mam problem. kiedy probuje zainstalowac jakąś starszą grę (Oni, Zeus, Original War) przez klikniecie w Setup.exe czy z autoruna komputer bezczelnie nic nie robi, a po jakims czasie wyskakuje blad wowexec.exe z komunikatem o 16 bitowej wersji programu… Zmienilam juz chyba wszystkie sterowniki, a tu lipa- nie dziala dalej.
Config:
Athlon 2000+ 1,7 GHz
Radeon 9550 128MB/128bit
RAM Kingston 512
Windows XP Professional
80GB na HDD, 10GB wolnych.
Logi z ComboScana:
ComboScan v20070306.20 run by Anka on 2007-06-04 at 17:07:57
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- HijackThis (run as Anka.exe) ------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 17:07:59, on 2007-06-04
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\Setup\svchost.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Documents and Settings\Anka\Pulpit\comboscan.exe
C:\DOCUME~1\Anka\Pulpit\Anka.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [svchost] C:\Program Files\Internet Explorer\Setup\svchost.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKCU\..\Run: [VS Online] "C:\Program Files\VS Online\VSOnline.exe" /tray
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {92ECE6FA-AC2E-4042-BFAE-0C8608E52A43} (SignActivX Control) - https://www.bph.pl/pi/components/SignActivX.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
-- Files created between 2007-05-04 and 2007-06-04 -----------------------------
2007-06-03 17:04:58 0 d-------- C:\Program Files\Common Files\Corel
2007-06-02 21:08:42 0 d-------- C:\Program Files\VS Online
2007-06-02 10:37:35 0 d-------- C:\Program Files\Artmoney
2007-06-01 18:49:33 1818 --a------ C:\WINDOWS\system32\tmp.reg
2007-06-01 18:49:06 79360 --a------ C:\WINDOWS\system32\swxcacls.exe
2007-06-01 18:49:06 40960 --a------ C:\WINDOWS\system32\swsc.exe
2007-06-01 18:49:06 135168 --a------ C:\WINDOWS\system32\swreg.exe
2007-06-01 18:49:06 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-06-01 18:49:06 51200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-05-31 08:47:46 0 d-------- C:\Program Files\Common Files\COWON
2007-05-31 08:47:45 0 d-------- C:\Program Files\JetAudio
2007-05-20 14:40:42 0 d-------- C:\Program Files\Napisy
2007-05-19 23:51:58 62744 --a------ C:\WINDOWS\system32\xinput1_2.dll
2007-05-19 23:51:58 236824 --a------ C:\WINDOWS\system32\xactengine2_3.dll
2007-05-19 23:21:32 0 d-------- C:\Program Files\Activision
2007-05-19 22:56:30 0 d-------- C:\Program Files\DAEMON Tools
2007-05-14 20:20:11 0 d-------- C:\Program Files\Combined Community Codec Pack
2007-05-14 20:11:53 0 d-------- C:\Program Files\Matroska Pack
2007-05-11 08:36:06 0 d-------- C:\Program Files\Truck Dismount
2007-05-08 18:27:37 3350 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2007-05-08 18:27:37 88 -r-hs---- C:\WINDOWS\system32\2BBDBB046B.sys<2BBDBB~1.SYS>
2007-05-08 18:25:25 0 d-------- C:\Program Files\Corel
-- Find3M Report ---------------------------------------------------------------
2007-06-02 13:03:44 91 --a------ C:\WINDOWS\system32\imon1.dat
2007-05-31 08:48:42 0 d-------- C:\Documents and Settings\Anka\Dane aplikacji\COWON
2007-05-29 19:07:20 0 d-------- C:\Documents and Settings\Anka\Dane aplikacji\Corel Portable
2007-05-29 17:59:36 852 --a------ C:\Documents and Settings\Anka\Dane aplikacji\Color.ini
2007-05-29 17:56:40 0 d-------- C:\Documents and Settings\Anka\Dane aplikacji\CorelDRAW11
2007-05-29 17:56:36 0 d-------- C:\Documents and Settings\Anka\Dane aplikacji\PaperTypes
2007-05-20 10:37:14 0 d-------- C:\Documents and Settings\Anka\Dane aplikacji\Activision
2007-05-11 19:35:34 98304 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2007-05-11 13:50:08 144384 --a------ C:\WINDOWS\system32\miccyhook.dll
2007-05-08 18:27:38 0 d-------- C:\Documents and Settings\Anka\Dane aplikacji\Corel
2007-05-03 21:05:40 0 d-------- C:\Program Files\The Thing
2007-04-27 07:48:36 457678 --a------ C:\WINDOWS\system32\perfh015.dat
2007-04-27 07:48:36 79188 --a------ C:\WINDOWS\system32\perfc015.dat
2007-04-19 14:51:10 0 d-------- C:\Program Files\DirectX
2007-04-18 18:14:32 2854400 --a------ C:\WINDOWS\system32\msi.dll
2007-04-17 18:33:38 0 d-------- C:\Program Files\Gimnazjum_testy_2007
2007-04-16 16:12:54 0 d-------- C:\Documents and Settings\Anka\Dane aplikacji\SecondLife
2007-04-16 16:12:20 0 d-------- C:\Program Files\SecondLife
2007-04-12 14:36:04 80980 --a------ C:\WINDOWS\Uninstall Jade Empire.exe
2007-04-01 13:21:54 35363 --a------ C:\WINDOWS\system32\windrvNT.sys
2007-03-27 18:08:16 298104 --a------ C:\WINDOWS\system32\imon.dll
2007-03-27 17:25:46 25992 --a------ C:\WINDOWS\system32\pgdfgsvc.exe
2007-03-22 21:05:00 520192 -----n--- C:\WINDOWS\system32\ati2sgag.exe
2007-03-21 21:41:40 35183 --a------ C:\WINDOWS\DIIUnin.dat
2007-03-21 21:38:46 21840 --a------ C:\WINDOWS\system32\SIntfNT.dll
2007-03-21 21:38:46 17212 --a------ C:\WINDOWS\system32\SIntf32.dll
2007-03-21 21:38:46 12067 --a------ C:\WINDOWS\system32\SIntf16.dll
2007-03-21 21:30:04 2829 --a------ C:\WINDOWS\DIIUnin.pif
2007-03-21 21:30:04 106496 --a------ C:\WINDOWS\DIIUnin.exe
2007-03-17 15:45:36 293376 --a------ C:\WINDOWS\system32\winsrv.dll
2007-03-15 03:58:38 315392 --a------ C:\WINDOWS\system32\ATIDEMGX.dll
2007-03-15 03:57:36 267776 --a------ C:\WINDOWS\system32\ati2dvag.dll
2007-03-15 03:55:38 307200 --a------ C:\WINDOWS\system32\atiiiexx.dll
2007-03-15 03:50:40 122880 --a------ C:\WINDOWS\system32\atipdlxx.dll
2007-03-15 03:50:28 114688 --a------ C:\WINDOWS\system32\Oemdspif.dll
2007-03-15 03:50:20 26112 --a------ C:\WINDOWS\system32\Ati2mdxx.exe
2007-03-15 03:50:14 42496 --a------ C:\WINDOWS\system32\ati2edxx.dll
2007-03-15 03:50:00 114688 --a------ C:\WINDOWS\system32\ati2evxx.dll
2007-03-15 03:48:40 450560 --a------ C:\WINDOWS\system32\ati2evxx.exe
2007-03-15 03:47:54 53248 --a------ C:\WINDOWS\system32\ATIDDC.DLL
2007-03-15 03:40:12 2820544 --a------ C:\WINDOWS\system32\ati3duag.dll
2007-03-15 03:29:48 1315712 --a------ C:\WINDOWS\system32\ativvaxx.dll
2007-03-15 03:19:34 5402624 --a------ C:\WINDOWS\system32\atioglxx.dll
2007-03-15 03:16:16 258048 --a------ C:\WINDOWS\system32\atikvmag.dll
2007-03-15 03:14:44 17408 --a------ C:\WINDOWS\system32\atitvo32.dll
2007-03-15 03:10:30 356352 --a------ C:\WINDOWS\system32\ati2cqag.dll
2007-03-09 18:36:42 83 ---hs---- C:\Documents and Settings\Anka\Dane aplikacji\.zreglib
2007-03-08 17:38:48 579072 --a------ C:\WINDOWS\system32\user32.dll
2007-03-08 17:38:48 40960 --a------ C:\WINDOWS\system32\mf3216.dll
2007-03-08 17:38:48 281600 --a------ C:\WINDOWS\system32\gdi32.dll
2007-03-08 17:37:34 1843840 --a------ C:\WINDOWS\system32\win32k.sys
2007-03-07 00:04:54 143676 --a------ C:\WINDOWS\system32\atiicdxx.dat
2007-03-04 21:52:28 729088 --a------ C:\WINDOWS\iun6002.exe
-- Registry Dump ---------------------------------------------------------------
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"VS Online"="\"C:\\Program Files\\VS Online\\VSOnline.exe\" /tray"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"svchost"="C:\\Program Files\\Internet Explorer\\Setup\\svchost.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_01\\bin\\jusched.exe\""
"ISUSPM Startup"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\ISUSPM.exe\" -startup"
"ISUSScheduler"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Speed Launch.lnk]
"path"="C:\\Documents and Settings\\All Users\\Menu Start\\Programy\\Autostart\\Adobe Reader Speed Launch.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~1.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="cli"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime -Delay"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ccApp"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CloneCDTray"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\SlySoft\\CloneCD\\CloneCDTray.exe\" /s"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ctfmon"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\system32\\ctfmon.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="daemon"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\D-Tools\\daemon.exe\" -lang 1033"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NBJ"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Ahead\\Nero BackItUp\\NBJ.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NeroCheck"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nod32kui]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="nod32kui"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Eset\\nod32kui.exe\" /WAITSERVICE"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Rapget]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="rapget"
"hkey"="HKLM"
"command"="C:\\Documents and Settings\\Anka\\Pulpit\\rapget.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SOUNDMAN"
"hkey"="HKLM"
"command"="SOUNDMAN.EXE"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SNDMon"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Consumer"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SNDSrvc"=dword:00000002
"Pml Driver HPZ12"=dword:00000003
"LiveUpdate"=dword:00000003
"LightScribeService"=dword:00000002
"IDriverT"=dword:00000003
"ewido anti-spyware 4.0 guard"=dword:00000002
"Diskeeper"=dword:00000002
"Automatic LiveUpdate Scheduler"=dword:00000002
"ATI Smart"=dword:00000002
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=dword:00000000
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{26f2c958-e1f1-11db-a923-806d6172696f}]
Shell\AutoRun\command E:\autorun.exe
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8ba08fbf-b3aa-11da-8fea-806d6172696f}]
Shell\AutoRun\command E:\autorun.exe
-- End of ComboScan: finished at 2007-06-04 at 17:08:25 ------------------------