Malware and Virus RemovalProblems removing malware/viruses? Get help from our Malware removal experts.
Mission Statement
WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.
Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-12-01.01)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 31/07/2006 4:54:09 PM
System Uptime: 1/04/2010 7:02:44 AM (-2087 hours ago)
RP754: 6/11/2009 11:20:51 AM - Installed Uniblue DriverScanner v1.0
RP755: 6/11/2009 1:59:16 PM - Software Distribution Service 3.0
RP756: 7/11/2009 4:30:43 PM - System Checkpoint
RP757: 8/11/2009 6:14:00 AM - Installed Java(TM) 6 Update 17
RP758: 9/11/2009 11:50:59 AM - System Checkpoint
RP759: 11/11/2009 1:06:55 PM - System Checkpoint
RP760: 12/11/2009 3:00:31 AM - Software Distribution Service 3.0
RP761: 13/11/2009 6:40:34 AM - System Checkpoint
RP762: 14/11/2009 3:00:31 AM - Software Distribution Service 3.0
RP763: 15/11/2009 7:19:17 AM - System Checkpoint
RP764: 15/11/2009 6:12:15 AM - System Checkpoint
RP765: 16/11/2009 6:37:29 AM - System Checkpoint
RP766: 1/01/2005 12:59:23 AM - System Checkpoint
RP767: 2/01/2005 4:22:10 AM - System Checkpoint
RP768: 19/11/2005 9:58:08 PM - Installed Windows Internet Explorer 8.
RP769: 19/11/2009 12:25:49 PM - System Checkpoint
RP770: 20/11/2009 1:22:48 PM - System Checkpoint
RP771: 21/11/2009 5:47:38 PM - System Checkpoint
RP772: 22/11/2009 7:05:35 PM - System Checkpoint
RP773: 23/11/2009 7:59:10 PM - System Checkpoint
RP774: 25/11/2009 6:42:54 AM - System Checkpoint
RP775: 25/11/2009 8:18:02 PM - Software Distribution Service 3.0
RP776: 27/11/2009 6:47:12 AM - System Checkpoint
RP777: 28/11/2009 8:23:07 AM - System Checkpoint
RP778: 29/11/2009 10:08:58 AM - System Checkpoint
RP779: 30/11/2009 10:47:02 PM - System Checkpoint
RP780: 2/12/2009 6:30:18 AM - System Checkpoint
RP781: 3/12/2009 1:57:48 PM - System Checkpoint
RP782: 4/12/2009 2:26:05 PM - System Checkpoint
RP783: 5/12/2009 2:44:55 PM - System Checkpoint
RP784: 6/12/2009 4:47:35 PM - System Checkpoint
RP785: 7/12/2009 4:50:59 PM - System Checkpoint
RP786: 8/12/2009 4:56:01 PM - System Checkpoint
RP787: 9/12/2009 5:23:17 PM - System Checkpoint
RP788: 10/12/2009 3:00:49 AM - Software Distribution Service 3.0
RP789: 11/12/2009 5:37:04 AM - System Checkpoint
RP790: 12/12/2009 8:13:47 AM - System Checkpoint
RP791: 13/12/2009 9:23:39 AM - System Checkpoint
RP792: 14/12/2009 10:07:45 AM - System Checkpoint
RP793: 15/12/2009 3:00:42 AM - Software Distribution Service 3.0
RP794: 16/12/2009 6:33:08 AM - System Checkpoint
RP795: 17/12/2009 7:17:10 AM - System Checkpoint
RP796: 18/12/2009 2:42:40 PM - System Checkpoint
RP797: 19/12/2009 3:25:31 PM - System Checkpoint
RP798: 20/12/2009 4:25:11 PM - System Checkpoint
RP799: 21/12/2009 5:10:56 PM - System Checkpoint
RP800: 22/12/2009 5:29:50 PM - System Checkpoint
RP801: 23/12/2009 8:32:44 PM - System Checkpoint
RP802: 25/12/2009 9:25:58 AM - System Checkpoint
RP803: 26/12/2009 9:49:28 AM - System Checkpoint
RP804: 27/12/2009 10:58:18 AM - System Checkpoint
RP805: 28/12/2009 1:07:48 PM - System Checkpoint
RP806: 29/12/2009 1:59:45 PM - System Checkpoint
RP807: 30/12/2009 2:07:12 PM - System Checkpoint
RP808: 31/12/2009 2:07:39 PM - System Checkpoint
RP809: 1/01/2010 2:38:48 PM - System Checkpoint
RP810: 2/01/2010 4:00:13 PM - System Checkpoint
RP811: 4/01/2010 6:57:12 AM - Software Distribution Service 3.0
==== Installed Programs ======================
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 8.1.2
Adobe Shockwave Player 11
Adobe® Photoshop® Album Starter Edition 3.0
Agere Systems PCI Soft Modem
µTorrent
Auslogics Disk Defrag
Brother MFL-Pro Suite
ccCommon
Crawler Toolbar
DVD Shrink 3.2
Fast Browser Search (My Web Tattoo)
FUJIFILM FinePixViewer S Ver.2.1
Home Media Server 4.0.0.0072
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB954708)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Imikimi Plugin
Inca Ball
J2SE Runtime Environment 5.0 Update 6
Java(TM) 6 Update 17
Java(TM) 6 Update 5
Junk Mail filter update
LimeWire 5.4.6
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Search Enhancement Pack
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
MSVCRT
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6.0 Parser (KB933579)
Multimedia Samples
Nero BurnRights
Nero Suite
Network Play System (Patching)
Norton AntiVirus 2006 (Symantec Corporation)
Norton Protection Center
OLYMPUS CAMEDIA Master 4.2
Optus Internet Security Suite 2009
Pando Media Booster
PaperPort
PowerDVD
QuickTime
Realtek AC'97 Audio
RegCure
SAGEM F@st 1201
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371-v2)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Segoe UI
Shockwave
SiS VGA Utilities
SIW version 2009.10.22
The Game Of Life
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB975364)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
USB PC Camera Plus
USB Remote NDIS Network Device
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Imaging Component
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Toolbar
Windows Live Upload Tool
Windows Live Writer
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
==== Event Viewer Messages From Past Week ========
31/12/2009 5:02:36 AM, error: Dhcp [1002] - The IP address lease 10.1.1.2 for the Network Card with network address 002569E32948 has been denied by the DHCP server 10.1.1.1 (The DHCP Server sent a DHCPNACK message).
30/12/2009 8:42:35 AM, error: F-Secure Gatekeeper [1] -
28/12/2009 6:56:08 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service.
1/01/2010 12:30:31 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the wscsvc service.
==== End Of File ===========================
Didn't find the information you thought to find? Check out these Similar Threads
DDS (Ver_09-12-01.01) - NTFSx86
Run by adam_missa_mia at 7:59:38.12 on Mon 04/01/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.61.1033.18.479.91 [GMT 10:00]
AV: Optus Internet Security Suite 2009 8.00 *On-access scanning enabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: Optus Internet Security Suite 2009 8.00 *enabled* {D4747503-0346-49EB-9262-997542F79BF4}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Optus Internet Security Suite\Anti-Virus\fsgk32st.exe
C:\Program Files\Optus Internet Security Suite\Common\FSMA32.EXE
C:\Program Files\Optus Internet Security Suite\Anti-Virus\FSGK32.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Optus Internet Security Suite\Common\FSMB32.EXE
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Optus Internet Security Suite\Common\FCH32.EXE
C:\Program Files\Optus Internet Security Suite\Anti-Virus\fsqh.exe
C:\Program Files\Optus Internet Security Suite\Common\FAMEH32.EXE
C:\Program Files\Optus Internet Security Suite\FSPC\fspc.exe
C:\Program Files\Optus Internet Security Suite\FWES\Program\fsdfwd.exe
C:\Program Files\Optus Internet Security Suite\Anti-Virus\fssm32.exe
C:\Program Files\Optus Internet Security Suite\FSAUA\program\fsaua.exe
C:\Program Files\Optus Internet Security Suite\FSAUA\program\fsus.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\RegCure\RegCure.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\vsnpstd3.exe
C:\Program Files\Optus Internet Security Suite\Common\FSM32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Pando Networks\Media Booster\PMB.exe
C:\Program Files\FinePixViewerS\QuickDCF2.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\Optus Internet Security Suite\FSGUI\fsguidll.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Optus Internet Security Suite\Anti-Virus\fsav32.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\SECURI~1\NSCSRVCE.EXE
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\PROGRA~1\Crawler\CToolbar.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Optus Internet Security Suite\FSGUI\scanwizard.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Documents and Settings\adam_missa_mia\Local Settings\Temporary Internet Files\Content.IE5\RBHN0EMG\dds[1].scr
NOTE. If any of the programs listed below refuse to run, try renaming executive file to something else; for instance, rename hijackthis.exe to scanner.exe
***VERY IMPORTANT! Make sure, you update Superantispyware, and Malwarebytes before running the scans.***
* Double-click SUPERAntiSpyware.exe and use the default settings for installation.
* An icon will be created on your desktop. Double-click that icon to launch the program.
* If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
* Close SUPERAntiSpyware.
PHYSICALLY DISCONNECT FROM THE INTERNET
Restart computer in Safe Mode. To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen
* Open SUPERAntiSpyware.
* Click Scan your Computer... button.
* Click Scanning Preferences/Control Center... button.
* Under General and Startup tab, make sure, Start SUPERAntiSpyware when Windows starts option is UN-checked.
* Click the Scanning Control tab.
* Under Scanner Options make sure the following are checked (leave all others unchecked):
Close browsers before scanning.
Terminate memory threats before quarantining.
* Click the Close button to leave the control center screen.
* On the left, make sure you check C:\Fixed Drive.
* On the right, choose Perform Complete Scan.
* Click Next to start the scan. Please be patient while it scans your computer.
* After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click OK.
* Make sure everything has a checkmark next to it and click Next.
* A notification will appear that Quarantine and Removal is Complete. Click OK and then click the Finish button to return to the main menu.
* If asked if you want to reboot, click Yes.
* To retrieve the removal information after reboot, launch SUPERAntispyware again.
Click Preferences, then click the Statistics/Logs tab.
Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
Please copy and paste the Scan Log results in your next reply.
* Click Close to exit the program. Post SUPERAntiSpyware log.
RECONNECT TO THE INTERNET
RESTART COMPUTER!
STEP 2. Download Malwarebytes' Anti-Malware: http://www.malwarebytes.org/mbam.php to your desktop. (Malwarebytes is free to use as a manual scanner. Payment is only required if you wish to have it run and update automatically which is not necessary for our purposes)
* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.
The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
STEP 4. Download HijackThis: http://www.trendsecure.com/portal/en...kthis/download
by clicking on Installer under Version 2.0.2
[DO NOT download version 2.0.3 (beta)]
Install, and run it. Post HijackThis log. NOTE. If you're using Vista, right click on HijackThis, and click Run as Administrator
Do NOT attempt to "fix" anything!
DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!