This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Chkdsk CHKDSK: File System is RAW issue led me to find virus PRAGMASER

44 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Good Morning,

For some months now I have been unable to perform system tasks like Chkdsk, when it tries to run I receive the error message that Chkdsk cannot run as the drive is RAW.

I had tried to find a resolution to this issue a while back with no success, today I decided to try again.

Whilst searching I came across post 17 in this topic on another site;

http://www.computing.net/answers/windows-x…run/178636.html

The guy seemed to know what was going on so I began to follow his instructions, I was on step 3 of his instruction;

3. Run RootRepeal
go to tab Files, press Scan (mark C if your OS is installed on it)
go to tab Hidden Services, press Scan


When I was continuing to research the problem, I came across your site and was quite frankly stunned by the support that you give here. Whilst reading through a post where support was given it was advised not to do anything before getting help. Therefore I let the scan complete but did not action any further on the linked instructions.

Instead I followed your advice on how to start up a topic here and downloaded OTL, I have run the scans as requested and the two reports I will post below.

One other thing to note is that when the Rootrepeal scan took place it identified quite a few files in various directories which all started with PRAGMA (apparently a back-door trojan). But also identified a massive amount (several hundred to a thousand) of files under Opera Cache, then eventually brought up an error message saying it was unable to access the next files. With regards to Opera, whenever I run it I get an error pop up saying that the cache is corrupt and that I should run Chkdsk, come to think about it I believe that is when I first found the problem with being unable to run Chkdsk.


Many thanks for any support or assistance you can give me, the two Txt files from OTL are here;

OTL.txt;

OTL logfile created on: 12/03/2011 08:58:04 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\DLL\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,014.00 Mb Total Physical Memory | 476.00 Mb Available Physical Memory | 47.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 4000 4000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.24 Gb Total Space | 5.82 Gb Free Space | 15.62% Space Free | Partition Type: NTFS
Drive D: | 207.75 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 279.39 Gb Total Space | 197.42 Gb Free Space | 70.66% Space Free | Partition Type: FAT32

Computer Name: DLL-54B15EFAE11 | User Name: DLL | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\DLL\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Opera\opera.exe (Opera Software)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgfws9.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\DLL\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (avgfws9) – C:\Program Files\AVG\AVG9\avgfws9.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9emc) – C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)


========== Driver Services (SafeList) ==========

DRV - (EterlogicVirtualSerialDriver) – C:\WINDOWS\system32\drivers\VSPE.sys ()
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSDriverxpx) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilterxpx) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShimxpx) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSErHrxpx) – C:\WINDOWS\System32\Drivers\AVGIDSxx.sys (AVG Technologies CZ, s.r.o. )
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (atapi) – C:\WINDOWS\system32\DRIVERS\atapi.sys ()
DRV - (AvgRkx86) – C:\WINDOWS\System32\Drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (mcdbus) – C:\WINDOWS\system32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (FilterService) – C:\WINDOWS\system32\drivers\lvuvcflt.sys (Logitech Inc.)
DRV - (LVUVC) Logitech QuickCam E3500(UVC) – C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (LVRS) – C:\WINDOWS\system32\drivers\lvrs.sys (Logitech Inc.)
DRV - (LVPr2Mon) – C:\WINDOWS\system32\drivers\LVPr2Mon.sys ()
DRV - (MusCAudio) – C:\WINDOWS\system32\drivers\MusCAudio.sys (Windows ® Codename Longhorn DDK provider)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (senfilt) – C:\WINDOWS\system32\drivers\senfilt.sys (Creative Technology Ltd.)
DRV - (Avgfwfd) – C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgfwdx) – C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\..\URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..browser.search.defaulturl: "http://www.bing.com/search?FORM=IEFM1&q;="
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.order.2: "Google"
FF - prefs.js..browser.search.selectedEngine: "Yahoo! Search"
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.4
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.2.20100119091315
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:[removed]
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.872
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.2
FF - prefs.js..keyword.URL: "http://uk.yhs.search.yahoo.com/avg/search?fr=yhs-avgb&type;=yahoo_avg_hs2-tb-web_uk&p;="
FF - prefs.js..network.proxy.type: 0


FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/12/09 13:45:55 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/11 22:28:52 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/02 19:44:46 | 000,000,000 | —D | M]

[2008/12/24 10:10:15 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\DLL\Application Data\Mozilla\Extensions
[2011/03/09 08:57:46 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\DLL\Application Data\Mozilla\Firefox\Profiles\vy1f2mhv.default\extensions
[2010/04/28 21:22:05 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\DLL\Application Data\Mozilla\Firefox\Profiles\vy1f2mhv.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/01/15 11:11:31 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\DLL\Application Data\Mozilla\Firefox\Profiles\vy1f2mhv.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2004/09/16 23:10:52 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\DLL\Application Data\Mozilla\Firefox\Profiles\vy1f2mhv.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}(2)
[2010/02/17 13:36:26 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\DLL\Application Data\Mozilla\Firefox\Profiles\vy1f2mhv.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/01/27 09:19:41 | 000,000,000 | —D | M] (Zynga Toolbar) – C:\Documents and Settings\DLL\Application Data\Mozilla\Firefox\Profiles\vy1f2mhv.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2010/04/11 22:52:21 | 000,000,000 | —D | M] ("Tab Mix Plus") – C:\Documents and Settings\DLL\Application Data\Mozilla\Firefox\Profiles\vy1f2mhv.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2010/01/20 17:01:56 | 000,002,171 | —- | M] () – C:\Documents and Settings\DLL\Application Data\Mozilla\Firefox\Profiles\vy1f2mhv.default\searchplugins\bing.xml
[2011/03/09 08:57:46 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/12/09 13:45:55 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES\AVG\AVG9\FIREFOX
[2010/04/10 05:44:25 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2009/02/24 08:08:43 | 000,000,000 | —D | M] (Veoh Web Player Video Finder) – C:\PROGRAM FILES\VEOH NETWORKS\VEOHWEBPLAYER\FFVIDEOFINDER
[2010/07/19 23:03:28 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/07/19 23:03:28 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/07/19 23:03:28 | 000,000,769 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/07/19 23:03:28 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2010/09/18 05:22:27 | 000,419,441 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 14476 more lines…
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - File not found
O3 - HKLM\..\Toolbar: (Veoh Web Player Video Finder) - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll (Veoh Networks Inc)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - File not found
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [none] c:\AUTOEXEC.BAT ()
O4 - HKCU..\Run: [EA Core] File not found
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Documents and Settings\DLL\Start Menu\Programs\Startup\MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
O4 - Startup: C:\Documents and Settings\DLL\Start Menu\Programs\Startup\Registration THE SETTLERS - Heritage of Kings.LNK = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper: C:\Documents and Settings\DLL\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/02/18 23:53:20 | 000,000,057 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2008/01/04 09:41:54 | 000,000,042 | R— | M] () - D:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{a1e68053-c6e5-11dd-929e-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{a1e68053-c6e5-11dd-929e-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{a1e68053-c6e5-11dd-929e-806d6172696f}\Shell\AutoRun\command - "" = D:\setup.exe – [2009/11/06 14:15:00 | 103,443,887 | R— | M] ()
O34 - HKLM BootExecute: (autocheck autochk /r \??\C:) - File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = secfile] – "C:\Documents and Settings\NetworkService\Local Settings\Application Data\ave.exe" /START "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.I420 - C:\WINDOWS\System32\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.VP60 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2011/03/12 08:55:17 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\DLL\Desktop\OTL.exe
[2011/03/12 08:34:13 | 000,472,064 | —- | C] ( ) – C:\Documents and Settings\DLL\Desktop\RootRepeal.exe
[2011/03/12 08:32:49 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/03/12 08:32:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/03/12 08:32:42 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/03/12 08:32:42 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/03/12 08:32:03 | 007,734,240 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\DLL\Desktop\mbam-setup.exe
[2011/03/11 00:28:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Gogii
[2011/03/11 00:26:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Trapped The Abduction
[2011/03/11 00:25:47 | 000,000,000 | —D | C] – C:\WINDOWS\Trapped The Abduction
[2011/03/11 00:25:47 | 000,000,000 | —D | C] – C:\Program Files\Trapped The Abduction
[2011/03/09 21:55:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Aspyr Media
[2011/03/09 21:39:38 | 000,000,000 | —D | C] – C:\Program Files\Aspyr
[2011/03/07 20:46:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Maxis
[2011/03/07 20:45:00 | 000,000,000 | —D | C] – C:\Program Files\Maxis
[2011/03/07 20:44:50 | 000,305,152 | —- | C] (InstallShield Software Corporation) – C:\WINDOWS\IsUn0419.exe
[2011/03/07 20:31:11 | 000,000,000 | —D | C] – C:\Documents and Settings\DLL\Start Menu\Programs\MagicDisc
[2011/03/07 20:30:59 | 000,116,736 | —- | C] (MagicISO, Inc.) – C:\WINDOWS\System32\drivers\mcdbus.sys
[2011/03/07 20:30:59 | 000,000,000 | —D | C] – C:\Program Files\MagicDisc
[2011/03/07 20:28:19 | 000,000,000 | —D | C] – C:\Documents and Settings\DLL\Start Menu\Programs\MagicISO
[2011/03/07 20:28:18 | 000,000,000 | —D | C] – C:\Program Files\MagicISO
[2011/03/07 05:19:29 | 000,000,000 | —D | C] – C:\Program Files\MouseEmulator
[2011/03/07 05:19:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\MouseEmulator
[2011/03/07 05:05:57 | 000,000,000 | —D | C] – C:\Documents and Settings\DLL\Start Menu\Programs\Virtual Serial Ports Emulator
[2011/03/07 05:05:54 | 000,000,000 | —D | C] – C:\Program Files\Eterlogic.com
[2011/03/07 04:53:57 | 000,000,000 | —D | C] – C:\Documents and Settings\DLL\My Documents\My eBooks
[2011/03/07 04:53:37 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2011/03/05 04:13:06 | 000,000,000 | —D | C] – C:\BLUEBYTE
[2011/03/02 19:44:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\PrintMe Internet Printing
[2011/03/02 19:44:39 | 000,000,000 | —D | C] – C:\Program Files\Adobe
[2011/03/02 19:38:50 | 000,000,000 | —D | C] – C:\WINDOWS\Cache
[2011/02/27 21:07:18 | 000,000,000 | —D | C] – C:\Documents and Settings\DLL\WINDOWS
[2011/02/27 21:04:23 | 000,000,000 | —D | C] – C:\Documents and Settings\DLL\My Documents\Downloads
[2011/02/27 21:04:22 | 000,000,000 | —D | C] – C:\Documents and Settings\DLL\Application Data\GetRightToGo
[2011/02/27 20:47:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\OldGames.sk
[2011/02/27 20:47:43 | 000,000,000 | —D | C] – C:\Program Files\Oldgames
[2011/02/27 01:45:19 | 000,000,000 | —D | C] – C:\Documents and Settings\DLL\Local Settings\Application Data\DOSBox
[2011/02/27 01:43:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\DOSBox-0.74
[2011/02/27 00:39:17 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{8A4124D0-6AF6-4584-A7BF-4CDFECF4B129}
[2011/02/27 00:38:44 | 000,000,000 | —D | C] – C:\Documents and Settings\DLL\Local Settings\Application Data\PackageAware
[2011/02/22 17:48:10 | 000,000,000 | —D | C] – C:\Documents and Settings\DLL\My Documents\Jonny
[2011/02/13 12:26:22 | 000,000,000 | —D | C] – C:\Documents and Settings\DLL\My Documents\My Received Files
[2011/02/10 21:02:05 | 000,000,000 | —D | C] – C:\Documents and Settings\DLL\Application Data\.minecraft
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/03/12 08:55:17 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\DLL\Desktop\OTL.exe
[2011/03/12 08:34:18 | 000,000,000 | —- | M] () – C:\Documents and Settings\DLL\Desktop\settings.dat
[2011/03/12 08:33:22 | 000,465,298 | —- | M] () – C:\Documents and Settings\DLL\Desktop\RootRepeal.rar
[2011/03/12 08:32:49 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/12 08:32:11 | 007,734,240 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\DLL\Desktop\mbam-setup.exe
[2011/03/12 08:11:09 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/03/12 08:10:18 | 000,000,280 | —- | M] () – C:\WINDOWS\tasks\iMeshNAG.job
[2011/03/12 08:10:17 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/03/11 09:55:01 | 000,000,724 | —- | M] () – C:\WINDOWS\tasks\03 Today.job
[2011/03/09 21:55:56 | 000,000,735 | —- | M] () – C:\Documents and Settings\DLL\Desktop\1701 A.D..lnk
[2011/03/09 03:10:19 | 000,001,391 | —- | M] () – C:\Documents and Settings\DLL\Start Menu\Programs\Startup\Registration THE SETTLERS - Heritage of Kings.LNK
[2011/03/09 03:03:43 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/03/09 03:03:35 | 000,000,219 | —- | M] () – C:\WINDOWS\System32\MRT.INI
[2011/03/07 20:31:11 | 000,000,652 | —- | M] () – C:\Documents and Settings\DLL\Start Menu\Programs\Startup\MagicDisc.lnk
[2011/03/07 05:05:56 | 000,025,984 | —- | M] () – C:\WINDOWS\System32\drivers\VSPE.sys
[2011/03/06 19:04:00 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\lvuvc.hs
[2011/03/06 19:03:56 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\logiflt.iad
[2011/02/27 11:19:14 | 071,823,095 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2011/02/25 00:07:00 | 000,000,000 | —- | M] () – C:\Documents and Settings\DLL\Local Settings\Application Data\prvlcl.dat
[2011/02/23 21:56:56 | 000,646,492 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\iavifw.avm
[2011/02/16 04:53:57 | 000,061,440 | —- | M] () – C:\Documents and Settings\DLL\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/03/12 08:34:18 | 000,000,000 | —- | C] () – C:\Documents and Settings\DLL\Desktop\settings.dat
[2011/03/12 08:33:21 | 000,465,298 | —- | C] () – C:\Documents and Settings\DLL\Desktop\RootRepeal.rar
[2011/03/12 08:32:49 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/09 21:55:56 | 000,000,735 | —- | C] () – C:\Documents and Settings\DLL\Desktop\1701 A.D..lnk
[2011/03/09 03:10:19 | 000,001,391 | —- | C] () – C:\Documents and Settings\DLL\Start Menu\Programs\Startup\Registration THE SETTLERS - Heritage of Kings.LNK
[2011/03/07 21:04:11 | 000,000,280 | —- | C] () – C:\WINDOWS\tasks\iMeshNAG.job
[2011/03/07 20:31:11 | 000,000,652 | —- | C] () – C:\Documents and Settings\DLL\Start Menu\Programs\Startup\MagicDisc.lnk
[2011/03/07 05:05:56 | 000,025,984 | —- | C] () – C:\WINDOWS\System32\drivers\VSPE.sys
[2011/03/02 19:44:47 | 000,002,377 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader 6.0.lnk
[2010/05/26 06:45:15 | 000,000,088 | RHS- | C] () – C:\Documents and Settings\All Users\Application Data\6ACA2FD747.sys
[2010/05/26 06:45:14 | 000,002,516 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys
[2010/05/02 08:39:01 | 000,015,786 | -HS- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\1947251409
[2010/05/02 08:39:01 | 000,015,786 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\1947251409
[2010/04/28 13:53:30 | 000,001,634 | -HS- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\8rMjiIiS5Lohx
[2010/04/28 13:53:30 | 000,001,634 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\8rMjiIiS5Lohx
[2010/04/28 06:52:42 | 000,003,544 | -HS- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\U8yYP41Rt
[2010/04/28 06:52:42 | 000,003,544 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\U8yYP41Rt
[2010/04/26 22:28:36 | 000,014,380 | -HS- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\6Kw2
[2010/04/26 22:28:36 | 000,014,380 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\6Kw2
[2010/04/24 22:39:11 | 000,001,844 | -HS- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\b5bq8uC1G1B
[2010/04/24 22:39:11 | 000,001,844 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\b5bq8uC1G1B
[2010/04/23 00:07:30 | 000,017,056 | -HS- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Mi715R2
[2010/04/23 00:07:30 | 000,017,056 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\Mi715R2
[2010/04/21 14:44:47 | 000,015,742 | -HS- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\4L05Y3527I
[2010/04/21 14:44:47 | 000,015,742 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\4L05Y3527I
[2010/04/18 06:32:08 | 000,000,219 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2010/04/17 09:33:29 | 000,017,838 | -HS- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\B5XE5d7g
[2010/04/17 09:33:29 | 000,017,838 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\B5XE5d7g
[2010/04/17 02:42:33 | 000,002,416 | -HS- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\jrNYi6G
[2010/04/17 02:42:33 | 000,002,416 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\jrNYi6G
[2010/03/31 19:02:37 | 000,000,760 | —- | C] () – C:\Documents and Settings\DLL\Application Data\setup_ldm.iss
[2010/03/20 06:51:28 | 000,017,896 | -HS- | C] () – C:\Documents and Settings\DLL\Local Settings\Application Data\7OWr8MdX62
[2010/03/20 06:51:28 | 000,017,896 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\7OWr8MdX62
[2010/03/20 03:11:21 | 000,000,000 | —- | C] () – C:\Documents and Settings\DLL\Local Settings\Application Data\prvlcl.dat
[2010/03/18 19:28:25 | 000,013,502 | -HS- | C] () – C:\Documents and Settings\DLL\Local Settings\Application Data\nSVDb4q65iE
[2010/03/18 17:44:32 | 000,000,722 | -HS- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\nSVDb4q65iE
[2009/09/12 12:20:39 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2009/07/17 13:41:37 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/02/10 18:02:06 | 000,000,126 | —- | C] () – C:\Documents and Settings\DLL\Local Settings\Application Data\fusioncache.dat
[2009/02/05 20:43:10 | 000,004,096 | —- | C] () – C:\WINDOWS\d3dx.dat
[2009/01/23 13:06:42 | 000,002,775 | —- | C] () – C:\WINDOWS\CDex.INI
[2009/01/08 17:45:47 | 000,081,110 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2008/12/27 01:43:38 | 000,061,440 | —- | C] () – C:\Documents and Settings\DLL\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/12/25 20:51:12 | 000,007,217 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/12/24 10:10:16 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2008/12/16 20:58:54 | 000,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2008/12/16 20:50:56 | 000,013,584 | —- | C] () – C:\WINDOWS\System32\drivers\iKeyLgFT.dll
[2008/12/10 18:29:47 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2008/12/10 18:23:47 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/12/10 18:17:24 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/12/10 18:16:12 | 000,120,544 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/03/21 23:48:05 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2005/03/21 23:48:05 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/12/19 13:29:40 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2004/12/19 13:17:10 | 000,614,400 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2004/09/17 00:14:43 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2004/08/04 10:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 10:00:00 | 000,470,458 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 10:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 10:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 10:00:00 | 000,096,512 | —- | C] () – C:\WINDOWS\System32\drivers\atapi.sys
[2004/08/04 10:00:00 | 000,084,654 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 10:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 10:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 10:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 10:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 10:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2002/10/06 18:42:56 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OggDS.dll
[2002/10/04 23:04:24 | 000,921,600 | —- | C] () – C:\WINDOWS\System32\VorbisEnc.dll
[2002/10/04 23:04:24 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2002/10/04 23:04:16 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2002/05/15 23:38:40 | 000,091,136 | —- | C] () – C:\WINDOWS\System32\mp4fil32.dll
[2002/04/19 14:23:26 | 000,106,137 | —- | C] () – C:\WINDOWS\System32\libpostproc.dll
[2002/04/19 13:51:04 | 000,211,760 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll

========== LOP Check ==========

[2004/09/17 02:13:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2004/09/17 00:27:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/05/12 20:38:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Escape From Paradise
[2011/03/11 00:28:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Gogii
[2010/03/10 21:38:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Installations
[2010/03/10 21:43:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2010/09/19 04:42:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/07/07 12:43:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2009/03/16 12:57:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2010/02/18 07:50:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2011/02/27 00:39:17 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{8A4124D0-6AF6-4584-A7BF-4CDFECF4B129}
[2011/02/10 21:15:36 | 000,000,000 | —D | M] – C:\Documents and Settings\DLL\Application Data\.minecraft
[2009/10/10 11:10:40 | 000,000,000 | —D | M] – C:\Documents and Settings\DLL\Application Data\FOG Downloader
[2011/03/05 04:26:27 | 000,000,000 | —D | M] – C:\Documents and Settings\DLL\Application Data\GetRightToGo
[2009/01/08 17:41:42 | 000,000,000 | —D | M] – C:\Documents and Settings\DLL\Application Data\Leadertech
[2010/09/04 00:14:22 | 000,000,000 | —D | M] – C:\Documents and Settings\DLL\Application Data\MSNInstaller
[2008/12/25 19:36:23 | 000,000,000 | —D | M] – C:\Documents and Settings\DLL\Application Data\NetMedia Providers
[2004/09/16 23:11:47 | 000,000,000 | —D | M] – C:\Documents and Settings\DLL\Application Data\Nokia
[2010/04/09 22:43:31 | 000,000,000 | —D | M] – C:\Documents and Settings\DLL\Application Data\OpenOffice.org
[2010/11/18 11:25:45 | 000,000,000 | —D | M] – C:\Documents and Settings\DLL\Application Data\Opera
[2010/03/10 21:46:28 | 000,000,000 | —D | M] – C:\Documents and Settings\DLL\Application Data\PC Suite
[2008/12/25 19:36:23 | 000,000,000 | —D | M] – C:\Documents and Settings\DLL\Application Data\Publish Providers
[2010/05/10 18:52:41 | 000,000,000 | —D | M] – C:\Documents and Settings\DLL\Application Data\SpinTop
[2004/09/16 23:10:43 | 000,000,000 | —D | M] – C:\Documents and Settings\DLL\Application Data\SPORE Creature Creator
[2009/06/14 04:06:20 | 000,000,000 | —D | M] – C:\Documents and Settings\DLL\Application Data\SystemRequirementsLab
[2009/06/14 04:07:37 | 000,000,000 | —D | M] – C:\Documents and Settings\DLL\Application Data\uTorrent
[2011/03/11 09:55:01 | 000,000,724 | —- | M] () – C:\WINDOWS\Tasks\03 Today.job
[2011/03/12 08:10:18 | 000,000,280 | —- | M] () – C:\WINDOWS\Tasks\iMeshNAG.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/04/04 05:08:51 | 000,001,032 | —- | M] () – C:\a.dat
[2010/02/18 23:53:20 | 000,000,057 | —- | M] () – C:\AUTOEXEC.BAT
[2010/04/04 05:08:51 | 000,001,032 | —- | M] () – C:\b.dat
[2008/12/10 18:21:40 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2008/12/10 18:26:53 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/12/10 18:26:53 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/12/10 18:26:53 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 10:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/12/26 13:06:13 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/03/12 08:10:12 | 4194,304,000 | -HS- | M] () – C:\pagefile.sys
[2010/12/06 08:12:59 | 000,000,187 | —- | M] () – C:\Shortcut (2) to HANDY300 (E).lnk
[2010/10/18 17:20:44 | 000,000,187 | —- | M] () – C:\Shortcut to HANDY300 (E).lnk
[2009/01/24 02:40:03 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2009/02/07 19:30:44 | 000,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2009/02/09 01:52:39 | 000,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2009/02/10 12:53:58 | 000,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2009/02/10 13:10:08 | 000,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2009/02/10 18:59:39 | 000,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2009/02/11 05:17:27 | 000,000,268 | -H– | M] () – C:\sqmdata06.sqm
[2009/02/26 01:14:30 | 000,000,268 | -H– | M] () – C:\sqmdata07.sqm
[2009/01/24 02:40:03 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009/02/07 19:30:44 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009/02/09 01:52:39 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2009/02/10 12:53:58 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009/02/10 13:10:08 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009/02/10 18:59:39 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009/02/11 05:17:27 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009/02/26 01:14:30 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm

< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2008/12/10 18:26:23 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 12:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 10:50:04 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/04/16 23:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >
[2010/04/26 22:28:41 | 000,000,008 | —- | M] () – C:\Documents and Settings\All Users\Favorites\_favdata.dat

< %APPDATA%\Microsoft\*.* >
[2010/03/10 03:21:26 | 000,001,730 | -H– | M] () – C:\Documents and Settings\DLL\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/12/10 18:15:36 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2008/12/10 18:15:36 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2008/12/10 18:15:36 | 000,905,216 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/12/26 13:10:11 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/12/26 13:17:42 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\DLL\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2008/12/10 18:37:59 | 000,000,079 | —- | M] () – C:\Documents and Settings\DLL\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/03/12 08:32:11 | 007,734,240 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\DLL\Desktop\mbam-setup.exe
[2011/03/12 08:55:17 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\DLL\Desktop\OTL.exe
[2009/08/13 11:14:17 | 000,472,064 | —- | M] ( ) – C:\Documents and Settings\DLL\Desktop\RootRepeal.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-03-12 07:41:16

========== Alternate Data Streams ==========

@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A1B23042
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9E3E060F
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8

< End of report >

Extras.Txt;

OTL Extras logfile created on: 12/03/2011 08:58:04 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\DLL\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,014.00 Mb Total Physical Memory | 476.00 Mb Available Physical Memory | 47.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 4000 4000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.24 Gb Total Space | 5.82 Gb Free Space | 15.62% Space Free | Partition Type: NTFS
Drive D: | 207.75 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 279.39 Gb Total Space | 197.42 Gb Free Space | 70.66% Space Free | Partition Type: FAT32

Computer Name: DLL-54B15EFAE11 | User Name: DLL | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.exe [@ = secfile] – "C:\Documents and Settings\NetworkService\Local Settings\Application Data\ave.exe" /START "%1" %*
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Documents and Settings\DLL\Desktop\utorrent.exe" = C:\Documents and Settings\DLL\Desktop\utorrent.exe:*:Enabled:µTorrent
"C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" = C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe:*:Enabled:Malwarebytes' Anti-Malware – (Malwarebytes Corporation)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files\2K Games\Firaxis Games\Sid Meier's Civilization 4 Complete\Civilization4.exe" = C:\Program Files\2K Games\Firaxis Games\Sid Meier's Civilization 4 Complete\Civilization4.exe:*:Enabled:Sid Meier's Civilization 4 Complete
"C:\Program Files\2K Games\Firaxis Games\Sid Meier's Civilization 4 Complete\Warlords\Civ4Warlords.exe" = C:\Program Files\2K Games\Firaxis Games\Sid Meier's Civilization 4 Complete\Warlords\Civ4Warlords.exe:*:Enabled:Sid Meier's Civilization 4: Warlords
"C:\Program Files\2K Games\Firaxis Games\Sid Meier's Civilization 4 Complete\Beyond the Sword\Civ4BeyondSword.exe" = C:\Program Files\2K Games\Firaxis Games\Sid Meier's Civilization 4 Complete\Beyond the Sword\Civ4BeyondSword.exe:*:Enabled:Sid Meier's Civilization 4: Beyond the Sword
"C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" = C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:*:Enabled:Veoh Web Player – (Veoh Networks)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\Electronic Arts\EADM\Core.exe" = C:\Program Files\Electronic Arts\EADM\Core.exe:*:Enabled:EA Download Manager
"C:\Documents and Settings\DLL\My Documents\Downloads\FOGDownloader-RoM_2_1_0_1871.exe" = C:\Documents and Settings\DLL\My Documents\Downloads\FOGDownloader-RoM_2_1_0_1871.exe:*:Enabled:FOGDownloader-RoM_2_1_0_1871
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes
"C:\Program Files\AVG\AVG9\avgam.exe" = C:\Program Files\AVG\AVG9\avgam.exe:*:Enabled:avgam.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgdiagex.exe" = C:\Program Files\AVG\AVG9\avgdiagex.exe:*:Enabled:avgdiagex.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgemc.exe" = C:\Program Files\AVG\AVG9\avgemc.exe:*:Enabled:avgemc.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{184E7118-0295-43C4-B72C-1D54AA75AAF7}" = Windows Live Mail
"{1BD07DF4-FB06-41BA-B896-B2DA59000C96}" = Windows Live Toolbar
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216019FF}" = Java™ 6 Update 19
"{2D37F6AE-D201-4580-B91A-6BF9BB93ED2D}" = The Sims™ 2 Double Deluxe
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{341201D4-4F61-4ADB-987E-9CCE4D83A58D}" = Windows Live Toolbar Extension (Windows Live Toolbar)
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{53735ECE-E461-4FD0-B742-23A352436D3A}" = Logitech Updater
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7745B7A9-F323-4BB9-9811-01BF57A028DA}" = Map Button (Windows Live Toolbar)
"{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}" = Windows Live Favorites for Windows Live Toolbar
"{7E369B27-13E2-41A5-9879-358EE1C8B5AD}" = Broadcom Gigabit Integrated Controller
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{8F3F769D-E9C4-42E5-9B35-82DDCE0790C1}" = Virtual Serial Ports Emulator
"{937B232D-9776-471E-92BD-D424E514EF14}" = Logitech QuickCam
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5C4AD72-25FE-4899-B6DF-6D8DF63C93CF}" = Highlight Viewer (Windows Live Toolbar)
"{AC76BA86-7AD7-1033-7B44-A00000000001}" = Adobe Reader 6.0.1
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D92FF8EB-BD77-40AE-B68B-A6BFC6F8661D}" = Windows Live Family Safety
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{ECEE0279-785F-4CB3-9F28-E69813234BF8}" = SPORE™ Creature Creator Trial Edition
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F084395C-40FB-4DB3-981C-B51E74E1E83D}" = Smart Menus (Windows Live Toolbar)
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"1701 A.D. Gold Edition_is1" = 1701 A.D. Gold Edition
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AVG9Uninstall" = AVG 9.0
"CCleaner" = CCleaner
"CDex_is1" = Cdex version 1.30
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"lvdrivers_11.90" = Logitech QuickCam Driver Package
"Magic ISO Maker v5.5 (build 0281)" = Magic ISO Maker v5.5 (build 0281)
"MagicDisc 2.7.106" = MagicDisc 2.7.106
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MouseEmulator_is1" = MouseEmulator V2.6
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"MSNINST" = MSN
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Opera 11.00.1029" = Opera 11.00 alpha build 1029
"Opera 11.01.1190" = Opera 11.01
"SpywareBlaster_is1" = SpywareBlaster 4.2
"SystemRequirementsLab" = System Requirements Lab
"Trapped The Abduction1.0" = Trapped The Abduction
"Veoh Web Player Beta" = Veoh Web Player Beta
"VLC media player" = VLC media player 1.0.1
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11/03/2011 20:24:07 | Computer Name = DLL-54B15EFAE11 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 11/03/2011 20:24:07 | Computer Name = DLL-54B15EFAE11 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 11/03/2011 20:24:10 | Computer Name = DLL-54B15EFAE11 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: A connection with the server could not be established

Error - 12/03/2011 01:19:54 | Computer Name = DLL-54B15EFAE11 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 12/03/2011 01:19:54 | Computer Name = DLL-54B15EFAE11 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 12/03/2011 01:19:57 | Computer Name = DLL-54B15EFAE11 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: A connection with the server could not be established

Error - 12/03/2011 04:10:59 | Computer Name = DLL-54B15EFAE11 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: A connection with the server could not be established

Error - 12/03/2011 04:10:59 | Computer Name = DLL-54B15EFAE11 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 12/03/2011 04:11:02 | Computer Name = DLL-54B15EFAE11 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 12/03/2011 04:11:02 | Computer Name = DLL-54B15EFAE11 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

[ System Events ]
Error - 12/03/2011 00:20:03 | Computer Name = DLL-54B15EFAE11 | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x8007f0f4: Security Update for Windows XP (KB2393802).

Error - 12/03/2011 00:28:08 | Computer Name = DLL-54B15EFAE11 | Source = DCOM | ID = 10010
Description = The server {1F87137D-0E7C-44D5-8C73-4EFFB68962F2} did not register
with DCOM within the required timeout.

Error - 12/03/2011 01:20:34 | Computer Name = DLL-54B15EFAE11 | Source = System Error | ID = 1003
Description = Error code 000000ea, parameter1 86bdf998, parameter2 86bbb008, parameter3
86b28158, parameter4 00000001.

Error - 12/03/2011 01:21:22 | Computer Name = DLL-54B15EFAE11 | Source = DCOM | ID = 10010
Description = The server {0002DF01-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.

Error - 12/03/2011 01:21:36 | Computer Name = DLL-54B15EFAE11 | Source = System Error | ID = 1003
Description = Error code 000000ea, parameter1 861d0020, parameter2 862bdbe8, parameter3
862cdf00, parameter4 00000002.

Error - 12/03/2011 01:21:41 | Computer Name = DLL-54B15EFAE11 | Source = System Error | ID = 1003
Description = Error code 000000ea, parameter1 86821da8, parameter2 866eb8d8, parameter3
866d2b10, parameter4 00000001.

Error - 12/03/2011 01:21:42 | Computer Name = DLL-54B15EFAE11 | Source = System Error | ID = 1003
Description = Error code 000000ea, parameter1 86952460, parameter2 86b584f0, parameter3
86b33fd8, parameter4 00000001.

Error - 12/03/2011 01:21:43 | Computer Name = DLL-54B15EFAE11 | Source = System Error | ID = 1003
Description = Error code 000000ea, parameter1 86851da8, parameter2 86bf0258, parameter3
86fd3420, parameter4 00000001.

Error - 12/03/2011 01:21:44 | Computer Name = DLL-54B15EFAE11 | Source = System Error | ID = 1003
Description = Error code 000000ea, parameter1 86e42658, parameter2 868af408, parameter3
86b26f38, parameter4 00000001.

Error - 12/03/2011 03:41:16 | Computer Name = DLL-54B15EFAE11 | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x8007f0f4: Security Update for Windows XP (KB2393802).


< End of report >

As instructed on another page, I will not run any scans, change any settings or remove or add any programmes.

Many Thanks,
Jon Hill
Hi Lost Dose, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Looks like there may be a disk controller hijacker onboard along with a keylogger and a backdoor trojan.


Your system has been infected by one or more Backdoor Trojans and a keylogger.

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

Its very possible that anything could have been installed on your computer by the remote attacker, including opening other backdoors and installing rootkits. While we can attempt to clean what we see in your logs, we cannot guarantee that your computer will be completely in the clear since we have no way of knowing that has been done to the computer. It may be prudent to backup your information, reformat, and reinstall.

More information on Remote Access Trojans can be found here.

I strongly suggest you do the following immediately:
  • Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
  • From a clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • DO NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.

If, however, you decide that the computer is not used for any sensitive work, or if you do not wish to reformat at this time, I can help you clean your computer to the best of my abilities. I must remind you that i cannot guarantee that your computer will be completely clean afterwards since we have no way of knowing what has been done to it.

To help you make your decision, here are a few related articles that i suggest you read:

  • Danger: Remote Access Trojans.
  • When should I re-format? How should I reinstall?
  • How Do I Handle Possible Identify Theft, Internet Fraud and Credit Card Fraud?

Should you have any questions, please feel free to ask.



If you wish to clean this machine we'll start with a quick little fix and look deeper.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
O37 - HKLM\…exe [@ = secfile] – "C:\Documents and Settings\NetworkService\Local Settings\Application Data\ave.exe" /START "%1" %*
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555
IE - HKCU\..\URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 

:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"none"=-
"nonep"=-
[HKEY_CLASSES_ROOT\.exe]
""="exefile"
"Content Type"="application/x-msdownload"

:Files
ipconfig /flushdns /c

:Commands
[emptytemp]
[createrestorepoint
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log.


Next

Go HERE to get a randomly named copy of GMER. Scroll down to the Download section and click Download EXE. Save it to your desktop.

Before scanning with GMER, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

  • Double click on the file you downloaded. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER will not run in normal windows, please run it in Safe Mode


Next
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • UNCheck the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following bold text
    /md5start
    atapi.*
    /md5stop
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window, OTL.Txt

Please post back with
  • OTL fix log
  • GMER log
  • new OTL.txt
Hello Oldman960,

Many Thanks for your warm welcome and fast and detailed response, I am extremely grateful.

With regards to reformatting the P.C. I do not think that will be an option, we purchased the P.C. online, it was a custom build from Germany and already had its Operating Systems installed when we received it, with no disks provided for re-installation.

I do occasionally check my bank account from this P.C. however I have a hand held device here that I have to put my card into in order for it to provide a unique code which constantly changes. I believe it's design is to protect against this exact type of worst case scenario. So if it is ok with you I would like to continue to try to fix the issues until it seems clean, I totally understand it can never be guaranteed as safe and will use my other P.C. for any sensitive work from now on.

I have just run the first OTL log and will post the Txt file results below before I go on to perform the next two steps, I hope this is ok, if you would rather I reply all at once next time please say and I will do that from now on.

One other thing of note, the text file is titled 03132011_020727, but there is a new icon on my desktop after running the fix called Thumbs.db, it is probably normal but just wanted to let you know incase.

Many Thanks again :)

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
HKEY_LOCAL_MACHINE\Software\Classes\.exe\shell\open\command\\|"%1" %* /E : value set successfully!
HKEY_LOCAL_MACHINE\Software\Classes\.exe\\|exefile /E : value set successfully!
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\*{CFBFAE00-17A6-11D0-99CB-00C04FD64497} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\*{CFBFAE00-17A6-11D0-99CB-00C04FD64497}\ deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\none deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\nonep not found.
HKEY_CLASSES_ROOT\.exe\\""|"exefile" /E : value set successfully!
HKEY_CLASSES_ROOT\.exe\\"Content Type"|"application/x-msdownload" /E : value set successfully!
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\DLL\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\DLL\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 41620 bytes

User: DLL
->Temp folder emptied: 9202421 bytes
->Temporary Internet Files folder emptied: 323691 bytes
->Java cache emptied: 1886080 bytes
->FireFox cache emptied: 138853967 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 75744 bytes

User: LocalService
->Temp folder emptied: 67387 bytes
->Temporary Internet Files folder emptied: 1245586 bytes
->Java cache emptied: 603 bytes
->Flash cache emptied: 12276 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 18383200 bytes
->Java cache emptied: 57857 bytes
->Flash cache emptied: 26038 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2195181 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 2036533 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 91140034 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 253.00 mb

Error: Unable to interpret <[createrestorepoint> in the current context!

OTL by OldTimer - Version 3.2.22.3 log created on 03132011_020727

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…
Hi Lost Dose,

the text file is titled 03132011_020727,

Yes the name reflects the date/time the log was created. It is commonly just called the "fix log" because it is created when a fix is done with OTL.

Don't worry about Thumbs.db, that's normally hidden, we'll rehide it by the time we are done.

It's best if you can provide all the logs at once. Depending on what is shown will determine where we go next.
Hey oldman960,

Sorry that took a while, it got hung up on the GMER scan.

A few things I should mention

1) Sorry about posting the first log separately above, Ill e sure to put everything together after this.

2) After the reboot from the first OTL fix I forgot to close down Spybot S&D; :smack: Really sorry about that.

3) I did get the warning message with GMER, I selected NO as instructed but then proceeded with the following steps, now I'm not so sure if I should have abandoned those steps, a second apology if I did it wrong.

4) The GMER scan ran fast, however, as a rough estimation it returned a few hundred thousand results under Opera/Cache/Cache/XXXXX . I really don't think that is an over estimation either, Ill see when it comes to posting you the log from that whether I need to cut out the middle as I'm sure you either want or need to see a reply log that long with the majority of it being form the same folder. I can always repost the full report if you wish.

5) When I ran the second OTL scan I forgot to close the opera page I had open to read your instructions, so another :smack: and a third apology.

The GMER scan;

GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2011-03-13 04:48:41
Windows 5.1.2600 Service Pack 3
Running: x85kvrmf.exe; Driver: C:\DOCUME~1\DLL\LOCALS~1\Temp\ffroraob.sys


—- System - GMER 1.0.15 —-

Code 8694DA00 ZwEnumerateKey
Code 86936328 ZwFlushInstructionCache
Code 8693C496 IofCallDriver
Code 8693342E IofCompleteRequest

—- Kernel code sections - GMER 1.0.15 —-

.text ntoskrnl.exe!IofCallDriver 804E37D5 5 Bytes JMP 8693C49B
.text ntoskrnl.exe!IofCompleteRequest 804E3C06 5 Bytes JMP 86933433
PAGE ntoskrnl.exe!ZwEnumerateKey 80570F41 5 Bytes JMP 8694DA04
PAGE ntoskrnl.exe!ZwFlushInstructionCache 80577873 5 Bytes JMP 8693632C
.rsrc C:\WINDOWS\system32\drivers\atapi.sys entry point in ".rsrc" section [0xF77A6794]
init C:\WINDOWS\system32\drivers\senfilt.sys entry point in "init" section [0xF73CDF80]

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 86ED490A
Device \Driver\atapi \Device\Ide\IdePort0 86ED490A
Device \Driver\atapi \Device\Ide\IdePort1 86ED490A
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e 86ED490A

AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat AVGIDSFilter.sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )

—- Modules - GMER 1.0.15 —-

Module \systemroot\PRAGMAitqstnevbq\PRAGMAd.sys (*** hidden *** ) AA22D000-AA24F000 (139264 bytes)

—- Services - GMER 1.0.15 —-

Service system32\drivers\msqpdxxjecbxhx.sys (*** hidden *** ) [SYSTEM] msqpdxserv.sys <– ROOTKIT !!!
Service C:\WINDOWS\PRAGMAitqstnevbq\PRAGMAd.sys (*** hidden *** ) [SYSTEM] PRAGMAitqstnevbq <– ROOTKIT !!!

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\msqpdxserv.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\msqpdxserv.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\msqpdxserv.sys@imagepath \systemroot\system32\drivers\msqpdxxjecbxhx.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\msqpdxserv.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\msqpdxserv.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\msqpdxserv.sys\modules@msqpdxserv
Reg HKLM\SYSTEM\CurrentControlSet\Services\msqpdxserv.sys\modules@msqpdxl
Reg HKLM\SYSTEM\CurrentControlSet\Services\PRAGMAitqstnevbq
Reg HKLM\SYSTEM\CurrentControlSet\Services\PRAGMAitqstnevbq@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\PRAGMAitqstnevbq@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\PRAGMAitqstnevbq@imagepath \systemroot\PRAGMAitqstnevbq\PRAGMAd.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\PRAGMAitqstnevbq\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\PRAGMAitqstnevbq\modules@PRAGMAd \systemroot\PRAGMAitqstnevbq\PRAGMAd.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\PRAGMAitqstnevbq\modules@PRAGMAc \systemroot\PRAGMAitqstnevbq\PRAGMAc.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\PRAGMAitqstnevbq\modules@PRAGMAsrcr \\?\globalroot\systemroot\system32\PRAGMAsrcr.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\PRAGMAitqstnevbq\modules@pragmaserf \\?\globalroot\systemroot\system32\pragmaserf.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\PRAGMAitqstnevbq\modules@pragmabbr \\?\globalroot\systemroot\system32\pragmabbr.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\PRAGMAitqstnevbq\modules@PRAGMAerrors \\?\globalroot\systemroot\system32\PRAGMAerrors.log
Reg HKLM\SYSTEM\ControlSet002\Services\msqpdxserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet002\Services\msqpdxserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet002\Services\msqpdxserv.sys@imagepath \systemroot\system32\drivers\msqpdxxjecbxhx.sys
Reg HKLM\SYSTEM\ControlSet002\Services\msqpdxserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet002\Services\msqpdxserv.sys\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\msqpdxserv.sys\modules@msqpdxserv
Reg HKLM\SYSTEM\ControlSet002\Services\msqpdxserv.sys\modules@msqpdxl
Reg HKLM\SYSTEM\ControlSet003\Services\msqpdxserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\msqpdxserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\msqpdxserv.sys@imagepath \systemroot\system32\drivers\msqpdxxjecbxhx.sys
Reg HKLM\SYSTEM\ControlSet003\Services\msqpdxserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\msqpdxserv.sys\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\msqpdxserv.sys\modules@msqpdxserv
Reg HKLM\SYSTEM\ControlSet003\Services\msqpdxserv.sys\modules@msqpdxl
Reg HKLM\SYSTEM\ControlSet003\Services\PRAGMAitqstnevbq (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\PRAGMAitqstnevbq@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\PRAGMAitqstnevbq@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\PRAGMAitqstnevbq@imagepath \systemroot\PRAGMAitqstnevbq\PRAGMAd.sys
Reg HKLM\SYSTEM\ControlSet003\Services\PRAGMAitqstnevbq\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\PRAGMAitqstnevbq\modules@PRAGMAd \systemroot\PRAGMAitqstnevbq\PRAGMAd.sys
Reg HKLM\SYSTEM\ControlSet003\Services\PRAGMAitqstnevbq\modules@PRAGMAc \systemroot\PRAGMAitqstnevbq\PRAGMAc.dll
Reg HKLM\SYSTEM\ControlSet003\Services\PRAGMAitqstnevbq\modules@PRAGMAsrcr \\?\globalroot\systemroot\system32\PRAGMAsrcr.dat
Reg HKLM\SYSTEM\ControlSet003\Services\PRAGMAitqstnevbq\modules@pragmaserf \\?\globalroot\systemroot\system32\pragmaserf.dll
Reg HKLM\SYSTEM\ControlSet003\Services\PRAGMAitqstnevbq\modules@pragmabbr \\?\globalroot\systemroot\system32\pragmabbr.dll
Reg HKLM\SYSTEM\ControlSet003\Services\PRAGMAitqstnevbq\modules@PRAGMAerrors \\?\globalroot\systemroot\system32\PRAGMAerrors.log

—- Files - GMER 1.0.15 —-

File C:\Documents and Settings\All Users\Application Data\pragmamfeklnmal.dll 1186 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI7J 810 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI7L 1592 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI7M 13155 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI7N 201 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI7O 51 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI7P 260 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI7Q 28995 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI7R 50 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI7S 35 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI7V 801 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI7W 1150 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI7X 26509 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI7Y 29743 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI7Z 312 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI80 5117 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI81 1022 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI82 376 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI84 1003 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI85 57254 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI86 810 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI87 22678 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI89 672 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI8B 1636 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI8C 17875 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI8D 1515 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI8E 1648 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI8F 50 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI8G 9257 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI8H 2911 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI8I 14922 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI8J 3340 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI8K 1644 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI8L 3340 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI8M 3372 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI8N 1612 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI8P 801 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI8Q 118 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI8R 118 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0PI8S 3627 bytes

……………….

There was approximately a hundred thousand plus entries exactly as above but with different unique file names varying from 0 bytes to several million bytes per file

………………

File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0QODC 43 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0QODW 12253 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0QOEK 1357 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0QOF5 149 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0QOFQ 1225 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0QOGA 262 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0QOGU 43 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0QOHG 43 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0QOI2 22350 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0QOIO 3657 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0QOJ8 3678 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0QOK5 363 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0QOL6 43 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0QOM5 8907 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\opr0QOMH 3628 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\pubsuffix 0 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\pubsuffix\dcache4.url 20 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\pubsuffix\sesn 0 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\pubsuffix\vlink4.dat 12 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation 0 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\dcache4.url 20 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\g_0000 0 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn 0 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000E2.tmp 545 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000E3.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000E4.tmp 14465 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000E5.tmp 2330 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000E6.tmp 1224 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000E7.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000E8.tmp 716 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000ES.tmp 545 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000ET.tmp 2308 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000EU.tmp 1224 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000EV.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000EW.tmp 3396 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000EX.tmp 1282 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000I5.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000I6.tmp 790 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000JJ.tmp 415 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000JK.tmp 545 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000JM.tmp 886 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000JN.tmp 16330 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000JO.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000JP.tmp 619 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000JQ.tmp 898 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000JR.tmp 902 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000JS.tmp 886 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000JT.tmp 533 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000JU.tmp 1728 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000JV.tmp 16360 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000JW.tmp 772 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000JX.tmp 312512 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000JY.tmp 1166 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000JZ.tmp 500 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000K0.tmp 545 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000K1.tmp 415 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000K2.tmp 3385 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000K4.tmp 902 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000KE.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000KF.tmp 902 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000KG.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000KH.tmp 545 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000KI.tmp 3353 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000KJ.tmp 1282 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000KK.tmp 886 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000KL.tmp 16360 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000KM.tmp 2198 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000KN.tmp 1224 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000KY.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000KZ.tmp 902 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000L0.tmp 545 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000L1.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000L2.tmp 3319 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000LQ.tmp 545 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000LS.tmp 3284 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000LT.tmp 1282 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000LU.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000LV.tmp 902 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000LW.tmp 545 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000LX.tmp 3302 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000LY.tmp 1282 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000LZ.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000M0.tmp 300927 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000M1.tmp 1166 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000M2.tmp 500 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000M3.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000M4.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000M5.tmp 902 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000M6.tmp 898 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000M7.tmp 886 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000M8.tmp 533 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000MA.tmp 16360 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000MB.tmp 619 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000MC.tmp 772 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000MD.tmp 1682 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000ME.tmp 187788 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000MF.tmp 473 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000MG.tmp 472 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000ML.tmp 2110 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000MM.tmp 1224 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000MN.tmp 545 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000MO.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000MP.tmp 3298 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000MQ.tmp 1282 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000MR.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000MS.tmp 898 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000MT.tmp 902 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000MU.tmp 1085 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000NC.tmp 902 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000ND.tmp 545 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000NE.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000NF.tmp 3252 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000NG.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000NH.tmp 619 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000NI.tmp 898 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000NJ.tmp 886 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000NK.tmp 533 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000NL.tmp 1728 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000NM.tmp 16360 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000NN.tmp 772 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000NO.tmp 1682 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000NP.tmp 1085 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000NQ.tmp 2088 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000NR.tmp 1224 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000NS.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000JL.tmp 3384 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000K3.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000LR.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000M9.tmp 1728 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000NB.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000NT.tmp 302117 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000PV.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000SF.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000U2.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000UP.tmp 1728 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000VP.tmp 1480 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000NU.tmp 1166 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000NV.tmp 500 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000NW.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000OS.tmp 2088 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000OT.tmp 1224 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000PJ.tmp 1310 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000PK.tmp 1597 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000PL.tmp 1597 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000PM.tmp 886 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000PN.tmp 533 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000PO.tmp 1946 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000PP.tmp 1597 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000PQ.tmp 1597 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000PR.tmp 898 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000PS.tmp 1085 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000PT.tmp 119112 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000PU.tmp 476 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000PW.tmp 2088 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000PX.tmp 1224 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000PY.tmp 1728 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000PZ.tmp 902 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000Q0.tmp 533 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000Q1.tmp 16450 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000Q2.tmp 1597 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000Q3.tmp 1728 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000Q4.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000Q5.tmp 477 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000Q6.tmp 429 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000Q7.tmp 2430 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000SA.tmp 2066 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000SB.tmp 1224 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000SC.tmp 898 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000SD.tmp 1728 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000SE.tmp 533 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000SG.tmp 545 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000SH.tmp 902 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000SI.tmp 886 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000SJ.tmp 16450 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000SK.tmp 3121 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000SL.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000SM.tmp 1728 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000SN.tmp 619 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000SO.tmp 772 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000SP.tmp 1728 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000SQ.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000SR.tmp 475 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000SS.tmp 2408 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000ST.tmp 2430 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000SU.tmp 429 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000SV.tmp 389 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000SW.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000U3.tmp 619 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000U4.tmp 898 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000U5.tmp 902 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000U6.tmp 886 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000U7.tmp 533 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000U8.tmp 1728 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000U9.tmp 16450 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000UA.tmp 772 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000UB.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000UC.tmp 545 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000UD.tmp 3114 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000UE.tmp 1282 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000UF.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000UG.tmp 2066 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000UH.tmp 475 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000UI.tmp 1224 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000UO.tmp 898 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000UQ.tmp 533 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000V9.tmp 429 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000VA.tmp 2430 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000VB.tmp 289517 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000VC.tmp 902 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000VD.tmp 2044 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000VE.tmp 500 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000VF.tmp 1224 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000VG.tmp 1206 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000VH.tmp 886 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000VI.tmp 16450 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000VJ.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000VK.tmp 545 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000VL.tmp 14242 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000VM.tmp 469 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000VN.tmp 3056 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000VO.tmp 1206 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000VQ.tmp 898 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000VR.tmp 1085 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000VS.tmp 471 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000VT.tmp 1728 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000VU.tmp 533 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\sesn\opr000VV.tmp 538 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\revocation\vlink4.dat 12 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\sesn 0 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\turbo 0 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\turbo\dcache4.url 20 bytes
File C:\Documents and Settings\DLL\Local Settings\Application Data\Opera\Opera\cache\turbo\vlink4.dat 12 bytes
File C:\Documents and Settings\DLL\Local Settings\Temp\pragmapdconf.ini 28 bytes
File C:\WINDOWS\PRAGMAitqstnevbq 0 bytes
File C:\WINDOWS\PRAGMAitqstnevbq\PRAGMAc.dll 30720 bytes executable
File C:\WINDOWS\PRAGMAitqstnevbq\PRAGMAcfg.ini 92 bytes
File C:\WINDOWS\PRAGMAitqstnevbq\PRAGMAd.sys 44544 bytes executable <– ROOTKIT !!!
File C:\WINDOWS\system32\pragmabbr.dll 57344 bytes executable
File C:\WINDOWS\system32\PRAGMAerrors.log 101 bytes
File C:\WINDOWS\system32\pragmaserf.dll 57344 bytes executable
File C:\WINDOWS\system32\PRAGMAsrcr.dat 149 bytes
File C:\WINDOWS\Temp\pragmamainqt.dll 10274 bytes
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification

—- EOF - GMER 1.0.15 —-

OTL second scan report;

OTL logfile created on: 13/03/2011 04:49:49 - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\DLL\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,014.00 Mb Total Physical Memory | 364.00 Mb Available Physical Memory | 36.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 4000 4000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.24 Gb Total Space | 5.90 Gb Free Space | 15.85% Space Free | Partition Type: NTFS
Drive D: | 207.75 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 279.39 Gb Total Space | 197.42 Gb Free Space | 70.66% Space Free | Partition Type: FAT32

Computer Name: DLL-54B15EFAE11 | User Name: DLL | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\DLL\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Opera\opera.exe (Opera Software)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgfws9.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\DLL\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (avgfws9) – C:\Program Files\AVG\AVG9\avgfws9.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9emc) – C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)


========== Driver Services (SafeList) ==========

DRV - (EterlogicVirtualSerialDriver) – C:\WINDOWS\system32\drivers\VSPE.sys ()
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSDriverxpx) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilterxpx) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShimxpx) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSErHrxpx) – C:\WINDOWS\System32\Drivers\AVGIDSxx.sys (AVG Technologies CZ, s.r.o. )
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (atapi) – C:\WINDOWS\system32\DRIVERS\atapi.sys ()
DRV - (AvgRkx86) – C:\WINDOWS\System32\Drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (mcdbus) – C:\WINDOWS\system32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (FilterService) – C:\WINDOWS\system32\drivers\lvuvcflt.sys (Logitech Inc.)
DRV - (LVUVC) Logitech QuickCam E3500(UVC) – C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (LVRS) – C:\WINDOWS\system32\drivers\lvrs.sys (Logitech Inc.)
DRV - (LVPr2Mon) – C:\WINDOWS\system32\drivers\LVPr2Mon.sys ()
DRV - (MusCAudio) – C:\WINDOWS\system32\drivers\MusCAudio.sys (Windows ® Codename Longhorn DDK provider)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (senfilt) – C:\WINDOWS\system32\drivers\senfilt.sys (Creative Technology Ltd.)
DRV - (Avgfwfd) – C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgfwdx) – C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - File not found
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..browser.search.defaulturl: "http://www.bing.com/search?FORM=IEFM1&q;="
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.order.2: "Google"
FF - prefs.js..browser.search.selectedEngine: "Yahoo! Search"
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.4
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.2.20100119091315
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:[removed]
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.872
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.2
FF - prefs.js..keyword.URL: "http://uk.yhs.search.yahoo.com/avg/search?fr=yhs-avgb&type;=yahoo_avg_hs2-tb-web_uk&p;="
FF - prefs.js..network.proxy.type: 0


FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/12/09 13:45:55 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/11 22:28:52 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/02 19:44:46 | 000,000,000 | —D | M]

[2008/12/24 10:10:15 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\DLL\Application Data\Mozilla\Extensions
[2011/03/09 08:57:46 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\DLL\Application Data\Mozilla\Firefox\Profiles\vy1f2mhv.default\extensions
[2010/04/28 21:22:05 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\DLL\Application Data\Mozilla\Firefox\Profiles\vy1f2mhv.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/01/15 11:11:31 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\DLL\Application Data\Mozilla\Firefox\Profiles\vy1f2mhv.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2004/09/16 23:10:52 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\DLL\Application Data\Mozilla\Firefox\Profiles\vy1f2mhv.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}(2)
[2010/02/17 13:36:26 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\DLL\Application Data\Mozilla\Firefox\Profiles\vy1f2mhv.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/01/27 09:19:41 | 000,000,000 | —D | M] (Zynga Toolbar) – C:\Documents and Settings\DLL\Application Data\Mozilla\Firefox\Profiles\vy1f2mhv.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2010/04/11 22:52:21 | 000,000,000 | —D | M] ("Tab Mix Plus") – C:\Documents and Settings\DLL\Application Data\Mozilla\Firefox\Profiles\vy1f2mhv.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2010/01/20 17:01:56 | 000,002,171 | —- | M] () – C:\Documents and Settings\DLL\Application Data\Mozilla\Firefox\Profiles\vy1f2mhv.default\searchplugins\bing.xml
[2011/03/09 08:57:46 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/12/09 13:45:55 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES\AVG\AVG9\FIREFOX
[2010/04/10 05:44:25 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2009/02/24 08:08:43 | 000,000,000 | —D | M] (Veoh Web Player Video Finder) – C:\PROGRAM FILES\VEOH NETWORKS\VEOHWEBPLAYER\FFVIDEOFINDER
[2010/07/19 23:03:28 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/07/19 23:03:28 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/07/19 23:03:28 | 000,000,769 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/07/19 23:03:28 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2010/09/18 05:22:27 | 000,419,441 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 14476 more lines…
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - File not found
O3 - HKLM\..\Toolbar: (Veoh Web Player Video Finder) - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll (Veoh Networks Inc)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - File not found
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKCU..\Run: [EA Core] File not found
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\DLL\Start Menu\Programs\Startup\MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
O4 - Startup: C:\Documents and Settings\DLL\Start Menu\Programs\Startup\Registration THE SETTLERS - Heritage of Kings.LNK = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper: C:\Documents and Settings\DLL\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/02/18 23:53:20 | 000,000,057 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2008/01/04 09:41:54 | 000,000,042 | R— | M] () - D:\autorun.inf – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk /r \??\C:) - File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

========== Files/Folders - Created Within 30 Days ==========

[2011/03/13 02:07:27 | 000,000,000 | —D | C] – C:\_OTL
[2011/03/12 08:55:17 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\DLL\Desktop\OTL.exe
[2011/03/12 08:34:13 | 000,472,064 | —- | C] ( ) – C:\Documents and Settings\DLL\Desktop\RootRepeal.exe
[2011/03/12 08:32:49 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/03/12 08:32:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/03/12 08:32:42 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/03/12 08:32:42 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/03/12 08:32:03 | 007,734,240 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\DLL\Desktop\mbam-setup.exe
[2011/03/11 00:28:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Gogii
[2011/03/11 00:26:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Trapped The Abduction
[2011/03/11 00:25:47 | 000,000,000 | —D | C] – C:\WINDOWS\Trapped The Abduction
[2011/03/11 00:25:47 | 000,000,000 | —D | C] – C:\Program Files\Trapped The Abduction
[2011/03/09 21:55:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Aspyr Media
[2011/03/09 21:39:38 | 000,000,000 | —D | C] – C:\Program Files\Aspyr
[2011/03/07 20:46:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Maxis
[2011/03/07 20:45:00 | 000,000,000 | —D | C] – C:\Program Files\Maxis
[2011/03/07 20:44:50 | 000,305,152 | —- | C] (InstallShield Software Corporation) – C:\WINDOWS\IsUn0419.exe
[2011/03/07 20:31:11 | 000,000,000 | —D | C] – C:\Documents and Settings\DLL\Start Menu\Programs\MagicDisc
[2011/03/07 20:30:59 | 000,116,736 | —- | C] (MagicISO, Inc.) – C:\WINDOWS\System32\drivers\mcdbus.sys
[2011/03/07 20:30:59 | 000,000,000 | —D | C] – C:\Program Files\MagicDisc
[2011/03/07 20:28:19 | 000,000,000 | —D | C] – C:\Documents and Settings\DLL\Start Menu\Programs\MagicISO
[2011/03/07 20:28:18 | 000,000,000 | —D | C] – C:\Program Files\MagicISO
[2011/03/07 05:19:29 | 000,000,000 | —D | C] – C:\Program Files\MouseEmulator
[2011/03/07 05:19:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\MouseEmulator
[2011/03/07 05:05:57 | 000,000,000 | —D | C] – C:\Documents and Settings\DLL\Start Menu\Programs\Virtual Serial Ports Emulator
[2011/03/07 05:05:54 | 000,000,000 | —D | C] – C:\Program Files\Eterlogic.com
[2011/03/07 04:53:57 | 000,000,000 | —D | C] – C:\Documents and Settings\DLL\My Documents\My eBooks
[2011/03/07 04:53:37 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2011/03/05 04:13:06 | 000,000,000 | —D | C] – C:\BLUEBYTE
[2011/03/02 19:44:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\PrintMe Internet Printing
[2011/03/02 19:44:39 | 000,000,000 | —D | C] – C:\Program Files\Adobe
[2011/03/02 19:38:50 | 000,000,000 | —D | C] – C:\WINDOWS\Cache
[2011/02/27 21:07:18 | 000,000,000 | —D | C] – C:\Documents and Settings\DLL\WINDOWS
[2011/02/27 21:04:23 | 000,000,000 | —D | C] – C:\Documents and Settings\DLL\My Documents\Downloads
[2011/02/27 21:04:22 | 000,000,000 | —D | C] – C:\Documents and Settings\DLL\Application Data\GetRightToGo
[2011/02/27 20:47:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\OldGames.sk
[2011/02/27 20:47:43 | 000,000,000 | —D | C] – C:\Program Files\Oldgames
[2011/02/27 01:45:19 | 000,000,000 | —D | C] – C:\Documents and Settings\DLL\Local Settings\Application Data\DOSBox
[2011/02/27 01:43:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\DOSBox-0.74
[2011/02/27 00:39:17 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{8A4124D0-6AF6-4584-A7BF-4CDFECF4B129}
[2011/02/27 00:38:44 | 000,000,000 | —D | C] – C:\Documents and Settings\DLL\Local Settings\Application Data\PackageAware
[2011/02/22 17:48:10 | 000,000,000 | —D | C] – C:\Documents and Settings\DLL\My Documents\Jonny
[2011/02/13 12:26:22 | 000,000,000 | —D | C] – C:\Documents and Settings\DLL\My Documents\My Received Files

========== Files - Modified Within 30 Days ==========

[2011/03/13 02:23:59 | 000,296,448 | —- | M] () – C:\Documents and Settings\DLL\Desktop\x85kvrmf.exe
[2011/03/13 02:12:14 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/03/13 02:11:27 | 000,000,280 | —- | M] () – C:\WINDOWS\tasks\iMeshNAG.job
[2011/03/13 02:11:23 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/03/12 09:55:01 | 000,000,724 | —- | M] () – C:\WINDOWS\tasks\03 Today.job
[2011/03/12 08:55:17 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\DLL\Desktop\OTL.exe
[2011/03/12 08:34:18 | 000,000,000 | —- | M] () – C:\Documents and Settings\DLL\Desktop\settings.dat
[2011/03/12 08:33:22 | 000,465,298 | —- | M] () – C:\Documents and Settings\DLL\Desktop\RootRepeal.rar
[2011/03/12 08:32:49 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/12 08:32:11 | 007,734,240 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\DLL\Desktop\mbam-setup.exe
[2011/03/09 21:55:56 | 000,000,735 | —- | M] () – C:\Documents and Settings\DLL\Desktop\1701 A.D..lnk
[2011/03/09 03:10:19 | 000,001,391 | —- | M] () – C:\Documents and Settings\DLL\Start Menu\Programs\Startup\Registration THE SETTLERS - Heritage of Kings.LNK
[2011/03/09 03:03:43 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/03/09 03:03:35 | 000,000,219 | —- | M] () – C:\WINDOWS\System32\MRT.INI
[2011/03/07 20:31:11 | 000,000,652 | —- | M] () – C:\Documents and Settings\DLL\Start Menu\Programs\Startup\MagicDisc.lnk
[2011/03/07 05:05:56 | 000,025,984 | —- | M] () – C:\WINDOWS\System32\drivers\VSPE.sys
[2011/03/06 19:04:00 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\lvuvc.hs
[2011/03/06 19:03:56 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\logiflt.iad
[2011/02/27 11:19:14 | 071,823,095 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2011/02/25 00:07:00 | 000,000,000 | —- | M] () – C:\Documents and Settings\DLL\Local Settings\Application Data\prvlcl.dat
[2011/02/23 21:56:56 | 000,646,492 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\iavifw.avm
[2011/02/16 04:53:57 | 000,061,440 | —- | M] () – C:\Documents and Settings\DLL\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== Files Created - No Company Name ==========

[2011/03/13 02:23:59 | 000,296,448 | —- | C] () – C:\Documents and Settings\DLL\Desktop\x85kvrmf.exe
[2011/03/12 08:34:18 | 000,000,000 | —- | C] () – C:\Documents and Settings\DLL\Desktop\settings.dat
[2011/03/12 08:33:21 | 000,465,298 | —- | C] () – C:\Documents and Settings\DLL\Desktop\RootRepeal.rar
[2011/03/12 08:32:49 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/09 21:55:56 | 000,000,735 | —- | C] () – C:\Documents and Settings\DLL\Desktop\1701 A.D..lnk
[2011/03/09 03:10:19 | 000,001,391 | —- | C] () – C:\Documents and Settings\DLL\Start Menu\Programs\Startup\Registration THE SETTLERS - Heritage of Kings.LNK
[2011/03/07 21:04:11 | 000,000,280 | —- | C] () – C:\WINDOWS\tasks\iMeshNAG.job
[2011/03/07 20:31:11 | 000,000,652 | —- | C] () – C:\Documents and Settings\DLL\Start Menu\Programs\Startup\MagicDisc.lnk
[2011/03/07 05:05:56 | 000,025,984 | —- | C] () – C:\WINDOWS\System32\drivers\VSPE.sys
[2011/03/02 19:44:47 | 000,002,377 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader 6.0.lnk
[2010/05/26 06:45:15 | 000,000,088 | RHS- | C] () – C:\Documents and Settings\All Users\Application Data\6ACA2FD747.sys
[2010/05/26 06:45:14 | 000,002,516 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys
[2010/05/02 08:39:01 | 000,015,786 | -HS- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\1947251409
[2010/05/02 08:39:01 | 000,015,786 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\1947251409
[2010/04/28 13:53:30 | 000,001,634 | -HS- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\8rMjiIiS5Lohx
[2010/04/28 13:53:30 | 000,001,634 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\8rMjiIiS5Lohx
[2010/04/28 06:52:42 | 000,003,544 | -HS- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\U8yYP41Rt
[2010/04/28 06:52:42 | 000,003,544 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\U8yYP41Rt
[2010/04/26 22:28:36 | 000,014,380 | -HS- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\6Kw2
[2010/04/26 22:28:36 | 000,014,380 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\6Kw2
[2010/04/24 22:39:11 | 000,001,844 | -HS- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\b5bq8uC1G1B
[2010/04/24 22:39:11 | 000,001,844 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\b5bq8uC1G1B
[2010/04/23 00:07:30 | 000,017,056 | -HS- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Mi715R2
[2010/04/23 00:07:30 | 000,017,056 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\Mi715R2
[2010/04/21 14:44:47 | 000,015,742 | -HS- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\4L05Y3527I
[2010/04/21 14:44:47 | 000,015,742 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\4L05Y3527I
[2010/04/18 06:32:08 | 000,000,219 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2010/04/17 09:33:29 | 000,017,838 | -HS- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\B5XE5d7g
[2010/04/17 09:33:29 | 000,017,838 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\B5XE5d7g
[2010/04/17 02:42:33 | 000,002,416 | -HS- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\jrNYi6G
[2010/04/17 02:42:33 | 000,002,416 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\jrNYi6G
[2010/03/31 19:02:37 | 000,000,760 | —- | C] () – C:\Documents and Settings\DLL\Application Data\setup_ldm.iss
[2010/03/20 06:51:28 | 000,017,896 | -HS- | C] () – C:\Documents and Settings\DLL\Local Settings\Application Data\7OWr8MdX62
[2010/03/20 06:51:28 | 000,017,896 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\7OWr8MdX62
[2010/03/20 03:11:21 | 000,000,000 | —- | C] () – C:\Documents and Settings\DLL\Local Settings\Application Data\prvlcl.dat
[2010/03/18 19:28:25 | 000,013,502 | -HS- | C] () – C:\Documents and Settings\DLL\Local Settings\Application Data\nSVDb4q65iE
[2010/03/18 17:44:32 | 000,000,722 | -HS- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\nSVDb4q65iE
[2009/09/12 12:20:39 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2009/07/17 13:41:37 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/02/10 18:02:06 | 000,000,126 | —- | C] () – C:\Documents and Settings\DLL\Local Settings\Application Data\fusioncache.dat
[2009/02/05 20:43:10 | 000,004,096 | —- | C] () – C:\WINDOWS\d3dx.dat
[2009/01/23 13:06:42 | 000,002,775 | —- | C] () – C:\WINDOWS\CDex.INI
[2009/01/08 17:45:47 | 000,081,110 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2008/12/27 01:43:38 | 000,061,440 | —- | C] () – C:\Documents and Settings\DLL\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/12/25 20:51:12 | 000,007,217 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/12/24 10:10:16 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2008/12/16 20:58:54 | 000,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2008/12/16 20:50:56 | 000,013,584 | —- | C] () – C:\WINDOWS\System32\drivers\iKeyLgFT.dll
[2008/12/10 18:29:47 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2008/12/10 18:23:47 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/12/10 18:17:24 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/12/10 18:16:12 | 000,120,544 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/03/21 23:48:05 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2005/03/21 23:48:05 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/12/19 13:29:40 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2004/12/19 13:17:10 | 000,614,400 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2004/09/17 00:14:43 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2004/08/04 10:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 10:00:00 | 000,470,458 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 10:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 10:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 10:00:00 | 000,096,512 | —- | C] () – C:\WINDOWS\System32\drivers\atapi.sys
[2004/08/04 10:00:00 | 000,084,654 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 10:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 10:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 10:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 10:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 10:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2002/10/06 18:42:56 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OggDS.dll
[2002/10/04 23:04:24 | 000,921,600 | —- | C] () – C:\WINDOWS\System32\VorbisEnc.dll
[2002/10/04 23:04:24 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2002/10/04 23:04:16 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2002/05/15 23:38:40 | 000,091,136 | —- | C] () – C:\WINDOWS\System32\mp4fil32.dll
[2002/04/19 14:23:26 | 000,106,137 | —- | C] () – C:\WINDOWS\System32\libpostproc.dll
[2002/04/19 13:51:04 | 000,211,760 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll

========== Custom Scans ==========



< MD5 for: ATAPI.SYS >
[2008/04/13 18:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2010/04/19 11:02:34 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\dllcache\atapi.sys
[2010/04/19 11:02:34 | 000,096,512 | —- | M] () MD5=A453FDCE8E7698A3FDAE2AA678BD6FB9 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/04 10:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0014\DriverFiles\i386\atapi.sys

========== Alternate Data Streams ==========

@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A1B23042
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9E3E060F
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8

< End of report >

Sorry again for all the mistakes and thanks so much again for you help,
Jonny
Hi Lost Dose,

GMER showed the disk controller hijacking and a rootkit or 2, including the one you origonally posted about.

The next tool will require that you uninstall AVG as the tool will not run if AVG is installed. Sorry about that but this is the most effective tool we have to deal with the multiple infections onboard all at once.

Download the tool then uninstall AVG and run the tool.

Do not use this computer on the internet except for downloading tools or posting in this thread. When I give you the go ahead you can either reinstall AVG or another free alternative which I can give you links to.

Please read through the instructions to familarize youself with what to expect when the tool runs.

It is vitally important that combofix is renamed before it is even started to download


Please download ComboFix from Link 1or Link 2 to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".
  • During the download, before you save it to your desktop, rename Combofix to jgh.exe

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix

———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • Double click on ComboFix.exe (jgh.exe in your case) & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


Please post back with
  • combofix log
How is the computer?

Thanks
Hey,

I am just up to here;

Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

And am disabling Spybot TeaTimer as per the instructions in your link, however I encountered a slight problem. This is their instructions;

SPYBOT TEATIMER
Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
On the left hand side, click on Tools, then click on the Resident Icon in the list.
Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
Click on the "System Startup" icon in the List
Uncheck the "TeaTimer" box and "OK" any prompts.
If Teatimer gives you a warning that changes were made, click the "Allow Change" box when prompted.
Exit Spybot S&D when done and reboot your computer.
(When we are done, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup.]


When I click System start-up there is no TeaTimer listed there, what should I do?
Hi Lost Dose,

Are you in advanced mode?

From the Spybot site

You only need to disable the resident feature of Spybot-S&D. And that is the way to deactivate it: Run Spybot-S&D, switch to the Advanced mode via the menu bar item Mode → hit Yes → select Tools in the navigation bar on the left → Resident and there you can untick the checkboxes in front of the two tools.



edit:

If you were able to disable Teatimer under Tools, it should be fine.

Hi Lost Dose,

Are you in advanced mode?

From the Spybot site

You only need to disable the resident feature of Spybot-S&D. And that is the way to deactivate it: Run Spybot-S&D, switch to the Advanced mode via the menu bar item Mode → hit Yes → select Tools in the navigation bar on the left → Resident and there you can untick the checkboxes in front of the two tools.


Hey,

I was in advanced mode yes, though their instructions were slightly different from what you have there. I read a little bit further on on their forum post and someone explained that as newer versions come out, instructions may change slightly. Given that it was only the section to disable it in start up that wasn't there, that TeaTimer had been disabled at that point in time and that I would be running the scan you requested before start up, I decided to press on. (It also did not start Spybot at startup and the scan rebooted)

A few points I should mention that came up whilst following your instructions, just for the sake of keeping you fully informed;

1) I deleted the main AVG 9.0 though Add and remove programs in control panel. I did receive an error message that AVG toolbar was not found, but since I always uncheck the toolbars during installations I proceeded.

2) I manually deleted all other AVG files from older versions that I could find.

3) CCleaner and Malwarebytes (free version) did not seem to have resident scanners so I left them untouched.

4) Disabled Spybot Teatimer as mentioned above.

5) Disabled Spyware Blaster which wasn't on the but had some active protection running.

Then I proceeded with the scan as instructed, a few points on this also;

a) When it started, even though Opera was closed, I had a caution pop up box (same as I get on opening opera) from where the clock is stating 'PEV.cfxxe - Corrupt File C:\Documents and settings\DLL\Local settings\Application data\Opera\ Cache is corrupt and unreadable. Please run the check disk utility'

B) After agreeing to download the software you said it would, and before the congratulations message, on its blue screed it said 'The file or directory is corrupt and unreadable'

However the operations carried on as I presume was to be expected.

As for how is my machine, well it is starting to look much better, during the reboot, Chkdsk actually ran! :clap: It seemed to do a lot of things, mainly with something it referred to as file 14466.

The only other changes I can see at the moment are that my background picture seems to be sized or fitted differently (not important, just wanted to note all differences), I have Internet explorer installed on my desktop now (it never worked or ran before, though I haven't tried to run it myself yet) and amazingly Opera didn't barrage me with warning message as I started it up :thumbup:

I know my machine can never be deemed as truly clean or safe without a reformat, and that there are probably still some more steps for us to take here, but things are definitely looking much better already, so thank-you so much yet again.

I'll wait to see what you would like me to do next :)
Whoops over-excited at the progress I forgot to post the log :blush:

ComboFix 11-03-12.01 - DLL 13/03/2011 6:09.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.676 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\jgh.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\pragmamfeklnmal.dll
c:\documents and settings\All Users\Favorites\_favdata.dat
c:\windows\system32\hccutils(10).dll
c:\windows\system32\hccutils(11).dll
c:\windows\system32\hccutils(12).dll
c:\windows\system32\hccutils(13).dll
c:\windows\system32\hccutils(14).dll
c:\windows\system32\hccutils(15).dll
c:\windows\system32\hccutils(16).dll
c:\windows\system32\hccutils(17).dll
c:\windows\system32\hccutils(18).dll
c:\windows\system32\hccutils(19).dll
c:\windows\system32\hccutils(2).dll
c:\windows\system32\hccutils(20).dll
c:\windows\system32\hccutils(21).dll
c:\windows\system32\hccutils(22).dll
c:\windows\system32\hccutils(23).dll
c:\windows\system32\hccutils(24).dll
c:\windows\system32\hccutils(25).dll
c:\windows\system32\hccutils(26).dll
c:\windows\system32\hccutils(27).dll
c:\windows\system32\hccutils(28).dll
c:\windows\system32\hccutils(29).dll
c:\windows\system32\hccutils(3).dll
c:\windows\system32\hccutils(30).dll
c:\windows\system32\hccutils(31).dll
c:\windows\system32\hccutils(4).dll
c:\windows\system32\hccutils(5).dll
c:\windows\system32\hccutils(6).dll
c:\windows\system32\hccutils(7).dll
c:\windows\system32\hccutils(8).dll
c:\windows\system32\hccutils(9).dll
c:\windows\system32\hkcmd(10).exe
c:\windows\system32\hkcmd(11).exe
c:\windows\system32\hkcmd(12).exe
c:\windows\system32\hkcmd(13).exe
c:\windows\system32\hkcmd(14).exe
c:\windows\system32\hkcmd(15).exe
c:\windows\system32\hkcmd(16).exe
c:\windows\system32\hkcmd(17).exe
c:\windows\system32\hkcmd(18).exe
c:\windows\system32\hkcmd(19).exe
c:\windows\system32\hkcmd(2).exe
c:\windows\system32\hkcmd(20).exe
c:\windows\system32\hkcmd(21).exe
c:\windows\system32\hkcmd(22).exe
c:\windows\system32\hkcmd(23).exe
c:\windows\system32\hkcmd(24).exe
c:\windows\system32\hkcmd(25).exe
c:\windows\system32\hkcmd(26).exe
c:\windows\system32\hkcmd(27).exe
c:\windows\system32\hkcmd(28).exe
c:\windows\system32\hkcmd(29).exe
c:\windows\system32\hkcmd(3).exe
c:\windows\system32\hkcmd(30).exe
c:\windows\system32\hkcmd(31).exe
c:\windows\system32\hkcmd(4).exe
c:\windows\system32\hkcmd(5).exe
c:\windows\system32\hkcmd(6).exe
c:\windows\system32\hkcmd(7).exe
c:\windows\system32\hkcmd(8).exe
c:\windows\system32\hkcmd(9).exe
c:\windows\system32\igfxsrvc(10).dll
c:\windows\system32\igfxsrvc(11).dll
c:\windows\system32\igfxsrvc(12).dll
c:\windows\system32\igfxsrvc(13).dll
c:\windows\system32\igfxsrvc(14).dll
c:\windows\system32\igfxsrvc(15).dll
c:\windows\system32\igfxsrvc(16).dll
c:\windows\system32\igfxsrvc(17).dll
c:\windows\system32\igfxsrvc(18).dll
c:\windows\system32\igfxsrvc(19).dll
c:\windows\system32\igfxsrvc(2).dll
c:\windows\system32\igfxsrvc(20).dll
c:\windows\system32\igfxsrvc(21).dll
c:\windows\system32\igfxsrvc(22).dll
c:\windows\system32\igfxsrvc(23).dll
c:\windows\system32\igfxsrvc(24).dll
c:\windows\system32\igfxsrvc(25).dll
c:\windows\system32\igfxsrvc(26).dll
c:\windows\system32\igfxsrvc(27).dll
c:\windows\system32\igfxsrvc(28).dll
c:\windows\system32\igfxsrvc(29).dll
c:\windows\system32\igfxsrvc(3).dll
c:\windows\system32\igfxsrvc(30).dll
c:\windows\system32\igfxsrvc(31).dll
c:\windows\system32\igfxsrvc(4).dll
c:\windows\system32\igfxsrvc(5).dll
c:\windows\system32\igfxsrvc(6).dll
c:\windows\system32\igfxsrvc(7).dll
c:\windows\system32\igfxsrvc(8).dll
c:\windows\system32\igfxsrvc(9).dll
c:\windows\system32\igfxsrvc.dll
c:\windows\system32\lowsec
E:\resycled
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_msqpdxserv.sys
——-\Legacy_MYWEBSEARCHSERVICE
——-\Legacy_PRAGMAITQSTNEVBQ
——-\Service_msqpdxserv.sys
——-\Service_PRAGMAitqstnevbq
.
.
((((((((((((((((((((((((( Files Created from 2011-02-13 to 2011-03-13 )))))))))))))))))))))))))))))))
.
.
2011-03-13 02:07 . 2011-03-13 02:07 ——– dc—-w- C:\_OTL
2011-03-12 08:32 . 2010-12-20 18:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-03-12 08:32 . 2011-03-12 08:32 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-03-12 08:32 . 2010-12-20 18:08 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-03-11 00:28 . 2011-03-11 00:28 ——– d—–w- c:\documents and settings\All Users\Application Data\Gogii
2011-03-11 00:25 . 2011-03-11 00:28 ——– d—–w- c:\program files\Trapped The Abduction
2011-03-11 00:25 . 2011-03-11 00:25 ——– d—–w- c:\windows\Trapped The Abduction
2011-03-09 21:39 . 2011-03-09 22:03 ——– d—–w- c:\program files\Aspyr
2011-03-07 20:45 . 2011-03-07 20:45 ——– d—–w- c:\program files\Maxis
2011-03-07 20:44 . 1998-01-23 12:55 305152 —-a-w- c:\windows\IsUn0419.exe
2011-03-07 20:30 . 2011-03-07 20:33 ——– d—–w- c:\program files\MagicDisc
2011-03-07 20:30 . 2009-02-24 18:42 116736 —-a-w- c:\windows\system32\drivers\mcdbus.sys
2011-03-07 20:28 . 2011-03-07 20:28 ——– d—–w- c:\program files\MagicISO
2011-03-07 05:19 . 2011-03-07 05:19 ——– d—–w- c:\program files\MouseEmulator
2011-03-07 05:05 . 2011-03-07 05:05 25984 —-a-w- c:\windows\system32\drivers\VSPE.sys
2011-03-07 05:05 . 2011-03-07 05:05 ——– d—–w- c:\program files\Eterlogic.com
2011-03-07 04:53 . 2011-03-07 04:53 ——– d—–w- c:\program files\Common Files\Adobe
2011-03-05 04:13 . 2011-03-05 04:13 ——– dc—-w- C:\BLUEBYTE
2011-03-02 19:38 . 2011-03-02 19:38 ——– d—–w- c:\windows\Cache
2011-02-27 21:07 . 2011-02-27 21:07 ——– d—–w- c:\documents and settings\DLL\WINDOWS
2011-02-27 21:04 . 2011-03-05 04:26 ——– d—–w- c:\documents and settings\DLL\Application Data\GetRightToGo
2011-02-27 20:47 . 2011-03-08 03:16 ——– d—–w- c:\program files\Oldgames
2011-02-27 01:45 . 2011-02-27 01:45 ——– d—–w- c:\documents and settings\DLL\Local Settings\Application Data\DOSBox
2011-02-27 00:39 . 2011-02-27 00:39 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{8A4124D0-6AF6-4584-A7BF-4CDFECF4B129}
2011-02-27 00:38 . 2011-02-27 00:38 ——– d—–w- c:\documents and settings\DLL\Local Settings\Application Data\PackageAware
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-09 13:53 . 2004-08-04 10:00 270848 —-a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2004-08-04 10:00 186880 —-a-w- c:\windows\system32\encdec.dll
2011-02-02 07:58 . 2008-12-10 18:22 2067456 —-a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2008-12-10 18:22 677888 —-a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44 . 2004-08-04 10:00 439296 —-a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2004-08-04 10:00 290048 —-a-w- c:\windows\system32\atmfd.dll
2010-12-31 13:10 . 2004-08-04 10:00 1854976 —-a-w- c:\windows\system32\win32k.sys
2010-12-22 12:34 . 2004-08-04 10:00 301568 —-a-w- c:\windows\system32\kerberos.dll
2010-12-20 23:08 . 2006-03-04 03:33 832512 —-a-w- c:\windows\system32\wininet.dll
2010-12-20 23:08 . 2004-08-04 10:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-12-20 23:08 . 2004-08-04 10:00 1830912 ——w- c:\windows\system32\inetcpl.cpl
2010-12-20 23:08 . 2004-08-04 10:00 17408 —-a-w- c:\windows\system32\corpol.dll
2010-12-20 17:26 . 2004-08-04 10:00 730112 —-a-w- c:\windows\system32\lsasrv.dll
2010-12-20 12:55 . 2004-08-04 10:00 389120 —-a-w- c:\windows\system32\html.iec
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\opera\program\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\opera\program\plugins\ssldivx.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-23 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-23 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-23 118784]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-10 417792]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http:" [X]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\DLL\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2011-3-7 576000]
Registration THE SETTLERS - Heritage of Kings.LNK - c:\program files\Ubisoft\Blue Byte\THE SETTLERS - Heritage of Kings\Support\Register\RegistrationReminder.exe [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
2008-12-20 06:50 2656528 —-a-w- c:\program files\Logitech\QuickCam\Quickcam.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
.
R1 EterlogicVirtualSerialDriver;EterlogicVirtualSerialDriver;c:\windows\system32\drivers\VSPE.sys [07/03/2011 05:05 25984]
S0 elbuvcpe;elbuvcpe; [x]
S3 MusCAudio;MusCAudio;c:\windows\system32\drivers\MusCAudio.sys [23/01/2009 13:14 23096]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-12 c:\windows\Tasks\03 Today.job
- e:\music!\Documents and Settings\searesi\Desktop\My Documents\filelib\music saves\My Deliveries\My Music\Smashing Pumpkins\Siamese Dream\03 Today.wma [2008-12-23 00:16]
.
.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = hxxp://shell.windows.com/fileassoc/0409/xml/redir.asp?Ext=DL_
IE: Add to Windows &Live; Favorites - http://favorites.live.com/quickadd.aspx
FF - ProfilePath - c:\documents and settings\DLL\Application Data\Mozilla\Firefox\Profiles\vy1f2mhv.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q;=
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: keyword.URL - hxxp://uk.yhs.search.yahoo.com/avg/search?fr=yhs-avgb&type;=yahoo_avg_hs2-tb-web_uk&p;=
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Veoh Web Player Video Finder: [removed] - c:\program files\Veoh Networks\VeohWebPlayer\FFVideoFinder
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - %profile%\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - %profile%\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: Tab Mix Plus: {dc572301-7619-498c-a57d-39143191b318} - %profile%\extensions\{dc572301-7619-498c-a57d-39143191b318}
FF - user.js: yahoo.homepage.dontask - true
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
BHO-{A3BC75A2-1F87-4686-AA43-5347D756017C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
HKCU-Run-EA Core - c:\program files\Electronic Arts\EADM\Core.exe
MSConfigStartUp-Corel Photo Downloader - c:\program files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe
AddRemove-{2D37F6AE-D201-4580-B91A-6BF9BB93ED2D} - c:\program files\EA GAMES\The Sims 2 Double Deluxe\EAUninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-13 06:26
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: ST340014AS rev.8.05 -> Harddisk0\DR0 -> \Device\Ide\IdePort1 P1T0L0-e
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x862D8CA1]<<
_asm { PUSH EBP; MOV EBP, ESP; SUB ESP, 0x58; PUSH EBX; PUSH ESI; MOV DWORD [EBP-0x4], 0xa8b8290b; SUB DWORD [EBP-0x4], 0xa8b82113; PUSH EDI; CALL 0xffffffffffffdedd; }
1 nt!IofCallDriver[0x804E37D5] -> \Device\Harddisk0\DR0[0x8637EAB8]
3 CLASSPNP[0xF764DFD7] -> nt!IofCallDriver[0x804E37D5] -> [0x863E1B00]
[0x86368D10] -> IRP_MJ_CREATE -> 0x862D8CA1
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
\Device\Ide\IdeDeviceP1T0L0-e -> \??\IDE#DiskST340014AS______________________________8.05____#4a3546585444514520
2020202020202020202020#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
\Driver\atapi DriverStartIo -> 0x862D88C3
user & kernel MBR OK
sectors 78124998 (+255): user != kernel
Warning: possible TDL3 rootkit infection !
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-790525478-1563985344-839522115-1003\Software\SecuROM\License information*]
"datasecu"=hex:95,e1,f1,28,f5,82,4b,08,2e,a1,9b,3f,5d,0d,ef,a1,55,0a,79,3b,14,
d3,fc,f9,59,d5,6a,ee,0d,81,94,3a,f8,1e,20,4c,c1,04,1b,de,10,6b,2a,37,3f,0c,\
"rkeysecu"=hex:46,28,c2,e8,8a,96,08,a4,e8,04,65,d1,d6,20,a6,97
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(664)
c:\windows\system32\WININET.dll
.
- - - - - - - > 'lsass.exe'(724)
c:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(5956)
c:\windows\system32\WININET.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
.
**************************************************************************
.
Completion time: 2011-03-13 06:34:36 - machine was rebooted
ComboFix-quarantined-files.txt 2011-03-13 06:34
.
Pre-Run: 6,668,976,128 bytes free
Post-Run: 11,259,809,792 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - E7221C2D841D0B60333FAB06D058ABA9
Hi Lost Dose, I edited my last post, must have been while you were posting. Seems like you found the answer yourself. Did combofix produce a log? It should be located at C:\combofix.txt Please post it if you find it. It will show us what to next. Thanks
Hi Lost Dose,

Combofix reset a few things to default. The IE icon is one of those.

We got most of it. Let's get the next big one.

Please read carefully and follow these steps.

Next

Please open OTL

  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, click the None button near the top (it may looked greyed out)
  • In the window under Custom Scans/Fixes copy and paste the following


    c:\documents and settings\All Users\Application Data\{8A4124D0-6AF6-4584-A7BF-4CDFECF4B129}\*.* /s
    c:\documents and settings\DLL\Local Settings\Application Data\PackageAware\*.* /s
    /md5start
    atapi.*
    IsUn0419.exe
    /md5stop


  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window, OTL.Txt. Please post this log.

Please post back with
  • TDSKiller log
  • OTL.txt
how is it now?

Thanks
Hey Oldman960

The computer seems the same as it was after our last progress, though without large applications running things seem to run pretty smoothly (It isn't the worlds greatest PC) anyway so it is hard to tell.

Only notable change, which I presume is to be expected. was that this time after the first scan did a reboot, when windows loaded up I got two of those red shield pop ups in the bottom right stating 'Antivirus software might not be installed' and 'No firewall is turned on.'

Here are the two log files;

TDSSKiller;

2011/03/13 07:26:52.0765 7232 TDSS rootkit removing tool 2.4.21.0 Mar 10 2011 12:26:28
2011/03/13 07:26:53.0000 7232 ================================================================================
2011/03/13 07:26:53.0000 7232 SystemInfo:
2011/03/13 07:26:53.0000 7232
2011/03/13 07:26:53.0000 7232 OS Version: 5.1.2600 ServicePack: 3.0
2011/03/13 07:26:53.0000 7232 Product type: Workstation
2011/03/13 07:26:53.0000 7232 ComputerName: DLL-54B15EFAE11
2011/03/13 07:26:53.0000 7232 UserName: DLL
2011/03/13 07:26:53.0000 7232 Windows directory: C:\WINDOWS
2011/03/13 07:26:53.0000 7232 System windows directory: C:\WINDOWS
2011/03/13 07:26:53.0000 7232 Processor architecture: Intel x86
2011/03/13 07:26:53.0000 7232 Number of processors: 1
2011/03/13 07:26:53.0000 7232 Page size: 0x1000
2011/03/13 07:26:53.0000 7232 Boot type: Normal boot
2011/03/13 07:26:53.0000 7232 ================================================================================
2011/03/13 07:26:53.0234 7232 Initialize success
2011/03/13 07:26:55.0906 7268 ================================================================================
2011/03/13 07:26:55.0906 7268 Scan started
2011/03/13 07:26:55.0906 7268 Mode: Manual;
2011/03/13 07:26:55.0906 7268 ================================================================================
2011/03/13 07:26:57.0609 7268 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2011/03/13 07:26:57.0843 7268 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
2011/03/13 07:26:58.0546 7268 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2011/03/13 07:26:58.0859 7268 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
2011/03/13 07:27:00.0734 7268 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2011/03/13 07:27:00.0953 7268 atapi (a453fdce8e7698a3fdae2aa678bd6fb9) C:\WINDOWS\system32\DRIVERS\atapi.sys
2011/03/13 07:27:00.0953 7268 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\atapi.sys. Real md5: a453fdce8e7698a3fdae2aa678bd6fb9, Fake md5: 9f3a2f5aa6875c72bf062c712cfa2674
2011/03/13 07:27:00.0968 7268 atapi - detected Rootkit.Win32.TDSS.tdl3 (0)
2011/03/13 07:27:01.0468 7268 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2011/03/13 07:27:01.0718 7268 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2011/03/13 07:27:01.0968 7268 b57w2k (3a3a82ffd268bcfb7ae6a48cecf00ad9) C:\WINDOWS\system32\DRIVERS\b57xp32.sys
2011/03/13 07:27:02.0250 7268 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2011/03/13 07:27:02.0500 7268 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2011/03/13 07:27:02.0734 7268 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
2011/03/13 07:27:03.0203 7268 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2011/03/13 07:27:03.0437 7268 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2011/03/13 07:27:03.0687 7268 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2011/03/13 07:27:03.0921 7268 cercsr6 (84853b3fd012251690570e9e7e43343f) C:\WINDOWS\system32\drivers\cercsr6.sys
2011/03/13 07:27:05.0265 7268 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2011/03/13 07:27:05.0515 7268 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
2011/03/13 07:27:05.0828 7268 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
2011/03/13 07:27:06.0093 7268 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2011/03/13 07:27:06.0328 7268 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2011/03/13 07:27:06.0812 7268 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2011/03/13 07:27:07.0406 7268 EterlogicVirtualSerialDriver (c2370b7a25174c0fb8fb10a19e091b46) C:\WINDOWS\system32\drivers\VSPE.sys
2011/03/13 07:27:07.0687 7268 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2011/03/13 07:27:08.0171 7268 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
2011/03/13 07:27:08.0421 7268 FilterService (1edc0df2da14e04504dd3bac21aa32cd) C:\WINDOWS\system32\DRIVERS\lvuvcflt.sys
2011/03/13 07:27:08.0640 7268 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
2011/03/13 07:27:08.0875 7268 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
2011/03/13 07:27:09.0171 7268 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2011/03/13 07:27:09.0406 7268 fssfltr (c6ee3a87fe609d3e1db9dbd072a248de) C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys
2011/03/13 07:27:09.0640 7268 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2011/03/13 07:27:09.0937 7268 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2011/03/13 07:27:10.0203 7268 GEARAspiWDM (ab8a6a87d9d7255c3884d5b9541a6e80) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
2011/03/13 07:27:10.0453 7268 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2011/03/13 07:27:10.0687 7268 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2011/03/13 07:27:11.0218 7268 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2011/03/13 07:27:11.0875 7268 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\drivers\i8042prt.sys
2011/03/13 07:27:12.0203 7268 ialm (0f0194c4b635c10c3f785e4fee52d641) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
2011/03/13 07:27:12.0484 7268 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2011/03/13 07:27:12.0906 7268 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
2011/03/13 07:27:13.0171 7268 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2011/03/13 07:27:13.0375 7268 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2011/03/13 07:27:13.0593 7268 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2011/03/13 07:27:13.0796 7268 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2011/03/13 07:27:14.0031 7268 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2011/03/13 07:27:14.0265 7268 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2011/03/13 07:27:14.0484 7268 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2011/03/13 07:27:15.0046 7268 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2011/03/13 07:27:15.0328 7268 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2011/03/13 07:27:15.0656 7268 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
2011/03/13 07:27:15.0906 7268 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2011/03/13 07:27:16.0234 7268 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2011/03/13 07:27:16.0718 7268 LVPr2Mon (f96cfb47903854f228baaf3e2d41a0a3) C:\WINDOWS\system32\Drivers\LVPr2Mon.sys
2011/03/13 07:27:17.0000 7268 LVRS (e22fd7852e74f04cceb6b8a684a51f3e) C:\WINDOWS\system32\DRIVERS\lvrs.sys
2011/03/13 07:27:17.0296 7268 LVUSBSta (5f987fc1aad215ec2c60cf07719b1cce) C:\WINDOWS\system32\drivers\LVUSBSta.sys
2011/03/13 07:27:17.0765 7268 LVUVC (e89df2b88ee659954de79827ddf46dc9) C:\WINDOWS\system32\DRIVERS\lvuvc.sys
2011/03/13 07:27:18.0265 7268 mcdbus (8fd868e32459ece2a1bb0169f513d31e) C:\WINDOWS\system32\DRIVERS\mcdbus.sys
2011/03/13 07:27:18.0500 7268 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2011/03/13 07:27:18.0703 7268 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
2011/03/13 07:27:19.0000 7268 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2011/03/13 07:27:19.0218 7268 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2011/03/13 07:27:19.0437 7268 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2011/03/13 07:27:19.0843 7268 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2011/03/13 07:27:20.0078 7268 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2011/03/13 07:27:20.0343 7268 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2011/03/13 07:27:20.0546 7268 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011/03/13 07:27:20.0765 7268 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011/03/13 07:27:20.0968 7268 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2011/03/13 07:27:21.0187 7268 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2011/03/13 07:27:21.0421 7268 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
2011/03/13 07:27:21.0625 7268 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
2011/03/13 07:27:21.0875 7268 MusCAudio (3e44ac015742401a685a4cf5d98ebd3e) C:\WINDOWS\system32\drivers\MusCAudio.sys
2011/03/13 07:27:22.0093 7268 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
2011/03/13 07:27:22.0296 7268 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2011/03/13 07:27:22.0515 7268 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
2011/03/13 07:27:22.0734 7268 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2011/03/13 07:27:22.0953 7268 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2011/03/13 07:27:23.0203 7268 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2011/03/13 07:27:23.0437 7268 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
2011/03/13 07:27:23.0687 7268 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2011/03/13 07:27:23.0937 7268 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2011/03/13 07:27:24.0203 7268 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2011/03/13 07:27:24.0484 7268 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2011/03/13 07:27:24.0718 7268 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2011/03/13 07:27:24.0968 7268 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2011/03/13 07:27:25.0187 7268 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2011/03/13 07:27:25.0421 7268 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
2011/03/13 07:27:25.0625 7268 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2011/03/13 07:27:25.0890 7268 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
2011/03/13 07:27:26.0125 7268 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
2011/03/13 07:27:26.0546 7268 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
2011/03/13 07:27:26.0796 7268 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
2011/03/13 07:27:28.0234 7268 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2011/03/13 07:27:30.0453 7268 ================================================================================
2011/03/13 07:27:30.0453 7268 Scan finished
2011/03/13 07:27:30.0453 7268 ================================================================================
2011/03/13 07:27:30.0468 7292 Detected object count: 1
2011/03/13 07:27:37.0531 7292 atapi (a453fdce8e7698a3fdae2aa678bd6fb9) C:\WINDOWS\system32\DRIVERS\atapi.sys
2011/03/13 07:27:37.0531 7292 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\atapi.sys. Real md5: a453fdce8e7698a3fdae2aa678bd6fb9, Fake md5: 9f3a2f5aa6875c72bf062c712cfa2674
2011/03/13 07:27:37.0828 7292 Backup copy found, using it..
2011/03/13 07:27:37.0828 7292 C:\WINDOWS\system32\DRIVERS\atapi.sys - will be cured after reboot
2011/03/13 07:27:37.0828 7292 Rootkit.Win32.TDSS.tdl3(atapi) - User select action: Cure
2011/03/13 07:27:42.0796 1536 Deinitialize success


OTL;

OTL logfile created on: 13/03/2011 07:32:18 - Run 3
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\DLL\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,014.00 Mb Total Physical Memory | 687.00 Mb Available Physical Memory | 68.00% Memory free
5.00 Gb Paging File | 5.00 Gb Available in Paging File | 96.00% Paging File free
Paging file location(s): C:\pagefile.sys 4000 4000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.24 Gb Total Space | 22.36 Gb Free Space | 60.03% Space Free | Partition Type: NTFS
Drive D: | 207.75 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 279.39 Gb Total Space | 197.42 Gb Free Space | 70.66% Space Free | Partition Type: FAT32

Computer Name: DLL-54B15EFAE11 | User Name: DLL | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

========== Custom Scans ==========


< c:\documents and settings\All Users\Application Data\{8A4124D0-6AF6-4584-A7BF-4CDFECF4B129}\*.* /s >

< c:\documents and settings\DLL\Local Settings\Application Data\PackageAware\*.* /s >


< MD5 for: ATAPI.SY_ >
[2004/08/03 22:59:44 | 000,049,558 | —- | M] () MD5=28541D14647BB58502D09D1CEAEE6684 – C:\cmdcons\ATAPI.SY_

< MD5 for: ATAPI.SYS >
[2010/04/19 11:02:34 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/13 18:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2010/04/19 11:02:34 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\dllcache\atapi.sys
[2011/03/13 07:28:28 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/04 10:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0014\DriverFiles\i386\atapi.sys

< MD5 for: ISUN0419.EXE >
[1998/01/23 12:55:14 | 000,305,152 | —- | M] (InstallShield Software Corporation) MD5=B9CCFE0B317D4B1C901ED7B45396769E – C:\WINDOWS\IsUn0419.exe

< End of report >

Many Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI