OK, here are the logs :
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Sunday, April 11, 2010
Operating system: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Saturday, April 10, 2010 23:53:41
Records in database: 3933653
--------------------------------------------------------------------------------
Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes
Scan area - My Computer:
A:\
C:\
D:\
F:\
G:\
Scan statistics:
Objects scanned: 101297
Threats found: 1
Infected objects found: 1
Suspicious objects found: 0
Scan duration: 11:12:36
File name / Threat / Threats count
D:\downloads\Daemon Tools 4.0 + crack.rar Infected: not-a-virus:WebToolbar.Win32.WhenU.a 1
Selected area has been scanned.
ComboFix 10-04-10.01 - Argaman 04/10/2010 22:03:16.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1255.972.1033.18.1006.459 [GMT 2:00]
Running from: c:\documents and settings\Argaman\Desktop\virus removal\ComboFix.exe
Command switches used :: c:\documents and settings\Argaman\Desktop\virus removal\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Argaman\Application Data\uTorrent
c:\documents and settings\Argaman\Application Data\uTorrent\Amazon.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\American Psycho.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Amy Winehouse - Frank.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Annie Lennox - Songs Of Mass Destruction [2007].torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Arthur Fiedler & The Boston Pops - A Christmas Festival.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Big.Love.S03E01.HDTV.XviD-SYS.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Big.Love.S03E02.HDTV.XviD-SYS.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Big.Love.S03E03.HDTV.XviD-0TV.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Big.Love.S03E04.HDTV.XviD-0TV.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Big.Love.S03E05.HDTV.XviD-0TV.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Big.Love.S03E06.HDTV.XviD-0TV.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Big.Love.S03E07.HDTV.XviD-SYS.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Big.Love.S03E08.HDTV.XviD-NoTV.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Big.Love.S03E09.HDTV.XviD-0TV.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Big.Love.S03E10.HDTV.XviD-0TV.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Blancmange - 1996 - Best Of Blancmange.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Blondie-Parallel Lines(Darkside_RG).torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Britney Spears - Blackout [Australian Limited Edition +4 bonus tracks].torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Britney.Spears.-.Gimme.More.(Live.At.MTV.VMA2007).[SatRip].By.Regenzy.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Brothers.And.Sisters.S01E02.HDTV.XviD-LOL[
www.moviex.info].torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Brothers.and.Sisters.S02E10.HDTV.XviD-XOR.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Brothers.and.Sisters.S02E11.HDTV.XviD-NoTV.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Brothers.and.Sisters.S02E12.HDTV.XViD-DOT.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Brothers.and.Sisters.S02E12.HDTV.XViD-DOT.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Brothers.and.Sisters.S02E13.HDTV.XViD-DOT.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Brothers.and.Sisters.S02E14.HDTV.XviD-0TV.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Brothers.and.Sisters.S02E15.HDTV.XViD-DOT.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Brothers.and.Sisters.S02E16.HDTV.XViD-DOT.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\CnC3_ISO_flt.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Command.And.Conquer.3.Kanes.Wrath-RELOADED.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Command.And.Conquer.Red.Alert.3-RELOADED.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Command_And_Conquer_3_Tiberium_Wars_Kane_Edition_DVD9-FLT.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Desperate Housewives (Season 1).torrent
c:\documents and settings\Argaman\Application Data\uTorrent\dht.dat
c:\documents and settings\Argaman\Application Data\uTorrent\dht.dat.old
c:\documents and settings\Argaman\Application Data\uTorrent\Fireflies - Owl City.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Greatest Hits.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Grey's anatomy - Season 4 Full - ENG.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Greys Anatomy s03e22 Vostfr by Ck and House-of-Subs.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Greys Anatomy s03e25 Didn't We Almost Have It All Vostfr by HoS.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\greys.anatomy.s03e18.hdtv.vostfr -LBP.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Greys.Anatomy.S03E19.HDTV.XviD-XOR.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Greys.Anatomy.S03E20.VOSTFR.HDTV.zip.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Greys.Anatomy.S03E21.Desire.SWESUB.HDTV.XviD-KORP.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\greys.anatomy.s03e23.hdtv.xvid.vostfr-LBP.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\greys.anatomy.s03e24.hdtv.vostfr-LBP.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\INXS.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\La Roux - La Roux [2009][CD+3 SkidVid_XviD+Cov]320Kbps.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Learn Hebrew - Pimsleur Hebrew I.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Leonard Cohen - Live In London [2cd-mp3-vbr-2009].torrent
c:\documents and settings\Argaman\Application Data\uTorrent\MGMT - Climbing To New Lows.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\MGMT - Oracular Spectacular 320kbs.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Michel Thomas - German.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Mortal.Kombat.Trilogy.DvdRip.Moviex.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\owlcity_fireflies.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Paranormal.Activity.Screener.XVID-IMAGiNE.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Pet Shop Boys - Yes [LE] [2009][2CD+SkidVid_XviD+Cov]320Kbps.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Pimsleur Hebrew.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\resume.dat
c:\documents and settings\Argaman\Application Data\uTorrent\resume.dat.old
c:\documents and settings\Argaman\Application Data\uTorrent\Rihanna - A Girl Like Me [2006][CD+3Vids+Cov].torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Rihanna - Music of the Sun (with covers) a dhz-employee Release.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\rss.dat
c:\documents and settings\Argaman\Application Data\uTorrent\rss.dat.old
c:\documents and settings\Argaman\Application Data\uTorrent\S3.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Sade - The Best of Sade.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Season 12.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\settings.dat
c:\documents and settings\Argaman\Application Data\uTorrent\settings.dat.old
c:\documents and settings\Argaman\Application Data\uTorrent\South Park Season 10 DvDrip-McTav.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\South park Season 11 Complete.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\South.Park.S13E01.HDTV.XviD.InTeGrAl.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\South.Park.S13E02.DSR.XviD-0TV.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\South.Park.S13E03.DSR.XviD-0TV.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\South.Park.S13E04.HDTV.XviD-aAF.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\South.Park.S13E05.DSR.XviD-0TV.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\South.Park.S13E06.HDTV.XVID-BAJSKORV.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\South.Park.S13E07.HDTV.XviD-aAF.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\South.Park.S13E08.Dead.Celebrities.HDTV.XviD-FQM.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\South.Park.S13E09.Butters.Bottom.Bitch.HDTV.XviD-FQM.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\South.Park.S13E10.W.T.F.HDTV.XviD-FQM.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\South.Park.S13E11.Whale.Whores.HDTV.XviD-FQM.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\South.Park.S13E12.HDTV.XviD-SYS.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\South.Park.S13E13.Dances.with.Smurfs.HDTV.XviD-FQM.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\South.Park.S13E14.Pee.HDTV.XviD-FQM.avi.1.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\South.Park.S13E14.Pee.HDTV.XviD-FQM.avi.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Spooks - 2.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Spooks Season 3.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Spooks, Season 1.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Spooks, Season 4.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Spooks.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Suburban Shootout Complete 1st Season.rar.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Survivor Marquesas - Complete Season 4.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Survivor S5 Thailand.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Survivor Season 4 Marquesas.1.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Survivor Season 4 Marquesas.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Survivor Season 7 Pearl Islands.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Survivor.s01.Pulau.Tiga.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Survivor.s02.Australian.Outback.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Survivor.s03.Africa.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Survivor.s04.Marquesas.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\TEARS FOR FEARS - Tears Roll Down (Greatest Hits 82-92) [2004 2CD Re-Issue].torrent
c:\documents and settings\Argaman\Application Data\uTorrent\The Best Of.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\The_Nightmare_Before_Christmas(DVDRip)(xvid)-Goblin10.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Ting Tings - We Started Nothing - P0w3rp0t1.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Ugly Betty Season 3.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\utorrent.lng
c:\documents and settings\Argaman\Application Data\uTorrent\Veronica Mars Season 1.torrent
c:\documents and settings\Argaman\Application Data\uTorrent\Weeds Season 5 - DAVENET -
www.RapidTreggy.com.torrent
c:\program files\eMule
c:\program files\eMule\Temp\002.part
c:\program files\eMule\Temp\002.part.met
c:\program files\eMule\Temp\002.part.met.bak
c:\program files\eMule\Temp\003.part
c:\program files\eMule\Temp\003.part.met
c:\program files\eMule\Temp\003.part.met.bak
c:\program files\eMule\Temp\004.part
c:\program files\eMule\Temp\004.part.met
c:\program files\eMule\Temp\004.part.met.bak
c:\program files\eMule\Temp\010.part
c:\program files\eMule\Temp\010.part.met
c:\program files\eMule\Temp\010.part.met.bak
c:\program files\eMule\Temp\014.part
c:\program files\eMule\Temp\014.part.met
c:\program files\eMule\Temp\014.part.met.bak
c:\program files\eMule\Temp\018.part
c:\program files\eMule\Temp\018.part.met
c:\program files\eMule\Temp\018.part.met.bak
c:\program files\eMule\Temp\020.part
c:\program files\eMule\Temp\020.part.met
c:\program files\eMule\Temp\020.part.met.bak
c:\windows\TEMP\logishrd\LVPrcInj01.dll
.
((((((((((((((((((((((((( Files Created from 2010-03-10 to 2010-04-10 )))))))))))))))))))))))))))))))
.
2010-04-01 21:37 . 2010-04-01 21:37 -------- d-----w- c:\program files\ERUNT
2010-04-01 21:20 . 2010-04-01 21:20 -------- d-----w- c:\program files\Trend Micro
2010-03-31 21:21 . 2010-03-31 21:21 -------- d-----w- c:\program files\iPod
2010-03-31 21:21 . 2010-03-31 21:23 -------- d-----w- c:\program files\iTunes
2010-03-31 21:21 . 2010-03-31 21:23 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-03-31 21:15 . 2010-03-31 21:16 -------- d-----w- c:\program files\QuickTime
2010-03-31 21:09 . 2010-03-31 21:09 -------- d-----w- c:\program files\Bonjour
2010-03-31 20:50 . 2010-03-31 20:50 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.0.79\SetupAdmin.exe
2010-03-22 14:04 . 2010-03-22 14:04 255472 ----a-w- c:\documents and settings\Argaman\Application Data\Mozilla\plugins\npgoogletalk.dll
2010-03-13 18:18 . 2010-03-13 18:18 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-03-13 18:17 . 2010-03-13 18:17 152576 ----a-w- c:\documents and settings\Argaman\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-03-13 18:16 . 2010-03-13 18:16 79488 ----a-w- c:\documents and settings\Argaman\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-10 20:17 . 2007-01-12 21:52 -------- d-----w- c:\documents and settings\Argaman\Application Data\Skype
2010-04-10 20:15 . 2009-09-21 15:01 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs
2010-04-10 20:15 . 2009-09-21 15:00 0 ----a-w- c:\windows\system32\drivers\logiflt.iad
2010-04-10 00:06 . 2010-01-24 17:51 -------- d-----w- c:\program files\Songbird
2010-03-31 21:21 . 2010-01-05 17:39 -------- d-----w- c:\program files\Common Files\Apple
2010-03-13 18:18 . 2007-03-15 18:05 -------- d-----w- c:\program files\Java
2010-03-02 20:12 . 2007-01-12 21:53 -------- d-----w- c:\program files\Picasa2
2010-02-26 11:21 . 2010-02-26 11:21 -------- d-----w- c:\program files\CheckPoint
2010-02-25 06:24 . 2004-08-03 22:56 916480 ------w- c:\windows\system32\wininet.dll
2010-02-19 23:47 . 2010-02-19 23:47 3604480 ----a-w- c:\windows\system32\GPhotos.scr
2010-02-16 21:33 . 2010-02-16 21:33 -------- d-----w- c:\program files\Doblon
2010-02-14 21:24 . 2010-02-14 21:24 -------- d-----w- c:\documents and settings\All Users\Application Data\GoldWave
2010-02-12 09:46 . 2010-02-12 09:46 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-02-12 09:46 . 2010-02-12 09:46 107808 ----a-w- c:\windows\system32\dns-sd.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\mozy2]
@="{747E722C-CB46-4A9D-BDFE-192AAD5099B1}"
[HKEY_CLASSES_ROOT\CLSID\{747E722C-CB46-4A9D-BDFE-192AAD5099B1}]
2008-01-04 23:47 2389296 ----a-w- c:\program files\MozyHome\mozyshell1.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\mozy3]
@="{EE6F5A00-7898-40F7-AB77-51FF9D6DEB20}"
[HKEY_CLASSES_ROOT\CLSID\{EE6F5A00-7898-40F7-AB77-51FF9D6DEB20}]
2008-01-04 23:47 2389296 ----a-w- c:\program files\MozyHome\mozyshell1.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2006-12-18 25365032]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-16 68856]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-10-02 1124352]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 7\PCSync2.exe" [2008-06-17 1249280]
"Google Update"="c:\documents and settings\Argaman\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-09-26 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelAudioStudio"="c:\program files\Intel Audio Studio\IntelAudioStudio.exe" [2006-08-02 9134080]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-07-21 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-07-21 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-01 7618560]
"nwiz"="nwiz.exe" [2006-06-01 1519616]
"NvMediaCenter"="NvMCTray.dll" [2006-06-01 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-03-13 149280]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2005-11-08 128920]
"UPSMON"="c:\program files\UPSMON\UPSMON.exe" [2005-03-30 429568]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2010-03-19 2046816]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-09-22 564496]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-03-25 142120]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-03 53760]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-19 07:59 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
2005-09-22 20:31 454144 ----a-w- c:\program files\AnyDVD\AnyDVD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 09:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-17 19:53 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-06-16 04:16 68856 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WmiApSrv"=3 (0x3)
"usnjsvc"=3 (0x3)
"STI Simulator"=2 (0x2)
"Spooler"=2 (0x2)
"IDriverT"=3 (0x3)
"gusvc"=3 (0x3)
"FastUserSwitchingCompatibility"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"Persistence"=c:\windows\system32\igfxpers.exe
"SigmatelSysTrayApp"=sttray.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"c:\\Program Files\\ESTsoft\\ALFTP\\ALFTP.exe"=
"c:\\WINDOWS\\system32\\javaw.exe"=
"c:\\Program Files\\cygwin\\usr\\X11R6\\bin\\XWin.exe"=
"c:\\Games\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"d:\\games\\Starcraft\\StarCraft.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Documents and Settings\\Argaman\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Argaman\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [4/7/2007 01:19 664064]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/14/2008 16:39 335240]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [1/30/2009 07:07 297752]
R2 cpextender;Check Point SSL Network Extender;c:\program files\CheckPoint\SSL Network Extender\slimsvc.exe [6/10/2007 16:48 331870]
R3 VNA;Check Point Virtual Network Adapter;c:\windows\system32\drivers\vna.sys [6/10/2007 16:48 110160]
S3 PAC207;SoC
PC-Camer@;c:\windows\system32\DRIVERS\pfc027.sys --> c:\windows\system32\DRIVERS\pfc027.sys [?]
S3 tj2knd5;Terayon Cable Modem (NDIS);c:\windows\system32\drivers\tj2knd5.sys [1/16/2007 16:33 17616]
S3 tj2kunic;Terayon Cable Modem (WDM);c:\windows\system32\drivers\tj2kunic.sys [1/16/2007 16:33 69680]
.
Contents of the 'Scheduled Tasks' folder
2010-03-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2010-04-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-682003330-1637723038-839522115-1005Core.job
- c:\documents and settings\Argaman\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-09-26 15:35]
2010-04-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-682003330-1637723038-839522115-1005UA.job
- c:\documents and settings\Argaman\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-09-26 15:35]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://goggleonline.blogspot.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
Trusted Zone: huji.ac.il\owl
FF - ProfilePath - c:\documents and settings\Argaman\Application Data\Mozilla\Firefox\Profiles\42a3c560.default\
FF - prefs.js: browser.startup.homepage - hxxp://he.wikipedia.org/wiki/%D7%A2%D7%9E%D7%95%D7%93_%D7%A8%D7%90%D7%A9%D7%99
FF - plugin: c:\documents and settings\Argaman\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\Argaman\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Picasa2\npPicasa3.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-04-10 22:17
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe >>UNKNOWN [0x86B978C0]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> 0x86b978c0
\Driver\ACPI -> ACPI.sys @ 0xf7386cb8
\Driver\atapi -> atapi.sys @ 0xf732b2f0
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x8058241c
ParseProcedure -> ntkrnlpa.exe @ 0x8058155c
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x8058241c
ParseProcedure -> ntkrnlpa.exe @ 0x8058155c
NDIS: Intel(R) 82566DC Gigabit Network Connection -> SendCompleteHandler -> NDIS.sys @ 0xf71edba0
PacketIndicateHandler -> NDIS.sys @ 0xf71fab21
SendHandler -> NDIS.sys @ 0xf71d887b
Warning: possible MBR rootkit infection !
user & kernel MBR OK
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-682003330-1637723038-839522115-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:d6,ad,38,e8,e0,34,13,40,59,53,08,3c,1e,4c,2a,8e,e6,bf,48,bb,ba,fc,6b,
02,c1,47,ee,ea,43,df,63,ff,ef,6f,4f,4a,fc,71,8e,69,f7,e5,f1,56,7a,e4,97,6e,\
"??"=hex:5a,72,24,8d,85,f6,c5,69,f9,c1,2a,1f,64,1a,95,bc
[HKEY_USERS\S-1-5-21-682003330-1637723038-839522115-1005\Software\SecuROM\License information*]
"datasecu"=hex:06,0c,d8,9f,c1,2e,ed,f5,c8,18,ea,29,ab,d4,1a,39,0b,4c,19,c9,f1,
6c,1f,43,da,05,09,33,6f,18,84,4a,f7,b2,74,53,71,72,6f,ed,cc,b5,40,df,b1,6b,\
"rkeysecu"=hex:30,aa,8e,59,3f,a8,50,1d,14,05,e2,ab,e1,7d,22,38
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(4292)
c:\windows\system32\WININET.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\program files\MozyHome\mozyshell1.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\browselc.dll
c:\windows\system32\igfxsrvc.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\RunDLL32.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\MozyHome\mozybackup.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wdfmgr.exe
c:\program files\UPSMON\UPSMON_Service.Exe
c:\program files\UPSMON\UPSInt2.exe
c:\program files\Skype\Plugin Manager\SkypePM.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\windows\system32\wscntfy.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Nokia\MPAPI\MPAPI3s.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\program files\Windows Live\Contacts\wlcomm.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2010-04-10 22:23:01 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-10 20:22
Pre-Run: 28,937,256,960 bytes free
Post-Run: 28,902,912,000 bytes free
- - End Of File - - 8DF1E01A72F72604181D67A80A91AAC6
DDS (Ver_10-03-17.01) - NTFSx86
Run by Argaman at 23:07:38.09 on Sun 04/11/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_19
Microsoft Windows XP Home Edition 5.1.2600.2.1255.972.1033.18.1006.484 [GMT 2:00]
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\UPSMON\UPSMON.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe
C:\WINDOWS\system32\ctfmon.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\CheckPoint\SSL Network Extender\slimsvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\MozyHome\mozybackup.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\UPSMON\UPSMON_Service.Exe
C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\UPSMON\UPSInt2.exe
C:\Program Files\Skype\Plugin Manager\SkypePM.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Argaman\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe
C:\Program Files\AVG\AVG8\avgscanx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Argaman\My Documents\Downloads\dds.com
============== Pseudo HJT Report ===============
uStart Page = hxxp://goggleonline.blogspot.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [MsnMsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [PC Suite Tray] "c:\program files\nokia\nokia pc suite 7\PCSuite.exe" -onlytray
uRun: [Nokia.PCSync] "c:\program files\nokia\nokia pc suite 7\PCSync2.exe" /NoDialog
uRun: [Google Update] "c:\documents and settings\argaman\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [IntelAudioStudio] "c:\program files\intel audio studio\IntelAudioStudio.exe" TRAY
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
mRun: [DAEMON Tools] "c:\program files\daemon tools\daemon.exe" -lang 1033
mRun: [UPSMON] c:\program files\upsmon\UPSMON.exe
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [googletalk] c:\program files\google\google talk\googletalk.exe /autostart
mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
dRun: [ctfmon.exe] c:\windows\system32\CTFMON.EXE
dRunOnce: [RunNarrator] Narrator.exe
StartupFolder: c:\docume~1\argaman\startm~1\programs\startup\adsl.lnk -
StartupFolder: c:\docume~1\argaman\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Trusted Zone: huji.ac.il\owl
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {474F00F5-3853-492C-AC3A-476512BBC336} - hxxp://picasaweb.google.com/s/v/e/36.24/KBTUZDFvTZs/uploader2.cab
DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} - hxxp://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/DE-DE/a-UNO1/GAME_UNO1.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1161242712516
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\argaman\applic~1\mozilla\firefox\profiles\42a3c560.default\
FF - prefs.js: browser.startup.homepage - hxxp://he.wikipedia.org/wiki/%D7%A2%D7%9E%D7%95%D7%93_%D7%A8%D7%90%D7%A9%D7%99
FF - plugin: c:\documents and settings\argaman\application data\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\argaman\local settings\application data\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\picasa2\npPicasa3.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-6-14 335240]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2007-1-8 27784]
R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-5-12 611664]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-1-30 297752]
R2 cpextender;Check Point SSL Network Extender;c:\program files\checkpoint\ssl network extender\slimsvc.exe [2007-6-10 331870]
R3 VNA;Check Point Virtual Network Adapter;c:\windows\system32\drivers\vna.sys [2007-6-10 110160]
S3 PAC207;SoC
PC-Camer@;c:\windows\system32\drivers\pfc027.sys --> c:\windows\system32\drivers\pfc027.sys [?]
S3 tj2knd5;Terayon Cable Modem (NDIS);c:\windows\system32\drivers\tj2knd5.sys [2007-1-16 17616]
S3 tj2kunic;Terayon Cable Modem (WDM);c:\windows\system32\drivers\tj2kunic.sys [2007-1-16 69680]
=============== Created Last 30 ================
2010-04-10 20:49:26 0 ------w- c:\temp\jre-6u19-windows-i586.exe
2010-04-10 20:48:40 0 d-----w- c:\documents and settings\argaman\.SunDownloadManager
2010-04-10 20:32:27 0 d-----w- c:\windows\system32\Adobe
2010-04-08 22:10:43 0 d-sha-r- C:\cmdcons
2010-04-08 22:09:28 98816 ----a-w- c:\windows\sed.exe
2010-04-08 22:09:28 77312 ----a-w- c:\windows\MBR.exe
2010-04-08 22:09:28 261632 ----a-w- c:\windows\PEV.exe
2010-04-08 22:09:28 161792 ----a-w- c:\windows\SWREG.exe
2010-04-01 21:20:50 0 d-----w- c:\program files\Trend Micro
2010-03-31 21:21:58 0 d-----w- c:\program files\iPod
2010-03-31 21:21:29 0 d-----w- c:\program files\iTunes
2010-03-31 21:21:29 0 d-----w- c:\docume~1\alluse~1\applic~1\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-03-31 21:09:38 0 d-----w- c:\program files\Bonjour
2010-03-17 19:53:42 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-03-17 19:53:42 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-03-13 18:18:29 411368 ----a-w- c:\windows\system32\deploytk.dll
==================== Find3M ====================
2010-04-10 20:15:46 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs
2010-04-10 20:15:42 0 ----a-w- c:\windows\system32\drivers\logiflt.iad
2010-02-25 09:54:36 11070976 ------w- c:\windows\system32\dllcache\ieframe.dll
2010-02-24 09:54:25 173056 ------w- c:\windows\system32\dllcache\ie4uinit.exe
2010-02-19 23:47:50 3604480 ----a-w- c:\windows\system32\GPhotos.scr
2010-02-12 09:46:14 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-02-12 09:46:14 107808 ----a-w- c:\windows\system32\dns-sd.exe
============= FINISH: 23:08:15.15 ===============
Thank you!