Witam.
Tak jak w temacie, cos zaczal mi zamulac i wszystko sie coraz wolniej otwiera, nawet po wylaczeniu antywirusa.
Pare dni temu antywirus pokazal wiadomosc, ze znaleziono plik w ktorego nazwie byl trojan (calego pliku nie pamietam), i jak staral sie go usunac, to wyskoczylo ze nie da sie bo plik zmienil nazwe. Przeszukalam innymi programami i niby nic nie znajduja.
Czy przy okazji mozecie mi napisac ktore programy i jak wyrzucic z autostartu, bo dlugo sie odpala i moze dlatego muli.
Dzieki z gory, oto log z combofix i hijackthis:
ComboFix 08-05-01.3 - Ägaren 2008-05-06 22:18:36.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.46.1053.18.460 [GMT 2:00]
Running from: C:\Documents and Settings\Ägaren\Skrivbord\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Ägaren\Lokala inställningar\Temporary Internet Files\MUZAoDA.cfg
C:\Documents and Settings\Ägaren\Lokala inställningar\Temporary Internet Files\MUZAoDA0.che
C:\Documents and Settings\Ägaren\Lokala inställningar\Temporary Internet Files\MUZAoDA1.che
C:\Documents and Settings\Ägaren\Lokala inställningar\Temporary Internet Files\MUZAoDA2.che
C:\Documents and Settings\Ägaren\Lokala inställningar\Temporary Internet Files\MUZAoDA3.che
C:\Documents and Settings\Ägaren\Lokala inställningar\Temporary Internet Files\MUZAoDA4.che
C:\Documents and Settings\Ägaren\Lokala inställningar\Temporary Internet Files\MUZAoDA5.che
C:\Documents and Settings\Ägaren\Lokala inställningar\Temporary Internet Files\MUZAoDA6.che
C:\Documents and Settings\Ägaren\Lokala inställningar\Temporary Internet Files\MUZAoDA7.che
C:\Documents and Settings\Ägaren\Lokala inställningar\Temporary Internet Files\MUZAoDA8.che
C:\Documents and Settings\Ägaren\Lokala inställningar\Temporary Internet Files\MUZAoDA9.che
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_6TO4
-------\Legacy_NPF
-------\Service_6to4
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2008-04-06 to 2008-05-06 )))))))))))))))))))))))))))))))
.
2008-05-06 21:51 . 2008-05-06 21:51 d-------- C:\Program\DNA
2008-05-06 21:51 . 2008-05-06 21:51 d-------- C:\Program\BitTorrent
2008-05-06 17:13 . 2008-05-06 17:13 d-------- C:\Program\PhotoBox
2008-05-01 23:31 . 2007-02-08 12:56 18,704 -ra------ C:\WINDOWS\system32\drivers\sea1nd5.sys
2008-04-28 21:21 . 2007-02-08 12:56 90,800 -ra------ C:\WINDOWS\system32\drivers\sea1unic.sys
2008-04-28 21:21 . 2007-02-08 12:56 88,624 -ra------ C:\WINDOWS\system32\drivers\sea1mgmt.sys
2008-04-28 21:21 . 2007-02-08 12:56 86,432 -ra------ C:\WINDOWS\system32\drivers\sea1obex.sys
2008-04-28 21:21 . 2007-02-08 12:55 4,128 -ra------ C:\WINDOWS\system32\drivers\sea1cr.sys
2008-04-27 14:30 . 2007-02-08 12:55 97,088 -ra------ C:\WINDOWS\system32\drivers\sea1mdm.sys
2008-04-27 14:30 . 2007-02-08 12:55 9,360 -ra------ C:\WINDOWS\system32\drivers\sea1mdfl.sys
2008-04-27 14:30 . 2007-02-08 12:55 6,240 -ra------ C:\WINDOWS\system32\drivers\sea1cmnt.sys
2008-04-27 14:30 . 2007-02-08 12:55 6,240 -ra------ C:\WINDOWS\system32\drivers\sea1cm.sys
2008-04-27 13:53 . 2007-02-08 12:55 61,536 -ra------ C:\WINDOWS\system32\drivers\sea1bus.sys
2008-04-27 13:53 . 2007-02-08 12:56 5,872 -ra------ C:\WINDOWS\system32\drivers\sea1whnt.sys
2008-04-27 13:53 . 2007-02-08 12:56 5,872 -ra------ C:\WINDOWS\system32\drivers\sea1wh.sys
2008-04-27 13:44 . 2008-04-27 13:44 d-------- C:\Program\Sony Ericsson
2008-04-27 13:44 . 2008-04-27 13:44 d-------- C:\Program\Delade filer\Sony Ericsson Shared
2008-04-27 13:44 . 2008-04-27 13:44 d-------- C:\Documents and Settings\All Users\Application Data\Teleca
2008-04-27 13:41 . 2008-04-27 13:41 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-27 13:41 . 2008-04-27 13:41 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-26 14:41 . 2008-04-26 16:35 d-------- C:\Bwgen
2008-04-26 13:22 . 2008-04-28 13:17 d-------- C:\Program\IDoser v4
2008-04-25 14:31 . 2008-04-25 14:31 d-------- C:\Program\Ashampoo
2008-04-25 14:31 . 2008-04-25 14:31 d-------- C:\Documents and Settings\All Users\Application Data\ashampoo
2008-04-25 14:18 . 2008-04-25 14:18 d-------- C:\Program\Alcohol Soft
2008-04-21 01:04 . 2008-04-21 01:05 d-------- C:\WINDOWS\system32\oodag
2008-04-21 01:04 . 2008-04-21 01:04 0 --a------ C:\WINDOWS\oodcnt.INI
2008-04-12 14:52 . 2008-04-12 14:52 d-------- C:\My Video
2008-04-07 06:01 . 2008-04-08 01:17 d-------- C:\Program\Total Video Converter
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-06 19:54 --------- d-----w C:\Program\FlashGet
2008-05-01 09:09 --------- d-----w C:\Program\ArcaMicroScan
2008-04-27 11:44 --------- d-----w C:\Program\Delade filer\Teleca Shared
2008-04-27 11:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sony Ericsson
2008-04-25 12:13 716,272 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-04-18 23:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-04-14 14:46 --------- d-----w C:\Program\Delade filer\Simple Star Shared
2008-04-09 22:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-04-07 03:40 --------- d-----w C:\Program\Delade filer\Adobe
2008-03-30 13:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-30 13:02 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-03-25 23:15 --------- d-----w C:\Program\Java
2008-03-24 01:36 2,672 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2008-03-23 21:45 --------- d-----w C:\Program\Delade filer\InstallShield
2008-03-23 21:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
2008-03-23 21:42 --------- d-----w C:\Program\Delade filer\Protexis
2008-03-23 11:55 --------- d-----w C:\Program\Bredbandsbolaget
2008-03-23 11:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Bredbandsbolaget
2008-03-20 08:10 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 15:31 --------- d–h--w C:\Program\Zero G Registry
2008-03-17 20:03 --------- d-----w C:\Program\Bredbandsbolaget Security Services
2008-03-17 19:58 51,072 ----a-w C:\WINDOWS\system32\drivers\fsdfw.sys
2008-03-17 19:58 30,016 ----a-w C:\WINDOWS\system32\drivers\fsndis5.sys
2008-03-16 19:24 --------- d-----w C:\Program\Winamp
2008-03-16 16:16 --------- d-----w C:\Program\Windows Media Connect 2
2008-03-16 11:57 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-03-16 11:57 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-03-16 11:57 --------- d-----w C:\Program\Real
2008-03-16 11:57 --------- d-----w C:\Program\Delade filer\xing shared
2008-03-16 11:57 --------- d-----w C:\Program\Delade filer\Real
2008-03-15 15:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Winamp Toolbar
2008-03-14 00:04 --------- d-----w C:\Program\Trend Micro
2008-03-13 16:33 --------- d–h--w C:\Program\InstallShield Installation Information
2008-03-01 13:02 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:38 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-17 10:18 65,024 ----a-w C:\WINDOWS\IFinst26.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 14:00 15360]
“Nero PhotoShow Media Manager”=“C:\Program\Nero\PHOTOS~1\data\Xtras\mssysmgr.exe” []
“BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}”=“C:\Program\Delade filer\Nero\Lib\NMBgMonitor.exe” []
“Gadu-Gadu”=“C:\Program\Gadu-Gadu\gg.exe” [2007-09-29 23:08 2111176]
“BitTorrent DNA”=“C:\Program\DNA\btdna.exe” [2008-05-06 21:51 289088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ATIPTA”=“C:\Program\ATI Technologies\ATI Control Panel\atiptaxx.exe” [2005-08-09 21:05 344064]
“Genväg till egenskapssida för High Definition Audio”=“HDAudPropShortcut.exe” [2004-08-12 17:45 61952 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
“AGRSMMSG”=“AGRSMMSG.exe” [2004-10-08 03:50 88363 C:\WINDOWS\AGRSMMSG.exe]
“IntelWireless”=“C:\Program\Intel\Wireless\Bin\ifrmewrk.exe” [2004-10-15 11:27 385024]
“EOUApp”=“C:\Program\Intel\Wireless\Bin\EOUWiz.exe” [2004-10-15 11:31 356352]
“BluetoothAuthenticationAgent”=“bthprops.cpl” [2004-08-04 14:00 110592 C:\WINDOWS\system32\bthprops.cpl]
“QuickTime Task”=“C:\Program\QuickTime\qttask.exe” [2006-09-24 04:24 282624]
“SoundMan”=“SOUNDMAN.EXE” [2007-04-16 15:28 577536 C:\WINDOWS\soundman.exe]
“AlcWzrd”=“ALCWZRD.EXE” [2004-12-10 08:38 2749440 C:\WINDOWS\ALCWZRD.EXE]
“F-Secure Manager”=“C:\Program\Bredbandsbolaget Security Services\Common\FSM32.exe” [2007-04-26 19:12 183208]
“F-Secure TNB”=“C:\Program\Bredbandsbolaget Security Services\FSGUI\TNBUtil.exe” [2007-04-26 19:10 740208]
“NBKeyScan”=“C:\Program\Nero\Nero8\Nero BackItUp\NBKeyScan.exe” []
“GrooveMonitor”=“C:\Program\Microsoft Office\Office12\GrooveMonitor.exe” [2006-10-27 01:47 31016]
“ISUSPM Startup”=“C:\Program\DELADE~1\INSTAL~1\UPDATE~1\ISUSPM.exe” []
“ISUSScheduler”=“C:\Program\Delade filer\InstallShield\UpdateService\issch.exe” [2005-02-16 17:15 81920]
“SunJavaUpdateSched”=“C:\Program\Java\jre1.6.0_05\bin\jusched.exe” [2008-02-22 05:25 144784]
“Adobe Reader Speed Launcher”=“C:\Program\Adobe\Reader 8.0\Reader\Reader_sl.exe” [2008-01-11 22:16 39792]
“SMSTray”=“C:\Program\Samsung\Samsung Media Studio 5\SMSTray.exe” [2007-09-20 09:23 132624]
“Sony Ericsson PC Suite”=“C:\Program\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe” [2007-01-26 13:36 495616]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2004-08-04 14:00 15360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
“{88485281-8b4b-4f8d-9ede-82e29a064277}”= C:\Program\MarkAny\CONTEN~1\MACSMA~1.DLL [2004-11-23 17:51 192512]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program\Intel\Wireless\Bin\LgNotify.dll 2004-10-15 11:27 110592 C:\Program\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“msacm.avis”= ff_acm.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
“EnableFirewall”= 0 (0x0)
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\Network Diagnostic\xpnetdiag.exe”=
“C:\Program\Microsoft Office\Office12\OUTLOOK.EXE”=
“C:\Program\Microsoft Office\Office12\GROOVE.EXE”=
“C:\Program\Microsoft Office\Office12\ONENOTE.EXE”=
“C:\WINDOWS\system32\muzapp.exe”=
“C:\Program\FlashGet\flashget.exe”=
“C:\Program\Bredbandsbolaget\Servicecenter\Bredbandsbolaget.exe”=
“C:\Program\DNA\btdna.exe”=
“C:\Program\BitTorrent\bittorrent.exe”=
“C:\Program\Skype\Phone\Skype.exe”=
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
“3389:TCP”= 3389:TCP:@xpsp2res.dll,-22009
R0 FSFW;F-Secure Firewall Driver;C:\WINDOWS\system32\drivers\fsdfw.sys [2008-03-17 21:58]
R1 F-Secure HIPS;F-Secure HIPS;C:\Program\Bredbandsbolaget Security Services\HIPS\fshs.sys [2008-03-03 12:31]
R3 CONAN;CONAN;C:\WINDOWS\system32\drivers\o2mmb.sys [2004-12-18 07:06]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;C:\Program\Bredbandsbolaget Security Services\Anti-Virus\minifilter\fsgk.sys [2007-04-26 19:07]
R3 MbxStby;MbxStby;C:\WINDOWS\system32\drivers\MbxStby.sys [2004-12-23 02:59]
S3 EpmShd;Acer EPM System Hardware Driver;C:\WINDOWS\system32\Drivers\epm-shd.sys []
S3 odysseyIM4;Odyssey Network Agent Miniport;C:\WINDOWS\system32\DRIVERS\odysseyIM4.sys [2005-06-10 06:55]
S3 sea1bus;Sony Ericsson Device 0A1 driver (WDM);C:\WINDOWS\system32\DRIVERS\sea1bus.sys [2007-02-08 12:55]
S3 sea1mdfl;Sony Ericsson Device 0A1 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\sea1mdfl.sys [2007-02-08 12:55]
S3 sea1mdm;Sony Ericsson Device 0A1 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\sea1mdm.sys [2007-02-08 12:55]
S3 sea1mgmt;Sony Ericsson Device 0A1 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\sea1mgmt.sys [2007-02-08 12:56]
S3 sea1nd5;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (NDIS);C:\WINDOWS\system32\DRIVERS\sea1nd5.sys [2007-02-08 12:56]
S3 sea1obex;Sony Ericsson Device 0A1 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\sea1obex.sys [2007-02-08 12:56]
S3 sea1unic;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (WDM);C:\WINDOWS\system32\DRIVERS\sea1unic.sys [2007-02-08 12:56]
S3 StreamSurge;StreamSurge Driver (miniport);C:\WINDOWS\system32\DRIVERS\ss.sys []
S4 F-Secure Filter;F-Secure File System Filter;C:\Program\Bredbandsbolaget Security Services\Anti-Virus\Win2K\FSfilter.sys [2007-04-26 19:08]
S4 F-Secure Recognizer;F-Secure File System Recognizer;C:\Program\Bredbandsbolaget Security Services\Anti-Virus\Win2K\FSrec.sys [2007-04-26 19:08]
.
Contents of the ‘Scheduled Tasks’ folder
“2007-04-18 09:03:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job”
- C:\Program\Apple Software Update\SoftwareUpdate.exe
“2008-05-06 14:55:16 C:\WINDOWS\Tasks\Scheduled scanning task.job”
- C:\Program\BREDBA~2\ANTI-V~1\fsav.exeP /HARD /POLICY /SCHED /NOBREAK /REPORT=C:\Program\BREDBA~2\ANTI-V~1\report.txt
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-06 22:26:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program\Intel\Wireless\Bin\EvtEng.exe
C:\Program\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\scardsvr.exe
C:\Program\Intel\Wireless\Bin\ZCfgSvc.exe
C:\Program\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program\WIDCOMM\Bluetooth-programvara\bin\btwdins.exe
C:\Program\Bredbandsbolaget Security Services\Anti-Virus\fsgk32st.exe
C:\Program\Bredbandsbolaget Security Services\Common\FSMA32.EXE
C:\Program\Bredbandsbolaget Security Services\Anti-Virus\fsgk32.exe
C:\Program\Intel\Wireless\Bin\OProtSvc.exe
C:\Program\Bredbandsbolaget Security Services\Common\FSMB32.EXE
C:\Program\Delade filer\Protexis\License Service\PSIService.exe
C:\Program\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program\Bredbandsbolaget Security Services\Common\FCH32.EXE
C:\Program\Bredbandsbolaget Security Services\Anti-Virus\fssm32.exe
C:\Program\Bredbandsbolaget Security Services\Common\FAMEH32.EXE
C:\Program\Bredbandsbolaget Security Services\Anti-Virus\fsqh.exe
C:\Program\Bredbandsbolaget Security Services\FSAUA\program\fsaua.exe
C:\Program\Bredbandsbolaget Security Services\FWES\program\fsdfwd.exe
C:\Program\Bredbandsbolaget Security Services\FSAUA\program\fsus.exe
C:\Program\BREDBA~2\ANTI-V~1\fsav32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program\BREDBA~2\Common\FSM32.EXE
C:\Program\Bredbandsbolaget Security Services\FSGUI\fsguidll.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-05-06 22:32:01 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-06 20:31:42
Pre-Run: 26,482,782,208 byte ledigt
Post-Run: 26,877,698,048 byte ledigt
227 — E O F — 2008-04-20 22:28:03
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:13:50 PM, on 5/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program\Intel\Wireless\Bin\EvtEng.exe
C:\Program\Intel\Wireless\Bin\S24EvMon.exe
C:\Program\Intel\Wireless\Bin\ZcfgSvc.exe
C:\Program\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program\WIDCOMM\Bluetooth-programvara\bin\btwdins.exe
C:\Program\Bredbandsbolaget Security Services\Anti-Virus\fsgk32st.exe
C:\Program\Bredbandsbolaget Security Services\Common\FSMA32.EXE
C:\Program\Bredbandsbolaget Security Services\Anti-Virus\FSGK32.EXE
C:\Program\Intel\Wireless\Bin\OProtSvc.exe
C:\Program\Bredbandsbolaget Security Services\Common\FSMB32.EXE
C:\Program\Delade filer\Protexis\License Service\PSIService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program\Intel\Wireless\Bin\RegSrvc.exe
C:\Program\Bredbandsbolaget Security Services\Common\FCH32.EXE
C:\Program\Bredbandsbolaget Security Services\Common\FAMEH32.EXE
C:\Program\Bredbandsbolaget Security Services\Anti-Virus\fsqh.exe
C:\Program\Bredbandsbolaget Security Services\FSAUA\program\fsaua.exe
C:\Program\Bredbandsbolaget Security Services\Anti-Virus\fssm32.exe
C:\Program\Bredbandsbolaget Security Services\FWES\Program\fsdfwd.exe
C:\Program\Bredbandsbolaget Security Services\FSAUA\program\fsus.exe
C:\Program\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program\Bredbandsbolaget Security Services\Anti-Virus\fsav32.exe
C:\Program\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program\Intel\Wireless\Bin\EOUWiz.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program\Bredbandsbolaget Security Services\Common\FSM32.EXE
C:\Program\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program\Delade filer\InstallShield\UpdateService\issch.exe
C:\Program\Java\jre1.6.0_05\bin\jusched.exe
C:\Program\Samsung\Samsung Media Studio 5\SMSTray.exe
C:\Program\Bredbandsbolaget Security Services\FSGUI\fsguidll.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program\Gadu-Gadu\gg.exe
C:\Program\DNA\btdna.exe
C:\Program\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.se/0SESVSE/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: Länkhjälp till Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Delade filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program\FlashGet\jccatch.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program\MICROS~3\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Servicecenter Plugin - {DB87CDE1-EF9C-44EB-A42F-6D0B3C72C516} - C:\Program\Bredbandsbolaget\Servicecenter\IEFixItNowPlugin.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program\FlashGet\getflash.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program\google\googletoolbar1.dll
O4 - HKLM…\Run: [ATIPTA] “C:\Program\ATI Technologies\ATI Control Panel\atiptaxx.exe”
O4 - HKLM…\Run: [Genväg till egenskapssida för High Definition Audio] HDAudPropShortcut.exe
O4 - HKLM…\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM…\Run: [intelWireless] C:\Program\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM…\Run: [EOUApp] C:\Program\Intel\Wireless\Bin\EOUWiz.exe
O4 - HKLM…\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,BluetoothAuthenticationAgent
O4 - HKLM…\Run: [QuickTime Task] “C:\Program\QuickTime\qttask.exe” -atboottime
O4 - HKLM…\Run: [soundMan] SOUNDMAN.EXE
O4 - HKLM…\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM…\Run: [F-Secure Manager] “C:\Program\Bredbandsbolaget Security Services\Common\FSM32.EXE” /splash
O4 - HKLM…\Run: [F-Secure TNB] “C:\Program\Bredbandsbolaget Security Services\FSGUI\TNBUtil.exe” /CHECKALL /WAITFORSW
O4 - HKLM…\Run: [NBKeyScan] “C:\Program\Nero\Nero8\Nero BackItUp\NBKeyScan.exe”
O4 - HKLM…\Run: [GrooveMonitor] “C:\Program\Microsoft Office\Office12\GrooveMonitor.exe”
O4 - HKLM…\Run: [iSUSPM Startup] C:\Program\DELADE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM…\Run: [iSUSScheduler] “C:\Program\Delade filer\InstallShield\UpdateService\issch.exe” -start
O4 - HKLM…\Run: [sunJavaUpdateSched] “C:\Program\Java\jre1.6.0_05\bin\jusched.exe”
O4 - HKLM…\Run: [Adobe Reader Speed Launcher] “C:\Program\Adobe\Reader 8.0\Reader\Reader_sl.exe”
O4 - HKLM…\Run: [sMSTray] C:\Program\Samsung\Samsung Media Studio 5\SMSTray.exe
O4 - HKLM…\Run: [sony Ericsson PC Suite] “C:\Program\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe” /startoptions
O4 - HKCU…\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU…\Run: [Nero PhotoShow Media Manager] C:\Program\Nero\PHOTOS~1\data\Xtras\mssysmgr.exe
O4 - HKCU…\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] “C:\Program\Delade filer\Nero\Lib\NMBgMonitor.exe”
O4 - HKCU…\Run: [Gadu-Gadu] “C:\Program\Gadu-Gadu\gg.exe” /tray
O4 - HKCU…\Run: [bitTorrent DNA] “C:\Program\DNA\btdna.exe”
O4 - HKUS\S-1-5-19…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘LOKAL TJÄNST’)
O4 - HKUS\S-1-5-20…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘NETWORK SERVICE’)
O4 - HKUS\S-1-5-18…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)
O4 - HKUS.DEFAULT…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)
O8 - Extra context menu item: Œci¹gnij przy pomocy FlashGet’a - C:\Program\FlashGet\jc_link.htm
O8 - Extra context menu item: Œci¹gnij wszystko przy pomocy FlashGet’a - C:\Program\FlashGet\jc_all.htm
O8 - Extra context menu item: Eksportuj do programu Microsoft Excel - res://C:\Program\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Skicka till Bluetooth - C:\Program\WIDCOMM\Bluetooth-programvara\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra ‘Tools’ menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Wyslij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra ‘Tools’ menuitem: Wyslij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program\WIDCOMM\Bluetooth-programvara\btsendto_ie.htm
O9 - Extra ‘Tools’ menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program\WIDCOMM\Bluetooth-programvara\btsendto_ie.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program\FlashGet\FlashGet.exe
O9 - Extra ‘Tools’ menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://downloadcenter.samsung.com/conte … ite_EN.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {3D8700FB-86A4-4CB4-B738-6F0FC016AC7D} (MainControl Class) - http://slimak.onet.pl/_m/wirusy/ArcaOnline.cab
O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} (king.com) - http://www.king.com/ctl/kingcomie.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda … 8938470031
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} - http://www.postfoto.se/aurigma/ImageUploader4.cab
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://se.photobox.com/clients/uploader_v2.2.0.6.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program\MICROS~3\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program\DELADE~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program\WIDCOMM\Bluetooth-programvara\bin\btwdins.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program\Bredbandsbolaget Security Services\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program\Bredbandsbolaget Security Services\FSAUA\program\fsaua.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program\Bredbandsbolaget Security Services\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program\Bredbandsbolaget Security Services\Common\FSMA32.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: OwnershipProtocol - Intel Corporation - C:\Program\Intel\Wireless\Bin\OProtSvc.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Program\Delade filer\Protexis\License Service\PSIService.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program\Intel\Wireless\Bin\S24EvMon.exe
–
End of file - 11935 bytes