great stuff! That was the ticket! That removed the Spybot folder, and I was able to successfully able to reinstall and run Spybot. I think we are finally all ok. I cannot thank you enough for your valued assistance.
ComboFix 09-10-18.02 - ralph herrera 10/18/2009 21:29.5.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.449 [GMT -4:00]
Running from: c:\documents and settings\ralph herrera\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\ralph herrera\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.080915-2039.log
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.080915-2053.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.081214-1921.log
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.081214-1933.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.081230-1458.log
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.081230-1506.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.081230-1739.log
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.081230-1739.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.081230-2015.log
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.081230-2016.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.090117-0852.log
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.090117-0900.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.090119-1927.log
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.090119-1927.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.090119-1928.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.090119-1931.log
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.090119-1944.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.090119-1945.log
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.090119-1945.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.090202-2102.log
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.090202-2102.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.090202-2105.log
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.090202-2114.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.090302-0831.log
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.090302-0840.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.090310-1836.log
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.090310-1844.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.090503-1828.log
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.090503-1828.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.090525-1739.log
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.090525-1749.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.090710-1745.log
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.090710-1755.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.090820-0948.log
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.090820-0950.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.090910-1622.log
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.090910-1622.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.090925-2055.log
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.091002-1522.log
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Fixes.080915-2058.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Fixes.081214-1935.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Fixes.081214-1936.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Fixes.081230-1506.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Fixes.081230-1739.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Fixes.090117-0902.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Fixes.090119-1929.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Fixes.090202-2105.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Fixes.090202-2115.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Fixes.090202-2118.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Fixes.090302-0940.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Fixes.090525-1749.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Resident.log
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\SDHelper.log
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Update downloads.log
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\ProcCache.sbc
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Avrlabs.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Avrlabs1.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FraudXPAntivirus.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Missinghelpfile.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MissingsharedDLL.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MissingsharedDLL1.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MissingsharedDLL2.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MissingsharedDLL3.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MissingsharedDLL4.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Overview.ini
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WMVideoPlugin.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WMVideoPlugin1.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Wrongapppath.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Wrongapppath1.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Wrongapppath10.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Wrongapppath11.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Wrongapppath12.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Wrongapppath13.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Wrongapppath14.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Wrongapppath15.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Wrongapppath16.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Wrongapppath17.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Wrongapppath2.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Wrongapppath3.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Wrongapppath4.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Wrongapppath5.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Wrongapppath6.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Wrongapppath7.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Wrongapppath8.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Wrongapppath9.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Wronguninstallinformation.zip
c:\program files\Spybot - Search & Destroy
c:\program files\Spybot - Search & Destroy\advcheck.dll
c:\program files\Spybot - Search & Destroy\SDHelper.dll
c:\program files\Spybot - Search & Destroy\SpybotSD.exe
.
((((((((((((((((((((((((( Files Created from 2009-09-19 to 2009-10-19 )))))))))))))))))))))))))))))))
.
2009-10-16 15:35 . 2009-03-30 14:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-10-16 15:35 . 2009-02-13 16:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-10-16 15:35 . 2009-02-13 16:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-10-16 15:35 . 2009-10-16 15:35 -------- d-----w- c:\program files\Avira
2009-10-15 19:57 . 2009-10-15 19:57 -------- d-----w- c:\documents and settings\ralph herrera\Application Data\Foxit
2009-10-15 19:57 . 2009-10-15 19:57 -------- d-----w- c:\program files\Foxit Software
2009-10-15 18:54 . 2009-09-10 18:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-15 18:54 . 2009-10-15 18:54 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-15 18:54 . 2009-09-10 18:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-15 18:00 . 2009-10-15 18:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-10-15 14:21 . 2009-10-15 14:23 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
2009-10-09 11:57 . 2009-10-09 11:57 -------- d-----w- c:\program files\ERUNT
2009-10-09 02:25 . 2009-10-09 02:31 -------- d-----w- c:\documents and settings\ralph herrera\DoctorWeb
2009-10-09 02:07 . 2009-10-09 02:07 -------- d-----w- c:\windows\system32\wbem\Repository
2009-10-09 01:57 . 2009-10-01 14:29 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-10-09 01:56 . 2009-10-17 00:32 -------- d-----w- c:\program files\Windows Defender
2009-10-09 01:53 . 2009-10-09 01:54 -------- d-----w- c:\documents and settings\ralph herrera\Application Data\Netscape
2009-10-09 00:41 . 2009-10-15 18:53 -------- d-----w- c:\program files\Mal
2009-10-02 20:05 . 2009-10-02 20:05 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-10-02 20:03 . 2009-07-28 20:33 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-10-02 19:32 . 2009-10-02 19:32 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2009-10-02 19:28 . 2009-10-14 20:01 -------- d--h--w- c:\windows\PIF
2009-10-02 19:26 . 2009-10-02 19:26 -------- d-----w- c:\documents and settings\ralph herrera\Application Data\Malwarebytes
2009-10-02 19:26 . 2009-10-02 19:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-02 19:04 . 2009-10-16 15:41 -------- d-----w- c:\program files\SpywareBlaster
2009-09-23 08:37 . 2009-09-23 08:37 -------- d-----w- c:\documents and settings\ralph herrera\Application Data\Template
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-16 15:42 . 2008-07-10 03:40 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-15 18:27 . 2006-03-23 01:22 -------- d-----w- c:\program files\Java
2009-10-15 18:23 . 2008-12-03 01:09 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-15 14:13 . 2008-07-10 00:35 -------- d-----w- c:\program files\Microsoft Works
2009-09-23 08:37 . 2009-09-23 08:37 0 ----a-w- c:\documents and settings\ralph herrera\Application Data\wklnhst.dat
2009-09-13 02:29 . 2009-01-17 19:43 -------- d-----w- c:\documents and settings\ralph herrera\Application Data\Apple Computer
2009-09-13 02:28 . 2009-08-30 20:29 -------- d-----w- c:\program files\iTunes
2009-09-13 02:22 . 2009-09-13 02:21 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-13 02:21 . 2009-09-13 02:21 -------- d-----w- c:\program files\iPod
2009-09-13 02:21 . 2009-01-17 19:41 -------- d-----w- c:\program files\Common Files\Apple
2009-09-13 02:19 . 2009-09-13 02:18 -------- d-----w- c:\program files\QuickTime
2009-09-11 14:18 . 2006-03-22 21:23 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 12:25 . 2009-08-30 23:51 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-04 21:03 . 2006-03-22 21:23 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-30 21:01 . 2009-08-30 21:01 27468 ---ha-w- c:\windows\system32\mlfcache.dat
2009-08-30 20:44 . 2009-08-30 20:44 -------- d-----w- c:\program files\Safari
2009-08-29 08:08 . 2006-03-22 21:24 916480 ------w- c:\windows\system32\wininet.dll
2009-08-28 23:42 . 2009-06-08 00:38 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-08-28 23:42 . 2009-01-17 19:41 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-08-26 08:00 . 2006-03-22 21:24 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-25 01:30 . 2009-08-23 23:57 -------- d-----w- c:\program files\MSECACHE
2009-08-25 00:17 . 2009-01-17 15:18 -------- d-----w- c:\program files\PeerGuardian2
2009-08-20 13:57 . 2009-08-20 13:57 -------- d-----w- c:\documents and settings\ralph herrera\Application Data\AVG8
2009-08-05 09:01 . 2006-03-22 21:23 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 15:13 . 2004-08-03 23:18 2145280 ------w- c:\windows\system32\ntoskrnl.exe
2009-08-04 14:20 . 2004-08-03 22:59 2023936 ------w- c:\windows\system32\ntkrnlpa.exe
2009-07-25 09:23 . 2009-07-15 22:35 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-24 23:44 . 2009-07-24 23:12 29359 ----a-w- c:\windows\hpoins03.dat
2009-07-24 23:39 . 2005-01-05 08:27 136 ----a-w- c:\documents and settings\ralph herrera\Local Settings\Application Data\fusioncache.dat
.
((((((((((((((((((((((((((((( SnapShot@2009-10-15_15.58.47 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-17 00:53 . 2009-10-17 00:53 85173 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2009-10-16 15:35 . 2009-05-11 14:12 28520 c:\windows\system32\drivers\ssmdrv.sys
- 2009-10-02 20:03 . 2009-05-11 14:12 28520 c:\windows\system32\drivers\ssmdrv.sys
+ 2009-07-18 03:21 . 2009-07-18 03:21 257440 c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2009-07-18 03:21 . 2009-07-18 03:21 3883424 c:\windows\system32\Macromed\Flash\NPSWF32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WCULauncher"="c:\program files\Sony\SmartWi Connection Utility\WCULauncher.exe" [2006-02-08 73728]
"VAIOSurvey"="c:\program files\sony\vaio survey\surveysa.exe" [2005-06-13 258048]
"VAIOSecurity"="c:\program files\Sony\VAIO Security Center\VSC.exe" [2006-03-20 679936]
"VAIOCameraUtility"="c:\program files\Sony\VAIO Camera Utility\VCUServe.exe" [2005-12-01 69632]
"VAIO Update 2"="c:\program files\Sony\VAIO Update 2\VAIOUpdt.exe" [2005-10-12 151552]
"VAIO Recovery"="c:\windows\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 28672]
"Switcher.exe"="c:\program files\Sony\Wireless Switch Setting Utility\Switcher.exe" [2005-11-24 167936]
"SonyPowerCfg"="c:\program files\Sony\VAIO Power Management\SPMgr.exe" [2006-01-26 212992]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
"PartSeal"="c:\windows\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 28672]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-03-08 7557120]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-09 305440]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 32768]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-02-28 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-02-28 602182]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-17 98304]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-17 118784]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-17 77824]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd.exe" [2003-08-04 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"EOUApp"="c:\program files\Intel\Wireless\Bin\EOUWiz.exe" [2006-02-28 569413]
"Biomenu"="c:\program files\Protector Suite QL\menusw.exe" [2006-02-23 1354240]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2004-11-18 118784]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2007-06-12 56080]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2007-07-13 23:30 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2006-02-23 01:11 39936 ----a-w- c:\windows\system32\fusstub.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2005-05-21 01:42 73728 ----a-w- c:\windows\system32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli fusstub
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Documents and Settings\\ralph herrera\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 shpf;Sony HDD Protection Filter Driver;c:\windows\system32\drivers\shpf.sys [3/22/2006 5:24 PM 9216]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [10/16/2009 11:35 AM 108289]
R2 FdRedir;FdRedir;c:\program files\Common Files\Protector Suite QL\Drivers\FdRedir.sys [2/22/2006 9:13 PM 13440]
R2 FileDisk2;FileDisk Protector Kernel Driver;c:\program files\Common Files\Protector Suite QL\Drivers\filedisk.sys [2/22/2006 9:13 PM 33024]
R3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\drivers\SonyImgF.sys [3/22/2006 5:24 PM 29184]
R3 SPI;Sony Programmable I/O Control Device;c:\windows\system32\drivers\SonyPI.sys [3/22/2006 5:24 PM 71961]
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [3/22/2006 5:24 PM 226304]
S3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [3/22/2006 5:24 PM 36352]
.
Contents of the 'Scheduled Tasks' folder
2009-09-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\ralph herrera\Application Data\Mozilla\Firefox\Profiles\olfe5vrw.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p=
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-18 21:34
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1481934566-1017197884-31544948-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(744)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\windows\system32\fusstub.dll
c:\program files\Protector Suite QL\infra.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
c:\program files\Protector Suite QL\homefus.dll
c:\windows\system32\biologon.dll
c:\program files\Protector Suite QL\homepass.dll
c:\program files\Protector Suite QL\passport.dll
c:\program files\Protector Suite QL\BhTcAll.dll
c:\program files\Protector Suite QL\BhDevTfm.dll
c:\program files\Protector Suite QL\remote.dll
c:\windows\system32\VESWinlogon.dll
c:\program files\Protector Suite QL\AlgVer.dll
c:\program files\Protector Suite QL\TCBioLib.dll
c:\program files\Protector Suite QL\mysafe.dll
c:\program files\Protector Suite QL\config.dll
- - - - - - - > 'lsass.exe'(800)
c:\windows\system32\fusstub.dll
c:\program files\Protector Suite QL\infra.dll
c:\program files\Protector Suite QL\homefus.dll
.
Completion time: 2009-10-19 21:38
ComboFix-quarantined-files.txt 2009-10-19 01:37
ComboFix2.txt 2009-10-17 17:21
ComboFix3.txt 2009-10-17 17:00
ComboFix4.txt 2009-10-15 18:45
ComboFix5.txt 2009-10-19 01:28
Pre-Run: 88,078,409,728 bytes free
Post-Run: 88,050,860,032 bytes free
- - End Of File - - 2453EF57421615CED96A9DBDD0B90BDE