A kind of serious problem..

Hello im new here and this is my first post :)

my pc has been infected by some weird problems lately, starting from random bsod's, self restarting,occasional lags, and the most annoying one is programs closing/crashing on its own without any notice..

i have reformatted the pc, reinstalled the latest graphic driver but to no good result :)

by the way here is the mbam test result..

Database version: 5304

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

12/13/2010 2:23:25 AM

mbam-log-2010-12-13 (02-23-25).txt

Scan type: Quick scan

Objects scanned: 127611

Time elapsed: 7 minute(s), 2 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 1

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

c:\documents and settings\Admin\my documents\downloads\evid4226patch.exe (Malware.Tool) -> Quarantined and deleted successfully.

your help is highly appreciated :)

Hello Dayplayer

Welcome to Malwarebytes.

Sounds more like a hardware or software issue to me.

I will look at the logs to see if they provide any type of sign as to what is going on.


  • Download OTL to your desktop.
  • Double click on OTL to run it.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Standard Registry box change it to All.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.


Download This file. Note its name and save it to your root folder, such as C:\.

  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security program drivers will not conflict with this file.
  • Click on this link to see a list of programs that should be disabled.
  • Double-click on the downloaded file to start the program. (If running Vista, right click on it and select "Run as an Administrator")
  • Allow the driver to load if asked.
  • You may be prompted to scan immediately if it detects rootkit activity.
  • If you are prompted to scan your system click "Yes" to begin the scan.
  • If not prompted, click the "Rootkit/Malware" tab.
  • On the right-side, all items to be scanned should be checked by default except for "Show All". Leave that box unchecked.
  • Select all drives that are connected to your system to be scanned.
  • Click the Scan button to begin. (Please be patient as it can take some time to complete)
  • When the scan is finished, click Save to save the scan results to your Desktop.
  • Save the file as Results.log and copy/paste the contents in your next reply.
  • Exit the program and re-enable all active protection when done.

hi, thanks for the response these are the txt you asked

The otl text

OTL logfile created on: 12/13/2010 7:21:20 AM - Run 1

OTL by OldTimer - Version Folder = C:\Documents and Settings\Admin\My Documents\Downloads

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 646.00 Mb Available Physical Memory | 63.00% Memory free

2.00 Gb Paging File | 2.00 Gb Available in Paging File | 88.00% Paging File free

Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 53.71 Gb Total Space | 38.89 Gb Free Space | 72.40% Space Free | Partition Type: NTFS

Drive D: | 20.81 Gb Total Space | 20.61 Gb Free Space | 99.08% Space Free | Partition Type: NTFS

Computer Name: DELUXE | User Name: Admin | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[2010/11/29 17:42:06 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys

========== Files Created - No Company Name ==========

[2010/12/13 05:00:38 | 000,000,176 | ---- | C] () -- C:\Documents and Settings\Admin\defogger_reenable

[2010/12/13 02:49:41 | 000,000,809 | ---- | C] () -- C:\Documents and Settings\Admin\Desktop\Luna Online Indonesia.lnk

[2010/12/13 02:00:38 | 000,000,802 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk

[2010/12/12 05:39:21 | 000,278,131 | ---- | C] () -- C:\Documents and Settings\Admin\My Documents\Tugas remedial - radian priambodo - XI A 2.cdr

[2010/12/12 05:28:17 | 000,039,669 | ---- | C] () -- C:\WINDOWS\FontData.fdb

[2010/12/12 05:24:15 | 000,002,828 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys

[2010/12/12 05:24:15 | 000,000,088 | RHS- | C] () -- C:\Documents and Settings\All Users\Application Data\6050E01D68.sys

[2010/12/12 04:08:59 | 000,000,741 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\DAEMON Tools Lite.lnk

[2010/12/12 03:57:03 | 000,000,983 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Finish Downloading Brothersoft Download Manager.lnk

[2010/12/12 02:34:51 | 000,240,592 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin

[2010/12/12 02:34:48 | 000,240,592 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin

[2010/12/12 02:34:47 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin

[2010/12/12 02:34:47 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvdrswr.lk

[2010/12/12 02:34:30 | 002,293,194 | ---- | C] () -- C:\WINDOWS\System32\nvdata.bin

[2010/12/12 02:34:27 | 000,003,739 | ---- | C] () -- C:\WINDOWS\System32\nvinfo.pb

[2010/12/10 16:08:04 | 000,000,886 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Advanced SystemCare.lnk

[2010/12/09 10:14:30 | 000,002,391 | ---- | C] () -- C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero StartSmart Essentials.lnk

[2010/12/09 10:14:30 | 000,002,373 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Nero StartSmart Essentials.lnk

[2010/12/09 10:14:30 | 000,002,279 | ---- | C] () -- C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero Home Essentials SE.lnk

[2010/12/09 06:48:27 | 000,000,610 | ---- | C] () -- C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk

[2010/12/09 06:48:27 | 000,000,592 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Opera.lnk

[2010/12/09 06:26:07 | 000,000,080 | ---- | C] () -- C:\Documents and Settings\Admin\default.pls

[2010/12/09 06:25:21 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini

[2010/12/09 01:56:11 | 000,002,088 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\ACDSee 10 Photo Manager.lnk

[2010/12/09 01:10:55 | 000,000,998 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk

[2010/12/09 01:05:02 | 000,001,729 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk

[2010/12/09 00:34:26 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat

[2010/12/09 00:32:43 | 000,000,682 | ---- | C] () -- C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Winamp.lnk

[2010/12/09 00:32:43 | 000,000,664 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Winamp.lnk

[2010/12/09 00:31:32 | 000,178,176 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll

[2010/12/09 00:31:30 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini

[2010/12/09 00:31:28 | 000,000,414 | ---- | C] () -- C:\WINDOWS\System32\lame_acm.xml

[2010/12/09 00:31:25 | 000,881,664 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll

[2010/12/09 00:31:25 | 000,205,824 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll

[2010/12/09 00:31:21 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll

[2010/12/09 00:31:05 | 000,085,504 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll

[2010/12/09 00:27:30 | 000,001,626 | ---- | C] () -- C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk

[2010/12/09 00:27:30 | 000,001,608 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk

[2010/12/09 00:16:47 | 000,000,079 | ---- | C] () -- C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

[2010/12/09 00:16:46 | 000,000,815 | ---- | C] () -- C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk

[2010/12/09 00:03:13 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat

[2010/12/08 23:55:41 | 000,068,200 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat

[2010/12/08 23:49:22 | 000,635,337 | ---- | C] () -- C:\WINDOWS\System32\unins000.exe

[2010/12/08 23:49:22 | 000,002,156 | ---- | C] () -- C:\WINDOWS\System32\unins000.dat

[2010/12/08 23:48:38 | 000,002,577 | ---- | C] () -- C:\WINDOWS\System32\CONFIG.NT

[2010/12/08 23:48:38 | 000,000,000 | RHS- | C] () -- C:\MSDOS.SYS

[2010/12/08 23:48:38 | 000,000,000 | RHS- | C] () -- C:\IO.SYS

[2010/12/08 23:48:38 | 000,000,000 | ---- | C] () -- C:\CONFIG.SYS

[2010/12/08 23:48:38 | 000,000,000 | ---- | C] () -- C:\AUTOEXEC.BAT

[2010/12/08 23:48:19 | 000,023,392 | ---- | C] () -- C:\WINDOWS\System32\nscompat.tlb

[2010/12/08 23:48:19 | 000,016,832 | ---- | C] () -- C:\WINDOWS\System32\amcompat.tlb

[2010/12/08 23:48:17 | 000,316,640 | ---- | C] () -- C:\WINDOWS\WMSysPr9.prx

[2010/12/08 23:41:43 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat

[2010/12/08 23:37:25 | 000,003,286 | ---- | C] () -- C:\WINDOWS\System32\tslabels.h

[2010/12/08 23:37:25 | 000,001,161 | ---- | C] () -- C:\WINDOWS\System32\usrlogon.cmd

[2010/12/08 23:37:24 | 000,000,768 | ---- | C] () -- C:\WINDOWS\System32\msdtcprf.h

[2010/12/08 23:37:13 | 000,062,694 | ---- | C] () -- C:\WINDOWS\System32\wmimgmt.msc

[2010/12/08 15:29:23 | 000,004,444 | ---- | C] () -- C:\WINDOWS\System32\pid.PNF

[2010/12/08 15:29:15 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI

[2010/12/08 15:28:24 | 000,001,688 | ---- | C] () -- C:\WINDOWS\System32\AUTOEXEC.NT

[2010/12/08 15:18:52 | 000,005,810 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys

[2010/12/08 15:18:24 | 000,272,576 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2010/12/08 15:16:42 | 000,000,232 | -HS- | C] () -- C:\boot.ini

[2010/12/08 15:16:39 | 000,001,400 | ---- | C] () -- C:\WINDOWS\System32\$winnt$.inf

[2009/04/15 12:39:56 | 000,002,245 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini

========== LOP Check ==========

[2010/12/09 01:56:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Application Data\ACD Systems

[2010/12/12 04:08:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Application Data\DAEMON Tools

[2010/12/12 03:57:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Application Data\GetRightToGo

[2010/12/10 19:30:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Application Data\IObit

[2010/12/09 06:48:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Application Data\Opera

[2010/12/09 01:56:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ACD Systems

========== Purity Check ==========

< End of report >

here's the extra

OTL Extras logfile created on: 12/13/2010 7:21:20 AM - Run 1

OTL by OldTimer - Version Folder = C:\Documents and Settings\Admin\My Documents\Downloads

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 646.00 Mb Available Physical Memory | 63.00% Memory free

2.00 Gb Paging File | 2.00 Gb Available in Paging File | 88.00% Paging File free

Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 53.71 Gb Total Space | 38.89 Gb Free Space | 72.40% Space Free | Partition Type: NTFS

Drive D: | 20.81 Gb Total Space | 20.61 Gb Free Space | 99.08% Space Free | Partition Type: NTFS

Computer Name: DELUXE | User Name: Admin | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========

i can't seem to post both extra and result log due to the length of post so i'll attach the gmer


Hi, my pc is still acting strange

everytime i run programs that contains tons of graphical/3d content such as games or when i browse pictures with my browser it either: occasionally lags,simply closes the program without any notice,self restarts, blue screened

i've tested my graphic card on another pc and it worked fine.. :)

btw do you need the minidump files?

Link to post
Share on other sites

hi thanks for the quick reply :)

i can't seem to upload the minidump files this always shows up "Upload failed. You are not permitted to upload this type of file"

so instead i txt the thing using bluescreenview program. below is the list of the most recent bluescreen'


Dump File : Mini121110-01.dmp

Crash Time : 12/11/2010 6:30:35 AM


Bug Check Code : 0x1000008e

Parameter 1 : 0xc0000005

Parameter 2 : 0xbfb07840

Parameter 3 : 0xbae82af8

Parameter 4 : 0x00000000

Caused By Driver : nv4_disp.dll

Caused By Address : nv4_disp.dll+131840

File Description :

Product Name :

Company :

File Version :

Processor : 32-bit

Computer Name :

Full Path : C:\Program Files\minidump\Mini121110-01.dmp

Processors Count : 2

Major Version : 15

Minor Version : 2600



Dump File : Mini121110-02.dmp

Crash Time : 12/11/2010 9:06:44 AM


Bug Check Code : 0x100000d1

Parameter 1 : 0x505f2100

Parameter 2 : 0x00000002

Parameter 3 : 0x00000001

Parameter 4 : 0xf42a381e

Caused By Driver : tcpip.sys

Caused By Address : tcpip.sys+81e

File Description :

Product Name :

Company :

File Version :

Processor : 32-bit

Computer Name :

Full Path : C:\Program Files\minidump\Mini121110-02.dmp

Processors Count : 2

Major Version : 15

Minor Version : 2600



Dump File : Mini121210-01.dmp

Crash Time : 12/12/2010 12:47:53 AM


Bug Check Code : 0x10000050

Parameter 1 : 0xbafc0eb8

Parameter 2 : 0x00000000

Parameter 3 : 0x8056ed7b

Parameter 4 : 0x00000000

Caused By Driver : nv4_mini.sys

Caused By Address : nv4_mini.sys+12167b

File Description :

Product Name :

Company :

File Version :

Processor : 32-bit

Computer Name :

Full Path : C:\Program Files\minidump\Mini121210-01.dmp

Processors Count : 2

Major Version : 15

Minor Version : 2600



Dump File : Mini121210-02.dmp

Crash Time : 12/12/2010 4:28:59 PM


Bug Check Code : 0x10000050

Parameter 1 : 0xe3244144

Parameter 2 : 0x00000000

Parameter 3 : 0xf721ae14

Parameter 4 : 0x00000000

Caused By Driver : Ntfs.sys

Caused By Address : Ntfs.sys+22e14

File Description :

Product Name :

Company :

File Version :

Processor : 32-bit

Computer Name :

Full Path : C:\Program Files\minidump\Mini121210-02.dmp

Processors Count : 2

Major Version : 15

Minor Version : 2600



Dump File : Mini121410-01.dmp

Crash Time : 12/14/2010 2:34:38 AM

Bug Check String : NTFS_FILE_SYSTEM

Bug Check Code : 0x00000024

Parameter 1 : 0x001902fe

Parameter 2 : 0xf78ee490

Parameter 3 : 0xf78ee18c

Parameter 4 : 0x804e8d80

Caused By Driver : Ntfs.sys

Caused By Address : Ntfs.sys+dff0

File Description :

Product Name :

Company :

File Version :

Processor : 32-bit

Computer Name :

Full Path : C:\Program Files\minidump\Mini121410-01.dmp

Processors Count : 2

Major Version : 15

Minor Version : 2600



Dump File : Mini121410-02.dmp

Crash Time : 12/14/2010 2:45:21 AM


Bug Check Code : 0x1000008e

Parameter 1 : 0xc0000005

Parameter 2 : 0xe1dc4019

Parameter 3 : 0xf5fbd9b1

Parameter 4 : 0x00000000

Caused By Driver :

Caused By Address :

File Description :

Product Name :

Company :

File Version :

Processor : 32-bit

Computer Name :

Full Path : C:\Program Files\minidump\Mini121410-02.dmp

Processors Count : 2

Major Version : 15

Minor Version : 2600


  • 2 weeks later...

Glad we could help. :)

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

This topic is now closed to further replies.
