u mnie ten sam problem. Przy starcie systemu avast znajduje virusa, ale kwarantanna nic nie daje. Dodaje loga z ComboFix.
ComboFix 08-02-24.4 - Joasia 2008-02-24 17:00:01.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.103 [GMT 1:00]
Running from: C:\Documents and Settings\Joasia\Pulpit\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\myglobalsearch
C:\Program Files\myglobalsearch\bar\1.bin\M9FFXTBR.JAR
C:\Program Files\myglobalsearch\bar\1.bin\M9FFXTBR.MANIFEST
C:\Program Files\myglobalsearch\bar\1.bin\M9NTSTBR.JAR
C:\Program Files\myglobalsearch\bar\1.bin\M9NTSTBR.MANIFEST
C:\Program Files\myglobalsearch\bar\1.bin\M9PLUGIN.DLL
C:\Program Files\myglobalsearch\bar\1.bin\MGSBAR.DLL
C:\Program Files\myglobalsearch\bar\1.bin\NPMYGLSH.DLL
C:\Program Files\myglobalsearch\bar\Cache\00163D2D
C:\Program Files\myglobalsearch\bar\Cache\00164115
C:\Program Files\myglobalsearch\bar\Cache\0016448F.bin
C:\Program Files\myglobalsearch\bar\Cache\001647EB.bin
C:\Program Files\myglobalsearch\bar\Cache\00164AAA.bin
C:\Program Files\myglobalsearch\bar\Cache\files.ini
C:\Program Files\myglobalsearch\bar\History\search
C:\Program Files\myglobalsearch\bar\Settings\prevcfg.htm
C:\WINDOWS\system32\hqghumea.dll
.
((((((((((((((((((((((((( Files Created from 2008-01-24 to 2008-02-24 )))))))))))))))))))))))))))))))
.
2008-02-24 12:12 . 2008-02-24 12:12 118 --a------ C:\WINDOWS\system32\MRT.INI
2008-02-24 11:21 . 2006-08-21 10:14 128,896 -----c— C:\WINDOWS\system32\dllcache\fltmgr.sys
2008-02-24 11:21 . 2006-08-21 10:14 23,040 -----c— C:\WINDOWS\system32\dllcache\fltmc.exe
2008-02-24 11:21 . 2006-08-21 13:28 16,896 -----c— C:\WINDOWS\system32\dllcache\fltlib.dll
2008-02-24 11:16 . 2008-02-24 11:16
2008-02-23 20:10 . 2008-02-23 20:10 32 --a------ C:\Documents and Settings\All Users\Dane aplikacji\ezsid.dat
2008-02-23 20:09 . 2008-02-24 16:09
2008-02-23 13:13 . 2007-07-09 14:11 584,192 -----c— C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-02-22 20:53 . 2008-02-24 11:32
2008-02-22 14:50 . 2008-02-22 14:50 0 --a------ C:\WINDOWS\nsreg.dat
2008-02-22 14:11 . 2008-02-22 14:11
2008-02-22 14:10 . 2008-02-22 14:10
2008-02-22 14:01 . 2004-08-04 00:44 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-02-22 13:54 . 2008-02-22 13:54
2008-02-22 13:48 . 2004-07-17 11:40 19,528 --a------ C:\WINDOWS\002344_.tmp
2008-02-22 13:47 . 2005-06-28 10:21 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-02-22 13:43 . 2008-02-22 13:59
2008-02-22 08:17 . 2008-02-22 08:17
2008-02-22 08:17 . 2008-02-22 08:17
2008-02-22 08:17 . 2008-02-22 08:17
2008-02-22 08:17 . 2008-02-22 08:17
2008-02-22 08:17 . 2008-02-22 14:12 316,640 --a------ C:\WINDOWS\WMSysPr9.prx
2008-02-22 08:09 . 2008-02-24 12:28
2008-02-22 08:08 . 2008-02-24 16:59
2008-02-22 08:08 . 2008-02-22 08:08
2008-02-22 08:07 . 2008-02-22 08:07
2008-02-22 08:07 . 2008-02-22 08:07
2008-02-22 08:07 . 2008-02-22 08:07
2008-02-22 08:05 . 2008-02-23 15:47
2008-02-21 19:41 . 2003-09-24 09:43 626,960 -ra------ C:\WINDOWS\system32\hpvaut32.dll
2008-02-21 19:41 . 2003-09-24 09:43 487,424 -ra------ C:\WINDOWS\system32\hpvcp70.dll
2008-02-21 19:41 . 2003-09-24 09:43 344,064 -ra------ C:\WINDOWS\system32\hpvcr70.dll
2008-02-21 19:41 . 2003-09-24 09:44 82,432 -ra------ C:\WINDOWS\system32\MSXML4r.dll
2008-02-21 19:41 . 2003-09-24 09:44 44,544 -ra------ C:\WINDOWS\system32\MSXML4a.dll
2008-02-21 18:23 . 2008-02-21 18:23 82,380 --a------ C:\WINDOWS\system32\drivers\AFS2K.SYS
2008-02-21 18:10 . 2008-02-21 18:10
2008-02-21 18:09 . 2008-02-21 18:08 350,814 --a------ C:\WINDOWS\hpdj5100.hi1
2008-02-21 18:09 . 2008-02-21 18:08 10,555 --a------ C:\WINDOWS\hpdj5100.bu1
2008-02-21 17:57 . 1998-10-07 12:54 327,168 --a------ C:\WINDOWS\IsUn0415.exe
2008-02-21 17:56 . 2008-02-21 18:23
2008-02-21 17:54 . 2008-02-21 18:24 366,570 --a------ C:\WINDOWS\hpdj5100.his
2008-02-21 17:54 . 2008-02-21 18:24 11,667 --a------ C:\WINDOWS\hpdj5100.ini
2008-02-20 18:59 . 2008-02-20 18:59 427 --a------ C:\WINDOWS\ODBC.INI
2008-02-20 18:56 . 2008-02-20 18:56
2008-02-20 18:54 . 2008-02-20 18:54
2008-02-20 18:45 . 2008-02-20 18:45
2008-02-20 16:47 . 2008-02-20 16:47
2008-02-20 16:47 . 2008-02-20 16:47
2008-02-20 16:04 . 2008-02-20 16:04
2008-02-20 15:02 . 2008-02-20 15:05 850,944 -ra------ C:\WINDOWS\system32\runsvc.exe
2008-02-20 14:51 . 2008-02-20 15:02 65 --a------ C:\WINDOWS\system32\x
2008-02-20 14:23 . 2002-12-09 18:24 49,152 --a------ C:\WINDOWS\system32\WooDial2000.dll
2008-02-20 14:23 . 2002-12-09 18:24 48,128 --a------ C:\WINDOWS\system32\SMMSCRPT.DLL
2008-02-20 14:23 . 2002-12-09 18:24 5,632 --a------ C:\WINDOWS\system32\SMMSETUP.DLL
2008-02-20 14:22 . 2008-02-20 14:22
2008-02-20 14:22 . 2003-01-30 09:48 143,360 --a------ C:\WINDOWS\autoclk.exe
2008-02-20 14:22 . 2002-02-21 09:19 45,148 --a------ C:\WINDOWS\system32\plugincpl131_03.cpl
2008-02-20 14:21 . 2008-02-24 16:58
2008-02-20 14:21 . 2003-03-04 10:26 9,728 --a------ C:\WINDOWS\system32\rnaph.dll
2008-02-20 14:13 . 2008-02-20 14:13 489 --a------ C:\WINDOWS\demo.INI
2008-02-20 14:11 . 2008-02-20 16:04
2008-02-20 14:11 . 2008-02-20 14:11
2008-02-20 14:11 . 2001-11-26 08:05 243,164 -ra------ C:\WINDOWS\system32\drivers\ALCXWDM.SYS
2008-02-20 14:11 . 2001-06-28 02:21 217,088 -ra------ C:\WINDOWS\alcupd.exe
2008-02-20 14:11 . 2001-06-13 04:49 151,552 -ra------ C:\WINDOWS\alcrmv.exe
2008-02-20 14:11 . 2004-08-03 23:15 145,792 --a------ C:\WINDOWS\system32\drivers\portcls.sys
2008-02-20 14:11 . 2001-05-29 10:02 124,416 -ra------ C:\WINDOWS\soundman.exe
2008-02-20 14:11 . 2004-08-03 23:08 60,288 --a------ C:\WINDOWS\system32\drivers\drmk.sys
2008-02-20 14:11 . 2001-10-18 05:00 6,144 -ra------ C:\WINDOWS\system32\drivers\viaidexp.sys
2008-02-20 14:10 . 2008-02-20 14:10
2008-02-20 14:10 . 2001-12-05 16:36 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-02-20 14:06 . 2008-02-20 14:06
2008-02-20 12:51 . 2006-06-14 09:47 172,416 --a------ C:\WINDOWS\system32\drivers\kmixer.sys
2008-02-20 12:51 . 2006-02-15 01:22 142,464 --a------ C:\WINDOWS\system32\drivers\aec.sys
2008-02-20 12:51 . 2006-06-14 10:00 82,944 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys
2008-02-20 12:51 . 2004-08-03 23:15 60,800 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys
2008-02-20 12:51 . 2004-08-04 00:35 58,624 --a------ C:\WINDOWS\system32\drivers\redbook.sys
2008-02-20 12:51 . 2001-08-17 22:00 54,272 --a------ C:\WINDOWS\system32\drivers\swmidi.sys
2008-02-20 12:51 . 2004-08-03 23:07 52,864 --a------ C:\WINDOWS\system32\drivers\dmusic.sys
2008-02-20 12:51 . 2006-06-14 09:47 6,400 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2008-02-20 12:51 . 2001-08-17 21:59 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys
2008-02-20 12:51 . 2004-08-03 23:07 2,944 --a------ C:\WINDOWS\system32\drivers\drmkaud.sys
2008-02-20 12:50 . 2001-10-26 17:29 1,738,496 --a------ C:\WINDOWS\system32\nv4.dll
2008-02-20 12:50 . 2001-08-17 20:50 731,648 --a------ C:\WINDOWS\system32\drivers\nv4.sys
2008-02-20 12:50 . 2004-08-04 00:44 77,312 --a------ C:\WINDOWS\system32\usbui.dll
2008-02-20 12:50 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-02-20 12:50 . 2001-08-17 22:00 2,944 --a------ C:\WINDOWS\system32\drivers\msmpu401.sys
2008-02-20 12:49 . 2004-08-03 23:07 42,240 --a------ C:\WINDOWS\system32\drivers\viaagp.sys
2008-02-20 12:49 . 2004-08-03 23:08 10,624 --a------ C:\WINDOWS\system32\drivers\gameenum.sys
2008-02-20 12:49 . 2008-02-24 11:32 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-02-20 12:48 . 2008-02-20 12:48
2008-02-20 12:48 . 2008-02-20 12:48
2008-02-20 12:48 . 2008-02-20 13:46
2008-02-20 12:48 . 2008-02-20 12:48
2008-02-20 12:48 . 2008-02-20 12:48
2008-02-20 12:48 . 2008-02-20 12:48
2008-02-20 12:48 . 2008-02-20 12:48
2008-02-20 12:48 . 2008-02-20 12:48
2008-02-20 12:48 . 2008-02-20 12:48
2008-02-20 12:48 . 2008-02-22 14:49
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-20 17:54 --------- d-----w C:\Program Files\microsoft frontpage
2008-02-20 15:04 22 ----a-w C:\WINDOWS\system32\drivers\adidsl.cfg
2008-02-20 12:59 --------- d-----w C:\Program Files\Alwil Software
2008-02-20 12:49 --------- d-----w C:\Program Files\Usługi online
2007-12-07 01:08 662,016 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:42 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE~\Browser Helper Objects{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
2007-12-13 17:49 1185120 --a------ C:\Program Files\Winamp Toolbar\winamptb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}
{37B85A29-692B-4205-9CAD-2626E4993404}
[HKEY_CLASSES_ROOT\clsid{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
“{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}”= C:\Program Files\Winamp Toolbar\winamptb.dll [2007-12-13 17:49 1185120]
[HKEY_CLASSES_ROOT\clsid{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 00:44 15360]
“Orb”=“C:\Program Files\Winamp Remote\bin\OrbTray.exe” [2008-01-07 21:02 495616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-12-04 14:00 79224]
“SoundMan”=“soundman.exe” [2001-05-29 10:02 124416 C:\WINDOWS\soundman.exe]
“runsvc”=“runsvc.exe” [2008-02-20 15:05 850944 C:\WINDOWS\system32\runsvc.exe]
“WOOWATCH”=“C:\PROGRA~1\Wanadoo\Watch.exe” [2002-12-09 18:24 20480]
“WOOTASKBARICON”=“C:\Program Files\Wanadoo\taskbaricon.exe” [2002-12-09 18:24 45056]
“HP Software Update”=“C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe” [2003-06-25 11:24 49152]
“HP Component Manager”=“C:\Program Files\HP\hpcoretech\hpcmpmgr.exe” [2003-10-23 19:51 233472]
“HPDJ Taskbar Utility”=“C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe” [2003-07-28 14:43 188416]
“DeviceDiscovery”=“C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe” [2003-05-21 18:37 229437]
“WinampAgent”=“D:\Winamp\winampa.exe” [2008-01-15 23:54 37376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
“runsvc”=“runsvc.exe” [2008-02-20 15:05 850944 C:\WINDOWS\system32\runsvc.exe]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\System32\CTFMON.EXE” [2004-08-04 00:44 15360]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2008-02-20 16:04:25 962667]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 20:05:56 65588]
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\system32\sessmgr.exe”=
“C:\Program Files\Winamp Remote\bin\OrbTray.exe”=
“C:\WINDOWS\system32\runsvc.exe”=
“D:\Gadu-Gadu\gg.exe”=
“C:\WINDOWS\system32\dpvsetup.exe”=
“C:\WINDOWS\system32\rundll32.exe”=
“C:\Program Files\Skype\Phone\Skype.exe”=
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-24 17:01:36
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-02-24 17:02:20
ComboFix-quarantined-files.txt 2008-02-24 16:02:05
.
2008-02-24 11:12:21 — E O F —