1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive Multiple BSOD plagueing Computer

Discussion in 'Malware and Virus Removal Archive' started by terencew, 2011/10/02.

  1. 2011/10/02
    terencew

    terencew Inactive Thread Starter

    Joined:
    2011/09/29
    Messages:
    34
    Likes Received:
    0
  2. 2011/10/02
    terencew

    terencew Inactive Thread Starter

    Joined:
    2011/09/29
    Messages:
    34
    Likes Received:
    0
    1. Mbam Log:

    Malwarebytes' Anti-Malware 1.51.2.1300
    www.malwarebytes.org

    Database version: 7833

    Windows 6.1.7601 Service Pack 1 (Safe Mode)
    Internet Explorer 8.0.7601.17514

    2/10/2011 12:24:44 AM
    mbam-log-2011-10-02 (00-24-44).txt

    Scan type: Quick scan
    Objects scanned: 191304
    Time elapsed: 4 minute(s), 10 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
     

  3. to hide this advert.

  4. 2011/10/02
    terencew

    terencew Inactive Thread Starter

    Joined:
    2011/09/29
    Messages:
    34
    Likes Received:
    0
    2. Gmer Log:

    GMER 1.0.15.15641 - http://www.gmer.net
    Rootkit scan 2011-10-02 20:08:51
    Windows 6.1.7601 Service Pack 1 Harddisk1\DR1 -> \Device\Ide\IdeDeviceP4T0L0-4 SAMSUNG_HD103UJ rev.1AA01118
    Running: 5pnu51kj.exe; Driver: C:\Users\Terence\AppData\Local\Temp\awdirfow.sys


    ---- Kernel code sections - GMER 1.0.15 ----

    .text ntkrnlpa.exe!ZwSaveKey + 13D1 8425C349 1 Byte [06]
    .text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 84295D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
    .text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x96C0D000, 0x3A3E05, 0xE8000020]

    ---- User code sections - GMER 1.0.15 ----

    .text C:\Program Files\Common Files\PPLiveNetwork\PPAP.exe[1076] kernel32.dll!CreateFileW 7656E8A5 5 Bytes JMP 02714BB0 C:\Program Files\Common Files\PPLiveNetwork\TipsClient.dll
    .text C:\Program Files\Common Files\PPLiveNetwork\PPAP.exe[1076] kernel32.dll!CreateFileA 7656EA61 5 Bytes JMP 02714B50 C:\Program Files\Common Files\PPLiveNetwork\TipsClient.dll
    .text C:\Program Files\Common Files\PPLiveNetwork\PPAP.exe[1076] USER32.dll!ShowWindow 75D1F2A9 5 Bytes JMP 027149A0 C:\Program Files\Common Files\PPLiveNetwork\TipsClient.dll
    .text D:\PPS.tv\PPStream\PPSAP.exe[1704] kernel32.dll!GetQueuedCompletionStatus 76554E40 5 Bytes JMP 10028AB1 D:\PPS.tv\PPStream\Vodres.dll (PPS 动态链接库/PPStream Inc.)
    .text D:\PPS.tv\PPStream\PPSAP.exe[1704] kernel32.dll!CreateIoCompletionPort 76558E89 5 Bytes JMP 10028A5D D:\PPS.tv\PPStream\Vodres.dll (PPS 动态链接库/PPStream Inc.)
    .text D:\PPS.tv\PPStream\PPSAP.exe[1704] kernel32.dll!SetFilePointerEx 7655FB6A 5 Bytes JMP 1002888A D:\PPS.tv\PPStream\Vodres.dll (PPS 动态链接库/PPStream Inc.)
    .text D:\PPS.tv\PPStream\PPSAP.exe[1704] kernel32.dll!GetFileSize 76560823 5 Bytes JMP 1002897C D:\PPS.tv\PPStream\Vodres.dll (PPS 动态链接库/PPStream Inc.)
    .text D:\PPS.tv\PPStream\PPSAP.exe[1704] kernel32.dll!GetOverlappedResult 76563629 5 Bytes JMP 10028A0A D:\PPS.tv\PPStream\Vodres.dll (PPS 动态链接库/PPStream Inc.)
    .text D:\PPS.tv\PPStream\PPSAP.exe[1704] kernel32.dll!GetFileSizeEx 765699B1 5 Bytes JMP 100289C3 D:\PPS.tv\PPStream\Vodres.dll (PPS 动态链接库/PPStream Inc.)
    .text D:\PPS.tv\PPStream\PPSAP.exe[1704] kernel32.dll!ReadFile 76569B66 7 Bytes JMP 1002867E D:\PPS.tv\PPStream\Vodres.dll (PPS 动态链接库/PPStream Inc.)
    .text D:\PPS.tv\PPStream\PPSAP.exe[1704] kernel32.dll!CloseHandle 7656E868 5 Bytes JMP 1002893B D:\PPS.tv\PPStream\Vodres.dll (PPS 动态链接库/PPStream Inc.)
    .text D:\PPS.tv\PPStream\PPSAP.exe[1704] kernel32.dll!CreateFileW 7656E8A5 5 Bytes JMP 10028618 D:\PPS.tv\PPStream\Vodres.dll (PPS 动态链接库/PPStream Inc.)
    .text D:\PPS.tv\PPStream\PPSAP.exe[1704] kernel32.dll!CreateFileA 7656EA61 5 Bytes JMP 100285B2 D:\PPS.tv\PPStream\Vodres.dll (PPS 动态链接库/PPStream Inc.)
    .text D:\PPS.tv\PPStream\PPSAP.exe[1704] kernel32.dll!SetFilePointer 7657060D 5 Bytes JMP 10028830 D:\PPS.tv\PPStream\Vodres.dll (PPS 动态链接库/PPStream Inc.)
    .text D:\PPS.tv\PPStream\PPSAP.exe[1704] kernel32.dll!WriteFile 765753EE 5 Bytes JMP 10028730 D:\PPS.tv\PPStream\Vodres.dll (PPS 动态链接库/PPStream Inc.)
    .text D:\PPS.tv\PPStream\PPSAP.exe[1704] kernel32.dll!OpenFile 7657D54F 5 Bytes JMP 100287E2 D:\PPS.tv\PPStream\Vodres.dll (PPS 动态链接库/PPStream Inc.)
    .text D:\PPS.tv\PPStream\PPSAP.exe[1704] kernel32.dll!ReadFileEx 76585515 5 Bytes JMP 100286D7 D:\PPS.tv\PPStream\Vodres.dll (PPS 动态链接库/PPStream Inc.)
    .text D:\PPS.tv\PPStream\PPSAP.exe[1704] kernel32.dll!WriteFileEx 7658552D 5 Bytes JMP 10028789 D:\PPS.tv\PPStream\Vodres.dll (PPS 动态链接库/PPStream Inc.)

    ---- User IAT/EAT - GMER 1.0.15 ----

    IAT C:\Windows\Explorer.EXE[1924] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [74192437] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1924] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [74175600] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1924] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [741756BE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1924] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [741924B2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1924] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [74188514] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1924] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [74184CC8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1924] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [7418506F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1924] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [74185144] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1924] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [74186671] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1924] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [7418826B] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1924] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [741887BA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1924] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [7418901B] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1924] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [7418E1BE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1924] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [74184BFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[3520] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [7557FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
    IAT C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[3520] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [7557FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
    IAT C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[3520] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [7557FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
    IAT C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[3520] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [7557FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
    IAT C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[3520] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [7557FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)

    ---- Registry - GMER 1.0.15 ----

    Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
    Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
    Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x9C 0x75 0x9F 0xE4 ...
    Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xC6 0x27 0x44 0x7C ...
    Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x12 0xC7 0xB9 0x15 ...
    Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x79 0x97 0x56 0x9B ...
    Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@hdf12 0x7D 0x06 0xDF 0x61 ...
    Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@a0 0x20 0x01 0x00 0x00 ...
    Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0@hdf12 0x66 0xBD 0x11 0x05 ...
    Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq1 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq1@hdf12 0x79 0x97 0x56 0x9B ...
    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x9C 0x75 0x9F 0xE4 ...
    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xC6 0x27 0x44 0x7C ...
    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x12 0xC7 0xB9 0x15 ...
    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1
    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x79 0x97 0x56 0x9B ...
    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002
    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@hdf12 0x7D 0x06 0xDF 0x61 ...
    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@a0 0x20 0x01 0x00 0x00 ...
    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0
    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0@hdf12 0x55 0x30 0x9D 0x55 ...
    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq1
    Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq1@hdf12 0x79 0x97 0x56 0x9B ...
    Reg HKLM\SYSTEM\ControlSet005\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet005\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
    Reg HKLM\SYSTEM\ControlSet005\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
    Reg HKLM\SYSTEM\ControlSet005\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x9C 0x75 0x9F 0xE4 ...
    Reg HKLM\SYSTEM\ControlSet005\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet005\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xC6 0x27 0x44 0x7C ...
    Reg HKLM\SYSTEM\ControlSet005\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet005\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x12 0xC7 0xB9 0x15 ...
    Reg HKLM\SYSTEM\ControlSet005\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet005\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x79 0x97 0x56 0x9B ...
    Reg HKLM\SYSTEM\ControlSet005\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet005\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@hdf12 0x7D 0x06 0xDF 0x61 ...
    Reg HKLM\SYSTEM\ControlSet005\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002@a0 0x20 0x01 0x00 0x00 ...
    Reg HKLM\SYSTEM\ControlSet005\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet005\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0@hdf12 0x55 0x30 0x9D 0x55 ...
    Reg HKLM\SYSTEM\ControlSet005\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq1 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet005\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq1@hdf12 0x79 0x97 0x56 0x9B ...
    Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4AEBADBC-27F3-4299-A8B4-22FE6B92CAAD}
    Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4AEBADBC-27F3-4299-A8B4-22FE6B92CAAD}
    Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4AEBADBC-27F3-4299-A8B4-22FE6B92CAAD}@Path \Microsoft\Windows Defender\MP Scheduled Scan
    Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4AEBADBC-27F3-4299-A8B4-22FE6B92CAAD}@Hash 0x0C 0xAD 0x40 0x9E ...
    Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4AEBADBC-27F3-4299-A8B4-22FE6B92CAAD}@Triggers 0x15 0x00 0x00 0x00 ...
    Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4AEBADBC-27F3-4299-A8B4-22FE6B92CAAD}@DynamicInfo 0x03 0x00 0x00 0x00 ...
    Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows Defender\MP Scheduled Scan@Id {4AEBADBC-27F3-4299-A8B4-22FE6B92CAAD}
    Reg HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted@C:\Users\Terence\Downloads\Steganos Internet Anonym\x2122 VPN+Serials-HeartBug\Setup.exe 1
    Reg HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted@C:\Program Files\ 1

    ---- Files - GMER 1.0.15 ----

    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\28.jpg 23924 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\1.jpg 39459 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\10.JPG 17207 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\11.jpg 17493 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\12.jpg 21628 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\13.jpg 37374 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\14.jpg 36456 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\15.jpg 47588 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\16.jpg 45148 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\17.jpg 52847 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\18.jpg 66813 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\19.jpg 36799 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\2.jpg 127634 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\20.jpg 30108 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\21.jpg 16641 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\22.jpg 26209 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\23.jpg 24836 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\24.jpg 42390 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\25.jpg 42585 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\26.jpg 43536 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\27.jpg 78000 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\29.jpg 22022 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\3.jpg 126918 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\30.jpg 19723 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\31.jpg 23735 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\32.jpg 31901 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\33.jpg 29028 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\34.jpg 32086 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\35.jpg 31538 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\36.jpg 39662 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\37.jpg 45480 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\38.jpg 45145 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\39.jpg 49767 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\4.jpg 103883 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\40.jpg 37361 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\41.jpg 14695 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\42.jpg 32618 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\43.jpg 59599 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\5.jpg 28927 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\6.jpg 21915 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\7.jpg 22255 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\8.jpg 87852 bytes
    File C:\Users\Terence\Downloads\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\Clara Adheline Supit a.k.a. Dewi Sartika Nude Photos Exposed On Facebook, Indonesian Model And BINUS Student Leaked Picture Scandal\9.JPG 18750 bytes

    ---- EOF - GMER 1.0.15 ----
     
  5. 2011/10/02
    terencew

    terencew Inactive Thread Starter

    Joined:
    2011/09/29
    Messages:
    34
    Likes Received:
    0
    3. aswMBR log

    aswMBR version 0.9.8.986 Copyright(c) 2011 AVAST Software
    Run date: 2011-10-02 15:48:48
    -----------------------------
    15:48:48.140 OS Version: Windows 6.1.7601 Service Pack 1
    15:48:48.140 Number of processors: 2 586 0x2302
    15:48:48.140 ComputerName: TERENCE-PC UserName: Terence
    15:49:03.609 Initialize success
    15:49:28.984 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP4T0L0-8
    15:49:28.984 Disk 0 Vendor: SAMSUNG_HD103UJ 1AA01118 Size: 953869MB BusType: 3
    15:49:28.984 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP5T0L0-a
    15:49:29.000 Disk 1 Vendor: WDC_WD5000KS-00MNB0 07.02E07 Size: 476940MB BusType: 3
    15:49:31.000 Disk 0 MBR read successfully
    15:49:31.000 Disk 0 MBR scan
    15:49:31.000 Disk 0 Windows 7 default MBR code
    15:49:31.015 Disk 0 scanning sectors +1953521664
    15:49:31.078 Disk 0 scanning C:\Windows\system32\drivers
    15:49:36.437 Service scanning
    15:49:37.843 Modules scanning
    15:49:42.281 Disk 0 trace - called modules:
    15:49:42.296 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
    15:49:42.312 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85b68030]
    15:49:42.312 3 CLASSPNP.SYS[87da759e] -> nt!IofCallDriver -> [0x856bc918]
    15:49:42.328 5 ACPI.sys[8779b3d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP4T0L0-8[0x856c5030]
    15:49:42.343 Scan finished successfully
    15:50:40.015 Disk 0 MBR has been saved successfully to "C:\Users\Terence\Desktop\MBR.dat "
    15:50:40.031 The log file has been saved successfully to "C:\Users\Terence\Desktop\aswMBR.txt "


    aswMBR version 0.9.8.986 Copyright(c) 2011 AVAST Software
    Run date: 2011-10-02 20:08:56
    -----------------------------
    20:08:56.299 OS Version: Windows 6.1.7601 Service Pack 1
    20:08:56.299 Number of processors: 2 586 0x2302
    20:08:56.315 ComputerName: TERENCE-PC UserName: Terence
    20:09:15.925 Initialize success
    20:09:23.766 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP5T0L0-5
    20:09:23.766 Disk 0 Vendor: WDC_WD5000KS-00MNB0 07.02E07 Size: 476940MB BusType: 3
    20:09:23.766 Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP4T0L0-4
    20:09:23.766 Disk 1 Vendor: SAMSUNG_HD103UJ 1AA01118 Size: 953869MB BusType: 3
    20:09:25.797 Disk 1 MBR read successfully
    20:09:25.797 Disk 1 MBR scan
    20:09:25.797 Disk 1 Windows 7 default MBR code
    20:09:25.813 Disk 1 scanning sectors +1953521664
    20:09:25.969 Disk 1 scanning C:\Windows\system32\drivers
    20:09:37.417 Service scanning
    20:09:41.511 Modules scanning
    20:10:04.079 Disk 1 trace - called modules:
    20:10:04.110 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
    20:10:04.110 1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0x86b73030]
    20:10:04.125 3 CLASSPNP.SYS[889a259e] -> nt!IofCallDriver -> [0x86abd918]
    20:10:04.141 5 ACPI.sys[84dbc3d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP4T0L0-4[0x86706030]
    20:10:04.141 Scan finished successfully
    20:10:10.281 Disk 1 MBR has been saved successfully to "C:\Users\Terence\Desktop\MBR.dat "
    20:10:10.312 The log file has been saved successfully to "C:\Users\Terence\Desktop\aswMBR.txt "
     
  6. 2011/10/02
    terencew

    terencew Inactive Thread Starter

    Joined:
    2011/09/29
    Messages:
    34
    Likes Received:
    0
    4. DDS log with attach:

    DDS Log

    .
    DDS (Ver_2011-08-26.01) - NTFSx86
    Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_22
    Run by Terence at 20:22:48 on 2011-10-02
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\atiesrxx.exe
    C:\Windows\system32\atieclxx.exe
    C:\Windows\system32\WUDFHost.exe
    C:\Windows\system32\WUDFHost.exe
    C:\Windows\System32\spoolsv.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Windows\system32\crypserv.exe
    C:\Program Files\CyberLink\Shared files\RichVideo.exe
    C:\Windows\system32\locator.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Windows\SOUNDMAN.EXE
    C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
    C:\Program Files\Logitech\GamePanel Software\LGDevAgt.exe
    C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
    C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
    C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
    C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Windows\System32\alg.exe
    C:\Program Files\Microsoft IntelliType Pro\itype.exe
    C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
    C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\uTorrent\uTorrent.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    D:\PPS.tv\PPStream\PPSAP.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
    C:\Program Files\Logitech\SetPoint\SetPoint.exe
    C:\Program Files\PPLive\PPTV\PPLive.exe
    C:\Program Files\Common Files\PPLiveNetwork\PPAP.exe
    C:\Windows\system32\taskhost.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
    C:\Windows\system32\WUDFHost.exe
    \\?\C:\Windows\system32\wbem\WMIADAP.EXE
    C:\Users\Terence\Desktop\dds.scr
    C:\Windows\system32\conhost.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\System32\svchost.exe -k secsvcs
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    .
    ============== Pseudo HJT Report ===============
    .
    uInternet Settings,ProxyOverride = *.local
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2012\ievkbd.dll
    BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office14\GROOVEEX.DLL
    BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~2\office14\URLREDIR.DLL
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky internet security 2012\klwtbbho.dll
    uRun: [VeohPlugin] "c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe "
    uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
    uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
    uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe "
    uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
    uRun: [DAEMON Tools Pro Agent] "c:\program files\daemon tools pro\DTProAgent.exe "
    uRun: [PPS Accelerator] d:\pps.tv\ppstream\ppsap.exe
    uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
    uRun: [PPAP] "c:\program files\common files\pplivenetwork\PPAP.exe" -background
    mRun: [SoundMan] SOUNDMAN.EXE
    mRun: [UpdatePDRShortCut] "c:\program files\cyberlink\powerdirector\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\powerdirector" updatewithcreateonce "software\cyberlink\powerdirector\8.0 "
    mRun: [PaperPort PTD] "c:\program files\scansoft\paperport\pptd40nt.exe "
    mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe "
    mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun
    mRun: [Launch LgDeviceAgent] "c:\program files\logitech\gamepanel software\LgDevAgt.exe "
    mRun: [Launch LCDMon] "c:\program files\logitech\gamepanel software\lcd manager\LCDMon.exe "
    mRun: [Launch LGDCore] "c:\program files\logitech\gamepanel software\g-series software\LGDCore.exe" /SHOWHIDE
    mRun: [BrMfcWnd] c:\program files\brother\brmfcmon\BrMfcWnd.exe /AUTORUN
    mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe "
    mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe "
    mRun: [RIMBBLaunchAgent.exe] c:\program files\common files\research in motion\usb drivers\RIMBBLaunchAgent.exe
    mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
    mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
    mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
    mPolicies-system: EnableLUA = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
    IE: &Save Flash In This Page by Flash Saver
    IE: E&xport to Microsoft Excel
    IE: S&end to OneNote
    IE: 使用迅雷下载
    IE: 使用迅雷下载全部链接
    IE: {09EA1F80-F40A-11D1-B792-444553540001} - c:\progra~1\flashs~1\save.htm
    IE: {95B3F550-91C4-4627-BCC4-521288C52977} - c:\program files\pplive\pptv\PPLive.exe
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
    IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - c:\program files\kaspersky lab\kaspersky internet security 2012\ievkbd.dll
    IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
    IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky internet security 2012\klwtbbho.dll
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    Trusted Zone: pps.tv
    Trusted Zone: ppstream.com
    Trusted Zone: webscache.com
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
    TCP: Interfaces\{22F05C82-54A4-40D4-9C65-FE747C8FA511} : DhcpNameServer = 192.168.0.1
    TCP: Interfaces\{884D7921-C814-4B29-96AD-AD9B04ABF6E7} : DhcpNameServer = 192.168.0.1
    Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
    Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
    Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
    Notify: klogon - c:\windows\system32\klogon.dll
    Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
    SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office14\GROOVEEX.DLL
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - c:\users\terence\appdata\roaming\mozilla\firefox\profiles\goad6cdl.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2653012&SearchSource=3&q={searchTerms}
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
    FF - prefs.js: keyword.URL - hxxp://www.google.com.au/search?q=
    FF - plugin: c:\progra~1\micros~2\office14\NPAUTHZ.DLL
    FF - plugin: c:\progra~1\micros~2\office14\NPSPWRAP.DLL
    FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll
    FF - plugin: c:\program files\common files\thunder network\kankan\npDapCtrlFirefox.2.0.5901.12.(806).dll
    FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
    FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll
    FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
    FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
    FF - plugin: c:\program files\veoh networks\veohwebplayer\npWebPlayerVideoPluginATL.dll
    FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
    FF - plugin: c:\program files\windows media player\np-mswmp.dll
    FF - plugin: c:\programdata\nexonus\ngm\npNxGameUS.dll
    FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
    .
    ---- FIREFOX POLICIES ----
    FF - user.js: network.cookie.cookieBehavior - 0
    FF - user.js: privacy.clearOnShutdown.cookies - false
    FF - user.js: security.warn_viewing_mixed - false
    FF - user.js: security.warn_viewing_mixed.show_once - false
    FF - user.js: security.warn_submit_insecure - false
    FF - user.js: security.warn_submit_insecure.show_once - false
    .
    ============= SERVICES / DRIVERS ===============
    .
    R? AODDriver4.0;AODDriver4.0
    R? atyle;atyle
    R? AVP;Kaspersky Anti-Virus Service
    R? b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0
    R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86
    R? gupdate;Google Update Service (gupdate)
    R? gupdatem;Google Update Service (gupdatem)
    R? hname;hname
    R? kl2;kl2
    R? KLIM6;Kaspersky Anti-Virus NDIS 6 Filter
    R? klmdb;klmdb
    R? klmouflt;Kaspersky Lab KLMOUFLT
    R? KMService;KMService
    R? Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service
    R? npggsvc;nProtect GameGuard Service
    R? osppsvc;Office Software Protection Platform
    R? RdpVideoMiniport;Remote Desktop Video Miniport Driver
    R? Synth3dVsc;Synth3dVsc
    R? TsUsbFlt;TsUsbFlt
    R? tsusbhub;tsusbhub
    R? VGPU;VGPU
    R? WatAdminSvc;Windows Activation Technologies Service
    R? whqeht;whqeht
    S? AMD External Events Utility;AMD External Events Utility
    S? AMD FUEL Service;AMD FUEL Service
    S? amdiox86;AMD IO Driver
    S? amdkmdag;amdkmdag
    S? amdkmdap;amdkmdap
    S? AtiHDAudioService;ATI Function Driver for HD Audio Service
    S? DKRtWrt;DKRtWrt
    S? LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter
    S? LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver
    S? LGVirHid;Logitech Gamepanel Virtual HID Device Driver
    S? LHidEqd;Logitech SetPoint Unifying KMDF HID Filter
    S? SBSDWSCService;SBSD Security Center Service
    S? vwififlt;Virtual WiFi Filter Driver
    .
    =============== Created Last 30 ================
    .
    2011-10-02 05:18:25 -------- d-sh--w- C:\$RECYCLE.BIN
    2011-10-02 05:18:19 -------- d-----w- c:\users\terence\appdata\local\temp
    2011-10-02 05:04:47 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2011-10-02 05:02:31 -------- d-----w- c:\users\terence\appdata\local\{F49790BA-A3CA-4F89-BF80-B8EBA42771F4}
    2011-10-02 04:51:57 -------- d-----w- c:\users\terence\appdata\roaming\Logishrd
    2011-10-02 04:29:14 6273872 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{e63e96e9-54d9-4799-8ed4-e19bb47c4cc9}\mpengine.dll
    2011-10-02 04:28:37 -------- d-----w- c:\users\terence\appdata\local\{3E750FEB-DEE9-47AC-B6C2-C436D0EAF54B}
    2011-10-02 04:28:15 -------- d-----w- c:\users\terence\appdata\local\{956A8F81-29B9-4B23-8C05-A80C2C4EBB80}
    2011-10-02 04:28:15 -------- d-----w- c:\users\terence\appdata\local\{3D6388C1-FE00-43DE-AE05-8DBF44A2B402}
    2011-09-30 08:36:31 -------- d-----w- c:\users\terence\appdata\local\{645CD13A-9005-47A6-BFC3-62D2966DAA94}
    2011-09-30 08:36:02 -------- d-----w- c:\users\terence\appdata\local\{F644A717-1294-43AC-951B-B39F4ACB3493}
    2011-09-30 08:19:14 -------- d-----w- c:\users\terence\appdata\local\{C25FC346-9B21-425F-B20C-59A49AFEE925}
    2011-09-29 21:30:14 -------- d-----w- C:\symbols
    2011-09-29 21:26:05 -------- d-----w- c:\program files\Debugging Tools for Windows (x86)
    2011-09-29 20:53:25 524288 ----a-w- C:\A8NSB014.BIN
    2011-09-29 19:38:06 -------- d-----w- c:\users\terence\appdata\local\{C3CACA81-292F-4A6B-9AF0-1E7CC404F9D0}
    2011-09-29 19:37:55 -------- d-----w- c:\users\terence\appdata\local\{A476766A-5585-4BB5-8E15-3DB9BD5D38FE}
    2011-09-29 19:27:26 -------- d--h--w- c:\windows\PIF
    2011-09-29 17:43:01 225280 ----a-w- c:\program files\common files\installshield\iscript\iscript.dll
    2011-09-29 17:43:00 77824 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ctor.dll
    2011-09-29 17:43:00 32768 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\objectps.dll
    2011-09-29 17:43:00 176128 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\iuser.dll
    2011-09-29 17:42:59 614532 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\IKernel.exe
    2011-09-29 13:45:07 -------- d-----w- c:\program files\common files\ATI Technologies
    2011-09-29 13:43:23 -------- d-----w- c:\program files\ATI Technologies
    2011-09-29 13:43:21 -------- d-----w- c:\program files\ATI
    2011-09-29 09:07:49 56496 ----a-w- c:\windows\system32\wbhelp2.dll
    2011-09-29 09:07:49 544768 ----a-w- c:\windows\system32\wbocx.ocx
    2011-09-29 09:07:49 4608 ----a-w- c:\windows\system32\W95INF32.DLL
    2011-09-29 09:07:49 33968 ----a-w- c:\windows\system32\anim.dll
    2011-09-29 09:07:49 2272 ----a-w- c:\windows\system32\W95INF16.DLL
    2011-09-29 09:07:49 -------- d-----w- c:\program files\WinUtilities
    2011-09-29 07:37:15 -------- d-----w- c:\users\terence\appdata\local\{D910ADA1-F8B7-4999-BCB7-F51097C882D3}
    2011-09-29 07:36:55 -------- d-----w- c:\users\terence\appdata\local\{AAF2E2A3-42B5-4EE3-9E10-8070100FA41C}
    2011-09-28 19:31:50 -------- d-----w- c:\users\terence\appdata\local\{E84210E9-0764-4AC2-83AA-074891BDC402}
    2011-09-28 19:31:23 -------- d-----w- c:\users\terence\appdata\local\{647310DD-E641-4FDC-AB27-CDDF9F420386}
    2011-09-28 07:10:18 -------- d-----w- c:\users\terence\appdata\local\{5118B93A-B915-4C40-AB19-7B5CAFABA72E}
    2011-09-28 07:09:45 -------- d-----w- c:\users\terence\appdata\local\{DD2F136D-43E5-4E26-ABE3-B6D9C2EDB92C}
    2011-09-27 18:03:02 -------- d-----w- c:\users\terence\appdata\local\{BC460F1B-BF18-4FB0-906C-EBBFFB2B2620}
    2011-09-27 18:02:50 -------- d-----w- c:\users\terence\appdata\local\{6F3A0AE2-4E1C-4A74-A8D8-01A0CB270B9F}
    2011-09-27 15:56:59 -------- d-----w- c:\programdata\ProcessLasso
    2011-09-27 06:02:17 -------- d-----w- c:\users\terence\appdata\local\{D0F35366-D2D7-4E7E-B3D2-7D9C0533E673}
    2011-09-27 06:02:02 -------- d-----w- c:\users\terence\appdata\local\{6A25AFDC-50EB-41DE-B6D5-0D1E7D4A365C}
    2011-09-26 18:00:13 -------- d-----w- c:\users\terence\appdata\local\{CCEEF399-D782-4690-AB83-2ECA53F7DC66}
    2011-09-26 18:00:01 -------- d-----w- c:\users\terence\appdata\local\{C125B9C9-F746-4278-A916-9AA637377589}
    2011-09-26 05:59:21 -------- d-----w- c:\users\terence\appdata\local\{7D16ADAF-0EC3-4A52-A205-9A50FEA2724C}
    2011-09-26 05:59:04 -------- d-----w- c:\users\terence\appdata\local\{181B0FB2-6486-4331-9D35-2E6A93EC275F}
    2011-09-25 17:58:47 -------- d-----w- c:\users\terence\appdata\local\{1EB9AA79-437C-403E-86E6-447E122A099A}
    2011-09-25 17:58:35 -------- d-----w- c:\users\terence\appdata\local\{18A64032-A529-4068-BCA4-67B071F05206}
    2011-09-25 05:58:10 -------- d-----w- c:\users\terence\appdata\local\{734A2576-9213-4031-9CAF-370C668FD8EB}
    2011-09-25 05:57:54 -------- d-----w- c:\users\terence\appdata\local\{FAC42487-7BE8-4539-B460-723B03A680A4}
    2011-09-24 17:57:35 -------- d-----w- c:\users\terence\appdata\local\{0A1E03CD-6266-45C8-942F-A7173D7C224F}
    2011-09-24 17:57:22 -------- d-----w- c:\users\terence\appdata\local\{C809D6D5-F65E-4C9E-B02A-436D08B8DBB6}
    2011-09-24 05:57:06 -------- d-----w- c:\users\terence\appdata\local\{77103622-197E-4E4C-8D63-6A3F242904A7}
    2011-09-24 05:56:52 -------- d-----w- c:\users\terence\appdata\local\{2B7EC4AC-30E9-40C6-BFDB-31563F8868F0}
    2011-09-23 17:56:37 -------- d-----w- c:\users\terence\appdata\local\{943B5A46-40AB-4A96-88F3-189FB238A958}
    2011-09-23 17:56:24 -------- d-----w- c:\users\terence\appdata\local\{A73691F8-8B78-4695-ACFE-EDA3A8EB2E76}
    2011-09-23 05:56:06 -------- d-----w- c:\users\terence\appdata\local\{AB79B87F-B8E1-4369-8027-06C1B367A006}
    2011-09-23 05:55:51 -------- d-----w- c:\users\terence\appdata\local\{2850428C-60B0-40B1-812D-0F0800DB8333}
    2011-09-22 17:55:35 -------- d-----w- c:\users\terence\appdata\local\{3A5CA02C-E3BD-4178-BFD0-9CF838E4CF8C}
    2011-09-22 17:55:10 -------- d-----w- c:\users\terence\appdata\local\{B55E6D35-4E45-4503-8F34-689C61290C83}
    2011-09-22 05:54:49 -------- d-----w- c:\users\terence\appdata\local\{4801F38C-1A64-4C51-90C8-AE574D6D301D}
    2011-09-22 05:54:35 -------- d-----w- c:\users\terence\appdata\local\{48EF1891-884D-48A6-9F08-044297726FF3}
    2011-09-22 03:24:44 -------- d-----w- c:\program files\Gravity
    2011-09-21 17:54:16 -------- d-----w- c:\users\terence\appdata\local\{C023E8C0-3FEC-476C-9A55-B0A8D7EF8505}
    2011-09-21 17:54:03 -------- d-----w- c:\users\terence\appdata\local\{70C643A2-441E-47CF-B733-1D5281E2178B}
    2011-09-21 13:44:19 -------- d---a-w- C:\out
    2011-09-21 05:52:34 -------- d-----w- c:\users\terence\appdata\local\{2E5D7CBC-2E2E-4966-8D1E-C109E8679298}
    2011-09-21 05:52:20 -------- d-----w- c:\users\terence\appdata\local\{110C35D6-F6D4-4C0F-8082-134DC6930A48}
    2011-09-20 17:53:27 -------- d-----w- c:\users\terence\appdata\local\{5DFCD29D-D6FC-4E98-881B-AA774C1A322F}
    2011-09-20 17:53:15 -------- d-----w- c:\users\terence\appdata\local\{450DDCC7-9C7E-40A7-88BB-877473A584A2}
    2011-09-20 05:52:58 -------- d-----w- c:\users\terence\appdata\local\{C87057CF-8BC2-497E-9748-9E2AFC97526D}
    2011-09-20 05:52:46 -------- d-----w- c:\users\terence\appdata\local\{4ADEFD18-CB4D-4F5F-8EE6-00A8C6098F11}
    2011-09-19 17:52:31 -------- d-----w- c:\users\terence\appdata\local\{50429CDF-1AD3-4D17-A537-9FA631427E9F}
    2011-09-19 17:52:18 -------- d-----w- c:\users\terence\appdata\local\{52013A4E-C32D-435B-882E-DDE39AFCAC20}
    2011-09-19 07:41:17 -------- d-----w- c:\users\terence\appdata\roaming\com.essexreddevelopment.mergepdfmac
    2011-09-19 05:51:47 -------- d-----w- c:\users\terence\appdata\local\{C0139CF9-FF6C-46D0-9551-5554E8DCEEF7}
    2011-09-19 05:51:31 -------- d-----w- c:\users\terence\appdata\local\{DED0F41B-9E97-4B00-BB63-F18FE7B42177}
    2011-09-18 17:51:10 -------- d-----w- c:\users\terence\appdata\local\{087603D7-42AB-4100-B47D-B3181C6E2031}
    2011-09-18 17:50:53 -------- d-----w- c:\users\terence\appdata\local\{1DBB247C-9E43-4D40-A6C9-F889AF754D0B}
    2011-09-18 11:42:51 -------- d-----w- c:\users\terence\appdata\roaming\Gatling Gears
    2011-09-18 05:50:38 -------- d-----w- c:\users\terence\appdata\local\{55560099-8028-45B7-A297-47561A0F552B}
    2011-09-18 05:50:26 -------- d-----w- c:\users\terence\appdata\local\{7586543C-1307-4A3F-85FE-5604DC7F6AAD}
    2011-09-17 17:50:11 -------- d-----w- c:\users\terence\appdata\local\{6E6EC004-41A0-4C09-AB86-06A2CC17B778}
    2011-09-17 17:49:59 -------- d-----w- c:\users\terence\appdata\local\{D67013E5-060C-45E0-BACC-8BDE24E48409}
    2011-09-17 07:30:54 -------- d-----w- c:\program files\AhnLab
    2011-09-17 05:49:43 -------- d-----w- c:\users\terence\appdata\local\{558C9AEE-D0A7-4552-85DA-BA0892549753}
    2011-09-17 05:49:30 -------- d-----w- c:\users\terence\appdata\local\{61D0277F-F2AB-4404-9BCC-CC7F3DF23AC5}
    2011-09-16 17:49:01 -------- d-----w- c:\users\terence\appdata\local\{B641AB8E-0F9B-482D-BCED-2A584FE643A5}
    2011-09-16 17:48:47 -------- d-----w- c:\users\terence\appdata\local\{FA4BBBF7-EF20-42B1-835A-4EFB93A004A0}
    2011-09-16 05:48:29 -------- d-----w- c:\users\terence\appdata\local\{4D186F93-CBA3-4875-B95E-BC18CF04F753}
    2011-09-16 05:48:14 -------- d-----w- c:\users\terence\appdata\local\{DBA51A7F-B209-47C1-B78D-DCC0739114B0}
    2011-09-15 17:46:34 -------- d-----w- c:\users\terence\appdata\local\{CA6C3736-5F50-4DB7-B360-14931EE4B578}
    2011-09-15 17:46:20 -------- d-----w- c:\users\terence\appdata\local\{1BC4AEED-E888-420A-B589-95DCDDAEA55C}
    2011-09-15 05:45:50 -------- d-----w- c:\users\terence\appdata\local\{29DD05BC-ADC1-483F-8984-FDD6883CE68C}
    2011-09-15 05:45:37 -------- d-----w- c:\users\terence\appdata\local\{DD759176-51A6-44AC-BC5B-21BFA2CB8D51}
    2011-09-15 02:39:38 -------- d-----w- c:\users\terence\appdata\local\Ubisoft Game Launcher
    2011-09-15 02:39:32 -------- d-----w- c:\users\terence\appdata\local\SKIDROW
    2011-09-14 17:45:22 -------- d-----w- c:\users\terence\appdata\local\{97DAEFAF-952F-4496-A6B6-65DE48E40D57}
    2011-09-14 17:45:09 -------- d-----w- c:\users\terence\appdata\local\{8E521DD9-490B-41B7-9C9F-233E1E123ED9}
    2011-09-14 11:32:15 -------- d-----w- c:\program files\Hard Disk Sentinel
    2011-09-14 05:44:35 -------- d-----w- c:\users\terence\appdata\local\{35BC6799-3E54-4E34-8799-62C66A6F34E7}
    2011-09-14 05:44:20 -------- d-----w- c:\users\terence\appdata\local\{AF1E8AB8-61F5-4770-A635-C92481FDFEAC}
    2011-09-14 02:17:40 53760 ----a-w- c:\windows\system32\OVDecode.dll
    2011-09-14 02:16:58 13625856 ----a-w- c:\windows\system32\amdocl.dll
    2011-09-14 02:08:28 37376 ----a-w- c:\windows\system32\amdoclcl.dll
    2011-09-13 17:44:05 -------- d-----w- c:\users\terence\appdata\local\{24D11011-C7D9-4525-AEC3-B8A849F94F37}
    2011-09-13 17:43:53 -------- d-----w- c:\users\terence\appdata\local\{ED38DCB8-8DE9-4AA7-BD2A-A421FE712F54}
    2011-09-13 05:43:21 -------- d-----w- c:\users\terence\appdata\local\{45526B55-4F2B-4661-8A09-75C849D7E620}
    2011-09-13 05:43:05 -------- d-----w- c:\users\terence\appdata\local\{0771B12A-9F31-4593-85D3-225FADCB21EC}
    2011-09-12 17:42:50 -------- d-----w- c:\users\terence\appdata\local\{495B040D-9EF7-4CDE-8EBB-946E6E6F9ACA}
    2011-09-12 17:42:31 -------- d-----w- c:\users\terence\appdata\local\{20304278-F99C-4DA3-A135-14696ABF72B5}
    2011-09-12 05:42:02 -------- d-----w- c:\users\terence\appdata\local\{055327EF-7142-430E-B901-67CF6466E5BB}
    2011-09-12 05:41:50 -------- d-----w- c:\users\terence\appdata\local\{29D69CC8-10AC-41B5-B838-97612C6C23EC}
    2011-09-11 17:41:35 -------- d-----w- c:\users\terence\appdata\local\{8096FC72-13EE-4A8D-9E06-4B8842D0BE74}
    2011-09-11 17:41:23 -------- d-----w- c:\users\terence\appdata\local\{715A5746-E6A1-46A9-9D8E-456457D67D0E}
    2011-09-11 05:41:08 -------- d-----w- c:\users\terence\appdata\local\{59FDEC43-769B-4C47-85FD-E65781865EA6}
    2011-09-11 05:40:56 -------- d-----w- c:\users\terence\appdata\local\{2DE3100C-3E7B-4EC6-99C5-45534ABAB493}
    2011-09-10 17:40:40 -------- d-----w- c:\users\terence\appdata\local\{FBB12325-38C0-41A8-B9AC-A947711454C1}
    2011-09-10 17:40:26 -------- d-----w- c:\users\terence\appdata\local\{C05E8398-CCCB-456F-A483-C645C33B4581}
    2011-09-10 05:40:11 -------- d-----w- c:\users\terence\appdata\local\{8B5D86D4-FEB1-4636-BD3B-31EE26B9B5BE}
    2011-09-10 05:39:56 -------- d-----w- c:\users\terence\appdata\local\{777741C9-F94F-4721-B936-41881028D062}
    2011-09-09 17:39:26 -------- d-----w- c:\users\terence\appdata\local\{02856537-B761-4639-8D16-1F969800A8C9}
    2011-09-09 17:39:12 -------- d-----w- c:\users\terence\appdata\local\{37B355FD-B417-449E-AD7E-6ACF022EC708}
    2011-09-09 05:38:53 -------- d-----w- c:\users\terence\appdata\local\{5BC8E909-CE84-47C7-B3C3-5F8B00EA36B6}
    2011-09-09 05:38:36 -------- d-----w- c:\users\terence\appdata\local\{E299C440-937E-4631-9961-4ED3E6AD2154}
    2011-09-08 18:26:10 8606208 ----a-w- c:\windows\system32\drivers\atikmdag.sys
    2011-09-08 17:39:44 18534912 ----a-w- c:\windows\system32\atioglxx.dll
    2011-09-08 17:34:30 -------- d-----w- c:\users\terence\appdata\local\{E13264A9-6EB7-4324-B3C7-698581A8FCBB}
    2011-09-08 17:34:20 151552 ----a-w- c:\windows\system32\atiapfxx.exe
    2011-09-08 17:34:06 -------- d-----w- c:\users\terence\appdata\local\{8AA111FC-5E2F-479B-B097-C53235640F45}
    2011-09-08 17:32:49 110992 ----a-w- c:\program files\mozilla firefox\extensions\kavantibanner@kaspersky.ru_bak2\components\abhelperxpcom.dll
    2011-09-08 17:32:48 147856 ----a-w- c:\program files\mozilla firefox\extensions\linkfilter@kaspersky.ru_bak2\components\kavlinkfilter.dll
    2011-09-08 17:30:38 466944 ----a-w- c:\windows\system32\ATIDEMGX.dll
    2011-09-08 17:30:10 401408 ----a-w- c:\windows\system32\atieclxx.exe
    2011-09-08 17:29:46 176128 ----a-w- c:\windows\system32\atiesrxx.exe
    2011-09-08 17:28:46 159744 ----a-w- c:\windows\system32\atitmmxx.dll
    2011-09-08 17:28:32 356352 ----a-w- c:\windows\system32\atipdlxx.dll
    2011-09-08 17:28:22 278528 ----a-w- c:\windows\system32\Oemdspif.dll
    2011-09-08 17:28:16 20992 ----a-w- c:\windows\system32\atimuixx.dll
    2011-09-08 17:28:10 43520 ----a-w- c:\windows\system32\ati2edxx.dll
    2011-09-08 17:18:22 1828864 ----a-w- c:\windows\system32\atiumdmv.dll
    2011-09-08 17:09:40 46080 ----a-w- c:\windows\system32\aticalrt.dll
    2011-09-08 17:09:28 44032 ----a-w- c:\windows\system32\aticalcl.dll
    2011-09-08 17:05:52 7331840 ----a-w- c:\windows\system32\aticaldd.dll
    2011-09-08 16:52:56 13312 ----a-w- c:\windows\system32\atiglpxx.dll
    2011-09-08 16:52:46 32768 ----a-w- c:\windows\system32\atigktxx.dll
    2011-09-08 16:52:20 248832 ----a-w- c:\windows\system32\drivers\atikmpag.sys
    2011-09-08 16:51:12 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
    2011-09-08 16:50:54 53760 ----a-w- c:\windows\system32\atimpc32.dll
    2011-09-08 16:50:54 53760 ----a-w- c:\windows\system32\amdpcom32.dll
    2011-09-08 13:07:56 -------- d-----w- c:\users\terence\appdata\local\dxhr
    2011-09-08 07:15:04 -------- d-----w- c:\users\terence\appdata\local\28050
    2011-09-08 05:33:27 -------- d-----w- c:\program files\Square Enix
    2011-09-08 05:29:32 -------- d-----w- c:\users\terence\appdata\local\{06C1A98F-2C6D-480A-9DD1-F7827618532C}
    2011-09-08 05:28:58 -------- d-----w- c:\users\terence\appdata\local\{C40AD283-0C1F-4150-954F-CB324ABDC0F9}
    2011-09-06 17:31:14 -------- d-----w- C:\fc0ba4149eb9e6c0caf077f138
    2011-09-06 16:00:01 -------- d-----w- c:\users\terence\vitamin base material_files
    2011-09-04 06:20:16 -------- d-----w- c:\users\terence\appdata\local\{262586AC-6EB4-4AFD-B41C-3BFC1E412A39}
    2011-09-04 06:19:40 -------- d-----w- c:\users\terence\appdata\local\{1E7BA4DD-C5CB-411E-BF4D-4F15D67B859F}
    .
    ==================== Find3M ====================
    .
    2011-09-26 11:57:49 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2011-09-08 17:34:10 732672 ----a-w- c:\windows\system32\aticfx32.dll
    2011-09-08 17:24:38 4204032 ----a-w- c:\windows\system32\atidxx32.dll
    2011-09-08 17:08:24 4064768 ----a-w- c:\windows\system32\atiumdva.dll
    2011-09-08 17:05:44 4289024 ----a-w- c:\windows\system32\atiumdag.dll
    2011-09-08 16:59:48 52736 ----a-w- c:\windows\system32\coinst.dll
    2011-09-08 16:53:10 270336 ----a-w- c:\windows\system32\atiadlxx.dll
    2011-09-08 16:51:54 31744 ----a-w- c:\windows\system32\atiuxpag.dll
    2011-09-08 16:51:44 29184 ----a-w- c:\windows\system32\atiu9pag.dll
    2011-09-06 07:19:15 60416 ----a-w- c:\windows\ALCFDRTM.VER
    2011-08-31 07:30:50 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-08-08 00:06:45 50320 ----a-w- c:\windows\system32\xjchalqivdszbsufi.exe
    2011-08-02 07:11:00 709992 ----a-w- c:\windows\system32\kindling.dll
    2011-07-22 04:54:18 1638912 ----a-w- c:\windows\system32\mshtml.tlb
    2011-07-16 04:27:30 290816 ----a-w- c:\windows\system32\KernelBase.dll
    2011-07-16 02:17:19 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
    2011-07-16 02:17:19 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
    2011-07-16 02:17:19 3584 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
    2011-07-16 02:17:19 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
    2011-07-12 01:50:54 83816 ----a-w- c:\windows\system32\dns-sd.exe
    2011-07-12 01:50:54 73064 ----a-w- c:\windows\system32\dnssd.dll
    2011-07-12 01:50:54 178536 ----a-w- c:\windows\system32\dnssdX.dll
    2011-07-09 04:29:46 2048 ----a-w- c:\windows\system32\tzres.dll
    2011-07-09 02:30:00 223744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
    2011-07-05 09:07:00 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
    2011-07-05 09:07:00 69632 ----a-w- c:\windows\system32\QuickTime.qts
    .
    ============= FINISH: 20:23:53.00 ===============

    Attach log:

    .
    ==== Installed Programs ======================
    .
    001Micron USB Drive Recovery(Demo) 5.8.4.1
    7-Zip 4.65
    Adobe AIR
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Reader 9.1
    Adobe Shockwave Player 11.5
    Agent Ransack 2010
    AMD APP KernelAnalyzer 1.8
    AMD APP Profiler 2.2
    AMD APP SDK Developer
    AMD APP SDK Runtime
    AMD APP SDK Samples
    AMD Drag and Drop Transcoding
    AMD Fuel
    AMD Media Foundation Decoders
    AMD VISION Engine Control Center
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    AsusUpdate
    ATI AVIVO Codecs
    ATI Catalyst Install Manager
    ATI Catalyst Registration
    ATI Problem Report Wizard
    Audacity 1.2.6
    Audacity 1.3.13 (Unicode)
    Batch PDF Merger
    BBSAK
    BlackBerry Desktop Software 6.0.2
    BlackBerry Device Software v5.0.0 for the BlackBerry 9000 smartphone
    Bonjour
    Brother MFL-Pro Suite MFC-295CN
    Catalyst Control Center - Branding
    Catalyst Control Center Graphics Previews Common
    Catalyst Control Center InstallProxy
    ccc-utility
    CCC Help English
    CDDRV_Installer
    Cheat Engine 5.6
    Contextual Tool Yourprofitclub
    CyberLink PowerDirector
    D3DX10
    Definition update for Microsoft Office 2010 (KB982726) 32-Bit Edition
    Deus Ex - Human Revolution
    DFX for Windows Media Player
    Diskeeper 2011
    Dual-Core Optimizer
    erLT
    Fable III
    FLAC 1.2.1b (remove only)
    Flash Saver
    FULL CLIENT
    Gatling Gears
    Google Earth
    Google Update Helper
    HydraVision
    Image Resizer Powertoy Clone for Windows
    ImgBurn
    iTunes
    Java Auto Updater
    Java(TM) 6 Update 22
    Kaspersky Internet Security 2012
    KhalInstallWrapper
    LADSPA_plugins-win-0.4.15
    LAME v3.98.3 for Audacity
    Legend of Edda USA_v1.0_101029
    Logitech GamePanel Software 3.06.109
    Logitech SetPoint
    Malwarebytes' Anti-Malware version 1.51.2.1300
    MapleStory
    Microsoft .NET Framework 4 Client Profile
    Microsoft .NET Framework 4 Extended
    Microsoft Application Error Reporting
    Microsoft Games for Windows - LIVE Redistributable
    Microsoft Games for Windows Marketplace
    Microsoft IntelliType Pro 8.0
    Microsoft Office Access MUI (English) 2010
    Microsoft Office Access Setup Metadata MUI (English) 2010
    Microsoft Office Excel MUI (English) 2010
    Microsoft Office Groove MUI (English) 2010
    Microsoft Office InfoPath MUI (English) 2010
    Microsoft Office OneNote MUI (English) 2010
    Microsoft Office Outlook MUI (English) 2010
    Microsoft Office PowerPoint MUI (English) 2010
    Microsoft Office Professional Plus 2010
    Microsoft Office Proof (English) 2010
    Microsoft Office Proof (French) 2010
    Microsoft Office Proof (Spanish) 2010
    Microsoft Office Proofing (English) 2010
    Microsoft Office Publisher MUI (English) 2010
    Microsoft Office Shared MUI (English) 2010
    Microsoft Office Shared Setup Metadata MUI (English) 2010
    Microsoft Office Word MUI (English) 2010
    Microsoft Silverlight
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft SQL Server Compact 3.5 SP2 ENU
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
    Microsoft WSE 3.0 Runtime
    Mozilla Firefox 6.0.2 (x86 en-US)
    MSVCRT
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    MSXML 4.0 SP2 Parser and SDK
    NVIDIA PhysX
    PaperPort Image Printer
    PPS影音 V2.7.0.1266 正式版
    PPS游戏 V1.0.1.206
    PPTV V3.0.4.0008
    QuickTime
    Rags Suite
    RealPlayer
    Realtek AC'97 Audio
    RealUpgrade 1.0
    ScanSoft PaperPort 11
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
    Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
    Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
    Skype Toolbars
    Skype? 5.3
    SmartSound Quicktracks Plugin
    Spybot - Search & Destroy
    The Lord of the Rings FREE Trial
    TP-LINK Driver Installation Program
    Ubisoft Game Launcher
    Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
    Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
    Update for Microsoft .NET Framework 4 Extended (KB2468871)
    Update for Microsoft .NET Framework 4 Extended (KB2533523)
    Update for Microsoft Office 2010 (KB2494150)
    Update for Microsoft Office 2010 (KB2553092)
    Veoh Web Player
    Virtua Tennis 4?
    VirtualCloneDrive
    WBFS Manager 3.0
    Win7codecs
    Winamp
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live ID Sign-in Assistant
    Windows Live Installer
    Windows Live Messenger
    Windows Live Movie Maker
    Windows Live Photo Common
    Windows Live Photo Gallery
    Windows Live PIMT Platform
    Windows Live SOXE
    Windows Live SOXE Definitions
    Windows Live Sync
    Windows Live UX Platform
    Windows Live UX Platform Language Pack
    Windows Media Player Firefox Plugin
    WinRAR archiver
    YouTube Downloader 2.7
    μTorrent
    .
    ==== End Of File ===========================
     
  7. 2011/10/02
    Admin.

    Admin. Administrator Administrator Staff

    Joined:
    2001/12/30
    Messages:
    6,687
    Likes Received:
    107
    I see you have P2P software ( Azures, Limewire, BitTorrent, uTorrent etc…) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It may be contributing to your current situation. This page will give you further information.

    Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares and their infections.

    References for the risk of these programs are here, and here.

    I would strongly recommend that you uninstall them, and read the links above for educational value!

    Note: Please be advised that continued use of these programs after being warned of the danger of infections from them, may result in the discontinued help of future cleaning of your system here at WindowsBBS Malware and Virus removal.

    A Malware expert will have a look at your log in due course.
     
  8. 2011/10/02
    terencew

    terencew Inactive Thread Starter

    Joined:
    2011/09/29
    Messages:
    34
    Likes Received:
    0
    As far as P2P programs goes, yes it is as dangerous as going to any infected websites..i understand those risk and do take necessary precautions when downloading files using it. depending on situations of course it is better not to use it in some sense.
     
  9. 2011/10/02
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running tools or applying updates other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ==========================================================

    Please download ComboFix from [color= "Red"]Here[/color] or [color= "#FF0000"]Here[/color] to your Desktop.

    [color= "Blue"]**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**[/color]
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results ".
      • Click on [color= "Red"]this link[/color] to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • [color= "Red"]WARNING:[/color] Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG users: ComboFix will not run until AVG is uninstalled as a protective measure against the anti-virus. This is because AVG "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results ". Since AVG cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion ", restart computer to fix the issue.



    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try one of the following:

    1. Run Combofix from Safe Mode (How to...)

    2. Delete Combofix file, download fresh one, but rename combofix.exe to yourname.exe BEFORE saving it to your desktop.
    Do NOT run it yet.

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click Rkill and choose Run as Administrator

    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    Rkill.com
    Rkill.scr
    Rkill.exe

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    If normal mode still doesn't work, run BOTH tools from safe mode.

    In case #2, please post BOTH logs, rKill and Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  10. 2011/10/03
    terencew

    terencew Inactive Thread Starter

    Joined:
    2011/09/29
    Messages:
    34
    Likes Received:
    0
    here is the combofix log running in safe mode. cause i still cannot get a decent uptime in my normal more...it still crashes in less than 10 minutes.

    ComboFix 11-10-02.03 - Terence 0/2011 Mon 16:16:47.19.2 - x86 MINIMAL
    Running from: c:\users\Terence\Desktop\ComboFix.exe
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\favoritevideo\InvisibleFolder
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-09-03 to 2011-10-03 )))))))))))))))))))))))))))))))
    .
    .
    2011-10-03 05:56 . 2011-10-03 05:56 -------- d-----w- c:\users\Public\AppData\Local\temp
    2011-10-03 05:56 . 2011-10-03 05:56 -------- d-----w- c:\users\Default\AppData\Local\temp
    2011-10-02 05:18 . 2011-10-03 05:56 -------- d-----w- c:\users\Terence\AppData\Local\temp
    2011-10-02 05:18 . 2011-10-02 05:18 -------- d-----w- c:\users\AEWR
    2011-10-02 05:04 . 2011-10-02 05:04 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2011-10-02 04:51 . 2011-10-02 04:52 -------- d-----w- c:\users\Terence\AppData\Roaming\Logishrd
    2011-10-02 04:29 . 2010-11-10 04:33 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E63E96E9-54D9-4799-8ED4-E19BB47C4CC9}\mpengine.dll
    2011-09-29 21:30 . 2011-09-30 09:01 -------- d-----w- C:\symbols
    2011-09-29 21:26 . 2011-10-02 09:47 -------- d-----w- c:\program files\Debugging Tools for Windows (x86)
    2011-09-29 21:25 . 2011-09-29 21:25 -------- d-----w- c:\program files\Microsoft SDKs
    2011-09-29 20:53 . 2005-11-25 01:53 524288 ----a-w- C:\A8NSB014.BIN
    2011-09-29 19:27 . 2011-09-29 19:27 -------- d--h--w- c:\windows\PIF
    2011-09-29 17:43 . 2001-09-04 18:48 225280 ----a-w- c:\program files\Common Files\InstallShield\IScript\iscript.dll
    2011-09-29 17:43 . 2001-09-04 18:48 77824 ----a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\ctor.dll
    2011-09-29 17:43 . 2001-09-04 18:44 176128 ----a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\iuser.dll
    2011-09-29 17:43 . 2001-09-04 18:43 32768 ----a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\objectps.dll
    2011-09-29 17:42 . 2002-07-25 08:07 614532 ----a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe
    2011-09-29 13:45 . 2011-09-29 13:45 -------- d-----w- c:\programdata\ATI
    2011-09-29 13:45 . 2011-09-29 13:45 -------- d-----w- c:\program files\Common Files\ATI Technologies
    2011-09-29 13:43 . 2011-09-29 13:44 -------- d-----w- c:\program files\ATI Technologies
    2011-09-29 13:43 . 2011-09-29 13:43 -------- d-----w- c:\program files\ATI
    2011-09-29 09:07 . 2011-09-29 09:17 -------- d-----w- c:\program files\WinUtilities
    2011-09-29 09:07 . 2010-07-25 12:53 56496 ----a-w- c:\windows\system32\wbhelp2.dll
    2011-09-29 09:07 . 2010-07-25 12:53 544768 ----a-w- c:\windows\system32\wbocx.ocx
    2011-09-29 09:07 . 2010-07-25 12:53 33968 ----a-w- c:\windows\system32\anim.dll
    2011-09-29 09:07 . 2010-07-25 12:53 4608 ----a-w- c:\windows\system32\W95INF32.DLL
    2011-09-29 09:07 . 2010-07-25 12:53 2272 ----a-w- c:\windows\system32\W95INF16.DLL
    2011-09-27 15:56 . 2011-09-27 15:56 -------- d-----w- c:\programdata\ProcessLasso
    2011-09-22 03:24 . 2011-09-22 03:24 -------- d-----w- c:\program files\Gravity
    2011-09-21 13:44 . 2011-09-21 13:44 -------- d---a-w- C:\out
    2011-09-19 07:41 . 2011-09-19 07:41 -------- d-----w- c:\users\Terence\AppData\Roaming\com.essexreddevelopment.mergepdfmac
    2011-09-19 07:41 . 2011-09-19 07:41 -------- d-----w- c:\program files\Common Files\Adobe AIR
    2011-09-18 11:42 . 2011-09-18 11:42 -------- d-----w- c:\users\Terence\AppData\Roaming\Gatling Gears
    2011-09-18 11:31 . 2011-09-18 11:31 -------- d-----w- c:\program files\Electronic Arts
    2011-09-17 07:30 . 2011-09-17 07:30 -------- d-----w- c:\program files\AhnLab
    2011-09-15 02:39 . 2011-09-15 03:04 -------- d-----w- c:\users\Terence\AppData\Local\Ubisoft Game Launcher
    2011-09-15 02:39 . 2011-09-15 02:39 -------- d-----w- c:\users\Terence\AppData\Local\SKIDROW
    2011-09-14 11:32 . 2011-09-29 13:06 -------- d-----w- c:\program files\Hard Disk Sentinel
    2011-09-14 02:17 . 2011-09-14 02:17 53760 ----a-w- c:\windows\system32\OVDecode.dll
    2011-09-14 02:16 . 2011-09-14 02:16 13625856 ----a-w- c:\windows\system32\amdocl.dll
    2011-09-14 02:08 . 2011-09-14 02:08 37376 ----a-w- c:\windows\system32\amdoclcl.dll
    2011-09-08 18:26 . 2011-09-08 18:26 8606208 ----a-w- c:\windows\system32\drivers\atikmdag.sys
    2011-09-08 17:39 . 2011-09-08 17:39 18534912 ----a-w- c:\windows\system32\atioglxx.dll
    2011-09-08 17:34 . 2011-09-08 17:34 151552 ----a-w- c:\windows\system32\atiapfxx.exe
    2011-09-08 17:32 . 2011-04-24 13:43 110992 ----a-w- c:\program files\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak2\components\abhelperxpcom.dll
    2011-09-08 17:32 . 2011-04-24 13:43 147856 ----a-w- c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak2\components\kavlinkfilter.dll
    2011-09-08 17:30 . 2011-09-08 17:30 466944 ----a-w- c:\windows\system32\ATIDEMGX.dll
    2011-09-08 17:30 . 2011-09-08 17:30 401408 ----a-w- c:\windows\system32\atieclxx.exe
    2011-09-08 17:29 . 2011-09-08 17:29 176128 ----a-w- c:\windows\system32\atiesrxx.exe
    2011-09-08 17:28 . 2011-09-08 17:28 159744 ----a-w- c:\windows\system32\atitmmxx.dll
    2011-09-08 17:28 . 2011-09-08 17:28 356352 ----a-w- c:\windows\system32\atipdlxx.dll
    2011-09-08 17:28 . 2011-09-08 17:28 278528 ----a-w- c:\windows\system32\Oemdspif.dll
    2011-09-08 17:28 . 2011-09-08 17:28 20992 ----a-w- c:\windows\system32\atimuixx.dll
    2011-09-08 17:28 . 2011-09-08 17:28 43520 ----a-w- c:\windows\system32\ati2edxx.dll
    2011-09-08 17:18 . 2011-09-08 17:18 1828864 ----a-w- c:\windows\system32\atiumdmv.dll
    2011-09-08 17:09 . 2011-09-08 17:09 46080 ----a-w- c:\windows\system32\aticalrt.dll
    2011-09-08 17:09 . 2011-09-08 17:09 44032 ----a-w- c:\windows\system32\aticalcl.dll
    2011-09-08 17:05 . 2011-09-08 17:05 7331840 ----a-w- c:\windows\system32\aticaldd.dll
    2011-09-08 16:52 . 2011-09-08 16:52 13312 ----a-w- c:\windows\system32\atiglpxx.dll
    2011-09-08 16:52 . 2011-09-08 16:52 32768 ----a-w- c:\windows\system32\atigktxx.dll
    2011-09-08 16:52 . 2011-09-08 16:52 248832 ----a-w- c:\windows\system32\drivers\atikmpag.sys
    2011-09-08 16:51 . 2011-09-08 16:51 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
    2011-09-08 16:50 . 2011-09-08 16:50 53760 ----a-w- c:\windows\system32\atimpc32.dll
    2011-09-08 16:50 . 2011-09-08 16:50 53760 ----a-w- c:\windows\system32\amdpcom32.dll
    2011-09-08 13:07 . 2011-09-27 08:58 -------- d-----w- c:\users\Terence\AppData\Local\dxhr
    2011-09-08 07:15 . 2011-09-08 07:15 -------- d-----w- c:\users\Terence\AppData\Local\28050
    2011-09-08 05:33 . 2011-09-08 05:33 -------- d-----w- c:\program files\Square Enix
    2011-09-06 17:31 . 2011-09-06 17:31 -------- d-----w- C:\fc0ba4149eb9e6c0caf077f138
    2011-09-06 16:00 . 2011-09-06 16:00 -------- d-----w- c:\users\Terence\vitamin base material_files
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-09-26 11:57 . 2011-05-19 15:23 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2011-09-08 17:34 . 2010-07-07 01:54 732672 ----a-w- c:\windows\system32\aticfx32.dll
    2011-09-08 17:24 . 2009-09-19 02:12 4204032 ----a-w- c:\windows\system32\atidxx32.dll
    2011-09-08 17:08 . 2009-09-19 01:38 4064768 ----a-w- c:\windows\system32\atiumdva.dll
    2011-09-08 17:05 . 2009-09-19 01:56 4289024 ----a-w- c:\windows\system32\atiumdag.dll
    2011-09-08 16:59 . 2010-07-07 01:24 52736 ----a-w- c:\windows\system32\coinst.dll
    2011-09-08 16:53 . 2011-03-09 04:18 270336 ----a-w- c:\windows\system32\atiadlxx.dll
    2011-09-08 16:51 . 2010-07-07 01:14 31744 ----a-w- c:\windows\system32\atiuxpag.dll
    2011-09-08 16:51 . 2010-07-07 01:14 29184 ----a-w- c:\windows\system32\atiu9pag.dll
    2011-09-06 07:19 . 2009-11-08 04:48 60416 ----a-w- c:\windows\ALCFDRTM.VER
    2011-08-31 07:30 . 2011-06-11 07:06 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-08-08 00:06 . 2011-08-07 11:49 50320 ----a-w- c:\windows\system32\xjchalqivdszbsufi.exe
    2011-08-04 07:11 . 2011-08-04 07:11 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
    2011-08-02 07:11 . 2011-08-02 07:11 709992 ----a-w- c:\windows\system32\kindling.dll
    2011-07-22 04:54 . 2011-08-10 04:50 1638912 ----a-w- c:\windows\system32\mshtml.tlb
    2011-07-16 04:27 . 2011-08-10 04:50 290816 ----a-w- c:\windows\system32\KernelBase.dll
    2011-07-16 04:15 . 2011-08-10 04:50 4096 ---ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 4096 ---ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 3072 ---ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 5120 ---ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 4608 ---ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 4096 ---ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 3072 ---ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 3072 ---ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 3584 ---ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 3584 ---ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 3584 ---ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 3072 ---ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 3072 ---ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 3584 ---ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 3584 ---ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 3072 ---ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 3072 ---ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 3072 ---ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 3072 ---ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 3072 ---ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:49 3584 ---ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:49 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:49 3072 ---ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll
    2011-07-16 02:17 . 2011-08-10 04:49 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
    2011-07-16 02:17 . 2011-08-10 04:49 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
    2011-07-16 02:17 . 2011-08-10 04:49 3584 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
    2011-07-16 02:17 . 2011-08-10 04:49 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
    2011-07-12 01:50 . 2011-07-12 01:50 83816 ----a-w- c:\windows\system32\dns-sd.exe
    2011-07-12 01:50 . 2011-07-12 01:50 73064 ----a-w- c:\windows\system32\dnssd.dll
    2011-07-12 01:50 . 2011-07-12 01:50 178536 ----a-w- c:\windows\system32\dnssdX.dll
    2011-07-09 04:29 . 2011-08-24 03:04 2048 ----a-w- c:\windows\system32\tzres.dll
    2011-07-09 02:30 . 2011-08-10 04:50 223744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
    2011-07-05 12:10 . 2011-07-05 12:10 594466 ----a-w- c:\windows\system32\Codec Analyzer.zip
    2011-07-05 09:07 . 2011-07-05 09:07 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
    2011-07-05 09:07 . 2011-07-05 09:07 69632 ----a-w- c:\windows\system32\QuickTime.qts
    2011-09-08 01:41 . 2011-05-26 15:07 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
    2010-02-05 06:50 . 2010-02-10 16:25 79664 ----a-w- c:\program files\mozilla firefox\components\ThunderComponent.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "VeohPlugin "= "c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2011-06-30 2648184]
    "Sidebar "= "c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
    "SpybotSD TeaTimer "= "c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
    "uTorrent "= "c:\program files\uTorrent\uTorrent.exe" [2011-05-06 399736]
    "msnmsgr "= "c:\program files\Windows Live\Messenger\msnmsgr.exe" [2011-05-13 4283256]
    "DAEMON Tools Pro Agent "= "c:\program files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 136136]
    "PPS Accelerator "= "d:\pps.tv\PPStream\ppsap.exe" [2010-02-24 214408]
    "Skype "= "c:\program files\Skype\Phone\Skype.exe" [2011-05-26 15147400]
    "PPAP "= "c:\program files\Common Files\PPLiveNetwork\PPAP.exe" [2011-08-05 442232]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SoundMan "= "SOUNDMAN.EXE" [2009-04-13 604704]
    "UpdatePDRShortCut "= "c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-12-03 218408]
    "PaperPort PTD "= "c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2008-07-09 29984]
    "IndexSearch "= "c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2008-07-09 46368]
    "ControlCenter3 "= "c:\program files\Brother\ControlCenter3\brctrcen.exe" [2008-12-24 114688]
    "Launch LgDeviceAgent "= "c:\program files\Logitech\GamePanel Software\LgDevAgt.exe" [2010-08-02 358472]
    "Launch LCDMon "= "c:\program files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2010-08-02 1809992]
    "Launch LGDCore "= "c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2010-08-02 3649096]
    "BrMfcWnd "= "c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2009-05-26 1159168]
    "TkBellExe "= "c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-04-15 202256]
    "iTunesHelper "= "c:\program files\iTunes\iTunesHelper.exe" [2011-08-18 421736]
    "Kernel and Hardware Abstraction Layer "= "KHALMNPR.EXE" [2009-06-17 55824]
    "itype "= "c:\program files\Microsoft IntelliType Pro\itype.exe" [2010-07-21 1778064]
    "RIMBBLaunchAgent.exe "= "c:\program files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe" [2011-02-18 79192]
    "BCSSync "= "c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-01-21 91520]
    "StartCCC "= "c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-09-08 343168]
    "QuickTime Task "= "c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin "= 0 (0x0)
    "ConsentPromptBehaviorUser "= 3 (0x3)
    "EnableLUA "= 0 (0x0)
    "EnableUIADesktopToggle "= 0 (0x0)
    "PromptOnSecureDesktop "= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
    2009-07-20 01:58 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\klmdb.sys]
    @=" "
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
    @= "Service "
    .
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
    "DAEMON Tools Pro Agent "= "c:\program files\DAEMON Tools Pro\DTProAgent.exe "
    "uTorrent "= "c:\program files\uTorrent\uTorrent.exe "
    "PPS Accelerator "=d:\pps.tv\PPStream\ppsap.exe
    "msnmsgr "= "c:\program files\Windows Live\Messenger\msnmsgr.exe" /background
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "BCSSync "= "c:\program files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
    "SSBkgdUpdate "= "c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
    "VirtualCloneDrive "= "c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
    "WinampAgent "= "c:\program files\Winamp\winampa.exe "
    "PPort11reminder "= "c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "c:\programdata\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini "
    "SunJavaUpdateSched "= "c:\program files\Common Files\Java\Java Update\jusched.exe "
    "ATICustomerCare "= "c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe "
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
    "DisableMonitoring "=dword:00000001
    .
    R0 atyle;atyle; [x]
    R0 klmdb;klmdb;c:\windows\system32\drivers\klmdb.sys [x]
    R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
    R0 whqeht;whqeht;c:\windows\System32\drivers\gcdejei.sys [x]
    R1 hname;hname;c:\windows\system32\hname.SYS [x]
    R1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [x]
    R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [x]
    R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
    R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-09-08 176128]
    R2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-09-08 291840]
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-02-07 136176]
    R2 KMService;KMService;c:\windows\system32\srvany.exe [2010-11-08 8192]
    R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
    R3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2011-09-08 8606208]
    R3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2011-09-08 248832]
    R3 AODDriver4.0;AODDriver4.0;c:\program files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [2011-06-23 39424]
    R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2011-06-06 211984]
    R3 DKRtWrt;DKRtWrt;c:\windows\system32\DRIVERS\DKRtWrt.sys [2011-02-13 38608]
    R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-02-07 136176]
    R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [x]
    R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2009-11-23 14856]
    R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-01-21 30963576]
    R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2010-08-29 3739080]
    R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
    R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
    R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
    R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
    R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-22 1343400]
    S3 amdiox86;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox86.sys [2010-02-17 37944]
    S3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\Drivers\LEqdUsb.Sys [2009-06-17 40720]
    S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2009-11-23 19720]
    S3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\Drivers\LHidEqd.Sys [2009-06-17 10384]
    .
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2011-10-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cc215cfc50b11a.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2011-02-07 21:28]
    .
    2011-10-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA1cc215cfd2c0972.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2011-02-07 21:28]
    .
    .
    ------- Supplementary Scan -------
    .
    uInternet Settings,ProxyOverride = *.local
    IE: &Save Flash In This Page by Flash Saver
    IE: E&xport to Microsoft Excel
    IE: S&end to OneNote
    IE: 使用迅雷下载
    IE: 使用迅雷下载全部链接
    Trusted Zone: pps.tv
    Trusted Zone: ppstream.com
    Trusted Zone: webscache.com
    FF - ProfilePath - c:\users\Terence\AppData\Roaming\Mozilla\Firefox\Profiles\goad6cdl.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2653012&SearchSource=3&q={searchTerms}
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
    FF - prefs.js: keyword.URL - hxxp://www.google.com.au/search?q=
    FF - user.js: network.cookie.cookieBehavior - 0
    FF - user.js: privacy.clearOnShutdown.cookies - false
    FF - user.js: security.warn_viewing_mixed - false
    FF - user.js: security.warn_viewing_mixed.show_once - false
    FF - user.js: security.warn_submit_insecure - false
    FF - user.js: security.warn_submit_insecure.show_once - false
    .
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\services\npggsvc]
    "ImagePath "= "c:\windows\system32\GameMon.des -service "
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    完成时间: 2011-10-03 16:30:08
    ComboFix-quarantined-files.txt 2011-10-03 06:00
    ComboFix2.txt 2011-10-03 05:20
    ComboFix3.txt 2011-10-02 05:18
    ComboFix4.txt 2011-09-29 04:40
    ComboFix5.txt 2011-10-03 05:31
    .
    Pre-Run: 148,935,938,048 bytes free
    Post-Run: 148,757,262,336 bytes free
    .
    - - End Of File - - 50D778089C963B48D6B216D9AEE10720
     
  11. 2011/10/03
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Download CKScanner from HERE

    Important : Save it to your desktop.

    • Doubleclick CKScanner.exe and click Search For Files.
    • After a very short time, when the cursor hourglass disappears, click Save List To File.
    • A message box will verify that the file is saved.
    • Double-click the CKFiles.txt icon on your desktop and copy/paste the contents in your next reply.

    ===========================================================

    1. Please open Notepad
    • Click Start , then Run
    • Type notepad .exe in the Run Box
    • Click OK
    Windows Vista/7 users: click Start, in "Start search" type notepad and press Enter.

    2. Now copy/paste the entire content of the codebox below into the Notepad window:

    Code:
    File::
    c:\windows\system32\xjchalqivdszbsufi.exe
    c:\windows\System32\drivers\gcdejei.sys
    c:\windows\system32\hname.SYS
    
    
    Folder::
    c:\users\Terence\AppData\Local\dxhr
    c:\users\Terence\AppData\Local\28050
    
    
    Driver::
    atyle
    klmdb
    whqeht
    hname
    
    
    DDS::
    Trusted Zone: pps.tv
    Trusted Zone: ppstream.com
    Trusted Zone: webscache.com
    
    

    3. Save the above as CFScript.txt

    4. Close/disable all anti virus and anti malware programs again, so they do not interfere with the running of ComboFix.

    5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

    [​IMG]


    6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
    • Combofix.txt
     
  12. 2011/10/03
    terencew

    terencew Inactive Thread Starter

    Joined:
    2011/09/29
    Messages:
    34
    Likes Received:
    0
    manage to get the CKscanner to finish running after 4 BSODs

    CKScanner - Additional Security Risks - These are not necessarily bad
    c:\users\terence\appdata\roaming\utorrent\alice.madness.returns.crackfix-skidrow.torrent
    c:\users\terence\appdata\roaming\utorrent\google earth plus v6.0.3.2197 + crack.torrent
    c:\users\terence\appdata\roaming\utorrent\mafia 2 crack v2 + exe + steam api.ddl.torrent
    c:\users\terence\appdata\roaming\utorrent\medal of honor limited edition crack.exe.torrent
    c:\users\terence\appdata\roaming\utorrent\microsoft office professional plus 2010 [activated forever] no crack no keygen needed.torrent
    c:\users\terence\appdata\roaming\utorrent\registrybooster 2010 4.7.6.10 __ keygen __.rar.torrent
    c:\users\terence\appdata\roaming\utorrent\stellar.phoenix.windows.data.recovery.v3.0.0.with crack.rar.torrent
    c:\users\terence\appdata\roaming\utorrent\the.sims.medieval.update.v1.1.10.cracked-reloaded.torrent
    c:\users\terence\appdata\roaming\utorrent\tuneup_utilities_2011 v10.0.2011.65 cracked.torrent
    c:\users\terence\appdata\roaming\utorrent\uniblue driverscanner 2010 ver. 2.0.0.1 final + keygen.torrent
    c:\users\terence\appdata\roaming\utorrent\microsoft office 2010 professional plus\cracked microsoft office 2010 professional plus\14.0.4734.1000_professionalplus_volume_ship_x86_en-us_exe.exe
    c:\users\terence\downloads\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat(1).rar
    c:\users\terence\downloads\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat.rar
    c:\users\terence\downloads\alice.madness.returns.crackfix-skidrow\skidrow.nfo
    c:\users\terence\downloads\alice.madness.returns.crackfix-skidrow\sr-amrf.rar
    c:\users\terence\downloads\alice.madness.returns.crackfix-skidrow\sr-amrf.sfv
    c:\users\terence\downloads\back to the future - the game\back to the future episode 3\crack\backtothefuture103.exe
    c:\users\terence\downloads\back to the future - the game\back to the future episode 4\crack\backtothefuture104.exe
    c:\users\terence\downloads\back to the future - the game\back to the future episode 5\crack\backtothefuture105.exe
    c:\users\terence\downloads\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat\eat.nfo
    c:\users\terence\downloads\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat(1)\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat\eat.nfo
    c:\users\terence\downloads\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat(1)\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat\eatpl545.zip
    c:\users\terence\downloads\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat(1)\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat\file_id.diz
    c:\users\terence\downloads\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat(1)\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat\eatpl545\eat.nfo
    c:\users\terence\downloads\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat(1)\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat\eatpl545\eatpl545.rar
    c:\users\terence\downloads\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat(1)\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat\eatpl545\file_id.diz
    c:\users\terence\downloads\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat(1)\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat\eatpl545\processlassoportable_v5.00.45.zip
    c:\users\terence\downloads\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat(1)\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat\eatpl545\processlassosetup_v5.00.45.exe
    c:\users\terence\downloads\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat(1)\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat\eatpl545\crack\installhelper.exe
    c:\users\terence\downloads\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat(1)\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat\eatpl545\crack\processgovernor.exe
    c:\users\terence\downloads\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat(1)\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat\eatpl545\crack\processlasso.exe
    c:\users\terence\downloads\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat(1)\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat\eatpl545\crack\processlasso.reg
    c:\users\terence\downloads\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat(1)\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat\eatpl545\crack\tweakscheduler.exe
    c:\users\terence\downloads\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat(1)\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat\eatpl545\crack\vistammsc.exe
    c:\users\terence\downloads\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat(1)\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat\eatpl545\works\!new.files.upload.dl\bitsum.technologies.process.lasso.pro.v5.00.45.cracked-eat\eat.nfo
    c:\users\terence\downloads\google earth plus v6.0.3.2197 + crack\googleearthwin v6.0.3.2197.exe
    c:\users\terence\downloads\google earth plus v6.0.3.2197 + crack\readme.txt
    c:\users\terence\downloads\google earth plus v6.0.3.2197 + crack\crack\crack\google.earth.plus.6.0.2.2074-mpt.exe
    c:\users\terence\downloads\google earth plus v6.0.3.2197 + crack\crack\crack\mpt.nfo
    c:\users\terence\downloads\google earth plus v6.0.3.2197 + crack\crack\crack\mpt.nfo.txt
    c:\users\terence\downloads\microsoft office professional plus 2010 [activated forever] no crack no keygen needed\office_2010_professional_plus.exe
    c:\users\terence\downloads\microsoft office professional plus 2010 [activated forever] no crack no keygen needed\readme.txt
    c:\users\terence\downloads\winutilities.pro.v10.34.multilingual.incl.keymaker-core(1)\keygen.exe
    scanner sequence 3.ZZ.11.GCAPUQ
    ----- EOF -----
     
  13. 2011/10/03
    terencew

    terencew Inactive Thread Starter

    Joined:
    2011/09/29
    Messages:
    34
    Likes Received:
    0
    after the constant BSODings...i finally manage to run 1 full combofix, though previously it did crash a few times..twice i think during the finish of it...so results might or might not all be there.

    ComboFix 11-10-02.03 - Terence 0/2011 Tue 3:10.23.2 - x86 MINIMAL
    Running from: c:\users\Terence\Desktop\ComboFix.exe
    Command switches used :: c:\users\Terence\Desktop\CFScript.txt
    .
    FILE ::
    "c:\windows\System32\drivers\gcdejei.sys "
    "c:\windows\system32\hname.SYS "
    "c:\windows\system32\xjchalqivdszbsufi.exe "
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-09-03 to 2011-10-03 )))))))))))))))))))))))))))))))
    .
    .
    2011-10-03 16:51 . 2011-10-03 16:51 -------- d-----w- c:\users\Public\AppData\Local\temp
    2011-10-03 16:51 . 2011-10-03 16:51 -------- d-----w- c:\users\Default\AppData\Local\temp
    2011-10-02 05:18 . 2011-10-03 16:51 -------- d-----w- c:\users\Terence\AppData\Local\temp
    2011-10-02 05:18 . 2011-10-02 05:18 -------- d-----w- c:\users\AEWR
    2011-10-02 05:04 . 2011-10-02 05:04 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2011-10-02 04:51 . 2011-10-02 04:52 -------- d-----w- c:\users\Terence\AppData\Roaming\Logishrd
    2011-10-02 04:29 . 2010-11-10 04:33 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E63E96E9-54D9-4799-8ED4-E19BB47C4CC9}\mpengine.dll
    2011-09-29 21:30 . 2011-09-30 09:01 -------- d-----w- C:\symbols
    2011-09-29 21:26 . 2011-10-02 09:47 -------- d-----w- c:\program files\Debugging Tools for Windows (x86)
    2011-09-29 21:25 . 2011-09-29 21:25 -------- d-----w- c:\program files\Microsoft SDKs
    2011-09-29 20:53 . 2005-11-25 01:53 524288 ----a-w- C:\A8NSB014.BIN
    2011-09-29 19:27 . 2011-09-29 19:27 -------- d--h--w- c:\windows\PIF
    2011-09-29 17:43 . 2001-09-04 18:48 225280 ----a-w- c:\program files\Common Files\InstallShield\IScript\iscript.dll
    2011-09-29 17:43 . 2001-09-04 18:48 77824 ----a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\ctor.dll
    2011-09-29 17:43 . 2001-09-04 18:44 176128 ----a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\iuser.dll
    2011-09-29 17:43 . 2001-09-04 18:43 32768 ----a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\objectps.dll
    2011-09-29 17:42 . 2002-07-25 08:07 614532 ----a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe
    2011-09-29 13:45 . 2011-09-29 13:45 -------- d-----w- c:\programdata\ATI
    2011-09-29 13:45 . 2011-09-29 13:45 -------- d-----w- c:\program files\Common Files\ATI Technologies
    2011-09-29 13:43 . 2011-09-29 13:44 -------- d-----w- c:\program files\ATI Technologies
    2011-09-29 13:43 . 2011-09-29 13:43 -------- d-----w- c:\program files\ATI
    2011-09-29 09:07 . 2011-09-29 09:17 -------- d-----w- c:\program files\WinUtilities
    2011-09-29 09:07 . 2010-07-25 12:53 56496 ----a-w- c:\windows\system32\wbhelp2.dll
    2011-09-29 09:07 . 2010-07-25 12:53 544768 ----a-w- c:\windows\system32\wbocx.ocx
    2011-09-29 09:07 . 2010-07-25 12:53 33968 ----a-w- c:\windows\system32\anim.dll
    2011-09-29 09:07 . 2010-07-25 12:53 4608 ----a-w- c:\windows\system32\W95INF32.DLL
    2011-09-29 09:07 . 2010-07-25 12:53 2272 ----a-w- c:\windows\system32\W95INF16.DLL
    2011-09-27 15:56 . 2011-09-27 15:56 -------- d-----w- c:\programdata\ProcessLasso
    2011-09-22 03:24 . 2011-09-22 03:24 -------- d-----w- c:\program files\Gravity
    2011-09-21 13:44 . 2011-09-21 13:44 -------- d---a-w- C:\out
    2011-09-19 07:41 . 2011-09-19 07:41 -------- d-----w- c:\users\Terence\AppData\Roaming\com.essexreddevelopment.mergepdfmac
    2011-09-19 07:41 . 2011-09-19 07:41 -------- d-----w- c:\program files\Common Files\Adobe AIR
    2011-09-18 11:42 . 2011-09-18 11:42 -------- d-----w- c:\users\Terence\AppData\Roaming\Gatling Gears
    2011-09-18 11:31 . 2011-09-18 11:31 -------- d-----w- c:\program files\Electronic Arts
    2011-09-17 07:30 . 2011-09-17 07:30 -------- d-----w- c:\program files\AhnLab
    2011-09-15 02:39 . 2011-09-15 03:04 -------- d-----w- c:\users\Terence\AppData\Local\Ubisoft Game Launcher
    2011-09-15 02:39 . 2011-09-15 02:39 -------- d-----w- c:\users\Terence\AppData\Local\SKIDROW
    2011-09-14 11:32 . 2011-09-29 13:06 -------- d-----w- c:\program files\Hard Disk Sentinel
    2011-09-14 02:17 . 2011-09-14 02:17 53760 ----a-w- c:\windows\system32\OVDecode.dll
    2011-09-14 02:16 . 2011-09-14 02:16 13625856 ----a-w- c:\windows\system32\amdocl.dll
    2011-09-14 02:08 . 2011-09-14 02:08 37376 ----a-w- c:\windows\system32\amdoclcl.dll
    2011-09-08 18:26 . 2011-09-08 18:26 8606208 ----a-w- c:\windows\system32\drivers\atikmdag.sys
    2011-09-08 17:39 . 2011-09-08 17:39 18534912 ----a-w- c:\windows\system32\atioglxx.dll
    2011-09-08 17:34 . 2011-09-08 17:34 151552 ----a-w- c:\windows\system32\atiapfxx.exe
    2011-09-08 17:32 . 2011-04-24 13:43 110992 ----a-w- c:\program files\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak2\components\abhelperxpcom.dll
    2011-09-08 17:32 . 2011-04-24 13:43 147856 ----a-w- c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak2\components\kavlinkfilter.dll
    2011-09-08 17:30 . 2011-09-08 17:30 466944 ----a-w- c:\windows\system32\ATIDEMGX.dll
    2011-09-08 17:30 . 2011-09-08 17:30 401408 ----a-w- c:\windows\system32\atieclxx.exe
    2011-09-08 17:29 . 2011-09-08 17:29 176128 ----a-w- c:\windows\system32\atiesrxx.exe
    2011-09-08 17:28 . 2011-09-08 17:28 159744 ----a-w- c:\windows\system32\atitmmxx.dll
    2011-09-08 17:28 . 2011-09-08 17:28 356352 ----a-w- c:\windows\system32\atipdlxx.dll
    2011-09-08 17:28 . 2011-09-08 17:28 278528 ----a-w- c:\windows\system32\Oemdspif.dll
    2011-09-08 17:28 . 2011-09-08 17:28 20992 ----a-w- c:\windows\system32\atimuixx.dll
    2011-09-08 17:28 . 2011-09-08 17:28 43520 ----a-w- c:\windows\system32\ati2edxx.dll
    2011-09-08 17:18 . 2011-09-08 17:18 1828864 ----a-w- c:\windows\system32\atiumdmv.dll
    2011-09-08 17:09 . 2011-09-08 17:09 46080 ----a-w- c:\windows\system32\aticalrt.dll
    2011-09-08 17:09 . 2011-09-08 17:09 44032 ----a-w- c:\windows\system32\aticalcl.dll
    2011-09-08 17:05 . 2011-09-08 17:05 7331840 ----a-w- c:\windows\system32\aticaldd.dll
    2011-09-08 16:52 . 2011-09-08 16:52 13312 ----a-w- c:\windows\system32\atiglpxx.dll
    2011-09-08 16:52 . 2011-09-08 16:52 32768 ----a-w- c:\windows\system32\atigktxx.dll
    2011-09-08 16:52 . 2011-09-08 16:52 248832 ----a-w- c:\windows\system32\drivers\atikmpag.sys
    2011-09-08 16:51 . 2011-09-08 16:51 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
    2011-09-08 16:50 . 2011-09-08 16:50 53760 ----a-w- c:\windows\system32\atimpc32.dll
    2011-09-08 16:50 . 2011-09-08 16:50 53760 ----a-w- c:\windows\system32\amdpcom32.dll
    2011-09-08 05:33 . 2011-09-08 05:33 -------- d-----w- c:\program files\Square Enix
    2011-09-06 17:31 . 2011-09-06 17:31 -------- d-----w- C:\fc0ba4149eb9e6c0caf077f138
    2011-09-06 16:00 . 2011-09-06 16:00 -------- d-----w- c:\users\Terence\vitamin base material_files
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3m Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-09-26 11:57 . 2011-05-19 15:23 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2011-09-08 17:34 . 2010-07-07 01:54 732672 ----a-w- c:\windows\system32\aticfx32.dll
    2011-09-08 17:24 . 2009-09-19 02:12 4204032 ----a-w- c:\windows\system32\atidxx32.dll
    2011-09-08 17:08 . 2009-09-19 01:38 4064768 ----a-w- c:\windows\system32\atiumdva.dll
    2011-09-08 17:05 . 2009-09-19 01:56 4289024 ----a-w- c:\windows\system32\atiumdag.dll
    2011-09-08 16:59 . 2010-07-07 01:24 52736 ----a-w- c:\windows\system32\coinst.dll
    2011-09-08 16:53 . 2011-03-09 04:18 270336 ----a-w- c:\windows\system32\atiadlxx.dll
    2011-09-08 16:51 . 2010-07-07 01:14 31744 ----a-w- c:\windows\system32\atiuxpag.dll
    2011-09-08 16:51 . 2010-07-07 01:14 29184 ----a-w- c:\windows\system32\atiu9pag.dll
    2011-09-06 07:19 . 2009-11-08 04:48 60416 ----a-w- c:\windows\ALCFDRTM.VER
    2011-08-31 07:30 . 2011-06-11 07:06 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-08-04 07:11 . 2011-08-04 07:11 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
    2011-08-02 07:11 . 2011-08-02 07:11 709992 ----a-w- c:\windows\system32\kindling.dll
    2011-07-22 04:54 . 2011-08-10 04:50 1638912 ----a-w- c:\windows\system32\mshtml.tlb
    2011-07-16 04:27 . 2011-08-10 04:50 290816 ----a-w- c:\windows\system32\KernelBase.dll
    2011-07-16 04:15 . 2011-08-10 04:50 4096 ---ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 4096 ---ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 3072 ---ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 5120 ---ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 4608 ---ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 4096 ---ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 3072 ---ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 3072 ---ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 3584 ---ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 3584 ---ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 3584 ---ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 3072 ---ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 3072 ---ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 3584 ---ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 3584 ---ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 3072 ---ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 3072 ---ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 3072 ---ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 3072 ---ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:50 3072 ---ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:49 3584 ---ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:49 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
    2011-07-16 04:15 . 2011-08-10 04:49 3072 ---ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll
    2011-07-16 02:17 . 2011-08-10 04:49 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
    2011-07-16 02:17 . 2011-08-10 04:49 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
    2011-07-16 02:17 . 2011-08-10 04:49 3584 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
    2011-07-16 02:17 . 2011-08-10 04:49 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
    2011-07-12 01:50 . 2011-07-12 01:50 83816 ----a-w- c:\windows\system32\dns-sd.exe
    2011-07-12 01:50 . 2011-07-12 01:50 73064 ----a-w- c:\windows\system32\dnssd.dll
    2011-07-12 01:50 . 2011-07-12 01:50 178536 ----a-w- c:\windows\system32\dnssdX.dll
    2011-07-09 04:29 . 2011-08-24 03:04 2048 ----a-w- c:\windows\system32\tzres.dll
    2011-07-09 02:30 . 2011-08-10 04:50 223744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
    2011-09-08 01:41 . 2011-05-26 15:07 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
    2010-02-05 06:50 . 2010-02-10 16:25 79664 ----a-w- c:\program files\mozilla firefox\components\ThunderComponent.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "VeohPlugin "= "c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2011-06-30 2648184]
    "Sidebar "= "c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
    "SpybotSD TeaTimer "= "c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
    "uTorrent "= "c:\program files\uTorrent\uTorrent.exe" [2011-05-06 399736]
    "msnmsgr "= "c:\program files\Windows Live\Messenger\msnmsgr.exe" [2011-05-13 4283256]
    "DAEMON Tools Pro Agent "= "c:\program files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 136136]
    "PPS Accelerator "= "d:\pps.tv\PPStream\ppsap.exe" [2010-02-24 214408]
    "Skype "= "c:\program files\Skype\Phone\Skype.exe" [2011-05-26 15147400]
    "PPAP "= "c:\program files\Common Files\PPLiveNetwork\PPAP.exe" [2011-08-05 442232]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SoundMan "= "SOUNDMAN.EXE" [2009-04-13 604704]
    "UpdatePDRShortCut "= "c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-12-03 218408]
    "PaperPort PTD "= "c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2008-07-09 29984]
    "IndexSearch "= "c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2008-07-09 46368]
    "ControlCenter3 "= "c:\program files\Brother\ControlCenter3\brctrcen.exe" [2008-12-24 114688]
    "Launch LgDeviceAgent "= "c:\program files\Logitech\GamePanel Software\LgDevAgt.exe" [2010-08-02 358472]
    "Launch LCDMon "= "c:\program files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2010-08-02 1809992]
    "Launch LGDCore "= "c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2010-08-02 3649096]
    "BrMfcWnd "= "c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2009-05-26 1159168]
    "TkBellExe "= "c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-04-15 202256]
    "iTunesHelper "= "c:\program files\iTunes\iTunesHelper.exe" [2011-08-18 421736]
    "Kernel and Hardware Abstraction Layer "= "KHALMNPR.EXE" [2009-06-17 55824]
    "itype "= "c:\program files\Microsoft IntelliType Pro\itype.exe" [2010-07-21 1778064]
    "RIMBBLaunchAgent.exe "= "c:\program files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe" [2011-02-18 79192]
    "BCSSync "= "c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-01-21 91520]
    "StartCCC "= "c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-09-08 343168]
    "QuickTime Task "= "c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin "= 0 (0x0)
    "ConsentPromptBehaviorUser "= 3 (0x3)
    "EnableLUA "= 0 (0x0)
    "EnableUIADesktopToggle "= 0 (0x0)
    "PromptOnSecureDesktop "= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
    2009-07-20 01:58 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\klmdb.sys]
    @=" "
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
    @= "Service "
    .
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
    "DAEMON Tools Pro Agent "= "c:\program files\DAEMON Tools Pro\DTProAgent.exe "
    "uTorrent "= "c:\program files\uTorrent\uTorrent.exe "
    "PPS Accelerator "=d:\pps.tv\PPStream\ppsap.exe
    "msnmsgr "= "c:\program files\Windows Live\Messenger\msnmsgr.exe" /background
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "BCSSync "= "c:\program files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
    "SSBkgdUpdate "= "c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
    "VirtualCloneDrive "= "c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
    "WinampAgent "= "c:\program files\Winamp\winampa.exe "
    "PPort11reminder "= "c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "c:\programdata\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini "
    "SunJavaUpdateSched "= "c:\program files\Common Files\Java\Java Update\jusched.exe "
    "ATICustomerCare "= "c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe "
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
    "DisableMonitoring "=dword:00000001
    .
    R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
    R1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [x]
    R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [x]
    R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
    R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-09-08 176128]
    R2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-09-08 291840]
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-02-07 136176]
    R2 KMService;KMService;c:\windows\system32\srvany.exe [2010-11-08 8192]
    R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
    R3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2011-09-08 8606208]
    R3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2011-09-08 248832]
    R3 AODDriver4.0;AODDriver4.0;c:\program files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [2011-06-23 39424]
    R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2011-06-06 211984]
    R3 DKRtWrt;DKRtWrt;c:\windows\system32\DRIVERS\DKRtWrt.sys [2011-02-13 38608]
    R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-02-07 136176]
    R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [x]
    R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2009-11-23 14856]
    R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-01-21 30963576]
    R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2010-08-29 3739080]
    R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
    R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
    R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
    R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
    R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-22 1343400]
    S3 amdiox86;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox86.sys [2010-02-17 37944]
    S3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\Drivers\LEqdUsb.Sys [2009-06-17 40720]
    S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2009-11-23 19720]
    S3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\Drivers\LHidEqd.Sys [2009-06-17 10384]
    .
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2011-10-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cc215cfc50b11a.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2011-02-07 21:28]
    .
    2011-10-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA1cc215cfd2c0972.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2011-02-07 21:28]
    .
    .
    ------- Supplementary Scan -------
    .
    uInternet Settings,ProxyOverride = *.local
    IE: &Save Flash In This Page by Flash Saver
    IE: E&xport to Microsoft Excel
    IE: S&end to OneNote
    IE: 使用迅雷下载
    IE: 使用迅雷下载全部链接
    FF - ProfilePath - c:\users\Terence\AppData\Roaming\Mozilla\Firefox\Profiles\goad6cdl.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2653012&SearchSource=3&q={searchTerms}
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
    FF - prefs.js: keyword.URL - hxxp://www.google.com.au/search?q=
    FF - user.js: network.cookie.cookieBehavior - 0
    FF - user.js: privacy.clearOnShutdown.cookies - false
    FF - user.js: security.warn_viewing_mixed - false
    FF - user.js: security.warn_viewing_mixed.show_once - false
    FF - user.js: security.warn_submit_insecure - false
    FF - user.js: security.warn_submit_insecure.show_once - false
    .
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\services\npggsvc]
    "ImagePath "= "c:\windows\system32\GameMon.des -service "
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    完成时间: 2011-10-04 03:24:59
    ComboFix-quarantined-files.txt 2011-10-03 16:54
    ComboFix2.txt 2011-10-03 06:00
    ComboFix3.txt 2011-10-03 05:20
    ComboFix4.txt 2011-10-02 05:18
    ComboFix5.txt 2011-10-03 15:38
    .
    Pre-Run: 148,470,865,920 bytes free
    Post-Run: 148,291,985,408 bytes free
    .
    - - End Of File - - 845A81A55AA50CC3BCBA85DDBF03726D
     
  14. 2011/10/03
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    See if you can operate in normal mode now.
    Let me know.
     
  15. 2011/10/03
    terencew

    terencew Inactive Thread Starter

    Joined:
    2011/09/29
    Messages:
    34
    Likes Received:
    0
    well...i can get in to windows normally but it still blue screened on me a few times....also i notice a couple of my widgets not showing, for example the calender widget is not showing the date.
     
  16. 2011/10/03
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Download BlueScreenView (in Zip file)
    No installation required.
    Unzip downloaded file and double click on BlueScreenView.exe file to run the program.
    When scanning is done, go Edit>Select All.
    Go File>Save Selected Items, and save the report as BSOD.txt.
    Open BSOD.txt in Notepad, copy all content, and paste it into your next reply.
     
  17. 2011/10/03
    terencew

    terencew Inactive Thread Starter

    Joined:
    2011/09/29
    Messages:
    34
    Likes Received:
    0
    here's the BSOD log:

    ==================================================
    Dump File : 100411-44359-01.dmp
    Crash Time : 4/10/2011 1:25:01 PM
    Bug Check String :
    Bug Check Code : 0x00000124
    Parameter 1 : 0x00000000
    Parameter 2 : 0x863ff024
    Parameter 3 : 0xb6294000
    Parameter 4 : 0x00000145
    Caused By Driver : halmacpi.dll
    Caused By Address : halmacpi.dll+efcd
    File Description : Hardware Abstraction Layer DLL
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17514 (win7sp1_rtm.101119-1850)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+deeb4
    Stack Address 1 : halmacpi.dll+efcd
    Stack Address 2 : ntkrnlpa.exe+d1a6c
    Stack Address 3 : halmacpi.dll+f27f
    Computer Name :
    Full Path : C:\Windows\Minidump\100411-44359-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 139,936
    ==================================================

    ==================================================
    Dump File : 100411-43281-01.dmp
    Crash Time : 4/10/2011 1:22:31 PM
    Bug Check String :
    Bug Check Code : 0x00000124
    Parameter 1 : 0x00000000
    Parameter 2 : 0x863ff024
    Parameter 3 : 0xb6044000
    Parameter 4 : 0x00000135
    Caused By Driver : halmacpi.dll
    Caused By Address : halmacpi.dll+efcd
    File Description : Hardware Abstraction Layer DLL
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17514 (win7sp1_rtm.101119-1850)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+deeb4
    Stack Address 1 : halmacpi.dll+efcd
    Stack Address 2 : ntkrnlpa.exe+d1a6c
    Stack Address 3 : halmacpi.dll+f27f
    Computer Name :
    Full Path : C:\Windows\Minidump\100411-43281-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 139,936
    ==================================================

    ==================================================
    Dump File : 100411-52515-01.dmp
    Crash Time : 4/10/2011 4:39:25 AM
    Bug Check String :
    Bug Check Code : 0x00000124
    Parameter 1 : 0x00000000
    Parameter 2 : 0x8787c1e4
    Parameter 3 : 0xf62dc000
    Parameter 4 : 0x00000145
    Caused By Driver : halmacpi.dll
    Caused By Address : halmacpi.dll+efcd
    File Description : Hardware Abstraction Layer DLL
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17514 (win7sp1_rtm.101119-1850)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+deeb4
    Stack Address 1 : halmacpi.dll+efcd
    Stack Address 2 : ntkrnlpa.exe+d1a6c
    Stack Address 3 : halmacpi.dll+f27f
    Computer Name :
    Full Path : C:\Windows\Minidump\100411-52515-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 144,152
    ==================================================

    ==================================================
    Dump File : 100411-46656-02.dmp
    Crash Time : 4/10/2011 4:35:36 AM
    Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
    Bug Check Code : 0x1000008e
    Parameter 1 : 0xc000001d
    Parameter 2 : 0x8401c645
    Parameter 3 : 0x8416fbd8
    Parameter 4 : 0x00000000
    Caused By Driver : halmacpi.dll
    Caused By Address : halmacpi.dll+b645
    File Description : Hardware Abstraction Layer DLL
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17514 (win7sp1_rtm.101119-1850)
    Processor : 32-bit
    Crash Address : halmacpi.dll+b645
    Stack Address 1 : halmacpi.dll+bb8c
    Stack Address 2 : halmacpi.dll+cb69
    Stack Address 3 : ntkrnlpa.exe+8461d
    Computer Name :
    Full Path : C:\Windows\Minidump\100411-46656-02.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 144,152
    ==================================================

    ==================================================
    Dump File : 100411-46328-01.dmp
    Crash Time : 4/10/2011 4:20:26 AM
    Bug Check String : DRIVER_IRQL_NOT_LESS_OR_EQUAL
    Bug Check Code : 0x000000d1
    Parameter 1 : 0x83d709dc
    Parameter 2 : 0x00000002
    Parameter 3 : 0x00000008
    Parameter 4 : 0x83d709dc
    Caused By Driver : ataport.SYS
    Caused By Address : ataport.SYS+ff2d
    File Description : ATAPI Driver Extension
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+415db
    Stack Address 1 :
    Stack Address 2 : ataport.SYS+a2ac
    Stack Address 3 : ataport.SYS+a677
    Computer Name :
    Full Path : C:\Windows\Minidump\100411-46328-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 144,152
    ==================================================

    ==================================================
    Dump File : 100411-46500-01.dmp
    Crash Time : 4/10/2011 4:07:48 AM
    Bug Check String : DRIVER_IRQL_NOT_LESS_OR_EQUAL
    Bug Check Code : 0x000000d1
    Parameter 1 : 0x04d35010
    Parameter 2 : 0x00000005
    Parameter 3 : 0x00000000
    Parameter 4 : 0x84d34394
    Caused By Driver : atapi.sys
    Caused By Address : atapi.sys+3394
    File Description : ATAPI IDE Miniport Driver
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+415db
    Stack Address 1 : atapi.sys+3394
    Stack Address 2 : ataport.SYS+9f10
    Stack Address 3 : ataport.SYS+a49a
    Computer Name :
    Full Path : C:\Windows\Minidump\100411-46500-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 144,104
    ==================================================

    ==================================================
    Dump File : 100411-46640-01.dmp
    Crash Time : 4/10/2011 4:03:18 AM
    Bug Check String : DRIVER_IRQL_NOT_LESS_OR_EQUAL
    Bug Check Code : 0x000000d1
    Parameter 1 : 0x44d6f092
    Parameter 2 : 0x00000002
    Parameter 3 : 0x00000008
    Parameter 4 : 0x44d6f092
    Caused By Driver : ataport.SYS
    Caused By Address : ataport.SYS+12001
    File Description : ATAPI Driver Extension
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+415db
    Stack Address 1 :
    Stack Address 2 : PCIIDEX.SYS+1074
    Stack Address 3 : halmacpi.dll+4a2e
    Computer Name :
    Full Path : C:\Windows\Minidump\100411-46640-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 144,152
    ==================================================

    ==================================================
    Dump File : 100411-47890-01.dmp
    Crash Time : 4/10/2011 3:48:09 AM
    Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
    Bug Check Code : 0x1000008e
    Parameter 1 : 0xc0000005
    Parameter 2 : 0x8327fe7e
    Parameter 3 : 0x807dec0d
    Parameter 4 : 0x00000000
    Caused By Driver : ntkrnlpa.exe
    Caused By Address : ntkrnlpa.exe+79e7e
    File Description : NT Kernel & System
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17640 (win7sp1_gdr.110622-1506)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+79e7e
    Stack Address 1 : ntkrnlpa.exe+7800e
    Stack Address 2 : ntkrnlpa.exe+77e38
    Stack Address 3 :
    Computer Name :
    Full Path : C:\Windows\Minidump\100411-47890-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 139,936
    ==================================================

    ==================================================
    Dump File : 100411-48390-01.dmp
    Crash Time : 4/10/2011 3:08:44 AM
    Bug Check String :
    Bug Check Code : 0x00000124
    Parameter 1 : 0x00000000
    Parameter 2 : 0x863121e4
    Parameter 3 : 0xb6294000
    Parameter 4 : 0x00000135
    Caused By Driver : halmacpi.dll
    Caused By Address : halmacpi.dll+efcd
    File Description : Hardware Abstraction Layer DLL
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17514 (win7sp1_rtm.101119-1850)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+deeb4
    Stack Address 1 : halmacpi.dll+efcd
    Stack Address 2 : ntkrnlpa.exe+d1a6c
    Stack Address 3 : halmacpi.dll+f27f
    Computer Name :
    Full Path : C:\Windows\Minidump\100411-48390-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 139,936
    ==================================================

    ==================================================
    Dump File : 100411-47203-01.dmp
    Crash Time : 4/10/2011 2:58:52 AM
    Bug Check String : IRQL_NOT_LESS_OR_EQUAL
    Bug Check Code : 0x0000000a
    Parameter 1 : 0x01df2600
    Parameter 2 : 0x0000001c
    Parameter 3 : 0x00000001
    Parameter 4 : 0x836150e6
    Caused By Driver : halmacpi.dll
    Caused By Address : halmacpi.dll+30e6
    File Description : Hardware Abstraction Layer DLL
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17514 (win7sp1_rtm.101119-1850)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+415db
    Stack Address 1 : halmacpi.dll+30e6
    Stack Address 2 : halmacpi.dll+19196
    Stack Address 3 : ntkrnlpa.exe+77e0d
    Computer Name :
    Full Path : C:\Windows\Minidump\100411-47203-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 137,600
    ==================================================

    ==================================================
    Dump File : 100411-56859-01.dmp
    Crash Time : 4/10/2011 2:42:20 AM
    Bug Check String : DRIVER_IRQL_NOT_LESS_OR_EQUAL
    Bug Check Code : 0x000000d1
    Parameter 1 : 0x075ad010
    Parameter 2 : 0x00000005
    Parameter 3 : 0x00000000
    Parameter 4 : 0x875ac394
    Caused By Driver : atapi.sys
    Caused By Address : atapi.sys+3394
    File Description : ATAPI IDE Miniport Driver
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+415db
    Stack Address 1 : atapi.sys+3394
    Stack Address 2 : ataport.SYS+9f10
    Stack Address 3 : ataport.SYS+a49a
    Computer Name :
    Full Path : C:\Windows\Minidump\100411-56859-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 139,936
    ==================================================

    ==================================================
    Dump File : 100411-49937-01.dmp
    Crash Time : 4/10/2011 2:21:25 AM
    Bug Check String :
    Bug Check Code : 0x00000124
    Parameter 1 : 0x00000000
    Parameter 2 : 0x866a7024
    Parameter 3 : 0xb6294000
    Parameter 4 : 0x00000135
    Caused By Driver : halmacpi.dll
    Caused By Address : halmacpi.dll+efcd
    File Description : Hardware Abstraction Layer DLL
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17514 (win7sp1_rtm.101119-1850)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+deeb4
    Stack Address 1 : halmacpi.dll+efcd
    Stack Address 2 : ntkrnlpa.exe+d1a6c
    Stack Address 3 : halmacpi.dll+f27f
    Computer Name :
    Full Path : C:\Windows\Minidump\100411-49937-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 139,936
    ==================================================

    ==================================================
    Dump File : 100411-68265-01.dmp
    Crash Time : 4/10/2011 2:06:41 AM
    Bug Check String : DRIVER_IRQL_NOT_LESS_OR_EQUAL
    Bug Check Code : 0x000000d1
    Parameter 1 : 0xc608364d
    Parameter 2 : 0x00000002
    Parameter 3 : 0x00000000
    Parameter 4 : 0x879ad5da
    Caused By Driver : ataport.SYS
    Caused By Address : ataport.SYS+a49a
    File Description : ATAPI Driver Extension
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+415db
    Stack Address 1 : ataport.SYS+a5da
    Stack Address 2 : ntkrnlpa.exe+781b5
    Stack Address 3 :
    Computer Name :
    Full Path : C:\Windows\Minidump\100411-68265-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 139,936
    ==================================================

    ==================================================
    Dump File : 100411-46984-01.dmp
    Crash Time : 4/10/2011 1:58:02 AM
    Bug Check String : DRIVER_IRQL_NOT_LESS_OR_EQUAL
    Bug Check Code : 0x000000d1
    Parameter 1 : 0x8995cb06
    Parameter 2 : 0x00000002
    Parameter 3 : 0x00000008
    Parameter 4 : 0x8995cb06
    Caused By Driver : atapi.sys
    Caused By Address : atapi.sys+2e8d
    File Description : ATAPI IDE Miniport Driver
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+415db
    Stack Address 1 :
    Stack Address 2 : ataport.SYS+a0f4
    Stack Address 3 : PCIIDEX.SYS+1074
    Computer Name :
    Full Path : C:\Windows\Minidump\100411-46984-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 139,936
    ==================================================

    ==================================================
    Dump File : 100411-50468-01.dmp
    Crash Time : 4/10/2011 1:52:20 AM
    Bug Check String : IRQL_NOT_LESS_OR_EQUAL
    Bug Check Code : 0x0000000a
    Parameter 1 : 0xbc650af8
    Parameter 2 : 0x0000001c
    Parameter 3 : 0x00000000
    Parameter 4 : 0x8461f149
    Caused By Driver : halmacpi.dll
    Caused By Address : halmacpi.dll+3149
    File Description : Hardware Abstraction Layer DLL
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17514 (win7sp1_rtm.101119-1850)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+415db
    Stack Address 1 : halmacpi.dll+3149
    Stack Address 2 : amdk8.sys+1bb6
    Stack Address 3 : ntkrnlpa.exe+77e0d
    Computer Name :
    Full Path : C:\Windows\Minidump\100411-50468-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 144,152
    ==================================================

    ==================================================
    Dump File : 100411-51328-01.dmp
    Crash Time : 4/10/2011 1:48:58 AM
    Bug Check String : IRQL_NOT_LESS_OR_EQUAL
    Bug Check Code : 0x0000000a
    Parameter 1 : 0xf0300aab
    Parameter 2 : 0x0000001c
    Parameter 3 : 0x00000000
    Parameter 4 : 0x83a2d147
    Caused By Driver : halmacpi.dll
    Caused By Address : halmacpi.dll+3147
    File Description : Hardware Abstraction Layer DLL
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17514 (win7sp1_rtm.101119-1850)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+415db
    Stack Address 1 : halmacpi.dll+3147
    Stack Address 2 : halmacpi.dll+19196
    Stack Address 3 : ntkrnlpa.exe+77e0d
    Computer Name :
    Full Path : C:\Windows\Minidump\100411-51328-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 139,936
    ==================================================

    ==================================================
    Dump File : 100411-61421-01.dmp
    Crash Time : 4/10/2011 1:45:28 AM
    Bug Check String : UNEXPECTED_KERNEL_MODE_TRAP
    Bug Check Code : 0x0000007f
    Parameter 1 : 0x0000000d
    Parameter 2 : 0x00000000
    Parameter 3 : 0x00000000
    Parameter 4 : 0x00000000
    Caused By Driver : ntkrnlpa.exe
    Caused By Address : ntkrnlpa.exe+41d1b
    File Description : NT Kernel & System
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17640 (win7sp1_gdr.110622-1506)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+41d1b
    Stack Address 1 : ntkrnlpa.exe+7d762
    Stack Address 2 :
    Stack Address 3 :
    Computer Name :
    Full Path : C:\Windows\Minidump\100411-61421-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 139,936
    ==================================================

    ==================================================
    Dump File : 100411-48328-01.dmp
    Crash Time : 4/10/2011 1:41:46 AM
    Bug Check String : DRIVER_IRQL_NOT_LESS_OR_EQUAL
    Bug Check Code : 0x000000d1
    Parameter 1 : 0x00000038
    Parameter 2 : 0x00000002
    Parameter 3 : 0x00000000
    Parameter 4 : 0x8795b7dd
    Caused By Driver : ataport.SYS
    Caused By Address : ataport.SYS+87dd
    File Description : ATAPI Driver Extension
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+415db
    Stack Address 1 : ataport.SYS+87dd
    Stack Address 2 : ataport.SYS+a199
    Stack Address 3 : ataport.SYS+a63e
    Computer Name :
    Full Path : C:\Windows\Minidump\100411-48328-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 139,936
    ==================================================

    ==================================================
    Dump File : 100311-49140-01.dmp
    Crash Time : 3/10/2011 4:14:35 PM
    Bug Check String : DRIVER_IRQL_NOT_LESS_OR_EQUAL
    Bug Check Code : 0x000000d1
    Parameter 1 : 0x00000000
    Parameter 2 : 0x00000002
    Parameter 3 : 0x00000001
    Parameter 4 : 0x86961e01
    Caused By Driver : atapi.sys
    Caused By Address : atapi.sys+2e3a
    File Description : ATAPI IDE Miniport Driver
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+415db
    Stack Address 1 :
    Stack Address 2 : ataport.SYS+a0f4
    Stack Address 3 : PCIIDEX.SYS+1074
    Computer Name :
    Full Path : C:\Windows\Minidump\100311-49140-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 139,936
    ==================================================

    ==================================================
    Dump File : 100311-51218-01.dmp
    Crash Time : 3/10/2011 4:07:49 PM
    Bug Check String : IRQL_NOT_LESS_OR_EQUAL
    Bug Check Code : 0x0000000a
    Parameter 1 : 0x6fdf0014
    Parameter 2 : 0x0000001c
    Parameter 3 : 0x00000001
    Parameter 4 : 0x842c89a0
    Caused By Driver : ntkrnlpa.exe
    Caused By Address : ntkrnlpa.exe+415db
    File Description : NT Kernel & System
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17640 (win7sp1_gdr.110622-1506)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+415db
    Stack Address 1 : ntkrnlpa.exe+7a9a0
    Stack Address 2 : ntkrnlpa.exe+7fbd7
    Stack Address 3 : amdk8.sys+1bb6
    Computer Name :
    Full Path : C:\Windows\Minidump\100311-51218-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 144,152
    ==================================================

    ==================================================
    Dump File : 100311-46062-01.dmp
    Crash Time : 3/10/2011 3:57:46 PM
    Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
    Bug Check Code : 0x1000008e
    Parameter 1 : 0x80000003
    Parameter 2 : 0x8463a0f5
    Parameter 3 : 0x8433bbac
    Parameter 4 : 0x00000000
    Caused By Driver : halmacpi.dll
    Caused By Address : halmacpi.dll+140f6
    File Description : Hardware Abstraction Layer DLL
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17514 (win7sp1_rtm.101119-1850)
    Processor : 32-bit
    Crash Address : halmacpi.dll+140f6
    Stack Address 1 : amdk8.sys+1bb6
    Stack Address 2 : ntkrnlpa.exe+77e0d
    Stack Address 3 :
    Computer Name :
    Full Path : C:\Windows\Minidump\100311-46062-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 144,152
    ==================================================

    ==================================================
    Dump File : 100311-34781-01.dmp
    Crash Time : 3/10/2011 3:34:45 PM
    Bug Check String : DRIVER_IRQL_NOT_LESS_OR_EQUAL
    Bug Check Code : 0x000000d1
    Parameter 1 : 0xe7926f38
    Parameter 2 : 0x00000005
    Parameter 3 : 0x00000001
    Parameter 4 : 0x84fbe8d1
    Caused By Driver : ataport.SYS
    Caused By Address : ataport.SYS+c8d1
    File Description : ATAPI Driver Extension
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+415db
    Stack Address 1 : ataport.SYS+c8d1
    Stack Address 2 : ataport.SYS+ca4c
    Stack Address 3 : ataport.SYS+ce05
    Computer Name :
    Full Path : C:\Windows\Minidump\100311-34781-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 137,504
    ==================================================

    ==================================================
    Dump File : 100311-53859-01.dmp
    Crash Time : 3/10/2011 3:25:42 PM
    Bug Check String :
    Bug Check Code : 0x00000124
    Parameter 1 : 0x00000000
    Parameter 2 : 0x87821024
    Parameter 3 : 0xf6000000
    Parameter 4 : 0x00000181
    Caused By Driver : halmacpi.dll
    Caused By Address : halmacpi.dll+efcd
    File Description : Hardware Abstraction Layer DLL
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17514 (win7sp1_rtm.101119-1850)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+deeb4
    Stack Address 1 : halmacpi.dll+efcd
    Stack Address 2 : ntkrnlpa.exe+d1a6c
    Stack Address 3 : halmacpi.dll+f27f
    Computer Name :
    Full Path : C:\Windows\Minidump\100311-53859-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 143,968
    ==================================================

    ==================================================
    Dump File : 100311-47375-01.dmp
    Crash Time : 3/10/2011 3:21:38 PM
    Bug Check String :
    Bug Check Code : 0x00000124
    Parameter 1 : 0x00000000
    Parameter 2 : 0x867fa024
    Parameter 3 : 0xb62c4000
    Parameter 4 : 0x00000135
    Caused By Driver : halmacpi.dll
    Caused By Address : halmacpi.dll+efcd
    File Description : Hardware Abstraction Layer DLL
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17514 (win7sp1_rtm.101119-1850)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+deeb4
    Stack Address 1 : halmacpi.dll+efcd
    Stack Address 2 : ntkrnlpa.exe+d1a6c
    Stack Address 3 : halmacpi.dll+f27f
    Computer Name :
    Full Path : C:\Windows\Minidump\100311-47375-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 137,560
    ==================================================

    ==================================================
    Dump File : 100211-50468-01.dmp
    Crash Time : 2/10/2011 8:15:38 PM
    Bug Check String : IRQL_NOT_LESS_OR_EQUAL
    Bug Check Code : 0x0000000a
    Parameter 1 : 0x51011c74
    Parameter 2 : 0x0000001c
    Parameter 3 : 0x00000000
    Parameter 4 : 0x846420f1
    Caused By Driver : halmacpi.dll
    Caused By Address : halmacpi.dll+140f1
    File Description : Hardware Abstraction Layer DLL
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17514 (win7sp1_rtm.101119-1850)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+415db
    Stack Address 1 : halmacpi.dll+140f1
    Stack Address 2 : amdk8.sys+1bb6
    Stack Address 3 : ntkrnlpa.exe+77e0d
    Computer Name :
    Full Path : C:\Windows\Minidump\100211-50468-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 144,112
    ==================================================

    ==================================================
    Dump File : 100211-52843-01.dmp
    Crash Time : 2/10/2011 8:12:26 PM
    Bug Check String : PAGE_FAULT_IN_NONPAGED_AREA
    Bug Check Code : 0x00000050
    Parameter 1 : 0xff797418
    Parameter 2 : 0x00000000
    Parameter 3 : 0x82466146
    Parameter 4 : 0x00000000
    Caused By Driver : ntkrnlpa.exe
    Caused By Address : ntkrnlpa.exe+8e3db
    File Description : NT Kernel & System
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17640 (win7sp1_gdr.110622-1506)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+8e3db
    Stack Address 1 : ntkrnlpa.exe+413e8
    Stack Address 2 : win32k.sys+c6146
    Stack Address 3 : win32k.sys+bb26e
    Computer Name :
    Full Path : C:\Windows\Minidump\100211-52843-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 144,112
    ==================================================

    ==================================================
    Dump File : 100211-40093-01.dmp
    Crash Time : 2/10/2011 7:39:37 PM
    Bug Check String : UNEXPECTED_KERNEL_MODE_TRAP
    Bug Check Code : 0x0000007f
    Parameter 1 : 0x0000000d
    Parameter 2 : 0x00000000
    Parameter 3 : 0x00000000
    Parameter 4 : 0x00000000
    Caused By Driver : ataport.SYS
    Caused By Address : ataport.SYS+51dc
    File Description : ATAPI Driver Extension
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+41d1b
    Stack Address 1 : halmacpi.dll+3806
    Stack Address 2 : ataport.SYS+8828
    Stack Address 3 : ataport.SYS+a199
    Computer Name :
    Full Path : C:\Windows\Minidump\100211-40093-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 144,112
    ==================================================

    ==================================================
    Dump File : 100211-50421-01.dmp
    Crash Time : 2/10/2011 7:03:25 PM
    Bug Check String : IRQL_NOT_LESS_OR_EQUAL
    Bug Check Code : 0x0000000a
    Parameter 1 : 0x00000000
    Parameter 2 : 0x0000001c
    Parameter 3 : 0x00000001
    Parameter 4 : 0x8361f166
    Caused By Driver : halmacpi.dll
    Caused By Address : halmacpi.dll+3166
    File Description : Hardware Abstraction Layer DLL
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17514 (win7sp1_rtm.101119-1850)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+415db
    Stack Address 1 : halmacpi.dll+3166
    Stack Address 2 : halmacpi.dll+19196
    Stack Address 3 : ntkrnlpa.exe+77e0d
    Computer Name :
    Full Path : C:\Windows\Minidump\100211-50421-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 139,896
    ==================================================

    ==================================================
    Dump File : 100211-50734-01.dmp
    Crash Time : 2/10/2011 6:35:56 PM
    Bug Check String : NTFS_FILE_SYSTEM
    Bug Check Code : 0x00000024
    Parameter 1 : 0x001904fb
    Parameter 2 : 0x8139c274
    Parameter 3 : 0x8139be50
    Parameter 4 : 0x87a18435
    Caused By Driver : Ntfs.sys
    Caused By Address : Ntfs.sys+13435
    File Description : NT File System Driver
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+deeb4
    Stack Address 1 : Ntfs.sys+1a9af
    Stack Address 2 : Ntfs.sys+1488f
    Stack Address 3 : ntkrnlpa.exe+3758e
    Computer Name :
    Full Path : C:\Windows\Minidump\100211-50734-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 139,896
    ==================================================

    ==================================================
    Dump File : 100211-48093-01.dmp
    Crash Time : 2/10/2011 6:29:39 PM
    Bug Check String : IRQL_NOT_LESS_OR_EQUAL
    Bug Check Code : 0x0000000a
    Parameter 1 : 0x21a76000
    Parameter 2 : 0x00000002
    Parameter 3 : 0x00000001
    Parameter 4 : 0x83a24a08
    Caused By Driver : halmacpi.dll
    Caused By Address : halmacpi.dll+4a08
    File Description : Hardware Abstraction Layer DLL
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17514 (win7sp1_rtm.101119-1850)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+415db
    Stack Address 1 : halmacpi.dll+4a08
    Stack Address 2 :
    Stack Address 3 :
    Computer Name :
    Full Path : C:\Windows\Minidump\100211-48093-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 139,800
    ==================================================

    ==================================================
    Dump File : 100211-36937-01.dmp
    Crash Time : 2/10/2011 4:40:15 PM
    Bug Check String :
    Bug Check Code : 0x00000124
    Parameter 1 : 0x00000000
    Parameter 2 : 0x867db024
    Parameter 3 : 0xb6044000
    Parameter 4 : 0x00000135
    Caused By Driver : halmacpi.dll
    Caused By Address : halmacpi.dll+efcd
    File Description : Hardware Abstraction Layer DLL
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17514 (win7sp1_rtm.101119-1850)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+deeb4
    Stack Address 1 : halmacpi.dll+efcd
    Stack Address 2 : ntkrnlpa.exe+d1a6c
    Stack Address 3 : halmacpi.dll+f27f
    Computer Name :
    Full Path : C:\Windows\Minidump\100211-36937-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 144,016
    ==================================================

    ==================================================
    Dump File : 100211-42937-01.dmp
    Crash Time : 2/10/2011 4:35:22 PM
    Bug Check String : IRQL_NOT_LESS_OR_EQUAL
    Bug Check Code : 0x0000000a
    Parameter 1 : 0x602f7aab
    Parameter 2 : 0x0000001c
    Parameter 3 : 0x00000000
    Parameter 4 : 0x83a24147
    Caused By Driver : halmacpi.dll
    Caused By Address : halmacpi.dll+3147
    File Description : Hardware Abstraction Layer DLL
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17514 (win7sp1_rtm.101119-1850)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+415db
    Stack Address 1 : halmacpi.dll+3147
    Stack Address 2 : halmacpi.dll+19196
    Stack Address 3 : ntkrnlpa.exe+77e0d
    Computer Name :
    Full Path : C:\Windows\Minidump\100211-42937-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 139,800
    ==================================================

    ==================================================
    Dump File : 100211-34687-01.dmp
    Crash Time : 2/10/2011 4:30:53 PM
    Bug Check String : UNEXPECTED_KERNEL_MODE_TRAP
    Bug Check Code : 0x0000007f
    Parameter 1 : 0x0000000d
    Parameter 2 : 0x00000000
    Parameter 3 : 0x00000000
    Parameter 4 : 0x00000000
    Caused By Driver : ndis.sys
    Caused By Address : ndis.sys+37f82
    File Description : NDIS 6.20 driver
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+41d1b
    Stack Address 1 : ntkrnlpa.exe+84607
    Stack Address 2 : ntkrnlpa.exe+77e0d
    Stack Address 3 :
    Computer Name :
    Full Path : C:\Windows\Minidump\100211-34687-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 144,016
    ==================================================

    ==================================================
    Dump File : 100211-40109-01.dmp
    Crash Time : 2/10/2011 4:26:27 PM
    Bug Check String : IRQL_NOT_LESS_OR_EQUAL
    Bug Check Code : 0x0000000a
    Parameter 1 : 0xbc4c8af8
    Parameter 2 : 0x0000001c
    Parameter 3 : 0x00000000
    Parameter 4 : 0x84627149
    Caused By Driver : halmacpi.dll
    Caused By Address : halmacpi.dll+3149
    File Description : Hardware Abstraction Layer DLL
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17514 (win7sp1_rtm.101119-1850)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+415db
    Stack Address 1 : halmacpi.dll+3149
    Stack Address 2 : amdk8.sys+1bb6
    Stack Address 3 : ntkrnlpa.exe+77e0d
    Computer Name :
    Full Path : C:\Windows\Minidump\100211-40109-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 144,016
    ==================================================

    ==================================================
    Dump File : 100211-103953-01.dmp
    Crash Time : 2/10/2011 4:21:49 PM
    Bug Check String : IRQL_NOT_LESS_OR_EQUAL
    Bug Check Code : 0x0000000a
    Parameter 1 : 0x000025a9
    Parameter 2 : 0x0000001c
    Parameter 3 : 0x00000000
    Parameter 4 : 0x836190f1
    Caused By Driver : halmacpi.dll
    Caused By Address : halmacpi.dll+140f1
    File Description : Hardware Abstraction Layer DLL
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17514 (win7sp1_rtm.101119-1850)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+415db
    Stack Address 1 : halmacpi.dll+140f1
    Stack Address 2 : halmacpi.dll+19196
    Stack Address 3 : ntkrnlpa.exe+77e0d
    Computer Name :
    Full Path : C:\Windows\Minidump\100211-103953-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 139,800
    ==================================================

    ==================================================
    Dump File : 100211-41578-01.dmp
    Crash Time : 2/10/2011 4:09:19 PM
    Bug Check String : DRIVER_IRQL_NOT_LESS_OR_EQUAL
    Bug Check Code : 0x000000d1
    Parameter 1 : 0x9fe264dc
    Parameter 2 : 0x00000002
    Parameter 3 : 0x00000001
    Parameter 4 : 0x88a839e2
    Caused By Driver : tcpip.sys
    Caused By Address : tcpip.sys+7d9e2
    File Description : TCP/IP Driver
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+415db
    Stack Address 1 : tcpip.sys+7d9e2
    Stack Address 2 : tcpip.sys+7bdb6
    Stack Address 3 : tcpip.sys+734f7
    Computer Name :
    Full Path : C:\Windows\Minidump\100211-41578-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 144,016
    ==================================================

    ==================================================
    Dump File : 100211-43734-01.dmp
    Crash Time : 2/10/2011 3:20:16 PM
    Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
    Bug Check Code : 0x1000008e
    Parameter 1 : 0xc000001d
    Parameter 2 : 0x84635b8d
    Parameter 3 : 0x807ddbf0
    Parameter 4 : 0x00000000
    Caused By Driver : halmacpi.dll
    Caused By Address : halmacpi.dll+bb8d
    File Description : Hardware Abstraction Layer DLL
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17514 (win7sp1_rtm.101119-1850)
    Processor : 32-bit
    Crash Address : halmacpi.dll+bb8d
    Stack Address 1 : halmacpi.dll+cb69
    Stack Address 2 : ntkrnlpa.exe+8461d
    Stack Address 3 : ntkrnlpa.exe+803c8
    Computer Name :
    Full Path : C:\Windows\Minidump\100211-43734-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 144,016
    ==================================================

    ==================================================
    Dump File : 100211-37671-01.dmp
    Crash Time : 2/10/2011 3:20:09 PM
    Bug Check String :
    Bug Check Code : 0x00000124
    Parameter 1 : 0x00000000
    Parameter 2 : 0x86375024
    Parameter 3 : 0xf6044000
    Parameter 4 : 0x00000135
    Caused By Driver : halmacpi.dll
    Caused By Address : halmacpi.dll+efcd
    File Description : Hardware Abstraction Layer DLL
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17514 (win7sp1_rtm.101119-1850)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+deeb4
    Stack Address 1 : halmacpi.dll+efcd
    Stack Address 2 : ntkrnlpa.exe+d1a6c
    Stack Address 3 : halmacpi.dll+f27f
    Computer Name :
    Full Path : C:\Windows\Minidump\100211-37671-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 139,800
    ==================================================

    ==================================================
    Dump File : 100211-38578-01.dmp
    Crash Time : 2/10/2011 3:13:11 PM
    Bug Check String : IRQL_NOT_LESS_OR_EQUAL
    Bug Check Code : 0x0000000a
    Parameter 1 : 0x8320cabd
    Parameter 2 : 0x00000005
    Parameter 3 : 0x00000000
    Parameter 4 : 0x83215aac
    Caused By Driver : halmacpi.dll
    Caused By Address : halmacpi.dll+5aac
    File Description : Hardware Abstraction Layer DLL
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17514 (win7sp1_rtm.101119-1850)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+415db
    Stack Address 1 : halmacpi.dll+5aac
    Stack Address 2 : halmacpi.dll+5ba9
    Stack Address 3 : ntkrnlpa.exe+7d92f
    Computer Name :
    Full Path : C:\Windows\Minidump\100211-38578-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 139,800
    ==================================================

    ==================================================
    Dump File : 100211-37156-01.dmp
    Crash Time : 2/10/2011 3:09:26 PM
    Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
    Bug Check Code : 0x1000008e
    Parameter 1 : 0xc0000005
    Parameter 2 : 0x833684a7
    Parameter 3 : 0x8f2571d4
    Parameter 4 : 0x00000000
    Caused By Driver : win32k.sys
    Caused By Address : win32k.sys+d8255
    File Description : Multi-User Win32 Driver
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+1204a7
    Stack Address 1 : win32k.sys+ca53e
    Stack Address 2 : win32k.sys+d17c5
    Stack Address 3 : win32k.sys+d85a9
    Computer Name :
    Full Path : C:\Windows\Minidump\100211-37156-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 139,752
    ==================================================

    ==================================================
    Dump File : 100211-36984-01.dmp
    Crash Time : 2/10/2011 3:04:55 PM
    Bug Check String : IRQL_NOT_LESS_OR_EQUAL
    Bug Check Code : 0x0000000a
    Parameter 1 : 0xb9cccaf8
    Parameter 2 : 0x0000001c
    Parameter 3 : 0x00000000
    Parameter 4 : 0x84016149
    Caused By Driver : halmacpi.dll
    Caused By Address : halmacpi.dll+3149
    File Description : Hardware Abstraction Layer DLL
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17514 (win7sp1_rtm.101119-1850)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+415db
    Stack Address 1 : halmacpi.dll+3149
    Stack Address 2 : amdk8.sys+1bb6
    Stack Address 3 : ntkrnlpa.exe+77e0d
    Computer Name :
    Full Path : C:\Windows\Minidump\100211-36984-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 143,968
    ==================================================

    ==================================================
    Dump File : 100211-41437-01.dmp
    Crash Time : 2/10/2011 3:02:17 PM
    Bug Check String : NTFS_FILE_SYSTEM
    Bug Check Code : 0x00000024
    Parameter 1 : 0x001904fb
    Parameter 2 : 0x89782324
    Parameter 3 : 0x89781f00
    Parameter 4 : 0x84e18435
    Caused By Driver : Ntfs.sys
    Caused By Address : Ntfs.sys+13435
    File Description : NT File System Driver
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+deeb4
    Stack Address 1 : Ntfs.sys+1a9af
    Stack Address 2 : Ntfs.sys+1488f
    Stack Address 3 : ntkrnlpa.exe+3758e
    Computer Name :
    Full Path : C:\Windows\Minidump\100211-41437-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 144,016
    ==================================================

    ==================================================
    Dump File : 100211-40250-01.dmp
    Crash Time : 2/10/2011 2:55:26 PM
    Bug Check String : BAD_SYSTEM_CONFIG_INFO
    Bug Check Code : 0x00000074
    Parameter 1 : 0x00000002
    Parameter 2 : 0x8be33ba8
    Parameter 3 : 0x00000002
    Parameter 4 : 0xc000015c
    Caused By Driver : ntkrnlpa.exe
    Caused By Address : ntkrnlpa.exe+deeb4
    File Description : NT Kernel & System
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17640 (win7sp1_gdr.110622-1506)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+deeb4
    Stack Address 1 : ntkrnlpa.exe+191974
    Stack Address 2 : ntkrnlpa.exe+208fda
    Stack Address 3 :
    Computer Name :
    Full Path : C:\Windows\Minidump\100211-40250-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 137,464
    ==================================================

    ==================================================
    Dump File : 100211-43640-01.dmp
    Crash Time : 2/10/2011 2:48:46 PM
    Bug Check String : IRQL_NOT_LESS_OR_EQUAL
    Bug Check Code : 0x0000000a
    Parameter 1 : 0xa442ecbc
    Parameter 2 : 0x0000001c
    Parameter 3 : 0x00000000
    Parameter 4 : 0x84425149
    Caused By Driver : halmacpi.dll
    Caused By Address : halmacpi.dll+3149
    File Description : Hardware Abstraction Layer DLL
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17514 (win7sp1_rtm.101119-1850)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+415db
    Stack Address 1 : halmacpi.dll+3149
    Stack Address 2 : amdk8.sys+1bb6
    Stack Address 3 : ntkrnlpa.exe+77e0d
    Computer Name :
    Full Path : C:\Windows\Minidump\100211-43640-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 144,016
    ==================================================

    ==================================================
    Dump File : 100211-59296-01.dmp
    Crash Time : 2/10/2011 2:26:23 AM
    Bug Check String : IRQL_NOT_LESS_OR_EQUAL
    Bug Check Code : 0x0000000a
    Parameter 1 : 0x83c48ca0
    Parameter 2 : 0x0000001c
    Parameter 3 : 0x00000000
    Parameter 4 : 0x8382f142
    Caused By Driver : halmacpi.dll
    Caused By Address : halmacpi.dll+3142
    File Description : Hardware Abstraction Layer DLL
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17514 (win7sp1_rtm.101119-1850)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+415db
    Stack Address 1 : halmacpi.dll+3142
    Stack Address 2 : halmacpi.dll+19196
    Stack Address 3 : ntkrnlpa.exe+77e0d
    Computer Name :
    Full Path : C:\Windows\Minidump\100211-59296-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 139,896
    ==================================================

    ==================================================
    Dump File : 100211-48109-01.dmp
    Crash Time : 2/10/2011 2:06:00 AM
    Bug Check String : DRIVER_IRQL_NOT_LESS_OR_EQUAL
    Bug Check Code : 0x000000d1
    Parameter 1 : 0x00fbb890
    Parameter 2 : 0x00000002
    Parameter 3 : 0x00000001
    Parameter 4 : 0x89000007
    Caused By Driver : usbohci.sys
    Caused By Address : usbohci.sys+7
    File Description : OHCI USB Miniport Driver
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17586 (win7sp1_gdr.110324-1501)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+415db
    Stack Address 1 : usbohci.sys+7
    Stack Address 2 :
    Stack Address 3 :
    Computer Name :
    Full Path : C:\Windows\Minidump\100211-48109-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 139,896
    ==================================================

    ==================================================
    Dump File : 100211-52343-01.dmp
    Crash Time : 2/10/2011 1:52:41 AM
    Bug Check String : IRQL_NOT_LESS_OR_EQUAL
    Bug Check Code : 0x0000000a
    Parameter 1 : 0x33bd77ac
    Parameter 2 : 0x0000001c
    Parameter 3 : 0x00000000
    Parameter 4 : 0x83821142
    Caused By Driver : halmacpi.dll
    Caused By Address : halmacpi.dll+3142
    File Description : Hardware Abstraction Layer DLL
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17514 (win7sp1_rtm.101119-1850)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+415db
    Stack Address 1 : halmacpi.dll+3142
    Stack Address 2 : halmacpi.dll+19196
    Stack Address 3 : ntkrnlpa.exe+77e0d
    Computer Name :
    Full Path : C:\Windows\Minidump\100211-52343-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 139,896
    ==================================================

    ==================================================
    Dump File : 100211-49906-01.dmp
    Crash Time : 2/10/2011 1:39:25 AM
    Bug Check String : ATTEMPTED_EXECUTE_OF_NOEXECUTE_MEMORY
    Bug Check Code : 0x000000fc
    Parameter 1 : 0x807ddc78
    Parameter 2 : 0x7c3c6963
    Parameter 3 : 0x807ddbd8
    Parameter 4 : 0x00000000
    Caused By Driver : atapi.sys
    Caused By Address : atapi.sys+2fc2
    File Description : ATAPI IDE Miniport Driver
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7600.16385 (win7_rtm.090713-1255)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+8e3db
    Stack Address 1 : ntkrnlpa.exe+413e8
    Stack Address 2 :
    Stack Address 3 : ataport.SYS+a638
    Computer Name :
    Full Path : C:\Windows\Minidump\100211-49906-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 139,896
    ==================================================

    ==================================================
    Dump File : 100211-39734-01.dmp
    Crash Time : 2/10/2011 1:35:13 AM
    Bug Check String : DRIVER_IRQL_NOT_LESS_OR_EQUAL
    Bug Check Code : 0x000000d1
    Parameter 1 : 0x5889172e
    Parameter 2 : 0x00000004
    Parameter 3 : 0x00000008
    Parameter 4 : 0x5889172e
    Caused By Driver : ntkrnlpa.exe
    Caused By Address : ntkrnlpa.exe+415db
    File Description : NT Kernel & System
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7601.17640 (win7sp1_gdr.110622-1506)
    Processor : 32-bit
    Crash Address : ntkrnlpa.exe+415db
    Stack Address 1 :
    Stack Address 2 : atapi.sys+32df
    Stack Address 3 : ataport.SYS+9f10
    Computer Name :
    Full Path : C:\Windows\Minidump\100211-39734-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7601
    Dump File Size : 139,896
    ==================================================
     
  18. 2011/10/03
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Since I don't think we're dealing with any infection anymore I have to ask you to go back to your original topic.
     
  19. 2011/10/03
    terencew

    terencew Inactive Thread Starter

    Joined:
    2011/09/29
    Messages:
    34
    Likes Received:
    0
    ok. i guess i will post the Bsod Log there then. thanks for you help in clearing the infection. may i ask what was the infection?
     
  20. 2011/10/03
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    It wasn't really much there.
    More like some inactive leftovers.
     
  21. 2011/10/03
    terencew

    terencew Inactive Thread Starter

    Joined:
    2011/09/29
    Messages:
    34
    Likes Received:
    0
    guess i didn't or more like don't know how to clean up the inactive ones.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.