This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

slow start up, freezing screen, [Closed]

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello dear computer helpers, my computer is just not working properly…first i thought it was internet explorer as i could see there was a browser redirection so I downloaded firefox..the pc was better for a while but now the start up is slow and sometimes the screen freezes…or program not responding. also google mail talk acts up ..i did downloaded some anti spyware without knowing if it is a secure source…once I got online help and a phone call I got weirded out as they were able to use my mouse and go into everything…I know this is possible but Iam just worried plus I am unable to remove this file…I do have a payed antivirus program from my internet provider…but it would not recognize a problem. May you please help me with identifying files on my hijack this log…and also direct me were to post this log. Thanks in advance Andrea
:welcome:

Hi Andrea, we dont use Hijackthis much anymore, what I would like you to do is run DDS and post the log please

Download DDS from one of the links below to your desktop

Link 1
Link 2

  • Double click the tool to run it.
  • A black Screen will open, just read the contents and do nothing.
  • When the tool finishes, it will open 2 reports, DDS.txt and attach.txt
  • Copy/Paste the contents of 'DDS.txt' into your post.
  • 'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files)

:welcome:

Hi Andrea, we dont use Hijackthis much anymore, what I would like you to do is run DDS and post the log please

Download DDS from one of the links below to your desktop

Link 1
Link 2

  • Double click the tool to run it.
  • A black Screen will open, just read the contents and do nothing.
  • When the tool finishes, it will open 2 reports, DDS.txt and attach.txt
  • Copy/Paste the contents of 'DDS.txt' into your post.
  • 'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files)




Hello dear Sir,
thank you for replying I hope I have posted this to the right reply spot. Please find attached the zip file with the attach txt and below the copy and paste contents of DDS txt ….

Kind regards
Andrea

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 7.0.5730.11
Run by [removed] at 23:01:38 on 2011-12-30
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.428 [GMT -4:00]
.
AV: COGECO Security Services 6.02 *Enabled/Updated* {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: COGECO Security Services 6.02 *Disabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\PROGRA~1\COGECO~1\backweb\9867844\Program\SERVIC~1.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\COGECO Security Services\Anti-Virus\fsgk32st.exe
C:\Program Files\COGECO Security Services\backweb\9867844\program\fsbwsys.exe
C:\Program Files\COGECO Security Services\Anti-Virus\FSGK32.EXE
C:\Program Files\COGECO Security Services\Common\FSMA32.EXE
C:\Program Files\COGECO Security Services\Anti-Virus\fssm32.exe
C:\Program Files\COGECO Security Services\Common\FSMB32.EXE
C:\Program Files\Java\jre1.6.0_13\bin\jqs.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
C:\Program Files\COGECO Security Services\Common\FCH32.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\Program Files\COGECO Security Services\Common\FAMEH32.EXE
C:\Program Files\COGECO Security Services\Anti-Virus\fsrw.exe
C:\Program Files\COGECO Security Services\FSPC\fspc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\OfferApp\OfferApp.exe
C:\Program Files\COGECO Security Services\Common\FSM32.EXE
C:\Program Files\Babylon\Babylon-Pro\Babylon.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\COGECO Security Services\FSGUI\ispnews.exe
C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\COGECO Security Services\backweb\9867844\Program\fspex.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\COGECO Security Services\FSPC\fshttps\fshttps.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\COGECO Security Services\Anti-Virus\fsav32.exe
C:\Program Files\COGECO Security Services\FWES\Program\fsdfwd.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\COGECO Security Services\FSGUI\fsguidll.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\Documents and Settings\Andrea\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\shmgrate.exe
C:\Documents and Settings\Andrea\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe
C:\PROGRA~1\COGECO~1\ANTI-V~1\fsav.exe
C:\Documents and Settings\Andrea\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe
C:\PROGRA~1\COGECO~1\ANTI-S~2\fsaw.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Andrea\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe
.
============== Pseudo HJT Report ===============
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uSearch Bar = hxxp://www.google.com/ie
uStart Page = hxxp://www.google.ca/
mStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
TB: {3160BAF9-CF68-48EC-9076-FAED7CE49467} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\andrea\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [Dell AIO Printer A920] "c:\program files\dell aio printer a920\dlbkbmgr.exe"
mRun: [OfferApp] "c:\program files\offerapp\OfferApp.exe"
mRun: [F-Secure TNB] "c:\program files\cogeco security services\tnb\TNBUtil.exe" /CHECKALL /WAITFORSW
mRun: [F-Secure Manager] "c:\program files\cogeco security services\common\FSM32.EXE" /splash
mRun: [F-Secure Startup Wizard] "c:\program files\cogeco security services\fsgui\FSSW.EXE" /reboot
mRun: [Babylon Client] "c:\program files\babylon\babylon-pro\Babylon.exe" -AutoStart
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe"
mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe"
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide
mRun: [News Service] c:\program files\cogeco security services\fsgui\ispnews.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [PMBVolumeWatcher] c:\program files\sony\pmb\PMBVolumeWatcher.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [googletalk] "c:\program files\google\google talk\googletalk.exe" /autostart
dRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
IE: Translate with &Babylon; - c:\program files\babylon\babylon-pro\utils\BabylonIEPI.dll/Translate.htm
LSP: winsflt.dll
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/7/3/e7345c16-80aa-4488-ae10-9ac6be844f99/OGAControl.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} - hxxp://picasaweb.google.com/s/v/70.11/uploader2.cab
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc2.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
TCP: DhcpNameServer = [removed] [removed] [removed]
TCP: Interfaces\{1F47C60D-40A6-463F-AC38-5FFC22CD6B0D} : DhcpNameServer = [removed] [removed] [removed]
SEH: {81559C35-8464-49F7-BB0E-07A383BEF910} - No File
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\andrea\application data\mozilla\firefox\profiles\cbnv70qk.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\documents and settings\andrea\application data\facebook\npfbplugin_1_0_1.dll
FF - plugin: c:\documents and settings\andrea\application data\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\andrea\application data\mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: c:\documents and settings\andrea\application data\mozilla\plugins\npPxPlay.dll
FF - plugin: c:\documents and settings\andrea\local settings\application data\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre1.6.0_13\bin\new_plugin\npdeploytk.dll
FF - plugin: c:\program files\java\jre1.6.0_13\bin\new_plugin\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
.
============= SERVICES / DRIVERS ===============
.
R? ddnt;ddnt
R? gupdate;Google Update Service (gupdate)
R? gupdatem;Google Update Service (gupdatem)
R? HPUATA;HP CD Writer Plus Controller Driver
R? NPF;NetGroup Packet Filter Driver
R? XDRIBLNA;XDRIBLNA
S? BackWeb Plug-in - 9867844;COGECO Security Services
S? F-Secure Filter;F-Secure File System Filter
S? F-Secure Gatekeeper Handler Starter;FSGKHS
S? F-Secure Gatekeeper;F-Secure Gatekeeper
S? F-Secure Recognizer;F-Secure File System Recognizer
S? FSFW;F-Secure Firewall Driver
S? PMBDeviceInfoProvider;PMBDeviceInfoProvider
.
=============== Created Last 30 ================
.
2011-12-28 14:12:22 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-27 12:04:53 ——– d—–w- c:\program files\TeaTimer (Spybot - Search & Destroy)
2011-12-13 13:20:18 ——– d—–w- c:\program files\iPod
2011-12-13 13:20:11 ——– d—–w- c:\program files\iTunes
2011-12-13 13:20:11 ——– d—–w- c:\documents and settings\all users\application data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-12-13 13:11:40 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll
2011-12-13 13:11:40 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll
2011-12-13 13:11:40 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2011-12-13 13:11:40 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2011-12-13 13:11:40 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2011-12-13 13:11:40 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2011-12-13 13:11:40 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
2011-12-05 18:14:30 ——– d—–w- c:\documents and settings\andrea\local settings\application data\LogMeIn Rescue Applet
2011-12-04 21:43:12 ——– d—–w- c:\windows\system32\wbem\repository\FS
2011-12-04 21:43:12 ——– d—–w- c:\windows\system32\wbem\Repository
.
==================== Find3M ====================
.
2011-11-23 13:25:32 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-01 16:07:10 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-10-31 23:43:21 832512 —-a-w- c:\windows\system32\wininet.dll
2011-10-31 23:43:21 78336 —-a-w- c:\windows\system32\ieencode.dll
2011-10-31 23:43:21 1830912 —-a-w- c:\windows\system32\inetcpl.cpl
2011-10-31 23:43:20 17408 —-a-w- c:\windows\system32\corpol.dll
2011-10-28 05:31:48 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37:08 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52:02 2027008 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-24 18:29:02 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 18:29:02 69632 —-a-w- c:\windows\system32\QuickTime.qts
2011-10-18 11:13:22 186880 —-a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22:41 692736 —-a-w- c:\windows\system32\inetcomm.dll
1996-12-02 23:44:28 582144 —-a-w- c:\program files\common files\dao350.dll
.
============= FINISH: 23:14:00.25 ===============

Good Morning I wont be able to reply til later or tomorrow, getting ready for work…have a super day and a Happy New Year thanks so much for helping, I truly appreciate it a lot…I wish I could sit here and finish this…. :wavey: but no rush well (-: tiny tiny bit Kind regards Andrea
Andrea,

Your system is outdated and leaving you open to infections. Let make sure there is no malware and then we can work on updating you.

Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please




Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]
Hello dear Ken, I have installed the malwarebytes and it is just runnning now…I had a bit of a problem because the pc is so slow, but I will post the results tonight…thank you so so much for your help this is very nice…. Kind regards, Andrea
Hello Ken,
this is the first scan log report. should I continue with the second scan like the black screen shots you described?
Thanks again for your help.

Andrea
:)



Malwarebytes Anti-Malware (Trial) 1.60.0.1800
www.malwarebytes.org

Database version: v2012.01.02.04

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 7.0.5730.11
Andrea :: MIL [administrator]

Protection: Disabled

1/2/2012 2:17:49 PM
mbam-log-2012-01-02 (14-17-49).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry |

File System | Heuristics/Extra | Heuristics/Shuriken |

PUP | PUM
Scan options disabled: P2P
Objects scanned: 258134
Time elapsed: 4 hour(s), 28 minute(s), 27 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 5
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion

\Ext\Settings\{00A6FAF1-072E-44CF-8957-

5838F569A31D} (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion

\Ext\Stats\{00A6FAF1-072E-44CF-8957-

5838F569A31D} (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion

\Ext\Settings\{07B18EA9-A523-4961-B6BB-

170DE4475CCA} (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion

\Ext\Stats\{07B18EA9-A523-4961-B6BB-

170DE4475CCA} (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKCU\SOFTWARE\UpMedia (Adware.SmartShopper)

-> Quarantined and deleted successfully.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 1
C:\WINDOWS\SYSTEM32\UpMedia

(Adware.SmartShopper) -> Quarantined and deleted

successfully.

Files Detected: 1
C:\WINDOWS\SYSTEM32\stfv.bin

(Fake.Dropped.Malware) -> Quarantined and deleted

successfully.

(end)
Andrea, Dont use any bold formatting or quote what I say , when you open a log in notepad, look up on the top under edit and make sure wordwrap is turned off, its making it difficult to read your logs. Yes, go ahead and run aswMBR please
Hello sorry for making it difficult to read. I hope its easier like this I was not aware… Ken, my pc got crazy now. the internet connection still works but whatever i want to do takes for hours …I disabled malwarebytes and my antivirus software. after I thought this might be the problem, but it still persist..right now my pc just doesnt do anything other than open a requested window after a 2 hour wait…word closes also other programs no response so i was unable to download the aswMBR tIhing…I tried to work offline but its not better either so I write from a tincy notebook..sorry .. Hope I got my response right…. cheers and thank you Ken Andrea.
Lets see if you can run this program

If it wont run normally then try running it in Safemode. You can also try downloading it to a known clean computer and transfer it by disk to the infected one


To Enter Safemode
  • Go to Start> Shut off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
    this will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to Safemode with Networking
  • Then press the Enter Key on your Keyboard
Tutorial if you need it How to boot into Safemode







Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Good Morning Ken,
my computer seems to run a lot better now but I haven't had my coffee yet. Here is the log file from Combofix.
You are awesome Ken thanks


ComboFix 12-01-05.04 - Andrea 01/05/2012 22:51:54.1.1 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.1165 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: COGECO Security Services 6.02 *Enabled/Updated* {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: COGECO Security Services 6.02 *Disabled* {D4747503-0346-49EB-9262-997542F79BF4}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\DirectCDUserNameD.txt
c:\documents and settings\Andrea\Application Data\HPSU_48BitScanUpdate.log
c:\documents and settings\Andrea\g2mdlhlpx.exe
c:\documents and settings\Andrea\WINDOWS
C:\Install.exe
c:\program files\Internet Explorer\SET38DA.tmp
c:\program files\Internet Explorer\SET38DB.tmp
c:\program files\Internet Explorer\SET38DD.tmp
c:\program files\Internet Explorer\SETFBD2.tmp
c:\program files\Internet Explorer\SETFBD3.tmp
c:\program files\Internet Explorer\SETFBD5.tmp
c:\program files\WinPCap
c:\program files\WinPCap\daemon_mgm.exe
c:\program files\WinPCap\NetMonInstaller.exe
c:\program files\WinPCap\npf_mgm.exe
c:\program files\WinPCap\rpcapd.exe
c:\program files\WinPCap\Uninstall.exe
c:\windows\bwUnin-6.3.2.116-9867844L.exe
c:\windows\Downloaded Program Files\WUInst.dll
c:\windows\help\wmplayer.bak
c:\windows\patch.exe
c:\windows\system32\Cache
c:\windows\system32\Cache\buts.bin
c:\windows\system32\Cache\comp40.bmp
c:\windows\system32\Cache\msg.bin
c:\windows\system32\Cache\search find 2.bmp
c:\windows\system32\Cache\showbtn.bmp
c:\windows\system32\Cache\showbtn1.bmp
c:\windows\system32\Cache\showbtn12.bmp
c:\windows\system32\Cache\showbtn123.bmp
c:\windows\system32\Cache\showbtn1234.bmp
c:\windows\system32\Cache\valentines copy.bmp
c:\windows\system32\Cache\web app.bmp
c:\windows\system32\CTFMON(2).EXE
c:\windows\system32\CTFMON(3).EXE
c:\windows\system32\CTFMON(4).EXE
c:\windows\system32\CTFMON(5).EXE
c:\windows\system32\CTFMON(6).EXE
c:\windows\system32\CTFMON(7).EXE
c:\windows\system32\CTFMON(8).EXE
c:\windows\system32\CTFMON(9).EXE
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\SET38E8.tmp
c:\windows\system32\SET38E9.tmp
c:\windows\system32\SET38EB.tmp
c:\windows\system32\SET38EC.tmp
c:\windows\system32\SET38ED.tmp
c:\windows\system32\SET38EE.tmp
c:\windows\system32\SET38EF.tmp
c:\windows\system32\SET38F1.tmp
c:\windows\system32\SET38F3.tmp
c:\windows\system32\SET38F4.tmp
c:\windows\system32\SET38F5.tmp
c:\windows\system32\SET38F8.tmp
c:\windows\system32\SET38F9.tmp
c:\windows\system32\SET38FC.tmp
c:\windows\system32\SET38FD.tmp
c:\windows\system32\SET38FF.tmp
c:\windows\system32\SET3902.tmp
c:\windows\system32\SET3903.tmp
c:\windows\system32\SET3904.tmp
c:\windows\system32\SET3905.tmp
c:\windows\system32\SET3906.tmp
c:\windows\system32\SET3907.tmp
c:\windows\system32\SET390B.tmp
c:\windows\system32\SET390C.tmp
c:\windows\system32\SET390D.tmp
c:\windows\system32\SET390E.tmp
c:\windows\system32\SET390F.tmp
c:\windows\system32\SET3910.tmp
c:\windows\system32\SET3911.tmp
c:\windows\system32\SET3912.tmp
c:\windows\system32\SET3913.tmp
c:\windows\system32\SET3914.tmp
c:\windows\system32\SET3915.tmp
c:\windows\system32\SET3917.tmp
c:\windows\system32\SET3918.tmp
c:\windows\system32\SET3919.tmp
c:\windows\system32\SET391A.tmp
c:\windows\system32\SET85B.tmp
c:\windows\system32\SET867.tmp
c:\windows\system32\SETFBE5.tmp
c:\windows\system32\SETFBE6.tmp
c:\windows\system32\SETFBE8.tmp
c:\windows\system32\SETFBE9.tmp
c:\windows\system32\SETFBEA.tmp
c:\windows\system32\SETFBEB.tmp
c:\windows\system32\SETFBEC.tmp
c:\windows\system32\SETFBEE.tmp
c:\windows\system32\SETFBF0.tmp
c:\windows\system32\SETFBF1.tmp
c:\windows\system32\SETFBF2.tmp
c:\windows\system32\SETFBF5.tmp
c:\windows\system32\SETFBF6.tmp
c:\windows\system32\SETFBF9.tmp
c:\windows\system32\SETFBFA.tmp
c:\windows\system32\SETFBFC.tmp
c:\windows\system32\SETFBFF.tmp
c:\windows\system32\SETFC00.tmp
c:\windows\system32\SETFC01.tmp
c:\windows\system32\SETFC02.tmp
c:\windows\system32\SETFC03.tmp
c:\windows\system32\SETFC04.tmp
c:\windows\system32\SETFC08.tmp
c:\windows\system32\SETFC09.tmp
c:\windows\system32\SETFC0A.tmp
c:\windows\system32\SETFC0B.tmp
c:\windows\system32\SETFC0C.tmp
c:\windows\system32\SETFC0D.tmp
c:\windows\system32\SETFC0E.tmp
c:\windows\system32\SETFC0F.tmp
c:\windows\system32\SETFC10.tmp
c:\windows\system32\SETFC11.tmp
c:\windows\system32\SETFC12.tmp
c:\windows\system32\SETFC14.tmp
c:\windows\system32\SETFC15.tmp
c:\windows\system32\SETFC16.tmp
c:\windows\system32\SETFC17.tmp
c:\windows\system32\Temp
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_NPF
——-\Service_NPF
.
.
((((((((((((((((((((((((( Files Created from 2011-12-06 to 2012-01-06 )))))))))))))))))))))))))))))))
.
.
2012-01-01 18:17 . 2012-01-01 18:17 ——– d—–w- c:\documents and settings\Andrea\Application Data\Malwarebytes
2012-01-01 18:17 . 2012-01-01 18:17 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-12-28 14:12 . 2011-12-28 14:12 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-27 12:04 . 2011-12-27 12:04 ——– d—–w- c:\program files\TeaTimer (Spybot - Search & Destroy)
2011-12-13 13:20 . 2011-12-13 13:20 ——– d—–w- c:\program files\iPod
2011-12-13 13:20 . 2011-12-13 13:22 ——– d—–w- c:\program files\iTunes
2011-12-13 13:20 . 2011-12-13 13:22 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-12-13 13:15 . 2011-12-13 13:15 ——– d—–w- c:\documents and settings\LocalService\Application Data\Apple Computer
2011-12-13 13:11 . 2011-12-13 13:11 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin7.dll
2011-12-13 13:11 . 2011-12-13 13:11 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin6.dll
2011-12-13 13:11 . 2011-12-13 13:11 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin5.dll
2011-12-13 13:11 . 2011-12-13 13:11 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin4.dll
2011-12-13 13:11 . 2011-12-13 13:11 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin3.dll
2011-12-13 13:11 . 2011-12-13 13:11 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin2.dll
2011-12-13 13:11 . 2011-12-13 13:11 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin.dll
2011-12-13 13:10 . 2011-12-13 13:11 ——– d—–w- c:\program files\QuickTime
2011-12-13 12:18 . 2011-12-13 12:18 ——– d—–w- c:\program files\Apple Software Update
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-23 13:25 . 2005-01-05 22:02 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-01 16:07 . 2005-01-14 05:33 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-10-31 23:43 . 2005-06-30 17:43 78336 —-a-w- c:\windows\system32\ieencode.dll
2011-10-31 23:43 . 2005-04-27 13:54 832512 —-a-w- c:\windows\system32\wininet.dll
2011-10-31 23:43 . 2002-08-29 10:00 1830912 —-a-w- c:\windows\system32\inetcpl.cpl
2011-10-31 23:43 . 2002-08-29 10:00 17408 —-a-w- c:\windows\system32\corpol.dll
2011-10-28 05:31 . 2005-01-05 22:03 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37 . 2005-01-05 22:02 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 2005-01-05 22:02 2027008 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-24 18:29 . 2011-10-24 18:29 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 18:29 . 2011-10-24 18:29 69632 —-a-w- c:\windows\system32\QuickTime.qts
2011-10-18 11:13 . 2002-11-26 19:15 186880 —-a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22 . 2005-05-03 19:26 692736 —-a-w- c:\windows\system32\inetcomm.dll
1996-12-02 23:44 . 1996-12-02 23:44 582144 —-a-w- c:\program files\Common Files\dao350.dll
2011-11-21 04:04 . 2011-12-08 14:37 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dell AIO Printer A920"="c:\program files\Dell AIO Printer A920\dlbkbmgr.exe" [2003-06-02 270336]
"OfferApp"="c:\program files\OfferApp\OfferApp.exe" [2004-04-30 40960]
"F-Secure TNB"="c:\program files\COGECO Security Services\TNB\TNBUtil.exe" [2005-06-02 700416]
"F-Secure Manager"="c:\program files\COGECO Security Services\Common\FSM32.EXE" [2005-05-09 118833]
"F-Secure Startup Wizard"="c:\program files\COGECO Security Services\FSGUI\FSSW.EXE" [2005-11-18 372736]
"Babylon Client"="c:\program files\Babylon\Babylon-Pro\Babylon.exe" [2006-12-13 2785256]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-03-30 624248]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-08-14 565008]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-08-14 2407184]
"News Service"="c:\program files\COGECO Security Services\FSGUI\ispnews.exe" [2005-05-31 356352]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"PMBVolumeWatcher"="c:\program files\Sony\PMB\PMBVolumeWatcher.exe" [2010-03-24 599328]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2003-10-06 5058560]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-02 59240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-12-08 421736]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
COGECO Security Services (2).lnk - c:\program files\COGECO Security Services\backweb\9867844\Program\fspex.exe [2007-1-27 32807]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2003-8-21 24576]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"c:\\WINDOWS\\SYSTEM32\\LEXPPS.EXE"=
"c:\\WINDOWS\\SYSTEM32\\rtcshare.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\COGECO Security Services\\backweb\\9867844\\Program\\fspex.exe"=
"c:\\Program Files\\Java\\jre1.6.0_01\\bin\\javaw.exe"=
"c:\\Program Files\\IBP 10\\IBP.exe"=
"c:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
"c:\\Program Files\\Common Files\\SafeNet Sentinel\\Sentinel Protection Server\\WinNT\\spnsrvnt.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Documents and Settings\\Andrea\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:UDP"= 1723:UDP:VPN2
.
R2 ddnt;ddnt;c:\windows\system32\drivers\ddnt.sys [x]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-09-16 136176]
R2 XDRIBLNA;XDRIBLNA;c:\windows\system32\xdriblna.ncs [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-09-16 136176]
R3 HPUATA;HP CD Writer Plus Controller Driver;c:\windows\system32\DRIVERS\HPUATA.sys [2001-09-24 75776]
S0 FSFW;F-Secure Firewall Driver;c:\windows\System32\drivers\fsdfw.sys [2005-08-22 70224]
S2 F-Secure Filter;F-Secure File System Filter;c:\program files\COGECO Security Services\Anti-Virus\Win2K\FSfilter.sys [2004-09-10 48720]
S2 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\COGECO Security Services\Anti-Virus\Win2K\FSgk.sys [2008-10-21 62176]
S2 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\COGECO Security Services\Anti-Virus\Win2K\FSrec.sys [2004-12-17 16848]
S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files\Sony\PMB\PMBDeviceInfoProvider.exe [2009-10-24 360224]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - GTNDIS5
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 21:57]
.
2012-01-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-16 12:25]
.
2012-01-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-16 12:25]
.
2012-01-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3901343504-3224471582-637956630-1007Core.job
- c:\documents and settings\Andrea\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-09 12:45]
.
2012-01-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3901343504-3224471582-637956630-1007UA.job
- c:\documents and settings\Andrea\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-09 12:45]
.
2012-01-06 c:\windows\Tasks\Scheduled scanning task.job
- c:\progra~1\COGECO~1\ANTI-V~1\fsav.exe [2007-01-28 14:42]
.
2012-01-05 c:\windows\Tasks\User_Feed_Synchronization-{936498DA-A5E1-442D-8CE8-336B192F3E37}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 15:58]
.
2012-01-04 c:\windows\Tasks\{407942FB-702C-4B0E-97C4-1FF6FB896A6C}_MIL_Andrea.job
- c:\windows\system32\mobsync.exe [2002-08-29 00:12]
.
2011-12-30 c:\windows\Tasks\{E2DD4F40-12ED-4054-A688-7ABFAB0FBA18}_MIL_Andrea.job
- c:\windows\system32\mobsync.exe [2002-08-29 00:12]
.
2012-01-05 c:\windows\Tasks\{F5E6583D-9905-46F3-8EFE-58A3464E5357}_MIL_Andrea.job
- c:\windows\system32\mobsync.exe [2002-08-29 00:12]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.google.ca/
mStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Translate with &Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
LSP: winsflt.dll
TCP: DhcpNameServer = [removed] [removed] [removed]
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Andrea\Application Data\Mozilla\Firefox\Profiles\cbnv70qk.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca
FF - prefs.js: network.proxy.type - 4
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-googletalk - c:\program files\Google\Google Talk\googletalk.exe
Notify-WgaLogon - (no file)
AddRemove-Babylon Builder - c:\program files\Babylon Builder\Uninst.isu
AddRemove-HPExtendedCapabilities - c:\program files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe
AddRemove-WinPcapInst - c:\program files\WinPcap\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-05 23:10
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\XDRIBLNA]
"ImagePath"="\??\c:\windows\system32\xdriblna.ncs"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-3901343504-3224471582-637956630-1007\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(772)
c:\program files\COGECO Security Services\FWES\Program\fsdc.dll
.
- - - - - - - > 'lsass.exe'(832)
c:\windows\system32\winsflt.dll
c:\program files\COGECO Security Services\FWES\Program\fsdc.dll
.
- - - - - - - > 'explorer.exe'(7288)
c:\windows\system32\WININET.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\IME\SPGRMR.DLL
c:\windows\system32\ieframe.dll
c:\program files\Babylon\Babylon-Pro\CAPTLIB.DLL
.
- - - - - - - > 'csrss.exe'(748)
c:\program files\COGECO Security Services\FWES\Program\fsdc.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\COGECO Security Services\Anti-Virus\fsgk32st.exe
c:\program files\COGECO Security Services\Anti-Virus\FSGK32.EXE
c:\program files\COGECO Security Services\Common\FSMA32.EXE
c:\program files\COGECO Security Services\Anti-Virus\fssm32.exe
c:\program files\Java\jre1.6.0_13\bin\jqs.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\System32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
c:\windows\System32\MsPMSPSv.exe
c:\program files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
c:\program files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
c:\program files\Dell AIO Printer A920\dlbkbmon.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\COGECO Security Services\FWES\Program\fsdfwd.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\program files\COGECO Security Services\Common\FSLAUNCH.EXE
.
**************************************************************************
.
Completion time: 2012-01-05 23:50:50 - machine was rebooted
ComboFix-quarantined-files.txt 2012-01-06 03:49
.
Pre-Run: 58,031,656,960 bytes free
Post-Run: 61,595,275,264 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
.
- - End Of File - - 25933E8B8E0BCDE1C52762AFC161D80E
:thumbup:

Just a few things to check that are questionable


  • Double-click My Computer.
  • Click the Tools menu, and then click Folder Options.
  • Click the View tab.
  • Clear "Hide file extensions for known file types."
  • Under the "Hidden files" folder, select "Show hidden files and folders."
  • Clear "Hide protected operating system files."
  • Click Apply, and then click OK.





Go to VirusTotal and submit these files for analysis, just use the BROWSE feature and then Send File , you will get a report back, post the report into this thread for me to see. If the site says this file has already been checked, have them check it again

c:\windows\system32\drivers\ddnt.sys <–This file
c:\windows\system32\xdriblna.ncs <–This file


If the site is busy you can try this one
http://virusscan.jotti.org/en
Hello Ken, it doesn't let me upload those files…I went under computer/C Drive/windows….I also checked the search feature and it said file not found…but Ken, my PC is running perfectly now. I am so happy you really helped me out a lot and definitely saved me a lot of money…. My kindest regards and best wishes Thank you so much. Andrea
Andrea,

Run this free online virus scanner and lets see what it finds that we may have missed


ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
Please make sure you include the following items in your next post:
The log that was produced after running ESET Online Scanner.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI