Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Mysterious BSOD : o


  • This topic is locked This topic is locked

#1
Twithh

Twithh

    Member

  • Member
  • PipPip
  • 13 posts
Hi, I've recently been getting a couple(a lot actually) of BSOD's, the reason for these are still unknown, even with the fine help of rshaffer61. We first thought that this was a matter of bad RAM, but after a bunch of testing and waiting, we found out that this was not the case. We even checked the HDD and OS files for errors, but there were none to be found.

I got a BSOD as recently as today, and I'm more than willing to upload the dumpfiles here if needed. Rshaffer told me to go to this forum for malware detection/removal as he's not allowed to help me any further at that category(malware detection that is).

Don't know if you need the dumpfile, but here's the one i got today.Attached File  BSOD.txt   1.5KB   94 downloads



OTL REPORT BELOW :D




OTL logfile created on: 27.01.2011 16:54:44 - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Users\Håvard\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000414 | Country: Norge | Language: NOR | Date Format: dd.MM.yyyy

4,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 62,00% Memory free
8,00 Gb Paging File | 6,00 Gb Available in Paging File | 77,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931,41 Gb Total Space | 879,28 Gb Free Space | 94,40% Space Free | Partition Type: NTFS

Computer Name: FYKZE | User Name: Håvard | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011.01.27 16:54:34 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Users\Håvard\Downloads\OTL.exe
PRC - [2011.01.24 00:18:19 | 000,407,336 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe
PRC - [2011.01.24 00:17:57 | 001,242,448 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Steam\steam.exe
PRC - [2011.01.20 10:20:12 | 001,305,408 | ---- | M] (DT Soft Ltd) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
PRC - [2011.01.20 10:20:04 | 000,313,152 | ---- | M] (DT Soft Ltd) -- C:\Program Files (x86)\DAEMON Tools Lite\DTShellHlp.exe
PRC - [2011.01.06 11:27:28 | 001,175,880 | ---- | M] (RockMelt, Inc.) -- C:\Users\Håvard\AppData\Local\RockMelt\Application\rockmelt.exe
PRC - [2010.12.09 10:48:10 | 000,247,760 | ---- | M] (Threat Expert Ltd.) -- C:\Program Files (x86)\PC Tools Security\BDT\BDTUpdateService.exe
PRC - [2010.12.03 15:34:46 | 000,108,496 | ---- | M] (Threat Expert Ltd.) -- C:\Program Files (x86)\PC Tools Security\BDT\FGuard.exe
PRC - [2010.12.02 11:33:12 | 000,070,928 | ---- | M] (PC Tools) -- C:\Program Files (x86)\PC Tools Security\TFEngine\TFService.exe
PRC - [2010.12.01 14:49:56 | 001,589,208 | ---- | M] (PC Tools) -- C:\Program Files (x86)\PC Tools Security\pctsGui.exe
PRC - [2010.11.19 06:57:14 | 001,150,936 | ---- | M] (PC Tools) -- C:\Program Files (x86)\PC Tools Security\pctsSvc.exe
PRC - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
PRC - [2010.03.15 14:02:36 | 000,366,840 | ---- | M] (PC Tools) -- C:\Program Files (x86)\PC Tools Security\pctsAuxs.exe
PRC - [2009.07.14 02:14:38 | 001,173,504 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Sidebar\sidebar.exe


========== Modules (SafeList) ==========

MOD - [2011.01.27 16:54:34 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Users\Håvard\Downloads\OTL.exe
MOD - [2010.12.02 11:33:12 | 000,406,800 | ---- | M] (PC Tools) -- C:\Program Files (x86)\PC Tools Security\TFEngine\TfWah.dll
MOD - [2010.08.21 06:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll
MOD - [2010.08.04 13:19:26 | 000,150,576 | ---- | M] (PC Tools) -- C:\Program Files (x86)\PC Tools Security\pctgmhk.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2010.11.26 03:54:12 | 000,203,776 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2010.06.17 05:23:36 | 000,194,496 | ---- | M] (Advanced Micro Devices) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe -- (AMD Reservation Manager)
SRV - [2011.01.24 00:18:19 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010.12.09 10:48:10 | 000,247,760 | ---- | M] (Threat Expert Ltd.) [Auto | Running] -- C:\Program Files (x86)\PC Tools Security\BDT\BDTUpdateService.exe -- (Browser Defender Update Service)
SRV - [2010.12.02 11:33:12 | 000,070,928 | ---- | M] (PC Tools) [On_Demand | Running] -- C:\Program Files (x86)\PC Tools Security\TFEngine\TFService.exe -- (ThreatFire)
SRV - [2010.11.19 06:57:14 | 001,150,936 | ---- | M] (PC Tools) [Auto | Running] -- C:\Program Files (x86)\PC Tools Security\pctsSvc.exe -- (sdCoreService)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.03.15 14:02:36 | 000,366,840 | ---- | M] (PC Tools) [Auto | Running] -- C:\Program Files (x86)\PC Tools Security\pctsAuxs.exe -- (sdAuxService)
SRV - [2009.06.10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2011.01.24 18:29:10 | 000,254,528 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2010.12.02 11:33:12 | 000,075,336 | --S- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\TfSysMon.sys -- (TFSysMon)
DRV:64bit: - [2010.12.02 11:33:12 | 000,065,072 | --S- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\TfFsMon.sys -- (TfFsMon)
DRV:64bit: - [2010.12.02 11:33:12 | 000,041,888 | --S- | M] (PC Tools) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\TfNetMon.sys -- (TfNetMon)
DRV:64bit: - [2010.11.26 05:20:20 | 008,120,320 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2010.11.26 03:16:46 | 000,289,792 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2010.11.25 10:43:26 | 000,257,232 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PCTCore64.sys -- (PCTCore)
DRV:64bit: - [2010.11.25 10:42:10 | 000,092,896 | ---- | M] (PC Tools) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\pctplsg64.sys -- (pctplsg)
DRV:64bit: - [2010.11.17 13:04:32 | 000,115,216 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2010.11.17 10:20:20 | 000,331,368 | ---- | M] (PC Tools) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\pctgntdi64.sys -- (pctgntdi)
DRV:64bit: - [2010.07.16 14:53:32 | 000,816,016 | ---- | M] (PC Tools) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\pctEFA64.sys -- (pctEFA)
DRV:64bit: - [2010.06.29 10:35:34 | 000,452,872 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pctDS64.sys -- (pctDS)
DRV:64bit: - [2010.02.18 09:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)
DRV:64bit: - [2009.07.14 02:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009.07.14 02:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009.07.14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009.07.14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 21:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009.06.10 21:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009.06.10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2005.03.29 01:30:38 | 000,008,192 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll (Conduit Ltd.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = astroburn-search.com
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKCU\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files (x86)\PC Tools Security\BDT\Firefox\ [2011.01.24 00:05:58 | 000,000,000 | ---D | M]


O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll (Conduit Ltd.)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3:64bit: - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (BitTorrentBar Toolbar) - {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll (Conduit Ltd.)
O4 - HKLM..\Run: [ISTray] C:\Program Files (x86)\PC Tools Security\pctsGui.exe (PC Tools)
O4 - HKLM..\Run: [PCTools FGuard] C:\Program Files (x86)\PC Tools Security\BDT\FGuard.exe (Threat Expert Ltd.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [RockMelt Update] C:\Users\Håvard\AppData\Local\RockMelt\Update\RockMeltUpdate.exe (Google Inc.)
O4 - HKCU..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\sidebar.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 130.67.15.198 193.213.112.4
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011.01.27 14:58:49 | 000,000,000 | ---D | C] -- C:\Users\Håvard\AppData\Roaming\LolClient
[2011.01.27 14:55:41 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\InstallShield Installation Information
[2011.01.27 14:55:41 | 000,000,000 | ---D | C] -- C:\Riot Games
[2011.01.27 14:55:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games
[2011.01.26 22:01:57 | 000,000,000 | ---D | C] -- C:\Users\Håvard\Desktop\League Of Legends
[2011.01.26 19:56:24 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Wat
[2011.01.26 19:56:24 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Wat
[2011.01.26 15:45:00 | 000,000,000 | ---D | C] -- C:\Users\Håvard\AppData\Local\PMB Files
[2011.01.26 15:44:59 | 000,000,000 | ---D | C] -- C:\ProgramData\PMB Files
[2011.01.26 15:44:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Pando Networks
[2011.01.25 23:57:00 | 000,000,000 | ---D | C] -- C:\Users\Håvard\Desktop\BSOD
[2011.01.25 20:51:55 | 000,000,000 | ---D | C] -- C:\Users\Håvard\Desktop\WD DIagnostic
[2011.01.25 19:31:39 | 000,000,000 | ---D | C] -- C:\cfbc7d7781e94023c660094e220fa6da
[2011.01.25 19:29:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2011.01.25 19:12:46 | 000,000,000 | ---D | C] -- C:\Users\Håvard\AppData\Local\Activision
[2011.01.25 17:30:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Astroburn Toolbar
[2011.01.25 17:30:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Astroburn Lite
[2011.01.25 17:30:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Astroburn Lite
[2011.01.25 17:30:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Astroburn Lite
[2011.01.25 17:29:59 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\DAEMON Tools Images
[2011.01.25 17:25:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ImgBurn
[2011.01.25 17:25:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ask.com
[2011.01.25 17:19:30 | 000,000,000 | ---D | C] -- C:\Users\Håvard\Desktop\MEMTEST
[2011.01.25 15:18:27 | 000,000,000 | ---D | C] -- C:\Users\Håvard\AppData\Roaming\ATI Drivers Update Utility
[2011.01.24 20:50:13 | 000,000,000 | ---D | C] -- C:\Users\Håvard\AppData\Roaming\Need for Speed World
[2011.01.24 20:24:33 | 000,000,000 | ---D | C] -- C:\Users\Håvard\AppData\Local\Electronic_Arts_Inc
[2011.01.24 20:23:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Electronic Arts
[2011.01.24 20:23:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Electronic Arts
[2011.01.24 18:59:47 | 000,000,000 | ---D | C] -- C:\Users\Håvard\AppData\Roaming\Spotify
[2011.01.24 18:59:47 | 000,000,000 | ---D | C] -- C:\Users\Håvard\AppData\Local\Spotify
[2011.01.24 18:59:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spotify
[2011.01.24 18:56:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2011.01.24 18:56:08 | 000,000,000 | ---D | C] -- C:\Users\Håvard\AppData\Roaming\.minecraft
[2011.01.24 18:56:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2011.01.24 18:55:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2011.01.24 18:29:10 | 000,254,528 | ---- | C] (DT Soft Ltd) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys
[2011.01.24 18:29:00 | 000,000,000 | ---D | C] -- C:\Users\Håvard\AppData\Local\Threat Expert
[2011.01.24 18:28:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DAEMON Tools Toolbar
[2011.01.24 18:28:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
[2011.01.24 18:28:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DAEMON Tools Lite
[2011.01.24 18:26:18 | 000,000,000 | ---D | C] -- C:\Users\Håvard\AppData\Roaming\DAEMON Tools Lite
[2011.01.24 18:26:18 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite
[2011.01.24 17:34:29 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2011.01.24 17:31:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Conduit
[2011.01.24 17:31:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ConduitEngine
[2011.01.24 17:31:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BitTorrentBar
[2011.01.24 17:30:59 | 000,000,000 | ---D | C] -- C:\extensions
[2011.01.24 17:30:29 | 000,000,000 | ---D | C] -- C:\Users\Håvard\AppData\Roaming\BitTorrent
[2011.01.24 17:24:48 | 000,000,000 | ---D | C] -- C:\Users\Håvard\AppData\Roaming\Macromedia
[2011.01.24 17:24:48 | 000,000,000 | ---D | C] -- C:\Users\Håvard\AppData\Roaming\Adobe
[2011.01.24 17:23:37 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed
[2011.01.24 17:21:28 | 000,000,000 | ---D | C] -- C:\Users\Håvard\AppData\Roaming\skypePM
[2011.01.24 17:19:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011.01.24 17:19:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2011.01.24 17:19:39 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
[2011.01.24 17:19:38 | 000,000,000 | ---D | C] -- C:\Users\Håvard\AppData\Roaming\Skype
[2011.01.24 17:19:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
[2011.01.24 17:16:43 | 000,000,000 | ---D | C] -- C:\Users\Håvard\AppData\Roaming\ATI
[2011.01.24 17:16:43 | 000,000,000 | ---D | C] -- C:\Users\Håvard\AppData\Local\ATI
[2011.01.24 17:16:43 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2011.01.24 00:16:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Steam
[2011.01.24 00:16:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[2011.01.24 00:16:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Steam
[2011.01.24 00:08:23 | 000,000,000 | ---D | C] -- C:\Users\Håvard\Documents\Just Cause2
[2011.01.24 00:07:43 | 000,000,000 | ---D | C] -- C:\Users\Håvard\AppData\Roaming\WinRAR
[2011.01.24 00:07:43 | 000,000,000 | ---D | C] -- C:\Users\Håvard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011.01.24 00:07:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011.01.24 00:07:40 | 000,000,000 | ---D | C] -- C:\Programfiler\WinRAR
[2011.01.24 00:05:58 | 000,149,456 | ---- | C] (PC Tools) -- C:\Windows\SGDetectionTool.dll
[2011.01.24 00:05:57 | 001,996,752 | ---- | C] (Threat Expert Ltd.) -- C:\Windows\PCTBDCore.dll
[2011.01.24 00:05:57 | 001,533,904 | ---- | C] (Threat Expert Ltd.) -- C:\Windows\PCTBDRes.dll
[2011.01.24 00:05:57 | 000,075,336 | --S- | C] (PC Tools) -- C:\Windows\SysNative\drivers\TfSysMon.sys
[2011.01.24 00:05:57 | 000,065,072 | --S- | C] (PC Tools) -- C:\Windows\SysNative\drivers\TfFsMon.sys
[2011.01.24 00:05:57 | 000,041,888 | --S- | C] (PC Tools) -- C:\Windows\SysNative\drivers\TfNetMon.sys
[2011.01.24 00:03:43 | 000,000,000 | ---D | C] -- C:\Users\Håvard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RockMelt
[2011.01.24 00:03:15 | 000,000,000 | ---D | C] -- C:\Users\Håvard\AppData\Local\RockMelt
[2011.01.24 00:01:50 | 000,816,016 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\pctEFA64.sys
[2011.01.24 00:01:50 | 000,452,872 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\pctDS64.sys
[2011.01.24 00:01:50 | 000,331,368 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\pctgntdi64.sys
[2011.01.24 00:01:50 | 000,136,168 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\pctwfpfilter64.sys
[2011.01.24 00:01:49 | 000,257,232 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\PCTCore64.sys
[2011.01.24 00:01:48 | 000,092,896 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\pctplsg64.sys
[2011.01.24 00:01:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Tools Security
[2011.01.24 00:01:43 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2011.01.24 00:01:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PC Tools Security
[2011.01.24 00:01:43 | 000,000,000 | ---D | C] -- C:\Users\Håvard\AppData\Roaming\PC Tools
[2011.01.24 00:01:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PC Tools
[2011.01.23 23:59:14 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2011.01.23 23:59:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ATI Technologies
[2011.01.23 23:59:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ATI-veiviser for problemrapport
[2011.01.23 23:59:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2011.01.23 23:58:33 | 000,000,000 | ---D | C] -- C:\Programfiler\Common Files\ATI Technologies
[2011.01.23 23:57:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ATI Technologies
[2011.01.23 23:57:39 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2011.01.23 23:57:39 | 000,000,000 | ---D | C] -- C:\Programfiler\ATI
[2011.01.23 23:57:24 | 000,000,000 | ---D | C] -- C:\Programfiler\ATI Technologies
[2011.01.23 23:56:57 | 000,000,000 | ---D | C] -- C:\AMD
[2011.01.23 23:55:57 | 000,000,000 | R--D | C] -- C:\Users\Håvard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2011.01.23 23:55:57 | 000,000,000 | R--D | C] -- C:\Users\Håvard\Searches
[2011.01.23 23:55:57 | 000,000,000 | R--D | C] -- C:\Users\Håvard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2011.01.23 23:55:50 | 000,000,000 | ---D | C] -- C:\Users\Håvard\AppData\Roaming\Identities
[2011.01.23 23:55:49 | 000,000,000 | R--D | C] -- C:\Users\Håvard\Contacts
[2011.01.23 23:55:48 | 000,000,000 | ---D | C] -- C:\Users\Håvard\AppData\Local\VirtualStore
[2011.01.23 23:55:42 | 000,000,000 | -HSD | C] -- C:\Users\Håvard\AppData\Local\Temporary Internet Files
[2011.01.23 23:55:42 | 000,000,000 | -HSD | C] -- C:\Users\Håvard\Start-meny
[2011.01.23 23:55:42 | 000,000,000 | -HSD | C] -- C:\Users\Håvard\Skrivere
[2011.01.23 23:55:42 | 000,000,000 | -HSD | C] -- C:\Users\Håvard\SendTo
[2011.01.23 23:55:42 | 000,000,000 | -HSD | C] -- C:\Users\Håvard\Recent
[2011.01.23 23:55:42 | 000,000,000 | -HSD | C] -- C:\Users\Håvard\Programdata
[2011.01.23 23:55:42 | 000,000,000 | -HSD | C] -- C:\Users\Håvard\AppData\Local\Programdata
[2011.01.23 23:55:42 | 000,000,000 | -HSD | C] -- C:\Users\Håvard\Mine dokumenter
[2011.01.23 23:55:42 | 000,000,000 | -HSD | C] -- C:\Users\Håvard\Documents\Mine bilder
[2011.01.23 23:55:42 | 000,000,000 | -HSD | C] -- C:\Users\Håvard\Documents\Min musikk
[2011.01.23 23:55:42 | 000,000,000 | -HSD | C] -- C:\Users\Håvard\Maler
[2011.01.23 23:55:42 | 000,000,000 | -HSD | C] -- C:\Users\Håvard\Lokale innstillinger
[2011.01.23 23:55:42 | 000,000,000 | -HSD | C] -- C:\Users\Håvard\AppData\Local\Logg
[2011.01.23 23:55:42 | 000,000,000 | -HSD | C] -- C:\Users\Håvard\Documents\Intern video
[2011.01.23 23:55:42 | 000,000,000 | -HSD | C] -- C:\Users\Håvard\Cookies
[2011.01.23 23:55:42 | 000,000,000 | -HSD | C] -- C:\Users\Håvard\AndrMask
[2011.01.23 23:55:41 | 000,000,000 | --SD | C] -- C:\Users\Håvard\AppData\Roaming\Microsoft
[2011.01.23 23:55:41 | 000,000,000 | R--D | C] -- C:\Users\Håvard\Videos
[2011.01.23 23:55:41 | 000,000,000 | R--D | C] -- C:\Users\Håvard\Saved Games
[2011.01.23 23:55:41 | 000,000,000 | R--D | C] -- C:\Users\Håvard\Pictures
[2011.01.23 23:55:41 | 000,000,000 | R--D | C] -- C:\Users\Håvard\Music
[2011.01.23 23:55:41 | 000,000,000 | R--D | C] -- C:\Users\Håvard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2011.01.23 23:55:41 | 000,000,000 | R--D | C] -- C:\Users\Håvard\Links
[2011.01.23 23:55:41 | 000,000,000 | R--D | C] -- C:\Users\Håvard\Favorites
[2011.01.23 23:55:41 | 000,000,000 | R--D | C] -- C:\Users\Håvard\Downloads
[2011.01.23 23:55:41 | 000,000,000 | R--D | C] -- C:\Users\Håvard\Documents
[2011.01.23 23:55:41 | 000,000,000 | R--D | C] -- C:\Users\Håvard\Desktop
[2011.01.23 23:55:41 | 000,000,000 | R--D | C] -- C:\Users\Håvard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2011.01.23 23:55:41 | 000,000,000 | -H-D | C] -- C:\Users\Håvard\AppData
[2011.01.23 23:55:41 | 000,000,000 | ---D | C] -- C:\Users\Håvard\AppData\Local\Temp
[2011.01.23 23:55:41 | 000,000,000 | ---D | C] -- C:\Users\Håvard\AppData\Local\Microsoft
[2011.01.23 23:55:41 | 000,000,000 | ---D | C] -- C:\Users\Håvard\AppData\Roaming\Media Center Programs
[2011.01.23 23:55:35 | 000,000,000 | -HSD | C] -- C:\ProgramData\Start-meny
[2011.01.23 23:55:35 | 000,000,000 | -HSD | C] -- C:\ProgramData\Skrivebord
[2011.01.23 23:55:35 | 000,000,000 | -HSD | C] -- C:\Recovery
[2011.01.23 23:55:35 | 000,000,000 | -HSD | C] -- C:\Programfiler
[2011.01.23 23:55:35 | 000,000,000 | -HSD | C] -- C:\ProgramData\Programdata
[2011.01.23 23:55:35 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Mine bilder
[2011.01.23 23:55:35 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Min musikk
[2011.01.23 23:55:35 | 000,000,000 | -HSD | C] -- C:\ProgramData\Maler
[2011.01.23 23:55:35 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Intern video
[2011.01.23 23:55:35 | 000,000,000 | -HSD | C] -- C:\Programfiler\Fellesfiler
[2011.01.23 23:55:35 | 000,000,000 | -HSD | C] -- C:\ProgramData\Favoritter
[2011.01.23 23:55:35 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dokumenter
[2011.01.23 23:55:34 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2011.01.23 23:49:54 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2011.01.23 23:49:26 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2011.01.23 23:48:40 | 000,000,000 | ---D | C] -- C:\Windows\Panther

========== Files - Modified Within 30 Days ==========

[2011.01.27 16:53:40 | 000,014,608 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.01.27 16:53:40 | 000,014,608 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.01.27 16:50:46 | 001,248,616 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011.01.27 16:50:46 | 000,615,810 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011.01.27 16:50:46 | 000,456,506 | ---- | M] () -- C:\Windows\SysNative\perfh014.dat
[2011.01.27 16:50:46 | 000,106,190 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011.01.27 16:50:46 | 000,077,012 | ---- | M] () -- C:\Windows\SysNative\perfc014.dat
[2011.01.27 16:46:11 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.01.27 16:46:01 | 3219,791,872 | -HS- | M] () -- C:\hiberfil.sys
[2011.01.27 16:40:03 | 377,923,867 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011.01.27 16:08:00 | 000,000,932 | ---- | M] () -- C:\Windows\tasks\RockMeltUpdateTaskUserS-1-5-21-3691913068-2864195956-2409333982-1000UA.job
[2011.01.27 14:57:25 | 000,001,720 | ---- | M] () -- C:\Users\Public\Desktop\Play League of Legends.lnk
[2011.01.26 18:36:00 | 000,003,560 | ---- | M] () -- C:\bootsqm.dat
[2011.01.25 18:29:23 | 000,274,680 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011.01.25 17:30:54 | 000,001,978 | ---- | M] () -- C:\Users\Public\Desktop\Astroburn Lite.lnk
[2011.01.25 16:14:41 | 000,046,697 | ---- | M] () -- C:\Users\Håvard\Desktop\Dump Files.zip
[2011.01.25 16:10:18 | 000,041,767 | ---- | M] () -- C:\Users\Håvard\Desktop\Dump Files.rar
[2011.01.25 15:52:11 | 000,275,904 | ---- | M] () -- C:\Users\Håvard\Desktop\012511-18938-01.dmp
[2011.01.25 14:50:23 | 001,422,776 | ---- | M] () -- C:\Windows\SysNative\drivers\Cat.DB
[2011.01.24 20:24:05 | 000,002,221 | ---- | M] () -- C:\Users\Public\Desktop\Need For Speed World.lnk
[2011.01.24 19:10:36 | 000,000,221 | ---- | M] () -- C:\Users\Håvard\Desktop\Call of Duty Black Ops - Multiplayer.url
[2011.01.24 19:09:46 | 000,000,995 | ---- | M] () -- C:\Users\Håvard\Desktop\Spotify.lnk
[2011.01.24 18:54:25 | 000,232,501 | ---- | M] () -- C:\Users\Håvard\Desktop\Minecraft.exe
[2011.01.24 18:41:59 | 000,000,218 | ---- | M] () -- C:\Users\Håvard\Desktop\Counter-Strike.url
[2011.01.24 18:29:10 | 000,254,528 | ---- | M] (DT Soft Ltd) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys
[2011.01.24 18:28:56 | 000,001,954 | ---- | M] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
[2011.01.24 18:22:15 | 000,000,917 | ---- | M] () -- C:\Users\Public\Desktop\Steam.lnk
[2011.01.24 17:34:30 | 000,275,904 | ---- | M] () -- C:\Users\Håvard\Desktop\012411-23462-01.dmp
[2011.01.24 17:28:54 | 000,083,642 | ---- | M] () -- C:\Users\Håvard\Documents\Need.for.Speed.Hot.Pursuit-RELOADED.5963592.TPB.torrent
[2011.01.24 17:21:33 | 000,000,056 | -H-- | M] () -- C:\ProgramData\ezsidmv.dat
[2011.01.24 17:19:40 | 000,002,513 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2011.01.24 17:15:36 | 000,000,000 | ---- | M] () -- C:\Windows\ativpsrm.bin
[2011.01.24 00:08:00 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\RockMeltUpdateTaskUserS-1-5-21-3691913068-2864195956-2409333982-1000Core.job
[2011.01.24 00:04:15 | 000,002,229 | ---- | M] () -- C:\Users\Håvard\Desktop\RockMelt.lnk
[2011.01.24 00:01:49 | 000,002,074 | ---- | M] () -- C:\Users\Public\Desktop\Spyware Doctor.lnk
[2011.01.23 23:56:19 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2011.01.23 23:52:26 | 000,043,627 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
[2011.01.23 23:52:26 | 000,043,627 | ---- | M] () -- C:\Windows\SysNative\license.rtf
[2011.01.04 17:08:12 | 000,513,032 | ---- | M] () -- C:\Users\Håvard\Desktop\sdasetup.exe

========== Files Created - No Company Name ==========

[2011.01.27 14:57:25 | 000,001,720 | ---- | C] () -- C:\Users\Public\Desktop\Play League of Legends.lnk
[2011.01.26 18:36:00 | 000,003,560 | ---- | C] () -- C:\bootsqm.dat
[2011.01.25 17:30:54 | 000,001,978 | ---- | C] () -- C:\Users\Public\Desktop\Astroburn Lite.lnk
[2011.01.25 16:14:41 | 000,046,697 | ---- | C] () -- C:\Users\Håvard\Desktop\Dump Files.zip
[2011.01.25 16:14:28 | 000,275,904 | ---- | C] () -- C:\Users\Håvard\Desktop\012511-18938-01.dmp
[2011.01.25 16:14:28 | 000,275,904 | ---- | C] () -- C:\Users\Håvard\Desktop\012411-23462-01.dmp
[2011.01.25 16:10:18 | 000,041,767 | ---- | C] () -- C:\Users\Håvard\Desktop\Dump Files.rar
[2011.01.24 20:24:05 | 000,002,221 | ---- | C] () -- C:\Users\Public\Desktop\Need For Speed World.lnk
[2011.01.24 19:10:36 | 000,000,221 | ---- | C] () -- C:\Users\Håvard\Desktop\Call of Duty Black Ops - Multiplayer.url
[2011.01.24 19:09:22 | 000,001,025 | ---- | C] () -- C:\Users\Håvard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
[2011.01.24 19:09:22 | 000,000,995 | ---- | C] () -- C:\Users\Håvard\Desktop\Spotify.lnk
[2011.01.24 18:54:31 | 000,232,501 | ---- | C] () -- C:\Users\Håvard\Desktop\Minecraft.exe
[2011.01.24 18:41:59 | 000,000,218 | ---- | C] () -- C:\Users\Håvard\Desktop\Counter-Strike.url
[2011.01.24 18:28:56 | 000,001,954 | ---- | C] () -- C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
[2011.01.24 17:34:22 | 377,923,867 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2011.01.24 17:28:40 | 000,083,642 | ---- | C] () -- C:\Users\Håvard\Documents\Need.for.Speed.Hot.Pursuit-RELOADED.5963592.TPB.torrent
[2011.01.24 17:21:33 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2011.01.24 17:19:40 | 000,002,513 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2011.01.24 17:15:36 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011.01.24 00:16:01 | 000,000,917 | ---- | C] () -- C:\Users\Public\Desktop\Steam.lnk
[2011.01.24 00:05:58 | 000,767,952 | ---- | C] () -- C:\Windows\BDTSupport.dll
[2011.01.24 00:05:58 | 000,002,052 | ---- | C] () -- C:\Windows\UDB.zip
[2011.01.24 00:05:58 | 000,000,882 | ---- | C] () -- C:\Windows\RegSDImport.xml
[2011.01.24 00:05:58 | 000,000,879 | ---- | C] () -- C:\Windows\RegISSImport.xml
[2011.01.24 00:05:58 | 000,000,131 | ---- | C] () -- C:\Windows\IDB.zip
[2011.01.24 00:04:15 | 000,002,229 | ---- | C] () -- C:\Users\Håvard\Desktop\RockMelt.lnk
[2011.01.24 00:03:18 | 000,000,932 | ---- | C] () -- C:\Windows\tasks\RockMeltUpdateTaskUserS-1-5-21-3691913068-2864195956-2409333982-1000UA.job
[2011.01.24 00:03:18 | 000,000,880 | ---- | C] () -- C:\Windows\tasks\RockMeltUpdateTaskUserS-1-5-21-3691913068-2864195956-2409333982-1000Core.job
[2011.01.24 00:01:50 | 001,422,776 | ---- | C] () -- C:\Windows\SysNative\drivers\Cat.DB
[2011.01.24 00:01:49 | 000,002,074 | ---- | C] () -- C:\Users\Public\Desktop\Spyware Doctor.lnk
[2011.01.23 23:59:14 | 000,513,032 | ---- | C] () -- C:\Users\Håvard\Desktop\sdasetup.exe
[2011.01.23 23:56:19 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2011.01.23 23:56:01 | 000,001,413 | ---- | C] () -- C:\Users\Håvard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2011.01.23 23:55:59 | 000,001,447 | ---- | C] () -- C:\Users\Håvard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011.01.23 23:52:18 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2011.01.23 23:52:18 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2011.01.23 23:49:26 | 3219,791,872 | -HS- | C] () -- C:\hiberfil.sys
[2009.07.14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009.07.13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll

========== LOP Check ==========

[2011.01.24 18:57:08 | 000,000,000 | ---D | M] -- C:\Users\Håvard\AppData\Roaming\.minecraft
[2011.01.27 16:44:57 | 000,000,000 | ---D | M] -- C:\Users\Håvard\AppData\Roaming\BitTorrent
[2011.01.25 17:20:10 | 000,000,000 | ---D | M] -- C:\Users\Håvard\AppData\Roaming\DAEMON Tools Lite
[2011.01.27 14:58:49 | 000,000,000 | ---D | M] -- C:\Users\Håvard\AppData\Roaming\LolClient
[2011.01.24 20:50:13 | 000,000,000 | ---D | M] -- C:\Users\Håvard\AppData\Roaming\Need for Speed World
[2011.01.26 22:32:05 | 000,000,000 | ---D | M] -- C:\Users\Håvard\AppData\Roaming\Spotify
[2011.01.24 00:08:00 | 000,000,880 | ---- | M] () -- C:\Windows\Tasks\RockMeltUpdateTaskUserS-1-5-21-3691913068-2864195956-2409333982-1000Core.job
[2011.01.27 16:08:00 | 000,000,932 | ---- | M] () -- C:\Windows\Tasks\RockMeltUpdateTaskUserS-1-5-21-3691913068-2864195956-2409333982-1000UA.job
[2009.07.14 06:08:49 | 000,006,190 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 185 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:430C6D84

< End of report >

Edited by Twithh, 27 January 2011 - 10:06 AM.

  • 0

Advertisements


#2
Salagubang

Salagubang

    Trusted Helper

  • Malware Removal
  • 3,891 posts
Hi Twithh,

Welcome to Geekstogo. Sorry for the delay. My name is Salagubang and I'll be helping you with this problem.

  • Please read all of my response through at least once before attempting to follow the procedures described. I would recommend printing them out, if you can, as you can check off each step as you complete it. If there's anything you don't understand or isn't totally clear, please come back to me for clarification.
  • Please do not attach any log files to your replies unless I specifically ask you. Instead please copy and paste so as to include the log in your reply. You can do this in separate posts if it's easier for you
  • English is not my first language, so please do not use slang or idioms, as this makes it difficult to understand for me.

Lets start.

Please download ComboFix from one of these locations:

Bleepingcomputer
ForoSpyware
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. (Click on this link to see a list of programs that should be disabled. The list is not all inclusive.)
  • Double click on Combofix.exe and follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, or if you are running Vista, ComboFix will continue it's malware removal procedures.

Posted Image


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
  • 0

#3
Salagubang

Salagubang

    Trusted Helper

  • Malware Removal
  • 3,891 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP