Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie
Hi there,
There is an issue with role permissions that is being worked on at the moment.
If you are having trouble with access or permissions on regional forums please post here to get access: https://www.boards.ie/discussion/2058365403/you-do-not-have-permission-for-that#latest

Windows taskbar not displaying active programmes

  • 24-08-2007 04:48PM
    #1
    Registered Users, Registered Users 2 Posts: 7,110 ✭✭✭


    Hello,

    My windows taskbar recently stopped displaying the programmes I have open (I get around by using the alt-tab keys).

    I can still see my quick launch and language bar...but if I close them I lose sight of the taskbar all together.

    I believe something in the registry has been changed (I did a system restore once and it solved the problem - now I don't have any restore points anymore)

    My other accounts have not been affected though...

    Anyone know what to do? Thanks!


Comments

  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    Try this

    Please download Deckard's System Scanner (DSS) and save it to your Desktop.
    • Close all other windows before proceeding.
    • Double-click on dss.exe and follow the prompts.
    • If your anti-virus or firewall complains, please allow this script to run as it is not malicious.
    • When it has finished, dss will open two Notepads main.txt and extra.txt -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.


  • Registered Users, Registered Users 2 Posts: 7,110 ✭✭✭Thirdfox


    Deckard's System Scanner v20070819.64
    Run by Thirdfox on 2007-08-24 18:14:18
    Computer is in Normal Mode.

    -- System Restore

    Successfully created a Deckard's System Scanner Restore Point.


    -- Last 2 Restore Point(s) --
    2: 2007-08-24 17:14:23 UTC - RP91 - Deckard's System Scanner Restore Point
    1: 2007-08-18 19:56:21 UTC - RP90 - Removed Star Wars JK II Jedi Outcast


    Backed up registry hives.
    Performed disk cleanup.



    -- HijackThis Clone

    Emulating logfile of HijackThis v1.99.1
    Scan saved at 2007-08-24 18:16:30
    Platform: Windows XP Service Pack 2 (5.01.2600)
    MSIE: Internet Explorer (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\system32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
    C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    E:\Programmes\Alcohol\Alcohol 120\StarWind\StarWindServiceAE.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\HPQ\Quick Launch Buttons\eabservr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
    C:\Program Files\Picasa2\PicasaMediaDetector.exe
    C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    E:\Programmes\ActiveSync\wcescomm.exe
    C:\Program Files\Kingsoft\PowerWord 2006\XDICT.exe
    C:\Program Files\WallpaperToy\Wallpapertoy.Exe
    E:\Programmes\ActiveSync\rapimgr.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\Program Files\Tencent\QQ\TIMPlatform.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\Skype\Plugin Manager\skypePM.exe
    C:\WINDOWS\system32\taskmgr.exe
    C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2F1.EXE
    C:\WINDOWS\system32\conime.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\Documents and Settings\Diyu Daniel Wu\Desktop\dss.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=Q305&bd=pavilion&pf=laptop
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.qq.com
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://qzone.qq.com/proxy.htm
    R3 - URLSearchHook: (no name) - {DB8B2393-7A6C-4C76-88CE-6B1F6FF6FFE9} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O4 - HKEY_LOCAL_MACHINE\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKEY_LOCAL_MACHINE\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKEY_LOCAL_MACHINE\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKEY_LOCAL_MACHINE\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKEY_LOCAL_MACHINE\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKEY_LOCAL_MACHINE\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKEY_LOCAL_MACHINE\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKEY_LOCAL_MACHINE\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKEY_LOCAL_MACHINE\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
    O4 - HKEY_LOCAL_MACHINE\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKEY_LOCAL_MACHINE\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
    O4 - HKEY_LOCAL_MACHINE\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKEY_LOCAL_MACHINE\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    O4 - HKEY_LOCAL_MACHINE\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - HKEY_LOCAL_MACHINE\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
    O4 - HKEY_LOCAL_MACHINE\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    O4 - HKEY_LOCAL_MACHINE\..\Run: [stup.exe] C:\PROGRA~1\TENCENT\Adplus\stup.exe
    O4 - HKEY_LOCAL_MACHINE\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKEY_LOCAL_MACHINE\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKEY_LOCAL_MACHINE\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKEY_LOCAL_MACHINE\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P30 "EPSON Stylus Photo R300 Series" /O6 "USB001" /M "Stylus Photo R300"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
    O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
    O4 - HKCU\..\Run: [AlcoholAutomount] "E:\Programmes\Alcohol\Alcohol 120\axcmd.exe" /automount
    O4 - HKCU\..\Run: [H/PC Connection Agent] "E:\Programmes\ActiveSync\wcescomm.exe"
    O4 - Startup: Powerword 2006.lnk = C:\Program Files\Kingsoft\PowerWord 2006\XDICT.EXE
    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Startup: Wallpaper Changer.lnk = C:\Program Files\WallpaperToy\Wallpapertoy.Exe
    O4 - Startup: 腾讯QQ.lnk = C:\Program Files\Tencent\QQ\QQ.exe
    O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
    O8 - Extra context menu item: Add to QQ Customized Emoticons - C:\Program Files\Tencent\QQ\AddEmotion.htm
    O8 - Extra context menu item: Add to QQ Customized Panel - C:\Program Files\Tencent\QQ\AddPanel.htm
    O8 - Extra context menu item: Add to QQ Emotions - C:\Program Files\Tencent\QQ\AddEmotion.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Locate Spot on Map by GPS - C:\Program Files\Opanda\IExif 2.26\IExifMap.htm
    O8 - Extra context menu item: Send picture by MMS - C:\Program Files\Tencent\QQ\SendMMS.htm
    O8 - Extra context menu item: Send Picture with QQ MMS - C:\Program Files\Tencent\QQ\SendMMS.htm
    O8 - Extra context menu item: Upload to QQ Network Hard Disk - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
    O8 - Extra context menu item: View Exif/GPS/IPTC with IExif - C:\Program Files\Opanda\IExif 2.26\IExifCom.htm
    O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - E:\Programmes\ActiveSync\INetRepl.dll
    O9 - Extra 'Tools' menuitem: (no name) - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - E:\Programmes\ActiveSync\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - E:\Programmes\ActiveSync\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - E:\Programmes\ActiveSync\INetRepl.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
    O9 - Extra 'Tools' menuitem: (no name) - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options Group: [TBH] SOSO AddressBar Search
    O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} (KooPlayer Control) - http://www.tvkoo.com/update/KooPlayer.ocx
    O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL
    O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL
    O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL
    O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
    O23 - Service: Adobe LM Service - Adobe Systems - "C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - "C:\Program Files\AntiVir PersonalEdition Classic\sched.exe"
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - "C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe"
    O23 - Service: Apple Mobile Device - Apple, Inc. - "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe"
    O23 - Service: GoogleDesktopManager - Google - "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe"
    O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\shared\hpqwmi.exe
    O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - E:\Programmes\Alcohol\Alcohol 120\StarWind\StarWindServiceAE.exe


    -- File Associations

    .chm - chm.file - shell\open\command - "hh.exe" %1
    .ini - inifile - shell\open\command - C:\WINDOWS\System32\NOTEPAD.EXE %1
    .txt - txtfile - shell\open\command - C:\WINDOWS\notepad.exe %1


    -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled

    R2 npkcrypt - c:\program files\tencent\npkcrypt.sys <Not Verified; INCA Internet Co., Ltd.; nProtect KeyCrypt Driver>
    R2 npkcusb - c:\program files\tencent\npkcusb.sys <Not Verified; INCA Internet Co., Ltd.; nProtect KeyCrypt Driver>


    -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled

    R2 AntiVirScheduler (AntiVir PersonalEdition Classic Scheduler) - "c:\program files\antivir personaledition classic\sched.exe" <Not Verified; Avira GmbH; Scheduler>
    R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
    R2 StarWindServiceAE (StarWind AE Service) - e:\programmes\alcohol\alcohol 120\starwind\starwindserviceae.exe <Not Verified; Rocket Division Software; StarWind Alcohol Edition>

    S3 hpqwmi (HP WMI Interface) - c:\program files\hpq\shared\hpqwmi.exe <Not Verified; Hewlett-Packard Development Company, L.P.; hpqwmi Module>


    -- Device Manager: Disabled

    No disabled devices found.


    -- Scheduled Tasks

    2007-08-24 12:23:02 284 --a
    C:\WINDOWS\Tasks\AppleSoftwareUpdate.job


    -- Files created between 2007-07-24 and 2007-08-24

    2007-08-24 12:36:30 0 d
    C:\WINDOWS\LastGood
    2007-08-24 12:36:17 0 d
    C:\Program Files\EPSON
    2007-08-24 12:36:08 0 d
    C:\epson
    2007-08-18 20:58:19 0 d
    C:\Documents and Settings\All\Application Data\Talkback
    2007-08-18 20:58:10 0 d
    C:\Documents and Settings\All\Application Data\Thunderbird
    2007-08-03 21:13:09 0 d
    C:\魔兽争霸3+冰封王座V1.6简体中文版
    2007-08-03 21:07:11 0 d
    C:\Documents and Settings\All\Application Data\Sun
    2007-08-03 21:03:06 0 d
    C:\Documents and Settings\All\Application Data\Macromedia
    2007-08-03 21:02:33 0 d
    C:\Documents and Settings\All\Application Data\Mozilla
    2007-08-03 20:57:09 0 d
    C:\Documents and Settings\All\Application Data\Apple Computer
    2007-08-03 12:41:51 0 d
    C:\Program Files\iPod
    2007-08-03 12:41:48 0 d
    C:\Program Files\iTunes
    2007-08-03 12:40:09 0 d
    C:\Program Files\Common Files\Apple
    2007-08-03 12:40:08 0 d
    C:\Documents and Settings\All Users\Application Data\Apple
    2007-08-03 12:29:26 0 d
    C:\Program Files\QuickTime
    2007-08-03 12:03:46 55547 --a
    C:\WINDOWS\War3Unin.dat
    2007-08-03 12:03:44 2829 --a
    C:\WINDOWS\War3Unin.pif
    2007-08-03 12:03:44 139264 --a
    C:\WINDOWS\War3Unin.exe <Not Verified; Blizzard Entertainment; Warcraft III Uninstaller>
    2007-08-02 16:58:45 283648 --a
    C:\WINDOWS\uninst.exe <Not Verified; Stirling Technologies, Inc.; InstallShield Deinstaller>
    2007-08-02 16:58:43 0 d
    C:\Documents and Settings\Diyu Daniel Wu\WINDOWS
    2007-08-02 16:58:41 180156 --a
    C:\WINDOWS\STUB.EXE
    2007-08-02 16:21:03 685816 --a
    C:\WINDOWS\system32\drivers\sptd.sys
    2007-07-29 10:42:08 0 d
    C:\Program Files\MIKSOFT
    2007-07-28 21:43:28 10 --a
    C:\WINDOWS\aaaaaaaaa
    2007-07-28 21:42:52 0 d
    C:\Documents and Settings\Diyu Daniel Wu\Application Data\CenturionPlayer
    2007-07-28 20:43:00 7680 --a
    C:\WINDOWS\system32\ff_vfw.dll
    2007-07-28 20:42:59 60273 --a
    C:\WINDOWS\system32\pthreadGC2.dll <Not Verified; Open Source Software community project; >


    -- Find3M Report

    2007-08-03 12:16:36 2528 --a
    C:\Documents and Settings\Diyu Daniel Wu\Application Data\$_hpcst$.hpc
    2007-07-21 20:27:24 1327 --a
    C:\WINDOWS\mozver.dat
    2007-07-19 11:31:18 0 d
    C:\Documents and Settings\Diyu Daniel Wu\Application Data\QQUpdate
    2007-07-18 23:59:00 0 d
    C:\Documents and Settings\Diyu Daniel Wu\Application Data\vlc
    2007-07-18 15:16:02 0 d
    C:\Documents and Settings\Diyu Daniel Wu\Application Data\Tencent
    2007-07-18 14:29:44 0 d
    C:\Documents and Settings\Diyu Daniel Wu\Application Data\QQ
    2007-07-18 13:21:20 0 d
    C:\Program Files\QQ
    2007-07-17 18:35:48 0 d
    C:\Documents and Settings\Diyu Daniel Wu\Application Data\Sun
    2007-07-16 20:07:58 0 d
    C:\Documents and Settings\Diyu Daniel Wu\Application Data\Command & Conquer 3 Tiberium Wars Demo
    2007-07-16 11:14:22 0 d
    C:\Documents and Settings\Diyu Daniel Wu\Application Data\Azureus


    -- Registry Dump

    *Note* empty entries & legit default entries are not shown


    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [04/08/2004 05:00]
    "MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [04/08/2004 05:00]
    "PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [04/08/2004 05:00]
    "PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [04/08/2004 05:00]
    "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [12/01/2006 15:40]
    "igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [19/07/2005 10:09]
    "igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [19/07/2005 10:06]
    "igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [19/07/2005 10:10]
    "eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [03/12/2004 13:24]
    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [12/01/2007 14:36]
    "WatchDog"="C:\Program Files\InterVideo\DVD Check\DVDCheck.exe" [08/12/2004 18:44]
    "avgnt"="C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" [02/04/2007 10:35]
    "Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [26/07/2007 22:31]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [14/03/2007 03:43]
    "Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [16/06/2007 07:15]
    "HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [16/02/2005 23:11]
    "stup.exe"="C:\PROGRA~1\TENCENT\Adplus\stup.exe" []
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [11/05/2007 03:06]
    "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [29/06/2007 06:24]
    "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [31/07/2007 18:44]
    "EPSON Stylus Photo R300 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.exe" [04/06/2003 03:00]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/08/2004 12:00]
    "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [31/05/2005 01:04]
    "NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [15/09/2006 13:27]
    "updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" []
    "AlcoholAutomount"="E:\Programmes\Alcohol\Alcohol 120\axcmd.exe" [02/07/2007 11:29]
    "H/PC Connection Agent"="E:\Programmes\ActiveSync\wcescomm.exe" [13/11/2006 13:39]

    C:\Documents and Settings\Diyu Daniel Wu\Start Menu\Programs\Startup\
    Powerword 2006.lnk - C:\Program Files\Kingsoft\PowerWord 2006\XDICT.EXE [29/09/2005 10:25:10]
    Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [16/03/2005 19:16:50]
    Wallpaper Changer.lnk - C:\Program Files\WallpaperToy\Wallpapertoy.Exe [14/05/2007 10:56:23]
    腾讯QQ.lnk - C:\Program Files\Tencent\QQ\QQ.exe [13/06/2007 02:07:02]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    DVD Check.lnk - C:\Program Files\InterVideo\DVD Check\DVDCheck.exe [13/05/2007 15:04:49]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL


    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{022846be-2443-11dc-a264-00c09fad929f}]
    1\Command- autorun.pif
    2\Command- autorun.pif
    AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.pif

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9a19abcb-0f2b-11dc-a25c-0012f0a2198e}]
    AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL delautorun.bat
    杀毒(&K)\command- G:\delautorun.bat

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ccbcbe67-1fab-11dc-a260-00c09fad929f}]
    AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL service.exe
    打开\command- service.exe




    -- End of Deckard's System Scanner: finished at 2007-08-24 18:17:04




























    Deckard's System Scanner v20070819.64
    Extra logfile - please post this as an attachment with your post.

    -- System Information

    Microsoft Windows XP Professional (build 2600) SP 2.0
    Architecture: X86; Language: English

    CPU 0: Intel(R) Pentium(R) M processor 1.86GHz
    Percentage of Memory in Use: 61%
    Physical Memory (total/avail): 1014.42 MiB / 394.73 MiB
    Pagefile Memory (total/avail): 2441.39 MiB / 1847.68 MiB
    Virtual Memory (total/avail): 2047.88 MiB / 1954.87 MiB

    C: is Fixed (FAT32) - 19.52 GiB total, 7.38 GiB free.
    D: is Fixed (NTFS) - 39.06 GiB total, 16.98 GiB free.
    E: is Fixed (NTFS) - 53.19 GiB total, 20.85 GiB free.
    F: is CDROM (No Media)
    G: is CDROM (No Media)


    -- Security Center

    AUOptions is disabled.
    Windows Internal Firewall is enabled.

    FirstRunDisabled is set.

    AV: Avira AntiVir PersonalEdition v 6.39.1.40
    (Avira GmbH)

    [HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "E:\\Programmes\\ActiveSync\\rapimgr.exe"="E:\\Programmes\\ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
    "E:\\Programmes\\ActiveSync\\wcescomm.exe"="E:\\Programmes\\ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
    "E:\\Programmes\\ActiveSync\\WCESMgr.exe"="E:\\Programmes\\ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

    [HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"="C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe:*:Enabled:BlueSoleil"
    "E:\\program files\\Tencent\\QQ\\QQ.exe"="E:\\program files\\Tencent\\QQ\\QQ.exe:*:Disabled:QQ"
    "E:\\program files\\Tencent\\QQ\\Qzone\\Qzone.exe"="E:\\program files\\Tencent\\QQ\\Qzone\\Qzone.exe:*:Disabled:QZoneClient1.2Beta02 V01.2.102.022"
    "C:\\Program Files\\Kingsoft\\PowerWord 2006\\xdict.exe"="C:\\Program Files\\Kingsoft\\PowerWord 2006\\xdict.exe:*:Enabled:Kingsoft PowerWord"
    "C:\\Program Files\\Kingsoft\\PowerWord 2006\\update.exe"="C:\\Program Files\\Kingsoft\\PowerWord 2006\\update.exe:*:Enabled:Kingsoft PowerWord Online Update"
    "C:\\Program Files\\Tencent\\QQ.exe"="C:\\Program Files\\Tencent\\QQ.exe:*:Disabled:QQ"
    "E:\\program files\\Skype\\Phone\\Skype.exe"="E:\\program files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
    "C:\\Program Files\\Tencent\\Qzone\\Qzone.exe"="C:\\Program Files\\Tencent\\Qzone\\Qzone.exe:*:Disabled:QZoneClient1.2Beta02 V01.2.102.022"
    "E:\\Daniel's Games\\Command and Conquer\\Command & Conquer Generals\\game.dat"="E:\\Daniel's Games\\Command and Conquer\\Command & Conquer Generals\\game.dat:*:Enabled:game"
    "E:\\Daniel's Games\\Halo\\halo.exe"="E:\\Daniel's Games\\Halo\\halo.exe:*:Enabled:Halo"
    "E:\\Backup\\Leftover recovery files\\program files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"="E:\\Backup\\Leftover recovery files\\program files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe:*:Enabled:BlueSoleil"
    "E:\\Programmes\\Azureus\\Azureus.exe"="E:\\Programmes\\Azureus\\Azureus.exe:*:Enabled:Azureus"
    "C:\\Program Files\\QQ\\Africa2003\\QQ.exe"="C:\\Program Files\\QQ\\Africa2003\\QQ.exe:*:Disabled:QQ"
    "C:\\Program Files\\Tencent\\QQ\\QQ.exe"="C:\\Program Files\\Tencent\\QQ\\QQ.exe:*:Enabled:QQ"
    "C:\\Program Files\\Tencent\\QQ\\Qzone\\Qzone.exe"="C:\\Program Files\\Tencent\\QQ\\Qzone\\Qzone.exe:*:Enabled:QZoneClient1.2Beta02 V01.2.102.022"
    "C:\\Program Files\\Tencent\\QQ\\QQUpdateCenter.exe"="C:\\Program Files\\Tencent\\QQ\\QQUpdateCenter.exe:*:Enabled:QQUpdate"
    "C:\\Program Files\\Tencent\\QQDownload\\QQDownload.exe"="C:\\Program Files\\Tencent\\QQDownload\\QQDownload.exe:*:Disabled:超级旋风"
    "C:\\Program Files\\Tencent\\QQDownload\\QDAutoUpdate.exe"="C:\\Program Files\\Tencent\\QQDownload\\QDAutoUpdate.exe:*:Disabled:AutoUpdate Module"
    "E:\\Programmes\\ActiveSync\\rapimgr.exe"="E:\\Programmes\\ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
    "E:\\Programmes\\ActiveSync\\wcescomm.exe"="E:\\Programmes\\ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
    "E:\\Programmes\\ActiveSync\\WCESMgr.exe"="E:\\Programmes\\ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
    "E:\\Daniel's Games\\Warcraft III\\Warcraft III.exe"="E:\\Daniel's Games\\Warcraft III\\Warcraft III.exe:*:Enabled:Warcraft III"
    "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
    "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype. Take a deep breath "


    -- Environment Variables

    ALLUSERSPROFILE=C:\Documents and Settings\All Users
    APPDATA=C:\Documents and Settings\Diyu Daniel Wu\Application Data
    CLASSPATH=.;C:\Program Files\Java\jre1.6.0_01\lib\ext\QTJava.zip
    CommonProgramFiles=C:\Program Files\Common Files
    COMPUTERNAME=TRINITY-9B6F4F1
    ComSpec=C:\WINDOWS\system32\cmd.exe
    FP_NO_HOST_CHECK=NO
    HOMEDRIVE=C:
    HOMEPATH=\Documents and Settings\Diyu Daniel Wu
    LOGONSERVER=\\TRINITY-9B6F4F1
    NUMBER_OF_PROCESSORS=1
    OS=Windows_NT
    Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\Common Files\Adobe\AGL;C:\Program Files\QuickTime\QTSystem\
    PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
    PROCESSOR_ARCHITECTURE=x86
    PROCESSOR_IDENTIFIER=x86 Family 6 Model 13 Stepping 8, GenuineIntel
    PROCESSOR_LEVEL=6
    PROCESSOR_REVISION=0d08
    ProgramFiles=C:\Program Files
    PROMPT=$P$G
    QTJAVA=C:\Program Files\Java\jre1.6.0_01\lib\ext\QTJava.zip
    SESSIONNAME=Console
    SonicCentral=C:\Program Files\Common Files\Sonic Shared\Sonic Central\
    SystemDrive=C:
    SystemRoot=C:\WINDOWS
    TEMP=C:\DOCUME~1\DIYUDA~1\LOCALS~1\Temp
    TMP=C:\DOCUME~1\DIYUDA~1\LOCALS~1\Temp
    USERDOMAIN=TRINITY-9B6F4F1
    USERNAME=Diyu Daniel Wu
    USERPROFILE=C:\Documents and Settings\Diyu Daniel Wu
    windir=C:\WINDOWS


    -- User Profiles

    Diyu Daniel Wu (admin)
    All


    -- Add/Remove Programs

    --> C:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}
    --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
    Adobe Bridge 1.0 --> MsiExec.exe /I{B74D4E10-6884-0000-0000-000000000103}
    Adobe Common File Installer --> MsiExec.exe /I{8EDBA74D-0686-4C99-BFDD-F894678E5B39}
    Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
    Adobe Help Center 1.0 --> MsiExec.exe /I{E9787678-1033-0000-8E67-000000000001}
    Adobe Photoshop CS2 --> msiexec /I {236BB7C4-4419-42FD-0409-1E257A25E34D}
    Adobe Reader 8.1.0 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81000000003}
    Adobe Stock Photos 1.0 --> MsiExec.exe /I{EE0D5DCD-2B97-4473-98DF-E93C0BD92F7A}
    Apple Mobile Device Support --> MsiExec.exe /I{967D588C-9B96-40C9-A222-DCD6922563CA}
    Apple Software Update --> MsiExec.exe /I{A260B422-70E1-41E2-957D-F76FA21266D5}
    Avira AntiVir PersonalEdition Classic --> C:\Program Files\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
    Azureus Vuze --> E:\Programmes\Azureus\uninstall.exe
    Broadcom 802.11 Wireless LAN Adapter --> C:\WINDOWS\system32\BCMWLU00.exe verbose /rootkey=Software\Broadcom\802.11\UninstallInfo
    CenturionPlayer v3.0.0 Release candidate 2 --> E:\PROGRA~1\CENTUR~1\UNWISE.EXE E:\PROGRA~1\CENTUR~1\INSTALL.LOG
    ClearType Tuning Control Panel Applet --> MsiExec.exe /I{C9E4932C-8417-4E4C-A0E3-EE534810AB4D}
    Conexant AC-Link Audio --> CIAunwdm.exe
    EPSON Printer Software --> C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
    ffdshow [rev 1376] [2007-07-28] --> "E:\Programmes\ffdshow\unins000.exe"
    Google Desktop --> C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
    Google Earth --> MsiExec.exe /I{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}
    HP Update --> MsiExec.exe /X{8C6027FD-53DC-446D-BB75-CACD7028A134}
    HP Wireless Assistant --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4302B2DD-D958-40E3-BAF3-B07FFE1978CE}\setup.exe" -l0x804
    Image Resizer Powertoy for Windows XP --> MsiExec.exe /I{1CB92574-96F2-467B-B793-5CEB35C40C29}
    Intel(R) Graphics Media Accelerator Driver for Mobile --> RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx2ID PCI\VEN_8086&DEV_2792 PCI\VEN_8086&DEV_2592
    InterVideo DVD Check --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5D97A4A7-C274-4B63-86D9-07A33435F505}\setup.exe" REMOVEALL
    InterVideo WinDVD --> "C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe" REMOVEALL
    iTunes --> MsiExec.exe /I{E0219810-16E4-437D-9165-93D7B22524F9}
    Java(TM) SE Runtime Environment 6 Update 1 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
    Microsoft ActiveSync --> MsiExec.exe /I{99052DB7-9592-4522-A558-5417BBAD48EE}
    Microsoft Cubicle Chaos for Pocket PC (Remove Only) --> C:\WINDOWS\uninst.exe -f"E:\Programmes\ActiveSync\Pocket PC Cubicle Chaos\DeIsL1.isu"
    Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
    Mozilla Firefox (2.0.0.5) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
    Mozilla Thunderbird (2.0.0.6) --> C:\Program Files\Mozilla Thunderbird\uninstall\helper.exe
    Nero 6 Ultra Edition --> C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
    Opanda IExif 2.26 --> "C:\Program Files\Opanda\IExif 2.26\unins000.exe"
    Picasa 2 --> "C:\Program Files\Picasa2\Uninstall.exe"
    Powerword 2006 --> MsiExec.exe /I{1D44EA4F-C446-4C4F-92F7-02F72E589989}
    QQ2007 Beta3 --> C:\Program Files\Tencent\QQ\uninst.exe
    QQ游戏 --> C:\Program Files\Tencent\QQGame\\Uninstall.EXE
    Quick Launch Buttons 5.10 B5 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CEB326EC-8F40-47B2-BA22-BB092565D66F}\Setup.exe" -l0x804 -uninst
    QuickTime --> MsiExec.exe /I{95A890AA-B3B1-44B6-9C18-A8F7AB3EE7FC}
    Skype? 3.2 --> MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
    Soft Data Fax Modem with SmartCP --> C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_8086&DEV_266D&SUBSYS_3080103C\HXFSETUP.EXE -U -IQTA3080K.INF
    Sonic Data Module --> MsiExec.exe /I{075473F5-846A-448B-BCB3-104AA1760205}
    SOSO AddressBar Search --> Rundll32.exe C:\WINDOWS\system32\scrax.dll,Uninstall
    Spybot - Search & Destroy 1.4 --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
    Stellar Frontier --> "C:\Program Files\Drengin.net\Stellar Frontier\uninstall.exe" "C:\Program Files\Drengin.net\Stellar Frontier"
    Stellarium 0.9.0 --> "E:\Daniel's Games\Stellarium\unins000.exe"
    Synaptics Pointing Device Driver --> rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
    Tencent Media Player by Viewpoint --> C:\Program Files\Tencent\Viewpoint Media Player\mtsAxInstaller.exe /u
    Texas Instruments PCIxx21/x515 drivers. --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{FF6F491D-BC82-4DCC-A72F-1824957C6466} /l2052
    VideoLAN VLC media player 0.8.6c --> E:\Programmes\VLC\uninstall.exe
    VOS --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{42B19500-EEB2-11D3-874E-00AA0068CDEB}\setup.exe"
    Wallpaper Changer for Windows XP --> C:\WINDOWS\walltoyUninst.exe UNINSTALL
    Warcraft III: All Products --> C:\WINDOWS\War3Unin.exe C:\WINDOWS\War3Unin.dat
    WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe
    一键GHOST v8.3 Build 070101 --> "c:\boot\ghos\uninstall.exe" "/U:c:\boot\ghos\uninstall.xml"


    -- Application Event Log

    Event Record #/Type1396 / Error
    Event Submitted/Written: 08/03/2007 09:09:58 PM
    Event ID/Source: 4126 / Ci
    Event Description:
    Cleaning up corrupt content index metadata on d:\system volume information\catalog.wci. Index will
    be automatically restored by refiltering all documents.

    Event Record #/Type1395 / Error
    Event Submitted/Written: 08/03/2007 09:09:58 PM
    Event ID/Source: 4124 / Ci
    Event Description:
    Content index on d:\system volume information\catalog.wci is corrupt. Please shutdown and restart
    the Indexing Service (cisvc).

    Event Record #/Type1394 / Warning
    Event Submitted/Written: 08/03/2007 09:09:58 PM
    Event ID/Source: 4132 / Ci
    Event Description:
    6 inconsistencies were detected in PropertyStore during recovery of catalog d:\system volume information\catalog.wci.

    Event Record #/Type1384 / Error
    Event Submitted/Written: 08/03/2007 08:59:24 PM
    Event ID/Source: 1000 / Application Error
    Event Description:
    Faulting application vos.exe, version 0.0.0.0, faulting module vos.exe, version 0.0.0.0, fault address 0x00043588.
    Processing media-specific event for [vos.exe!ws!]

    Event Record #/Type1380 / Warning
    Event Submitted/Written: 08/03/2007 08:56:54 PM
    Event ID/Source: 1001 / MsiInstaller
    Event Description:
    Detection of product '{E0219810-16E4-437D-9165-93D7B22524F9}', feature 'iTunes' failed during request for component '{E8A1D3E2-F5D3-4B24-AB93-52F7E602A235}'



    -- Security Event Log

    No Errors/Warnings found.


    -- System Event Log

    Event Record #/Type5740 / Error
    Event Submitted/Written: 08/24/2007 05:31:15 PM
    Event ID/Source: 29 / W32Time
    Event Description:
    The time provider NtpClient is configured to acquire time from one or more
    time sources, however none of the sources are currently accessible.
    No attempt to contact a source will be made for 14 minutes.
    NtpClient has no source of accurate time.

    Event Record #/Type5739 / Error
    Event Submitted/Written: 08/24/2007 05:31:15 PM
    Event ID/Source: 17 / W32Time
    Event Description:
    Time Provider NtpClient: An error occurred during DNS lookup of the manually
    configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15
    minutes.
    The error was: A socket operation was attempted to an unreachable host. (0x80072751)

    Event Record #/Type5736 / Warning
    Event Submitted/Written: 08/24/2007 00:37:41 PM
    Event ID/Source: 20 / Print
    Event Description:
    Printer Driver EPSON Stylus Photo R300 Series for Windows NT x86 Version-3 was added or updated. Files:- E_DMAI16.DLL, E_DU18KE.DLL, E_DM18FA.VIF, E_QI021E.HLP, E_DDSP13.DLL, E_DJB307.DLL, E_DCON02.DLL, EE254__1.PRM, EPIBSR30.EXE, E_DI08FA.DLL, E_DD18FA.CFG, EPIPGI20.DLL, E_DPUI03.DLL, E_DPPE03.EXE, E_DI13AE.TXT, EPSET32.DLL, E_DHMM12.DLL, E_DUMWF2.DLL, E_DHT41D.DLL, E_DS80HE.DLL, E_H4X2F1.DXT, E_H490F2.DLL, EPUTIX25.DLL, EPUTIX25.EXE, E_H4E0F2.DLL, EBAPI4.DLL, EBPLPT4.DLL, E_DM18FA.DAT, EBPSHRE4.DLL, SAGENT4.EXE, EBPSAGT4.DAT, EPUPDATE.EXE, EPUPDATE.DAT, E_S10RN1.EXE, E_SKN321.DLL, E_S10MT1.EXE, E_S1T0A1.EXE, E_SMSTE3.HLP, E_H26UIA.DLL, E_S490F1.DLL, E_S4I2F1.EXE, E_S4E2F1.DLL, E_SIINS1.EXE, E_A4X2F1.DAT, E_S00RP1.EXE.

    Event Record #/Type5735 / Error
    Event Submitted/Written: 08/24/2007 00:23:01 PM
    Event ID/Source: 59 / SideBySide
    Event Description:
    Generate Activation Context failed for C:\Program Files\Apple Software Update\Plugins\MSIInstallPlugin.dll.Manifest.
    Reference error message: The operation completed successfully.
    .

    Event Record #/Type5734 / Error
    Event Submitted/Written: 08/24/2007 00:23:01 PM
    Event ID/Source: 58 / SideBySide
    Event Description:
    Syntax error in manifest or policy file "The manifest file contains one or more syntax errors.
    1" on line The manifest file contains one or more syntax errors.
    2.



    -- End of Deckard's System Scanner: finished at 2007-08-24 18:17:04


  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    Was expecting to see some restriction there....Not sure how to help you, sorry.

    Do this anyway since you got some malware, go to Start > Control Panel > Add or Remove Programs > Remove Tencent


  • Registered Users, Registered Users 2 Posts: 7,110 ✭✭✭Thirdfox


    Oh Tencent is a very famous IM service... millions of people use it in China (basically it's almost used like a mobile phone number). I know it contains some spyware but it's the only way of keeping in contact with my Chinese friends...

    Are there any other obvious problems in my computer?

    Thanks for the help so far!


  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    Ah ok I didn't know what it was really, only that it contains malware. Your DSS log would show if it was a malware problem. Lets try this if you want, will help us rule out for sure whether it is malware related.


    Download GMER from here:
    http://www.gmer.net/gmer.zip

    Unzip it to the desktop.

    Open the program and click on the Rootkit tab.
    Make sure all the boxes on the right of the screen are checked, EXCEPT for ‘Show All’.
    Click on Scan.
    When the scan has run click Copy and paste the results (if any) into this thread.



    Please do an online scan with Kaspersky WebScanner

    Click on Kaspersky Online Scanner

    You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
    • The program will launch and then begin downloading the latest definition files:
    • Once the files have been downloaded click on NEXT
    • Now click on Scan Settings
    • In the scan settings make that the following are selected:
      • Scan using the following Anti-Virus database:
        Extended (if available otherwise Standard)
      • Scan Options:
        Scan Archives
        Scan Mail Bases


        [*]Click OK
        [*]Now under select a target to scan:
          Select
        My Computer

        [*]This will program will start and scan your system.
        [*]The scan will take a while so be patient and let it run.
        [*]Once the scan is complete it will display if your system has been infected.
        • Now click on the Save as Text button:
        [*]Save the file to your desktop.
        [*]Copy and paste that information in your next post.


      • Advertisement
      • Registered Users, Registered Users 2 Posts: 7,110 ✭✭✭Thirdfox


        Here's the results from GMER:


        GMER 1.0.13.12551 - http://www.gmer.net
        Rootkit scan 2007-08-25 09:35:45
        Windows 5.1.2600 Service Pack 2


        ---- System - GMER 1.0.13 ----

        SSDT sptd.sys ZwCreateKey
        SSDT sptd.sys ZwEnumerateKey
        SSDT sptd.sys ZwEnumerateValueKey
        SSDT sptd.sys ZwOpenKey
        SSDT sptd.sys ZwQueryKey
        SSDT sptd.sys ZwQueryValueKey
        SSDT sptd.sys ZwSetValueKey

        ---- Kernel code sections - GMER 1.0.13 ----

        ? C:\WINDOWS\system32\drivers\sptd.sys The process cannot access the file because it is being used by another process.
        .text USBPORT.SYS!DllUnload F6FD262C 5 Bytes JMP 8609B770
        .text apoqzbin.SYS AAC4C384 1 Byte [ 20 ]
        .text apoqzbin.SYS AAC4C386 35 Bytes [ 00, 68, 00, 00, 00, 00, 00, ... ]
        .text apoqzbin.SYS AAC4C3AA 24 Bytes [ 00, 00, 20, 00, 00, E0, 00, ... ]
        .text apoqzbin.SYS AAC4C3C4 3 Bytes [ 00, 00, 00 ]
        .text apoqzbin.SYS AAC4C3C9 1 Byte [ 00 ]
        .text ...

        ---- Kernel IAT/EAT - GMER 1.0.13 ----

        IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F73D2AD4] sptd.sys
        IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F73D2C1A] sptd.sys
        IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F73D2B9C] sptd.sys
        IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F73D3748] sptd.sys
        IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F73D361E] sptd.sys
        IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F73E829A] sptd.sys
        IAT \SystemRoot\System32\Drivers\apoqzbin.SYS[HAL.dll!KfAcquireSpinLock] 6C000000
        IAT \SystemRoot\System32\Drivers\apoqzbin.SYS[HAL.dll!READ_PORT_UCHAR] 56000000
        IAT \SystemRoot\System32\Drivers\apoqzbin.SYS[HAL.dll!KeGetCurrentIrql] F4000000
        IAT \SystemRoot\System32\Drivers\apoqzbin.SYS[HAL.dll!KfRaiseIrql] EA000000
        IAT \SystemRoot\System32\Drivers\apoqzbin.SYS[HAL.dll!KfLowerIrql] 65000000
        IAT \SystemRoot\System32\Drivers\apoqzbin.SYS[HAL.dll!HalGetInterruptVector] 7A000000
        IAT \SystemRoot\System32\Drivers\apoqzbin.SYS[HAL.dll!HalTranslateBusAddress] AE000000
        IAT \SystemRoot\System32\Drivers\apoqzbin.SYS[HAL.dll!KeStallExecutionProcessor] 08000000
        IAT \SystemRoot\System32\Drivers\apoqzbin.SYS[HAL.dll!KfReleaseSpinLock] BA000000
        IAT \SystemRoot\System32\Drivers\apoqzbin.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 78000000
        IAT \SystemRoot\System32\Drivers\apoqzbin.SYS[HAL.dll!READ_PORT_USHORT] 25000000
        IAT \SystemRoot\System32\Drivers\apoqzbin.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 2E000000
        IAT \SystemRoot\System32\Drivers\apoqzbin.SYS[HAL.dll!WRITE_PORT_UCHAR] 1C000000
        IAT \SystemRoot\System32\Drivers\apoqzbin.SYS[WMILIB.SYS!WmiSystemControl] B4000000
        IAT \SystemRoot\System32\Drivers\apoqzbin.SYS[WMILIB.SYS!WmiCompleteRequest] C6000000

        ---- User IAT/EAT - GMER 1.0.13 ----

        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [005D41B7] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [005D4150] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [005D41DE] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [005D4170] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateFileW] [005D4378] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [005D41B7] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [005D4150] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [005D41DE] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [005D4170] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!CreateFileW] [005D4378] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [005D41B7] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!CreateFileA] [005D425C] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!OpenFile] [005D44D5] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [005D4170] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!CreateFileW] [005D4378] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [005D4150] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [005D41DE] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateFileW] [005D4378] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [005D4150] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [005D4170] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [005D41DE] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [005D4150] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [005D4170] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [005D41DE] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateFileW] [005D4378] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [005D41B7] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [005D4190] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileA] [005D425C] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileW] [005D4378] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [005D4190] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [005D41B7] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [005D4170] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [005D4150] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [005D41DE] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [005D41DE] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [005D4150] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [005D4170] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [005D41B7] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [005D4190] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateFileW] [005D4378] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [005D41DE] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [005D4150] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [005D4150] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] [005D41DE] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExA] [005D4190] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] [005D4170] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [005D41DE] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [005D4150] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!CreateFileA] [005D425C] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [005D41DE] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [005D4150] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!CreateFileA] [005D425C] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!CreateFileW] [005D4378] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExA] [005D4190] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] [005D41B7] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!CreateFileW] [005D4378] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!CreateFileA] [005D425C] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!GetProcAddress] [005D41DE] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!LoadLibraryA] [005D4150] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [005D4170] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [005D4150] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] [005D41DE] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!CreateFileW] [005D4378] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [005D4150] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!CreateFileW] [005D4378] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [005D4170] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [005D41DE] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [005D4170] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateFileW] [005D4378] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [005D4190] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [005D41DE] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Tencent\QQ\QQ.exe[2948] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [005D4150] C:\Program Files\Tencent\QQ\QQHelperDll.dll
        IAT C:\Program Files\Mozilla Thunderbird\thunderbird.exe[3088] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [01C473CC] C:\Program Files\Mozilla Thunderbird\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
        IAT C:\Program Files\Mozilla Thunderbird\thunderbird.exe[3088] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [01C47376] C:\Program Files\Mozilla Thunderbird\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
        IAT C:\Program Files\Mozilla Thunderbird\thunderbird.exe[3088] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [01C47376] C:\Program Files\Mozilla Thunderbird\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
        IAT C:\Program Files\Mozilla Thunderbird\thunderbird.exe[3088] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [01C473CC] C:\Program Files\Mozilla Thunderbird\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
        IAT C:\Program Files\Mozilla Thunderbird\thunderbird.exe[3088] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [01C47376] C:\Program Files\Mozilla Thunderbird\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
        IAT C:\Program Files\Mozilla Thunderbird\thunderbird.exe[3088] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [01C473CC] C:\Program Files\Mozilla Thunderbird\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
        IAT C:\Program Files\Mozilla Thunderbird\thunderbird.exe[3088] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [01C473CC] C:\Program Files\Mozilla Thunderbird\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
        IAT C:\Program Files\Mozilla Thunderbird\thunderbird.exe[3088] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [01C47376] C:\Program Files\Mozilla Thunderbird\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
        IAT C:\Program Files\Mozilla Thunderbird\thunderbird.exe[3088] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [01C47376] C:\Program Files\Mozilla Thunderbird\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
        IAT C:\Program Files\Mozilla Thunderbird\thunderbird.exe[3088] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [01C473CC] C:\Program Files\Mozilla Thunderbird\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
        IAT C:\Program Files\Mozilla Thunderbird\thunderbird.exe[3088] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [01C473CC] C:\Program Files\Mozilla Thunderbird\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
        IAT C:\Program Files\Mozilla Thunderbird\thunderbird.exe[3088] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [01C47376] C:\Program Files\Mozilla Thunderbird\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
        IAT C:\Program Files\Mozilla Thunderbird\thunderbird.exe[3088] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [01C473CC] C:\Program Files\Mozilla Thunderbird\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
        IAT C:\Program Files\Mozilla Thunderbird\thunderbird.exe[3088] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [01C47376] C:\Program Files\Mozilla Thunderbird\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
        IAT C:\Program Files\Mozilla Thunderbird\thunderbird.exe[3088] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [01C473CC] C:\Program Files\Mozilla Thunderbird\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
        IAT C:\Program Files\Mozilla Thunderbird\thunderbird.exe[3088] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [01C47376] C:\Program Files\Mozilla Thunderbird\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
        IAT C:\Program Files\Mozilla Thunderbird\thunderbird.exe[3088] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [01C47376] C:\Program Files\Mozilla Thunderbird\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
        IAT C:\Program Files\Mozilla Thunderbird\thunderbird.exe[3088] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [01C473CC] C:\Program Files\Mozilla Thunderbird\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
        IAT C:\Program Files\Mozilla Thunderbird\thunderbird.exe[3088] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [01C473CC] C:\Program Files\Mozilla Thunderbird\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
        IAT C:\Program Files\Mozilla Thunderbird\thunderbird.exe[3088] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [01C47376] C:\Program Files\Mozilla Thunderbird\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
        IAT C:\Program Files\Mozilla Thunderbird\thunderbird.exe[3088] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [01C473CC] C:\Program Files\Mozilla Thunderbird\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
        IAT C:\Program Files\Mozilla Thunderbird\thunderbird.exe[3088] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!LoadLibraryA] [01C47376] C:\Program Files\Mozilla Thunderbird\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
        IAT C:\Program Files\Mozilla Thunderbird\thunderbird.exe[3088] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [01C473CC] C:\Program Files\Mozilla Thunderbird\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
        IAT C:\Program Files\Mozilla Thunderbird\thunderbird.exe[3088] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [01C47376] C:\Program Files\Mozilla Thunderbird\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
        IAT C:\Program Files\Mozilla Thunderbird\thunderbird.exe[3088] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [01C47376] C:\Program Files\Mozilla Thunderbird\extensions\talkback@mozilla.org\components\FULLSOFT.DLL
        IAT C:\Program Files\Mozilla Thunderbird\thunderbird.exe[3088] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [01C473CC] C:\Program Files\Mozilla Thunderbird\extensions\talkback@mozilla.org\components\FULLSOFT.DLL

        Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 86223790
        Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE 86223790
        Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 86223790
        Device \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE 86223790
        Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION 86223790
        Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION 86223790
        Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA 86223790
        Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA 86223790
        Device \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS 86223790
        Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION 86223790
        Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION 86223790
        Device \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL 86223790
        Device \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL 86223790
        Device \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL 86223790
        Device \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN 86223790
        Device \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL 86223790
        Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP 86223790
        Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY 86223790
        Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY 86223790
        Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA 86223790
        Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA 86223790
        Device \FileSystem\Ntfs \Ntfs IRP_MJ_PNP 86223790

        AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE [F72EFF70] fltMgr.sys
        AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_NAMED_PIPE [F72EFF70] fltMgr.sys
        AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE [F72E3F08] fltMgr.sys
        AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_READ [F72E3F08] fltMgr.sys
        AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE [F72E3F08] fltMgr.sys
        AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION [F72E3F08] fltMgr.sys
        AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION [F72E3F08] fltMgr.sys
        AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA [F72E3F08] fltMgr.sys
        AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA [F72E3F08] fltMgr.sys
        AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS [F72E3F08] fltMgr.sys
        AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION [F72E3F08] fltMgr.sys
        AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION [F72E3F08] fltMgr.sys
        AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL [F72E3F08] fltMgr.sys
        AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL [F72F0160] fltMgr.sys
        AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL [F72E3F08] fltMgr.sys
        AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_INTERNAL_DEVICE_CONTROL [F72E3F08] fltMgr.sys
        AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN [F72E3F08] fltMgr.sys
        AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL [F72E3F08] fltMgr.sys
        AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP [F72E3F08] fltMgr.sys
        AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_MAILSLOT [F72EFF70] fltMgr.sys
        AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY [F72E3F08] fltMgr.sys
        AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY [F72E3F08] fltMgr.sys
        AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_POWER [F72E3F08] fltMgr.sys
        AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SYSTEM_CONTROL [F72E3F08] fltMgr.sys
        AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CHANGE [F72E3F08] fltMgr.sys
        AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA [F72E3F08] fltMgr.sys
        AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA [F72E3F08] fltMgr.sys

        Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CREATE 8656E1E8
        Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLOSE 8656E1E8
        Device \FileSystem\Fastfat \FatCdrom IRP_MJ_READ 8656E1E8
        Device \FileSystem\Fastfat \FatCdrom IRP_MJ_WRITE 8656E1E8
        Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_INFORMATION 8656E1E8
        Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_INFORMATION 8656E1E8
        Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_EA 8656E1E8
        Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_EA 8656E1E8
        Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FLUSH_BUFFERS 8656E1E8
        Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_VOLUME_INFORMATION 8656E1E8
        Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_VOLUME_INFORMATION 8656E1E8
        Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DIRECTORY_CONTROL 8656E1E8
        Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FILE_SYSTEM_CONTROL 8656E1E8
        Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DEVICE_CONTROL 8656E1E8
        Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SHUTDOWN 8656E1E8
        Device \FileSystem\Fastfat \FatCdrom IRP_MJ_LOCK_CONTROL 8656E1E8
        Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLEANUP 8656E1E8
        Device \FileSystem\Fastfat \FatCdrom IRP_MJ_PNP 8656E1E8

        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_CREATE [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_CREATE_NAMED_PIPE [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_CLOSE [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_READ [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_WRITE [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_QUERY_INFORMATION [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_SET_INFORMATION [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_QUERY_EA [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_SET_EA [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_FLUSH_BUFFERS [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_QUERY_VOLUME_INFORMATION [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_SET_VOLUME_INFORMATION [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_DIRECTORY_CONTROL [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_FILE_SYSTEM_CONTROL [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_DEVICE_CONTROL [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_INTERNAL_DEVICE_CONTROL [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_SHUTDOWN [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_LOCK_CONTROL [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_CLEANUP [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_CREATE_MAILSLOT [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_QUERY_SECURITY [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_SET_SECURITY [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_POWER [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_SYSTEM_CONTROL [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_DEVICE_CHANGE [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_QUERY_QUOTA [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_SET_QUOTA [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_CREATE [F7AD4416] EABFiltr.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_CLOSE [F7AD4416] EABFiltr.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_READ [F7AD49B8] EABFiltr.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_DEVICE_CONTROL [F7AD4A16] EABFiltr.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_POWER [F7AD4B8A] EABFiltr.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 IRP_MJ_SYSTEM_CONTROL [F7AD4CBC] EABFiltr.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_CREATE [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_CREATE_NAMED_PIPE [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_CLOSE [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_READ [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_WRITE [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_QUERY_INFORMATION [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_SET_INFORMATION [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_QUERY_EA [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_SET_EA [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_FLUSH_BUFFERS [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_QUERY_VOLUME_INFORMATION [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_SET_VOLUME_INFORMATION [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_DIRECTORY_CONTROL [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_FILE_SYSTEM_CONTROL [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_DEVICE_CONTROL [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_INTERNAL_DEVICE_CONTROL [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_SHUTDOWN [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_LOCK_CONTROL [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_CLEANUP [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_CREATE_MAILSLOT [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_QUERY_SECURITY [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_SET_SECURITY [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_POWER [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_SYSTEM_CONTROL [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_DEVICE_CHANGE [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_QUERY_QUOTA [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_SET_QUOTA [F6AC4B10] SynTP.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_CREATE [F7AD4416] EABFiltr.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_CLOSE [F7AD4416] EABFiltr.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_READ [F7AD49B8] EABFiltr.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_DEVICE_CONTROL [F7AD4A16] EABFiltr.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_POWER [F7AD4B8A] EABFiltr.sys
        AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 IRP_MJ_SYSTEM_CONTROL [F7AD4CBC] EABFiltr.sys

        Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_CREATE 8609A1E8
        Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_CLOSE 8609A1E8
        Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_DEVICE_CONTROL 8609A1E8
        Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8609A1E8
        Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_POWER 8609A1E8
        Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_SYSTEM_CONTROL 8609A1E8
        Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_PNP 8609A1E8
        Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CREATE 865711E8
        Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CLOSE 865711E8
        Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_READ 865711E8
        Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_WRITE 865711E8
        Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_FLUSH_BUFFERS 865711E8
        Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_DEVICE_CONTROL 865711E8
        Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_INTERNAL_DEVICE_CONTROL 865711E8
        Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SHUTDOWN 865711E8
        Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_POWER 865711E8
        Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SYSTEM_CONTROL 865711E8
        Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_PNP 865711E8
        Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CREATE 865711E8
        Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CLOSE 865711E8
        Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_READ 865711E8
        Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_WRITE 865711E8
        Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_FLUSH_BUFFERS 865711E8
        Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_DEVICE_CONTROL 865711E8
        Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_INTERNAL_DEVICE_CONTROL 865711E8
        Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SHUTDOWN 865711E8
        Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_POWER 865711E8
        Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SYSTEM_CONTROL 865711E8
        Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_PNP 865711E8
        Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CREATE 865711E8
        Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CLOSE 865711E8
        Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_READ 865711E8
        Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_WRITE 865711E8
        Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_FLUSH_BUFFERS 865711E8
        Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_DEVICE_CONTROL 865711E8
        Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_INTERNAL_DEVICE_CONTROL 865711E8
        Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SHUTDOWN 865711E8
        Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_POWER 865711E8
        Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SYSTEM_CONTROL 865711E8
        Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_PNP 865711E8
        Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CREATE 865711E8
        Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CLOSE 865711E8
        Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_READ 865711E8
        Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_WRITE 865711E8
        Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_FLUSH_BUFFERS 865711E8
        Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_DEVICE_CONTROL 865711E8
        Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_INTERNAL_DEVICE_CONTROL 865711E8
        Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SHUTDOWN 865711E8
        Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_POWER 865711E8
        Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SYSTEM_CONTROL 865711E8
        Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_PNP 865711E8
        Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_CREATE 8609A1E8
        Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_CLOSE 8609A1E8
        Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_DEVICE_CONTROL 8609A1E8
        Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8609A1E8
        Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_POWER 8609A1E8
        Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_SYSTEM_CONTROL 8609A1E8
        Device \Driver\usbuhci \Device\USBPDO-1 IRP_MJ_PNP 8609A1E8
        Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_CREATE 8609A1E8
        Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_CLOSE 8609A1E8
        Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_DEVICE_CONTROL 8609A1E8
        Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_INTERNAL_DEVICE_CONTROL 8609A1E8
        Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_POWER 8609A1E8
        Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_SYSTEM_CONTROL 8609A1E8
        Device \Driver\usbuhci \Device\USBPDO-2 IRP_MJ_PNP 8609A1E8
        Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_CREATE 8609A1E8
        Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_CLOSE 8609A1E8
        Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_DEVICE_CONTROL 8609A1E8
        Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 8609A1E8
        Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_POWER 8609A1E8
        Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_SYSTEM_CONTROL 8609A1E8
        Device \Driver\usbuhci \Device\USBPDO-3 IRP_MJ_PNP 8609A1E8
        Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_CREATE 860991E8
        Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_CLOSE 860991E8
        Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_DEVICE_CONTROL 860991E8
        Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_INTERNAL_DEVICE_CONTROL 860991E8
        Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_POWER 860991E8
        Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_SYSTEM_CONTROL 860991E8
        Device \Driver\usbehci \Device\USBPDO-4 IRP_MJ_PNP 860991E8
        Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE 865721E8
        Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_READ 865721E8
        Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_WRITE 865721E8
        Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_FLUSH_BUFFERS 865721E8
        Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DEVICE_CONTROL 865721E8
        Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_INTERNAL_DEVICE_CONTROL 865721E8
        Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SHUTDOWN 865721E8
        Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CLEANUP 865721E8
        Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_POWER 865721E8
        Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_


      Advertisement