My computer keeps having pop ups asking to install antivirus 2009. My firewall asked to gain access to a program called "~.exe" which I denied. That tipped me off something was not right then I start recieving the antivirus 2009 warning messages. Any help would be appreciated. Below is my hijack this log.
Thank you
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:59:36 PM, on 12/19/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device
Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\COGECO Security
Services\Anti-Virus\fsgk32st.exe
C:\Program Files\COGECO Security
Services\Common\FSMA32.EXE
C:\Program Files\COGECO Security
Services\Anti-Virus\FSGK32.EXE
C:\Program Files\COGECO Security
Services\Common\FSMB32.EXE
C:\Program Files\Pinnacle\MediaServer\Microsoft SQL
Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
C:\Program Files\COGECO Security
Services\Common\FCH32.EXE
C:\Program Files\COGECO Security
Services\Anti-Virus\fsqh.exe
C:\Program Files\COGECO Security
Services\Common\FAMEH32.EXE
C:\Program Files\COGECO Security Services\FSPC\fspc.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\COGECO Security
Services\Anti-Virus\fssm32.exe
C:\Program Files\COGECO Security
Services\FSAUA\program\fsaua.exe
C:\Program Files\COGECO Security
Services\FWES\Program\fsdfwd.exe
C:\Program Files\COGECO Security
Services\Anti-Virus\fsav32.exe
C:\Program Files\COGECO Security
Services\FSAUA\program\fsus.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\COGECO Security
Services\Common\FSM32.EXE
C:\Program Files\COGECO Security
Services\FSGUI\ispnews.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\COGECO Security
Services\FSGUI\fsguidll.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\SanDisk\Sansa
Updater\SansaDispatch.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Macrovision
Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Infinite Mind LC\eyeQ\ARLaunch.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\Program Files\Common
Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Microsoft Shared\Windows
Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet
Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection
Wizard,ShellNext =
http://go.microsoft.com/fwlink/?LinkId=33568
R1 -
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program
Files\Common
Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection -
{53707962-6F74-2D53-2644-206D7942484F} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) -
{709840f3-7156-4e56-bdf8-3523da159177} -
C:\WINDOWS\system32\vidijoso.dll
O2 - BHO: SSVHelper Class -
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program
Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) -
{7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper -
{9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program
Files\Common Files\Microsoft Shared\Windows
Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper -
{AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program
files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper -
{AE7CD045-E861-484f-8273-0445EE161910} - C:\Program
Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Gears Helper -
{E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program
Files\Google\Google Gears\Internet
Explorer\0.5.4.2\gears.dll
O3 - Toolbar: Veoh Web Player Video Finder -
{0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program
Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
O3 - Toolbar: &Google -
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program
files\google\googletoolbar1.dll
O3 - Toolbar: Adobe PDF -
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program
Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program
Files\COGECO Security Services\Common\FSM32.EXE"
/splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program
Files\COGECO Security Services\FSGUI\TNBUtil.exe"
/CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [News Service] "C:\Program
Files\COGECO Security Services\FSGUI\ispnews.exe"
O4 - HKLM\..\Run: [NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program
Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SansaDispatch] C:\Program
Files\SanDisk\Sansa Updater\SansaDispatch.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program
Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program
Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program
Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe_ID0EYTHM]
C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2
.EXE
O4 - HKLM\..\Run: [luwukawuri] Rundll32.exe
"C:\WINDOWS\system32\bohumoye.dll",s
O4 - HKLM\..\Run: [f0f1ba21] rundll32.exe
"C:\WINDOWS\system32\hemakebi.dll",b
O4 - HKLM\..\Run: [CPMf3c289bd] Rundll32.exe
"c:\windows\system32\bodulava.dll",a
O4 - HKCU\..\Run: [ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SsAAD.exe]
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKCU\..\Run: [NBJ]
"C:\PROGRA~1\Ahead\NEROBA~1\NBJ.exe"
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting]
"c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t
(User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting]
"c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t
(User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk =
?
O4 - Global Startup: Adobe Acrobat Synchronizer.lnk =
C:\Program Files\Adobe\Acrobat
8.0\Acrobat\AdobeCollabSync.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk =
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk =
C:\Program Files\Adobe\Reader
8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program
Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: MiniEYE-MiniREAD Launch.lnk =
C:\Program Files\Infinite Mind LC\eyeQ\ARLaunch.exe
O8 - Extra context menu item: Append to existing PDF -
res://C:\Program Files\Adobe\Acrobat
8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to
Adobe PDF - res://C:\Program Files\Adobe\Acrobat
8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to
existing PDF - res://C:\Program Files\Adobe\Acrobat
8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to
Adobe PDF - res://C:\Program Files\Adobe\Acrobat
8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.h
tml
O8 - Extra context menu item: Convert selected links to
existing PDF - res://C:\Program Files\Adobe\Acrobat
8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.ht
ml
O8 - Extra context menu item: Convert selection to
Adobe PDF - res://C:\Program Files\Adobe\Acrobat
8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to
existing PDF - res://C:\Program Files\Adobe\Acrobat
8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF -
res://C:\Program Files\Adobe\Acrobat
8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Open with WordPerfect -
C:\Program Files\WordPerfect Office
X3\Programs\WPLauncher.hta
O9 - Extra button: (no name) -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) -
{09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program
Files\Google\Google Gears\Internet
Explorer\0.5.4.2\gears.dll
O9 - Extra 'Tools' menuitem: &Gears Settings -
{09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program
Files\Google\Google Gears\Internet
Explorer\0.5.4.2\gears.dll
O9 - Extra button: Parental... -
{200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program
Files\COGECO Security Services\FSPC\fspcmsie.dll
O9 - Extra button: (no name) -
{200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program
Files\COGECO Security Services\FSPC\fspcmsie.dll
O9 - Extra 'Tools' menuitem: Parental... -
{200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program
Files\COGECO Security Services\FSPC\fspcmsie.dll
O9 - Extra button: (no name) -
{B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program
Files\Common Files\Microsoft Shared\Encarta Search
Bar\ENCSBAR.DLL
O9 - Extra button: (no name) -
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy
Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2}
- C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) -
{e2e2dd38-d088-4134-82b7-f2ba38496583} -
C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 -
{e2e2dd38-d088-4134-82b7-f2ba38496583} -
C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://downloads.linkinpark.com
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3}
(StagingUI Object) -
http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579
.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83}
(Facebook Photo Uploader 5 Control) -
http://upload.facebook.com/controls/2008.10.10_v5.5.8/F
acebookPhotoUploader5.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75}
(CKAVWebScan Object) -
http://www.kaspersky.com/kos/eng/partner/default/kavweb
scan_unicode.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE}
(Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin
/AvSniff.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN
Games – Buddy Invite) -
http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.ca
b
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN
Photo Upload Tool) -
http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3}
(ZonePAChat Object) -
http://zone.msn.com/binframework/v10/ZPAChat.cab55579.c
ab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5}
(Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedContent/common
/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
(MUWebControl Class) -
http://www.update.microsoft.com/microsoftupdate/v6/V5Co
ntrols/en/x86/client/muweb_site.cab?1190479144125
O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (MSN
Games – Texas Holdem Poker) -
http://zone.msn.com/bingame/zpagames/zpa_txhe.cab60231.
cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN
Games - Installer) -
http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab566
49.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
(Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/fl
ash/swflash.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN
Games – Game Communicator) -
http://zone.msn.com/binframework/v10/StProxy.cab55579.c
ab
O16 - DPF: {F127B9BA-89EA-4B04-9C67-2074A9DF61FD}
(Photo Upload Plugin Class) -
http://walmart.pnimedia.com/upload/activex/v2_0_0_9/PCA
XSetupv2.0.0.9.cab?
O16 - DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD}
(Photo Upload Plugin Class) -
http://walmart.pnimedia.com/upload/activex/v2_0_0_10/PC
AXSetupv2.0.0.10.cab?
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1}
(DownloadManager Control) -
http://dlm.tools.akamai.com/dlmanager/versions/activex/
dlm-activex-2.2.1.6.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\mopeleve.dll
c:\windows\system32\bodulava.dll
O21 - SSODL: SSODL -
{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} -
c:\windows\system32\bodulava.dll
O22 - SharedTaskScheduler: STS -
{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} -
c:\windows\system32\bodulava.dll
O23 - Service: Adobe Version Cue CS3 - Adobe Systems
Incorporated - C:\Program Files\Common
Files\Adobe\Adobe Version Cue
CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Apple Mobile Device - Apple, Inc. -
C:\Program Files\Common Files\Apple\Mobile Device
Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies
Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner -
C:\WINDOWS\system32\ati2sgag.exe
O23 - Service:
##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##
(Bonjour Service) - Apple Computer, Inc. - C:\Program
Files\Bonjour\mDNSResponder.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler
Starter) - F-Secure Corporation - C:\Program
Files\COGECO Security Services\Anti-Virus\fsgk32st.exe
O23 - Service: FLEXnet Licensing Service - Macrovision
Europe Ltd. - C:\Program Files\Common Files\Macrovision
Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: F-Secure Automatic Update Agent (FSAUA)
- F-Secure Corporation - C:\Program Files\COGECO
Security Services\FSAUA\program\fsaua.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon
(FSDFWD) - F-Secure Corporation - C:\Program
Files\COGECO Security Services\FWES\Program\fsdfwd.exe
O23 - Service: FSMA - F-Secure Corporation - C:\Program
Files\COGECO Security Services\Common\FSMA32.EXE
O23 - Service: Google Update Service
(gupdate1c92716c28023d2) (gupdate1c92716c28023d2) -
Google Inc. - C:\Program
Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google
- C:\Program Files\Google\Common\Google
Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) -
Macrovision Corporation - C:\Program Files\Common
Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG -
C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program
Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark
International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MSCSPTISRV - Sony Corporation -
C:\Program Files\Common Files\Sony
Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Pure Networks Net2Go Service
(nmraapache) - Pure Networks, Inc. - C:\Program
Files\Pure Networks\Network
Magic\WebServer\bin\nmraapache.exe
O23 - Service: Pure Networks Network Magic Service
(nmservice) - Pure Networks, Inc. - C:\Program
Files\Pure Networks\Network Magic\nmsrvc.exe
O23 - Service: PACSPTISVR - Sony Corporation -
C:\Program Files\Common Files\Sony
Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony
Corporation - C:\Program Files\Common Files\Sony
Shared\AVLib\SPTISRV.exe
--
End of file - 16350 bytes
Thank you
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:59:36 PM, on 12/19/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device
Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\COGECO Security
Services\Anti-Virus\fsgk32st.exe
C:\Program Files\COGECO Security
Services\Common\FSMA32.EXE
C:\Program Files\COGECO Security
Services\Anti-Virus\FSGK32.EXE
C:\Program Files\COGECO Security
Services\Common\FSMB32.EXE
C:\Program Files\Pinnacle\MediaServer\Microsoft SQL
Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
C:\Program Files\COGECO Security
Services\Common\FCH32.EXE
C:\Program Files\COGECO Security
Services\Anti-Virus\fsqh.exe
C:\Program Files\COGECO Security
Services\Common\FAMEH32.EXE
C:\Program Files\COGECO Security Services\FSPC\fspc.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\COGECO Security
Services\Anti-Virus\fssm32.exe
C:\Program Files\COGECO Security
Services\FSAUA\program\fsaua.exe
C:\Program Files\COGECO Security
Services\FWES\Program\fsdfwd.exe
C:\Program Files\COGECO Security
Services\Anti-Virus\fsav32.exe
C:\Program Files\COGECO Security
Services\FSAUA\program\fsus.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\COGECO Security
Services\Common\FSM32.EXE
C:\Program Files\COGECO Security
Services\FSGUI\ispnews.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\COGECO Security
Services\FSGUI\fsguidll.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\SanDisk\Sansa
Updater\SansaDispatch.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Macrovision
Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Infinite Mind LC\eyeQ\ARLaunch.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\Program Files\Common
Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Microsoft Shared\Windows
Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet
Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection
Wizard,ShellNext =
http://go.microsoft.com/fwlink/?LinkId=33568
R1 -
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program
Files\Common
Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection -
{53707962-6F74-2D53-2644-206D7942484F} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) -
{709840f3-7156-4e56-bdf8-3523da159177} -
C:\WINDOWS\system32\vidijoso.dll
O2 - BHO: SSVHelper Class -
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program
Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) -
{7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper -
{9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program
Files\Common Files\Microsoft Shared\Windows
Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper -
{AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program
files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper -
{AE7CD045-E861-484f-8273-0445EE161910} - C:\Program
Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Gears Helper -
{E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program
Files\Google\Google Gears\Internet
Explorer\0.5.4.2\gears.dll
O3 - Toolbar: Veoh Web Player Video Finder -
{0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program
Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
O3 - Toolbar: &Google -
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program
files\google\googletoolbar1.dll
O3 - Toolbar: Adobe PDF -
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program
Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program
Files\COGECO Security Services\Common\FSM32.EXE"
/splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program
Files\COGECO Security Services\FSGUI\TNBUtil.exe"
/CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [News Service] "C:\Program
Files\COGECO Security Services\FSGUI\ispnews.exe"
O4 - HKLM\..\Run: [NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program
Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SansaDispatch] C:\Program
Files\SanDisk\Sansa Updater\SansaDispatch.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program
Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program
Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program
Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe_ID0EYTHM]
C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2
.EXE
O4 - HKLM\..\Run: [luwukawuri] Rundll32.exe
"C:\WINDOWS\system32\bohumoye.dll",s
O4 - HKLM\..\Run: [f0f1ba21] rundll32.exe
"C:\WINDOWS\system32\hemakebi.dll",b
O4 - HKLM\..\Run: [CPMf3c289bd] Rundll32.exe
"c:\windows\system32\bodulava.dll",a
O4 - HKCU\..\Run: [ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SsAAD.exe]
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKCU\..\Run: [NBJ]
"C:\PROGRA~1\Ahead\NEROBA~1\NBJ.exe"
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting]
"c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t
(User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting]
"c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t
(User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk =
?
O4 - Global Startup: Adobe Acrobat Synchronizer.lnk =
C:\Program Files\Adobe\Acrobat
8.0\Acrobat\AdobeCollabSync.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk =
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk =
C:\Program Files\Adobe\Reader
8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program
Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: MiniEYE-MiniREAD Launch.lnk =
C:\Program Files\Infinite Mind LC\eyeQ\ARLaunch.exe
O8 - Extra context menu item: Append to existing PDF -
res://C:\Program Files\Adobe\Acrobat
8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to
Adobe PDF - res://C:\Program Files\Adobe\Acrobat
8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to
existing PDF - res://C:\Program Files\Adobe\Acrobat
8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to
Adobe PDF - res://C:\Program Files\Adobe\Acrobat
8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.h
tml
O8 - Extra context menu item: Convert selected links to
existing PDF - res://C:\Program Files\Adobe\Acrobat
8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.ht
ml
O8 - Extra context menu item: Convert selection to
Adobe PDF - res://C:\Program Files\Adobe\Acrobat
8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to
existing PDF - res://C:\Program Files\Adobe\Acrobat
8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF -
res://C:\Program Files\Adobe\Acrobat
8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Open with WordPerfect -
C:\Program Files\WordPerfect Office
X3\Programs\WPLauncher.hta
O9 - Extra button: (no name) -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) -
{09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program
Files\Google\Google Gears\Internet
Explorer\0.5.4.2\gears.dll
O9 - Extra 'Tools' menuitem: &Gears Settings -
{09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program
Files\Google\Google Gears\Internet
Explorer\0.5.4.2\gears.dll
O9 - Extra button: Parental... -
{200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program
Files\COGECO Security Services\FSPC\fspcmsie.dll
O9 - Extra button: (no name) -
{200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program
Files\COGECO Security Services\FSPC\fspcmsie.dll
O9 - Extra 'Tools' menuitem: Parental... -
{200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program
Files\COGECO Security Services\FSPC\fspcmsie.dll
O9 - Extra button: (no name) -
{B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program
Files\Common Files\Microsoft Shared\Encarta Search
Bar\ENCSBAR.DLL
O9 - Extra button: (no name) -
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy
Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2}
- C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) -
{e2e2dd38-d088-4134-82b7-f2ba38496583} -
C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 -
{e2e2dd38-d088-4134-82b7-f2ba38496583} -
C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://downloads.linkinpark.com
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3}
(StagingUI Object) -
http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579
.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83}
(Facebook Photo Uploader 5 Control) -
http://upload.facebook.com/controls/2008.10.10_v5.5.8/F
acebookPhotoUploader5.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75}
(CKAVWebScan Object) -
http://www.kaspersky.com/kos/eng/partner/default/kavweb
scan_unicode.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE}
(Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin
/AvSniff.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN
Games – Buddy Invite) -
http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.ca
b
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN
Photo Upload Tool) -
http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3}
(ZonePAChat Object) -
http://zone.msn.com/binframework/v10/ZPAChat.cab55579.c
ab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5}
(Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedContent/common
/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
(MUWebControl Class) -
http://www.update.microsoft.com/microsoftupdate/v6/V5Co
ntrols/en/x86/client/muweb_site.cab?1190479144125
O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (MSN
Games – Texas Holdem Poker) -
http://zone.msn.com/bingame/zpagames/zpa_txhe.cab60231.
cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN
Games - Installer) -
http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab566
49.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
(Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/fl
ash/swflash.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN
Games – Game Communicator) -
http://zone.msn.com/binframework/v10/StProxy.cab55579.c
ab
O16 - DPF: {F127B9BA-89EA-4B04-9C67-2074A9DF61FD}
(Photo Upload Plugin Class) -
http://walmart.pnimedia.com/upload/activex/v2_0_0_9/PCA
XSetupv2.0.0.9.cab?
O16 - DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD}
(Photo Upload Plugin Class) -
http://walmart.pnimedia.com/upload/activex/v2_0_0_10/PC
AXSetupv2.0.0.10.cab?
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1}
(DownloadManager Control) -
http://dlm.tools.akamai.com/dlmanager/versions/activex/
dlm-activex-2.2.1.6.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\mopeleve.dll
c:\windows\system32\bodulava.dll
O21 - SSODL: SSODL -
{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} -
c:\windows\system32\bodulava.dll
O22 - SharedTaskScheduler: STS -
{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} -
c:\windows\system32\bodulava.dll
O23 - Service: Adobe Version Cue CS3 - Adobe Systems
Incorporated - C:\Program Files\Common
Files\Adobe\Adobe Version Cue
CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Apple Mobile Device - Apple, Inc. -
C:\Program Files\Common Files\Apple\Mobile Device
Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies
Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner -
C:\WINDOWS\system32\ati2sgag.exe
O23 - Service:
##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##
(Bonjour Service) - Apple Computer, Inc. - C:\Program
Files\Bonjour\mDNSResponder.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler
Starter) - F-Secure Corporation - C:\Program
Files\COGECO Security Services\Anti-Virus\fsgk32st.exe
O23 - Service: FLEXnet Licensing Service - Macrovision
Europe Ltd. - C:\Program Files\Common Files\Macrovision
Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: F-Secure Automatic Update Agent (FSAUA)
- F-Secure Corporation - C:\Program Files\COGECO
Security Services\FSAUA\program\fsaua.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon
(FSDFWD) - F-Secure Corporation - C:\Program
Files\COGECO Security Services\FWES\Program\fsdfwd.exe
O23 - Service: FSMA - F-Secure Corporation - C:\Program
Files\COGECO Security Services\Common\FSMA32.EXE
O23 - Service: Google Update Service
(gupdate1c92716c28023d2) (gupdate1c92716c28023d2) -
Google Inc. - C:\Program
Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google
- C:\Program Files\Google\Common\Google
Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) -
Macrovision Corporation - C:\Program Files\Common
Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG -
C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program
Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark
International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MSCSPTISRV - Sony Corporation -
C:\Program Files\Common Files\Sony
Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Pure Networks Net2Go Service
(nmraapache) - Pure Networks, Inc. - C:\Program
Files\Pure Networks\Network
Magic\WebServer\bin\nmraapache.exe
O23 - Service: Pure Networks Network Magic Service
(nmservice) - Pure Networks, Inc. - C:\Program
Files\Pure Networks\Network Magic\nmsrvc.exe
O23 - Service: PACSPTISVR - Sony Corporation -
C:\Program Files\Common Files\Sony
Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony
Corporation - C:\Program Files\Common Files\Sony
Shared\AVLib\SPTISRV.exe
--
End of file - 16350 bytes