I'm sorry this is my first post, please forgive me if I do it wrong.
Cannot remove:
Fraud.WindowsProtectionSuite
Microsoft.Windows.RedirectedHosts
DDS (Ver_10-10-10.03) - NTFSx86
Run by Janice at 16:51:00.76 on Thu 10/14/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.462 [GMT -8:00]
AV: Smart Engine *On-access scanning enabled* (Updated) {612F2188-7BCD-4059-BB11-733307F47813}
AV: Norton 360 Premier Edition *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Smart Engine *enabled* {AE61382B-3C9E-4A02-8BB4-EA9CC9EEBF07}
FW: Norton 360 Premier Edition *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton 360 Premier Edition\Engine\4.3.0.5\ccSvcHst.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Norton 360 Premier Edition\Engine\4.3.0.5\ccSvcHst.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Documents and Settings\Janice\Desktop\dds.com
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uWindow Title =
mWindow Title =
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360 premier edition\engine\4.3.0.5\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360 premier edition\engine\4.3.0.5\IPSBHO.DLL
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5612.1312\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360 premier edition\engine\4.3.0.5\coIEPlg.dll
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /installquiet
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: c:\docume~1\janice\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
uPolicies-explorer: DisallowRun = 1 (0x1)
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} - hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1286784124609
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1283149629921
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {8CFCF42C-1C64-47D6-AEEC-F9D001832ED3} - hxxp://xserv.dell.com/DellDriverScanner/DellSystem.CAB
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: {B471173C-15F5-4148-A484-84FBC9402DA0} = 204.17.139.2 209.112.128.2
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
IFEO: image file execution options - svchost.exe
Hosts: 127.0.0.1 www.spywareinfo.com
Hosts: 74.125.45.100 securitysoftwarepayments.com
Hosts: 74.125.45.100 privatesecuredpayments.com
Hosts: 74.125.45.100 secure.privatesecuredpayments.com
Hosts: 74.125.45.100 secure-plus-payments.com
Note: multiple HOSTS entries found. Please refer to Attach.txt
============= SERVICES / DRIVERS ===============
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0403000.005\symds.sys [2010-10-13 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0403000.005\symefa.sys [2010-10-13 173104]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\bashdefs\20101001.001\BHDrvx86.sys [2010-10-2 692272]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0403000.005\cchpx86.sys [2010-10-13 501888]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0403000.005\ironx86.sys [2010-10-13 116784]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2010-10-11 54760]
R2 N360;Norton 360;c:\program files\norton 360 premier edition\engine\4.3.0.5\ccsvchst.exe [2010-10-13 126392]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-10-13 102448]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\ipsdefs\20101012.001\IDSXpx86.sys [2010-9-15 341880]
R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\virusdefs\20101014.008\NAVENG.SYS [2010-10-14 86064]
R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\virusdefs\20101014.008\NAVEX15.SYS [2010-10-14 1371184]
S0 cerc6;cerc6; [x]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-10-12 136176]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-4-28 704872]
S3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys --> c:\windows\system32\drivers\rt2870.sys [?]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2008-4-13 14336]
=============== Created Last 30 ================
2010-10-14 04:00:22 -------- d-----w- c:\windows\system32\N360_BACKUP
2010-10-14 03:54:19 361904 ----a-w- c:\windows\system32\drivers\n360\0403000.005\symtdi.sys
2010-10-14 03:54:19 339504 ----a-w- c:\windows\system32\drivers\n360\0403000.005\symtdiv.sys
2010-10-14 03:54:19 328752 ----a-r- c:\windows\system32\drivers\n360\0403000.005\symds.sys
2010-10-14 03:54:19 173104 ----a-w- c:\windows\system32\drivers\n360\0403000.005\symefa.sys
2010-10-14 03:54:18 501888 ----a-w- c:\windows\system32\drivers\n360\0403000.005\cchpx86.sys
2010-10-14 03:54:18 43696 ----a-w- c:\windows\system32\drivers\n360\0403000.005\srtspx.sys
2010-10-14 03:54:18 325680 ----a-w- c:\windows\system32\drivers\n360\0403000.005\srtsp.sys
2010-10-14 03:54:18 116784 ----a-w- c:\windows\system32\drivers\n360\0403000.005\ironx86.sys
2010-10-14 03:53:56 -------- d-----w- c:\windows\system32\drivers\n360\0403000.005
2010-10-14 03:40:29 26600 ----a-r- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-10-14 03:40:29 107368 ----a-r- c:\windows\system32\GEARAspi.dll
2010-10-14 03:40:19 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2010-10-14 03:40:19 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-10-14 03:40:19 -------- d-----w- c:\program files\Symantec
2010-10-14 03:40:19 -------- d-----w- c:\program files\common files\Symantec Shared
2010-10-14 03:39:49 -------- d-----w- c:\windows\system32\drivers\N360
2010-10-14 03:39:47 -------- d-----w- c:\program files\Norton 360 Premier Edition
2010-10-14 03:33:01 -------- d-----w- c:\program files\NortonInstaller
2010-10-14 03:33:01 -------- d-----w- c:\docume~1\alluse~1\applic~1\NortonInstaller
2010-10-14 03:16:19 -------- d-----w- c:\docume~1\alluse~1\applic~1\Norton
2010-10-13 15:48:02 -------- d-sh--w- c:\docume~1\janice\applic~1\Smart Engine
2010-10-13 15:47:53 -------- d-sh--w- c:\docume~1\alluse~1\applic~1\SMSGE
2010-10-13 15:46:58 -------- d-sh--w- c:\docume~1\alluse~1\applic~1\74807e
2010-10-13 00:28:37 -------- d-----w- c:\windows\system32\winrm
2010-10-13 00:28:37 -------- d-----w- c:\windows\system32\GroupPolicy
2010-10-13 00:28:29 -------- dc-h--w- c:\windows\$968930Uinstall_KB968930$
2010-10-12 10:00:30 -------- d-----w- c:\docume~1\janice\locals~1\applic~1\Google
2010-10-11 09:01:01 221184 ----a-w- c:\windows\system32\wmpns.dll
2010-10-11 09:00:54 -------- d-----w- c:\program files\Windows Media Connect 2
2010-10-11 08:59:31 -------- d-----w- c:\windows\system32\LogFiles
2010-10-11 08:26:21 -------- d-----w- c:\documents and settings\janice\Tracing
2010-10-11 08:25:15 54760 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys
2010-10-11 08:24:00 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2010-10-11 08:23:56 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2010-10-11 08:22:52 -------- d-----w- c:\program files\Microsoft
2010-10-11 08:22:35 -------- d-----w- c:\program files\Windows Live SkyDrive
2010-10-11 08:21:54 4927864 ----a-w- c:\program files\common files\windows live\.cache\5cc999381cb691d\Silverlight.2.0.exe
2010-10-11 08:16:04 74520 ----a-w- c:\program files\common files\windows live\.cache\8c24af2a1cb691c\DSETUP.dll
2010-10-11 08:16:04 484632 ----a-w- c:\program files\common files\windows live\.cache\8c24af2a1cb691c\DXSETUP.exe
2010-10-11 08:16:04 1670936 ----a-w- c:\program files\common files\windows live\.cache\8c24af2a1cb691c\dsetup32.dll
2010-10-11 08:15:28 1013800 ----a-w- c:\program files\common files\windows live\.cache\76b449de1cb691c\WindowsXP-KB954708-x86-ENU.exe
2010-10-11 08:06:48 -------- d-----w- c:\program files\common files\Windows Live
2010-10-11 07:12:00 -------- d-----w- c:\docume~1\janice\applic~1\ElevatedDiagnostics
2010-10-11 06:55:26 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-10-11 06:55:26 16736 ----a-w- c:\windows\system32\mucltui.dll.mui
2010-10-11 03:43:30 -------- d-----w- c:\docume~1\janice\applic~1\Malwarebytes
2010-10-11 03:43:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-11 03:43:06 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-10-11 03:43:05 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-11 03:43:05 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-11 03:36:56 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-10-11 03:36:56 -------- d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
==================== Find3M ====================
2010-09-18 20:23:26 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53:25 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53:25 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53:25 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-10 05:58:08 916480 ----a-w- c:\windows\system32\wininet.dll
2010-09-10 05:58:06 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:58:06 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-09-01 11:51:14 285824 ----a-w- c:\windows\system32\atmfd.dll
2010-08-31 13:42:52 1852800 ----a-w- c:\windows\system32\win32k.sys
2010-08-30 05:33:08 0 ----a-w- c:\windows\invcol.tmp
2010-08-27 08:02:29 119808 ----a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:57:43 99840 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-26 12:52:45 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-08-23 16:12:04 617472 ----a-w- c:\windows\system32\comctl32.dll
2010-08-17 13:17:06 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:45:00 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-07-17 13:00:04 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-17 10:42:29 73728 ----a-w- c:\windows\system32\javacpl.cpl
============= FINISH: 16:52:12.10 ===============
Cannot remove:
Fraud.WindowsProtectionSuite
Microsoft.Windows.RedirectedHosts
DDS (Ver_10-10-10.03) - NTFSx86
Run by Janice at 16:51:00.76 on Thu 10/14/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.462 [GMT -8:00]
AV: Smart Engine *On-access scanning enabled* (Updated) {612F2188-7BCD-4059-BB11-733307F47813}
AV: Norton 360 Premier Edition *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Smart Engine *enabled* {AE61382B-3C9E-4A02-8BB4-EA9CC9EEBF07}
FW: Norton 360 Premier Edition *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton 360 Premier Edition\Engine\4.3.0.5\ccSvcHst.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Norton 360 Premier Edition\Engine\4.3.0.5\ccSvcHst.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Documents and Settings\Janice\Desktop\dds.com
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uWindow Title =
mWindow Title =
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360 premier edition\engine\4.3.0.5\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360 premier edition\engine\4.3.0.5\IPSBHO.DLL
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5612.1312\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360 premier edition\engine\4.3.0.5\coIEPlg.dll
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /installquiet
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: c:\docume~1\janice\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
uPolicies-explorer: DisallowRun = 1 (0x1)
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} - hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1286784124609
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1283149629921
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {8CFCF42C-1C64-47D6-AEEC-F9D001832ED3} - hxxp://xserv.dell.com/DellDriverScanner/DellSystem.CAB
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: {B471173C-15F5-4148-A484-84FBC9402DA0} = 204.17.139.2 209.112.128.2
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
IFEO: image file execution options - svchost.exe
Hosts: 127.0.0.1 www.spywareinfo.com
Hosts: 74.125.45.100 securitysoftwarepayments.com
Hosts: 74.125.45.100 privatesecuredpayments.com
Hosts: 74.125.45.100 secure.privatesecuredpayments.com
Hosts: 74.125.45.100 secure-plus-payments.com
Note: multiple HOSTS entries found. Please refer to Attach.txt
============= SERVICES / DRIVERS ===============
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0403000.005\symds.sys [2010-10-13 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0403000.005\symefa.sys [2010-10-13 173104]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\bashdefs\20101001.001\BHDrvx86.sys [2010-10-2 692272]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0403000.005\cchpx86.sys [2010-10-13 501888]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0403000.005\ironx86.sys [2010-10-13 116784]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2010-10-11 54760]
R2 N360;Norton 360;c:\program files\norton 360 premier edition\engine\4.3.0.5\ccsvchst.exe [2010-10-13 126392]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-10-13 102448]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\ipsdefs\20101012.001\IDSXpx86.sys [2010-9-15 341880]
R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\virusdefs\20101014.008\NAVENG.SYS [2010-10-14 86064]
R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\virusdefs\20101014.008\NAVEX15.SYS [2010-10-14 1371184]
S0 cerc6;cerc6; [x]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-10-12 136176]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-4-28 704872]
S3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys --> c:\windows\system32\drivers\rt2870.sys [?]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2008-4-13 14336]
=============== Created Last 30 ================
2010-10-14 04:00:22 -------- d-----w- c:\windows\system32\N360_BACKUP
2010-10-14 03:54:19 361904 ----a-w- c:\windows\system32\drivers\n360\0403000.005\symtdi.sys
2010-10-14 03:54:19 339504 ----a-w- c:\windows\system32\drivers\n360\0403000.005\symtdiv.sys
2010-10-14 03:54:19 328752 ----a-r- c:\windows\system32\drivers\n360\0403000.005\symds.sys
2010-10-14 03:54:19 173104 ----a-w- c:\windows\system32\drivers\n360\0403000.005\symefa.sys
2010-10-14 03:54:18 501888 ----a-w- c:\windows\system32\drivers\n360\0403000.005\cchpx86.sys
2010-10-14 03:54:18 43696 ----a-w- c:\windows\system32\drivers\n360\0403000.005\srtspx.sys
2010-10-14 03:54:18 325680 ----a-w- c:\windows\system32\drivers\n360\0403000.005\srtsp.sys
2010-10-14 03:54:18 116784 ----a-w- c:\windows\system32\drivers\n360\0403000.005\ironx86.sys
2010-10-14 03:53:56 -------- d-----w- c:\windows\system32\drivers\n360\0403000.005
2010-10-14 03:40:29 26600 ----a-r- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-10-14 03:40:29 107368 ----a-r- c:\windows\system32\GEARAspi.dll
2010-10-14 03:40:19 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2010-10-14 03:40:19 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-10-14 03:40:19 -------- d-----w- c:\program files\Symantec
2010-10-14 03:40:19 -------- d-----w- c:\program files\common files\Symantec Shared
2010-10-14 03:39:49 -------- d-----w- c:\windows\system32\drivers\N360
2010-10-14 03:39:47 -------- d-----w- c:\program files\Norton 360 Premier Edition
2010-10-14 03:33:01 -------- d-----w- c:\program files\NortonInstaller
2010-10-14 03:33:01 -------- d-----w- c:\docume~1\alluse~1\applic~1\NortonInstaller
2010-10-14 03:16:19 -------- d-----w- c:\docume~1\alluse~1\applic~1\Norton
2010-10-13 15:48:02 -------- d-sh--w- c:\docume~1\janice\applic~1\Smart Engine
2010-10-13 15:47:53 -------- d-sh--w- c:\docume~1\alluse~1\applic~1\SMSGE
2010-10-13 15:46:58 -------- d-sh--w- c:\docume~1\alluse~1\applic~1\74807e
2010-10-13 00:28:37 -------- d-----w- c:\windows\system32\winrm
2010-10-13 00:28:37 -------- d-----w- c:\windows\system32\GroupPolicy
2010-10-13 00:28:29 -------- dc-h--w- c:\windows\$968930Uinstall_KB968930$
2010-10-12 10:00:30 -------- d-----w- c:\docume~1\janice\locals~1\applic~1\Google
2010-10-11 09:01:01 221184 ----a-w- c:\windows\system32\wmpns.dll
2010-10-11 09:00:54 -------- d-----w- c:\program files\Windows Media Connect 2
2010-10-11 08:59:31 -------- d-----w- c:\windows\system32\LogFiles
2010-10-11 08:26:21 -------- d-----w- c:\documents and settings\janice\Tracing
2010-10-11 08:25:15 54760 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys
2010-10-11 08:24:00 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2010-10-11 08:23:56 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2010-10-11 08:22:52 -------- d-----w- c:\program files\Microsoft
2010-10-11 08:22:35 -------- d-----w- c:\program files\Windows Live SkyDrive
2010-10-11 08:21:54 4927864 ----a-w- c:\program files\common files\windows live\.cache\5cc999381cb691d\Silverlight.2.0.exe
2010-10-11 08:16:04 74520 ----a-w- c:\program files\common files\windows live\.cache\8c24af2a1cb691c\DSETUP.dll
2010-10-11 08:16:04 484632 ----a-w- c:\program files\common files\windows live\.cache\8c24af2a1cb691c\DXSETUP.exe
2010-10-11 08:16:04 1670936 ----a-w- c:\program files\common files\windows live\.cache\8c24af2a1cb691c\dsetup32.dll
2010-10-11 08:15:28 1013800 ----a-w- c:\program files\common files\windows live\.cache\76b449de1cb691c\WindowsXP-KB954708-x86-ENU.exe
2010-10-11 08:06:48 -------- d-----w- c:\program files\common files\Windows Live
2010-10-11 07:12:00 -------- d-----w- c:\docume~1\janice\applic~1\ElevatedDiagnostics
2010-10-11 06:55:26 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-10-11 06:55:26 16736 ----a-w- c:\windows\system32\mucltui.dll.mui
2010-10-11 03:43:30 -------- d-----w- c:\docume~1\janice\applic~1\Malwarebytes
2010-10-11 03:43:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-11 03:43:06 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-10-11 03:43:05 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-11 03:43:05 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-11 03:36:56 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-10-11 03:36:56 -------- d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
==================== Find3M ====================
2010-09-18 20:23:26 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53:25 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53:25 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53:25 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-10 05:58:08 916480 ----a-w- c:\windows\system32\wininet.dll
2010-09-10 05:58:06 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:58:06 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-09-01 11:51:14 285824 ----a-w- c:\windows\system32\atmfd.dll
2010-08-31 13:42:52 1852800 ----a-w- c:\windows\system32\win32k.sys
2010-08-30 05:33:08 0 ----a-w- c:\windows\invcol.tmp
2010-08-27 08:02:29 119808 ----a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:57:43 99840 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-26 12:52:45 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-08-23 16:12:04 617472 ----a-w- c:\windows\system32\comctl32.dll
2010-08-17 13:17:06 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:45:00 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-07-17 13:00:04 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-17 10:42:29 73728 ----a-w- c:\windows\system32\javacpl.cpl
============= FINISH: 16:52:12.10 ===============