Good Morning Ken,
my computer seems to run a lot better now but I haven't had my coffee yet. Here is the log file from Combofix.
You are awesome Ken thanks
ComboFix 12-01-05.04 - Andrea 01/05/2012 22:51:54.1.1 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.1165 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: COGECO Security Services 6.02 *Enabled/Updated* {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: COGECO Security Services 6.02 *Disabled* {D4747503-0346-49EB-9262-997542F79BF4}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\DirectCDUserNameD.txt
c:\documents and settings\Andrea\Application Data\HPSU_48BitScanUpdate.log
c:\documents and settings\Andrea\g2mdlhlpx.exe
c:\documents and settings\Andrea\WINDOWS
C:\Install.exe
c:\program files\Internet Explorer\SET38DA.tmp
c:\program files\Internet Explorer\SET38DB.tmp
c:\program files\Internet Explorer\SET38DD.tmp
c:\program files\Internet Explorer\SETFBD2.tmp
c:\program files\Internet Explorer\SETFBD3.tmp
c:\program files\Internet Explorer\SETFBD5.tmp
c:\program files\WinPCap
c:\program files\WinPCap\daemon_mgm.exe
c:\program files\WinPCap\NetMonInstaller.exe
c:\program files\WinPCap\npf_mgm.exe
c:\program files\WinPCap\rpcapd.exe
c:\program files\WinPCap\Uninstall.exe
c:\windows\bwUnin-6.3.2.116-9867844L.exe
c:\windows\Downloaded Program Files\WUInst.dll
c:\windows\help\wmplayer.bak
c:\windows\patch.exe
c:\windows\system32\Cache
c:\windows\system32\Cache\buts.bin
c:\windows\system32\Cache\comp40.bmp
c:\windows\system32\Cache\msg.bin
c:\windows\system32\Cache\search find 2.bmp
c:\windows\system32\Cache\showbtn.bmp
c:\windows\system32\Cache\showbtn1.bmp
c:\windows\system32\Cache\showbtn12.bmp
c:\windows\system32\Cache\showbtn123.bmp
c:\windows\system32\Cache\showbtn1234.bmp
c:\windows\system32\Cache\valentines copy.bmp
c:\windows\system32\Cache\web app.bmp
c:\windows\system32\CTFMON(2).EXE
c:\windows\system32\CTFMON(3).EXE
c:\windows\system32\CTFMON(4).EXE
c:\windows\system32\CTFMON(5).EXE
c:\windows\system32\CTFMON(6).EXE
c:\windows\system32\CTFMON(7).EXE
c:\windows\system32\CTFMON(8).EXE
c:\windows\system32\CTFMON(9).EXE
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\SET38E8.tmp
c:\windows\system32\SET38E9.tmp
c:\windows\system32\SET38EB.tmp
c:\windows\system32\SET38EC.tmp
c:\windows\system32\SET38ED.tmp
c:\windows\system32\SET38EE.tmp
c:\windows\system32\SET38EF.tmp
c:\windows\system32\SET38F1.tmp
c:\windows\system32\SET38F3.tmp
c:\windows\system32\SET38F4.tmp
c:\windows\system32\SET38F5.tmp
c:\windows\system32\SET38F8.tmp
c:\windows\system32\SET38F9.tmp
c:\windows\system32\SET38FC.tmp
c:\windows\system32\SET38FD.tmp
c:\windows\system32\SET38FF.tmp
c:\windows\system32\SET3902.tmp
c:\windows\system32\SET3903.tmp
c:\windows\system32\SET3904.tmp
c:\windows\system32\SET3905.tmp
c:\windows\system32\SET3906.tmp
c:\windows\system32\SET3907.tmp
c:\windows\system32\SET390B.tmp
c:\windows\system32\SET390C.tmp
c:\windows\system32\SET390D.tmp
c:\windows\system32\SET390E.tmp
c:\windows\system32\SET390F.tmp
c:\windows\system32\SET3910.tmp
c:\windows\system32\SET3911.tmp
c:\windows\system32\SET3912.tmp
c:\windows\system32\SET3913.tmp
c:\windows\system32\SET3914.tmp
c:\windows\system32\SET3915.tmp
c:\windows\system32\SET3917.tmp
c:\windows\system32\SET3918.tmp
c:\windows\system32\SET3919.tmp
c:\windows\system32\SET391A.tmp
c:\windows\system32\SET85B.tmp
c:\windows\system32\SET867.tmp
c:\windows\system32\SETFBE5.tmp
c:\windows\system32\SETFBE6.tmp
c:\windows\system32\SETFBE8.tmp
c:\windows\system32\SETFBE9.tmp
c:\windows\system32\SETFBEA.tmp
c:\windows\system32\SETFBEB.tmp
c:\windows\system32\SETFBEC.tmp
c:\windows\system32\SETFBEE.tmp
c:\windows\system32\SETFBF0.tmp
c:\windows\system32\SETFBF1.tmp
c:\windows\system32\SETFBF2.tmp
c:\windows\system32\SETFBF5.tmp
c:\windows\system32\SETFBF6.tmp
c:\windows\system32\SETFBF9.tmp
c:\windows\system32\SETFBFA.tmp
c:\windows\system32\SETFBFC.tmp
c:\windows\system32\SETFBFF.tmp
c:\windows\system32\SETFC00.tmp
c:\windows\system32\SETFC01.tmp
c:\windows\system32\SETFC02.tmp
c:\windows\system32\SETFC03.tmp
c:\windows\system32\SETFC04.tmp
c:\windows\system32\SETFC08.tmp
c:\windows\system32\SETFC09.tmp
c:\windows\system32\SETFC0A.tmp
c:\windows\system32\SETFC0B.tmp
c:\windows\system32\SETFC0C.tmp
c:\windows\system32\SETFC0D.tmp
c:\windows\system32\SETFC0E.tmp
c:\windows\system32\SETFC0F.tmp
c:\windows\system32\SETFC10.tmp
c:\windows\system32\SETFC11.tmp
c:\windows\system32\SETFC12.tmp
c:\windows\system32\SETFC14.tmp
c:\windows\system32\SETFC15.tmp
c:\windows\system32\SETFC16.tmp
c:\windows\system32\SETFC17.tmp
c:\windows\system32\Temp
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_NPF
——-\Service_NPF
.
.
((((((((((((((((((((((((( Files Created from 2011-12-06 to 2012-01-06 )))))))))))))))))))))))))))))))
.
.
2012-01-01 18:17 . 2012-01-01 18:17 ——– d—–w- c:\documents and settings\Andrea\Application Data\Malwarebytes
2012-01-01 18:17 . 2012-01-01 18:17 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-12-28 14:12 . 2011-12-28 14:12 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-27 12:04 . 2011-12-27 12:04 ——– d—–w- c:\program files\TeaTimer (Spybot - Search & Destroy)
2011-12-13 13:20 . 2011-12-13 13:20 ——– d—–w- c:\program files\iPod
2011-12-13 13:20 . 2011-12-13 13:22 ——– d—–w- c:\program files\iTunes
2011-12-13 13:20 . 2011-12-13 13:22 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-12-13 13:15 . 2011-12-13 13:15 ——– d—–w- c:\documents and settings\LocalService\Application Data\Apple Computer
2011-12-13 13:11 . 2011-12-13 13:11 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin7.dll
2011-12-13 13:11 . 2011-12-13 13:11 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin6.dll
2011-12-13 13:11 . 2011-12-13 13:11 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin5.dll
2011-12-13 13:11 . 2011-12-13 13:11 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin4.dll
2011-12-13 13:11 . 2011-12-13 13:11 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin3.dll
2011-12-13 13:11 . 2011-12-13 13:11 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin2.dll
2011-12-13 13:11 . 2011-12-13 13:11 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin.dll
2011-12-13 13:10 . 2011-12-13 13:11 ——– d—–w- c:\program files\QuickTime
2011-12-13 12:18 . 2011-12-13 12:18 ——– d—–w- c:\program files\Apple Software Update
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-23 13:25 . 2005-01-05 22:02 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-01 16:07 . 2005-01-14 05:33 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-10-31 23:43 . 2005-06-30 17:43 78336 —-a-w- c:\windows\system32\ieencode.dll
2011-10-31 23:43 . 2005-04-27 13:54 832512 —-a-w- c:\windows\system32\wininet.dll
2011-10-31 23:43 . 2002-08-29 10:00 1830912 —-a-w- c:\windows\system32\inetcpl.cpl
2011-10-31 23:43 . 2002-08-29 10:00 17408 —-a-w- c:\windows\system32\corpol.dll
2011-10-28 05:31 . 2005-01-05 22:03 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37 . 2005-01-05 22:02 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 2005-01-05 22:02 2027008 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-24 18:29 . 2011-10-24 18:29 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 18:29 . 2011-10-24 18:29 69632 —-a-w- c:\windows\system32\QuickTime.qts
2011-10-18 11:13 . 2002-11-26 19:15 186880 —-a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22 . 2005-05-03 19:26 692736 —-a-w- c:\windows\system32\inetcomm.dll
1996-12-02 23:44 . 1996-12-02 23:44 582144 —-a-w- c:\program files\Common Files\dao350.dll
2011-11-21 04:04 . 2011-12-08 14:37 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dell AIO Printer A920"="c:\program files\Dell AIO Printer A920\dlbkbmgr.exe" [2003-06-02 270336]
"OfferApp"="c:\program files\OfferApp\OfferApp.exe" [2004-04-30 40960]
"F-Secure TNB"="c:\program files\COGECO Security Services\TNB\TNBUtil.exe" [2005-06-02 700416]
"F-Secure Manager"="c:\program files\COGECO Security Services\Common\FSM32.EXE" [2005-05-09 118833]
"F-Secure Startup Wizard"="c:\program files\COGECO Security Services\FSGUI\FSSW.EXE" [2005-11-18 372736]
"Babylon Client"="c:\program files\Babylon\Babylon-Pro\Babylon.exe" [2006-12-13 2785256]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-03-30 624248]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-08-14 565008]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-08-14 2407184]
"News Service"="c:\program files\COGECO Security Services\FSGUI\ispnews.exe" [2005-05-31 356352]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"PMBVolumeWatcher"="c:\program files\Sony\PMB\PMBVolumeWatcher.exe" [2010-03-24 599328]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2003-10-06 5058560]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-02 59240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-12-08 421736]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
COGECO Security Services (2).lnk - c:\program files\COGECO Security Services\backweb\9867844\Program\fspex.exe [2007-1-27 32807]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2003-8-21 24576]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"c:\\WINDOWS\\SYSTEM32\\LEXPPS.EXE"=
"c:\\WINDOWS\\SYSTEM32\\rtcshare.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\COGECO Security Services\\backweb\\9867844\\Program\\fspex.exe"=
"c:\\Program Files\\Java\\jre1.6.0_01\\bin\\javaw.exe"=
"c:\\Program Files\\IBP 10\\IBP.exe"=
"c:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
"c:\\Program Files\\Common Files\\SafeNet Sentinel\\Sentinel Protection Server\\WinNT\\spnsrvnt.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Documents and Settings\\Andrea\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:UDP"= 1723:UDP:VPN2
.
R2 ddnt;ddnt;c:\windows\system32\drivers\ddnt.sys [x]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-09-16 136176]
R2 XDRIBLNA;XDRIBLNA;c:\windows\system32\xdriblna.ncs [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-09-16 136176]
R3 HPUATA;HP CD Writer Plus Controller Driver;c:\windows\system32\DRIVERS\HPUATA.sys [2001-09-24 75776]
S0 FSFW;F-Secure Firewall Driver;c:\windows\System32\drivers\fsdfw.sys [2005-08-22 70224]
S2 F-Secure Filter;F-Secure File System Filter;c:\program files\COGECO Security Services\Anti-Virus\Win2K\FSfilter.sys [2004-09-10 48720]
S2 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\COGECO Security Services\Anti-Virus\Win2K\FSgk.sys [2008-10-21 62176]
S2 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\COGECO Security Services\Anti-Virus\Win2K\FSrec.sys [2004-12-17 16848]
S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files\Sony\PMB\PMBDeviceInfoProvider.exe [2009-10-24 360224]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - GTNDIS5
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 21:57]
.
2012-01-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-16 12:25]
.
2012-01-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-16 12:25]
.
2012-01-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3901343504-3224471582-637956630-1007Core.job
- c:\documents and settings\Andrea\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-09 12:45]
.
2012-01-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3901343504-3224471582-637956630-1007UA.job
- c:\documents and settings\Andrea\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-09 12:45]
.
2012-01-06 c:\windows\Tasks\Scheduled scanning task.job
- c:\progra~1\COGECO~1\ANTI-V~1\fsav.exe [2007-01-28 14:42]
.
2012-01-05 c:\windows\Tasks\User_Feed_Synchronization-{936498DA-A5E1-442D-8CE8-336B192F3E37}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 15:58]
.
2012-01-04 c:\windows\Tasks\{407942FB-702C-4B0E-97C4-1FF6FB896A6C}_MIL_Andrea.job
- c:\windows\system32\mobsync.exe [2002-08-29 00:12]
.
2011-12-30 c:\windows\Tasks\{E2DD4F40-12ED-4054-A688-7ABFAB0FBA18}_MIL_Andrea.job
- c:\windows\system32\mobsync.exe [2002-08-29 00:12]
.
2012-01-05 c:\windows\Tasks\{F5E6583D-9905-46F3-8EFE-58A3464E5357}_MIL_Andrea.job
- c:\windows\system32\mobsync.exe [2002-08-29 00:12]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.google.ca/
mStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Translate with &Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
LSP: winsflt.dll
TCP: DhcpNameServer = [removed] [removed] [removed]
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Andrea\Application Data\Mozilla\Firefox\Profiles\cbnv70qk.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca
FF - prefs.js: network.proxy.type - 4
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-googletalk - c:\program files\Google\Google Talk\googletalk.exe
Notify-WgaLogon - (no file)
AddRemove-Babylon Builder - c:\program files\Babylon Builder\Uninst.isu
AddRemove-HPExtendedCapabilities - c:\program files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe
AddRemove-WinPcapInst - c:\program files\WinPcap\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-01-05 23:10
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\XDRIBLNA]
"ImagePath"="\??\c:\windows\system32\xdriblna.ncs"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-3901343504-3224471582-637956630-1007\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(772)
c:\program files\COGECO Security Services\FWES\Program\fsdc.dll
.
- - - - - - - > 'lsass.exe'(832)
c:\windows\system32\winsflt.dll
c:\program files\COGECO Security Services\FWES\Program\fsdc.dll
.
- - - - - - - > 'explorer.exe'(7288)
c:\windows\system32\WININET.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\IME\SPGRMR.DLL
c:\windows\system32\ieframe.dll
c:\program files\Babylon\Babylon-Pro\CAPTLIB.DLL
.
- - - - - - - > 'csrss.exe'(748)
c:\program files\COGECO Security Services\FWES\Program\fsdc.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\COGECO Security Services\Anti-Virus\fsgk32st.exe
c:\program files\COGECO Security Services\Anti-Virus\FSGK32.EXE
c:\program files\COGECO Security Services\Common\FSMA32.EXE
c:\program files\COGECO Security Services\Anti-Virus\fssm32.exe
c:\program files\Java\jre1.6.0_13\bin\jqs.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\System32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
c:\windows\System32\MsPMSPSv.exe
c:\program files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
c:\program files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
c:\program files\Dell AIO Printer A920\dlbkbmon.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\COGECO Security Services\FWES\Program\fsdfwd.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\program files\COGECO Security Services\Common\FSLAUNCH.EXE
.
**************************************************************************
.
Completion time: 2012-01-05 23:50:50 - machine was rebooted
ComboFix-quarantined-files.txt 2012-01-06 03:49
.
Pre-Run: 58,031,656,960 bytes free
Post-Run: 61,595,275,264 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
.
- - End Of File - - 25933E8B8E0BCDE1C52762AFC161D80E