Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Has Malware got me again?!

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Has Malware got me again?!

Unread postby MadatMalware » July 8th, 2012, 11:37 am

A few days ago I started to get event/error codes which led me to believe one of my hard drives was failing. Got this event several times:
event_code=50 message={Delayed Write Failed}
Windows was unable to save all the data for the file . The data has been lost. This error may be caused by a failure of your computer hardware or network connection. Please try to save this file elsewhere. record_number=51810 resource_name=System risk=High source_name=Ntfs time=1341332969 type=0

Today, when I attempted to update my Malwarebytes Anti-Malware database I got this message-
The Malwarebytes Anti-Malware database is missing or corrupt. Would you like to download a new copy?
---------------------------
Yes No
---------------------------

That's when a red flag went up. I recall this happened the last time I was attacked by Malware, of which your forums helped save me from (very thankful for it). I am hoping I can be saved again if this is a Malware attack or told its not and i truly do have some hardware issues.

One last thing, my eset smart security license ended so there was probably a about 10days i had no virus protection. I just recently installed Bitdefender which i paid for online so i am praying it is legit!

.
DDS (Ver_11-05-19.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.5.1
Run by Administrator at 10:21:46 on 2012-07-08
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2814.1555 [GMT -5:00]
.
AV: Bitdefender Antivirus *Enabled/Updated* {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: Bitdefender Firewall *Enabled*
.
============== Running Processes ===============
.
C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bitdefender\Bitdefender 2013\bdparentalservice.exe
C:\Program Files\Bonjour\mDNSResponder.exe
svchost.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE
C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\vm_sti.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Acronis\DriveMonitor\adm_tray.exe
C:\WINDOWS\system32\ICO.EXE
C:\WINDOWS\system32\FSRremoS.EXE
C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\Pelmiced.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Stardock\CursorFX\CursorFX.exe
C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe
C:\Program Files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe
C:\Program Files\Bitdefender\Bitdefender 2013\BdParentalSysTray.exe
C:\Program Files\WallpaperToy\Wallpapertoy.Exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\Desktop\dds.scr
C:\WINDOWS\system32\WSCRIPT.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com/
mStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\oracle\javafx 2.1 runtime\bin\ssv.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\oracle\javafx 2.1 runtime\bin\jp2ssv.dll
TB: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File
uRun: [CursorFX] "c:\program files\stardock\cursorfx\CursorFX.exe"
uRun: [Google Update] "c:\documents and settings\administrator\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [<NO NAME>]
mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot
mRun: [bigdogpath] c:\windows\vm_sti.EXE DMC Driver
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mRun: [adm_tray.exe] c:\program files\acronis\drivemonitor\adm_tray.exe
mRun: [Mouse Suite 98 Daemon] ICO.EXE
mRun: [Bdagent] c:\program files\bitdefender\bitdefender 2013\bdagent.exe
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\wallpa~1.lnk - c:\program files\wallpapertoy\Wallpapertoy.Exe
LSP: c:\program files\bitdefender\bitdefender 2013\BdProvider.dll
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/produ ... wsdc32.cab
DPF: {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} - hxxp://download.gigabyte.com.tw/object/Dldrv.ocx
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/s ... wflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\administrator\application data\mozilla\firefox\profiles\2shzedxx.default\
FF - prefs.js: browser.search.selectedEngine - Secure Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=mcafee&p=
FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll
FF - component: c:\program files\nokia\nokia ovi suite\connectors\bookmarks connector\firefoxextension\components\FirefoxExtension.dll
FF - plugin: c:\documents and settings\administrator\application

data\mozilla\firefox\profiles\2shzedxx.default\extensions\coralietab@mozdev.org\plugins\npCoralIETab.dll
FF - plugin: c:\documents and settings\administrator\local settings\application data\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\documents and settings\administrator\local settings\application data\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mcafee\siteadvisor\NPMcFFPlg32.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll
FF - plugin: c:\program files\nos\bin\np_gp.dll
FF - plugin: c:\program files\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\virtual earth 3d\npVE3D.dll
.
---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
============= SERVICES / DRIVERS ===============
.
R0 avc3;avc3;c:\windows\system32\drivers\avc3.sys [2012-7-1 611520]
R0 gzflt;gzflt;c:\windows\system32\drivers\gzflt.sys [2012-7-1 154464]
R1 BDVEDISK;BDVEDISK;c:\windows\system32\drivers\bdvedisk.sys [2012-7-1 72704]
R1 CSN5PDTS82;CSN5PDTS82 NDIS Protocol Driver;c:\windows\system32\drivers\CSN5PDTS82.sys [2011-6-27 28184]
R2 BdDesktopParental;Bitdefender Desktop Parental Control;c:\program files\bitdefender\bitdefender 2013\bdparentalservice.exe [2012-7-1 56544]
R2 cpuz132;cpuz132;c:\windows\system32\drivers\cpuz132_x32.sys [2010-3-8 12672]
R2 ES lite Service;ES lite Service for program management.;c:\program files\gigabyte\easysaver\essvr.exe [2009-8-25 68136]
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [2010-7-31 10448]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2009-9-22 654408]
R2 SafeBox;SafeBox;c:\program files\bitdefender\bitdefender safebox\safeboxservice.exe [2012-7-1 82824]
R2 UPDATESRV;Bitdefender Desktop Update Service;c:\program files\bitdefender\bitdefender 2013\updatesrv.exe [2012-7-1 55544]
R3 avchv;avchv Function Driver;c:\windows\system32\drivers\avchv.sys [2012-7-1 240184]
R3 avckf;avckf;c:\windows\system32\drivers\avckf.sys [2012-7-1 447208]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf.sys [2012-7-1 113616]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2009-9-22 22344]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2012-7-8 40776]
R3 RT80x86;Linksys WPC600N/WMP600N Wireless-N Card Driver;c:\windows\system32\drivers\rt2860.sys [2009-12-21 712704]
R3 WJ430A;WJ430A Audio Capture Device Ver3.0;c:\windows\system32\drivers\WJ430A.sys [2009-9-23 9344]
R3 WJ430V;WJ430V Video Capture Device Ver3.0;c:\windows\system32\drivers\WJ430V.sys [2009-9-23 24576]
S1 CSN5PDTS82x64;CSN5PDTS82x64 NDIS Protocol Driver;c:\windows\system32\drivers\csn5pdts82x64.sys --> c:\windows\system32\drivers\CSN5PDTS82x64.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-12-24 136176]
S3 ALSysIO;ALSysIO;\??\c:\docume~1\admini~1\locals~1\temp\alsysio.sys --> c:\docume~1\admini~1\locals~1\temp\ALSysIO.sys [?]
S3 BDSandBox;BDSandBox;c:\windows\system32\drivers\bdsandbox.sys [2012-7-1 63056]
S3 esihdrv;esihdrv;\??\c:\docume~1\admini~1\locals~1\temp\esihdrv.sys --> c:\docume~1\admini~1\locals~1\temp\esihdrv.sys [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-12-24 136176]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\31b8.tmp --> c:\windows\system32\31B8.tmp [?]
S3 sxuptp;SXUPTP Driver;c:\windows\system32\drivers\sxuptp.sys --> c:\windows\system32\drivers\sxuptp.sys [?]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2004-8-4 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S3 ZSMC302;DMC Driver;c:\windows\system32\drivers\usbVM302.sys [2010-7-31 90513]
S4 0044151329353453mcinstcleanup;McAfee Application Installer Cleanup (0044151329353453);c:\windows\temp\004415~1.exe -cleanup -nolog -->

c:\windows\temp\004415~1.EXE -cleanup -nolog [?]
S4 pkHppA;pkHppA;c:\program files\cpuid\pc wizard 2009\data\pcwizntl.exe -s --> c:\program files\cpuid\pc wizard 2009\data\pcwizntl.exe -s [?]
S4 XWtpZC;XWtpZC;c:\program files\cpuid\pc wizard 2010\data\pcwizntl.exe -s --> c:\program files\cpuid\pc wizard 2010\data\pcwizntl.exe -s [?]
.
=============== Created Last 30 ================
.
2012-07-08 14:56:34 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2012-07-01 21:48:45 -------- d-----w- c:\documents and settings\administrator\local settings\application data\kray_zee_kat
2012-07-01 21:44:07 459760 ----a-w- c:\documents and settings\all users\application data\1341178555.bdinstall.bin
2012-07-01 21:40:40 -------- d-----w- c:\documents and settings\all users\application data\BDLogging
2012-07-01 21:40:31 72704 ----a-w- c:\windows\system32\drivers\bdvedisk.sys
2012-07-01 21:40:29 63056 ----a-w- c:\windows\system32\drivers\bdsandbox.sys
2012-07-01 21:40:29 511328 ----a-w- c:\windows\capicom.dll
2012-07-01 21:40:29 113616 ----a-w- c:\windows\system32\drivers\bdfndisf.sys
2012-07-01 21:40:29 -------- d-----w- c:\windows\system32\ui
2012-07-01 21:40:15 611520 ----a-w- c:\windows\system32\drivers\avc3.sys
2012-07-01 21:40:15 447208 ----a-w- c:\windows\system32\drivers\avckf.sys
2012-07-01 21:40:15 240184 ----a-w- c:\windows\system32\drivers\avchv.sys
2012-07-01 21:39:02 -------- d-----w- c:\documents and settings\administrator\application data\Bitdefender
2012-07-01 21:39:00 -------- d-----w- c:\documents and settings\all users\application data\Bitdefender
2012-07-01 21:37:34 -------- d-----w- c:\documents and settings\administrator\application data\QuickScan
2012-07-01 21:36:31 154464 ----a-w- c:\windows\system32\drivers\gzflt.sys
2012-07-01 21:36:28 340624 ----a-w- c:\windows\system32\drivers\trufos.sys
2012-07-01 21:36:28 -------- d-----w- c:\program files\Bitdefender
2012-07-01 21:35:47 -------- d-----w- c:\program files\common files\Bitdefender
2012-06-13 01:01:38 521728 -c----w- c:\windows\system32\dllcache\jsdbgui.dll
2012-06-12 22:37:11 -------- d-----w- c:\documents and settings\administrator\local settings\application data\Sun
2012-06-12 22:36:35 -------- d-----w- c:\program files\Oracle
2012-06-12 22:36:18 772504 ----a-w- c:\windows\system32\npDeployJava1.dll
.
==================== Find3M ====================
.
2012-07-08 13:12:20 16608 ----a-w- c:\windows\gdrv.sys
2012-07-06 06:30:50 24944 ----a-w- c:\windows\system32\drivers\GVTDrv.sys
2012-06-02 20:19:44 22040 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 20:19:38 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 20:19:38 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 20:19:34 15384 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 20:19:30 17944 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 20:18:58 275696 ----a-w- c:\windows\system32\mucltui.dll
2012-06-02 20:18:58 214256 ----a-w- c:\windows\system32\muweb.dll
2012-06-02 20:18:58 17136 ----a-w- c:\windows\system32\mucltui.dll.mui
2012-05-31 13:22:09 599040 ----a-w- c:\windows\system32\crypt32.dll
2012-05-17 12:10:00 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-05-17 12:10:00 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-05-16 15:08:26 916992 ----a-w- c:\windows\system32\wininet.dll
2012-05-15 13:20:33 1863168 ----a-w- c:\windows\system32\win32k.sys
2012-05-11 14:42:33 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-05-11 14:42:33 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38:02 385024 ----a-w- c:\windows\system32\html.iec
2012-05-05 00:29:50 143872 ----a-w- c:\windows\system32\javacpl.cpl
2012-05-05 00:29:16 687504 ----a-w- c:\windows\system32\deployJava1.dll
2012-05-04 13:16:13 2148352 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 12:32:19 2026496 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-02 13:46:36 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
.
============= FINISH: 10:23:42.90 ===========



.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-05-19.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 2009-08-24 16:34:52
System Uptime: 2012-07-08 08:10:33 (2 hours ago)
.
Motherboard: Gigabyte Technology Co., Ltd. | | GA-MA78GM-US2H
Processor: AMD Athlon(tm) 7750 Dual-Core Processor | Socket M2 | 2705/200mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 233 GiB total, 204.594 GiB free.
D: is CDROM ()
E: is FIXED (NTFS) - 19 GiB total, 15.744 GiB free.
F: is FIXED (NTFS) - 18 GiB total, 1.258 GiB free.
G: is FIXED (NTFS) - 18 GiB total, 13.366 GiB free.
H: is FIXED (NTFS) - 18 GiB total, 17.612 GiB free.
I: is Removable
J: is Removable
K: is Removable
L: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC
Device ID: PCI\VEN_10EC&DEV_8168&SUBSYS_E0001458&REV_02\4&36A73F9A&0&0050
Manufacturer: Realtek Semiconductor Corp.
Name: Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC
PNP Device ID: PCI\VEN_10EC&DEV_8168&SUBSYS_E0001458&REV_02\4&36A73F9A&0&0050
Service: RTLE8023xp
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Cisco Systems VPN Adapter
Device ID: ROOT\NET\0000
Manufacturer: Cisco Systems
Name: Cisco Systems VPN Adapter
PNP Device ID: ROOT\NET\0000
Service: CVirtA
.
==== System Restore Points ===================
.
RP355: 2012-04-09 21:00:24 - System Checkpoint
RP356: 2012-04-10 21:52:13 - System Checkpoint
RP357: 2012-04-11 03:00:25 - Software Distribution Service 3.0
RP358: 2012-04-16 14:40:13 - System Checkpoint
RP359: 2012-04-17 15:40:01 - System Checkpoint
RP360: 2012-04-18 15:55:09 - System Checkpoint
RP361: 2012-04-19 16:43:15 - System Checkpoint
RP362: 2012-04-20 16:45:43 - System Checkpoint
RP363: 2012-04-21 16:47:22 - System Checkpoint
RP364: 2012-04-22 16:49:27 - System Checkpoint
RP365: 2012-04-23 17:05:10 - System Checkpoint
RP366: 2012-04-24 17:55:14 - System Checkpoint
RP367: 2012-04-25 17:57:17 - System Checkpoint
RP368: 2012-04-26 17:59:20 - System Checkpoint
RP369: 2012-04-27 18:14:56 - System Checkpoint
RP370: 2012-04-28 19:03:32 - System Checkpoint
RP371: 2012-04-29 19:05:35 - System Checkpoint
RP372: 2012-04-30 19:07:39 - System Checkpoint
RP373: 2012-05-01 19:08:23 - System Checkpoint
RP374: 2012-05-02 19:24:55 - System Checkpoint
RP375: 2012-05-03 20:24:58 - System Checkpoint
RP376: 2012-05-04 21:14:33 - System Checkpoint
RP377: 2012-05-05 22:16:43 - System Checkpoint
RP378: 2012-05-09 02:03:23 - System Checkpoint
RP379: 2012-05-10 02:07:35 - System Checkpoint
RP380: 2012-05-10 03:00:33 - Software Distribution Service 3.0
RP381: 2012-05-11 01:04:37 - Software Distribution Service 3.0
RP382: 2012-05-12 01:54:49 - System Checkpoint
RP383: 2012-05-13 02:43:51 - System Checkpoint
RP384: 2012-05-14 02:46:03 - System Checkpoint
RP385: 2012-05-15 02:48:00 - System Checkpoint
RP386: 2012-05-16 03:12:02 - System Checkpoint
RP387: 2012-05-17 07:00:40 - Removed ESET Smart Security
RP388: 2012-05-18 07:08:13 - System Checkpoint
RP389: 2012-05-19 07:24:49 - System Checkpoint
RP390: 2012-05-20 07:24:54 - System Checkpoint
RP391: 2012-05-21 08:14:32 - System Checkpoint
RP392: 2012-05-22 03:01:19 - Software Distribution Service 3.0
RP393: 2012-05-23 02:33:29 - Software Distribution Service 3.0
RP394: 2012-05-23 03:00:17 - Software Distribution Service 3.0
RP395: 2012-05-24 03:48:11 - System Checkpoint
RP396: 2012-05-25 04:25:39 - System Checkpoint
RP397: 2012-05-26 04:25:49 - System Checkpoint
RP398: 2012-05-27 04:36:21 - System Checkpoint
RP399: 2012-05-28 04:44:28 - System Checkpoint
RP400: 2012-05-29 05:33:17 - System Checkpoint
RP401: 2012-05-30 05:55:53 - System Checkpoint
RP402: 2012-05-31 06:36:53 - System Checkpoint
RP403: 2012-06-01 06:38:54 - System Checkpoint
RP404: 2012-06-02 06:55:01 - System Checkpoint
RP405: 2012-06-03 07:43:10 - System Checkpoint
RP406: 2012-06-04 07:45:20 - System Checkpoint
RP407: 2012-06-05 03:02:20 - Software Distribution Service 3.0
RP408: 2012-06-06 03:23:37 - System Checkpoint
RP409: 2012-06-07 03:24:11 - System Checkpoint
RP410: 2012-06-08 03:25:42 - System Checkpoint
RP411: 2012-06-09 03:28:11 - System Checkpoint
RP412: 2012-06-10 03:29:56 - System Checkpoint
RP413: 2012-06-11 03:44:59 - System Checkpoint
RP414: 2012-06-12 04:34:06 - System Checkpoint
RP415: 2012-06-12 17:35:42 - Installed Java(TM) 7 Update 5
RP416: 2012-06-12 17:36:32 - Installed JavaFX 2.1.1
RP417: 2012-06-13 03:00:20 - Software Distribution Service 3.0
RP418: 2012-06-14 03:46:00 - System Checkpoint
RP419: 2012-06-15 04:05:39 - System Checkpoint
RP420: 2012-06-16 05:09:41 - System Checkpoint
RP421: 2012-06-17 05:59:56 - System Checkpoint
RP422: 2012-06-18 06:15:04 - System Checkpoint
RP423: 2012-06-19 07:04:14 - System Checkpoint
RP424: 2012-06-20 07:07:13 - System Checkpoint
RP425: 2012-06-21 07:08:42 - System Checkpoint
RP426: 2012-06-22 08:24:52 - System Checkpoint
RP427: 2012-06-23 09:12:56 - System Checkpoint
RP428: 2012-06-24 09:15:02 - System Checkpoint
RP429: 2012-06-25 09:25:41 - System Checkpoint
RP430: 2012-06-26 09:34:46 - System Checkpoint
RP431: 2012-06-27 10:23:10 - System Checkpoint
RP432: 2012-06-28 10:25:39 - System Checkpoint
RP433: 2012-06-29 10:26:34 - System Checkpoint
RP434: 2012-06-30 10:28:43 - System Checkpoint
RP435: 2012-07-01 10:44:55 - System Checkpoint
RP436: 2012-07-01 16:23:45 - Removed ESET Smart Security
RP437: 2012-07-01 16:57:59 - Software Distribution Service 3.0
RP438: 2012-07-02 21:06:10 - System Checkpoint
RP439: 2012-07-06 00:51:51 - System Checkpoint
RP440: 2012-07-07 09:41:32 - System Checkpoint
RP441: 2012-07-08 08:59:50 - System Checkpoint
.
==== Installed Programs ======================
.
@BIOS Ver.2.04
Acrobat.com
Acronis Drive Monitor
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.3)
Adobe Shockwave Player 11.6
Adobe SVG Viewer 3.0
AiO_Scan_CDA
AiOSoftwareNPI
AMD Processor Driver
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ArcSoft PhotoStudio 5.5
ATI Catalyst Install Manager
Backup Magic
Bing Maps 3D
Bitdefender Total Security 2013
Bonjour
Browser Configuration Utility
BufferChm
C4100
c4100_Help
Canon CanoScan LiDE 200 User Registration
Canon MP Navigator EX 2.0
Canon Utilities Solution Menu
CanoScan LiDE 200 Scanner Driver
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center HydraVision Full
Catalyst Control Center Localization All
ccc-core-preinstall
ccc-core-static
ccc-utility
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help English
CCC Help Japanese
CCC Help Korean
CCC Help Thai
CCleaner
CDBurnerXP
Cisco Systems VPN Client 5.0.04.0300
Colasoft Capsa 7 Free
ColorPic
Core Temp version 0.99.8
CP_CalendarTemplates1
cp_OnlineProjectsConfig
CP_Package_Basic1
CP_Panorama1Config
cp_PosterPrintConfig
CPUID CPU-Z 1.53.1
CueTour
CursorFX
Destinations
DeviceManagementQFolder
Disk Space Fan 1.4.2.796
DiskCheckup V2.1
DMIView B8.0717.01
DocProc
DocProcQFolder
DocumentViewer
DocumentViewerQFolder
doPDF 6.3 printer
Download Updater (AOL LLC)
Easy Tune 6 B08.1212.1
EasySaver B8.1208.1
eReg
ERUNT 1.1j
eSupportQFolder
Extra Photo SlideShow Free 7.07
Face_Wizard B08.0908.01
Fax_CDA
Firefox Preloader
foobar2000 v1.0.3
Free Nokia Ringtone Converter 1.1
FullDPAppQFolder
GhostBuster
Google Chrome
Google Earth Plug-in
Google Update Helper
HiJackThis
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Document Viewer 7.0
HP Imaging Device Functions 7.0
HP Photosmart Essential
HP Photosmart Premier Software 6.5
HP Photosmart, Officejet and Deskjet 7.0.A
HP Software Update
HP Solution Center 7.0
HPPhotoSmartExpress
HPProductAssistant
IconViewer
ImTOO DVD Ripper Platinum 6
InstantShareDevices
InstantShareDevicesMFC
iTunes
Java Auto Updater
Java(TM) 6 Update 29
Java(TM) 7 Update 5
JavaFX 2.1.1
Kensington SlimBlade Driver
LEGO Digital Designer
Lorex mCam
Malwarebytes Anti-Malware version 1.61.0.1400
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2656353)
Microsoft .NET Framework 1.1 Security Update (KB2656370)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Color Control Panel Applet for Windows XP
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 12
Microsoft USB Flash Drive Manager
Microsoft User-Mode Driver Framework Feature Pack 1.7
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft_VC100_CRT_SP1_x86
Minilyrics(remove only)
MobileMe Control Panel
Mozilla Firefox 7.0.1 (x86 en-US)
MSVC80_x86
MSVC80_x86_v2
MSVC90_x86
MSXML 4.0 SP2 (KB954430)
MSXML 6 Service Pack 2 (KB954459)
NewCopy_CDA
Nikon Message Center
Nikon RAW Codec
Nikon Transfer
Nokia Connectivity Cable Driver
Nokia Ovi Player
Nokia PC Suite
Nokia Software Updater
Nokia Suite
Nokia_Multimedia_Common_Components_2_5
OCR Software by I.R.I.S 7.0
PanoStandAlone
PC Connectivity Solution
PC Wizard 2009.1.90
PC Wizard 2010.1.93
Photo Story 3 for Windows
PhotoGallery
Picture Control Utility
ProductContextNPI
QuickTime
RandMap
Readme
REALTEK GbE & FE Ethernet PCI-E NIC Driver
Realtek High Definition Audio Driver
RSA SecurID Software Token
Scan
ScannerCopy
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596880) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597162) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2598041) 32-Bit Edition
Security Update for Microsoft Office Excel 2007 (KB2597161) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition
Security Update for Microsoft Office Word 2007 (KB2596917) 32-Bit Edition
Security Update for Windows Internet Explorer 8 (KB2183461)
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB2416400)
Security Update for Windows Internet Explorer 8 (KB2482017)
Security Update for Windows Internet Explorer 8 (KB2497640)
Security Update for Windows Internet Explorer 8 (KB2510531)
Security Update for Windows Internet Explorer 8 (KB2530548)
Security Update for Windows Internet Explorer 8 (KB2544521)
Security Update for Windows Internet Explorer 8 (KB2559049)
Security Update for Windows Internet Explorer 8 (KB2586448)
Security Update for Windows Internet Explorer 8 (KB2618444)
Security Update for Windows Internet Explorer 8 (KB2647516)
Security Update for Windows Internet Explorer 8 (KB2675157)
Security Update for Windows Internet Explorer 8 (KB2699988)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
SkinsHP1
SlideShow
SnagIt 7
SolutionCenter
Sonic_PrimoSDK
Sophos Anti-Rootkit 1.5.4
SpeedFan (remove only)
SpywareBlaster 4.6
Status
swMSM
System Requirements Lab
TaxACT 2008
The Lord of the Rings FREE Trial
ThreatExpert Memory Scanner 1.0
Toolbox
TrayApp
Tweak UI
Unity Web Player
Unity Web Player (All users)
Unknown Device Identifier 6.01
Unload
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2687267) 32-Bit Edition
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Update for Windows Internet Explorer 8 (KB2362765)
Update for Windows Internet Explorer 8 (KB2447568)
Update for Windows Internet Explorer 8 (KB2598845)
Update for Windows Internet Explorer 8 (KB2632503)
Update for Windows Internet Explorer 8 (KB975364)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows Internet Explorer 8 (KB980302)
Update for Windows Internet Explorer 8 (KB982632)
VC 9.0 Runtime
ViewNX
VLC media player 2.0.1
VoiceOver Kit
Wallpaper Changer for Windows XP
WD Diagnostics
WebFldrs XP
WebReg
Winamp
Winamp Detector Plug-in
Winamp Essentials Pack
Windows Driver Package - Nokia Modem (06/01/2009 4.1)
Windows Driver Package - Nokia Modem (06/01/2009 7.01.0.3)
Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Imaging Component
Windows Management Framework Core
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WinPatrol
WinRAR archiver
.
==== Event Viewer Messages From Past Week ========
.
2012-07-06 02:24:51, error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume C:.
2012-07-03 01:22:03, error: Disk [11] - The driver detected a controller error on \Device\Harddisk2\D.
2012-07-02 19:12:21, error: Dhcp [1002] - The IP address lease 192.168.2.8 for the Network Card with network address 00259CB37ECD has been denied by the DHCP server 192.168.2.1 (The DHCP Server sent a DHCPNACK message).
2012-07-01 12:26:03, error: Disk [11] - The driver detected a controller error on \Device\Harddisk3\D.
.
==== End Of File ===========================
MadatMalware
Regular Member
 
Posts: 16
Joined: April 7th, 2011, 3:02 pm
Advertisement
Register to Remove

Re: Has Malware got me again?!

Unread postby deltalima » July 8th, 2012, 12:00 pm

User avatar
deltalima
Admin/Teacher
Admin/Teacher
 
Posts: 7614
Joined: February 28th, 2009, 4:38 pm
Location: UK


  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 27 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware