И того итоги, промониторила в диагностическом режиме:

Unchecking R-O

1 19:43:13 EXPLORER.EXE:1400 OpenKey HKLM\Software\Microsoft\Speech\Recognizers\Tokens SUCCESS Access: 0x20019
2 19:43:13 EXPLORER.EXE:1400 EnumerateKey HKLM\Software\Microsoft\Speech\Recognizers\Tokens NO MORE ENTRIES
3 19:43:13 EXPLORER.EXE:1400 CloseKey HKLM\Software\Microsoft\Speech\Recognizers\Tokens SUCCESS
4 19:43:29 EXPLORER.EXE:1400 OpenKey HKLM\Software\Microsoft\Speech\Recognizers\Tokens SUCCESS Access: 0x20019

Applying

5 19:43:29 EXPLORER.EXE:1400 EnumerateKey HKLM\Software\Microsoft\Speech\Recognizers\Tokens NO MORE ENTRIES
6 19:43:29 EXPLORER.EXE:1400 CloseKey HKLM\Software\Microsoft\Speech\Recognizers\Tokens SUCCESS
7 19:43:29 System:4 OpenKey HKLM\System\CurrentControlSet\Services\SymEvent\Parameters SUCCESS Access: 0x20019
8 19:43:29 System:4 QueryValue HKLM\System\CurrentControlSet\Services\SymEvent\Parameters\LPNtoSPN SUCCESS 0x1
9 19:43:29 System:4 CloseKey HKLM\System\CurrentControlSet\Services\SymEvent\Parameters SUCCESS
10 19:43:29 EXPLORER.EXE:1400 OpenKey HKLM\Software\Microsoft\Speech\Recognizers\Tokens SUCCESS Access: 0x20019
11 19:43:29 EXPLORER.EXE:1400 EnumerateKey HKLM\Software\Microsoft\Speech\Recognizers\Tokens NO MORE ENTRIES
12 19:43:29 EXPLORER.EXE:1400 CloseKey HKLM\Software\Microsoft\Speech\Recognizers\Tokens SUCCESS


Applying to this file only

13 19:43:34 EXPLORER.EXE:1400 OpenKey HKLM\Software\Microsoft\Speech\Recognizers\Tokens SUCCESS Access: 0x20019
14 19:43:34 EXPLORER.EXE:1400 EnumerateKey HKLM\Software\Microsoft\Speech\Recognizers\Tokens NO MORE ENTRIES
15 19:43:34 EXPLORER.EXE:1400 CloseKey HKLM\Software\Microsoft\Speech\Recognizers\Tokens SUCCESS


Final applying

16 19:43:37 EXPLORER.EXE:1400 OpenKey HKLM\Software\Microsoft\Speech\Recognizers\Tokens SUCCESS Access: 0x20019
17 19:43:37 EXPLORER.EXE:1400 EnumerateKey HKLM\Software\Microsoft\Speech\Recognizers\Tokens NO MORE ENTRIES
18 19:43:37 EXPLORER.EXE:1400 CloseKey HKLM\Software\Microsoft\Speech\Recognizers\Tokens SUCCESS
19 19:43:37 EXPLORER.EXE:1400 OpenKey HKLM\Software\Microsoft\Speech\Recognizers\Tokens SUCCESS Access: 0x20019
20 19:43:37 EXPLORER.EXE:1400 EnumerateKey HKLM\Software\Microsoft\Speech\Recognizers\Tokens NO MORE ENTRIES
21 19:43:37 EXPLORER.EXE:1400 CloseKey HKLM\Software\Microsoft\Speech\Recognizers\Tokens SUCCESS
22 19:43:37 EXPLORER.EXE:1400 OpenKey HKLM\Software\Microsoft\Speech\Recognizers\Tokens SUCCESS Access: 0x20019
23 19:43:37 EXPLORER.EXE:1400 EnumerateKey HKLM\Software\Microsoft\Speech\Recognizers\Tokens NO MORE ENTRIES
24 19:43:37 EXPLORER.EXE:1400 CloseKey HKLM\Software\Microsoft\Speech\Recognizers\Tokens SUCCESS
25 19:43:37 EXPLORER.EXE:1400 OpenKey HKLM\Software\Microsoft\Speech\Recognizers\Tokens SUCCESS Access: 0x20019
26 19:43:37 EXPLORER.EXE:1400 EnumerateKey HKLM\Software\Microsoft\Speech\Recognizers\Tokens NO MORE ENTRIES
27 19:43:37 EXPLORER.EXE:1400 CloseKey HKLM\Software\Microsoft\Speech\Recognizers\Tokens SUCCESS
28 19:43:37 EXPLORER.EXE:1400 OpenKey HKLM\Software\Microsoft\Speech\Recognizers\Tokens SUCCESS Access: 0x20019
29 19:43:37 EXPLORER.EXE:1400 EnumerateKey HKLM\Software\Microsoft\Speech\Recognizers\Tokens NO MORE ENTRIES
30 19:43:37 EXPLORER.EXE:1400 CloseKey HKLM\Software\Microsoft\Speech\Recognizers\Tokens SUCCESS
31 19:43:37 Regmon.exe:1524 OpenKey HKLM\Software\Microsoft\Speech\Recognizers\Tokens SUCCESS Access: 0x20019
32 19:43:37 Regmon.exe:1524 EnumerateKey HKLM\Software\Microsoft\Speech\Recognizers\Tokens NO MORE ENTRIES
33 19:43:37 Regmon.exe:1524 CloseKey HKLM\Software\Microsoft\Speech\Recognizers\Tokens SUCCESS
34 19:43:37 EXPLORER.EXE:1400 CloseKey HKCR\Directory SUCCESS
35 19:43:37 EXPLORER.EXE:1400 CloseKey HKCR\Folder SUCCESS
36 19:43:37 EXPLORER.EXE:1400 CloseKey HKCR\AllFilesystemObjects SUCCESS
37 19:43:37 EXPLORER.EXE:1400 CreateKey HKCU\SOFTWARE\Microsoft\CTF\Compartment SUCCESS Access: 0xF003F
38 19:43:37 EXPLORER.EXE:1400 CreateKey HKCU\SOFTWARE\Microsoft\CTF\Compartment\{2DC1CC1F-3E09-49C5-9CF0-BF67154DC827} SUCCESS Access: 0xF003F
39 19:43:37 EXPLORER.EXE:1400 SetValue HKCU\SOFTWARE\Microsoft\CTF\Compartment\{2DC1CC1F-3E09-49C5-9CF0-BF67154DC827}\GlobalCompartment SUCCESS 1F CC C1 2D 09 3E C5 49 ...
40 19:43:37 EXPLORER.EXE:1400 CloseKey HKCU\SOFTWARE\Microsoft\CTF\Compartment\{2DC1CC1F-3E09-49C5-9CF0-BF67154DC827} SUCCESS
41 19:43:37 EXPLORER.EXE:1400 CreateKey HKCU\SOFTWARE\Microsoft\CTF\Compartment\{544D6A63-E2E8-4752-BBD1-000960BCA083} SUCCESS Access: 0xF003F
42 19:43:37 EXPLORER.EXE:1400 SetValue HKCU\SOFTWARE\Microsoft\CTF\Compartment\{544D6A63-E2E8-4752-BBD1-000960BCA083}\GlobalCompartment SUCCESS 63 6A 4D 54 E8 E2 52 47 ...
43 19:43:37 EXPLORER.EXE:1400 CloseKey HKCU\SOFTWARE\Microsoft\CTF\Compartment\{544D6A63-E2E8-4752-BBD1-000960BCA083} SUCCESS
44 19:43:37 EXPLORER.EXE:1400 CreateKey HKCU\SOFTWARE\Microsoft\CTF\Compartment\{C1A1554F-B715-48E1-921F-716FD7332CE9} SUCCESS Access: 0xF003F
45 19:43:37 EXPLORER.EXE:1400 SetValue HKCU\SOFTWARE\Microsoft\CTF\Compartment\{C1A1554F-B715-48E1-921F-716FD7332CE9}\GlobalCompartment SUCCESS 4F 55 A1 C1 15 B7 E1 48 ...
46 19:43:37 EXPLORER.EXE:1400 CloseKey HKCU\SOFTWARE\Microsoft\CTF\Compartment\{C1A1554F-B715-48E1-921F-716FD7332CE9} SUCCESS
47 19:43:37 EXPLORER.EXE:1400 CloseKey HKCU\SOFTWARE\Microsoft\CTF\Compartment SUCCESS


Лог HijackThis

Logfile of HijackThis v1.97.7
Scan saved at 21:12:38, on 29/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\clipsrv.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\tlntsvr.exe
C:\Program Files\Windows Media Connect\mswmcls.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\dmadmin.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
D:\Tools\HijackThis\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.walla.co.il/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.netvision.net.il:8080
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Babylon Client] C:\Program Files\Babylon\Babylon.exe -AutoStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\\vptray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O15 - Trusted Zone: http://security.symantec.com
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa...director/sw.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeup...tent/opuc2.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1127866875614
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab
O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab