------- d-----w- c:\users\terg\AppData\Local\cache
2009-09-03 15:06 . 2009-08-29 00:27 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-09-03 15:06 . 2009-08-29 00:14 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-08-30 19:09 . 2009-08-30 19:12 -------- d-----w- c:\windows\system32\ca-ES
2009-08-30 19:09 . 2009-08-30 19:12 -------- d-----w- c:\windows\system32\eu-ES
2009-08-30 19:09 . 2009-08-30 19:11 -------- d-----w- c:\windows\system32\vi-VN
2009-08-29 09:11 . 2009-08-29 09:11 -------- d-----w- c:\windows\system32\EventProviders
2009-08-29 09:08 . 2009-04-11 06:28 677376 ----a-w- c:\windows\system32\imapi2fs.dll
2009-08-29 09:07 . 2009-04-11 06:28 29184 ----a-w- c:\windows\system32\wsepno.dll
2009-08-29 09:06 . 2009-04-11 06:28 247808 ----a-w- c:\windows\system32\drvstore.dll
2009-08-29 08:46 . 2009-06-22 10:09 2048 ----a-w- c:\windows\system32\tzres.dll
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-17 15:02 . 2009-06-19 09:43 17408 ----a-w- c:\windows\system32\rpcnetp.exe
2009-09-16 20:52 . 2008-04-17 09:47 662380 ----a-w- c:\windows\system32\perfh015.dat
2009-09-16 20:52 . 2008-04-17 09:47 127248 ----a-w- c:\windows\system32\perfc015.dat
2009-09-16 20:46 . 2009-06-19 09:50 56680 ----a-w- c:\windows\system32\rpcnet.dll
2009-09-16 20:45 . 2009-05-11 23:48 1076 ----a-w- c:\windows\bthservsdp.dat
2009-09-16 20:45 . 2009-06-18 20:42 -------- d-----w- c:\users\terg\AppData\Roaming\uTorrent
2009-09-16 20:05 . 2009-07-22 20:42 -------- d-----w- c:\users\terg\AppData\Roaming\vlc
2009-09-16 17:01 . 2009-07-04 21:23 -------- d-----w- c:\users\terg\AppData\Roaming\dvdcss
2009-09-13 22:06 . 2009-06-20 00:05 680 ----a-w- c:\users\terg\AppData\Local\d3d9caps.dat
2009-09-13 13:15 . 2009-05-11 23:33 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-12 23:28 . 2009-05-11 23:33 -------- d-----w- c:\program files\Common Files\InstallShield
2009-09-12 17:38 . 2009-06-19 21:57 -------- d-----w- c:\users\terg\AppData\Roaming\Skype
2009-09-12 15:17 . 2009-06-19 22:03 -------- d-----w- c:\users\terg\AppData\Roaming\skypePM
2009-09-11 16:32 . 2009-06-18 15:25 -------- d-----w- c:\users\terg\AppData\Roaming\Apple Computer
2009-09-11 15:29 . 2009-06-18 15:25 -------- d-----w- c:\program files\iTunes
2009-09-11 15:29 . 2009-06-18 15:23 -------- d-----w- c:\program files\Common Files\Apple
2009-09-10 04:46 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-09-10 04:45 . 2009-05-11 23:22 -------- d-----w- c:\programdata\Microsoft Help
2009-09-05 14:46 . 2009-05-11 23:35 -------- d-----w- c:\programdata\CyberLink
2009-09-05 14:39 . 2009-07-02 14:52 -------- d-----w- c:\users\terg\AppData\Roaming\CyberLink
2009-09-03 20:36 . 2009-08-01 08:34 -------- d-----w- c:\program files\Nowe Gadu-Gadu
2009-08-30 19:15 . 2009-05-11 23:13 17408 ----a-w- c:\windows\system32\rpcnetp.dll
2009-08-30 19:12 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Calendar
2009-08-30 19:12 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Sidebar
2009-08-30 19:12 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Collaboration
2009-08-30 19:12 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Photo Gallery
2009-08-30 19:12 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Defender
2009-08-20 21:55 . 2009-06-15 16:44 -------- d-----w- c:\program files\Common Files\Adobe
2009-08-14 16:27 . 2009-09-09 17:54 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-08-14 15:53 . 2009-09-09 17:54 17920 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 13:49 . 2009-09-09 17:54 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 13:49 . 2009-09-09 17:54 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 13:49 . 2009-09-09 17:54 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 13:49 . 2009-09-09 17:54 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 13:49 . 2009-09-09 17:54 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 13:49 . 2009-09-09 17:54 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 13:49 . 2009-09-09 17:54 10240 ----a-w- c:\windows\system32\finger.exe
2009-08-14 13:48 . 2009-09-09 17:54 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2009-08-14 13:48 . 2009-09-09 17:54 105984 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-07 17:51 . 2009-08-07 17:51 15308424 ----a-w- c:\windows\system32\xlive.dll
2009-08-07 17:51 . 2009-08-07 17:51 13642888 ----a-w- c:\windows\system32\xlivefnt.dll
2009-08-04 19:20 . 2009-08-04 19:20 -------- d-----w- c:\program files\DivX
2009-08-04 19:20 . 2009-08-04 19:20 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-08-02 16:12 . 2009-08-02 16:12 -------- d-----w- c:\users\terg\AppData\Roaming\VistaCodecs
2009-08-02 16:12 . 2009-08-02 16:11 -------- d-----w- c:\program files\VistaCodecPack
2009-08-02 16:12 . 2009-08-02 16:11 -------- d-----w- c:\programdata\VistaCodecs
2009-08-01 12:10 . 2009-08-01 08:34 -------- d-----w- c:\users\terg\AppData\Roaming\Nowe Gadu-Gadu
2009-08-01 08:41 . 2009-08-01 08:39 -------- d-----w- c:\programdata\OpenFM
2009-08-01 08:39 . 2009-08-01 08:39 -------- d-----w- c:\users\terg\AppData\Roaming\OpenFM
2009-07-31 20:15 . 2009-07-31 20:15 -------- d-----w- c:\users\terg\AppData\Roaming\Ashampoo
2009-07-31 20:14 . 2009-07-31 20:14 -------- d-----w- c:\programdata\ashampoo
2009-07-31 20:14 . 2009-07-31 20:14 -------- d-----w- c:\program files\Ashampoo
2009-07-31 20:11 . 2009-07-31 20:11 -------- d-----w- c:\users\terg\AppData\Roaming\Ahead
2009-07-31 20:05 . 2009-07-31 20:05 -------- d-----w- c:\program files\Common Files\Ahead
2009-07-31 20:05 . 2009-07-31 20:05 -------- d-----w- c:\program files\Nero
2009-07-31 19:37 . 2009-07-31 19:37 -------- d-----w- c:\programdata\ASUS
2009-07-21 21:52 . 2009-07-29 10:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-07-29 10:00 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-07-29 10:00 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-07-29 10:00 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-17 13:54 . 2009-08-12 04:34 71680 ----a-w- c:\windows\system32\atl.dll
2009-07-16 13:20 . 2009-07-16 13:20 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2009-07-15 12:40 . 2009-08-12 04:34 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-07-15 12:39 . 2009-08-12 04:34 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-15 12:39 . 2009-08-12 04:34 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-07-15 12:39 . 2009-08-12 04:34 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-07-11 19:01 . 2009-09-09 17:54 302592 ----a-w- c:\windows\system32\wlansec.dll
2009-07-11 19:01 . 2009-09-09 17:54 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2009-07-11 19:01 . 2009-09-09 17:54 513536 ----a-w- c:\windows\system32\wlansvc.dll
2009-07-11 19:01 . 2009-09-09 17:54 65024 ----a-w- c:\windows\system32\wlanapi.dll
2009-07-11 17:03 . 2009-09-09 17:54 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2009-07-11 14:31 . 2009-07-11 14:31 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-07-06 10:21 . 2009-07-06 10:21 1003520 ----a-w- c:\windows\system32\VSFilter.dll
2009-06-21 16:43 . 2009-06-20 12:17 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-06-21 12:47 . 2009-06-15 16:43 99864 ----a-w- c:\users\terg\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-19 22:03 . 2009-06-19 22:03 56 ---ha-w- c:\programdata\ezsidmv.dat
2009-04-08 17:31 . 2009-04-08 17:31 106496 ----a-w- c:\program files\Common Files\CPInstallAction.dll
2008-05-22 15:35 . 2008-05-22 15:35 51962 ----a-w- c:\program files\Common Files\banner.jpg
2007-06-12 16:34 . 2007-06-12 16:34 35822 ----a-w- c:\program files\Common Files\ASPG_icon.ico
2009-05-11 23:40 . 2009-05-11 23:40 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2009-04-02 10:47 333192 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-02 00:08 143360 ----a-w- c:\program files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-11 39408]
"Google Update"="c:\users\terg\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-06-18 133104]
"AQQ"="c:\progra~1\WapSter\WAPSTE~1\AQQ.exe" [2009-07-22 4777472]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"AdobeBridge"="c:\program files\Adobe\Adobe Bridge CS4\Bridge.exe" [2008-08-28 13145448]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"WindowsWelcomeCenter"="oobefldr.dll" - c:\windows\System32\oobefldr.dll [2009-04-11 2153472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"RemoteControl"="c:\program files\ASUSTek\ASUSDVD\PDVDServ.exe" [2008-12-12 87336]
"LanguageShortcut"="c:\program files\ASUSTek\ASUSDVD\Language\Language.exe" [2008-12-19 62760]
"CLMLServer"="c:\program files\CyberLink\Power2Go\CLMLSvc.exe" [2008-07-19 104936]
"P2Go_Menu"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"SmartAudio"="c:\program files\CONEXANT\SMARTAUDIO\SMAUDIO.EXE" [2009-02-26 2742840]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-03-05 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-03-05 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-03-05 150552]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-03-30 424864]
"HControlUser"="c:\program files\ASUS\ATK Hotkey\HControlUser.exe" [2008-08-18 98304]
"ATKOSD2"="c:\program files\ASUS\ATKOSD2\ATKOSD2.exe" [2009-03-04 8392704]
"ATKMEDIA"="c:\program files\ASUS\ATK Media\DMedia.exe" [2009-03-27 159744]
"ADSMTray"="c:\program files\ASUS\ASUS Data Security Manager\ADSMTray.exe" [2008-04-01 266240]
"ACMON"="c:\program files\ASUS\Splendid\ACMON.exe" [2008-10-01 851968]
"Wireless Console 3"="c:\program files\ASUS\Wireless Console 3\wcourier.exe" [2009-02-06 1593344]
"ASUS Camera ScreenSaver"="c:\windows\AsScrProlog.exe" [2009-05-12 47672]
"fssui"="c:\program files\Windows Live\Family Safety\fsui.exe" [2009-02-06 454000]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-11 148888]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-04 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-08 305440]
c:\users\terg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartupYahoo! Widgets.lnk - c:\program files\Yahoo!\Widgets\YahooWidgets.exe [2008-3-19 4742184]
c:\programdata\Microsoft\Windows\Start Menu\Programs\StartupBluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-7-30 752168]
FancyStart daemon.lnk - c:\windows\Installer\{F9F20920-313D-4D6F-866B-2737B77E1857}\_DC60F4E342E06843E7FCD0.exe [2009-5-12 12862]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):55,ae,12,94,a6,29,ca,01
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{E0645264-E687-4732-B811-DDD2F971A93B}"= c:\program files\ASUSTek\ASUSDVD\PowerDVD.EXE:CyberLink PowerDVD
"{808148C4-486E-4ACE-A911-4A753FAC1734}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{C13C0739-CD55-4295-9497-CF0EAC016D3B}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{FBAC000C-8B16-4140-8386-AD916DE849CB}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{C177CD1A-D2D4-481C-B65E-A834A3C95440}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{6F8FFEEB-DAB2-43F1-9CB0-0422B2147395}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{F55A9907-FFCD-4856-A900-03A070A6A422}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"{8260BED6-AEA1-4CA9-BC5A-D4E333BC76DD}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{5AC67912-671C-4BD2-B86A-83FD653BDD3D}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"TCP Query User{A6A3FDE7-DAC6-4181-9472-6787DA8386EB}c:\\program files\\wapster\\wapster aqq\\aqq.exe"= UDP:c:\program files\wapster\wapster aqq\aqq.exe:AQQ
"UDP Query User{88C5C5FC-76F5-4216-9CE9-692B1C2A54C2}c:\\program files\\wapster\\wapster aqq\\aqq.exe"= TCP:c:\program files\wapster\wapster aqq\aqq.exe:AQQ
"{7D5EDD49-A7C4-49CF-A980-9A6D18708CD5}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"{FFFEECF7-B5A1-4D5B-9172-6D9D5AEF5F14}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{03BE16CA-A5C0-4971-A3CE-98859C7BAC1B}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{E7264AAA-E124-44F6-A50A-A170816978AE}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{2B5B31D8-1F4F-4BBD-BE3C-81D649AE718B}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{2B28EF6C-B575-4AA7-8FB8-6EA6A7365E03}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{F82818CE-5C94-4007-8C94-505A989FD3CA}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{F935C5BD-ED3D-4A90-B372-5720B9EA0E7E}"= UDP:5353:Adobe CSI CS4
"{F29CD37D-1A6D-44C2-868C-CC2670E03902}"= UDP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{256D459C-4669-4BAD-A60B-51C17C0252CC}"= TCP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"TCP Query User{B01D5A3E-6068-4FD8-ACCD-5AF7312B402A}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:µTorrent
"UDP Query User{47DE35DF-74A3-4AD5-9796-08C6A16C9BE7}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:µTorrent
"TCP Query User{2E480657-B6AC-4C93-BB3A-EAC0492C5158}c:\\program files\\wapster\\wapster aqq\\aqq.exe"= UDP:c:\program files\wapster\wapster aqq\aqq.exe:AQQ Instant Messenger
"UDP Query User{7612FE76-67EB-4B10-8B85-7F2E5037A0ED}c:\\program files\\wapster\\wapster aqq\\aqq.exe"= TCP:c:\program files\wapster\wapster aqq\aqq.exe:AQQ Instant Messenger
"TCP Query User{29EDA382-784E-4569-A809-E9AD7736AA5C}c:\\program files\\videolan\\vlc\\vlc.exe"= UDP:c:\program files\videolan\vlc\vlc.exe:VLC media player
"UDP Query User{06896A41-60D8-4EB2-BC4B-56E816FCD872}c:\\program files\\videolan\\vlc\\vlc.exe"= TCP:c:\program files\videolan\vlc\vlc.exe:VLC media player
"TCP Query User{A3D1B279-E21D-474F-93EE-928A2F39DDC8}c:\\users\\terg\\appdata\\local\\google\\chrome\\application\\chrome.exe"= UDP:c:\users\terg\appdata\local\google\chrome\application\chrome.exe:chrome.exe
"UDP Query User{787C8560-9D2F-430D-9DA2-3F93CFBECFFD}c:\\users\\terg\\appdata\\local\\google\\chrome\\application\\chrome.exe"= TCP:c:\users\terg\appdata\local\google\chrome\application\chrome.exe:chrome.exe
"TCP Query User{BCEB784E-DAB4-42FE-8B60-94866F4391A1}c:\\program files\\nowe gadu-gadu\\gg.exe"= UDP:c:\program files\nowe gadu-gadu\gg.exe:Nowe Gadu-Gadu
"UDP Query User{2397F163-CDA6-44F3-8953-C5966D6981AC}c:\\program files\\nowe gadu-gadu\\gg.exe"= TCP:c:\program files\nowe gadu-gadu\gg.exe:Nowe Gadu-Gadu
"TCP Query User{E183C7C2-FE06-4EE7-8493-4CDC3E69468A}c:\\program files\\nowe gadu-gadu\\gg.exe"= UDP:c:\program files\nowe gadu-gadu\gg.exe:Nowe Gadu-Gadu
"UDP Query User{E74A2344-692F-4904-9A31-7735A4A00673}c:\\program files\\nowe gadu-gadu\\gg.exe"= TCP:c:\program files\nowe gadu-gadu\gg.exe:Nowe Gadu-Gadu
"TCP Query User{488F5A4C-B787-42F9-996D-72F998233C27}d:\\games\\stepmania cvs\\program\\stepmania.exe"= UDP:d:\games\stepmania cvs\program\stepmania.exe:StepMania
"UDP Query User{43C29D33-BC8B-4643-B1C9-466A03F14528}d:\\games\\stepmania cvs\\program\\stepmania.exe"= TCP:d:\games\stepmania cvs\program\stepmania.exe:StepMania
"TCP Query User{5CCE9536-A23D-4F5E-AD6D-450A5FAF9381}c:\\users\\terg\\appdata\\local\\google\\chrome\\application\\chrome.exe"= UDP:c:\users\terg\appdata\local\google\chrome\application\chrome.exe:chrome.exe
"UDP Query User{60AA9A24-565A-49BF-860A-5D562533BDEE}c:\\users\\terg\\appdata\\local\\google\\chrome\\application\\chrome.exe"= TCP:c:\users\terg\appdata\local\google\chrome\application\chrome.exe:chrome.exe
"{C2CAD410-342F-4671-AD6A-2A21463A9B87}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{2C95CC2B-DDAF-4E10-8146-2C59D27631B5}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
R0 lullaby;lullaby;c:\windows\System32\drivers\lullaby.sys [2009-05-12 15416]
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [2009-09-08 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [2009-09-08 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [2009-09-08 53328]
R2 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [2009-06-15 55264]
R2 fsssvc;Bezpieczeństwo rodzinne usługi Windows Live;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-09-11 1153368]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\System32\drivers\btwl2cap.sys [2009-05-12 29736]
R3 ETD;ELAN PS/2 Port Input Device;c:\windows\System32\drivers\ETD.sys [2009-03-30 129536]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\System32\drivers\IntcHdmi.sys [2008-09-21 112128]
R3 SRS_PremiumSound_Service;SRS Labs Premium Sound;c:\windows\System32\drivers\SRS_PremiumSound_i386.sys [2009-05-12 233128]
S2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [2009-06-18 234888]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Zawartość folderu 'Zaplanowane zadania'
2009-09-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1902306930-607540321-198858816-1000Core.job
- c:\users\terg\AppData\Local\Google\Update\GoogleUpdate.exe [2009-06-18 20:37]
2009-09-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1902306930-607540321-198858816-1000UA.job
- c:\users\terg\AppData\Local\Google\Update\GoogleUpdate.exe [2009-06-18 20:37]
.
.
------- Skan uzupełniający -------
.
mStart Page = hxxp://www.yahoo.com
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
- - - - USUNIĘTO PUSTE WPISY - - - -
HKCU-Run-EA Core - c:\program files\Electronic Arts\EADM\Core.exe
AddRemove-ShockwaveFlash - c:\windows\system32\Macromed\Flash\UninstFl.exe
**************************************************************************
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki:
**************************************************************************
.
--------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
- - - - - - - > 'Explorer.exe'(1540)
c:\program files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt.dll
c:\program files\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\windows\System32\audiodg.exe
c:\program files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
c:\program files\ASUS\ATK Hotkey\AsLdrSrv.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\ATKGFNEX\GFNEXSrv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\System32\wlanext.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\System32\rpcnet.exe
c:\windows\System32\WUDFHost.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\Windows Defender\MpCmdRun.exe
c:\windows\servicing\TrustedInstaller.exe
c:\program files\ASUS\ASUS CopyProtect\ASPG.exe
c:\program files\ASUS\AI Recovery\AIRecoveryRemind.exe
c:\program files\ASUS\SmartLogon\sensorsrv.exe
c:\program files\P4G\BatteryLife.exe
c:\program files\ASUS\ATK Hotkey\MsgTranAgt.exe
c:\program files\ASUS\ATK Hotkey\HControl.exe
c:\program files\ASUS\ATK Hotkey\ATKOSD.exe
c:\program files\ASUS\ATK Hotkey\KBFiltr.exe
c:\program files\ASUS\ATK Hotkey\WDC.exe
c:\windows\System32\ACEngSvr.exe
c:\windows\System32\igfxsrvc.exe
c:\windows\System32\VSSVC.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Czas ukończenia: 2009-09-17 17:08 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2009-09-17 15:08
Przed: 18 530 222 080 bajtów wolnych
Po: 18 240 237 568 bajtów wolnych
337 --- E O F --- 2009-09-17 15:05
Po pierwsze - czy Twój system jest legalny, czy aktywowany inaczej ?
Jeśli nie jest legalny - to właśnie masz przed sobą jedną z wielu możliwości ograniczenie funkcjonalności pirata przez MS.
Jeśli jest legalny - to przyczyn należy jak słusznie się domyśliłeś szukać po stronie infekcji. Tyle że nie wirusowej, lecz np. trojana albo co jeszcze bardziej prawdopodobne - rootkita. Aby go wykluczyć - należy przetestować system combofixem (a jeśli nie umiesz czytać jego logów - to wklej je tutaj).
Po trzecie - jeśli combofix nic nie wykryje - to sprawdź czy przypadkiem w Windows/system32 nie masz pliku activexdebugger32.exe - jesli masz - to postępuj zgodnie z instrukcją opisaną [url=http://xforum.pl/index.php?s=2b8e202e4e96290aee2cb7b14b5d017c&showtopic=5319&st=0&p=78495entry78495]tutaj[/url].
Powyższe punkty raczej nie pomogą w przypadku blokady funkcjonalności uruchomionej przez MS ...
sugeruje ze dotyczy foto galerii ale robię wszelskie scany i nic. nawet w rejestrze jest czysto
tak wyglada okno ktore mnie denerwuje :)
[URL=http://img406.imageshack.us/i/bladr.jpg/][IMG]http://img406.imageshack.us/img406/3462/bladr.jpg[/IMG][/URL]
Czarny ekran powiadasz...
Treść błędu nic nie sugeruje?
Strona 1 / 1