Jump to content

keep getting blue screens

Recommended Posts

Not sure what is going on as I just had my comp reformatted and windows reinstalled. Keep getting the IRQL blue screen and sometimes have been getting one that says system exception. Also noticed that sometimes after a blue screen shutdown, windows will fail to load. Here are the dds reports.


DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16660
Run by Drew at 9:15:50 on 2013-08-18
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.8191.5365 [GMT -4:00]
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
C:\Program Files (x86)\ASUS\AI Manager\AsShellApplication.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files (x86)\World of Warcraft\Wow.exe
C:\Program Files (x86)\World of Warcraft\Utils\WowBrowserProxy.exe
============== Pseudo HJT Report ===============
mWinlogon: Userinit = userinit.exe
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - <orphaned>
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
TB: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
uRun: [best Buy pc app] C:\Users\Drew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Best Buy\Best Buy pc app.appref-ms
mRun: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
mRun: [RunAIShell] C:\Program Files (x86)\ASUS\AI Manager\AsShellApplication.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
dRunOnce: [sPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
StartupFolder: C:\Users\Drew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
TCP: NameServer =
TCP: Interfaces\{DAD76672-7A98-49EA-82D8-BDF92CCA35A8} : DHCPNameServer =
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: Windows Live Family Safety Browser Helper Class: {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
x64-TB: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-Run: [Nvtmru] "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
x64-Run: [Logitech Download Assistant] C:\Windows\System32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
x64-SSODL: WebCheck - <orphaned>
============= SERVICES / DRIVERS ===============
R0 aswRvrt;aswRvrt;C:\Windows\System32\drivers\aswRvrt.sys [2013-8-7 65336]
R0 aswVmm;aswVmm;C:\Windows\System32\drivers\aswVmm.sys [2013-8-7 189936]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2013-8-7 1030952]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2013-8-7 378944]
R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2013-8-7 33400]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2013-8-7 80816]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-8-7 46808]
R2 Device Handle Service;Device Handle Service;C:\Windows\SysWOW64\AsHookDevice.exe [2010-7-30 203392]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-8-18 418376]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-8-18 701512]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-6-21 413472]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-8-18 25928]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-7-30 215040]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2013-8-7 38456]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;C:\Windows\System32\drivers\viahduaa.sys [2010-7-30 1301504]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2010-7-30 61280]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2009-8-6 704864]
S3 netr28x;Ralink 802.11n Wireless Driver for Windows Vista;C:\Windows\System32\drivers\netr28x.sys [2009-6-10 620544]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-8-7 59392]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-8-7 1255736]
=============== Created Last 30 ================
2013-08-18 13:05:50 -------- d-----w- C:\Users\Drew\AppData\Roaming\Malwarebytes
2013-08-18 13:05:41 -------- d-----w- C:\ProgramData\Malwarebytes
2013-08-18 13:05:40 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-08-18 13:05:40 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-18 13:05:23 -------- d-----w- C:\Users\Drew\AppData\Local\Programs
2013-08-17 20:46:21 -------- d-----w- C:\Users\Drew\AppData\Local\Apple Computer
2013-08-17 20:46:06 33240 ----a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys
2013-08-17 20:45:11 -------- d-----w- C:\Program Files\iPod
2013-08-17 20:45:10 -------- d-----w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-08-17 20:45:10 -------- d-----w- C:\Program Files\iTunes
2013-08-17 20:45:10 -------- d-----w- C:\Program Files (x86)\iTunes
2013-08-17 20:44:28 -------- d-----w- C:\Users\Drew\AppData\Local\Apple
2013-08-17 20:43:45 -------- d-----w- C:\Program Files\Bonjour
2013-08-17 20:43:45 -------- d-----w- C:\Program Files (x86)\Bonjour
2013-08-16 09:02:06 9460976 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5D60A7BC-60CD-4490-B6A1-752C10FA5AE6}\mpengine.dll
2013-08-14 13:34:43 -------- d-----w- C:\Users\Drew\AppData\Local\Blizzard Entertainment
2013-08-12 07:43:28 -------- d-----w- C:\Program Files (x86)\World of Warcraft Beta
2013-08-09 21:34:48 -------- d-----w- C:\Program Files\Ventrilo
2013-08-09 21:34:24 -------- d-----w- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2013-08-09 16:39:56 -------- d-----w- C:\Users\Drew\AppData\Roaming\Curse Advertising
2013-08-09 15:23:33 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-08-09 15:23:33 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-08-09 15:19:10 -------- d-----w- C:\Users\Drew\AppData\Local\Adobe
2013-08-09 14:57:06 -------- d-----w- C:\ProgramData\Blizzard Entertainment
2013-08-09 14:57:06 -------- d-----w- C:\Program Files (x86)\World of Warcraft
2013-08-09 14:57:06 -------- d-----w- C:\Program Files (x86)\Common Files\Blizzard Entertainment
2013-08-09 14:55:53 -------- d-----w- C:\ProgramData\Battle.net
2013-08-09 14:54:09 163504 ----a-w- C:\ProgramData\Microsoft\Windows\Sqm\Manifest\Sqm10144.bin
2013-08-09 13:47:59 9460976 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2013-08-08 06:09:30 1424384 ----a-w- C:\Windows\System32\WindowsCodecs.dll
2013-08-08 06:09:30 1230336 ----a-w- C:\Windows\SysWow64\WindowsCodecs.dll
2013-08-08 06:07:20 1643520 ----a-w- C:\Windows\System32\DWrite.dll
2013-08-08 06:07:20 1247744 ----a-w- C:\Windows\SysWow64\DWrite.dll
2013-08-08 05:55:43 9728 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-08 04:36:10 48640 ----a-w- C:\Windows\System32\wwanprotdim.dll
2013-08-08 04:36:10 230400 ----a-w- C:\Windows\System32\wwansvc.dll
2013-08-08 04:36:05 751104 ----a-w- C:\Windows\System32\win32spl.dll
2013-08-08 04:36:05 68608 ----a-w- C:\Windows\System32\taskhost.exe
2013-08-08 04:36:05 492544 ----a-w- C:\Windows\SysWow64\win32spl.dll
2013-08-08 04:34:54 903168 ----a-w- C:\Windows\SysWow64\certutil.exe
2013-08-08 00:40:49 -------- d-----w- C:\Windows\System32\MRT
2013-08-08 00:38:23 -------- d-----w- C:\Windows\System32\SPReview
2013-08-08 00:38:01 -------- d-----w- C:\Windows\System32\EventProviders
2013-08-08 00:12:22 48976 ----a-w- C:\Windows\System32\netfxperf.dll
2013-08-08 00:12:22 1942856 ----a-w- C:\Windows\System32\dfshim.dll
2013-08-08 00:12:14 1130824 ----a-w- C:\Windows\SysWow64\dfshim.dll
2013-08-08 00:12:11 59392 ----a-w- C:\Windows\System32\drivers\TsUsbFlt.sys
2013-08-08 00:12:11 12288 ----a-w- C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll
2013-08-08 00:12:10 14967808 ----a-w- C:\Program Files\DVD Maker\OmdBase.dll
2013-08-08 00:12:02 954752 ----a-w- C:\Windows\SysWow64\mfc40.dll
2013-08-08 00:12:02 954288 ----a-w- C:\Windows\SysWow64\mfc40u.dll
2013-08-08 00:12:02 1743360 ----a-w- C:\Windows\System32\sysmain.dll
2013-08-08 00:10:59 1525248 ----a-w- C:\Program Files\Windows Media Player\wmpnetwk.exe
2013-08-08 00:09:59 854016 ----a-w- C:\Windows\SysWow64\dbghelp.dll
2013-08-08 00:08:59 89600 ----a-w- C:\Windows\SysWow64\wbem\WmiApRpl.dll
2013-08-08 00:07:59 7680 ----a-w- C:\Windows\SysWow64\spwizres.dll
2013-08-08 00:06:58 529408 ----a-w- C:\Windows\System32\wbemcomn.dll
2013-08-08 00:06:58 244736 ----a-w- C:\Program Files\Windows Portable Devices\sqmapi.dll
2013-08-08 00:06:56 244736 ----a-w- C:\Windows\System32\sqmapi.dll
2013-08-07 23:34:33 -------- d-----w- C:\Windows\SysWow64\Wat
2013-08-07 23:34:32 -------- d-----w- C:\Windows\System32\Wat
2013-08-07 22:47:03 2560 ----a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui
2013-08-07 22:47:02 9728 ----a-w- C:\Windows\System32\Wdfres.dll
2013-08-07 22:47:02 785512 ----a-w- C:\Windows\System32\drivers\Wdf01000.sys
2013-08-07 22:47:02 54376 ----a-w- C:\Windows\System32\drivers\WdfLdr.sys
2013-08-07 22:25:39 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
2013-08-07 22:25:39 46080 ----a-w- C:\Windows\System32\atmlib.dll
2013-08-07 22:25:39 367616 ----a-w- C:\Windows\System32\atmfd.dll
2013-08-07 22:25:39 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2013-08-07 22:25:39 100864 ----a-w- C:\Windows\System32\fontsub.dll
2013-08-07 22:25:38 295424 ----a-w- C:\Windows\SysWow64\atmfd.dll
2013-08-07 22:24:47 87040 ----a-w- C:\Windows\System32\drivers\WUDFPf.sys
2013-08-07 22:24:47 198656 ----a-w- C:\Windows\System32\drivers\WUDFRd.sys
2013-08-07 22:24:46 84992 ----a-w- C:\Windows\System32\WUDFSvc.dll
2013-08-07 22:24:46 194048 ----a-w- C:\Windows\System32\WUDFPlatform.dll
2013-08-07 22:24:45 744448 ----a-w- C:\Windows\System32\WUDFx.dll
2013-08-07 22:24:45 45056 ----a-w- C:\Windows\System32\WUDFCoinstaller.dll
2013-08-07 22:24:45 229888 ----a-w- C:\Windows\System32\WUDFHost.exe
2013-08-07 22:21:28 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2013-08-07 22:21:28 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2013-08-07 22:21:28 5120 ----a-w- C:\Windows\System32\wmi.dll
2013-08-07 22:21:28 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2013-08-07 22:21:28 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2013-08-07 22:16:26 183296 ----a-w- C:\Windows\System32\dnsrslvr.dll
2013-08-07 22:16:25 30208 ----a-w- C:\Windows\System32\dnscacheugc.exe
2013-08-07 22:16:25 28672 ----a-w- C:\Windows\SysWow64\dnscacheugc.exe
2013-08-07 22:16:20 3717632 ----a-w- C:\Windows\System32\mstscax.dll
2013-08-07 22:16:20 3217408 ----a-w- C:\Windows\SysWow64\mstscax.dll
2013-08-07 22:16:19 158720 ----a-w- C:\Windows\System32\aaclient.dll
2013-08-07 22:16:18 44032 ----a-w- C:\Windows\System32\tsgqec.dll
2013-08-07 22:16:18 36864 ----a-w- C:\Windows\SysWow64\tsgqec.dll
2013-08-07 22:16:18 131584 ----a-w- C:\Windows\SysWow64\aaclient.dll
2013-08-07 22:14:44 495616 ----a-w- C:\Program Files\Common Files\System\ado\msadox.dll
2013-08-07 22:13:53 64512 ----a-w- C:\Windows\SysWow64\devobj.dll
2013-08-07 22:12:59 2002432 ----a-w- C:\Windows\System32\msxml6.dll
2013-08-07 22:11:59 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe
2013-08-07 21:52:43 77312 ----a-w- C:\Windows\System32\packager.dll
2013-08-07 21:52:43 67072 ----a-w- C:\Windows\SysWow64\packager.dll
2013-08-07 20:04:09 72016 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
2013-08-07 20:04:08 189936 ----a-w- C:\Windows\System32\drivers\aswVmm.sys
2013-08-07 20:04:08 1030952 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2013-08-07 20:04:06 65336 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys
2013-08-07 20:04:05 80816 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2013-08-07 20:03:17 41664 ----a-w- C:\Windows\avastSS.scr
2013-08-07 20:02:58 -------- d-----w- C:\Program Files\AVAST Software
2013-08-07 20:02:19 -------- d-----w- C:\ProgramData\AVAST Software
2013-08-07 19:08:02 -------- d-----w- C:\NVIDIA
2013-08-07 19:01:58 -------- d-----w- C:\Windows\System32\log
2013-08-07 18:55:24 -------- d-----w- C:\Users\Drew\AppData\Local\Google
2013-08-07 18:51:25 -------- d-----w- C:\Users\Drew\AppData\Local\Best Buy pc app
2013-08-07 18:31:58 278800 ------w- C:\Windows\System32\MpSigStub.exe
2013-08-07 18:27:23 884512 ----a-w- C:\Windows\System32\nvvsvc.exe
2013-08-07 18:27:23 6496544 ----a-w- C:\Windows\System32\nvcpl.dll
2013-08-07 18:27:23 63776 ----a-w- C:\Windows\System32\nvshext.dll
2013-08-07 18:27:23 3514656 ----a-w- C:\Windows\System32\nvsvc64.dll
2013-08-07 18:27:23 3253909 ----a-w- C:\Windows\System32\nvcoproc.bin
2013-08-07 18:27:23 2558240 ----a-w- C:\Windows\System32\nvsvcr.dll
2013-08-07 18:27:23 237856 ----a-w- C:\Windows\System32\nvmctray.dll
2013-08-07 18:27:05 61216 ----a-w- C:\Windows\System32\OpenCL.dll
2013-08-07 18:27:05 53024 ----a-w- C:\Windows\SysWow64\OpenCL.dll
2013-08-07 18:26:43 -------- d-----w- C:\ProgramData\NVIDIA Corporation
2013-08-07 18:26:31 -------- d-----w- C:\Program Files\NVIDIA Corporation
2013-08-07 18:26:31 -------- d-----w- C:\Program Files (x86)\NVIDIA Corporation
2013-08-07 18:24:02 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2013-08-07 18:24:02 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2013-08-07 18:24:02 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2013-08-07 18:23:46 -------- d-----w- C:\Users\Drew\AppData\Local\Apps
2013-08-07 18:23:45 -------- d-----w- C:\Users\Drew\AppData\Local\Deployment
2013-08-07 18:23:11 -------- d-----w- C:\Users\Drew\AppData\Local\VirtualStore
2013-08-07 18:22:53 16896 ----a-w- C:\Windows\AsTaskSched.dll
2013-08-07 18:21:01 38456 ----a-w- C:\Windows\System32\drivers\usbfilter.sys
2013-08-07 18:21:00 -------- d-----w- C:\Program Files (x86)\AMD
2013-08-07 18:20:41 -------- d-----w- C:\Program Files\ATI
2013-08-07 18:19:46 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2013-08-07 18:19:37 99840 ----a-w- C:\Windows\System32\wudriver.dll
2013-08-07 18:19:15 36864 ----a-w- C:\Windows\System32\wuapp.exe
2013-08-07 18:19:15 186752 ----a-w- C:\Windows\System32\wuwebv.dll
==================== Find3M  ====================
2013-08-08 05:55:43 9728 ---ha-w- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-08 01:13:21 175616 ----a-w- C:\Windows\System32\msclmd.dll
2013-08-08 01:13:21 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2013-07-26 05:13:37 2241024 ----a-w- C:\Windows\System32\wininet.dll
2013-07-26 05:12:08 3958784 ----a-w- C:\Windows\System32\jscript9.dll
2013-07-26 05:12:04 136704 ----a-w- C:\Windows\System32\iesysprep.dll
2013-07-26 05:12:03 67072 ----a-w- C:\Windows\System32\iesetup.dll
2013-07-26 03:35:08 2706432 ----a-w- C:\Windows\System32\mshtml.tlb
2013-07-26 03:13:24 1767936 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-07-26 03:12:04 2877440 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-07-26 03:12:00 61440 ----a-w- C:\Windows\SysWow64\iesetup.dll
2013-07-26 03:12:00 109056 ----a-w- C:\Windows\SysWow64\iesysprep.dll
2013-07-26 02:49:14 2706432 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2013-07-26 02:39:38 89600 ----a-w- C:\Windows\System32\RegisterIEPKEYs.exe
2013-07-26 01:59:38 71680 ----a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe
2013-07-25 09:25:54 1888768 ----a-w- C:\Windows\System32\WMVDECOD.DLL
2013-07-25 08:57:27 1620992 ----a-w- C:\Windows\SysWow64\WMVDECOD.DLL
2013-07-19 01:58:42 2048 ----a-w- C:\Windows\System32\tzres.dll
2013-07-19 01:41:01 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2013-07-09 06:03:30 5550528 ----a-w- C:\Windows\System32\ntoskrnl.exe
2013-07-09 05:54:22 1732032 ----a-w- C:\Windows\System32\ntdll.dll
2013-07-09 05:53:12 243712 ----a-w- C:\Windows\System32\wow64.dll
2013-07-09 05:52:52 224256 ----a-w- C:\Windows\System32\wintrust.dll
2013-07-09 05:51:16 1217024 ----a-w- C:\Windows\System32\rpcrt4.dll
2013-07-09 05:46:20 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
2013-07-09 05:46:20 1472512 ----a-w- C:\Windows\System32\crypt32.dll
2013-07-09 05:46:20 139776 ----a-w- C:\Windows\System32\cryptnet.dll
2013-07-09 05:03:34 3968960 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2013-07-09 05:03:34 3913664 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2013-07-09 04:53:47 1292192 ----a-w- C:\Windows\SysWow64\ntdll.dll
2013-07-09 04:52:33 663552 ----a-w- C:\Windows\SysWow64\rpcrt4.dll
2013-07-09 04:52:33 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2013-07-09 04:52:10 175104 ----a-w- C:\Windows\SysWow64\wintrust.dll
2013-07-09 04:46:31 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2013-07-09 04:46:31 1166848 ----a-w- C:\Windows\SysWow64\crypt32.dll
2013-07-09 04:46:31 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
2013-07-09 04:45:07 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2013-07-09 02:49:42 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2013-07-09 02:49:41 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2013-07-09 02:49:39 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2013-07-09 02:49:38 2048 ----a-w- C:\Windows\SysWow64\user.exe
2013-07-06 06:03:53 1910208 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2013-06-21 09:16:02 566048 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
2013-06-15 04:32:16 39936 ----a-w- C:\Windows\System32\drivers\tssecsrv.sys
2013-06-05 03:34:27 3153920 ----a-w- C:\Windows\System32\win32k.sys
2013-06-04 06:00:13 624128 ----a-w- C:\Windows\System32\qedit.dll
2013-06-04 04:53:07 509440 ----a-w- C:\Windows\SysWow64\qedit.dll
============= FINISH:  9:17:02.06 ===============



DDS (Ver_2012-11-20.01)
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 8/7/2013 2:18:40 PM
System Uptime: 8/18/2013 9:01:02 AM (0 hours ago)
Motherboard: ASUSTeK Computer INC. |  | CM1630
Processor: AMD Athlon II X2 220 Processor | AM3 | 2800/200mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 680 GiB total, 576.384 GiB free.
D: is Removable
E: is Removable
F: is Removable
G: is Removable
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP72: 8/8/2013 2:11:35 AM - Windows Update
RP73: 8/9/2013 5:34:34 PM - Installed Ventrilo Client for Windows x64
RP74: 8/11/2013 3:03:54 AM - Windows Update
RP75: 8/15/2013 3:00:16 AM - Windows Update
RP76: 8/17/2013 1:40:14 PM - Windows Backup
RP77: 8/17/2013 4:44:31 PM - Installed iTunes
==== Installed Programs ======================
64 Bit HP CIO Components Installer
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Reader 9.1
AI Manager
AMD USB Filter Driver
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ASUS Backup Wizard
ATI Catalyst Install Manager
avast! Free Antivirus
Best Buy pc app
Curse Client
EPU-4 Engine
Google Chrome
Google Update Helper
Junk Mail filter update
Malwarebytes Anti-Malware version
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Office 2010
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP3 Parser (KB2758694)
MSXML 4.0 SP3 Parser (KB973685)
NVIDIA 3D Vision Controller Driver 320.49
NVIDIA 3D Vision Driver 320.49
NVIDIA Control Panel 320.49
NVIDIA GeForce Experience 1.5
NVIDIA Graphics Driver 320.49
NVIDIA HD Audio Driver
NVIDIA Install Application
NVIDIA PhysX System Software 9.13.0604
NVIDIA Stereoscopic 3D Driver
NVIDIA Update 4.11.9
NVIDIA Update Components
Realtek 8136 8168 8169 Ethernet Driver
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft .NET Framework 4 Extended (KB2736428)
Security Update for Microsoft .NET Framework 4 Extended (KB2742595)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2836939)
Ventrilo Client for Windows x64
VIA Platform Device Manager
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live Mail
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
Windows Live Writer
World of Warcraft
==== Event Viewer Messages From Past Week ========
8/18/2013 9:01:21 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001]  - The computer has rebooted from a bugcheck.  The bugcheck was: 0x0000007e (0xffffffffc0000005, 0xfffff80003343aba, 0xfffff88002ff57f8, 0xfffff88002ff5050). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081813-18610-01.
8/18/2013 6:36:37 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001]  - The computer has rebooted from a bugcheck.  The bugcheck was: 0x000000fe (0x0000000000000006, 0xfffffa80078d3d70, 0x0000000048766544, 0x0000000000000000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081813-16192-01.
8/18/2013 5:36:59 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001]  - The computer has rebooted from a bugcheck.  The bugcheck was: 0x0000000a (0x0000000000000004, 0x0000000000000002, 0x0000000000000001, 0xfffff80003075536). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081813-23166-01.
8/18/2013 5:29:14 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001]  - The computer has rebooted from a bugcheck.  The bugcheck was: 0x0000007e (0xffffffffc0000005, 0xfffff800033bdde8, 0xfffff88002fef9a8, 0xfffff88002fef200). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081813-22198-01.
8/18/2013 5:16:40 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001]  - The computer has rebooted from a bugcheck.  The bugcheck was: 0x0000000a (0x00000000000000ca, 0x000000000000000a, 0x0000000000000000, 0xfffff80003070f43). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081813-21933-01.
8/17/2013 8:58:21 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001]  - The computer has rebooted from a bugcheck.  The bugcheck was: 0x0000003b (0x00000000c0000005, 0xfffff880010b53a9, 0xfffff8800944e6f0, 0x0000000000000000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081713-21060-01.
8/17/2013 6:05:58 PM, Error: Disk [11]  - The driver detected a controller error on \Device\Harddisk5\DR5.
8/17/2013 5:39:31 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001]  - The computer has rebooted from a bugcheck.  The bugcheck was: 0x000000fe (0x0000000000000006, 0xfffffa8008915960, 0x0000000048766544, 0x0000000000000000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081713-16021-01.
8/17/2013 12:23:47 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001]  - The computer has rebooted from a bugcheck.  The bugcheck was: 0x0000000a (0x0000000000000002, 0x0000000000000002, 0x0000000000000001, 0xfffff80003086536). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081713-15381-01.
8/17/2013 11:40:08 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001]  - The computer has rebooted from a bugcheck.  The bugcheck was: 0x00000044 (0xfffffa80086f9b50, 0x0000000000000eae, 0x0000000000000000, 0x0000000000000000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081713-21699-01.
8/17/2013 11:31:01 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001]  - The computer has rebooted from a bugcheck.  The bugcheck was: 0x0000000a (0x0000000000000001, 0x0000000000000002, 0x0000000000000001, 0xfffff800030c0536). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081713-22027-01.
8/17/2013 11:25:35 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001]  - The computer has rebooted from a bugcheck.  The bugcheck was: 0x0000000a (0x000000000058000b, 0x0000000000000002, 0x0000000000000001, 0xfffff800030a7192). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081713-22822-01.
8/17/2013 10:33:28 PM, Error: Disk [11]  - The driver detected a controller error on \Device\Harddisk1\DR1.
8/17/2013 1:22:00 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001]  - The computer has rebooted from a bugcheck.  The bugcheck was: 0x0000000a (0x0000000000000002, 0x0000000000000002, 0x0000000000000001, 0xfffff8000306f536). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081713-21824-01.
8/16/2013 11:15:40 AM, Error: nvlddmkm [14]  -
8/16/2013 1:54:14 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001]  - The computer has rebooted from a bugcheck.  The bugcheck was: 0x0000007f (0x0000000000000008, 0x0000000080050031, 0x00000000000006f8, 0xfffff80003088fc1). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081613-16489-01.
8/16/2013 1:19:02 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001]  - The computer has rebooted from a bugcheck.  The bugcheck was: 0x0000007e (0xffffffffc0000005, 0xfffff88004177b77, 0xfffff880045946d8, 0xfffff88004593f30). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081613-17050-01.
8/15/2013 7:52:42 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001]  - The computer has rebooted from a bugcheck.  The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff800031aa9bc, 0x0000000000000000, 0xffffffffffffffff). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081513-16738-01.
8/15/2013 7:50:30 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001]  - The computer has rebooted from a bugcheck.  The bugcheck was: 0x0000004e (0x0000000000000007, 0x00000000001a5b10, 0x0000000000000001, 0x0000000000000000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081513-15428-01.
8/15/2013 7:40:01 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001]  - The computer has rebooted from a bugcheck.  The bugcheck was: 0x00000019 (0x0000000000000003, 0xfffffa80069932a0, 0xfffffa80069932a0, 0xfffffa8006993220). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081513-15646-01.
8/15/2013 7:24:45 AM, Error: Microsoft-Windows-Kernel-General [5]  - {Registry Hive Recovered} Registry hive (file): '\??\Volume{2b521bb8-ffa5-11e2-baa4-806e6f6e6963}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{33DCDD15-D2F3-4325-AC1C-48E458E67FBD}' was corrupted and it has been recovered. Some data might have been lost.
8/15/2013 12:35:29 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1005]  - Unable to produce a minidump file from the full dump file.
8/15/2013 12:35:29 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001]  - The computer has rebooted from a bugcheck.  The bugcheck was: 0x00000050 (0xffffffffffffff7f, 0x0000000000000000, 0xfffff8000307d156, 0x0000000000000000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: .
8/14/2013 12:16:17 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001]  - The computer has rebooted from a bugcheck.  The bugcheck was: 0x0000000a (0x0000000000000001, 0x0000000000000002, 0x0000000000000001, 0xfffff8000306b576). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081413-24866-01.
8/13/2013 2:49:01 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001]  - The computer has rebooted from a bugcheck.  The bugcheck was: 0x00000050 (0xffffffffffffff7f, 0x0000000000000000, 0xfffff800030c6156, 0x0000000000000000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081313-15631-01.
8/13/2013 2:48:56 PM, Error: Microsoft-Windows-Kernel-General [5]  - {Registry Hive Recovered} Registry hive (file): '\SystemRoot\System32\Config\SOFTWARE' was corrupted and it has been recovered. Some data might have been lost.
8/13/2013 10:42:07 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001]  - The computer has rebooted from a bugcheck.  The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff800030b985c, 0x0000000000000000, 0x000000000000000c). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081313-17019-01.
8/12/2013 2:28:51 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001]  - The computer has rebooted from a bugcheck.  The bugcheck was: 0x0000000a (0x0000000000000000, 0x0000000000000002, 0x0000000000000001, 0xfffff8000307793d). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081213-18252-01.
8/12/2013 10:48:18 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001]  - The computer has rebooted from a bugcheck.  The bugcheck was: 0x0000000a (0xfffffa7fffffe7e0, 0x0000000000000002, 0x0000000000000001, 0xfffff80003054ac1). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081213-20545-01.
8/11/2013 3:07:56 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001]  - The computer has rebooted from a bugcheck.  The bugcheck was: 0x00000019 (0x0000000000000020, 0xfffffa8006c33390, 0xfffffa8006c33d10, 0x0000000005986810). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 081113-18439-01.
==== End Of File ===========================


Link to post
Share on other sites

Hello ravenschyld! My name is Borislav and I will be glad to help you solve your malware problem.

Please note:

  • If you are a paying customer, you have the privilege to contact the help desk at Consumer Support. If you choose this option to get help, please let me know.
  • I recommend you to keep the instructions I will be giving you so that they are available to you at any time. You can save them in a text file or print them.
  • Make sure you read all of the instructions and fixes thoroughly before continuing with them.
  • Follow my instructions strictly and don’t hesitate to stop and ask me if you have any questions.
  • Post your log files, don't attach them. Every log file should be copy/pasted in your next reply.
  • Do not perform any kind of scanning and fixing without my instructions. If you want to proceed on your own, please let me know.
It seems your problem is not due to malware. Take a look at this article:


Link to post
Share on other sites

  • Root Admin

Glad we could help. :)

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.