OTS logfile created on: 26/06/2009 20:00:47 - Run 2
OTS by OldTimer - Version 3.0.8.0 Folder = C:\Documents and Settings\עדן\שולחן העבודה
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 0000040D | Country: ישר×ל | Language: HEB | Date Format: dd/MM/yyyy
511.48 Mb Total Physical Memory | 340.32 Mb Available Physical Memory | 66.54% Memory free
1.22 Gb Paging File | 1.06 Gb Available in Paging File | 86.94% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 24.46 Gb Free Space | 21.88% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: TAP-7409E23BDD
Current User Name: עדן
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: Off
File Age = 30 Days
[Processes - Safe List]
explorer.exe -> C:\WINDOWS\Explorer.EXE -> [2007/06/13 16:21:34 | 01,201,664 | ---- | M] (Microsoft Corporation)
googleupdate.exe -> C:\Documents and Settings\עדן\Local Settings\Application Data\Google\Update\GoogleUpdate.exe -> [2009/06/13 11:45:57 | 00,133,104 | ---- | M] (Google Inc.)
nmbgmonitor.exe -> C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe -> [2006/08/22 10:52:02 | 00,094,208 | ---- | M] (Nero AG)
nvsvc32.exe -> C:\WINDOWS\System32\nvsvc32.exe -> [2004/09/30 08:35:00 | 00,127,043 | ---- | M] (NVIDIA Corporation)
ots.exe -> C:\Documents and Settings\עדן\שולחן העבודה\OTS.exe -> [2009/06/26 19:58:04 | 00,510,976 | ---- | M] (OldTimer Tools)
soundman.exe -> C:\WINDOWS\SOUNDMAN.EXE -> [2004/09/16 15:39:44 | 00,069,632 | R--- | M] (Realtek Semiconductor Corp.)
wscntfy.exe -> C:\WINDOWS\System32\wscntfy.exe -> [2004/08/27 15:00:00 | 00,013,824 | ---- | M] (Microsoft Corporation)
[Win32 Services - Safe List]
(Adobe LM Service) Adobe LM Service [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe -> [2008/03/13 14:13:57 | 00,072,704 | ---- | M] (Adobe Systems)
(aspnet_state) ASP.NET State Service [Win32_Own | On_Demand | Stopped] -> C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -> [2007/10/24 02:47:22 | 00,033,800 | ---- | M] (Microsoft Corporation)
(clr_optimization_v2.0.50727_32) .NET Runtime Optimization Service v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2007/10/24 02:47:40 | 00,070,144 | ---- | M] (Microsoft Corporation)
(FontCache3.0.0.0) Windows Presentation Foundation Font Cache 3.0.0.0 [Win32_Own | On_Demand | Stopped] -> c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe -> [2007/10/09 13:58:12 | 00,036,864 | ---- | M] (Microsoft Corporation)
(helpsvc) Help and Support [Win32_Shared | Auto | Running] -> C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -> [2004/08/27 15:00:00 | 00,038,912 | ---- | M] (Microsoft Corporation)
(idsvc) Windows CardSpace [Win32_Shared | Unknown | Stopped] -> C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -> [2007/10/11 10:55:10 | 00,864,256 | ---- | M] (Microsoft Corporation)
(NBService) NBService [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe -> [2006/08/08 22:15:50 | 00,208,896 | ---- | M] (Nero AG)
(NetTcpPortSharing) Net.Tcp Port Sharing Service [Win32_Shared | Disabled | Stopped] -> C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -> [2007/10/11 10:55:14 | 00,122,880 | ---- | M] (Microsoft Corporation)
(NVSvc) NVIDIA Display Driver Service [Win32_Own | Auto | Running] -> C:\WINDOWS\System32\nvsvc32.exe -> [2004/09/30 08:35:00 | 00,127,043 | ---- | M] (NVIDIA Corporation)
(WMPNetworkSvc) Windows Media Player Network Sharing Service [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Windows Media Player\WMPNetwk.exe -> [2006/12/01 13:06:10 | 00,908,800 | ---- | M] (Microsoft Corporation)
[Driver Services - Safe List]
(ADILOADER) General Purpose USB Driver (adildr.sys) [Kernel | Auto | Stopped] -> C:\WINDOWS\System32\Drivers\adildr.sys -> [2002/10/11 11:19:00 | 00,046,551 | ---- | M] (Analog Deivces)
(adiusbaw) USB ADSL WAN Adapter [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\adiusbaw.sys -> [2002/12/18 19:13:34 | 00,122,121 | ---- | M] (Analog Devices Inc.)
(ALCXWDM) Service for Realtek AC97 Audio (WDM) [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\drivers\ALCXWDM.SYS -> [2004/09/21 14:53:18 | 02,278,784 | R--- | M] (Realtek Semiconductor Corp.)
(DumaNT) NVIDIA Stereo Helper Service [Kernel | System | Running] -> C:\WINDOWS\System32\DRIVERS\dumant.sys -> [2002/11/18 15:29:26 | 00,399,700 | ---- | M] (NVIDIA Corporation)
(EL90X) 3Com EtherLink XL 90X Adapter Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\el90xnd5.sys -> [2001/09/18 15:26:38 | 00,153,631 | ---- | M] (3Com Corporation)
(gameenum) Game Port Enumerator [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\gameenum.sys -> [2004/08/04 00:08:22 | 00,010,624 | ---- | M] (Microsoft Corporation)
(NEOFLTR_600_12507) Juniper Networks TDI Filter Driver (NEOFLTR_600_12507) [Kernel | System | Running] -> C:\WINDOWS\System32\Drivers\NEOFLTR_600_12507.SYS -> [2007/12/28 06:23:10 | 00,064,160 | ---- | M] (Juniper Networks)
(nv) nv [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\nv4_mini.sys -> [2004/09/30 08:35:00 | 02,743,840 | ---- | M] (NVIDIA Corporation)
(Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\ptilink.sys -> [2004/08/27 15:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.)
(PxHelp20) PxHelp20 [Kernel | Boot | Running] -> C:\WINDOWS\System32\Drivers\PxHelp20.sys -> [2007/03/08 02:51:00 | 00,043,528 | ---- | M] (Sonic Solutions)
(Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\secdrv.sys -> [2007/11/13 13:25:54 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(sptd) sptd [Kernel | Boot | Running] -> C:\WINDOWS\System32\Drivers\sptd.sys -> [2008/01/01 16:53:43 | 00,715,248 | ---- | M] ()
(usbaudio) USB Audio Driver (WDM) [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\drivers\usbaudio.sys -> [2004/08/04 02:07:56 | 00,059,264 | ---- | M] (Microsoft Corporation)
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" ->
http://go.microsoft.com/fwlink/?LinkId=69157 ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" ->
http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" -> [binary data] ->
HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons ->
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm ->
HKEY_LOCAL_MACHINE\: Main\\"Search Page" ->
http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk ->
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> about:blank ->
HKEY_LOCAL_MACHINE\: Search\\"CustomizeSearch" ->
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm ->
HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" ->
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm ->
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> ->
HKEY_CURRENT_USER\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm ->
HKEY_CURRENT_USER\: Main\\"Page_Transitions" -> 1 ->
HKEY_CURRENT_USER\: Main\\"Search Page" ->
http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch ->
HKEY_CURRENT_USER\: Main\\"Start Page" ->
http://www.google.co.il/ ->
HKEY_CURRENT_USER\: "ProxyEnable" -> 0 ->
< FireFox Settings [Prefs.js] > -> C:\Documents and Settings\עדן\Application Data\Mozilla\FireFox\Profiles\sx612zxc.default\prefs.js ->
browser.search.update -> false ->
browser.startup.homepage -> "
http://www.google.co.uk/" ->
extensions.enabledItems -> {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.11 ->
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
HKLM\software\mozilla\Firefox\Extensions -> ->
HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c} -> C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\MOZILLA\FIREFOX EXTENSIONS\{3112CA9C-DE6D-4884-A869-9855DE68056C} [C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\MOZILLA\FIREFOX EXTENSIONS\{3112CA9C-DE6D-4884-A869-9855DE68056C}] -> [2007/06/19 11:44:00 | 00,000,000 | ---D | M]
HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions -> ->
HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Components -> C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS] -> [2009/06/13 12:13:43 | 00,000,000 | ---D | M]
HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Plugins -> C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS] -> [2009/06/13 12:13:35 | 00,000,000 | ---D | M]
< FireFox Extensions [User Folders] > ->
-> C:\Documents and Settings\עדן\Application Data\mozilla\Extensions -> [2009/06/13 12:13:43 | 00,000,000 | ---D | M]
-> C:\Documents and Settings\עדן\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} -> [2009/06/13 12:13:43 | 00,000,000 | ---D | M]
-> C:\Documents and Settings\עדן\Application Data\mozilla\Firefox\Profiles\sx612zxc.default\extensions -> [2009/06/13 12:13:52 | 00,096,232 | ---- | M] ()
< FireFox Extensions [Program Folders] > ->
-> C:\PROGRAM FILES\MOZILLA FIREFOX\extensions -> [2009/06/03 07:24:27 | 09,777,144 | ---- | M] (Mozilla Foundation)
-> C:\PROGRAM FILES\MOZILLA FIREFOX\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} -> [2009/06/03 07:24:27 | 09,777,144 | ---- | M] (Mozilla Foundation)
< FireFox Components [Program Folders] > ->
C:\PROGRAM FILES\MOZILLA FIREFOX\components\ -> C:\PROGRAM FILES\MOZILLA FIREFOX\components -> [2009/06/13 12:13:43 | 00,000,000 | ---D | M]
browserdirprovider.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\components\browserdirprovider.dll -> [2009/06/03 07:24:27 | 00,023,032 | ---- | M] (Mozilla Foundation)
brwsrcmp.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\components\brwsrcmp.dll -> [2009/06/03 07:24:27 | 00,134,648 | ---- | M] (Mozilla Foundation)
< FireFox Plugins [Program Folders] > ->
C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\ -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins -> [2009/06/13 12:13:35 | 00,000,000 | ---D | M]
npnul32.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npnul32.dll -> [2009/06/03 07:24:27 | 00,065,528 | ---- | M] (mozilla.org)
< FireFox SearchPlugins [Program Folders] > ->
C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\ -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins -> [2009/06/13 12:13:38 | 00,000,000 | ---D | M]
amazon-en-GB.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\amazon-en-GB.xml -> [2008/01/04 18:36:50 | 00,001,538 | ---- | M] ()
answers.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\answers.xml -> [2006/07/05 21:47:38 | 00,002,193 | ---- | M] ()
chambers-en-GB.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\chambers-en-GB.xml -> [2008/01/04 18:36:50 | 00,000,947 | ---- | M] ()
creativecommons.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\creativecommons.xml -> [2008/03/08 12:35:22 | 00,001,534 | ---- | M] ()
eBay-en-GB.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\eBay-en-GB.xml -> [2008/09/22 22:14:04 | 00,000,759 | ---- | M] ()
google.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\google.xml -> [2008/04/16 07:08:20 | 00,001,706 | ---- | M] ()
wikipedia.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\wikipedia.xml -> [2008/03/28 21:11:14 | 00,001,178 | ---- | M] ()
yahoo-en-GB.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\yahoo-en-GB.xml -> [2008/01/04 18:36:50 | 00,000,831 | ---- | M] ()
< HOSTS File > (686 bytes and 19 lines) -> C:\WINDOWS\System32\drivers\etc\Hosts ->
Reset Hosts
127.0.0.1 localhost
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> [2006/10/23 00:08:42 | 00,062,080 | ---- | M] (Adobe Systems Incorporated)
{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> C:\Program Files\Spybot - Search & Destroy2\SDHelper.dll [Spybot-S&D IE Protection] -> [2008/01/28 12:43:28 | 01,554,256 | ---- | M] (Safer Networking Limited)
{5C255C8A-E604-49b4-9D64-90988571CECB} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll [SSVHelper Class] -> [2007/09/25 02:11:33 | 00,501,136 | ---- | M] (Sun Microsystems, Inc.)
{9030D464-4C02-4ABF-8ECC-5164760863C6} [HKLM] -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [עוזר ×”×›× ×™×¡×” של Windows Live] -> [2009/01/22 15:41:30 | 00,408,448 | ---- | M] (Microsoft Corporation)
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ ->
WebBrowser\\"{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"BluetoothAuthenticationAgent" -> C:\WINDOWS\System32\bthprops.cpl [rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent] -> [2004/08/27 15:00:00 | 00,110,592 | ---- | M] (Microsoft Corporation)
"KernelFaultCheck" -> [%systemroot%\system32\dumprep 0 -k] -> File not found
"NeroFilterCheck" -> C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe] -> [2006/01/12 17:40:44 | 00,155,648 | ---- | M] (Nero AG)
"NvCplDaemon" -> C:\WINDOWS\System32\NvCpl.DLL [RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup] -> [2004/09/30 08:35:00 | 04,603,904 | ---- | M] (NVIDIA Corporation)
"NvMediaCenter" -> C:\WINDOWS\System32\NvMcTray.DLL [RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit] -> [2004/09/30 08:35:00 | 00,086,016 | ---- | M] (NVIDIA Corporation)
"nwiz" -> C:\WINDOWS\System32\nwiz.exe [nwiz.exe /install] -> [2004/09/30 08:35:00 | 00,921,600 | ---- | M] (NVIDIA Corporation)
"PHIME2002A" -> C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE [C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName] -> [2004/08/27 15:00:00 | 00,455,168 | ---- | M] (Microsoft Corporation)
"PHIME2002ASync" -> [C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC] -> File not found
"QuickTime Task" -> C:\Program Files\QuickTime\qttask.exe ["C:\Program Files\QuickTime\qttask.exe" -atboottime] -> [2008/03/20 22:33:53 | 00,385,024 | ---- | M] (Apple Inc.)
"SoundMan" -> C:\WINDOWS\SOUNDMAN.EXE [SOUNDMAN.EXE] -> [2004/09/16 15:39:44 | 00,069,632 | R--- | M] (Realtek Semiconductor Corp.)
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}" -> C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe ["C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"] -> [2006/08/22 10:52:02 | 00,094,208 | ---- | M] (Nero AG)
"Google Update" -> C:\Documents and Settings\עדן\Local Settings\Application Data\Google\Update\GoogleUpdate.exe ["C:\Documents and Settings\עדן\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c] -> [2009/06/13 11:45:57 | 00,133,104 | ---- | M] (Google Inc.)
"msnmsgr" -> C:\Program Files\Windows Live\Messenger\msnmsgr.exe ["C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background] -> [2009/02/06 18:52:08 | 03,885,408 | ---- | M] (Microsoft Corporation)
< All Users.WINDOWS Startup Folder > -> C:\Documents and Settings\All Users.WINDOWS\תפריט התחלה\×ª×•×›× ×™×•×ª\הפעלה ->
C:\Documents and Settings\All Users.WINDOWS\תפריט התחלה\×ª×•×›× ×™×•×ª\הפעלה\Microsoft Office.lnk -> C:\Program Files\Microsoft Office\Office10\OSA.EXE -> [2001/02/13 03:01:04 | 00,083,360 | ---- | M] (Microsoft Corporation)
< עדן Startup Folder > -> C:\Documents and Settings\עדן\תפריט התחלה\×ª×•×›× ×™×•×ª\הפעלה ->
C:\Documents and Settings\עדן\תפריט התחלה\×ª×•×›× ×™×•×ª\הפעלה\Adobe Gamma.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe -> [1999/11/04 16:06:48 | 00,113,664 | ---- | M] (Adobe Systems, Inc.)
< Software Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer ->
< Software Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer ->
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveAutoRun" -> [67108863] -> File not found
\\"NoDriveTypeAutoRun" -> [323] -> File not found
\\"NoDrives" ->
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"dontdisplaylastusername" ->
\\"legalnoticecaption" -> [] -> File not found
\\"legalnoticetext" -> [] -> File not found
\\"shutdownwithoutlogon" -> [1] -> File not found
\\"undockwithoutlogon" -> [1] -> File not found
\\"DisableRegistryTools" ->
< CurrentVersion Policy Settings - Explorer [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [323] -> File not found
\\"NoDriveAutoRun" -> [67108863] -> File not found
\\"NoDrives" ->
< CurrentVersion Policy Settings - System [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
< Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ ->
&×™×¦× ×œ- Microsoft Excel -> C:\Program Files\Microsoft Office\Office10\EXCEL.EXE [res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000] -> [2008/01/29 12:41:28 | 09,364,480 | R--- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} [HKLM] -> C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll [Menu: Sun Java Console] -> [2007/09/25 02:11:34 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
{B863453A-26C3-4e1f-A54D-A2CD196348E9}:Exec [HKLM] -> C:\Program Files\ICQLite\ICQLite.exe [Button: ICQ Lite] -> File not found
{B863453A-26C3-4e1f-A54D-A2CD196348E9}:Exec [HKLM] -> C:\Program Files\ICQLite\ICQLite.exe [Menu: ICQ Lite] -> File not found
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}:{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> C:\Program Files\Spybot - Search & Destroy2\SDHelper.dll [Menu: Spybot - Search & Destroy Configuration] -> [2008/01/28 12:43:28 | 01,554,256 | ---- | M] (Safer Networking Limited)
{e2e2dd38-d088-4134-82b7-f2ba38496583}:Exec [HKLM] -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [Menu: @xpsp3res.dll,-20001] -> [2006/10/10 15:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation)
{E59EB121-F339-4851-A3BA-FE49C35617C2}:Exec [HKLM] -> C:\Program Files\ICQ6\ICQ.exe [Button: ICQ6] -> [2008/09/01 18:08:21 | 00,173,304 | ---- | M] (ICQ, Inc.)
{E59EB121-F339-4851-A3BA-FE49C35617C2}:Exec [HKLM] -> C:\Program Files\ICQ6\ICQ.exe [Menu: ICQ6] -> [2008/09/01 18:08:21 | 00,173,304 | ---- | M] (ICQ, Inc.)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Button: Messenger] -> [2004/10/13 19:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Menu: Windows Messenger] -> [2004/10/13 19:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\"{B863453A-26C3-4e1f-A54D-A2CD196348E9}" [HKLM] -> C:\Program Files\ICQLite\ICQLite.exe [ICQ Lite] -> File not found
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Messenger] -> [2004/10/13 19:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation)
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
PluginsPageFriendlyName -> Microsoft ActiveX Gallery ->
PluginsPage ->
http://activex.microsoft.com/controls/find...=%s&mime=%s ->
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 4239 domain(s) found. ->
33 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. ->
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 4251 domain(s) found. ->
32 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 93 range(s) found. ->
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} [HKLM] ->
http://appldnld.apple.com.edgesuite.net/co...ex/qtplugin.cab [QuickTime Plugin Control] ->
{02ECD07A-22D0-4AF0-BA0A-3F6B06086D08} [HKLM] ->
http://xiah.gamescampus.com/luncher/GamesCampus.cab [GamesCampus Control] ->
{17492023-C23A-453E-A040-C7C580BBF700} [HKLM] ->
http://download.microsoft.com/download/5/b...heckControl.cab [Windows Genuine Advantage Validation Tool] ->
{20A60F0D-9AFA-4515-A0FD-83BD84642501} [HKLM] ->
http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab [Checkers Class] ->
{233C1507-6A77-46A4-9443-F871F945D258} [HKLM] ->
http://download.macromedia.com/pub/shockwa...director/sw.cab [Shockwave ActiveX Control] ->
{33564D57-0000-0010-8000-00AA00389B71} [HKLM] ->
http://download.microsoft.com/download/F/6...922/wmv9VCM.CAB [Reg Error: Key error.] ->
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} [HKLM] ->
http://www.update.microsoft.com/microsoftu...b?1202306177953 [MUWebControl Class] ->
{784797A8-342D-4072-9486-03C8D0F2F0A1} [HKLM] ->
https://play.battlefield-heroes.com/static/...er_4.0.15.0.cab [Battlefield Heroes Updater] ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] ->
http://javadl-esd.sun.com/update/1.6.0/jin...ows-i586-jc.cab [Java Plug-in 1.6.0_03] ->
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} [HKLM] ->
http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab [Reg Error: Key error.] ->
{A90A5822-F108-45AD-8482-9BC8B12DD539} [HKLM] ->
http://www.crucial.com/controls/cpcScanner.cab [Crucial cpcScan] ->
{C3F79A2B-B9B4-4A66-B012-3EE46475B072} [HKLM] ->
http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab [MessengerStatsClient Class] ->
{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} [HKLM] ->
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab [Java Plug-in 1.6.0_03] ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] ->
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab [Java Plug-in 1.6.0_03] ->
{CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} [HKLM] ->
http://www.adobe.com/products/acrobat/nos/gp.cab [get_atlcom Class] ->
{E5F5D008-DD2C-4D32-977D-1A0ADF03058B} [HKLM] ->
https://ssl.sonol.co.il/dana-cached/setup/J...perSetupSP1.cab [JuniperSetupSP1 Control] ->
{F59AB0C4-3443-4551-A78F-C101F9DE0215} [HKLM] ->
http://irc.nana.co.il/Cabs/launcher39.cab [Reg Error: Key error.] ->
{F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} [HKLM] ->
http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab [Minesweeper Flags Class] ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ ->
DhcpNameServer -> 10.0.0.138 ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{05E2438F-3031-492D-B72B-71C15ECD9249}\\DhcpNameServer -> 10.0.0.138 (מת×× ××ª×¨× ×˜ 3Com 3C905TX-based (כללי)) ->
{66E548E8-DA0E-4FD2-941F-A76CDE410636}\\DhcpNameServer -> 10.0.0.138 (מת×× ××ª×¨× ×˜ 3Com 3C905TX-based (כללי)) ->
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
Explorer.exe -> C:\WINDOWS\explorer.exe -> [2007/06/13 16:21:34 | 01,201,664 | ---- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List ->
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\System32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2004/08/27 15:00:00 | 00,140,800 | ---- | M] (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" -> C:\Program Files\Windows Live\Messenger\msnmsgr.exe [C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger] -> [2009/02/06 18:52:08 | 03,885,408 | ---- | M] (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" -> C:\Program Files\Windows Live\Messenger\wlcsdk.exe [C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call] -> [2009/02/06 18:21:00 | 00,583,024 | ---- | M] (Microsoft Corporation)
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List ->
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\System32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2004/08/27 15:00:00 | 00,140,800 | ---- | M] (Microsoft Corporation)
"C:\Documents and Settings\עדן\Application Data\Juniper Networks\Juniper Terminal Services Client\dsTermServ.exe" -> C:\Documents and Settings\עדן\Application Data\Juniper Networks\Juniper Terminal Services Client\dsTermServ.exe [C:\Documents and Settings\עדן\Application Data\Juniper Networks\Juniper Terminal Services Client\dsTermServ.exe:*:Enabled:Juniper Terminal Services Client] -> [2007/12/28 06:39:00 | 00,120,192 | ---- | M] (Juniper Networks)
"C:\Documents and Settings\עדן\שולחן העבודה\new.logic.1.1.beta.1a\emule.exe" -> C:\Documents and Settings\עדן\שולחן העבודה\new.logic.1.1.beta.1a\emule.exe [C:\Documents and Settings\עדן\שולחן העבודה\new.logic.1.1.beta.1a\emule.exe:*:Enabled:eMule] -> File not found
"C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe" -> C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe [C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe:*:Enabled:NEXON_EU_Downloader_Engine] -> [2009/02/13 16:53:40 | 00,966,656 | ---- | M] ()
"C:\Program Files\ICQ6\ICQ.exe" -> C:\Program Files\ICQ6\ICQ.exe [C:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6] -> [2008/09/01 18:08:21 | 00,173,304 | ---- | M] (ICQ, Inc.)
"C:\Program Files\Juniper Networks\Secure Application Manager\dsSamProxy.exe" -> C:\Program Files\Juniper Networks\Secure Application Manager\dsSamProxy.exe [C:\Program Files\Juniper Networks\Secure Application Manager\dsSamProxy.exe:*:Enabled:Secure Application Manager Proxy] -> [2007/12/28 06:23:06 | 00,390,536 | ---- | M] (Juniper Networks)
"C:\Program Files\mIRC\mirc.exe" -> C:\Program Files\mIRC\mirc.exe [C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC] -> [2009/06/19 11:32:30 | 02,756,096 | ---- | M] (mIRC Co. Ltd.)
"C:\Program Files\Tactical Ops\TacticalOps 1\System\TacticalOps.exe" -> C:\Program Files\Tactical Ops\TacticalOps 1\System\TacticalOps.exe [C:\Program Files\Tactical Ops\TacticalOps 1\System\TacticalOps.exe:*:Enabled:TacticalOps] -> [2005/10/05 07:11:50 | 00,233,472 | ---- | M] ()
"C:\Program Files\Tactical Ops\TacticalOps 2\System\TacticalOps.exe" -> C:\Program Files\Tactical Ops\TacticalOps 2\System\TacticalOps.exe [C:\Program Files\Tactical Ops\TacticalOps 2\System\TacticalOps.exe:*:Enabled:TacticalOps] -> [2005/10/04 21:11:50 | 00,233,472 | ---- | M] ()
"C:\Program Files\Tactical Ops\TacticalOps 3\System\TacticalOps.exe" -> C:\Program Files\Tactical Ops\TacticalOps 3\System\TacticalOps.exe [C:\Program Files\Tactical Ops\TacticalOps 3\System\TacticalOps.exe:*:Enabled:TacticalOps] -> [2005/10/04 21:11:50 | 00,233,472 | ---- | M] ()
"C:\Program Files\Tactical Ops\TacticalOps 4\System\TacticalOps.exe" -> C:\Program Files\Tactical Ops\TacticalOps 4\System\TacticalOps.exe [C:\Program Files\Tactical Ops\TacticalOps 4\System\TacticalOps.exe:*:Enabled:TacticalOps] -> [2005/10/04 21:11:50 | 00,233,472 | ---- | M] ()
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" -> C:\Program Files\Windows Live\Messenger\msnmsgr.exe [C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger] -> [2009/02/06 18:52:08 | 03,885,408 | ---- | M] (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" -> C:\Program Files\Windows Live\Messenger\wlcsdk.exe [C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call] -> [2009/02/06 18:21:00 | 00,583,024 | ---- | M] (Microsoft Corporation)
"C:\Program Files\Xfire\Xfire.exe" -> C:\Program Files\Xfire\Xfire.exe [C:\Program Files\Xfire\Xfire.exe:*:Enabled:Xfire] -> [2009/06/12 01:29:44 | 03,182,928 | ---- | M] (Xfire Inc.)
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot ->
"AlternateShell" -> cmd.exe ->
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 ->
"DisplayName" -> CD-ROM Driver ->
"ImagePath" -> [system32\DRIVERS\cdrom.sys] -> File not found
< Drives with AutoRun files > -> ->
C:\AUTOEXEC.BAT [] -> C:\AUTOEXEC.BAT [ NTFS ] -> [2004/04/30 19:13:50 | 00,000,000 | ---- | M] ()
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 ->
[Registry - Additional Scans - Safe List]
< File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>\ ->
.bat [@ = batfile] -> "%1" %* ->
.chm [@ = chm.file] -> C:\WINDOWS\hh.exe -> [2005/05/27 02:22:01 | 00,010,752 | ---- | M] (Microsoft Corporation)
.cmd [@ = cmdfile] -> "%1" %* ->
.com [@ = ComFile] -> "%1" %* ->
.exe [@ = exefile] -> "%1" %* ->
.html [@ = htmlfile] -> C:\Program Files\Internet Explorer\IEXPLORE.EXE -> [2008/04/22 10:41:30 | 00,625,664 | ---- | M] (Microsoft Corporation)
.pif [@ = piffile] -> "%1" %* ->
.scr [@ = scrfile] -> "%1" /S ->
< Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ ->
cdo:{CD00020A-8B95-11D1-82DB-00C04FB1625D} [HKLM] -> C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL[Microsoft PKM KnowledgePluggable Class] -> [2004/01/29 17:08:23 | 00,868,352 | ---- | M] (Microsoft Corporation)
ipp: [HKLM] -> No CLSID value
ipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} [HKLM] -> C:\Program Files\Common Files\System\OLE DB\msdaipp.dll[MSDAMON.BINDER] -> [2004/01/29 17:08:23 | 01,130,496 | ---- | M] (Microsoft Corporation)
livecall:{828030A1-22C1-4009-854F-8E305202313F} [HKLM] -> C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll[Reg Error: Value error.] -> [2009/02/06 18:52:44 | 00,062,304 | ---- | M] (Microsoft Corporation)
msdaipp: [HKLM] -> No CLSID value
msdaipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} [HKLM] -> C:\Program Files\Common Files\System\OLE DB\msdaipp.dll[MSDAMON.BINDER] -> [2004/01/29 17:08:23 | 01,130,496 | ---- | M] (Microsoft Corporation)
msdaipp\oledb:{E1D2BF40-A96B-11d1-9C6B-0000F875AC61} [HKLM] -> C:\Program Files\Common Files\System\OLE DB\msdaipp.dll[MSDAIPP.BINDER] -> [2004/01/29 17:08:23 | 01,130,496 | ---- | M] (Microsoft Corporation)
msnim:{828030A1-22C1-4009-854F-8E305202313F} [HKLM] -> C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll[Reg Error: Value error.] -> [2009/02/06 18:52:44 | 00,062,304 | ---- | M] (Microsoft Corporation)
mso-offdap:{3D9F03FA-7A94-11D3-BE81-0050048385D1} [HKLM] -> C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL[Data Page Pluggable Protocol mso-offdap Handler] -> [2008/01/24 16:22:56 | 07,255,384 | ---- | M] (Microsoft Corporation)
vnd.ms.radio:{3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} [HKLM] -> C:\Program Files\Monopol500\MSDXM.OCX[AsyncPProt Class] -> File not found
< Security Center Settings > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center
\\"FirstRunDisabled" -> [1] -> File not found
\\"AntiVirusDisableNotify" ->
\\"FirewallDisableNotify" ->
\\"UpdatesDisableNotify" ->
\\"AntiVirusOverride" ->
\\"FirewallOverride" ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring
\Monitoring\\"DisableMonitoring" -> [1] -> File not found
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus
\Monitoring\SymantecAntiVirus\\"DisableMonitoring" -> [1] -> File not found
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall
\Monitoring\SymantecFirewall\\"DisableMonitoring" -> [1] -> File not found
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\ -> ->
< Winsock2 Catalogs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\ ->
NameSpace_Catalog5\Catalog_Entries\000000000002 [Bluetooth Namespace] -> C:\WINDOWS\System32\wshbth.dll -> [2004/08/27 15:00:00 | 00,108,032 | ---- | M] (Microsoft Corporation)
NameSpace_Catalog5\Catalog_Entries\000000000003 [Juniper Secure DNS (Top)] -> C:\Program Files\Juniper Networks\Secure Application Manager\samnsp.dll -> [2007/12/28 06:23:04 | 00,071,032 | ---- | M] (Juniper Networks)
NameSpace_Catalog5\Catalog_Entries\000000000004 [Proxifier NSP] -> C:\WINDOWS\System32\PrxerNsp.dll -> [2007/02/28 16:56:34 | 00,061,440 | ---- | M] ( )
NameSpace_Catalog5\Catalog_Entries\000000000007 [Juniper Secure DNS (Bottom)] -> C:\Program Files\Juniper Networks\Secure Application Manager\samnsp.dll -> [2007/12/28 06:23:04 | 00,071,032 | ---- | M] (Juniper Networks)
Protocol_Catalog9\Catalog_Entries\000000000001 -> C:\WINDOWS\System32\PrxerDrv.dll -> [2007/09/25 15:40:32 | 00,073,728 | ---- | M] (Initex Software)
Protocol_Catalog9\Catalog_Entries\000000000005 -> C:\WINDOWS\System32\rsvpsp.dll -> [2004/08/27 15:00:00 | 00,090,112 | ---- | M] (Microsoft Corporation)
Protocol_Catalog9\Catalog_Entries\000000000006 -> C:\WINDOWS\System32\rsvpsp.dll -> [2004/08/27 15:00:00 | 00,090,112 | ---- | M] (Microsoft Corporation)
Protocol_Catalog9\Catalog_Entries\000000000008 -> C:\WINDOWS\System32\PrxerDrv.dll -> [2007/09/25 15:40:32 | 00,073,728 | ---- | M] (Initex Software)
< Uninstall List [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ ->
{048298C9-A4D3-490B-9FF9-AB023A9238F3} -> Steam
{18D10072035C4515918F7E37EAFAACFC} -> AutoUpdate
{205C6BDD-7B73-42DE-8505-9A093F35A238} -> כלי ההעל××” של Windows Live
{22B775E7-6C42-4FC5-8E10-9A5E3257BD94} -> MSVCRT
{236BB7C4-4419-42FD-0409-1E257A25E34D} -> Adobe Photoshop CS2
{2BA00471-0328-3743-93BD-FA813353A783} -> Microsoft .NET Framework 3.0 Service Pack 1
{3248F0A8-6813-11D6-A77B-00B0D0160030} -> Java(tm) 6 Update 3
{350C97B4-3D7C-4EE8-BAA9-00BCB3D54227} -> WebFldrs XP
{38E0C491-5230-4373-B62E-F1A6E94B1033} -> Nero 7 Ultra Edition
{3B4E636E-9D65-4D67-BA61-189800823F52} -> Windows Live Communications Platform
{3CEA4CA8-CDD4-451C-B673-E8F17BE01B15} -> Ulead COOL 360 1.0
{3D5C877F-8C4B-4623-BAD0-1BCD6FEA297B} -> Windows Live Essentials
{43DCF766-6838-4F9A-8C91-D92DA586DFA8} -> Microsoft Windows Journal Viewer
{4AE3A0CB-87B0-4F51-BECD-3D1F8DFDD62F} -> ECI USB ADSL
{60DE4033-9503-48D1-A483-7846BD217CA9} -> ICQ6
{6279F390-2AC9-11DD-6784-007F2D4018BE} -> Knight Empire
{63569CE9-FA00-469C-AF5C-E5D4D93ACF91} -> Windows Genuine Advantage v1.3.0254.0
{7197F874-B0E0-4A73-A880-7E712F4D0EB7}}_is1 -> Uninstall KnightOnline
{7299052b-02a4-4627-81f2-1818da5d550d} -> Microsoft Visual C++ 2005 Redistributable
{74EC78BC-B379-4E29-9006-8F161DCAABA6} -> Apple Software Update
{7784A172-61F1-445E-8368-601607E0DD22} -> MP3 Player Utilities 3.73
{786C5747-1033-0000-B58E-000000000001} -> Adobe Stock Photos 1.0
{789289CA-F73A-4A16-A331-54D498CE069F} -> Ventrilo Client
{7B63B2922B174135AFC0E1377DD81EC2} -> DivX Codec
{7C9AD221-994C-45B2-B46D-26F5735158CF} -> Sony Vegas Pro 8.0
{83FB9DEC-89ED-4D9D-AE85-F2752D107C79} -> Windows Live Messenger
{885A5214-9CDD-40E0-A89D-7672588748E1} -> Windows Live Call
{8ADFC4160D694100B5B8A22DE9DCABD9} -> DivX Player
{8EDBA74D-0686-4C99-BFDD-F894678E5B39} -> Adobe Common File Installer
{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E} -> Choice Guard
{9028040D-6000-11D3-8CFE-0050048383C9} -> Microsoft Office XP Professional ×¢× FrontPage
{908A2F10-4DFC-11DD-6784-03B71C4018BE} -> Knight Empire
{95120000-00B9-0409-0000-0000000FF1CE} -> Microsoft Application Error Reporting
{95774351-6087-3A3B-8CA8-70BEE49D2BD5} -> Google Gears
{9A25302D-30C0-39D9-BD6F-21E6EC160475} -> Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
{A0D6AA15-66B9-41BE-BA85-17EB8C84A685} -> Knight Online
{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7} -> Segoe UI
{A34386F8-7655-4E3B-9F51-D3064F607C89} -> blaxxun Contact
{AA7D532A-6C19-4168-A887-BF306A431B65} -> Game Cam Lite v1.4
{AC76BA86-7AD7-1033-7B44-A81200000003} -> Adobe Reader 8.1.2
{AF5E8D43-49AD-4BE7-A941-2BB0A8CACA62} -> ACDSee 5.0 Standard
{B13A7C41581B411290FBC0395694E2A9} -> DivX Converter
{B508B3F1-A24A-32C0-B310-85786919EF28} -> Microsoft .NET Framework 2.0 Service Pack 1
{B50C6AA0-1524-4285-A68C-003DDFF12073}_is1 -> Knight Empire V5.0
{B7050CBDB2504B34BC2A9CA0A692CC29} -> DivX Web Player
{B74D4E10-1033-0000-0000-000000000001} -> Adobe Bridge 1.0
{BAF78226-3200-4DB4-BE33-4D922A799840} -> Windows Presentation Foundation
{BCBA462D-3E1B-416C-89F8-492020D4BBF4} -> מסייע ×”×›× ×™×¡×” של Windows Live
{D271DAE0-8D68-4C97-8356-A126D48A1D8C} -> Ulead Photo Explorer 8.0 SE Basic
{DF3E37E0-06D5-4A1B-A264-BD2B7E30B458} -> Knight Online
{E9787678-1033-0000-8E67-000000000001} -> Adobe Help Center 1.0
Adobe Flash Player ActiveX -> Adobe Flash Player ActiveX
Adobe Flash Player Plugin -> Adobe Flash Player Plugin
Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D} -> Adobe Photoshop CS2
Adobe Shockwave Player -> Adobe Shockwave Player
CCleaner -> CCleaner (remove only)
ESE_Registration -> ESE Account Manager (remove only)
Fire eMule_is1 -> Fire eMule.co.il v7.1 (0.47c)
Fraps -> Fraps (remove only)
getPlus®_ocx -> getPlus®_ocx
GOM Player -> GOM Player
HijackThis -> HijackThis 2.0.2
IDNMitigationAPIs -> Microsoft Internationalized Domain Names Mitigation APIs
ie7 -> Windows Internet Explorer 7
Knight-Empire 5.4 -> Knight-Empire 5.4
Malwarebytes' Anti-Malware_is1 -> Malwarebytes' Anti-Malware
mIRC -> mIRC
Mozilla Firefox (3.0.11) -> Mozilla Firefox (3.0.11)
MSCompPackV1 -> Microsoft Compression Client Pack 1.0 for Windows XP
Neoteris_Secure_Application_Manager -> Juniper Networks Secure Application Manager
NLSDownlevelMapping -> Microsoft National Language Support Downlevel APIs
NVIDIA Drivers -> NVIDIA Drivers
NVIDIAStereo -> NVIDIA Windows 95/98/ME/2000/XP Stereo Drivers
Proxifier_is1 -> Proxifier version 2.7
Speed eMule_is1 -> Speed eMule.co.il v8.0 (0.48a)
Spybot - Search & Destroy_is1 -> Spybot - Search & Destroy 1.5.2.20
Teamspeak 2 RC2_is1 -> TeamSpeak 2 RC2
TeamSpeak 2 Server_is1 -> TeamSpeak 2 Server RC2
UnrealTournament -> Unreal Tournament G.O.T.Y. Edition
VentriloMIX -> VentriloMIX
WIC -> Windows Imaging Component
Windows Media Format Runtime -> Windows Media Format 11 runtime
Windows Media Player -> Windows Media Player 11
WinLiveSuite_Wave3 -> Windows Live Essentials
WinRAR archiver -> WinRAR archiver
WMFDist11 -> Windows Media Format 11 runtime
wmp11 -> Windows Media Player 11
WOW -> WOW
Wudf01000 -> Microsoft User-Mode Driver Framework Feature Pack 1.0
Xfire -> Xfire (remove only)
XpsEPSC -> XML Paper Specification Shared Components Pack 1.0
XviD -> XviD MPEG-4 Codec
< Uninstall List [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ ->
Google Chrome -> Google Chrome
Juniper_Networks_Cache_Cleaner 6.0.0 -> Juniper Networks Cache Cleaner 6.0.0
Juniper_Term_Services -> Juniper Terminal Services Client
Neoteris_Host_Checker -> Juniper Networks Host Checker
NoNameScript -> NoNameScript
< EventViewer Logs - Last 10 Errors > -> Event Information -> Description
Application [ Error ] 16/06/2009 01:01:38 Computer Name = TAP-7409E23BDD | Source = Google Update | ID = 20 -> Description =
Application [ Error ] 16/06/2009 04:06:46 Computer Name = TAP-7409E23BDD | Source = Google Update | ID = 20 -> Description =
Application [ Error ] 20/06/2009 04:57:40 Computer Name = TAP-7409E23BDD | Source = Google Update | ID = 20 -> Description =
Application [ Error ] 20/06/2009 09:03:27 Computer Name = TAP-7409E23BDD | Source = Application Hang | ID = 1002 -> Description = â€â€×™×™×©×•× ×œ× ×ž×’×™×‘ chrome.exe, גירסה 0.0.0.0, מודול חוסר תגובה hungapp, גירסה 0.0.0.0, כתובת חוסר תגובה 0x00000000â€.
Application [ Error ] 20/06/2009 09:13:58 Computer Name = TAP-7409E23BDD | Source = Application Hang | ID = 1002 -> Description = â€â€×™×™×©×•× ×œ× ×ž×’×™×‘ chrome.exe, גירסה 0.0.0.0, מודול חוסר תגובה hungapp, גירסה 0.0.0.0, כתובת חוסר תגובה 0x00000000â€.
Application [ Error ] 23/06/2009 06:03:50 Computer Name = TAP-7409E23BDD | Source = Application Error | ID = 1000 -> Description = â€â€×ª×§×œ×” ×‘×™×™×©×•× iexplore.exe, גירסה 7.0.6000.16674, תקלה במודול ntdll.dll, גירסה 5.1.2600.2180, כתובת התקלה 0x0002ae22â€.
Application [ Error ] 23/06/2009 06:03:57 Computer Name = TAP-7409E23BDD | Source = Application Error | ID = 1000 -> Description = â€â€×ª×§×œ×” ×‘×™×™×©×•× drwtsn32.exe, גירסה 5.1.2600.0, תקלה במודול dbghelp.dll, גירסה 5.1.2600.2180, כתובת התקלה 0x0001295dâ€.
Application [ Error ] 23/06/2009 06:05:39 Computer Name = TAP-7409E23BDD | Source = Application Hang | ID = 1002 -> Description = â€â€×™×™×©×•× ×œ× ×ž×’×™×‘ iexplore.exe, גירסה 7.0.6000.16674, מודול חוסר תגובה hungapp, גירסה 0.0.0.0, כתובת חוסר תגובה 0x00000000â€.
Application [ Error ] 25/06/2009 12:42:39 Computer Name = TAP-7409E23BDD | Source = Application Error | ID = 1000 -> Description = â€â€×ª×§×œ×” ×‘×™×™×©×•× chrome.exe, גירסה 0.0.0.0, תקלה במודול unknown, גירסה 0.0.0.0, כתובת התקלה 0x806fdf43â€.
Application [ Error ] 26/06/2009 03:18:29 Computer Name = TAP-7409E23BDD | Source = Google Update | ID = 20 -> Description =
System [ Error ] 24/06/2009 02:20:21 Computer Name = TAP-7409E23BDD | Source = Dhcp | ID = 1002 -> Description = The IP address lease 10.0.0.1 for the Network Card with network address 00104B360A8E has been denied by the DHCP server 10.0.0.138 (The DHCP Server sent a DHCPNACK message).
System [ Error ] 24/06/2009 02:20:41 Computer Name = TAP-7409E23BDD | Source = Service Control Manager | ID = 7000 -> Description = The General Purpose USB Driver (adildr.sys) service failed to start due to the following error: %%1058
System [ Error ] 24/06/2009 04:58:56 Computer Name = TAP-7409E23BDD | Source = Service Control Manager | ID = 7000 -> Description = The General Purpose USB Driver (adildr.sys) service failed to start due to the following error: %%1058
System [ Error ] 24/06/2009 05:26:59 Computer Name = TAP-7409E23BDD | Source = Service Control Manager | ID = 7000 -> Description = The General Purpose USB Driver (adildr.sys) service failed to start due to the following error: %%1058
System [ Error ] 25/06/2009 02:07:15 Computer Name = TAP-7409E23BDD | Source = Dhcp | ID = 1002 -> Description = The IP address lease 10.0.0.1 for the Network Card with network address 00104B360A8E has been denied by the DHCP server 10.0.0.138 (The DHCP Server sent a DHCPNACK message).
System [ Error ] 25/06/2009 02:07:35 Computer Name = TAP-7409E23BDD | Source = Service Control Manager | ID = 7000 -> Description = The General Purpose USB Driver (adildr.sys) service failed to start due to the following error: %%1058
System [ Error ] 25/06/2009 06:31:30 Computer Name = TAP-7409E23BDD | Source = DCOM | ID = 10000 -> Description = Unable to start a DCOM Server: {46986115-84D6-459C-8F95-52DD653E532E}. The error: "%3" Happened while starting this command: "C:\Program Files\Winamp\winamp.exe" -Embedding
System [ Error ] 26/06/2009 03:05:23 Computer Name = TAP-7409E23BDD | Source = Dhcp | ID = 1002 -> Description = The IP address lease 10.0.0.1 for the Network Card with network address 00104B360A8E has been denied by the DHCP server 10.0.0.138 (The DHCP Server sent a DHCPNACK message).
System [ Error ] 26/06/2009 03:06:01 Computer Name = TAP-7409E23BDD | Source = Service Control Manager | ID = 7000 -> Description = The General Purpose USB Driver (adildr.sys) service failed to start due to the following error: %%1058
System [ Error ] 26/06/2009 06:33:15 Computer Name = TAP-7409E23BDD | Source = Service Control Manager | ID = 7000 -> Description = The General Purpose USB Driver (adildr.sys) service failed to start due to the following error: %%1058
[Files/Folders - Created Within 30 Days]
3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp ->
OTS.exe -> C:\Documents and Settings\עדן\שולחן העבודה\OTS.exe -> [2009/06/26 19:57:52 | 00,510,976 | ---- | C] (OldTimer Tools)
קיצור דרך ×ל ‎TeamSpeak.exe.lnk -> C:\Documents and Settings\עדן\שולחן העבודה\קיצור דרך ×ל ‎TeamSpeak.exe.lnk -> [2009/06/22 16:44:48 | 00,000,729 | ---- | C] ()
NoNameScript-June -> C:\Documents and Settings\עדן\Application Data\NoNameScript-June -> [2009/06/21 07:48:36 | 00,000,000 | ---D | C]
BASSMOD.dll -> C:\WINDOWS\System32\BASSMOD.dll -> [2009/06/19 11:30:40 | 00,009,728 | ---- | C] ()
mIRC Cracking Patch -> C:\Documents and Settings\עדן\My Documents\mIRC Cracking Patch -> [2009/06/19 11:30:03 | 00,000,000 | ---D | C]
mIRC -> C:\Program Files\mIRC -> [2009/06/19 11:14:17 | 00,000,000 | ---D | C]
bookmarks2.html -> C:\Documents and Settings\עדן\My Documents\bookmarks2.html -> [2009/06/16 07:57:59 | 00,005,119 | ---- | C] ()
nsreg.dat -> C:\WINDOWS\nsreg.dat -> [2009/06/13 12:13:44 | 00,000,000 | ---- | C] ()
Mozilla -> C:\Documents and Settings\עדן\Application Data\Mozilla -> [2009/06/13 12:13:42 | 00,000,000 | ---D | C]
Mozilla Firefox.lnk -> C:\Documents and Settings\All Users.WINDOWS\שולחן העבודה\Mozilla Firefox.lnk -> [2009/06/13 12:13:38 | 00,001,602 | ---- | C] ()
Mozilla Firefox -> C:\Program Files\Mozilla Firefox -> [2009/06/13 12:13:35 | 00,000,000 | ---D | C]
GoogleUpdateTask