ComboFix log
ComboFix 08-10-19.01 - yehuda 10/19/2008 22:32:21.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1255.1.1037.18.525 [GMT 2:00]
Running from: C:\Documents and Settings\yehuda\שולחן העבודה\ComboFix.exe
Command switches used :: C:\Documents and Settings\yehuda\שולחן העבודה\CFScript.txt
* Created a new restore point
FILE ::
C:\Program Files\ Azureus2.lnk
C:\WINDOWS\lomxeqsn.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\zibkhyha
C:\Program Files\ Azureus2.lnk
C:\Program Files\Azureus
C:\Program Files\Azureus\AzureusUpdater.exe
C:\Program Files\Azureus\plugins\azplugins\azplugins_2.1.4.jar
C:\Program Files\Azureus\plugins\azrating\azrating_1.3.1.jar
C:\Program Files\Azureus\plugins\azupdater\azupdater_1.8.5.zip
C:\Program Files\Azureus\plugins\azupdater\azupdater_1.8.8.zip
C:\Program Files\Azureus\plugins\azupdater\azupdaterpatcher_1.8.3.jar
C:\Program Files\Azureus\plugins\azupdater\azupdaterpatcher_1.8.5.jar
C:\Program Files\Azureus\plugins\azupdater\azupdaterpatcher_1.8.8.jar
C:\Program Files\Azureus\plugins\azupdater\plugin.properties
C:\Program Files\Azureus\plugins\azupdater\plugin.properties_1.8.5
C:\Program Files\Azureus\plugins\azupdater\plugin.properties_1.8.8
C:\Program Files\Azureus\plugins\azupdater\Updater.jar
C:\Program Files\Azureus\plugins\azupdater\Updater.jar.bak
C:\Program Files\Azureus\Uninstall.exe
C:\Program Files\eMule
C:\Program Files\eMule\Temp\
003.part
C:\Program Files\eMule\Temp\
003.part.met
C:\Program Files\eMule\Temp\
003.part.met.bak
C:\Program Files\eMule\Temp\
005.part
C:\Program Files\eMule\Temp\
005.part.met
C:\Program Files\eMule\Temp\
005.part.met.bak
C:\Program Files\eMule\Temp\
006.part
C:\Program Files\eMule\Temp\
006.part.met
C:\Program Files\eMule\Temp\
006.part.met.bak
C:\Program Files\LPVideoPlugin
C:\WINDOWS\lomxeqsn.exe
.
((((((((((((((((((((((((( Files Created from 2008-09-19 to 2008-10-19 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-19 20:14 --------- d-----w C:\Program Files\Java
2008-10-19 19:12 --------- d-----w C:\Program Files\Common Files\Adobe
2008-10-18 20:01 --------- d-----w C:\Program Files\CompeGPS
2008-10-17 11:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-17 11:08 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-10-16 20:46 --------- d---a-w C:\Documents and Settings\All Users\Application Data\Temp
2008-10-15 17:57 267,776 ----a-w C:\WINDOWS\system32\pmnoPjHA.dll
2008-10-15 06:30 --------- d-----w C:\Program Files\eToro
2008-10-15 05:45 --------- d-----w C:\Program Files\Suunto Monitor
2008-10-13 21:28 --------- d-----w C:\Documents and Settings\yehuda\Application Data\Juniper Networks
2008-10-13 13:20 --------- d-----w C:\Documents and Settings\yehuda\Application Data\GARMIN
2008-10-11 05:08 --------- d-----w C:\Program Files\Suunto Training Manager
2008-10-11 04:27 684,377 ----a-w C:\WINDOWS\unins000.exe
2008-10-11 04:27 --------- d-----w C:\Program Files\SuuntoUSBDrivers
2008-10-11 04:22 --------- d-----w C:\Program Files\DIFX
2008-10-08 07:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\ATI
2008-10-08 05:56 --------- d-----w C:\Program Files\ATI Technologies
2008-10-02 10:36 --------- d-----w C:\Program Files\Suunto
2008-10-02 10:35 --------- d-----w C:\Program Files\Firstbeat
2008-09-29 12:31 --------- d-----w C:\Documents and Settings\yehuda\Application Data\Canon
2008-09-24 18:55 --------- d-----w C:\Program Files\ImTOO
2008-09-24 18:53 --------- d-----w C:\Program Files\VideoLAN
2008-09-23 18:00 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-09-23 18:00 --------- d-----w C:\Program Files\Real
2008-09-23 18:00 --------- d-----w C:\Program Files\Common Files\xing shared
2008-09-23 18:00 --------- d-----w C:\Program Files\Common Files\Real
2008-09-23 17:26 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-09-15 15:26 1,846,272 ----a-w C:\WINDOWS\system32\win32k.sys
2008-09-08 10:41 333,824 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-09-06 09:33 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-06 09:33 --------- d-----w C:\Program Files\Sony Ericsson
2008-09-06 09:33 --------- d-----w C:\Documents and Settings\yehuda\Application Data\Teleca
2008-09-06 09:32 --------- d-----w C:\Program Files\Common Files\Teleca Shared
2008-09-06 09:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sony Ericsson
2008-08-31 18:04 --------- d-----w C:\Program Files\QuickTime
2008-08-31 18:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-08-31 18:03 --------- d-----w C:\Program Files\Apple Software Update
2008-08-31 18:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-08-31 18:00 --------- d-----w C:\Documents and Settings\yehuda\Application Data\Apple Computer
2008-08-31 15:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-08-31 14:59 --------- d-----w C:\Documents and Settings\yehuda\Application Data\CyberLink
2008-08-31 14:51 --------- d-----w C:\Program Files\CyberLink
2008-08-31 14:50 --------- d-----w C:\Program Files\SmartSound Software
2008-08-31 14:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
2008-08-29 05:25 97,928 ----a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-26 08:11 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-08-21 04:52 3,299,840 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
2008-08-21 02:19 425,984 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll
2008-08-21 02:18 314,880 ----a-w C:\WINDOWS\system32\ati2dvag.dll
2008-08-21 02:08 184,320 ----a-w C:\WINDOWS\system32\atipdlxx.dll
2008-08-21 02:08 143,360 ----a-w C:\WINDOWS\system32\Oemdspif.dll
2008-08-21 02:07 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll
2008-08-21 02:07 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
2008-08-21 02:07 143,360 ----a-w C:\WINDOWS\system32\ati2evxx.dll
2008-08-21 02:05 573,440 ----a-w C:\WINDOWS\system32\ati2evxx.exe
2008-08-21 02:04 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
2008-08-21 02:01 10,084,352 ----a-w C:\WINDOWS\system32\atioglxx.dll
2008-08-21 01:55 4,094,560 ----a-w C:\WINDOWS\system32\ati3duag.dll
2008-08-21 01:50 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
2008-08-21 01:38 2,377,856 ----a-w C:\WINDOWS\system32\ativvaxx.dll
2008-08-21 01:23 48,640 ----a-w C:\WINDOWS\system32\amdpcom32.dll
2008-08-21 01:19 380,928 ----a-w C:\WINDOWS\system32\atikvmag.dll
2008-08-21 01:18 37,376 ----a-w C:\WINDOWS\system32\atiadlxx.dll
2008-08-21 01:18 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
2008-08-21 01:17 53,248 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll
2008-08-21 01:17 253,952 ----a-w C:\WINDOWS\system32\atiok3x2.dll
2008-08-21 01:11 561,152 ----a-w C:\WINDOWS\system32\ati2cqag.dll
2008-08-20 19:05 593,920 ----a-w C:\WINDOWS\system32\ati2sgag.exe
2008-08-14 13:24 2,146,816 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 13:24 2,025,472 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-08-05 21:14 90,112 ----a-w C:\WINDOWS\system32\ATIBRTMON.EXE
2008-01-30 20:19 11,114 ----a-w C:\Documents and Settings\All Users\Application Data\MainApp.dll
2007-06-01 12:39 81,920 ----a-w C:\Documents and Settings\yehuda\Application Data\ezpinst.exe
2007-06-01 12:39 47,360 ----a-w C:\Documents and Settings\yehuda\Application Data\pcouffin.sys
.
((((((((((((((((((((((((((((( snapshot@Sat 10-18-2008_22.28.24.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-26 09:10:29 347,136 ----a-w C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\dxtmsft.dll
+ 2008-08-26 09:10:29 214,528 ----a-w C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\dxtrans.dll
+ 2008-08-26 09:10:29 63,488 ----a-w C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\icardie.dll
+ 2008-08-25 08:43:21 70,656 ----a-w C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\ie4uinit.exe
+ 2008-08-26 09:10:29 153,088 ----a-w C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\ieakeng.dll
+ 2007-04-17 09:32:38 2,455,488 ----a-w C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\ieapfltr.dat
+ 2008-08-26 09:10:31 44,544 ----a-w C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\iernonce.dll
+ 2008-08-26 09:10:31 267,776 ----a-w C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\iertutil.dll
+ 2008-08-25 08:43:21 13,824 ----a-w C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\ieudinit.exe
+ 2008-08-23 05:56:16 635,848 ----a-w C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\iexplore.exe
+ 2008-08-26 09:10:32 27,648 ----a-w C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\jsproxy.dll
+ 2008-08-26 09:10:32 459,264 ----a-w C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\msfeeds.dll
+ 2008-08-26 09:10:32 52,224 ----a-w C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\msfeedsbs.dll
+ 2008-08-26 09:10:33 3,594,752 ----a-w C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\mshtml.dll
+ 2008-08-26 09:10:33 477,696 ----a-w C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\mshtmled.dll
+ 2008-08-26 09:10:33 193,024 ----a-w C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\msrating.dll
+ 2008-08-26 09:10:34 671,232 ----a-w C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\mstime.dll
+ 2008-08-26 09:10:34 102,912 ----a-w C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\occache.dll
+ 2008-08-26 09:10:34 44,544 ----a-w C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\pngfilt.dll
+ 2008-08-26 09:10:34 105,984 ----a-w C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\url.dll
+ 2008-08-26 09:10:34 1,162,752 ----a-w C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\urlmon.dll
+ 2008-08-26 09:10:34 827,904 ----a-w C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll
+ 2007-11-30 12:39:33 16,760 ----a-w C:\WINDOWS\$hf_mig$\KB956391\spmsg.dll
+ 2007-11-30 12:39:33 230,264 ----a-w C:\WINDOWS\$hf_mig$\KB956391\spuninst.exe
+ 2007-11-30 12:39:33 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB956391\update\spcustom.dll
+ 2007-11-30 12:39:36 749,944 ----a-w C:\WINDOWS\$hf_mig$\KB956391\update\update.exe
+ 2007-11-30 12:39:36 374,648 ----a-w C:\WINDOWS\$hf_mig$\KB956391\update\updspapi.dll
+ 2008-08-14 10:34:26 138,496 ----a-w C:\WINDOWS\$hf_mig$\KB956803\SP3QFE\afd.sys
+ 2007-11-30 11:19:16 16,760 ----a-w C:\WINDOWS\$hf_mig$\KB956803\spmsg.dll
+ 2007-11-30 11:19:16 230,264 ----a-w C:\WINDOWS\$hf_mig$\KB956803\spuninst.exe
+ 2007-11-30 11:19:15 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB956803\update\spcustom.dll
+ 2007-11-30 11:19:20 749,944 ----a-w C:\WINDOWS\$hf_mig$\KB956803\update\update.exe
+ 2007-11-30 11:19:20 374,648 ----a-w C:\WINDOWS\$hf_mig$\KB956803\update\updspapi.dll
+ 2008-09-08 11:37:19 333,824 ----a-w C:\WINDOWS\$hf_mig$\KB957095\SP3QFE\srv.sys
+ 2007-11-30 11:19:16 16,760 ----a-w C:\WINDOWS\$hf_mig$\KB957095\spmsg.dll
+ 2007-11-30 11:19:16 230,264 ----a-w C:\WINDOWS\$hf_mig$\KB957095\spuninst.exe
+ 2007-11-30 11:19:15 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB957095\update\spcustom.dll
+ 2007-11-30 11:19:20 749,944 ----a-w C:\WINDOWS\$hf_mig$\KB957095\update\update.exe
+ 2007-11-30 11:19:20 374,648 ----a-w C:\WINDOWS\$hf_mig$\KB957095\update\updspapi.dll
+ 2007-11-30 12:39:33 230,264 -c----w C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe
+ 2007-11-30 12:39:36 374,648 -c----w C:\WINDOWS\$NtUninstallKB956391$\spuninst\updspapi.dll
+ 2008-06-20 11:40:08 138,496 -c----w C:\WINDOWS\$NtUninstallKB956803$\afd.sys
+ 2007-11-30 11:19:16 230,264 -c----w C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe
+ 2007-11-30 11:19:20 374,648 -c----w C:\WINDOWS\$NtUninstallKB956803$\spuninst\updspapi.dll
+ 2007-11-30 11:19:16 230,264 -c----w C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe
+ 2007-11-30 11:19:20 374,648 -c----w C:\WINDOWS\$NtUninstallKB957095$\spuninst\updspapi.dll
+ 2008-04-13 19:15:11 334,848 -c----w C:\WINDOWS\$NtUninstallKB957095$\srv.sys
- 2008-06-23 16:28:17 124,928 ------w C:\WINDOWS\system32\advpack.dll
+ 2008-08-26 08:11:45 124,928 ----a-w C:\WINDOWS\system32\advpack.dll
- 2008-06-20 11:40:08 138,496 -c----w C:\WINDOWS\system32\dllcache\afd.sys
+ 2008-08-14 10:04:36 138,496 -c----w C:\WINDOWS\system32\dllcache\afd.sys
- 2008-06-20 11:40:08 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys
+ 2008-08-14 10:04:36 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys
- 2008-09-05 06:52:22 332,280 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-10-18 20:39:15 332,280 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
- 2008-06-23 16:28:17 63,488 ------w C:\WINDOWS\system32\icardie.dll
+ 2008-08-26 08:11:46 63,488 ----a-w C:\WINDOWS\system32\icardie.dll
- 2008-06-23 16:28:17 383,488 ------w C:\WINDOWS\system32\ieapfltr.dll
+ 2008-08-26 08:11:46 383,488 ----a-w C:\WINDOWS\system32\ieapfltr.dll
- 2008-06-23 16:28:19 6,066,176 ------w C:\WINDOWS\system32\ieframe.dll
+ 2008-10-03 17:16:39 6,066,176 ----a-w C:\WINDOWS\system32\ieframe.dll
- 2008-06-23 16:28:19 267,776 ------w C:\WINDOWS\system32\iertutil.dll
+ 2008-08-26 08:11:49 267,776 ----a-w C:\WINDOWS\system32\iertutil.dll
- 2008-06-23 16:28:20 459,264 ------w C:\WINDOWS\system32\msfeeds.dll
+ 2008-08-26 08:11:50 459,264 ----a-w C:\WINDOWS\system32\msfeeds.dll
- 2008-06-23 16:28:20 52,224 ------w C:\WINDOWS\system32\msfeedsbs.dll
+ 2008-08-26 08:11:50 52,224 ----a-w C:\WINDOWS\system32\msfeedsbs.dll
- 2008-06-24 07:28:22 3,592,192 ------w C:\WINDOWS\system32\mshtml.dll
+ 2008-08-27 09:11:54 3,593,216 ----a-w C:\WINDOWS\system32\mshtml.dll
- 2008-10-18 20:25:08 73,560 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-10-19 04:48:57 73,560 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-10-18 20:25:08 71,248 ----a-w C:\WINDOWS\system32\perfc00d.dat
+ 2008-10-19 04:48:57 71,248 ----a-w C:\WINDOWS\system32\perfc00d.dat
- 2008-10-18 20:25:08 448,168 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-10-19 04:48:57 448,168 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2008-10-18 20:25:09 354,598 ----a-w C:\WINDOWS\system32\perfh00d.dat
+ 2008-10-19 04:48:57 354,598 ----a-w C:\WINDOWS\system32\perfh00d.dat
- 2008-06-23 16:28:21 105,984 ------w C:\WINDOWS\system32\url.dll
+ 2008-08-26 08:11:54 105,984 ----a-w C:\WINDOWS\system32\url.dll
- 2008-06-23 16:28:22 1,159,680 ------w C:\WINDOWS\system32\urlmon.dll
+ 2008-08-26 08:11:54 1,159,680 ----a-w C:\WINDOWS\system32\urlmon.dll
+ 2008-10-19 18:27:51 16,384 ----atw C:\WINDOWS\temp\Perflib_Perfdata_614.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [04/14/2008 04:17 AM 15360]
"AnyDVD"="C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe" [08/12/2007 01:28 PM 1465280]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [10/18/2007 10:34 AM 5724184]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [06/23/2007 04:03 PM 68856]
"Google Update"="C:\Documents and Settings\yehuda\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [09/05/2008 08:26 AM 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [07/09/2001 10:50 AM 155648]
"CloneCDTray"="C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" [09/28/2006 09:21 PM 57344]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [10/06/2006 06:11 AM 98304]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [10/06/2006 06:13 AM 114688]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [10/06/2006 06:10 AM 94208]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [09/23/2008 08:00 PM 185896]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [08/01/2008 03:23 PM 61440]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [09/30/2008 08:39 AM 1234712]
"SkyTel"="SkyTel.EXE" [05/16/2006 12:04 PM 2879488 C:\WINDOWS\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [10/30/2006 01:49 PM 16269312 C:\WINDOWS\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [04/14/2008 04:17 AM 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\qoMddBrS]
[BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^תפריט התחלה^תוכניות^הפעלה^DigiCell.lnk]
path=C:\Documents and Settings\All Users\תפריט התחלה\תוכניות\הפעלה\DigiCell.lnk
backup=C:\WINDOWS\pss\DigiCell.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^תפריט התחלה^תוכניות^הפעלה^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\תפריט התחלה\תוכניות\הפעלה\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^תפריט התחלה^תוכניות^הפעלה^HP Photosmart Premier Fast Start.lnk]
path=C:\Documents and Settings\All Users\תפריט התחלה\תוכניות\הפעלה\HP Photosmart Premier Fast Start.lnk
backup=C:\WINDOWS\pss\HP Photosmart Premier Fast Start.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^תפריט התחלה^תוכניות^הפעלה^MSI Wireless Utility.lnk]
path=C:\Documents and Settings\All Users\תפריט התחלה\תוכניות\הפעלה\MSI Wireless Utility.lnk
backup=C:\WINDOWS\pss\MSI Wireless Utility.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^תפריט התחלה^תוכניות^הפעלה^PC Alert 4.lnk]
path=C:\Documents and Settings\All Users\תפריט התחלה\תוכניות\הפעלה\PC Alert 4.lnk
backup=C:\WINDOWS\pss\PC Alert 4.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^תפריט התחלה^תוכניות^הפעלה^Program Neighborhood Agent.lnk]
path=C:\Documents and Settings\All Users\תפריט התחלה\תוכניות\הפעלה\Program Neighborhood Agent.lnk
backup=C:\WINDOWS\pss\Program Neighborhood Agent.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^yehuda^תפריט התחלה^תוכניות^הפעלה^MotionBased Agent.lnk]
path=C:\Documents and Settings\yehuda\תפריט התחלה\תוכניות\הפעלה\MotionBased Agent.lnk
backup=C:\WINDOWS\pss\MotionBased Agent.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 09/03/2005 02:18 PM 94208 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 02/19/2006 01:41 AM 49152 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
--a------ 07/08/2006 01:15 AM 600896 C:\Program Files\Microsoft IntelliPoint\ipoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\itype]
--a------ 07/08/2006 01:14 AM 576320 C:\Program Files\Microsoft IntelliType Pro\itype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
--------- 03/14/2007 09:01 PM 54832 C:\Program Files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 05/27/2008 09:50 AM 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--------- 03/14/2007 09:01 PM 71216 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
--a------ 02/20/2008 11:22 AM 356352 C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 06/23/2007 04:03 PM 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"C:\\Documents and Settings\\yehuda\\Application Data\\Juniper Networks\\Juniper Citrix Services Client\\dsCitrixProxy.exe"=
"C:\\Documents and Settings\\nir\\Application Data\\Juniper Networks\\Juniper Citrix Services Client\\dsCitrixProxy.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\CyberLink\\PowerDirector\\PDR.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\CompeGPS\\CompeGPSLAND.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [08/29/2008 07:25 AM 97928]
R2 {95808DC4-FA4A-4C74-92FE-5B863F82066B};{95808DC4-FA4A-4C74-92FE-5B863F82066B};C:\Program Files\CyberLink\PowerDVD\
000.fcl [09/19/2007 09:37 PM 41456]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [08/29/2008 07:25 AM 875288]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [08/29/2008 07:25 AM 231704]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [07/04/2008 08:18 AM 76040]
R2 mgnt;mgnt;C:\WINDOWS\system32\drivers\mgnt.sys [09/22/1997 10:55 AM 19232]
R3 dsNcAdpt;Juniper Network Connect Adapter;C:\WINDOWS\system32\DRIVERS\dsNcAdpt.sys [12/28/2007 04:48 AM 23552]
S3 DigiCellDriver;DigiCellDriver;C:\Program Files\MSI\DigiCell\NTGLM7X.sys [06/07/2006 10:00 AM 28672]
S3 PCASp50;PCASp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\PCASp50.sys [10/25/2004 02:40 PM 17664]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1797ffd9-1a0c-11dd-b9ba-0019db231763}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2008-10-15 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [04/11/2008 04:57 PM]
2008-10-19 C:\WINDOWS\Tasks\GoogleUpdateTaskUser.job
- C:\Documents and Settings\yehuda\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [09/05/2008 08:26 AM]
.
- - - - ORPHANS REMOVED - - - -
BHO-{3D663865-4C76-4403-8A4F-33711B5AD700} - (no file)
BHO-{BCE97A72-640B-4DED-923F-8196FC01F76B} - (no file)
MSConfigStartUp-Adobe Reader Speed Launcher - C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-19 22:35:10
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{95808DC4-FA4A-4C74-92FE-5B863F82066B}]
"ImagePath"="\??\C:\Program Files\CyberLink\PowerDVD\
000.fcl"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\NavLogon.dll
.
Completion time: 10/19/2008 22:36:26
ComboFix-quarantined-files.txt 2008-10-19 20:36:16
ComboFix2.txt 2008-10-18 20:29:18
Pre-Run: 183,827,296,256 bytes free
Post-Run: 183,838,474,240 bytes free
336 --- E O F --- 2008-10-18 20:26:14