paulito
2010-06-06, 02:52
When i ran Spybot Search & Destroy i came with with two problems that could'nt be removed.
Fraud.WindowsProtectionSuite
Microsoft.Windows.RedirectedHosts.
"Unexpected error fixxing problems (Cannot create file "C\WINDOWS\System32\drivers\etc\hosts". Access is denied."
I hope this helps you help me! Thanks in advance.
DDS (Ver_10-03-17.01) - NTFSx86
Run by Paul at 18:49:17.84 on Sat 06/05/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1525 [GMT -5:00]
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
============== Running Processes ===============
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Nova Development\Scrapbook Factory\ReminderApp.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Logitech\SetPoint II\SetpointII.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Paul\Desktop\dds.scr
============== Pseudo HJT Report ===============
uSearch Bar = hxxp://www.google.com/ie
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13917&gct=&gc=1&q=%s
uURLSearchHooks: DefaultSearchHook Class: {c94e154b-1459-4a47-966b-4b843befc7db} - c:\program files\asksearch\bin\DefaultSearch.dll
BHO: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - c:\program files\lexmark toolbar\toolband.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AT&&T Toolbar: {4e7bd74f-2b8d-469e-94be-fd60bb9aae29} - c:\progra~1\atttoo~1\ATTTOO~1.DLL
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.5126.1836\swg.dll
BHO: MSN Toolbar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\4.0.0379.0\npwinext.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - c:\program files\lexmark toolbar\toolband.dll
TB: AT&&T Toolbar: {4e7bd74f-2b8d-469e-94be-fd60bb9aae29} - c:\progra~1\atttoo~1\ATTTOO~1.DLL
TB: MSN Toolbar: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\4.0.0379.0\npwinext.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [igndlm.exe] c:\program files\download manager\DLM.exe /windowsstart /startifwork
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [<NO NAME>]
mRun: [ReminderApp] c:\program files\nova development\scrapbook factory\ReminderApp.exe
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [EM_EXEC] c:\progra~1\mousew~1\system\EM_EXEC.EXE
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\setpoi~1.lnk - c:\program files\logitech\setpoint ii\SetpointII.exe
IE: &Search
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html
IE: {d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\house\start menu\programs\imvu\Run IMVU.lnk
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {E59EB121-F339-4851-A3BA-FE49C35617C2} - c:\program files\icq6.5\ICQ.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {38AB6A6C-CC4C-4F9E-A3DD-3C5681EF18A1} - hxxp://www-cdn.freerealms.com/gamedata/FreeRealmsInstaller.cab?v=1030
DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - hxxp://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.9.113.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
IFEO: image file execution options - svchost.exe
Hosts: 127.0.0.1 www.spywareinfo.com
Hosts: 74.125.45.100 securitysoftwarepayments.com
Hosts: 74.125.45.100 privatesecuredpayments.com
Hosts: 74.125.45.100 secure.privatesecuredpayments.com
Hosts: 74.125.45.100 secure-plus-payments.com
Note: multiple HOSTS entries found. Please refer to Attach.txt
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\paul\applic~1\mozilla\firefox\profiles\gjnpotfc.default\
FF - plugin: c:\program files\common files\motive\npMotive.dll
FF - plugin: c:\program files\download manager\npfpdlm.dll
FF - plugin: c:\program files\sony online entertainment\npsoe.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-8-22 11608]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-8-22 56816]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [2010-4-13 10384]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2010-3-8 1684736]
S3 cpuz132;cpuz132;\??\c:\docume~1\paul\locals~1\temp\cpuz132\cpuz132_x32.sys --> c:\docume~1\paul\locals~1\temp\cpuz132\cpuz132_x32.sys [?]
S4 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-8-22 108289]
S4 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-8-22 185089]
S4 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-5-20 136176]
S4 lxdv_device;lxdv_device;c:\windows\system32\lxdvcoms.exe -service --> c:\windows\system32\lxdvcoms.exe -service [?]
S4 lxdvCATSCustConnectService;lxdvCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdvserv.exe [2009-9-10 98984]
=============== Created Last 30 ================
2010-06-04 19:11:46 110 ----a-w- c:\windows\wininit.ini
2010-05-27 01:59:15 0 d-----w- c:\docume~1\alluse~1\applic~1\PMB Files
2010-05-27 01:59:03 0 d-----w- c:\program files\Pando Networks
2010-05-23 02:03:17 0 d-----w- c:\program files\iPod
2010-05-23 02:03:11 0 d-----w- c:\program files\iTunes
2010-05-23 02:00:35 0 d-----w- c:\program files\Bonjour
2010-05-17 20:30:42 0 d-sh--w- c:\docume~1\alluse~1\applic~1\MSAXYSSPE
2010-05-17 20:30:11 0 d-sh--w- c:\docume~1\alluse~1\applic~1\91cd877
2010-05-16 22:26:19 0 d-----w- c:\program files\Microsoft
2010-05-16 22:26:12 0 d-----w- c:\program files\MSN Toolbar
2010-05-16 22:25:35 0 d-----w- c:\program files\MSN Toolbar Installer
2010-05-16 22:24:37 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-05-16 22:24:37 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-05-08 17:33:08 0 d-----w- c:\docume~1\alluse~1\applic~1\PC Drivers HeadQuarters
==================== Find3M ====================
2010-06-04 22:23:22 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-05-18 23:30:08 137256 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-05-18 23:29:59 218808 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-05-02 00:47:43 138056 ----a-w- c:\docume~1\paul\applic~1\PnkBstrK.sys
2010-05-02 00:47:27 2434856 ----a-w- c:\windows\system32\pbsvc_bc2.exe
2010-04-29 20:39:38 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 20:39:26 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-13 21:00:48 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2010-04-13 21:00:48 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf
2010-04-13 21:00:46 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2010-04-08 18:20:02 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-04-08 18:20:02 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-03-10 06:15:52 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-03-09 00:16:58 77824 ----a-w- c:\windows\SOUNDMAN.EXE
2010-03-09 00:16:58 348160 ----a-w- c:\windows\vncutil.exe
2010-03-09 00:16:58 1826816 ----a-w- c:\windows\SkyTel.exe
2010-03-09 00:16:57 9715200 ----a-w- c:\windows\RTLCPL.EXE
2010-03-09 00:16:57 41472 ----a-w- c:\windows\system32\RtkCoInstXP.dll
2010-03-09 00:16:57 18702336 ----a-w- c:\windows\RTHDCPL.EXE
2010-03-09 00:16:57 1482752 ----a-w- c:\windows\RtlUpd.exe
2010-03-09 00:16:57 122880 ----a-w- c:\windows\RtkAudioService.exe
2010-03-09 00:16:55 2170880 ----a-w- c:\windows\MicCal.exe
2010-03-09 00:16:53 57344 ----a-w- c:\windows\ALCMTR.EXE
2010-03-09 00:16:53 2808832 ----a-w- c:\windows\ALCWZRD.EXE
2010-03-09 00:16:45 831488 ----a-w- c:\windows\RtlExUpd.dll
============= FINISH: 18:49:34.68 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-03-17.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 8/11/2009 12:40:08 AM
System Uptime: 6/5/2010 6:04:29 PM (0 hours ago)
Motherboard: First International Computer, Inc. | | KTBC51G
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 4200+ | Socket 939 | 2210/201mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 466 GiB total, 405.899 GiB free.
D: is CDROM ()
E: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable
==== Disabled Device Manager Items =============
Class GUID:
Description: USB Cable Modem
Device ID: USB\VID_069A&PID_4402\0018687F94E9
Manufacturer:
Name: USB Cable Modem
PNP Device ID: USB\VID_069A&PID_4402\0018687F94E9
Service:
==== System Restore Points ===================
RP185: 3/8/2010 5:59:29 PM - Installed Driver Access
RP186: 3/8/2010 6:07:37 PM - 3-8-10
RP187: 3/8/2010 6:17:21 PM - Installed Realtek High Definition Audio Driver
RP188: 3/9/2010 4:17:33 PM - Removed Driver Access
RP189: 3/9/2010 5:23:32 PM - Software Distribution Service 3.0
RP190: 3/9/2010 5:26:54 PM - Software Distribution Service 3.0
RP191: 3/10/2010 8:38:17 PM - System Checkpoint
RP192: 3/12/2010 1:51:34 PM - System Checkpoint
RP193: 3/13/2010 5:54:01 PM - System Checkpoint
RP194: 3/14/2010 9:12:58 PM - System Checkpoint
RP195: 3/16/2010 4:39:32 PM - System Checkpoint
RP196: 3/17/2010 8:03:53 PM - System Checkpoint
RP197: 3/19/2010 10:13:27 AM - System Checkpoint
RP198: 3/20/2010 10:35:55 PM - System Checkpoint
RP199: 3/22/2010 12:53:55 PM - System Checkpoint
RP200: 3/23/2010 12:58:42 PM - System Checkpoint
RP201: 3/24/2010 4:37:53 PM - System Checkpoint
RP202: 3/26/2010 12:38:17 AM - System Checkpoint
RP203: 3/27/2010 6:26:33 AM - System Checkpoint
RP204: 3/29/2010 3:24:22 PM - System Checkpoint
RP205: 3/30/2010 9:33:03 PM - System Checkpoint
RP206: 3/31/2010 3:52:21 PM - Software Distribution Service 3.0
RP207: 4/1/2010 6:50:43 PM - System Checkpoint
RP208: 4/3/2010 2:08:31 PM - System Checkpoint
RP209: 4/4/2010 2:27:10 PM - System Checkpoint
RP210: 4/7/2010 10:05:08 AM - System Checkpoint
RP211: 4/8/2010 4:05:22 PM - System Checkpoint
RP212: 4/10/2010 3:05:12 PM - System Checkpoint
RP213: 4/12/2010 1:38:58 PM - System Checkpoint
RP214: 4/13/2010 3:59:51 PM - Logitech SetPoint 5.20
RP215: 4/14/2010 3:55:55 PM - Software Distribution Service 3.0
RP216: 4/15/2010 4:24:11 PM - System Checkpoint
RP217: 4/16/2010 4:41:21 PM - System Checkpoint
RP218: 4/18/2010 12:08:12 AM - System Checkpoint
RP219: 4/18/2010 8:21:41 PM - Installed Steam
RP220: 4/20/2010 5:26:49 AM - System Checkpoint
RP221: 4/21/2010 7:20:57 AM - System Checkpoint
RP222: 4/22/2010 12:55:08 PM - System Checkpoint
RP223: 4/23/2010 1:44:03 PM - System Checkpoint
RP224: 4/24/2010 2:54:03 PM - System Checkpoint
RP225: 4/26/2010 12:56:08 PM - System Checkpoint
RP226: 4/27/2010 1:36:19 PM - System Checkpoint
RP227: 4/29/2010 12:51:30 PM - System Checkpoint
RP228: 4/30/2010 1:21:59 PM - System Checkpoint
RP229: 5/1/2010 7:37:19 PM - Installed Microsoft Visual C++ 2005 Redistributable
RP230: 5/1/2010 7:37:48 PM - Installed Battlefield: Bad Company™ 2
RP231: 5/3/2010 5:18:01 PM - System Checkpoint
RP232: 5/5/2010 10:00:23 AM - System Checkpoint
RP233: 5/6/2010 1:02:22 PM - System Checkpoint
RP234: 5/7/2010 4:45:23 PM - System Checkpoint
RP235: 5/8/2010 12:32:40 PM - Installed Driver Detective.
RP236: 5/8/2010 12:37:19 PM - Removed Bonjour
RP237: 5/8/2010 12:37:41 PM - Removed Driver Detective.
RP238: 5/8/2010 12:38:29 PM - Removed MobileMe Control Panel
RP239: 5/8/2010 12:38:54 PM - Removed Safari
RP240: 5/9/2010 2:01:38 PM - System Checkpoint
RP241: 5/10/2010 4:38:42 PM - System Checkpoint
RP242: 5/12/2010 10:40:26 AM - System Checkpoint
RP243: 5/12/2010 4:08:07 PM - Software Distribution Service 3.0
RP244: 5/13/2010 4:19:35 PM - System Checkpoint
RP245: 5/14/2010 6:33:36 PM - System Checkpoint
RP246: 5/16/2010 5:24:14 PM - Installed Java(TM) 6 Update 20
RP247: 5/16/2010 5:24:51 PM - Installed MSN Toolbar Setup
RP248: 5/18/2010 5:13:25 PM - System Checkpoint
RP249: 5/19/2010 8:34:29 PM - System Checkpoint
RP250: 5/21/2010 2:33:34 PM - System Checkpoint
RP251: 5/22/2010 8:40:42 PM - System Checkpoint
RP252: 5/24/2010 1:26:40 PM - System Checkpoint
RP253: 5/25/2010 2:05:49 PM - System Checkpoint
RP254: 5/25/2010 4:13:11 PM - Software Distribution Service 3.0
RP255: 5/25/2010 4:54:05 PM - Removed Darkfall US
RP256: 5/25/2010 4:54:23 PM - Installed Darkfall US
RP257: 5/27/2010 1:02:41 PM - System Checkpoint
RP258: 5/27/2010 4:07:15 PM - Removed Darkfall US
RP259: 5/27/2010 4:07:41 PM - Installed Darkfall US
RP260: 5/29/2010 1:17:10 AM - System Checkpoint
RP261: 5/30/2010 4:09:40 PM - System Checkpoint
RP262: 6/2/2010 12:51:48 PM - System Checkpoint
RP263: 6/4/2010 9:20:09 AM - System Checkpoint
RP264: 6/4/2010 4:16:08 PM - Software Distribution Service 3.0
RP265: 6/5/2010 4:47:58 PM - System Checkpoint
==== Hosts File Hijack ======================
Hosts: 127.0.0.1 www.spywareinfo.com
Hosts: 74.125.45.100 securitysoftwarepayments.com
Hosts: 74.125.45.100 privatesecuredpayments.com
Hosts: 74.125.45.100 secure.privatesecuredpayments.com
Hosts: 74.125.45.100 secure-plus-payments.com
Hosts: 74.125.45.100 www.secure-plus-payments.com
Hosts: 74.125.45.100 safebrowsing-cache.google.com
Hosts: 74.125.45.100 urs.microsoft.com
Hosts: 74.125.45.100 www.securesoftwarebill.com
Hosts: 74.125.45.100 secure.paysecuresystem.com
Hosts: 74.125.45.100 paysoftbillsolution.com
Hosts: 74.125.45.100 protected.maxisoftwaremart.com
==== Installed Programs ======================
ABBYY FineReader 6.0 Sprint
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Reader 9.1.3
Adobe Shockwave Player 11.5
Apple Application Support
Apple Mobile Device Support
Apple Software Update
AT&T Self Support Tool
AT&T Toolbar
ATT-HSI
att.net Internet Mail
AutoHotkey 1.0.48.05
Avira AntiVir Personal - Free Antivirus
Battlefield: Bad Company™ 2
Bonjour
Cheat Engine 5.5
Darkfall US
Data Lifeguard Tools
Download Manager 2.3.9
EA Download Manager
EA Download Manager UI
erLT
ERUNT 1.1j
Google Toolbar for Internet Explorer
Google Update Helper
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
ICQ6.5
iTunes
Java Auto Updater
Java(TM) 6 Update 20
Lexmark Toolbar
Lexmark X5400 Series
Logitech SetPoint 5.20
Malwarebytes' Anti-Malware
Media Player Codec Pack 3.9.5
Microsoft .NET Framework 1.0 Hotfix (KB953295)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Default Manager
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft UI Engine
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
mIRC
MouseWare 9.60
Mozilla Firefox (3.5.2)
MSN Toolbar
MSN Toolbar Platform
NVIDIA Display Control Panel
NVIDIA Drivers
NVIDIA nView Desktop Manager
Pando Media Booster
PunkBuster Services
QuickTime
Realtek High Definition Audio Driver
Safari
Scrapbook Factory
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972260)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980232)
Soft Data Fax Modem with SmartCP
Sonic Encoders
Spybot - Search & Destroy
Steam
Ultima Online Stygian Abyss Classic
Ultima Online: Gold
UOAssist
UOCartographer 0.9
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB972636)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows Media Player 10 (KB913800)
Update for Windows XP (KB951978)
Update for Windows XP (KB953356)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update Rollup 2 for Windows XP Media Center Edition 2005
User's Guides
Ventrilo Client
WebFldrs XP
Windows Backup Utility
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Live ID Sign-in Assistant
Windows Media Format Runtime
Windows XP Media Center Edition 2005 KB908250
Windows XP Media Center Edition 2005 KB973768
Windows XP Service Pack 3
==== Event Viewer Messages From Past Week ========
5/31/2010 8:31:12 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service gupdate with arguments "/comsvc" in order to run the server: {E225E692-4B47-4777-9BED-4FD7FE257F0E}
5/31/2010 6:02:01 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service gusvc with arguments "" in order to run the server: {89DAE4CD-9F17-4980-902A-99BA84A8F5C8}
==== End Of File ===========================
Fraud.WindowsProtectionSuite
Microsoft.Windows.RedirectedHosts.
"Unexpected error fixxing problems (Cannot create file "C\WINDOWS\System32\drivers\etc\hosts". Access is denied."
I hope this helps you help me! Thanks in advance.
DDS (Ver_10-03-17.01) - NTFSx86
Run by Paul at 18:49:17.84 on Sat 06/05/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1525 [GMT -5:00]
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
============== Running Processes ===============
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Nova Development\Scrapbook Factory\ReminderApp.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Logitech\SetPoint II\SetpointII.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Paul\Desktop\dds.scr
============== Pseudo HJT Report ===============
uSearch Bar = hxxp://www.google.com/ie
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13917&gct=&gc=1&q=%s
uURLSearchHooks: DefaultSearchHook Class: {c94e154b-1459-4a47-966b-4b843befc7db} - c:\program files\asksearch\bin\DefaultSearch.dll
BHO: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - c:\program files\lexmark toolbar\toolband.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AT&&T Toolbar: {4e7bd74f-2b8d-469e-94be-fd60bb9aae29} - c:\progra~1\atttoo~1\ATTTOO~1.DLL
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.5126.1836\swg.dll
BHO: MSN Toolbar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\4.0.0379.0\npwinext.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - c:\program files\lexmark toolbar\toolband.dll
TB: AT&&T Toolbar: {4e7bd74f-2b8d-469e-94be-fd60bb9aae29} - c:\progra~1\atttoo~1\ATTTOO~1.DLL
TB: MSN Toolbar: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\4.0.0379.0\npwinext.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [igndlm.exe] c:\program files\download manager\DLM.exe /windowsstart /startifwork
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [<NO NAME>]
mRun: [ReminderApp] c:\program files\nova development\scrapbook factory\ReminderApp.exe
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [EM_EXEC] c:\progra~1\mousew~1\system\EM_EXEC.EXE
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\setpoi~1.lnk - c:\program files\logitech\setpoint ii\SetpointII.exe
IE: &Search
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html
IE: {d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\house\start menu\programs\imvu\Run IMVU.lnk
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {E59EB121-F339-4851-A3BA-FE49C35617C2} - c:\program files\icq6.5\ICQ.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {38AB6A6C-CC4C-4F9E-A3DD-3C5681EF18A1} - hxxp://www-cdn.freerealms.com/gamedata/FreeRealmsInstaller.cab?v=1030
DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - hxxp://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.9.113.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
IFEO: image file execution options - svchost.exe
Hosts: 127.0.0.1 www.spywareinfo.com
Hosts: 74.125.45.100 securitysoftwarepayments.com
Hosts: 74.125.45.100 privatesecuredpayments.com
Hosts: 74.125.45.100 secure.privatesecuredpayments.com
Hosts: 74.125.45.100 secure-plus-payments.com
Note: multiple HOSTS entries found. Please refer to Attach.txt
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\paul\applic~1\mozilla\firefox\profiles\gjnpotfc.default\
FF - plugin: c:\program files\common files\motive\npMotive.dll
FF - plugin: c:\program files\download manager\npfpdlm.dll
FF - plugin: c:\program files\sony online entertainment\npsoe.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-8-22 11608]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-8-22 56816]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [2010-4-13 10384]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2010-3-8 1684736]
S3 cpuz132;cpuz132;\??\c:\docume~1\paul\locals~1\temp\cpuz132\cpuz132_x32.sys --> c:\docume~1\paul\locals~1\temp\cpuz132\cpuz132_x32.sys [?]
S4 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-8-22 108289]
S4 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-8-22 185089]
S4 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-5-20 136176]
S4 lxdv_device;lxdv_device;c:\windows\system32\lxdvcoms.exe -service --> c:\windows\system32\lxdvcoms.exe -service [?]
S4 lxdvCATSCustConnectService;lxdvCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdvserv.exe [2009-9-10 98984]
=============== Created Last 30 ================
2010-06-04 19:11:46 110 ----a-w- c:\windows\wininit.ini
2010-05-27 01:59:15 0 d-----w- c:\docume~1\alluse~1\applic~1\PMB Files
2010-05-27 01:59:03 0 d-----w- c:\program files\Pando Networks
2010-05-23 02:03:17 0 d-----w- c:\program files\iPod
2010-05-23 02:03:11 0 d-----w- c:\program files\iTunes
2010-05-23 02:00:35 0 d-----w- c:\program files\Bonjour
2010-05-17 20:30:42 0 d-sh--w- c:\docume~1\alluse~1\applic~1\MSAXYSSPE
2010-05-17 20:30:11 0 d-sh--w- c:\docume~1\alluse~1\applic~1\91cd877
2010-05-16 22:26:19 0 d-----w- c:\program files\Microsoft
2010-05-16 22:26:12 0 d-----w- c:\program files\MSN Toolbar
2010-05-16 22:25:35 0 d-----w- c:\program files\MSN Toolbar Installer
2010-05-16 22:24:37 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-05-16 22:24:37 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-05-08 17:33:08 0 d-----w- c:\docume~1\alluse~1\applic~1\PC Drivers HeadQuarters
==================== Find3M ====================
2010-06-04 22:23:22 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-05-18 23:30:08 137256 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-05-18 23:29:59 218808 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-05-02 00:47:43 138056 ----a-w- c:\docume~1\paul\applic~1\PnkBstrK.sys
2010-05-02 00:47:27 2434856 ----a-w- c:\windows\system32\pbsvc_bc2.exe
2010-04-29 20:39:38 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 20:39:26 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-13 21:00:48 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2010-04-13 21:00:48 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf
2010-04-13 21:00:46 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2010-04-08 18:20:02 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-04-08 18:20:02 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-03-10 06:15:52 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-03-09 00:16:58 77824 ----a-w- c:\windows\SOUNDMAN.EXE
2010-03-09 00:16:58 348160 ----a-w- c:\windows\vncutil.exe
2010-03-09 00:16:58 1826816 ----a-w- c:\windows\SkyTel.exe
2010-03-09 00:16:57 9715200 ----a-w- c:\windows\RTLCPL.EXE
2010-03-09 00:16:57 41472 ----a-w- c:\windows\system32\RtkCoInstXP.dll
2010-03-09 00:16:57 18702336 ----a-w- c:\windows\RTHDCPL.EXE
2010-03-09 00:16:57 1482752 ----a-w- c:\windows\RtlUpd.exe
2010-03-09 00:16:57 122880 ----a-w- c:\windows\RtkAudioService.exe
2010-03-09 00:16:55 2170880 ----a-w- c:\windows\MicCal.exe
2010-03-09 00:16:53 57344 ----a-w- c:\windows\ALCMTR.EXE
2010-03-09 00:16:53 2808832 ----a-w- c:\windows\ALCWZRD.EXE
2010-03-09 00:16:45 831488 ----a-w- c:\windows\RtlExUpd.dll
============= FINISH: 18:49:34.68 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-03-17.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 8/11/2009 12:40:08 AM
System Uptime: 6/5/2010 6:04:29 PM (0 hours ago)
Motherboard: First International Computer, Inc. | | KTBC51G
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 4200+ | Socket 939 | 2210/201mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 466 GiB total, 405.899 GiB free.
D: is CDROM ()
E: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable
==== Disabled Device Manager Items =============
Class GUID:
Description: USB Cable Modem
Device ID: USB\VID_069A&PID_4402\0018687F94E9
Manufacturer:
Name: USB Cable Modem
PNP Device ID: USB\VID_069A&PID_4402\0018687F94E9
Service:
==== System Restore Points ===================
RP185: 3/8/2010 5:59:29 PM - Installed Driver Access
RP186: 3/8/2010 6:07:37 PM - 3-8-10
RP187: 3/8/2010 6:17:21 PM - Installed Realtek High Definition Audio Driver
RP188: 3/9/2010 4:17:33 PM - Removed Driver Access
RP189: 3/9/2010 5:23:32 PM - Software Distribution Service 3.0
RP190: 3/9/2010 5:26:54 PM - Software Distribution Service 3.0
RP191: 3/10/2010 8:38:17 PM - System Checkpoint
RP192: 3/12/2010 1:51:34 PM - System Checkpoint
RP193: 3/13/2010 5:54:01 PM - System Checkpoint
RP194: 3/14/2010 9:12:58 PM - System Checkpoint
RP195: 3/16/2010 4:39:32 PM - System Checkpoint
RP196: 3/17/2010 8:03:53 PM - System Checkpoint
RP197: 3/19/2010 10:13:27 AM - System Checkpoint
RP198: 3/20/2010 10:35:55 PM - System Checkpoint
RP199: 3/22/2010 12:53:55 PM - System Checkpoint
RP200: 3/23/2010 12:58:42 PM - System Checkpoint
RP201: 3/24/2010 4:37:53 PM - System Checkpoint
RP202: 3/26/2010 12:38:17 AM - System Checkpoint
RP203: 3/27/2010 6:26:33 AM - System Checkpoint
RP204: 3/29/2010 3:24:22 PM - System Checkpoint
RP205: 3/30/2010 9:33:03 PM - System Checkpoint
RP206: 3/31/2010 3:52:21 PM - Software Distribution Service 3.0
RP207: 4/1/2010 6:50:43 PM - System Checkpoint
RP208: 4/3/2010 2:08:31 PM - System Checkpoint
RP209: 4/4/2010 2:27:10 PM - System Checkpoint
RP210: 4/7/2010 10:05:08 AM - System Checkpoint
RP211: 4/8/2010 4:05:22 PM - System Checkpoint
RP212: 4/10/2010 3:05:12 PM - System Checkpoint
RP213: 4/12/2010 1:38:58 PM - System Checkpoint
RP214: 4/13/2010 3:59:51 PM - Logitech SetPoint 5.20
RP215: 4/14/2010 3:55:55 PM - Software Distribution Service 3.0
RP216: 4/15/2010 4:24:11 PM - System Checkpoint
RP217: 4/16/2010 4:41:21 PM - System Checkpoint
RP218: 4/18/2010 12:08:12 AM - System Checkpoint
RP219: 4/18/2010 8:21:41 PM - Installed Steam
RP220: 4/20/2010 5:26:49 AM - System Checkpoint
RP221: 4/21/2010 7:20:57 AM - System Checkpoint
RP222: 4/22/2010 12:55:08 PM - System Checkpoint
RP223: 4/23/2010 1:44:03 PM - System Checkpoint
RP224: 4/24/2010 2:54:03 PM - System Checkpoint
RP225: 4/26/2010 12:56:08 PM - System Checkpoint
RP226: 4/27/2010 1:36:19 PM - System Checkpoint
RP227: 4/29/2010 12:51:30 PM - System Checkpoint
RP228: 4/30/2010 1:21:59 PM - System Checkpoint
RP229: 5/1/2010 7:37:19 PM - Installed Microsoft Visual C++ 2005 Redistributable
RP230: 5/1/2010 7:37:48 PM - Installed Battlefield: Bad Company™ 2
RP231: 5/3/2010 5:18:01 PM - System Checkpoint
RP232: 5/5/2010 10:00:23 AM - System Checkpoint
RP233: 5/6/2010 1:02:22 PM - System Checkpoint
RP234: 5/7/2010 4:45:23 PM - System Checkpoint
RP235: 5/8/2010 12:32:40 PM - Installed Driver Detective.
RP236: 5/8/2010 12:37:19 PM - Removed Bonjour
RP237: 5/8/2010 12:37:41 PM - Removed Driver Detective.
RP238: 5/8/2010 12:38:29 PM - Removed MobileMe Control Panel
RP239: 5/8/2010 12:38:54 PM - Removed Safari
RP240: 5/9/2010 2:01:38 PM - System Checkpoint
RP241: 5/10/2010 4:38:42 PM - System Checkpoint
RP242: 5/12/2010 10:40:26 AM - System Checkpoint
RP243: 5/12/2010 4:08:07 PM - Software Distribution Service 3.0
RP244: 5/13/2010 4:19:35 PM - System Checkpoint
RP245: 5/14/2010 6:33:36 PM - System Checkpoint
RP246: 5/16/2010 5:24:14 PM - Installed Java(TM) 6 Update 20
RP247: 5/16/2010 5:24:51 PM - Installed MSN Toolbar Setup
RP248: 5/18/2010 5:13:25 PM - System Checkpoint
RP249: 5/19/2010 8:34:29 PM - System Checkpoint
RP250: 5/21/2010 2:33:34 PM - System Checkpoint
RP251: 5/22/2010 8:40:42 PM - System Checkpoint
RP252: 5/24/2010 1:26:40 PM - System Checkpoint
RP253: 5/25/2010 2:05:49 PM - System Checkpoint
RP254: 5/25/2010 4:13:11 PM - Software Distribution Service 3.0
RP255: 5/25/2010 4:54:05 PM - Removed Darkfall US
RP256: 5/25/2010 4:54:23 PM - Installed Darkfall US
RP257: 5/27/2010 1:02:41 PM - System Checkpoint
RP258: 5/27/2010 4:07:15 PM - Removed Darkfall US
RP259: 5/27/2010 4:07:41 PM - Installed Darkfall US
RP260: 5/29/2010 1:17:10 AM - System Checkpoint
RP261: 5/30/2010 4:09:40 PM - System Checkpoint
RP262: 6/2/2010 12:51:48 PM - System Checkpoint
RP263: 6/4/2010 9:20:09 AM - System Checkpoint
RP264: 6/4/2010 4:16:08 PM - Software Distribution Service 3.0
RP265: 6/5/2010 4:47:58 PM - System Checkpoint
==== Hosts File Hijack ======================
Hosts: 127.0.0.1 www.spywareinfo.com
Hosts: 74.125.45.100 securitysoftwarepayments.com
Hosts: 74.125.45.100 privatesecuredpayments.com
Hosts: 74.125.45.100 secure.privatesecuredpayments.com
Hosts: 74.125.45.100 secure-plus-payments.com
Hosts: 74.125.45.100 www.secure-plus-payments.com
Hosts: 74.125.45.100 safebrowsing-cache.google.com
Hosts: 74.125.45.100 urs.microsoft.com
Hosts: 74.125.45.100 www.securesoftwarebill.com
Hosts: 74.125.45.100 secure.paysecuresystem.com
Hosts: 74.125.45.100 paysoftbillsolution.com
Hosts: 74.125.45.100 protected.maxisoftwaremart.com
==== Installed Programs ======================
ABBYY FineReader 6.0 Sprint
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Reader 9.1.3
Adobe Shockwave Player 11.5
Apple Application Support
Apple Mobile Device Support
Apple Software Update
AT&T Self Support Tool
AT&T Toolbar
ATT-HSI
att.net Internet Mail
AutoHotkey 1.0.48.05
Avira AntiVir Personal - Free Antivirus
Battlefield: Bad Company™ 2
Bonjour
Cheat Engine 5.5
Darkfall US
Data Lifeguard Tools
Download Manager 2.3.9
EA Download Manager
EA Download Manager UI
erLT
ERUNT 1.1j
Google Toolbar for Internet Explorer
Google Update Helper
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
ICQ6.5
iTunes
Java Auto Updater
Java(TM) 6 Update 20
Lexmark Toolbar
Lexmark X5400 Series
Logitech SetPoint 5.20
Malwarebytes' Anti-Malware
Media Player Codec Pack 3.9.5
Microsoft .NET Framework 1.0 Hotfix (KB953295)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Default Manager
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft UI Engine
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
mIRC
MouseWare 9.60
Mozilla Firefox (3.5.2)
MSN Toolbar
MSN Toolbar Platform
NVIDIA Display Control Panel
NVIDIA Drivers
NVIDIA nView Desktop Manager
Pando Media Booster
PunkBuster Services
QuickTime
Realtek High Definition Audio Driver
Safari
Scrapbook Factory
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972260)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980232)
Soft Data Fax Modem with SmartCP
Sonic Encoders
Spybot - Search & Destroy
Steam
Ultima Online Stygian Abyss Classic
Ultima Online: Gold
UOAssist
UOCartographer 0.9
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB972636)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows Media Player 10 (KB913800)
Update for Windows XP (KB951978)
Update for Windows XP (KB953356)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update Rollup 2 for Windows XP Media Center Edition 2005
User's Guides
Ventrilo Client
WebFldrs XP
Windows Backup Utility
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Live ID Sign-in Assistant
Windows Media Format Runtime
Windows XP Media Center Edition 2005 KB908250
Windows XP Media Center Edition 2005 KB973768
Windows XP Service Pack 3
==== Event Viewer Messages From Past Week ========
5/31/2010 8:31:12 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service gupdate with arguments "/comsvc" in order to run the server: {E225E692-4B47-4777-9BED-4FD7FE257F0E}
5/31/2010 6:02:01 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service gusvc with arguments "" in order to run the server: {89DAE4CD-9F17-4980-902A-99BA84A8F5C8}
==== End Of File ===========================