Hi!
I am in need of some help with removing malware from my computer. I have already done what was requested with the DDS.txt and Spybot results along with zipping the attach.txt. Please help me with whatever assistance you may offer. The texts are as follows with DDS.txt, first, followed by Spybot results. Thank you so much for your help. Leon.
DDS (Ver_10-10-10.01) - NTFSx86
Run by User at 13:21:03.96 on Sat 10/09/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.639.121 [GMT -5:00]
AV: My Security Shield *On-access scanning enabled* (Updated) {D56B2FA8-871B-47E5-A679-0C116F87DD68}
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: My Security Shield *enabled* {730BECE1-339E-4709-99CB-42F2EBA9A9BF}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\O8CF91JO\dds[1].com
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/ig
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe"
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [Search Protection] c:\program files\yahoo!\search protection\SearchProtection.exe
uRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NVMCTRAY.DLL,NvTaskbarInit
uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [nwiz] nwiz.exe /install
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
StartupFolder: c:\docume~1\user\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\user\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
IE: &Search - ?p=ZJxdm128YYUS
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {6F6FDB9E-5072-498C-BCB0-2B7F00C49EE7} - hxxp://support.dell.com/systemprofiler/DellSystemLite.CAB
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
IFEO: image file execution options - svchost.exe
Hosts: 74.125.45.100 4-open-davinci.com
Hosts: 74.125.45.100 securitysoftwarepayments.com
Hosts: 74.125.45.100 privatesecuredpayments.com
Hosts: 74.125.45.100 secure.privatesecuredpayments.com
Hosts: 74.125.45.100 getantivirusplusnow.com
Note: multiple HOSTS entries found. Please refer to Attach.txt
============= SERVICES / DRIVERS ===============
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-1-9 56816]
S1 avgio;avgio;\??\c:\program files\avira\antivir desktop\avgio.sys --> c:\program files\avira\antivir desktop\avgio.sys [?]
S3 MTK;Media Technology Kernel Driver;c:\windows\system32\drivers\mtk.sys --> c:\windows\system32\drivers\mtk.sys [?]
S4 AntiVirSchedulerService;Avira AntiVir Scheduler;"c:\program files\avira\antivir desktop\sched.exe" --> c:\program files\avira\antivir desktop\sched.exe [?]
S4 AntiVirService;Avira AntiVir Guard;"c:\program files\avira\antivir desktop\avguard.exe" --> c:\program files\avira\antivir desktop\avguard.exe [?]
=============== Created Last 30 ================
2010-10-09 17:41:04 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-124104.backup
2010-10-09 17:36:40 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123640.backup
2010-10-09 17:36:39 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123639.backup
2010-10-09 17:36:38 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123638.backup
2010-10-09 17:36:37 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123637.backup
2010-10-09 17:36:36 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123636.backup
2010-10-09 17:36:35 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123635.backup
2010-10-09 17:36:34 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123634.backup
2010-10-09 17:36:33 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123633.backup
2010-10-09 17:36:32 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123632.backup
2010-10-09 17:36:31 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123631.backup
2010-10-09 17:36:30 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123630.backup
2010-10-09 17:35:26 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123526.backup
2010-10-09 17:34:17 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123417.backup
2010-10-09 17:34:16 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123416.backup
2010-10-09 17:34:15 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123415.backup
2010-10-09 17:34:14 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123414.backup
2010-10-09 17:34:13 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123413.backup
2010-10-09 17:34:12 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123412.backup
2010-10-09 17:34:11 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123411.backup
2010-10-09 17:34:10 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123410.backup
2010-10-09 17:34:09 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123409.backup
2010-10-09 17:34:08 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123408.backup
2010-10-09 17:34:05 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123405.backup
2010-10-09 17:33:36 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123336.backup
2010-10-09 17:33:35 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123335.backup
2010-10-09 17:33:34 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123334.backup
2010-10-09 17:33:33 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123333.backup
2010-10-09 17:33:32 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123332.backup
2010-10-09 17:33:31 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123331.backup
2010-10-09 17:33:29 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123329.backup
2010-10-09 17:33:24 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123324.backup
2010-09-26 04:46:08 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll
2010-09-26 04:46:08 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll
2010-09-26 04:46:08 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2010-09-26 04:46:08 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2010-09-26 04:46:08 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2010-09-26 04:46:08 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2010-09-26 04:46:08 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
2010-09-26 04:39:49 -------- d-----w- c:\program files\Bonjour
2010-09-10 04:53:30 -------- d-----w- c:\docume~1\user\applic~1\Malwarebytes
2010-09-10 04:53:13 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-10 04:53:11 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-09-10 04:53:09 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-10 04:53:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-10 03:59:52 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225952.backup
2010-09-10 03:59:51 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225951.backup
2010-09-10 03:59:50 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225950.backup
2010-09-10 03:59:49 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225949.backup
2010-09-10 03:59:48 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225948.backup
2010-09-10 03:59:47 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225947.backup
2010-09-10 03:59:46 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225946.backup
2010-09-10 03:59:45 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225945.backup
2010-09-10 03:59:43 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225943.backup
2010-09-10 03:57:41 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225741.backup
2010-09-10 03:56:59 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225659.backup
2010-09-10 03:54:31 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225431.backup
2010-09-10 03:54:29 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225429.backup
2010-09-10 03:54:28 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225428.backup
2010-09-10 03:54:27 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225427.backup
2010-09-10 03:54:26 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225426.backup
2010-09-10 03:54:25 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225425.backup
2010-09-10 03:54:24 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225424.backup
2010-09-10 03:54:23 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225423.backup
2010-09-10 03:54:09 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225409.backup
2010-09-10 03:53:16 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225316.backup
2010-09-10 03:53:09 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225309.backup
2010-09-10 03:53:08 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225308.backup
2010-09-10 03:53:07 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225307.backup
2010-09-10 03:53:04 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225304.backup
2010-09-10 03:53:03 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225303.backup
2010-09-10 03:53:01 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225301.backup
2010-09-10 03:52:45 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225245.backup
2010-09-10 03:52:43 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225243.backup
2010-09-10 03:51:51 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225151.backup
2010-09-10 03:51:50 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225150.backup
2010-09-10 03:51:49 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225149.backup
2010-09-10 03:51:48 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225148.backup
2010-09-10 03:51:44 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225144.backup
2010-09-10 03:51:42 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225142.backup
2010-09-10 03:51:41 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225141.backup
2010-09-10 03:51:35 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225135.backup
2010-09-10 02:30:16 -------- d-----w- c:\program files\SDHelper (Spybot - Search & Destroy)
2010-09-10 02:30:15 -------- d-----w- c:\program files\TeaTimer (Spybot - Search & Destroy)
2010-09-10 02:30:15 -------- d-----w- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2010-09-10 02:30:14 -------- d-----w- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2010-09-10 02:28:17 -------- d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-09-10 02:28:13 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-09-10 02:26:19 -------- d-----w- c:\program files\Lavasoft
2010-09-10 02:00:50 -------- d-sh--w- c:\docume~1\alluse~1\applic~1\MSOFDHS
2010-09-10 02:00:18 -------- d-sh--w- c:\docume~1\alluse~1\applic~1\26be784
==================== Find3M ====================
2010-09-08 16:17:46 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-09-08 16:17:46 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-08-17 13:17:06 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-07-27 23:44:10 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-07-27 23:44:10 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-07-22 15:49:15 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-07-22 05:57:20 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-07-17 10:00:04 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-17 07:42:29 73728 ----a-w- c:\windows\system32\javacpl.cpl
============= FINISH: 13:21:58.93 ===============
SPYBOT RESULTS
Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
4-open-davinci.com=74.125.45.100
Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
securitysoftwarepayments.com=74.125.45.100
Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
privatesecuredpayments.com=74.125.45.100
Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
secure.privatesecuredpayments.com=74.125.45.100
Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
getantivirusplusnow.com=74.125.45.100
Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
secure-plus-payments.com=74.125.45.100
Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
www.getantivirusplusnow.com=74.125.45.100
Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
www.secure-plus-payments.com=74.125.45.100
Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
www.getavplusnow.com=74.125.45.100
Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
safebrowsing-cache.google.com=74.125.45.100
Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
urs.microsoft.com=74.125.45.100
Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
www.securesoftwarebill.com=74.125.45.100
Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
secure.paysecuresystem.com=74.125.45.100
Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
paysoftbillsolution.com=74.125.45.100
Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
protected.maxisoftwaremart.com=74.125.45.100
Microsoft.Windows.RedirectedHosts: [SBI $B89FBA81] Redirected host (Redirected host, nothing done)
www.securesoftwarebill.com=74.125.45.100
Microsoft.Windows.RedirectedHosts: [SBI $19781685] Redirected host (Redirected host, nothing done)
secure.paysecuresystem.com=74.125.45.100
Microsoft.Windows.RedirectedHosts: [SBI $CEFF52BA] Redirected host (Redirected host, nothing done)
paysoftbillsolution.com=74.125.45.100
Right Media: Tracking cookie (Internet Explorer: User) (Cookie, nothing done)
--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---
2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2004-04-27 unins000.exe (51.13.0.0)
2010-09-09 unins001.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-11-04 advcheck.dll (1.6.5.20)
2007-04-02 aports.dll (2.1.0.0)
2004-05-12 borlndmm.dll (7.0.4.453)
2004-05-12 delphimm.dll (7.0.4.453)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2004-05-12 UnzDll.dll (1.73.1.1)
2004-05-12 ZipDll.dll (1.73.2.0)
2010-06-29 Includes\Adware.sbi (*)
2010-08-24 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2009-11-03 Includes\Dialer.sbi (*)
2010-07-27 Includes\DialerC.sbi (*)
2010-01-25 Includes\HeavyDuty.sbi (*)
2009-05-26 Includes\Hijackers.sbi (*)
2010-07-27 Includes\HijackersC.sbi (*)
2010-06-29 Includes\iPhone.sbi (*)
2010-08-02 Includes\Keyloggers.sbi (*)
2010-08-31 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2010-06-01 Includes\Malware.sbi (*)
2010-09-07 Includes\MalwareC.sbi (*)
2010-05-18 Includes\PUPS.sbi (*)
2010-07-20 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2010-07-27 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2010-06-29 Includes\Spyware.sbi (*)
2010-07-27 Includes\SpywareC.sbi (*)
2010-03-08 Includes\Tracks.uti
2010-08-04 Includes\Trojans.sbi (*)
2010-07-28 Includes\TrojansC-02.sbi (*)
2010-07-28 Includes\TrojansC-03.sbi (*)
2010-07-28 Includes\TrojansC-04.sbi (*)
2010-09-07 Includes\TrojansC-05.sbi (*)
2010-08-15 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll
I am in need of some help with removing malware from my computer. I have already done what was requested with the DDS.txt and Spybot results along with zipping the attach.txt. Please help me with whatever assistance you may offer. The texts are as follows with DDS.txt, first, followed by Spybot results. Thank you so much for your help. Leon.
DDS (Ver_10-10-10.01) - NTFSx86
Run by User at 13:21:03.96 on Sat 10/09/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.639.121 [GMT -5:00]
AV: My Security Shield *On-access scanning enabled* (Updated) {D56B2FA8-871B-47E5-A679-0C116F87DD68}
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: My Security Shield *enabled* {730BECE1-339E-4709-99CB-42F2EBA9A9BF}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\O8CF91JO\dds[1].com
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/ig
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe"
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [Search Protection] c:\program files\yahoo!\search protection\SearchProtection.exe
uRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NVMCTRAY.DLL,NvTaskbarInit
uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [nwiz] nwiz.exe /install
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
StartupFolder: c:\docume~1\user\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\user\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
IE: &Search - ?p=ZJxdm128YYUS
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {6F6FDB9E-5072-498C-BCB0-2B7F00C49EE7} - hxxp://support.dell.com/systemprofiler/DellSystemLite.CAB
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
IFEO: image file execution options - svchost.exe
Hosts: 74.125.45.100 4-open-davinci.com
Hosts: 74.125.45.100 securitysoftwarepayments.com
Hosts: 74.125.45.100 privatesecuredpayments.com
Hosts: 74.125.45.100 secure.privatesecuredpayments.com
Hosts: 74.125.45.100 getantivirusplusnow.com
Note: multiple HOSTS entries found. Please refer to Attach.txt
============= SERVICES / DRIVERS ===============
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-1-9 56816]
S1 avgio;avgio;\??\c:\program files\avira\antivir desktop\avgio.sys --> c:\program files\avira\antivir desktop\avgio.sys [?]
S3 MTK;Media Technology Kernel Driver;c:\windows\system32\drivers\mtk.sys --> c:\windows\system32\drivers\mtk.sys [?]
S4 AntiVirSchedulerService;Avira AntiVir Scheduler;"c:\program files\avira\antivir desktop\sched.exe" --> c:\program files\avira\antivir desktop\sched.exe [?]
S4 AntiVirService;Avira AntiVir Guard;"c:\program files\avira\antivir desktop\avguard.exe" --> c:\program files\avira\antivir desktop\avguard.exe [?]
=============== Created Last 30 ================
2010-10-09 17:41:04 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-124104.backup
2010-10-09 17:36:40 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123640.backup
2010-10-09 17:36:39 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123639.backup
2010-10-09 17:36:38 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123638.backup
2010-10-09 17:36:37 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123637.backup
2010-10-09 17:36:36 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123636.backup
2010-10-09 17:36:35 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123635.backup
2010-10-09 17:36:34 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123634.backup
2010-10-09 17:36:33 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123633.backup
2010-10-09 17:36:32 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123632.backup
2010-10-09 17:36:31 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123631.backup
2010-10-09 17:36:30 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123630.backup
2010-10-09 17:35:26 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123526.backup
2010-10-09 17:34:17 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123417.backup
2010-10-09 17:34:16 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123416.backup
2010-10-09 17:34:15 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123415.backup
2010-10-09 17:34:14 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123414.backup
2010-10-09 17:34:13 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123413.backup
2010-10-09 17:34:12 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123412.backup
2010-10-09 17:34:11 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123411.backup
2010-10-09 17:34:10 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123410.backup
2010-10-09 17:34:09 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123409.backup
2010-10-09 17:34:08 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123408.backup
2010-10-09 17:34:05 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123405.backup
2010-10-09 17:33:36 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123336.backup
2010-10-09 17:33:35 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123335.backup
2010-10-09 17:33:34 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123334.backup
2010-10-09 17:33:33 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123333.backup
2010-10-09 17:33:32 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123332.backup
2010-10-09 17:33:31 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123331.backup
2010-10-09 17:33:29 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123329.backup
2010-10-09 17:33:24 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20101009-123324.backup
2010-09-26 04:46:08 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll
2010-09-26 04:46:08 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll
2010-09-26 04:46:08 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2010-09-26 04:46:08 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2010-09-26 04:46:08 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2010-09-26 04:46:08 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2010-09-26 04:46:08 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
2010-09-26 04:39:49 -------- d-----w- c:\program files\Bonjour
2010-09-10 04:53:30 -------- d-----w- c:\docume~1\user\applic~1\Malwarebytes
2010-09-10 04:53:13 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-10 04:53:11 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-09-10 04:53:09 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-10 04:53:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-10 03:59:52 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225952.backup
2010-09-10 03:59:51 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225951.backup
2010-09-10 03:59:50 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225950.backup
2010-09-10 03:59:49 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225949.backup
2010-09-10 03:59:48 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225948.backup
2010-09-10 03:59:47 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225947.backup
2010-09-10 03:59:46 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225946.backup
2010-09-10 03:59:45 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225945.backup
2010-09-10 03:59:43 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225943.backup
2010-09-10 03:57:41 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225741.backup
2010-09-10 03:56:59 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225659.backup
2010-09-10 03:54:31 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225431.backup
2010-09-10 03:54:29 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225429.backup
2010-09-10 03:54:28 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225428.backup
2010-09-10 03:54:27 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225427.backup
2010-09-10 03:54:26 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225426.backup
2010-09-10 03:54:25 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225425.backup
2010-09-10 03:54:24 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225424.backup
2010-09-10 03:54:23 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225423.backup
2010-09-10 03:54:09 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225409.backup
2010-09-10 03:53:16 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225316.backup
2010-09-10 03:53:09 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225309.backup
2010-09-10 03:53:08 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225308.backup
2010-09-10 03:53:07 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225307.backup
2010-09-10 03:53:04 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225304.backup
2010-09-10 03:53:03 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225303.backup
2010-09-10 03:53:01 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225301.backup
2010-09-10 03:52:45 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225245.backup
2010-09-10 03:52:43 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225243.backup
2010-09-10 03:51:51 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225151.backup
2010-09-10 03:51:50 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225150.backup
2010-09-10 03:51:49 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225149.backup
2010-09-10 03:51:48 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225148.backup
2010-09-10 03:51:44 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225144.backup
2010-09-10 03:51:42 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225142.backup
2010-09-10 03:51:41 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225141.backup
2010-09-10 03:51:35 2705 --sha-r- c:\windows\system32\drivers\etc\hosts.20100909-225135.backup
2010-09-10 02:30:16 -------- d-----w- c:\program files\SDHelper (Spybot - Search & Destroy)
2010-09-10 02:30:15 -------- d-----w- c:\program files\TeaTimer (Spybot - Search & Destroy)
2010-09-10 02:30:15 -------- d-----w- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2010-09-10 02:30:14 -------- d-----w- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2010-09-10 02:28:17 -------- d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-09-10 02:28:13 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-09-10 02:26:19 -------- d-----w- c:\program files\Lavasoft
2010-09-10 02:00:50 -------- d-sh--w- c:\docume~1\alluse~1\applic~1\MSOFDHS
2010-09-10 02:00:18 -------- d-sh--w- c:\docume~1\alluse~1\applic~1\26be784
==================== Find3M ====================
2010-09-08 16:17:46 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-09-08 16:17:46 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-08-17 13:17:06 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-07-27 23:44:10 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-07-27 23:44:10 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-07-22 15:49:15 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-07-22 05:57:20 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-07-17 10:00:04 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-17 07:42:29 73728 ----a-w- c:\windows\system32\javacpl.cpl
============= FINISH: 13:21:58.93 ===============
SPYBOT RESULTS
Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
4-open-davinci.com=74.125.45.100
Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
securitysoftwarepayments.com=74.125.45.100
Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
privatesecuredpayments.com=74.125.45.100
Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
secure.privatesecuredpayments.com=74.125.45.100
Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
getantivirusplusnow.com=74.125.45.100
Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
secure-plus-payments.com=74.125.45.100
Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
www.getantivirusplusnow.com=74.125.45.100
Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
www.secure-plus-payments.com=74.125.45.100
Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
www.getavplusnow.com=74.125.45.100
Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
safebrowsing-cache.google.com=74.125.45.100
Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
urs.microsoft.com=74.125.45.100
Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
www.securesoftwarebill.com=74.125.45.100
Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
secure.paysecuresystem.com=74.125.45.100
Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
paysoftbillsolution.com=74.125.45.100
Fraud.WindowsProtectionSuite: [SBI $B197733A] Redirected host (Redirected host, nothing done)
protected.maxisoftwaremart.com=74.125.45.100
Microsoft.Windows.RedirectedHosts: [SBI $B89FBA81] Redirected host (Redirected host, nothing done)
www.securesoftwarebill.com=74.125.45.100
Microsoft.Windows.RedirectedHosts: [SBI $19781685] Redirected host (Redirected host, nothing done)
secure.paysecuresystem.com=74.125.45.100
Microsoft.Windows.RedirectedHosts: [SBI $CEFF52BA] Redirected host (Redirected host, nothing done)
paysoftbillsolution.com=74.125.45.100
Right Media: Tracking cookie (Internet Explorer: User) (Cookie, nothing done)
--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---
2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2004-04-27 unins000.exe (51.13.0.0)
2010-09-09 unins001.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-11-04 advcheck.dll (1.6.5.20)
2007-04-02 aports.dll (2.1.0.0)
2004-05-12 borlndmm.dll (7.0.4.453)
2004-05-12 delphimm.dll (7.0.4.453)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2004-05-12 UnzDll.dll (1.73.1.1)
2004-05-12 ZipDll.dll (1.73.2.0)
2010-06-29 Includes\Adware.sbi (*)
2010-08-24 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2009-11-03 Includes\Dialer.sbi (*)
2010-07-27 Includes\DialerC.sbi (*)
2010-01-25 Includes\HeavyDuty.sbi (*)
2009-05-26 Includes\Hijackers.sbi (*)
2010-07-27 Includes\HijackersC.sbi (*)
2010-06-29 Includes\iPhone.sbi (*)
2010-08-02 Includes\Keyloggers.sbi (*)
2010-08-31 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2010-06-01 Includes\Malware.sbi (*)
2010-09-07 Includes\MalwareC.sbi (*)
2010-05-18 Includes\PUPS.sbi (*)
2010-07-20 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2010-07-27 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2010-06-29 Includes\Spyware.sbi (*)
2010-07-27 Includes\SpywareC.sbi (*)
2010-03-08 Includes\Tracks.uti
2010-08-04 Includes\Trojans.sbi (*)
2010-07-28 Includes\TrojansC-02.sbi (*)
2010-07-28 Includes\TrojansC-03.sbi (*)
2010-07-28 Includes\TrojansC-04.sbi (*)
2010-09-07 Includes\TrojansC-05.sbi (*)
2010-08-15 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll