Laptop coraz wolniej chodzi, zamula, wirus?

Witam.

Tak jak w temacie, cos zaczal mi zamulac i wszystko sie coraz wolniej otwiera, nawet po wylaczeniu antywirusa.

Pare dni temu antywirus pokazal wiadomosc, ze znaleziono plik w ktorego nazwie byl trojan (calego pliku nie pamietam), i jak staral sie go usunac, to wyskoczylo ze nie da sie bo plik zmienil nazwe. Przeszukalam innymi programami i niby nic nie znajduja.

Czy przy okazji mozecie mi napisac ktore programy i jak wyrzucic z autostartu, bo dlugo sie odpala i moze dlatego muli.

Dzieki z gory, oto log z combofix i hijackthis:

ComboFix 08-05-01.3 - Ägaren 2008-05-06 22:18:36.2 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.46.1053.18.460 [GMT 2:00]

Running from: C:\Documents and Settings\Ägaren\Skrivbord\ComboFix.exe

* Created a new restore point

* Resident AV is active

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED!!

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

C:\Documents and Settings\Ägaren\Lokala inställningar\Temporary Internet Files\MUZAoDA.cfg

C:\Documents and Settings\Ägaren\Lokala inställningar\Temporary Internet Files\MUZAoDA0.che

C:\Documents and Settings\Ägaren\Lokala inställningar\Temporary Internet Files\MUZAoDA1.che

C:\Documents and Settings\Ägaren\Lokala inställningar\Temporary Internet Files\MUZAoDA2.che

C:\Documents and Settings\Ägaren\Lokala inställningar\Temporary Internet Files\MUZAoDA3.che

C:\Documents and Settings\Ägaren\Lokala inställningar\Temporary Internet Files\MUZAoDA4.che

C:\Documents and Settings\Ägaren\Lokala inställningar\Temporary Internet Files\MUZAoDA5.che

C:\Documents and Settings\Ägaren\Lokala inställningar\Temporary Internet Files\MUZAoDA6.che

C:\Documents and Settings\Ägaren\Lokala inställningar\Temporary Internet Files\MUZAoDA7.che

C:\Documents and Settings\Ägaren\Lokala inställningar\Temporary Internet Files\MUZAoDA8.che

C:\Documents and Settings\Ägaren\Lokala inställningar\Temporary Internet Files\MUZAoDA9.che

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

-------\Legacy_6TO4

-------\Legacy_NPF

-------\Service_6to4

-------\Service_NPF

((((((((((((((((((((((((( Files Created from 2008-04-06 to 2008-05-06 )))))))))))))))))))))))))))))))

.

2008-05-06 21:51 . 2008-05-06 21:51 d-------- C:\Program\DNA

2008-05-06 21:51 . 2008-05-06 21:51 d-------- C:\Program\BitTorrent

2008-05-06 17:13 . 2008-05-06 17:13 d-------- C:\Program\PhotoBox

2008-05-01 23:31 . 2007-02-08 12:56 18,704 -ra------ C:\WINDOWS\system32\drivers\sea1nd5.sys

2008-04-28 21:21 . 2007-02-08 12:56 90,800 -ra------ C:\WINDOWS\system32\drivers\sea1unic.sys

2008-04-28 21:21 . 2007-02-08 12:56 88,624 -ra------ C:\WINDOWS\system32\drivers\sea1mgmt.sys

2008-04-28 21:21 . 2007-02-08 12:56 86,432 -ra------ C:\WINDOWS\system32\drivers\sea1obex.sys

2008-04-28 21:21 . 2007-02-08 12:55 4,128 -ra------ C:\WINDOWS\system32\drivers\sea1cr.sys

2008-04-27 14:30 . 2007-02-08 12:55 97,088 -ra------ C:\WINDOWS\system32\drivers\sea1mdm.sys

2008-04-27 14:30 . 2007-02-08 12:55 9,360 -ra------ C:\WINDOWS\system32\drivers\sea1mdfl.sys

2008-04-27 14:30 . 2007-02-08 12:55 6,240 -ra------ C:\WINDOWS\system32\drivers\sea1cmnt.sys

2008-04-27 14:30 . 2007-02-08 12:55 6,240 -ra------ C:\WINDOWS\system32\drivers\sea1cm.sys

2008-04-27 13:53 . 2007-02-08 12:55 61,536 -ra------ C:\WINDOWS\system32\drivers\sea1bus.sys

2008-04-27 13:53 . 2007-02-08 12:56 5,872 -ra------ C:\WINDOWS\system32\drivers\sea1whnt.sys

2008-04-27 13:53 . 2007-02-08 12:56 5,872 -ra------ C:\WINDOWS\system32\drivers\sea1wh.sys

2008-04-27 13:44 . 2008-04-27 13:44 d-------- C:\Program\Sony Ericsson

2008-04-27 13:44 . 2008-04-27 13:44 d-------- C:\Program\Delade filer\Sony Ericsson Shared

2008-04-27 13:44 . 2008-04-27 13:44 d-------- C:\Documents and Settings\All Users\Application Data\Teleca

2008-04-27 13:41 . 2008-04-27 13:41 54,156 --ah----- C:\WINDOWS\QTFont.qfn

2008-04-27 13:41 . 2008-04-27 13:41 1,409 --a------ C:\WINDOWS\QTFont.for

2008-04-26 14:41 . 2008-04-26 16:35 d-------- C:\Bwgen

2008-04-26 13:22 . 2008-04-28 13:17 d-------- C:\Program\IDoser v4

2008-04-25 14:31 . 2008-04-25 14:31 d-------- C:\Program\Ashampoo

2008-04-25 14:31 . 2008-04-25 14:31 d-------- C:\Documents and Settings\All Users\Application Data\ashampoo

2008-04-25 14:18 . 2008-04-25 14:18 d-------- C:\Program\Alcohol Soft

2008-04-21 01:04 . 2008-04-21 01:05 d-------- C:\WINDOWS\system32\oodag

2008-04-21 01:04 . 2008-04-21 01:04 0 --a------ C:\WINDOWS\oodcnt.INI

2008-04-12 14:52 . 2008-04-12 14:52 d-------- C:\My Video

2008-04-07 06:01 . 2008-04-08 01:17 d-------- C:\Program\Total Video Converter

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-05-06 19:54 --------- d-----w C:\Program\FlashGet

2008-05-01 09:09 --------- d-----w C:\Program\ArcaMicroScan

2008-04-27 11:44 --------- d-----w C:\Program\Delade filer\Teleca Shared

2008-04-27 11:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sony Ericsson

2008-04-25 12:13 716,272 ----a-w C:\WINDOWS\system32\drivers\sptd.sys

2008-04-18 23:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero

2008-04-14 14:46 --------- d-----w C:\Program\Delade filer\Simple Star Shared

2008-04-09 22:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help

2008-04-07 03:40 --------- d-----w C:\Program\Delade filer\Adobe

2008-03-30 13:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft

2008-03-30 13:02 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe

2008-03-25 23:15 --------- d-----w C:\Program\Java

2008-03-24 01:36 2,672 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys

2008-03-23 21:45 --------- d-----w C:\Program\Delade filer\InstallShield

2008-03-23 21:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield

2008-03-23 21:42 --------- d-----w C:\Program\Delade filer\Protexis

2008-03-23 11:55 --------- d-----w C:\Program\Bredbandsbolaget

2008-03-23 11:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Bredbandsbolaget

2008-03-20 08:10 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys

2008-03-19 15:31 --------- d–h--w C:\Program\Zero G Registry

2008-03-17 20:03 --------- d-----w C:\Program\Bredbandsbolaget Security Services

2008-03-17 19:58 51,072 ----a-w C:\WINDOWS\system32\drivers\fsdfw.sys

2008-03-17 19:58 30,016 ----a-w C:\WINDOWS\system32\drivers\fsndis5.sys

2008-03-16 19:24 --------- d-----w C:\Program\Winamp

2008-03-16 16:16 --------- d-----w C:\Program\Windows Media Connect 2

2008-03-16 11:57 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll

2008-03-16 11:57 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll

2008-03-16 11:57 --------- d-----w C:\Program\Real

2008-03-16 11:57 --------- d-----w C:\Program\Delade filer\xing shared

2008-03-16 11:57 --------- d-----w C:\Program\Delade filer\Real

2008-03-15 15:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Winamp Toolbar

2008-03-14 00:04 --------- d-----w C:\Program\Trend Micro

2008-03-13 16:33 --------- d–h--w C:\Program\InstallShield Installation Information

2008-03-01 13:02 826,368 ----a-w C:\WINDOWS\system32\wininet.dll

2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll

2008-02-20 05:38 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll

2008-02-17 10:18 65,024 ----a-w C:\WINDOWS\IFinst26.exe

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

“CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 14:00 15360]

“Nero PhotoShow Media Manager”=“C:\Program\Nero\PHOTOS~1\data\Xtras\mssysmgr.exe” []

“BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}”=“C:\Program\Delade filer\Nero\Lib\NMBgMonitor.exe” []

“Gadu-Gadu”=“C:\Program\Gadu-Gadu\gg.exe” [2007-09-29 23:08 2111176]

“BitTorrent DNA”=“C:\Program\DNA\btdna.exe” [2008-05-06 21:51 289088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

“ATIPTA”=“C:\Program\ATI Technologies\ATI Control Panel\atiptaxx.exe” [2005-08-09 21:05 344064]

“Genväg till egenskapssida för High Definition Audio”=“HDAudPropShortcut.exe” [2004-08-12 17:45 61952 C:\WINDOWS\system32\Hdaudpropshortcut.exe]

“AGRSMMSG”=“AGRSMMSG.exe” [2004-10-08 03:50 88363 C:\WINDOWS\AGRSMMSG.exe]

“IntelWireless”=“C:\Program\Intel\Wireless\Bin\ifrmewrk.exe” [2004-10-15 11:27 385024]

“EOUApp”=“C:\Program\Intel\Wireless\Bin\EOUWiz.exe” [2004-10-15 11:31 356352]

“BluetoothAuthenticationAgent”=“bthprops.cpl” [2004-08-04 14:00 110592 C:\WINDOWS\system32\bthprops.cpl]

“QuickTime Task”=“C:\Program\QuickTime\qttask.exe” [2006-09-24 04:24 282624]

“SoundMan”=“SOUNDMAN.EXE” [2007-04-16 15:28 577536 C:\WINDOWS\soundman.exe]

“AlcWzrd”=“ALCWZRD.EXE” [2004-12-10 08:38 2749440 C:\WINDOWS\ALCWZRD.EXE]

“F-Secure Manager”=“C:\Program\Bredbandsbolaget Security Services\Common\FSM32.exe” [2007-04-26 19:12 183208]

“F-Secure TNB”=“C:\Program\Bredbandsbolaget Security Services\FSGUI\TNBUtil.exe” [2007-04-26 19:10 740208]

“NBKeyScan”=“C:\Program\Nero\Nero8\Nero BackItUp\NBKeyScan.exe” []

“GrooveMonitor”=“C:\Program\Microsoft Office\Office12\GrooveMonitor.exe” [2006-10-27 01:47 31016]

“ISUSPM Startup”=“C:\Program\DELADE~1\INSTAL~1\UPDATE~1\ISUSPM.exe” []

“ISUSScheduler”=“C:\Program\Delade filer\InstallShield\UpdateService\issch.exe” [2005-02-16 17:15 81920]

“SunJavaUpdateSched”=“C:\Program\Java\jre1.6.0_05\bin\jusched.exe” [2008-02-22 05:25 144784]

“Adobe Reader Speed Launcher”=“C:\Program\Adobe\Reader 8.0\Reader\Reader_sl.exe” [2008-01-11 22:16 39792]

“SMSTray”=“C:\Program\Samsung\Samsung Media Studio 5\SMSTray.exe” [2007-09-20 09:23 132624]

“Sony Ericsson PC Suite”=“C:\Program\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe” [2007-01-26 13:36 495616]

[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

“CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2004-08-04 14:00 15360]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]

“{88485281-8b4b-4f8d-9ede-82e29a064277}”= C:\Program\MarkAny\CONTEN~1\MACSMA~1.DLL [2004-11-23 17:51 192512]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]

C:\Program\Intel\Wireless\Bin\LgNotify.dll 2004-10-15 11:27 110592 C:\Program\Intel\Wireless\Bin\LgNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

“msacm.avis”= ff_acm.acm

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

“EnableFirewall”= 0 (0x0)

[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

“%windir%\Network Diagnostic\xpnetdiag.exe”=

“C:\Program\Microsoft Office\Office12\OUTLOOK.EXE”=

“C:\Program\Microsoft Office\Office12\GROOVE.EXE”=

“C:\Program\Microsoft Office\Office12\ONENOTE.EXE”=

“C:\WINDOWS\system32\muzapp.exe”=

“C:\Program\FlashGet\flashget.exe”=

“C:\Program\Bredbandsbolaget\Servicecenter\Bredbandsbolaget.exe”=

“C:\Program\DNA\btdna.exe”=

“C:\Program\BitTorrent\bittorrent.exe”=

“C:\Program\Skype\Phone\Skype.exe”=

[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

“3389:TCP”= 3389:TCP:@xpsp2res.dll,-22009

R0 FSFW;F-Secure Firewall Driver;C:\WINDOWS\system32\drivers\fsdfw.sys [2008-03-17 21:58]

R1 F-Secure HIPS;F-Secure HIPS;C:\Program\Bredbandsbolaget Security Services\HIPS\fshs.sys [2008-03-03 12:31]

R3 CONAN;CONAN;C:\WINDOWS\system32\drivers\o2mmb.sys [2004-12-18 07:06]

R3 F-Secure Gatekeeper;F-Secure Gatekeeper;C:\Program\Bredbandsbolaget Security Services\Anti-Virus\minifilter\fsgk.sys [2007-04-26 19:07]

R3 MbxStby;MbxStby;C:\WINDOWS\system32\drivers\MbxStby.sys [2004-12-23 02:59]

S3 EpmShd;Acer EPM System Hardware Driver;C:\WINDOWS\system32\Drivers\epm-shd.sys []

S3 odysseyIM4;Odyssey Network Agent Miniport;C:\WINDOWS\system32\DRIVERS\odysseyIM4.sys [2005-06-10 06:55]

S3 sea1bus;Sony Ericsson Device 0A1 driver (WDM);C:\WINDOWS\system32\DRIVERS\sea1bus.sys [2007-02-08 12:55]

S3 sea1mdfl;Sony Ericsson Device 0A1 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\sea1mdfl.sys [2007-02-08 12:55]

S3 sea1mdm;Sony Ericsson Device 0A1 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\sea1mdm.sys [2007-02-08 12:55]

S3 sea1mgmt;Sony Ericsson Device 0A1 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\sea1mgmt.sys [2007-02-08 12:56]

S3 sea1nd5;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (NDIS);C:\WINDOWS\system32\DRIVERS\sea1nd5.sys [2007-02-08 12:56]

S3 sea1obex;Sony Ericsson Device 0A1 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\sea1obex.sys [2007-02-08 12:56]

S3 sea1unic;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (WDM);C:\WINDOWS\system32\DRIVERS\sea1unic.sys [2007-02-08 12:56]

S3 StreamSurge;StreamSurge Driver (miniport);C:\WINDOWS\system32\DRIVERS\ss.sys []

S4 F-Secure Filter;F-Secure File System Filter;C:\Program\Bredbandsbolaget Security Services\Anti-Virus\Win2K\FSfilter.sys [2007-04-26 19:08]

S4 F-Secure Recognizer;F-Secure File System Recognizer;C:\Program\Bredbandsbolaget Security Services\Anti-Virus\Win2K\FSrec.sys [2007-04-26 19:08]

.

Contents of the ‘Scheduled Tasks’ folder

“2007-04-18 09:03:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job”

  • C:\Program\Apple Software Update\SoftwareUpdate.exe

“2008-05-06 14:55:16 C:\WINDOWS\Tasks\Scheduled scanning task.job”

  • C:\Program\BREDBA~2\ANTI-V~1\fsav.exeP /HARD /POLICY /SCHED /NOBREAK /REPORT=C:\Program\BREDBA~2\ANTI-V~1\report.txt

.

**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-05-06 22:26:05

Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully

hidden files: 0

**************************************************************************

.

------------------------ Other Running Processes ------------------------

.

C:\WINDOWS\system32\ati2evxx.exe

C:\Program\Intel\Wireless\Bin\EvtEng.exe

C:\Program\Intel\Wireless\Bin\S24EvMon.exe

C:\WINDOWS\system32\scardsvr.exe

C:\Program\Intel\Wireless\Bin\ZCfgSvc.exe

C:\Program\Intel\Wireless\Bin\1XConfig.exe

C:\WINDOWS\system32\agrsmsvc.exe

C:\Program\WIDCOMM\Bluetooth-programvara\bin\btwdins.exe

C:\Program\Bredbandsbolaget Security Services\Anti-Virus\fsgk32st.exe

C:\Program\Bredbandsbolaget Security Services\Common\FSMA32.EXE

C:\Program\Bredbandsbolaget Security Services\Anti-Virus\fsgk32.exe

C:\Program\Intel\Wireless\Bin\OProtSvc.exe

C:\Program\Bredbandsbolaget Security Services\Common\FSMB32.EXE

C:\Program\Delade filer\Protexis\License Service\PSIService.exe

C:\Program\Intel\Wireless\Bin\RegSrvc.exe

C:\WINDOWS\system32\ati2evxx.exe

C:\Program\Bredbandsbolaget Security Services\Common\FCH32.EXE

C:\Program\Bredbandsbolaget Security Services\Anti-Virus\fssm32.exe

C:\Program\Bredbandsbolaget Security Services\Common\FAMEH32.EXE

C:\Program\Bredbandsbolaget Security Services\Anti-Virus\fsqh.exe

C:\Program\Bredbandsbolaget Security Services\FSAUA\program\fsaua.exe

C:\Program\Bredbandsbolaget Security Services\FWES\program\fsdfwd.exe

C:\Program\Bredbandsbolaget Security Services\FSAUA\program\fsus.exe

C:\Program\BREDBA~2\ANTI-V~1\fsav32.exe

C:\WINDOWS\system32\rundll32.exe

C:\Program\BREDBA~2\Common\FSM32.EXE

C:\Program\Bredbandsbolaget Security Services\FSGUI\fsguidll.exe

C:\WINDOWS\system32\imapi.exe

.

**************************************************************************

.

Completion time: 2008-05-06 22:32:01 - machine was rebooted

ComboFix-quarantined-files.txt 2008-05-06 20:31:42

Pre-Run: 26,482,782,208 byte ledigt

Post-Run: 26,877,698,048 byte ledigt

227 — E O F — 2008-04-20 22:28:03

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 10:13:50 PM, on 5/6/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16640)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Program\Intel\Wireless\Bin\EvtEng.exe

C:\Program\Intel\Wireless\Bin\S24EvMon.exe

C:\Program\Intel\Wireless\Bin\ZcfgSvc.exe

C:\Program\Intel\Wireless\Bin\1XConfig.exe

C:\WINDOWS\system32\agrsmsvc.exe

C:\Program\WIDCOMM\Bluetooth-programvara\bin\btwdins.exe

C:\Program\Bredbandsbolaget Security Services\Anti-Virus\fsgk32st.exe

C:\Program\Bredbandsbolaget Security Services\Common\FSMA32.EXE

C:\Program\Bredbandsbolaget Security Services\Anti-Virus\FSGK32.EXE

C:\Program\Intel\Wireless\Bin\OProtSvc.exe

C:\Program\Bredbandsbolaget Security Services\Common\FSMB32.EXE

C:\Program\Delade filer\Protexis\License Service\PSIService.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\Program\Intel\Wireless\Bin\RegSrvc.exe

C:\Program\Bredbandsbolaget Security Services\Common\FCH32.EXE

C:\Program\Bredbandsbolaget Security Services\Common\FAMEH32.EXE

C:\Program\Bredbandsbolaget Security Services\Anti-Virus\fsqh.exe

C:\Program\Bredbandsbolaget Security Services\FSAUA\program\fsaua.exe

C:\Program\Bredbandsbolaget Security Services\Anti-Virus\fssm32.exe

C:\Program\Bredbandsbolaget Security Services\FWES\Program\fsdfwd.exe

C:\Program\Bredbandsbolaget Security Services\FSAUA\program\fsus.exe

C:\Program\ATI Technologies\ATI Control Panel\atiptaxx.exe

C:\WINDOWS\AGRSMMSG.exe

C:\Program\Bredbandsbolaget Security Services\Anti-Virus\fsav32.exe

C:\Program\Intel\Wireless\Bin\ifrmewrk.exe

C:\Program\Intel\Wireless\Bin\EOUWiz.exe

C:\WINDOWS\system32\rundll32.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\Program\Bredbandsbolaget Security Services\Common\FSM32.EXE

C:\Program\Microsoft Office\Office12\GrooveMonitor.exe

C:\Program\Delade filer\InstallShield\UpdateService\issch.exe

C:\Program\Java\jre1.6.0_05\bin\jusched.exe

C:\Program\Samsung\Samsung Media Studio 5\SMSTray.exe

C:\Program\Bredbandsbolaget Security Services\FSGUI\fsguidll.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program\Gadu-Gadu\gg.exe

C:\Program\DNA\btdna.exe

C:\Program\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.se/0SESVSE/SAOS01?FORM=TOOLBR

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar

O2 - BHO: Länkhjälp till Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Delade filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program\FlashGet\jccatch.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program\Real\RealPlayer\rpbrowserrecordplugin.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program\MICROS~3\Office12\GRA8E1~1.DLL

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: Servicecenter Plugin - {DB87CDE1-EF9C-44EB-A42F-6D0B3C72C516} - C:\Program\Bredbandsbolaget\Servicecenter\IEFixItNowPlugin.dll

O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program\FlashGet\getflash.dll

O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)

O3 - Toolbar: Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program\google\googletoolbar1.dll

O4 - HKLM…\Run: [ATIPTA] “C:\Program\ATI Technologies\ATI Control Panel\atiptaxx.exe”

O4 - HKLM…\Run: [Genväg till egenskapssida för High Definition Audio] HDAudPropShortcut.exe

O4 - HKLM…\Run: [AGRSMMSG] AGRSMMSG.exe

O4 - HKLM…\Run: [intelWireless] C:\Program\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless

O4 - HKLM…\Run: [EOUApp] C:\Program\Intel\Wireless\Bin\EOUWiz.exe

O4 - HKLM…\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,BluetoothAuthenticationAgent

O4 - HKLM…\Run: [QuickTime Task] “C:\Program\QuickTime\qttask.exe” -atboottime

O4 - HKLM…\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM…\Run: [AlcWzrd] ALCWZRD.EXE

O4 - HKLM…\Run: [F-Secure Manager] “C:\Program\Bredbandsbolaget Security Services\Common\FSM32.EXE” /splash

O4 - HKLM…\Run: [F-Secure TNB] “C:\Program\Bredbandsbolaget Security Services\FSGUI\TNBUtil.exe” /CHECKALL /WAITFORSW

O4 - HKLM…\Run: [NBKeyScan] “C:\Program\Nero\Nero8\Nero BackItUp\NBKeyScan.exe”

O4 - HKLM…\Run: [GrooveMonitor] “C:\Program\Microsoft Office\Office12\GrooveMonitor.exe”

O4 - HKLM…\Run: [iSUSPM Startup] C:\Program\DELADE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup

O4 - HKLM…\Run: [iSUSScheduler] “C:\Program\Delade filer\InstallShield\UpdateService\issch.exe” -start

O4 - HKLM…\Run: [sunJavaUpdateSched] “C:\Program\Java\jre1.6.0_05\bin\jusched.exe”

O4 - HKLM…\Run: [Adobe Reader Speed Launcher] “C:\Program\Adobe\Reader 8.0\Reader\Reader_sl.exe”

O4 - HKLM…\Run: [sMSTray] C:\Program\Samsung\Samsung Media Studio 5\SMSTray.exe

O4 - HKLM…\Run: [sony Ericsson PC Suite] “C:\Program\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe” /startoptions

O4 - HKCU…\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU…\Run: [Nero PhotoShow Media Manager] C:\Program\Nero\PHOTOS~1\data\Xtras\mssysmgr.exe

O4 - HKCU…\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] “C:\Program\Delade filer\Nero\Lib\NMBgMonitor.exe”

O4 - HKCU…\Run: [Gadu-Gadu] “C:\Program\Gadu-Gadu\gg.exe” /tray

O4 - HKCU…\Run: [bitTorrent DNA] “C:\Program\DNA\btdna.exe”

O4 - HKUS\S-1-5-19…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘LOKAL TJÄNST’)

O4 - HKUS\S-1-5-20…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘NETWORK SERVICE’)

O4 - HKUS\S-1-5-18…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)

O4 - HKUS.DEFAULT…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)

O8 - Extra context menu item: Œci¹gnij przy pomocy FlashGet’a - C:\Program\FlashGet\jc_link.htm

O8 - Extra context menu item: Œci¹gnij wszystko przy pomocy FlashGet’a - C:\Program\FlashGet\jc_all.htm

O8 - Extra context menu item: Eksportuj do programu Microsoft Excel - res://C:\Program\MICROS~3\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Skicka till Bluetooth - C:\Program\WIDCOMM\Bluetooth-programvara\btsendto_ie_ctx.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra ‘Tools’ menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Wyslij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra ‘Tools’ menuitem: Wyslij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program\WIDCOMM\Bluetooth-programvara\btsendto_ie.htm

O9 - Extra ‘Tools’ menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program\WIDCOMM\Bluetooth-programvara\btsendto_ie.htm

O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program\FlashGet\FlashGet.exe

O9 - Extra ‘Tools’ menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program\FlashGet\FlashGet.exe

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe

O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll

O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://downloadcenter.samsung.com/conte … ite_EN.cab

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {3D8700FB-86A4-4CB4-B738-6F0FC016AC7D} (MainControl Class) - http://slimak.onet.pl/_m/wirusy/ArcaOnline.cab

O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} (king.com) - http://www.king.com/ctl/kingcomie.cab

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda … 8938470031

O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} - http://www.postfoto.se/aurigma/ImageUploader4.cab

O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://se.photobox.com/clients/uploader_v2.2.0.6.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program\MICROS~3\Office12\GR99D3~1.DLL

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program\DELADE~1\Skype\SKYPE4~1.DLL

O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program\Lavasoft\Ad-Aware 2007\aawservice.exe

O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program\WIDCOMM\Bluetooth-programvara\bin\btwdins.exe

O23 - Service: EvtEng - Intel Corporation - C:\Program\Intel\Wireless\Bin\EvtEng.exe

O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program\Bredbandsbolaget Security Services\Anti-Virus\fsgk32st.exe

O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program\Bredbandsbolaget Security Services\FSAUA\program\fsaua.exe

O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program\Bredbandsbolaget Security Services\FWES\Program\fsdfwd.exe

O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program\Bredbandsbolaget Security Services\Common\FSMA32.EXE

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: OwnershipProtocol - Intel Corporation - C:\Program\Intel\Wireless\Bin\OProtSvc.exe

O23 - Service: ProtexisLicensing - Unknown owner - C:\Program\Delade filer\Protexis\License Service\PSIService.exe

O23 - Service: RegSrvc - Intel Corporation - C:\Program\Intel\Wireless\Bin\RegSrvc.exe

O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program\Intel\Wireless\Bin\S24EvMon.exe

End of file - 11935 bytes

Wklej do Notatnika:

File::

C:\WINDOWS\Tasks\AppleSoftwareUpdate.job

C:\WINDOWS\Tasks\Scheduled scanning task.job


Driver::

EpmShd

StreamSurge


Registry::

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Nero PhotoShow Media Manager"=-

"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NBKeyScan"=-

"ISUSPM Startup"=-

>>Plik>>Zapisz jako… >>> CFScript (najwygodniej będzie, jeśli zapiszesz w takiej lokalizacji, by ikonka CFScript.txt znalazła się obok ikonki ComboFix.exe )

Przeciągnij i upuść plik CFScript.txt na plik ComboFix.exe (czyli ikonkę CFScript.txt na ikonkę ComboFix.exe )

– podobnie jak na tym obrazku –>88953CFScript-createdbyMiekiemoes.gif

(jeśli pojawi się pytanie " 1 or 2" - to wpisz 1 i naciśnij ENTER) Ma się rozpocząć usuwanie. (i powstanie log)

Po restarcie usuń ręcznie folder C: ** Qoobox**.

Dziekuje za odpowiedz, zrobilam jak napisales i albo mam wrazenie, albo juz lepiej chodzi:)

Tak czy inaczej dzieki!