a-squared Free - Version 4.5
Last update: 7/1/2009 3:13:50 AM
Scan settings:
Scan type: Smart Scan
Objects: Memory, Traces, Cookies, C:\WINDOWS\, C:\Program Files
Scan archives: On
Heuristics: Off
ADS Scan: On
Scan start: 7/1/2009 3:15:45 AM
Value: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Smart Keystroke Recorder --> Order detected: Trace.Registry.Smart Keystroke Recorder 2.0!A2
Value: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\Software\Elcom\Advanced ZIP Password Recovery --> Installer Language detected: Trace.Registry.Advanced ZIP Password Recovery!A2
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Elcom\Advanced ZIP Password Recovery --> InstallDir detected: Trace.Registry.Advanced ZIP Password Recovery!A2
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Elcom\Advanced ZIP Password Recovery --> Stat param #1 detected: Trace.Registry.Advanced ZIP Password Recovery!A2
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Elcom\Advanced ZIP Password Recovery --> Stat param #2 detected: Trace.Registry.Advanced ZIP Password Recovery!A2
Key: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\software\kazaa detected: Trace.Registry.KaZaA!A2
Value: HKEY_CLASSES_ROOT\.xnpd --> Content Type detected: Trace.Registry.NetPumper!A2
Value: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\NetPumper --> Order detected: Trace.Registry.NetPumper!A2
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.xnpd --> Content Type detected: Trace.Registry.NetPumper!A2
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{2F9718C7-3DBD-4ef2-BBC1-E4F91F38E51A} --> Changed detected: Trace.Registry.Smart Keystoke Recorder!A2
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{2F9718C7-3DBD-4ef2-BBC1-E4F91F38E51A} --> SlowInfoCache detected: Trace.Registry.Smart Keystoke Recorder!A2
Value: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\Software\Viewpoint\Content Debugger --> Viewpoint Manager Installer detected: Trace.Registry.Viewpoint Media Toolbar!A2
Value: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\WhenU --> Order detected: Trace.Registry.WhenU.SaveNow!A2
Value: HKEY_CLASSES_ROOT\CLSID\{371D0743-7A57-11D2-AD5A-00105A17B608}\InprocServer32 --> ThreadingModel detected: Trace.Registry.SpyPc 8.0!A2
Value: HKEY_CLASSES_ROOT\CLSID\{4F99A075-5227-11D2-AD06-00105A17B608}\InprocServer32 --> ThreadingModel detected: Trace.Registry.SpyPc 8.0!A2
Value: HKEY_CLASSES_ROOT\CLSID\{CA4FC24B-C65C-11D1-AA6F-000000000000}\InprocServer32 --> ThreadingModel detected: Trace.Registry.SpyPc 8.0!A2
Value: HKEY_CLASSES_ROOT\CLSID\{DDD136CE-517B-11D2-AD03-00105A17B608}\InprocServer32 --> ThreadingModel detected: Trace.Registry.SpyPc 8.0!A2
Value: HKEY_CLASSES_ROOT\CLSID\{E9D55102-9683-11D2-BA68-0040053687FE}\InprocServer32 --> ThreadingModel detected: Trace.Registry.SpyPc 8.0!A2
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{371D0743-7A57-11D2-AD5A-00105A17B608}\InprocServer32 --> ThreadingModel detected: Trace.Registry.SpyPc 8.0!A2
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4F99A075-5227-11D2-AD06-00105A17B608}\InprocServer32 --> ThreadingModel detected: Trace.Registry.SpyPc 8.0!A2
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CA4FC24B-C65C-11D1-AA6F-000000000000}\InprocServer32 --> ThreadingModel detected: Trace.Registry.SpyPc 8.0!A2
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DDD136CE-517B-11D2-AD03-00105A17B608}\InprocServer32 --> ThreadingModel detected: Trace.Registry.SpyPc 8.0!A2
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E9D55102-9683-11D2-BA68-0040053687FE}\InprocServer32 --> ThreadingModel detected: Trace.Registry.SpyPc 8.0!A2
Value: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\Software\ORL\WinVNC3 --> AutoPortSelect detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\Software\ORL\WinVNC3 --> BlankScreen detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\Software\ORL\WinVNC3 --> DontSetHooks detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\Software\ORL\WinVNC3 --> DontUseDriver detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\Software\ORL\WinVNC3 --> EnableFileTransfers detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\Software\ORL\WinVNC3 --> IdleTimeout detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\Software\ORL\WinVNC3 --> InputsEnabled detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\Software\ORL\WinVNC3 --> LocalInputsDisabled detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\Software\ORL\WinVNC3 --> LocalInputsPriority detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\Software\ORL\WinVNC3 --> LocalInputsPriorityTime detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\Software\ORL\WinVNC3 --> LockSetting detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\Software\ORL\WinVNC3 --> OnlyPollConsole detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\Software\ORL\WinVNC3 --> OnlyPollOnEvent detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\Software\ORL\WinVNC3 --> Password detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\Software\ORL\WinVNC3 --> PasswordViewOnly detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\Software\ORL\WinVNC3 --> PollForeground detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\Software\ORL\WinVNC3 --> PollFullScreen detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\Software\ORL\WinVNC3 --> PollingCycle detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\Software\ORL\WinVNC3 --> PollUnderCursor detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\Software\ORL\WinVNC3 --> QueryAccept detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\Software\ORL\WinVNC3 --> QueryAllowNoPass detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\Software\ORL\WinVNC3 --> QuerySetting detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\Software\ORL\WinVNC3 --> QueryTimeout detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\Software\ORL\WinVNC3 --> RemoveWallpaper detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\Software\ORL\WinVNC3 --> SocketConnect detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_LOCAL_MACHINE\SOFTWARE\ORL\WinVNC3 --> AllowLoopback detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_LOCAL_MACHINE\SOFTWARE\ORL\WinVNC3 --> AuthRequired detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_LOCAL_MACHINE\SOFTWARE\ORL\WinVNC3 --> ConnectPriority detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_LOCAL_MACHINE\SOFTWARE\ORL\WinVNC3 --> DebugLevel detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_LOCAL_MACHINE\SOFTWARE\ORL\WinVNC3 --> DebugMode detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_LOCAL_MACHINE\SOFTWARE\ORL\WinVNC3 --> EnableHTTPDaemon detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_LOCAL_MACHINE\SOFTWARE\ORL\WinVNC3 --> EnableURLParams detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_LOCAL_MACHINE\SOFTWARE\ORL\WinVNC3 --> LoopbackOnly detected: Trace.Registry.Remote Administration Tool 1.1!A2
Value: HKEY_USERS\S-1-5-21-2052111302-1085031214-725345543-1004\Software\ORL\WinVNC3 --> DriverDirectAccess detected: Trace.Registry.TightVNC 1.3!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:51 detected: Trace.TrackingCookie.myspace.com!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:52 detected: Trace.TrackingCookie.myspace.com!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:53 detected: Trace.TrackingCookie.myspace.com!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:54 detected: Trace.TrackingCookie.myspace.com!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:55 detected: Trace.TrackingCookie.myspace.com!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:56 detected: Trace.TrackingCookie.myspace.com!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:66 detected: Trace.TrackingCookie.ads.revsci.net!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:72 detected: Trace.TrackingCookie.aol.com!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:81 detected: Trace.TrackingCookie.cdn.atwola.com!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:83 detected: Trace.TrackingCookie.anad.tacoda.net!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:164 detected: Trace.TrackingCookie.ads.adsonar.com!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:267 detected: Trace.TrackingCookie.publishers.clickbooth.com!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:296 detected: Trace.TrackingCookie.tag.contextweb.com!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:297 detected: Trace.TrackingCookie.tag.contextweb.com!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:319 detected: Trace.TrackingCookie.ad1.clickhype.com!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:336 detected: Trace.TrackingCookie.count!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:337 detected: Trace.TrackingCookie.cnt.tyxo.bg!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:359 detected: Trace.TrackingCookie.ads.bridgetrack.com!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:360 detected: Trace.TrackingCookie.ads.bridgetrack.com!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:366 detected: Trace.TrackingCookie.
www.burstnet.com!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:367 detected: Trace.TrackingCookie.ads.realtechnetwork.net!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:369 detected: Trace.TrackingCookie.ads.realtechnetwork.net!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:370 detected: Trace.TrackingCookie.ads.realtechnetwork.net!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:401 detected: Trace.TrackingCookie.server.cpmstar.com!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:402 detected: Trace.TrackingCookie.server.cpmstar.com!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:403 detected: Trace.TrackingCookie.server.cpmstar.com!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:408 detected: Trace.TrackingCookie.
www.3dstats.com!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:409 detected: Trace.TrackingCookie.pub.softonic.com!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:410 detected: Trace.TrackingCookie.pub.softonic.com!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:411 detected: Trace.TrackingCookie.pub.softonic.com!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:412 detected: Trace.TrackingCookie.pub.softonic.com!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:419 detected: Trace.TrackingCookie.clicktorrent.info!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:420 detected: Trace.TrackingCookie.clicktorrent.info!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:421 detected: Trace.TrackingCookie.clicktorrent.info!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:422 detected: Trace.TrackingCookie.clicktorrent.info!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:423 detected: Trace.TrackingCookie.clicktorrent.info!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:424 detected: Trace.TrackingCookie.clicktorrent.info!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:425 detected: Trace.TrackingCookie.clicktorrent.info!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:426 detected: Trace.TrackingCookie.clicktorrent.info!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:427 detected: Trace.TrackingCookie.clicktorrent.info!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:452 detected: Trace.TrackingCookie.rotator.adjuggler.com!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:453 detected: Trace.TrackingCookie.rotator.adjuggler.com!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:454 detected: Trace.TrackingCookie.m.rmbclick.com!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:569 detected: Trace.TrackingCookie.e.nvero.net!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:589 detected: Trace.TrackingCookie.lycos.com!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:597 detected: Trace.TrackingCookie.roia.biz!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\mbcv803t.default\cookies.txt:598 detected: Trace.TrackingCookie.roia.biz!A2
C:\Documents and Settings\Premo House\Application Data\Mozilla\Firefox\Profiles\n56rw3il.default\cookies.sqlite:1246381338687 503 detected: Trace.TrackingCookie.cms!A2
C:\WINDOWS\system32\drivers\scdemu.sys detected: Trojan.Win32.Monder!IK
C:\Program Files\Cheat Engine\Systemcallretriever.exe detected: Virus.Win32.Sality!IK
Scanned
Files: 352073
Traces: 632556
Cookies: 1107
Processes: 33
Found
Files: 2
Traces: 57
Cookies: 49
Processes: 0
Registry keys: 0
Scan end: 7/1/2009 5:00:06 AM
Scan time: 1:44:21
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:07:51 AM, on 7/1/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Silicon Image\3114-W-I32-R SATARAID5\SATARaid5ConfigService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Electronic Arts\EADM\Core.exe
C:\PROGRAM FILES\A-SQUARED FREE\A2FREE.EXE
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://tain.freehostia.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/S...in/AvSniff.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) -
http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) -
http://www.acclaim.com/cabs/acclaim_v4.cab
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) -
http://www.nvidia.com/content/Driver...aSmartScan.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: SATARaid5 Configuration Service (SATARaid5 Config Service) - Unknown owner - C:\Program Files\Silicon Image\3114-W-I32-R SATARAID5\SATARaid5ConfigService.exe
O23 - Service: VET Message Service (VETMSGNT) - Unknown owner - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 6595 bytes