Both logs are attached to this reply. Thanks again!
#Edit: I ran a full complete scan with SuperAntiSpyware and it seems to have removed one of the reappearing files (there is another one still, 4.exe, which it didn't detect in the scan), and also two other trojans. Here's the log:
Memory items scanned : 448
Memory threats detected : 0
Registry items scanned : 7496
Registry threats detected : 0
File items scanned : 22438
File threats detected : 3
Trojan.Agent/Gen-MailPassView
C:\DOCUMENTS AND SETTINGS\עדן\LOCAL SETTINGS\TEMP\3.EXE
Trojan.Agent/Gen-Krpytik
C:\SYSTEM VOLUME INFORMATION\_RESTORE{0D1368F3-4705-4684-A322-DC445637B4F1}\RP640\A1162847.EXE
Trojan.Agent/Gen
C:\SYSTEM VOLUME INFORMATION\_RESTORE{0D1368F3-4705-4684-A322-DC445637B4F1}\RP644\A1163187.EXE
OTL logfile created on: 17/07/2010 10:11:45 - Run 1
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Documents and Settings\עדן\שולחן העבודה
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 0000040D | Country: ישראל | Language: HEB | Date Format: dd/MM/yyyy
511.00 Mb Total Physical Memory | 266.00 Mb Available Physical Memory | 52.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 73.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 1.57 Gb Free Space | 1.40% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: TAP-7409E23BDD
Current User Name: עדן
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ========== PRC - [2010/07/17 10:10:14 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\עדן\שולחן העבודה\OTL.exe
PRC - [2010/07/17 09:50:31 | 002,403,568 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\44371c0f-58c5-4c7b-9bd4-12ac96b5e9ba.com
PRC - [2010/06/27 19:08:29 | 000,134,808 | ---- | M] (Google Inc.) -- C:\Documents and Settings\עדן\Local Settings\Application Data\Google\Update\1.2.183.29\GoogleCrashHandler.exe
PRC - [2008/04/14 05:17:44 | 001,429,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/04/13 20:39:20 | 000,049,152 | ---- | M] (artArmin) -- C:\Program Files\Vista Drive Icon\DrvIcon.exe
PRC - [2004/09/16 15:39:44 | 000,069,632 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE
========== Modules (SafeList) ========== MOD - [2010/07/17 10:10:14 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\עדן\שולחן העבודה\OTL.exe
MOD - [2008/04/14 05:16:00 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ========== SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\XTrapD12.sys -- (XTrapD12)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\XDva136.sys -- (XDva136)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\XDva090.sys -- (XDva090)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\XDva089.sys -- (XDva089)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\XDva078.sys -- (XDva078)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\XDva062.sys -- (XDva062)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\XDva054.sys -- (XDva054)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\XDva049.sys -- (XDva049)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\XDva041.sys -- (XDva041)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\XDva039.sys -- (XDva039)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\XDva033.sys -- (XDva033)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\XDva032.sys -- (XDva032)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\XDva031.sys -- (XDva031)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\XDva025.sys -- (XDva025)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\XDva020.sys -- (XDva020)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\XDva010.sys -- (XDva010)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\XDva009.sys -- (XDva009)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\XDva007.sys -- (XDva007)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\XDva002.sys -- (XDva002)
DRV - File not found [Kernel | On_Demand | Stopped] -- E:\NTGLM7X.sys -- (SetupNTGLM7X)
DRV - File not found [Kernel | System | Stopped] -- C:\Program Files\SUPERAntiSpyware\SABKUTIL.sys -- (SABKUTIL)
DRV - File not found [Kernel | On_Demand | Stopped] -- E:\NTACCESS.sys -- (NTACCESS)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Gravity\SpiritusRO\npkcrypt.sys -- (npkcrypt)
DRV - File not found [Kernel | On_Demand | Stopped] -- D:\INSTALL\GMSIPCI.SYS -- (GMSIPCI)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\EagleNT.sys -- (EagleNT)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\9E2D~1\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - [2010/05/10 21:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/02/17 21:25:48 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2009/10/27 13:26:38 | 000,077,608 | ---- | M] (Juniper Networks) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NEOFLTR_640_14811.sys -- (NEOFLTR_640_14811) Juniper Networks TDI Filter Driver (NEOFLTR_640_14811)
DRV - [2008/04/13 21:45:29 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2008/04/13 21:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2008/01/01 16:53:43 | 000,715,248 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2004/09/30 08:35:00 | 002,743,840 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2004/09/21 14:53:18 | 002,278,784 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2002/12/18 19:13:34 | 000,122,121 | ---- | M] (Analog Devices Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\adiusbaw.sys -- (adiusbaw)
DRV - [2002/11/18 15:29:26 | 000,399,700 | ---- | M] (NVIDIA Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\dumant.sys -- (DumaNT)
DRV - [2002/10/11 11:19:00 | 000,046,551 | ---- | M] (Analog Deivces) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\adildr.sys -- (ADILOADER) General Purpose USB Driver (adildr.sys)
DRV - [2001/09/18 15:26:38 | 000,153,631 | ---- | M] (3Com Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\el90xnd5.sys -- (EL90X)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "
http://www.google.co.uk/"
FF - prefs.js..keyword.URL: "
http://search.icq.com/search/afe_results.php?ch_id=afex&q="
FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\Documents and Settings\All Users.WINDOWS\Application Data\Mozilla\Firefox Extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2007/06/19 11:44:00 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/12/17 09:18:45 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/16 20:18:27 | 000,000,000 | ---D | M]
[2009/06/13 12:13:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\עדן\Application Data\Mozilla\Extensions
[2009/11/08 21:36:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\עדן\Application Data\Mozilla\Firefox\Profiles\sx612zxc.default\extensions
[2009/07/13 17:12:02 | 000,000,944 | ---- | M] () -- C:\Documents and Settings\עדן\Application Data\Mozilla\Firefox\Profiles\sx612zxc.default\searchplugins\icqplugin.xml
[2010/07/16 20:18:33 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/07/16 20:18:35 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/07/16 20:17:54 | 000,423,656 | ---- | M] (Oracle) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2008/01/04 18:36:50 | 000,001,538 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2008/01/04 18:36:50 | 000,000,947 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2008/09/22 22:14:04 | 000,000,759 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2008/01/04 18:36:50 | 000,000,831 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2010/01/04 23:40:48 | 000,000,849 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (FlashFXP Helper for Internet Explorer) - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\Program Files\FlashFXP\IEFlash.dll (IniCom Networks, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [DrvIcon] C:\Program Files\Vista Drive Icon\DrvIcon.exe (artArmin)
O4 - HKLM..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &יצא ל- Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {03EC4525-6918-4674-9EFF-738EEB3E189F}
http://maxshein10.cctvuser.com/plusviewer.cab (PlusViewer Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F}
http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501}
http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258}
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71}
http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1202306177953 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539}
http://www.crucial.com/controls/cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7}
http://www.adobe.com/products/acrobat/nos/gp.cab (get_atlcom Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B}
https://ssl.sonol.co.il/dana-cached/setup/JuniperSetupSP1.cab (JuniperSetupSP1 Control)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F}
https://ssl.sonol.co.il/dana-cached/sc/JuniperSetupClient.cab (JuniperSetupClientControl Class)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48}
http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O18 - Protocol\Handler\http - No CLSID value found
O18 - Protocol\Handler\https - No CLSID value found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (sevenui.exe) - C:\WINDOWS\System32\sevenui.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop Components:0 (דף הבית הנוכחי שלי) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\עדן\My Documents\My Pictures\2.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\עדן\My Documents\My Pictures\2.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/04/30 19:13:50 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{a1aca993-c3bb-11de-8dbc-00104b360a8e}\Shell\AutoRun\command - "" = G:\RECYCLER\usbassist.exe -- File not found
O33 - MountPoints2\{a1aca993-c3bb-11de-8dbc-00104b360a8e}\Shell\opEN\CoMmanD - "" = G:\RECYCLER\usbassist.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2010/07/17 10:10:14 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\עדן\שולחן העבודה\OTL.exe
[2010/07/16 22:47:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\עדן\Application Data\SUPERAntiSpyware.com
[2010/07/16 22:47:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\SUPERAntiSpyware.com
[2010/07/16 22:46:59 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2010/07/16 22:42:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\עדן\שולחן העבודה\SAP.v4.36.1006
[2010/07/16 22:41:31 | 009,070,944 | ---- | C] (SUPERAntiSpyware.com) -- C:\Documents and Settings\עדן\שולחן העבודה\SUPERAntiSpywarePro.exe
[2010/07/16 22:17:35 | 000,000,000 | ---D | C] -- C:\Program Files\Uniblue
[2010/07/16 20:19:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Sun
[2010/07/16 20:18:27 | 000,073,728 | ---- | C] (Oracle) -- C:\WINDOWS\System32\javacpl.cpl
[2010/07/16 20:18:26 | 000,423,656 | ---- | C] (Oracle) -- C:\WINDOWS\System32\deployJava1.dll
[2010/07/16 20:18:26 | 000,153,376 | ---- | C] (Oracle) -- C:\WINDOWS\System32\javaws.exe
[2010/07/16 20:18:26 | 000,145,184 | ---- | C] (Oracle) -- C:\WINDOWS\System32\javaw.exe
[2010/07/16 20:18:26 | 000,145,184 | ---- | C] (Oracle) -- C:\WINDOWS\System32\java.exe
[2010/07/16 16:48:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\עדן\Application Data\Uniblue
[2010/07/14 13:58:52 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\helpsvc.exe
[2010/07/11 23:37:36 | 000,000,000 | ---D | C] -- C:\Program Files\TeamSpeak 3 Client
[2010/06/19 22:31:38 | 000,000,000 | ---D | C] -- C:\Program Files\SexyKO
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2010/07/17 10:13:06 | 000,000,960 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-261903793-1801674531-1004UA.job
[2010/07/17 10:10:14 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\עדן\שולחן העבודה\OTL.exe
[2010/07/17 10:03:28 | 000,000,854 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/07/17 10:03:28 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/07/17 10:03:28 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2010/07/17 09:05:44 | 000,007,883 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010/07/17 09:05:39 | 000,002,422 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/07/17 09:05:02 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/07/17 09:05:00 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/07/17 09:04:59 | 536,399,872 | -HS- | M] () -- C:\hiberfil.sys
[2010/07/17 00:20:41 | 012,582,912 | ---- | M] () -- C:\Documents and Settings\עדן\ntuser.dat
[2010/07/17 00:20:41 | 000,000,306 | -HS- | M] () -- C:\Documents and Settings\עדן\ntuser.ini
[2010/07/16 23:11:15 | 000,013,205 | ---- | M] () -- C:\Documents and Settings\עדן\שולחן העבודה\asd.JPG
[2010/07/16 22:47:04 | 000,001,678 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\שולחן העבודה\SUPERAntiSpyware Professional.lnk
[2010/07/16 22:41:46 | 000,277,459 | ---- | M] () -- C:\Documents and Settings\עדן\שולחן העבודה\SAP.v4.36.1006.rar
[2010/07/16 22:41:31 | 009,070,944 | ---- | M] (SUPERAntiSpyware.com) -- C:\Documents and Settings\עדן\שולחן העבודה\SUPERAntiSpywarePro.exe
[2010/07/16 20:17:53 | 000,423,656 | ---- | M] (Oracle) -- C:\WINDOWS\System32\deployJava1.dll
[2010/07/16 20:17:53 | 000,153,376 | ---- | M] (Oracle) -- C:\WINDOWS\System32\javaws.exe
[2010/07/16 20:17:53 | 000,145,184 | ---- | M] (Oracle) -- C:\WINDOWS\System32\javaw.exe
[2010/07/16 20:17:53 | 000,145,184 | ---- | M] (Oracle) -- C:\WINDOWS\System32\java.exe
[2010/07/16 20:17:53 | 000,073,728 | ---- | M] (Oracle) -- C:\WINDOWS\System32\javacpl.cpl
[2010/07/16 19:13:01 | 000,000,908 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-261903793-1801674531-1004Core.job
[2010/07/16 14:32:33 | 003,147,656 | -H-- | M] () -- C:\Documents and Settings\עדן\Local Settings\Application Data\IconCache.db
[2010/07/15 18:20:26 | 000,000,372 | ---- | M] () -- C:\Documents and Settings\עדן\My Documents\spider.sav
[2010/07/15 15:31:48 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\עדן\Application Data\Microsoft\Internet Explorer\Quick Launch\הפעל את Microsoft Outlook.lnk
[2010/07/14 13:16:57 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010/07/13 21:56:57 | 000,000,654 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\שולחן העבודה\Mp3tag.lnk
[2010/07/11 23:37:42 | 000,000,837 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\שולחן העבודה\TeamSpeak 3 Client.lnk
[2010/07/06 17:43:33 | 106,954,753 | ---- | M] () -- C:\Documents and Settings\עדן\שולחן העבודה\VDay.2010.720p.700MB.ShAaNiG.part1.rar
[2010/06/24 00:15:29 | 000,432,356 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/06/24 00:15:29 | 000,345,584 | ---- | M] () -- C:\WINDOWS\System32\perfh00d.dat
[2010/06/24 00:15:29 | 000,067,296 | ---- | M] () -- C:\WINDOWS\System32\perfc00d.dat
[2010/06/24 00:15:28 | 000,888,296 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/06/24 00:15:28 | 000,067,312 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/06/24 00:12:25 | 000,001,776 | ---- | M] () -- C:\Documents and Settings\עדן\שולחן העבודה\Adobe Photoshop CS2.lnk
[2010/06/20 09:38:55 | 000,000,666 | ---- | M] () -- C:\Documents and Settings\עדן\שולחן העבודה\קיצור דרך אל Launcher.exe.lnk
[2010/06/19 23:43:51 | 000,182,272 | ---- | M] () -- C:\Documents and Settings\עדן\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ========== [2010/07/16 23:11:15 | 000,013,205 | ---- | C] () -- C:\Documents and Settings\עדן\שולחן העבודה\asd.JPG
[2010/07/16 22:47:04 | 000,001,678 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\שולחן העבודה\SUPERAntiSpyware Professional.lnk
[2010/07/16 22:41:46 | 000,277,459 | ---- | C] () -- C:\Documents and Settings\עדן\שולחן העבודה\SAP.v4.36.1006.rar
[2010/07/15 18:20:26 | 000,000,372 | ---- | C] () -- C:\Documents and Settings\עדן\My Documents\spider.sav
[2010/07/11 23:37:42 | 000,000,837 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\שולחן העבודה\TeamSpeak 3 Client.lnk
[2010/07/06 17:43:09 | 106,954,753 | ---- | C] () -- C:\Documents and Settings\עדן\שולחן העבודה\VDay.2010.720p.700MB.ShAaNiG.part1.rar
[2010/06/24 00:12:25 | 000,001,776 | ---- | C] () -- C:\Documents and Settings\עדן\שולחן העבודה\Adobe Photoshop CS2.lnk
[2010/06/20 09:38:55 | 000,000,666 | ---- | C] () -- C:\Documents and Settings\עדן\שולחן העבודה\קיצור דרך אל Launcher.exe.lnk
[2009/11/30 22:33:46 | 000,041,872 | ---- | C] () -- C:\WINDOWS\System32\xfcodec.dll
[2009/11/26 22:41:03 | 000,258,048 | ---- | C] () -- C:\WINDOWS\libFLAC.dll
[2009/09/07 12:40:20 | 000,070,236 | ---- | C] () -- C:\WINDOWS\System32\rus_lang_plusviewer.ini
[2009/09/07 12:40:20 | 000,033,899 | ---- | C] () -- C:\WINDOWS\System32\rus_lang_setupmng.ini
[2009/07/28 12:37:46 | 000,072,342 | ---- | C] () -- C:\WINDOWS\System32\spn_lang_plusviewer.ini
[2009/07/10 13:43:46 | 000,033,761 | ---- | C] () -- C:\WINDOWS\System32\spn_lang_setupmng.ini
[2009/07/10 13:43:40 | 000,033,761 | ---- | C] () -- C:\WINDOWS\System32\prt_lang_setupmng.ini
[2009/07/10 13:43:34 | 000,033,761 | ---- | C] () -- C:\WINDOWS\System32\pol_lang_setupmng.ini
[2009/07/10 13:43:28 | 000,033,110 | ---- | C] () -- C:\WINDOWS\System32\kor_lang_setupmng.ini
[2009/07/10 13:43:24 | 000,033,761 | ---- | C] () -- C:\WINDOWS\System32\jpn_lang_setupmng.ini
[2009/07/10 13:43:18 | 000,033,761 | ---- | C] () -- C:\WINDOWS\System32\heb_lang_setupmng.ini
[2009/07/10 13:43:12 | 000,033,761 | ---- | C] () -- C:\WINDOWS\System32\eng_lang_setupmng.ini
[2009/07/10 13:43:06 | 000,033,761 | ---- | C] () -- C:\WINDOWS\System32\chat_lang_setupmng.ini
[2009/07/10 13:43:00 | 000,033,761 | ---- | C] () -- C:\WINDOWS\System32\chas_lang_setupmng.ini
[2009/07/06 15:19:10 | 000,054,028 | ---- | C] () -- C:\WINDOWS\System32\chas_lang_plusviewer.ini
[2009/07/02 18:20:40 | 000,054,080 | ---- | C] () -- C:\WINDOWS\System32\chat_lang_plusviewer.ini
[2009/06/29 15:24:20 | 000,033,357 | ---- | C] () -- C:\WINDOWS\System32\eng_lang_plusviewer.ini
[2009/06/19 11:30:40 | 000,014,848 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
[2009/06/18 15:27:28 | 000,032,762 | ---- | C] () -- C:\WINDOWS\System32\kor_lang_plusviewer.ini
[2009/06/18 15:27:06 | 000,033,285 | ---- | C] () -- C:\WINDOWS\System32\jpn_lang_plusviewer.ini
[2009/06/16 17:52:50 | 000,066,734 | ---- | C] () -- C:\WINDOWS\System32\prt_lang_plusviewer.ini
[2009/03/12 19:13:50 | 000,064,436 | ---- | C] () -- C:\WINDOWS\System32\heb_lang_plusviewer.ini
[2009/03/11 12:08:48 | 000,033,234 | ---- | C] () -- C:\WINDOWS\System32\pol_lang_plusviewer.ini
[2008/06/16 18:17:50 | 000,098,892 | ---- | C] () -- C:\WINDOWS\System32\PPPoEWin.sys
[2008/06/16 18:17:50 | 000,098,892 | ---- | C] () -- C:\WINDOWS\System32\drivers\PPPoEWin.sys
[2007/05/12 12:01:25 | 000,715,248 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2007/03/21 17:30:52 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\mp4dec2avi.dll
[2006/12/02 21:50:05 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2006/11/19 20:14:09 | 000,000,072 | ---- | C] () -- C:\WINDOWS\MediaManager.INI
[2006/10/30 21:28:05 | 000,000,068 | ---- | C] () -- C:\WINDOWS\rootcracker.ini
[2006/02/23 21:00:26 | 000,156,672 | R--- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2006/02/21 15:18:59 | 000,000,139 | ---- | C] () -- C:\WINDOWS\msicpl.ini
[2006/01/28 18:19:35 | 000,000,039 | ---- | C] () -- C:\WINDOWS\ideq32.ini
[2006/01/26 20:19:42 | 000,000,026 | ---- | C] () -- C:\WINDOWS\NeoSetup.INI
[2006/01/26 16:08:35 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI
[2006/01/12 19:53:18 | 000,045,056 | R--- | C] () -- C:\WINDOWS\System32\memtest.dll
[2006/01/12 19:53:17 | 000,039,208 | R--- | C] () -- C:\WINDOWS\System32\drivers\vgauti.sys
[2006/01/12 19:53:17 | 000,039,208 | R--- | C] () -- C:\WINDOWS\System32\drivers\msicpl.sys
[2006/01/02 21:21:44 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\cwsmaf40.dll
[2006/01/02 21:21:43 | 001,097,728 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2006/01/02 21:21:43 | 001,003,520 | ---- | C] () -- C:\WINDOWS\System32\vorbisenc.dll
[2006/01/02 21:21:43 | 000,511,488 | ---- | C] () -- C:\WINDOWS\System32\pwmdtl40.dll
[2006/01/02 21:21:43 | 000,430,080 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2006/01/02 21:21:43 | 000,182,784 | ---- | C] () -- C:\WINDOWS\System32\DGVorbis.dll
[2006/01/02 21:21:43 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\Mp3dec.dll
[2006/01/02 21:21:43 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\cwpwmd10.dll
[2006/01/02 21:21:43 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\MP3enc.dll
[2006/01/02 21:21:43 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\vorbisfile.dll
[2006/01/02 21:21:43 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2005/12/08 13:52:38 | 000,000,651 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005/12/08 12:57:41 | 000,000,154 | ---- | C] () -- C:\WINDOWS\adidsl.ini
[2005/12/08 12:57:37 | 000,000,331 | ---- | C] () -- C:\WINDOWS\adiras.ini
[2005/12/08 12:57:33 | 000,046,892 | ---- | C] () -- C:\WINDOWS\System32\ADADIX16.DLL
[2005/03/10 21:47:18 | 000,356,352 | ---- | C] () -- C:\WINDOWS\System32\rfmp4dec.dll
[2004/12/14 14:04:48 | 000,266,240 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2004/12/14 14:02:49 | 001,175,552 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2004/09/16 14:26:40 | 000,012,634 | ---- | C] () -- C:\WINDOWS\System32\drivers\ADFUUD.SYS
[2004/09/16 14:26:40 | 000,012,634 | ---- | C] () -- C:\WINDOWS\ADFUUD.SYS
[2004/05/31 15:39:46 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\rfg726.dll
[2004/01/19 18:17:58 | 000,356,352 | ---- | C] () -- C:\WINDOWS\System32\mwmp4dec.dll
[2002/11/18 15:29:28 | 000,368,640 | ---- | C] () -- C:\WINDOWS\System32\nvimage.dll
[2002/11/18 15:29:28 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\stereoi.dll
[2002/03/21 14:51:52 | 000,503,808 | R--- | C] () -- C:\WINDOWS\System32\lt_xtrans.dll
[2002/03/21 14:51:52 | 000,286,720 | R--- | C] () -- C:\WINDOWS\System32\MrSIDD.dll
[2002/03/21 14:51:52 | 000,163,840 | R--- | C] () -- C:\WINDOWS\System32\lt_common.dll
[2002/03/21 14:51:52 | 000,126,976 | R--- | C] () -- C:\WINDOWS\System32\lt_trans.dll
[2002/03/21 14:51:52 | 000,069,632 | R--- | C] () -- C:\WINDOWS\System32\lt_meta.dll
[2002/03/21 14:51:52 | 000,053,248 | R--- | C] () -- C:\WINDOWS\System32\lt_encrypt.dll
[2002/03/21 14:51:52 | 000,020,480 | R--- | C] () -- C:\WINDOWS\System32\lt_messagetext.dll
[2002/03/20 23:01:06 | 000,006,688 | R--- | C] () -- C:\WINDOWS\System32\Digita.sys
[2002/03/20 23:00:20 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\TransportUSB.dll
[2002/03/20 23:00:20 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\TransportSerial.dll
[2002/03/20 23:00:20 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\TransportIrDA.dll
[2002/03/20 23:00:20 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\TransportIrCOMM.dll
[2002/03/13 17:46:46 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\zlib.dll
[1996/04/03 22:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys
========== Alternate Data Streams ========== @Alternate Data Stream - 219 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:05EE1EEF
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:0F8F5844
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:4295826C
< End of report >
OTL Extras logfile created on: 17/07/2010 10:11:45 - Run 1
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Documents and Settings\עדן\שולחן העבודה
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 0000040D | Country: ישראל | Language: HEB | Date Format: dd/MM/yyyy
511.00 Mb Total Physical Memory | 266.00 Mb Available Physical Memory | 52.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 73.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 1.57 Gb Free Space | 1.40% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: TAP-7409E23BDD
Current User Name: עדן
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDBrowse] -- "C:\Program Files\ACD Systems\ACDSee\5.0\ACDSee5.exe" "%1" (ACD Systems, Ltd.)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Scan with Ad-aware...] -- "C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe" "%1" "+SD" File not found
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"FirewallDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 1
"UpdatesDisableNotify" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
"C:\Program Files\FlashFXP\FlashFXP.exe" = C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3 -- (IniCom Networks, Inc.)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Tactical Ops\TacticalOps 3\System\TacticalOps.exe" = C:\Program Files\Tactical Ops\TacticalOps 3\System\TacticalOps.exe:*:Enabled:TacticalOps -- ()
"C:\Program Files\mIRC\mirc.exe" = C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC -- (mIRC Co. Ltd.)
"C:\Documents and Settings\עדן\Application Data\Juniper Networks\Juniper Terminal Services Client\dsTermServ.exe" = C:\Documents and Settings\עדן\Application Data\Juniper Networks\Juniper Terminal Services Client\dsTermServ.exe:*:Enabled:Juniper Terminal Services Client -- (Juniper Networks)
"C:\Program Files\Juniper Networks\Secure Application Manager\dsSamProxy.exe" = C:\Program Files\Juniper Networks\Secure Application Manager\dsSamProxy.exe:*:Enabled:Secure Application Manager Proxy -- (Juniper Networks)
"C:\Program Files\Tactical Ops\TacticalOps 4\System\TacticalOps.exe" = C:\Program Files\Tactical Ops\TacticalOps 4\System\TacticalOps.exe:*:Enabled:TacticalOps -- ()
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
"C:\Program Files\Xfire\Xfire.exe" = C:\Program Files\Xfire\Xfire.exe:*:Enabled:Xfire -- (Xfire Inc.)
"C:\UnrealTournament\System\UnrealTournament.exe" = C:\UnrealTournament\System\UnrealTournament.exe:*:Enabled:UnrealTournament -- File not found
"C:\Program Files\eMule.co.il\Fire eMule 7\eMule.exe" = C:\Program Files\eMule.co.il\Fire eMule 7\eMule.exe:*:Enabled:eMule -- File not found
"C:\Program Files\ICQ6.5\ICQ.exe" = C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6 -- (ICQ, LLC.)
"C:\Program Files\Teamspeak2_RC2_Server\server_windows.exe" = C:\Program Files\Teamspeak2_RC2_Server\server_windows.exe:*:Enabled:Server -- File not found
"C:\Documents and Settings\עדן\שולחן העבודה\wormsarm\WA.exe" = C:\Documents and Settings\עדן\שולחן העבודה\wormsarm\WA.exe:*:Disabled:Worms Armageddon -- File not found
"C:\Documents and Settings\עדן\Application Data\GameRanger\GameRanger\GameRanger.exe" = C:\Documents and Settings\עדן\Application Data\GameRanger\GameRanger\GameRanger.exe:*:Enabled:GameRanger -- File not found
"C:\Documents and Settings\עדן\שולחן העבודה\WWPBy FeuoZz For HorAdoT.nEt\wwp.exe" = C:\Documents and Settings\עדן\שולחן העבודה\WWPBy FeuoZz For HorAdoT.nEt\wwp.exe:*:Enabled:Worms World Party -- File not found
"C:\Program Files\UT2004\System\UT2004.exe" = C:\Program Files\UT2004\System\UT2004.exe:*:Enabled:UT2004 -- ()
"C:\Program Files\FlashFXP\FlashFXP.exe" = C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3 -- (IniCom Networks, Inc.)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- (Oracle)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"C:\Program Files\UnisonPlay\UniFS.exe" = C:\Program Files\UnisonPlay\UniFS.exe:*:Enabled:UniFS Media - UniFS.exe -- File not found
"" = :*:Enabled:ldrsoft
"C:\Documents and Settings\עדן\Local Settings\temp\957822.exe" = C:\Documents and Settings\עדן\Local Settings\temp\957822.exe:*:Disabled:957822 -- File not found
========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{035D48BB-503E-4F09-9D52-EC57D3411DDC}" = Windows Live Essentials
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = כלי ההעלאה של Windows Live
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java(TM) 6 Update 21
"{350C97B4-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{38E0C491-5230-4373-B62E-F1A6E94B1033}" = Nero 7 Ultra Edition
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3CEA4CA8-CDD4-451C-B673-E8F17BE01B15}" = Ulead COOL 360 1.0
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{43DCF766-6838-4F9A-8C91-D92DA586DFA8}" = Microsoft Windows Journal Viewer
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AE3A0CB-87B0-4F51-BECD-3D1F8DFDD62F}" = ECI USB ADSL
"{4B719A70-F14A-4f5c-90B5-346B24B7FFF1}" = Windows 7 Upgrade Advisor
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6.5
"{634328D0-C948-4C4D-BDE9-58015B941648}" = Windows Live Messenger
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76C24F39-B161-498F-BD8B-C64789812D13}_is1" = ConvertXtoDVD 3.8.0.193j
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7784A172-61F1-445E-8368-601607E0DD22}" = MP3 Player Utilities 3.73
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{885A5214-9CDD-40E0-A89D-7672588748E1}" = Windows Live Call
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{90120000-0020-040D-0000-0000000FF1CE}" = חבילת תאימות עבור מהדורת 2007 של מערכת Office
"{9028040D-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional עם FrontPage
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95774351-6087-3A3B-8CA8-70BEE49D2BD5}" = Google Gears
"{96E3AED5-3D0B-4BB0-84C2-1EDADB204487}" = FlashFXP v3
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A0D6AA15-66B9-41BE-BA85-17EB8C84A685}" = Knight Online
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A34386F8-7655-4E3B-9F51-D3064F607C89}" = blaxxun Contact
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.4
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{AF5E8D43-49AD-4BE7-A941-2BB0A8CACA62}" = ACDSee 5.0 Standard
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Plus Web Player
"{B74D4E10-1033-0000-0000-000000000001}" = Adobe Bridge 1.0
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BCBA462D-3E1B-416C-89F8-492020D4BBF4}" = מסייע הכניסה של Windows Live
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D271DAE0-8D68-4C97-8356-A126D48A1D8C}" = Ulead Photo Explorer 8.0 SE Basic
"{DF3E37E0-06D5-4A1B-A264-BD2B7E30B458}" = Knight Online
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"7-Zip" = 7-Zip 9.10 beta
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Adobe Shockwave Player" = Adobe Shockwave Player
"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2008-09-21 16:18
"dBpoweramp AAC Encoder" = dBpoweramp AAC Encoder
"dBpoweramp CD Writer" = dBpoweramp CD Writer
"dBpoweramp DirectShow Decoder" = dBpoweramp DirectShow Decoder
"dBpoweramp DSP Effects" = dBpoweramp DSP Effects
"dBpoweramp FLAC Codec" = dBpoweramp FLAC Codec
"dBpoweramp m4a Codec" = dBpoweramp m4a Codec
"dBpoweramp Music Converter" = dBpoweramp Music Converter
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"ESE_Registration" = ESE Account Manager (remove only)
"ESET Online Scanner" = ESET Online Scanner v3
"Fraps" = Fraps (remove only)
"getPlus(R)_ocx" = getPlus(R)_ocx
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"mIRC" = mIRC
"MKVtoolnix" = MKVtoolnix 2.9.8
"Mozilla Firefox (3.0.11)" = Mozilla Firefox (3.0.11)
"Mp3 Audio Editor" = Mp3 Audio Editor
"Mp3tag" = Mp3tag v2.46a
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Neoteris_Secure_Application_Manager" = Juniper Networks Secure Application Manager
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIAStereo" = NVIDIA Windows 95/98/ME/2000/XP Stereo Drivers
"Ogg Codecs" = Ogg Codecs 0.81.15562
"Seven Transformation Pack" = Seven Transformation Pack 3.0
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.5.2.20
"ST6UNST #1" = RonlightSync
"SystemRequirementsLab" = System Requirements Lab
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"TeamSpeak 2 Server_is1" = TeamSpeak 2 Server RC2
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"UnrealTournament" = Unreal Tournament G.O.T.Y. Edition
"uTorrent" = µTorrent
"VentriloMIX" = VentriloMIX
"WIC" = Windows Imaging Component
"Winamp" = Winamp
"Winamp Essentials Pack" = Winamp Essentials Pack
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"WOW" = WOW
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xfire" = Xfire (remove only)
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XviD" = XviD MPEG-4 Codec
"YouTubeGet_is1" = YouTubeGet 5.2.3
========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"Juniper_Networks_Cache_Cleaner 6.0.0" = Juniper Networks Cache Cleaner 6.0.0
"Juniper_Networks_Cache_Cleaner 6.4.0" = Juniper Networks Cache Cleaner 6.4.0
"Juniper_Setup_Client" = Juniper Networks Setup Client
"Juniper_Term_Services" = Juniper Terminal Services Client
"MaxKO" = MaxKO
"Neoteris_Host_Checker" = Juniper Networks Host Checker
"NoNameScript" = NoNameScript
========== Last 10 Event Log Errors ========== [ Application Events ]
Error - 02/07/2010 03:42:59 | Computer Name = TAP-7409E23BDD | Source = Application Error | ID = 1000
Description = תקלה ביישום maxkoc.exe, גירסה 2.3.11.1718, תקלה במודול maxkoc.exe,
גירסה 2.3.11.1718, כתובת התקלה 0x000dac5e.
Error - 08/07/2010 03:22:48 | Computer Name = TAP-7409E23BDD | Source = SecurityCenter | ID = 1802
Description = לשירות מרכז האבטחה של Windows לא היתה אפשרות ליצור שאילתות אירוע
ב- WMI כדי לפקח על תוכניות אנטי-וירוס וחומת אש של יצרנים אחרים.
Error - 08/07/2010 04:57:57 | Computer Name = TAP-7409E23BDD | Source = Application Error | ID = 1000
Description = תקלה ביישום chrome.exe, גירסה 0.0.0.0, תקלה במודול unknown, גירסה
0.0.0.0, כתובת התקלה 0x806fff43.
Error - 09/07/2010 16:19:58 | Computer Name = TAP-7409E23BDD | Source = Application Error | ID = 1000
Description = תקלה ביישום explorer.exe, גירסה 6.0.2900.5512, תקלה במודול unknown,
גירסה 0.0.0.0, כתובת התקלה 0x0b2fd6b0.
Error - 10/07/2010 23:13:34 | Computer Name = TAP-7409E23BDD | Source = Google Update | ID = 20
Description =
Error - 12/07/2010 16:42:13 | Computer Name = TAP-7409E23BDD | Source = Application Hang | ID = 1002
Description = יישום לא מגיב MaxKOC.exe, גירסה 2.3.11.1718, מודול חוסר תגובה hungapp,
גירסה 0.0.0.0, כתובת חוסר תגובה 0x00000000.
Error - 15/07/2010 07:13:34 | Computer Name = TAP-7409E23BDD | Source = Google Update | ID = 20
Description =
Error - 15/07/2010 08:13:34 | Computer Name = TAP-7409E23BDD | Source = Google Update | ID = 20
Description =
Error - 16/07/2010 04:10:39 | Computer Name = TAP-7409E23BDD | Source = Google Update | ID = 20
Description =
Error - 16/07/2010 04:13:34 | Computer Name = TAP-7409E23BDD | Source = Google Update | ID = 20
Description =
[ System Events ]
Error - 16/07/2010 13:10:56 | Computer Name = TAP-7409E23BDD | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 16/07/2010 13:10:56 | Computer Name = TAP-7409E23BDD | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 16/07/2010 13:10:56 | Computer Name = TAP-7409E23BDD | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 16/07/2010 13:10:56 | Computer Name = TAP-7409E23BDD | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 16/07/2010 13:10:56 | Computer Name = TAP-7409E23BDD | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 16/07/2010 15:45:31 | Computer Name = TAP-7409E23BDD | Source = Service Control Manager | ID = 7000
Description = The General Purpose USB Driver (adildr.sys) service failed to start
due to the following error: %%1058
Error - 16/07/2010 15:50:56 | Computer Name = TAP-7409E23BDD | Source = Service Control Manager | ID = 7000
Description = The SABKUTIL service failed to star