Solved Need help - I believe malware causing appcrash

perezfab5

New Member
Thread author
Feb 27, 2015
12
Not sure how long system has been infected. My laptop has been running slow for quite some time and my hard drive was running low on space so I thought I could clean out to free up space and performance. I downloaded Malwarebytes Anti-Malware & CCleaner earlier this week and began having problems with some programs(Photoshop & Silhouette Studio) thereafter. Both stopped working and details revealed Appcrash. I'm completely at a loss and need some help. I would appreciate any guidance and direction.
 

perezfab5

New Member
Thread author
Feb 27, 2015
12
Thank you for your time and help. I have run the FRST and have uploaded the 2 files as per the instructions.
 

Attachments

  • Addition.txt
    31.9 KB · Views: 43
  • FRST.txt
    64.4 KB · Views: 103

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
FRST.gif
Fix with Farbar Recovery Scan Tool

icon_exclaim.gif
This fix was created for this user for use on that particular machine.
icon_exclaim.gif

icon_exclaim.gif
Running it on another one may cause damage and render the system unstable.
icon_exclaim.gif

Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.

Please attach it to your reply.
 

Attachments

  • fixlist.txt
    5.1 KB · Views: 79

perezfab5

New Member
Thread author
Feb 27, 2015
12
Getting the same error message when I opened my Photoshop:

Problem signature:


Problem Event Name: APPCRASH

Application Name: PhotoshopElementsEditor.exe

Application Version: 11.0.0.0

Application Timestamp: 505d12ab

Fault Module Name: ntdll.dll

Fault Module Version: 6.1.7601.18247

Fault Module Timestamp: 521ea8e7

Exception Code: c0000005

Exception Offset: 0003a74b

OS Version: 6.1.7601.2.1.0.768.3

Locale ID: 1033

Additional Information 1: e8ad

Additional Information 2: e8adce1c2b9e7be834b4063ac3c53863

Additional Information 3: e8ad

Additional Information 4: e8adce1c2b9e7be834b4063ac3c53863
 

perezfab5

New Member
Thread author
Feb 27, 2015
12
I'm currently re-installing photoshop but appears that it will be taking a while to download. I will be back in touch once the download is complete and I can re-open.
 

perezfab5

New Member
Thread author
Feb 27, 2015
12
I am having issues installing photoshop. It appears its a common error but I can't seem to get past. Waiting for adobe assist. Will be back in touch once I can get the install issue resolved.
 

perezfab5

New Member
Thread author
Feb 27, 2015
12
okay...not sure how I managed but photoshop has finally re-installed. However now I've noticed the following problems:
1. Appcrash happens when I open the program from the desktop short cut but works fine if I open from the Program Files(86x).
2. Appcrash for Silhouette Studio when opened from desktop shortcut and program files. (Fault Module Name: StackHash_68cf
Fault Module Version: 6.1.7601.18247) I've uninstalled and re-installed the software but to no avail.

Please advise what, if anything, can or should be done.
Thank you.
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Download
51a5f31352b88-icon_MBAR.png
Malwarebytes Anti-Rootkit to your desktop.
  • Double-click the icon to start the tool.
  • It will ask you where to extract it, then it will start.
  • Warning! Malwarebytes Anti-Rootkit needs to be run from an account with administrator rights.
  • Click in the introduction screen "next" to continue.
  • Click in the following screen "Update" to obtain the latest malware definitions.
  • Once the update is complete select "Next" and click "Scan".
  • When the scan is finished and no malware has been found select "Exit".
  • If malware was detected, make sure to check all the items and click "Cleanup". Reboot your computer.
  • Open the MBAR folder and paste the content of the following files in your next reply:
    • "mbar-log-{date} (xx-xx-xx).txt"
    • "system-log.txt"
 

perezfab5

New Member
Thread author
Feb 27, 2015
12
Malwarebytes Anti-Rootkit BETA 1.09.1.1004
www.malwarebytes.org

Database version:
main: v2015.03.02.05
rootkit: v2015.02.25.01

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.17633
Mom's Computer :: MOMSCOMPUTER-PC [administrator]

3/2/2015 11:03:29 AM
mbar-log-2015-03-02 (11-03-29).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 401315
Time elapsed: 21 minute(s), 47 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)
 
Last edited:

perezfab5

New Member
Thread author
Feb 27, 2015
12
---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.09.1.1004

(c) Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x64

Account is Administrative

Internet Explorer version: 11.0.9600.17633

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED
CPU speed: 2.094000 GHz
Memory total: 4193456128, free: 998834176

Downloaded database version: v2015.03.02.05
Downloaded database version: v2015.02.25.01
Downloaded database version: v2014.12.06.01
=======================================
Initializing...
This version of Malwarebytes Anti-Rootkit requires you to completely exit the Malwarebytes Anti-Malware application to continue.
=======================================


---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.09.1.1004

(c) Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x64

Account is Administrative

Internet Explorer version: 11.0.9600.17633

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED
CPU speed: 2.094000 GHz
Memory total: 4193456128, free: 727121920

=======================================
Initializing...
This version of Malwarebytes Anti-Rootkit requires you to completely exit the Malwarebytes Anti-Malware application to continue.
=======================================


---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.09.1.1004

(c) Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x64

Account is Administrative

Internet Explorer version: 11.0.9600.17633

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED
CPU speed: 2.094000 GHz
Memory total: 4193456128, free: 1446137856

=======================================
Initializing...
This version of Malwarebytes Anti-Rootkit requires you to completely exit the Malwarebytes Anti-Malware application to continue.
=======================================


---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.09.1.1004

(c) Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x64

Account is Administrative

Internet Explorer version: 11.0.9600.17633

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED
CPU speed: 2.094000 GHz
Memory total: 4193456128, free: 1660682240

=======================================


---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.09.1.1004

(c) Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x64

Account is Administrative

Internet Explorer version: 11.0.9600.17633

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED
CPU speed: 2.094000 GHz
Memory total: 4193456128, free: 1652613120

=======================================
Initializing...
This version of Malwarebytes Anti-Rootkit requires you to completely exit the Malwarebytes Anti-Malware application to continue.
=======================================
Initializing...
This version of Malwarebytes Anti-Rootkit requires you to completely exit the Malwarebytes Anti-Malware application to continue.
=======================================


---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.09.1.1004

(c) Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x64

Account is Administrative

Internet Explorer version: 11.0.9600.17633

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED
CPU speed: 2.094000 GHz
Memory total: 4193456128, free: 2407079936

=======================================
Initializing...
------------ Kernel report ------------
03/02/2015 11:02:59
------------ Loaded modules -----------
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\ACPI.sys
\SystemRoot\system32\drivers\WMILIB.SYS
\SystemRoot\system32\drivers\msisadrv.sys
\SystemRoot\system32\drivers\pci.sys
\SystemRoot\system32\drivers\vdrvroot.sys
\SystemRoot\system32\drivers\isapnp.sys
\SystemRoot\system32\drivers\mpio.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\DRIVERS\compbatt.sys
\SystemRoot\system32\DRIVERS\BATTC.SYS
\SystemRoot\system32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\system32\drivers\intelide.sys
\SystemRoot\system32\drivers\PCIIDEX.SYS
\SystemRoot\system32\drivers\aliide.sys
\SystemRoot\system32\drivers\amdide.sys
\SystemRoot\system32\drivers\cmdide.sys
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\drivers\msdsm.sys
\SystemRoot\system32\drivers\nvraid.sys
\SystemRoot\system32\drivers\CLASSPNP.SYS
\SystemRoot\system32\drivers\pciide.sys
\SystemRoot\system32\drivers\viaide.sys
\SystemRoot\system32\drivers\iaStorV.sys
\SystemRoot\system32\drivers\atapi.sys
\SystemRoot\system32\drivers\ataport.SYS
\SystemRoot\system32\DRIVERS\lsi_sas.sys
\SystemRoot\system32\DRIVERS\storport.sys
\SystemRoot\system32\drivers\msahci.sys
\SystemRoot\system32\drivers\HpSAMD.sys
\SystemRoot\system32\DRIVERS\adp94xx.sys
\SystemRoot\system32\DRIVERS\adpahci.sys
\SystemRoot\system32\DRIVERS\adpu320.sys
\SystemRoot\system32\drivers\amdsata.sys
\SystemRoot\system32\DRIVERS\amdsbs.sys
\SystemRoot\system32\drivers\amdxata.sys
\SystemRoot\system32\DRIVERS\arc.sys
\SystemRoot\system32\DRIVERS\arcsas.sys
\SystemRoot\system32\DRIVERS\elxstor.sys
\SystemRoot\system32\DRIVERS\iirsp.sys
\SystemRoot\system32\DRIVERS\lsi_fc.sys
\SystemRoot\system32\DRIVERS\lsi_sas2.sys
\SystemRoot\system32\DRIVERS\lsi_scsi.sys
\SystemRoot\system32\DRIVERS\megasas.sys
\SystemRoot\system32\DRIVERS\MegaSR.sys
\SystemRoot\system32\DRIVERS\nfrd960.sys
\SystemRoot\system32\drivers\nvstor.sys
\SystemRoot\system32\DRIVERS\ql2300.sys
\SystemRoot\system32\DRIVERS\ql40xx.sys
\SystemRoot\system32\DRIVERS\SiSRaid2.sys
\SystemRoot\system32\DRIVERS\sisraid4.sys
\SystemRoot\system32\DRIVERS\stexstor.sys
\SystemRoot\system32\DRIVERS\vsmraid.sys
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\system32\drivers\NAVx64\1207010.003\SYMDS64.SYS
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\system32\drivers\NAVx64\1207010.003\SYMEFA64.SYS
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\msrpc.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\DRIVERS\wd.sys
\SystemRoot\system32\drivers\volsnap.sys
\SystemRoot\System32\Drivers\spldr.sys
\SystemRoot\system32\drivers\sbp2port.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\hwpolicy.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\system32\DRIVERS\disk.sys
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\system32\drivers\rdprefmp.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\DRIVERS\wfplwf.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\vwififlt.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\drivers\termdd.sys
\SystemRoot\System32\Drivers\NAVx64\1207010.003\SYMNETS.SYS
\??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS
\SystemRoot\system32\drivers\NAVx64\1207010.003\SRTSPX64.SYS
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\system32\drivers\mssmbios.sys
\??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.5.0.125\Definitions\IPSDefs\20140227.001\IDSvia64.sys
\??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys
\SystemRoot\System32\drivers\discache.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\blbdrive.sys
\SystemRoot\system32\DRIVERS\tunnel.sys
\SystemRoot\system32\DRIVERS\intelppm.sys
\SystemRoot\system32\drivers\wmiacpi.sys
\SystemRoot\system32\DRIVERS\igdkmd64.sys
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\dxgmms1.sys
\SystemRoot\system32\drivers\usbuhci.sys
\SystemRoot\system32\drivers\USBPORT.SYS
\SystemRoot\system32\drivers\usbehci.sys
\SystemRoot\system32\drivers\HDAudBus.sys
\SystemRoot\system32\DRIVERS\Rt64win7.sys
\SystemRoot\system32\DRIVERS\athrx.sys
\SystemRoot\system32\DRIVERS\vwifibus.sys
\SystemRoot\system32\drivers\i8042prt.sys
\SystemRoot\system32\DRIVERS\HpqKbFiltr.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\SynTP.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\DRIVERS\CmBatt.sys
\SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
\SystemRoot\system32\drivers\CompositeBus.sys
\SystemRoot\system32\DRIVERS\AgileVpn.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\drivers\swenum.sys
\SystemRoot\system32\drivers\ks.sys
\SystemRoot\system32\drivers\umbus.sys
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\drivers\CHDRT64.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\drivers\ksthunk.sys
\SystemRoot\system32\DRIVERS\CAXHWAZL.sys
\SystemRoot\system32\DRIVERS\CAX_DPV.sys
\SystemRoot\system32\DRIVERS\CAX_CNXT.sys
\SystemRoot\system32\drivers\modem.sys
\SystemRoot\system32\drivers\IntcHdmi.sys
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\Drivers\dump_dumpata.sys
\SystemRoot\System32\Drivers\dump_msahci.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\System32\Drivers\usbvideo.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\system32\DRIVERS\kbdhid.sys
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\system32\DRIVERS\monitor.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\system32\drivers\luafv.sys
\??\C:\Windows\system32\drivers\mbam.sys
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\nwifi.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\system32\DRIVERS\vwifimp.sys
\SystemRoot\system32\DRIVERS\mdmxsdk.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\Drivers\secdrv.SYS
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\system32\DRIVERS\XAudio64.sys
\SystemRoot\System32\drivers\ipnat.sys
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\DRIVERS\srv.sys
\SystemRoot\System32\Drivers\PxHlpa64.sys
\SystemRoot\system32\drivers\cdrom.sys
\SystemRoot\system32\DRIVERS\cdfs.sys
\??\C:\Windows\system32\drivers\mwac.sys
\??\C:\Windows\system32\drivers\mbamchameleon.sys
\??\C:\Windows\system32\drivers\MBAMSwissArmy.sys
\Windows\System32\ntdll.dll
\Windows\System32\smss.exe
\Windows\System32\apisetschema.dll
\Windows\System32\autochk.exe
\Windows\System32\kernel32.dll
\Windows\System32\iertutil.dll
\Windows\System32\normaliz.dll
\Windows\System32\psapi.dll
\Windows\System32\sechost.dll
\Windows\System32\shlwapi.dll
\Windows\System32\rpcrt4.dll
\Windows\System32\imm32.dll
\Windows\System32\setupapi.dll
\Windows\System32\gdi32.dll
\Windows\System32\urlmon.dll
\Windows\System32\lpk.dll
\Windows\System32\wininet.dll
\Windows\System32\oleaut32.dll
\Windows\System32\msctf.dll
\Windows\System32\difxapi.dll
\Windows\System32\Wldap32.dll
\Windows\System32\shell32.dll
\Windows\System32\ole32.dll
\Windows\System32\msvcrt.dll
\Windows\System32\clbcatq.dll
\Windows\System32\comdlg32.dll
\Windows\System32\ws2_32.dll
\Windows\System32\usp10.dll
\Windows\System32\nsi.dll
\Windows\System32\advapi32.dll
\Windows\System32\imagehlp.dll
\Windows\System32\user32.dll
\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
\Windows\System32\devobj.dll
\Windows\System32\comctl32.dll
\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
\Windows\System32\userenv.dll
\Windows\System32\cfgmgr32.dll
\Windows\System32\KernelBase.dll
\Windows\System32\crypt32.dll
\Windows\System32\wintrust.dll
\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
\Windows\System32\profapi.dll
\Windows\System32\msasn1.dll
----------- End -----------
Done!

Scan started
Database versions:
main: v2015.03.02.05
rootkit: v2015.02.25.01

<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xfffffa8004932060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa8004932b90, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa8004932060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa8004745060, DeviceName: \Device\Ide\IdeDeviceP0T0L0-0\, DriverName: \Driver\atapi\
------------ End ----------
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
File "C:\Windows\System32\drivers\acpipmi.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\acpipmi.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\adp94xx.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\adp94xx.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\adpahci.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\adpahci.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\adpu320.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\adpu320.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\aliide.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\aliide.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\amdide.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\amdide.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\amdk8.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\amdk8.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\amdppm.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\amdppm.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\amdsata.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\amdsata.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\amdsbs.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\amdsbs.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\amdxata.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\amdxata.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\arc.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\arc.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\arcsas.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\arcsas.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\athrx.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\athrx.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\blbdrive.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\blbdrive.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\BrFiltLo.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\BrFiltLo.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\BrFiltUp.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\BrFiltUp.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\BrSerId.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\BrSerId.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\BrSerIf.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\BrSerIf.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\BrSerWdm.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\BrSerWdm.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\BrUsbMdm.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\BrUsbMdm.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\BrUsbSer.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\BrUsbSer.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\bthmodem.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\bthmodem.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\bxvbda.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\bxvbda.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\Cat.DB" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\Cat.DB" is compressed (flags = 1)
File "C:\Windows\System32\drivers\CAXHWAZL.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\CAXHWAZL.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\CAX_CNXT.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\CAX_CNXT.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\CAX_DPV.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\CAX_DPV.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\cdr4_xp.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\cdr4_xp.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\cdralw2k.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\cdralw2k.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\CHDRT64.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\CHDRT64.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\circlass.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\circlass.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\cmdide.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\cmdide.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\crcdisk.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\crcdisk.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\cricut_x64.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\cricut_x64.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\elxstor.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\elxstor.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\evbda.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\evbda.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\fdc.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\fdc.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\HpSAMD.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\HpSAMD.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\HSFProf.cty" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\HSFProf.cty" is compressed (flags = 1)
File "C:\Windows\System32\drivers\iaStorV.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\iaStorV.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\igdkmd64.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\igdkmd64.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\iirsp.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\iirsp.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\IntcHdmi.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\IntcHdmi.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\intelide.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\intelide.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\IPMIDrv.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\IPMIDrv.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\msahci.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\msahci.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\pcmcia.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\pcmcia.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\processr.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\processr.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\PxHlpa64.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\PxHlpa64.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\ql2300.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\ql2300.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\ql40xx.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\ql40xx.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\rdpbus.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\rdpbus.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\b57nd60a.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\b57nd60a.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\flpydisk.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\flpydisk.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\HpqKbFiltr.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\HpqKbFiltr.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\sfloppy.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\sfloppy.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\sisraid2.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\sisraid2.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\sisraid4.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\sisraid4.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\stexstor.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\stexstor.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\swenum.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\swenum.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\SynTP.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\SynTP.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\MTConfig.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\MTConfig.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\mwac.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\mwac.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\netw5v64.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\netw5v64.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\nfrd960.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\nfrd960.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\RimUsb_AMD64.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\RimUsb_AMD64.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\Rt64win7.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\Rt64win7.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\RtsUStor.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\RtsUStor.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\sbp2port.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\sbp2port.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\secdrv.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\secdrv.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\serenum.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\serenum.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\serial.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\serial.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\serscan.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\serscan.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\usbscan.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\usbscan.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\vgapnp.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\vgapnp.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\viaide.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\viaide.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\vsmraid.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\vsmraid.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\VSTAZL6.SYS" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\VSTAZL6.SYS" is compressed (flags = 1)
File "C:\Windows\System32\drivers\VSTCNXT6.SYS" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\VSTCNXT6.SYS" is compressed (flags = 1)
File "C:\Windows\System32\drivers\VSTDPV6.SYS" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\VSTDPV6.SYS" is compressed (flags = 1)
File "C:\Windows\System32\drivers\VSTProf.cty" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\VSTProf.cty" is compressed (flags = 1)
File "C:\Windows\System32\drivers\UAGP35.SYS" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\UAGP35.SYS" is compressed (flags = 1)
File "C:\Windows\System32\drivers\ULIAGPKX.SYS" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\ULIAGPKX.SYS" is compressed (flags = 1)
File "C:\Windows\System32\drivers\umpass.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\umpass.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\usbaapl64.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\usbaapl64.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\usbcir.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\usbcir.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\FlyUsb.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\FlyUsb.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\fssfltr.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\fssfltr.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\GAGP30KX.SYS" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\GAGP30KX.SYS" is compressed (flags = 1)
File "C:\Windows\System32\drivers\GEARAspiWDM.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\GEARAspiWDM.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\hcw85cir.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\hcw85cir.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\hidbatt.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\hidbatt.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\hidbth.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\hidbth.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\hidir.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\hidir.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\wacompen.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\wacompen.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\wd.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\wd.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\wdfcoinstaller01005.dll" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\wdfcoinstaller01005.dll" is compressed (flags = 1)
File "C:\Windows\System32\drivers\WSDPrint.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\WSDPrint.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\XAudio64.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\XAudio64.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\yk62x64.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\yk62x64.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\nvraid.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\nvraid.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\nvstor.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\nvstor.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\NV_AGP.SYS" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\NV_AGP.SYS" is compressed (flags = 1)
File "C:\Windows\System32\drivers\NWADIenum.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\NWADIenum.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\NwUsbCdFil64.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\NwUsbCdFil64.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\nwusbmdm.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\nwusbmdm.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\nwusbser.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\nwusbser.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\nwusbser2.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\nwusbser2.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\parport.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\parport.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\lsi_fc.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\lsi_fc.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\lsi_sas.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\lsi_sas.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\lsi_sas2.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\lsi_sas2.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\lsi_scsi.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\lsi_scsi.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\mbam.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\mbam.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\mbamchameleon.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\mbamchameleon.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\MBAMSwissArmy.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\MBAMSwissArmy.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\mdmxsdk.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\mdmxsdk.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\megasas.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\megasas.sys" is compressed (flags = 1)
File "C:\Windows\System32\drivers\MegaSR.sys" is compressed (flags = 1)
File "C:\WINDOWS\SYSTEM32\drivers\MegaSR.sys" is compressed (flags = 1)
Done!
Drive 0
This is a System drive
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 135C058F

Partition information:

Partition 0 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 2048 Numsec = 407552
Partition file system is NTFS
Partition is bootable

Partition 1 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 409600 Numsec = 463007744

Partition 2 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 463417344 Numsec = 24977408

Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Disk Size: 250059350016 bytes
Sector size: 512 bytes

Done!
File "C:\ProgramData\Malwarebytes' Anti-Malware (portable)\S-1-5-21-388765262-82104682-801132495-1001-0-UsrClass.dat" is compressed (flags = 1)
File "C:\Users\Mom's Computer\AppData\Roaming\Apple Computer\Logs\asl.093207_01Mar15.log" is compressed (flags = 1)
File "C:\Users\Mom's Computer\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db" is compressed (flags = 1)
File "C:\Users\Mom's Computer\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db" is compressed (flags = 1)
File "C:\Users\Mom's Computer\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db" is compressed (flags = 1)
File "C:\Users\Mom's Computer\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db" is compressed (flags = 1)
File "C:\Users\Mom's Computer\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db" is compressed (flags = 1)
File "C:\Users\Mom's Computer\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db" is compressed (flags = 1)
File "C:\Users\Mom's Computer\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat" is compressed (flags = 1)
File "C:\Users\Mom's Computer\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.tmp" is compressed (flags = 1)
File "C:\Users\Mom's Computer\AppData\Local\Temp\AdobeARM.log" is compressed (flags = 1)
File "C:\Users\Mom's Computer\AppData\Local\Temp\~DF08EE888CEF19E213.TMP" is compressed (flags = 1)
File "C:\Users\Mom's Computer\AppData\Local\Temp\~DF201FA9842719A41E.TMP" is compressed (flags = 1)
File "C:\Users\Mom's Computer\AppData\Local\Temp\~DF2CCD3BF36FAAC0EE.TMP" is compressed (flags = 1)
File "C:\Users\Mom's Computer\AppData\Local\Temp\~DF5FBFC119F48EE57E.TMP" is compressed (flags = 1)
File "C:\Users\Mom's Computer\AppData\Local\Temp\~DF84EB9466DCFCFCC7.TMP" is compressed (flags = 1)
File "C:\Users\Mom's Computer\AppData\Local\Temp\~DF8E1CF90AA42BC47E.TMP" is compressed (flags = 1)
File "C:\Users\Mom's Computer\AppData\Local\Temp\~DF908D27FD1F61224D.TMP" is compressed (flags = 1)
File "C:\Users\Mom's Computer\AppData\Local\Temp\~DFAF61503021A80DE0.TMP" is compressed (flags = 1)
File "C:\Users\Mom's Computer\AppData\Local\Temp\~DFE840021001F2D0B9.TMP" is compressed (flags = 1)
File "C:\Users\Mom's Computer\AppData\Local\Temp\~DFEB02B39213FF7DCB.TMP" is compressed (flags = 1)
File "C:\Users\Mom's Computer\AppData\Local\Temp\~DFFA51BB3BFC3A5AD2.TMP" is compressed (flags = 1)
File "C:\Users\Mom's Computer\AppData\Local\Temp\PDApp.log" is compressed (flags = 1)
File "C:\Users\Mom's Computer\AppData\Local\Temp\Low\JavaDeployReg.log" is compressed (flags = 1)
File "C:\Users\Mom's Computer\AppData\Local\Akamai\Logs\debug.log" is compressed (flags = 1)
File "C:\Users\Mom's Computer\AppData\Local\Apple Computer\Cache.db" is compressed (flags = 1)
File "C:\Windows\WindowsUpdate.log" is compressed (flags = 1)
Scan finished
=======================================


Removal queue found; removal started
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-0-0-2048-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-r.mbam...
Removal finished
 
Last edited:

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
PC seems clean, malware isn't causing this.


Use the Windows Error Checking utility (Check Disk), with the options to fix file system errors and scan the disk surface for errors, attempt recovery of data and repair the disk:

  • Click the "Windows Orb" Start button, then click Computer.
  • Right-click on the drive (that would be C in your case) that you wish to check > Properties > Tools tab
  • In the "Error checking" section, click on Check now.
  • Place a checkmark in both boxes > Start.
  • If the disk you have chosen is the Windows system disk:
  • A message will notify you that a restart is necessary ask "Do you want to check for hard disk errors the next time you start your computer?".
  • Click Schedule disk check > OK and close all windows.
  • Re-start the computer. The disk will be checked when the system boots.
  • This will take some time to run and at times may appear stalled but just let it run.
  • When the disk check is complete, the system will re-start automatically and load Windows.
A log of the disk check is recorded only if the scheduled re-start is used, and only for drives on the same HDD as the Operating System.
To open Event Viewer and view the log:


  • Click the "Windows Orb" Start button -> type "eventvwr" without the quotes -> press the key.
  • The Event Viewer window will open.
  • In the left pane, expand "Windows Logs" and then click on Application.
  • In the right pane, at the top, click on the column heading Source to sort the list alphabetically.
  • Look in the Source column for "Wininit", with an entry corresponding to the date and time of the disk check.
  • Click on that Wininit entry to select it.
  • On the top main menu, click Action > Copy > Copy Details as Text.
  • Paste the contents into your next reply.
 

perezfab5

New Member
Thread author
Feb 27, 2015
12
Log Name: Application
Source: Microsoft-Windows-Wininit
Date: 3/2/2015 5:10:40 PM
Event ID: 1001
Task Category: None
Level: Information
Keywords: Classic
User: N/A
Computer: MomsComputer-PC
Description:


Checking file system on C:
The type of the file system is NTFS.

A disk check has been scheduled.
Windows will now check the disk.

CHKDSK is verifying files (stage 1 of 5)...
343552 file records processed.

File verification completed.
5751 large file records processed.

0 bad file records processed.

0 EA records processed.

60 reparse records processed.

CHKDSK is verifying indexes (stage 2 of 5)...
409626 index entries processed.

Index verification completed.
0 unindexed files scanned.

0 unindexed files recovered.

CHKDSK is verifying security descriptors (stage 3 of 5)...
343552 file SDs/SIDs processed.

Cleaning up 399 unused index entries from index $SII of file 0x9.
Cleaning up 399 unused index entries from index $SDH of file 0x9.
Cleaning up 399 unused security descriptors.
Security descriptor verification completed.
33038 data files processed.

CHKDSK is verifying Usn Journal...
37517240 USN bytes processed.

Usn Journal verification completed.
CHKDSK is verifying file data (stage 4 of 5)...
Windows replaced bad clusters in file 154556
of name \Users\MOM'SC~1\Pictures\2014\FALLPI~1\TASRAN~1\DZ1_2950.jpg.
Windows replaced bad clusters in file 189732
of name \Users\MOM'SC~1\Pictures\2014\FALLPI~1\TASRAN~1\DZ1_3050.jpg.
Windows replaced bad clusters in file 192990
of name \Users\MOM'SC~1\Pictures\APPLEI~1\2015-0~1\530.JPG.
Windows replaced bad clusters in file 234220
of name \Users\MOM'SC~1\Pictures\HOLIDA~1\DEC_3578.NEF.
Windows replaced bad clusters in file 234266
of name \Users\MOM'SC~1\Pictures\HOLIDA~1\DEC_3582.NEF.
Windows replaced bad clusters in file 244969
of name \Users\MOM'SC~1\Pictures\APPLEI~1\2015-0~1\718.JPG.
343536 files processed.

File data verification completed.
CHKDSK is verifying free space (stage 5 of 5)...
5277304 free clusters processed.

Free space verification is complete.
CHKDSK discovered free space marked as allocated in the
master file table (MFT) bitmap.
CHKDSK discovered free space marked as allocated in the volume bitmap.
Windows has made corrections to the file system.

231503871 KB total disk space.
209787628 KB in 183448 files.
151216 KB in 33039 indexes.
0 KB in bad sectors.
455811 KB in use by the system.
65536 KB occupied by the log file.
21109216 KB available on disk.

4096 bytes in each allocation unit.
57875967 total allocation units on disk.
5277304 allocation units available on disk.

Internal Info:
00 3e 05 00 b3 4d 03 00 45 d2 05 00 00 00 00 00 .>...M..E.......
34 74 00 00 3c 00 00 00 00 00 00 00 00 00 00 00 4t..<...........
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................

Windows has finished checking your disk.
Please wait while your computer restarts.

Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Wininit" Guid="{206f6dea-d3c5-4d10-bc72-989f03c8b84b}" EventSourceName="Wininit" />
<EventID Qualifiers="16384">1001</EventID>
<Version>0</Version>
<Level>4</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2015-03-02T23:10:40.000000000Z" />
<EventRecordID>4792765</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>Application</Channel>
<Computer>MomsComputer-PC</Computer>
<Security />
</System>
<EventData>
<Data>

Checking file system on C:
The type of the file system is NTFS.

A disk check has been scheduled.
Windows will now check the disk.

CHKDSK is verifying files (stage 1 of 5)...
343552 file records processed.

File verification completed.
5751 large file records processed.

0 bad file records processed.

0 EA records processed.

60 reparse records processed.

CHKDSK is verifying indexes (stage 2 of 5)...
409626 index entries processed.

Index verification completed.
0 unindexed files scanned.

0 unindexed files recovered.

CHKDSK is verifying security descriptors (stage 3 of 5)...
343552 file SDs/SIDs processed.

Cleaning up 399 unused index entries from index $SII of file 0x9.
Cleaning up 399 unused index entries from index $SDH of file 0x9.
Cleaning up 399 unused security descriptors.
Security descriptor verification completed.
33038 data files processed.

CHKDSK is verifying Usn Journal...
37517240 USN bytes processed.

Usn Journal verification completed.
CHKDSK is verifying file data (stage 4 of 5)...
Windows replaced bad clusters in file 154556
of name \Users\MOM'SC~1\Pictures\2014\FALLPI~1\TASRAN~1\DZ1_2950.jpg.
Windows replaced bad clusters in file 189732
of name \Users\MOM'SC~1\Pictures\2014\FALLPI~1\TASRAN~1\DZ1_3050.jpg.
Windows replaced bad clusters in file 192990
of name \Users\MOM'SC~1\Pictures\APPLEI~1\2015-0~1\530.JPG.
Windows replaced bad clusters in file 234220
of name \Users\MOM'SC~1\Pictures\HOLIDA~1\DEC_3578.NEF.
Windows replaced bad clusters in file 234266
of name \Users\MOM'SC~1\Pictures\HOLIDA~1\DEC_3582.NEF.
Windows replaced bad clusters in file 244969
of name \Users\MOM'SC~1\Pictures\APPLEI~1\2015-0~1\718.JPG.
343536 files processed.

File data verification completed.
CHKDSK is verifying free space (stage 5 of 5)...
5277304 free clusters processed.

Free space verification is complete.
CHKDSK discovered free space marked as allocated in the
master file table (MFT) bitmap.
CHKDSK discovered free space marked as allocated in the volume bitmap.
Windows has made corrections to the file system.

231503871 KB total disk space.
209787628 KB in 183448 files.
151216 KB in 33039 indexes.
0 KB in bad sectors.
455811 KB in use by the system.
65536 KB occupied by the log file.
21109216 KB available on disk.

4096 bytes in each allocation unit.
57875967 total allocation units on disk.
5277304 allocation units available on disk.

Internal Info:
00 3e 05 00 b3 4d 03 00 45 d2 05 00 00 00 00 00 .&gt;...M..E.......
34 74 00 00 3c 00 00 00 00 00 00 00 00 00 00 00 4t..&lt;...........
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................

Windows has finished checking your disk.
Please wait while your computer restarts.
</Data>
</EventData>
</Event>
 

perezfab5

New Member
Thread author
Feb 27, 2015
12
Still experiencing 'stackHash' appcrash issues with the one program...looking into further as I believe it has something to do with my cpu memory getting close to being full. Currently working on trying to clean out files(mainly photos). Other than that, seems to be working just fine - a lot better anyway. Any suggestions you might could offer to help in cleaning up my pc I.e. uninstalling programs? Or things I should avoid?

Thanks again for your time and help with this mess. I do appreciate it all.
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Glad I could help. We will delete all used tools and I'll give you some tips to harden your security and learn how to protect yourself :)


Recommended reading:
icon_exclaim.gif
MUST READ - security tips:

icon_exclaim.gif
MUST READ - general maintenance:


The Importance of Software Updating:

In order to stay protected it is
very important that you regularly update all of your software. Cybercriminals depend on the apathy of users around software updates to keep their malicious endeavor running.

Operating systems, such as Windows, and applications, such as Adobe Reader or JAVA, are used by tens of millions of computers and devices around the world, making them a huge target for cybercriminals. Downloading updates and installing them can sometimes be tedious, but the advantages you get from the updates are certainly worth it.




Recommended additional software:
icon_arrow.gif
TFC - to clean unneeded temporary files.
icon_arrow.gif
Malwarebytes' Anti-Malware - to scan your system from time to time in search for malware.
icon_arrow.gif
Malwarebytes' Anti-Exploit - to prevent plenty of mostly exploited vulnerabilities.
icon_arrow.gif
McShield - to prevent infections spread by removable media.
icon_arrow.gif
Unchecky - to prevent from installing additional foistware, implemented in legitimate installations.
icon_arrow.gif
Adblock - to surf the web without annoying ads!



Post-cleanup procedures:


Download DelFix by Xplode and save it to your desktop.
  • Run the tool by right click on the
    51a5ce45263de-delfix.png
    icon and Run as administrator option.
  • Make sure that these ones are checked:
    • Remove disinfection tools
    • Purge system restore
    • Reset system settings
  • Push Run and wait until the tool completes his work.
  • All tools we used should be gone. Tool will create an report for you (C:\DelFix.txt)
The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.



My help is free for everybody.
If you're happy with the help provided and/or wish to buy me a beer for the assistance you received, then you can consider a donation:
Thank you!​




Stay safe,
TwinHeadedEagle :)
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top