Logfile of HijackThis v1.98.2
Scan saved at 16:15:16, on 18/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\GlobespanVirata\Adsl\dslstat.exe
C:\Program Files\GlobespanVirata\Adsl\dslagent.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\pwl\hijackthis.exe
C:\WINDOWS\system32\wuauclt.exe
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch" target="_blank" title="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch">http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch" target="_blank" title="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch" target="_blank" title="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch">http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch">http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch" target="_blank" title="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch">http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch" target="_blank" title="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch">http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch" target="_blank" title="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch" target="_blank" title="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch">http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch">http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch" target="_blank" title="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch">http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie" target="_blank" title="http://www.google.com/ie">http://www.google.com/ie
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch" target="_blank" title="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch">http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch" target="_blank" title="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch" target="_blank" title="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch">http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch">http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch" target="_blank" title="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch">http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 – HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R1 – HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/" target="_blank" title="http://ie.search.msn.com/">http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
R1 – HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/" target="_blank" title="http://ie.search.msn.com/">http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
R1 – HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie" target="_blank" title="http://www.google.com/ie">http://www.google.com/ie
R0 – HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.not.co.il/ie
R1 – HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
R1 – HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
O2 – BHO: XTTBPos00 – {055FD26D-3A88-4e15-963D-DC8493744B1D} – (no file)
O2 – BHO: SWEETIE – {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} – (no file)
O2 – BHO: Skype add-on (mastermind) – {22BF413B-C6D2-4d91-82A9-A0F997BA588C} – C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 – BHO: Zango Search Assistant Helper /fleok=1D8A83A5C2E616799AA475760EA83FA5EF80752B94E2DF7E547D442138C1 – {56F1D444-11BF-4879-A12B-79CF0177F038} – (no file)
O2 – BHO: SSVHelper Class – {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} – C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 – BHO: (no name) – {7E853D72-626A-48EC-A868-BA8D5E23E045} – (no file)
O2 – BHO: Windows Live Sign-in Helper – {9030D464-4C02-4ABF-8ECC-5164760863C6} – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 – Toolbar: ICQ Toolbar – {855F3B16-6D32-4fe6-8A56-BBB695989046} – (no file)
O3 – Toolbar: SweetIM For Internet Explorer – {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} – (no file)
O4 – HKLM\..\Run: [DSLSTATEXE] C:\Program Files\GlobespanVirata\Adsl\dslstat.exe icon
O4 – HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\GlobespanVirata\Adsl\dslagent.exe
O4 – HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 – HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 – HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 – HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 – HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 – HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 – HKCU\..\Run: [eMuleAutoStart] D:\eMule.co.il\Fire eMule 7\eMule.exe -AutoStart
O8 – Extra context menu item: &יצא ל- Microsoft Excel – res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 – Extra button: (no name) – {08B0E5C0-4FCB-11CF-AAA5-00401C608501} – C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 – Extra 'Tools' menuitem: Sun Java Console – {08B0E5C0-4FCB-11CF-AAA5-00401C608501} – C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 – Extra button: ICQ Pro – {6224f700-cba3-4071-b251-47cb894244cd} – (no file)
O9 – Extra 'Tools' menuitem: ICQ – {6224f700-cba3-4071-b251-47cb894244cd} – (no file)
O9 – Extra button: Skype – {77BF5300-1474-4EC7-9980-D32B190E9B07} – C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 – Extra button: מחקר – {92780B25-18CC-41C8-B9BE-3C9C571A8263} – C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 – Extra button: ICQ Lite – {B863453A-26C3-4e1f-A54D-A2CD196348E9} – C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 – Extra 'Tools' menuitem: ICQ Lite – {B863453A-26C3-4e1f-A54D-A2CD196348E9} – C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 – Extra button: ICQ6 – {E59EB121-F339-4851-A3BA-FE49C35617C2} – C:\Program Files\ICQ6\ICQ.exe
O9 – Extra 'Tools' menuitem: ICQ6 – {E59EB121-F339-4851-A3BA-FE49C35617C2} – C:\Program Files\ICQ6\ICQ.exe
O9 – Extra button: Messenger – {FB5F1910-F110-11d2-BB9E-00C04F795683} – C:\Program Files\Messenger\msmsgs.exe
O9 – Extra 'Tools' menuitem: Windows Messenger – {FB5F1910-F110-11d2-BB9E-00C04F795683} – C:\Program Files\Messenger\msmsgs.exe
O16 – DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) – http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb…
O16 – DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) – http://www.gamehouse.com/realarcade-webgames/caramba/zylomplayer.cab
O16 – DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) – http://a532.g.akamai.net/f/532/6712/4h/player.virtools.com/downloads/player/I…
O16 – DPF: {D79B6F43-F214-4E7A-9ECB-CCC8771F2416} (LauncherV1 Class) – http://www.tapuz.co.il/irc/main/launcher.cab
O17 – HKLM\System\CCS\Services\Tcpip\..\{B8379E65-A5AA-4351-8514-4A7ABEA1FC4A}: NameServer = 192.117.235.235 62.219.186.7
O18 – Protocol: livecall – {828030A1-22C1-4009-854F-8E305202313F} – C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 – Protocol: msnim – {828030A1-22C1-4009-854F-8E305202313F} – C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 – Protocol: skype4com – {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} – C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O21 – SSODL: WPDShServiceObj – {AAA288BA-9A4C-45B0-95D7-94D524869DB5} – C:\WINDOWS\system32\WPDShServiceObj.dll