Mitch Flander
Posts: 23 +0
I have the new posts. Can you tell me if we're addressing the IDP. Trojan? If so, did you get a chance to look at the procedure I had a question about a few posts back where I dropped in the security check log?
Here is the GMER log and Listparts log:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-08-20 09:39:57
Windows 6.1.7600 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 rev.
Running: 7ex48rit.exe; Driver: C:\Users\Mitch\AppData\Local\Temp\kgloypog.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwNotifyChangeKey [0x9787A004]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwNotifyChangeMultipleKeys [0x9787A0D4]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0x97879D76]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateProcess [0x97879E1E]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0x97879EBA]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0x97879F56]
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKeyEx + 13BD 82E47589 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82E6C092 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!RtlSidHashLookup + 4A0 82E73AB0 8 Bytes [04, A0, 87, 97, D4, A0, 87, ...] {ADD AL, 0xa0; XCHG [EDI-0x68785f2c], EDX}
.text ntkrnlpa.exe!RtlSidHashLookup + 4E8 82E73AF8 4 Bytes [76, 9D, 87, 97]
.text ntkrnlpa.exe!RtlSidHashLookup + 7B8 82E73DC8 8 Bytes [1E, 9E, 87, 97, BA, 9E, 87, ...] {PUSH DS; SAHF ; XCHG [EDI-0x68786146], EDX}
.text ntkrnlpa.exe!RtlSidHashLookup + 82C 82E73E3C 4 Bytes [56, 9F, 87, 97]
---- User code sections - GMER 1.0.15 ----
? C:\Program Files\AVG\AVG2012\avgwdsvc.exe[384] C:\Windows\system32\IPHLPAPI.DLL time/date stamp mismatch; unknown module: dhcpcsvc.DLLunknown module: dhcpcsvc6.DLLunknown module: DNSAPI.dllunknown module: WINNSI.DLLunknown module: NSI.dll
? C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe[512] C:\Windows\system32\IPHLPAPI.DLL time/date stamp mismatch; unknown module: dhcpcsvc.DLLunknown module: dhcpcsvc6.DLLunknown module: DNSAPI.dllunknown module: WINNSI.DLLunknown module: NSI.dll
? C:\Windows\system32\lsass.exe[820] C:\Windows\system32\IPHLPAPI.DLL time/date stamp mismatch; unknown module: dhcpcsvc.DLLunknown module: dhcpcsvc6.DLLunknown module: DNSAPI.dllunknown module: WINNSI.DLLunknown module: NSI.dll
? C:\Windows\System32\svchost.exe[1096] c:\windows\system32\IPHLPAPI.DLL time/date stamp mismatch; unknown module: dhcpcsvc.DLLunknown module: dhcpcsvc6.DLLunknown module: DNSAPI.dllunknown module: WINNSI.DLLunknown module: NSI.dll
? C:\Windows\System32\svchost.exe[1128] c:\windows\system32\IPHLPAPI.DLL time/date stamp mismatch; unknown module: dhcpcsvc.DLLunknown module: dhcpcsvc6.DLLunknown module: DNSAPI.dllunknown module: WINNSI.DLLunknown module: NSI.dll
? C:\Windows\system32\svchost.exe[1172] c:\windows\system32\IPHLPAPI.DLL time/date stamp mismatch; unknown module: dhcpcsvc.DLLunknown module: dhcpcsvc6.DLLunknown module: DNSAPI.dllunknown module: WINNSI.DLLunknown module: NSI.dll
? C:\Windows\system32\svchost.exe[1276] c:\windows\system32\IPHLPAPI.DLL time/date stamp mismatch; unknown module: dhcpcsvc.DLLunknown module: dhcpcsvc6.DLLunknown module: DNSAPI.dllunknown module: WINNSI.DLLunknown module: NSI.dll
? C:\Windows\system32\svchost.exe[1448] C:\Windows\system32\iphlpapi.dll time/date stamp mismatch; unknown module: dhcpcsvc.DLLunknown module: dhcpcsvc6.DLLunknown module: DNSAPI.dllunknown module: WINNSI.DLLunknown module: NSI.dll
? C:\Windows\system32\winlogon.exe[1480] C:\Windows\system32\ADVAPI32.dll time/date stamp mismatch; unknown module: CRYPTSP.dllunknown module: WINTRUST.dllunknown module: SspiCli.dllunknown module: bcrypt.dllunknown module: pcwum.dllunknown module: KERNELBASE.dll
? C:\Windows\system32\winlogon.exe[1480] C:\Windows\system32\userenv.dll time/date stamp mismatch; unknown module: DNSAPI.dllunknown module: logoncli.dllunknown module: netutils.dllunknown module: SspiCli.dllunknown module: GPAPI.dllunknown module: GPSVC.dllunknown module: profapi.dllunknown module: KERNELBASE.dll
? C:\Windows\System32\spoolsv.exe[1892] C:\Windows\System32\IPHLPAPI.DLL time/date stamp mismatch; unknown module: dhcpcsvc.DLLunknown module: dhcpcsvc6.DLLunknown module: DNSAPI.dllunknown module: WINNSI.DLLunknown module: NSI.dll
? C:\Windows\system32\svchost.exe[1928] C:\Windows\system32\IPHLPAPI.DLL time/date stamp mismatch; unknown module: dhcpcsvc.DLLunknown module: dhcpcsvc6.DLLunknown module: DNSAPI.dllunknown module: WINNSI.DLLunknown module: NSI.dll
? C:\Windows\System32\svchost.exe[1952] C:\Windows\System32\IPHLPAPI.DLL time/date stamp mismatch; unknown module: dhcpcsvc.DLLunknown module: dhcpcsvc6.DLLunknown module: DNSAPI.dllunknown module: WINNSI.DLLunknown module: NSI.dll
? C:\Windows\Explorer.EXE[3464] C:\Windows\System32\IPHLPAPI.DLL time/date stamp mismatch; unknown module: dhcpcsvc.DLLunknown module: dhcpcsvc6.DLLunknown module: DNSAPI.dllunknown module: WINNSI.DLLunknown module: NSI.dll
? C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe[3732] C:\Windows\system32\iphlpapi.DLL time/date stamp mismatch; unknown module: dhcpcsvc.DLLunknown module: dhcpcsvc6.DLLunknown module: DNSAPI.dllunknown module: WINNSI.DLLunknown module: NSI.dll
? C:\Program Files\Google\Chrome\Application\chrome.exe[3888] C:\Windows\system32\IPHLPAPI.DLL time/date stamp mismatch; unknown module: dhcpcsvc.DLLunknown module: dhcpcsvc6.DLLunknown module: DNSAPI.dllunknown module: WINNSI.DLLunknown module: NSI.dll
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\system32\winlogon.exe[1480] @ C:\Windows\system32\winlogon.exe [KERNEL32.dll!LoadLibraryExA] [738C9B20] C:\Program Files\NetMotion Client\nmlogon.dll (NetMotion Logon DLL/NetMotion Wireless, Inc.)
IAT C:\Windows\system32\winlogon.exe[1480] @ C:\Windows\system32\winlogon.exe [KERNEL32.dll!LoadLibraryW] [738C9A80] C:\Program Files\NetMotion Client\nmlogon.dll (NetMotion Logon DLL/NetMotion Wireless, Inc.)
IAT C:\Windows\system32\winlogon.exe[1480] @ C:\Windows\system32\winlogon.exe [KERNEL32.dll!GetProcAddress] [738C9800] C:\Program Files\NetMotion Client\nmlogon.dll (NetMotion Logon DLL/NetMotion Wireless, Inc.)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Tcp nmdrv.sys
Device \Driver\ACPI_HAL \Device\00000057 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Udp nmdrv.sys
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp nmdrv.sys
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat avgidsfilterx.sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0007615150eb
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0007615150eb (not active ControlSet)
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sector 00: rootkit-like behavior
---- Files - GMER 1.0.15 ----
File C:\Users\Mitch\Documents\personal\Locked 0 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct 0 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\lowes login.txt 30 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\amazon log in.txt 77 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\att and uverse login.txt 109 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\avg license.txt 53 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\blackberry forums.txt 35 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\blue cross blue shield log in.txt 47 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\cigna dental log in.txt 40 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\citimortgage login.txt 53 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\COA benefits login.txt 49 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\directv login.txt 49 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\MXenergy.txt 33 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\online payment confirmation 0 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\online payment confirmation\simmons 6_11 online payment conf.txt 160 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\paypal login.txt 76 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\peachcare login.txt 88 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\retirement acct logins.txt 649 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\scottrade login.txt 67 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\simmons first login.txt 95 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\state farm.txt 38 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\target log in.txt 387 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\taxact login 09.txt 50 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\trev gosolar.txt 60 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\world golf tour.txt 38 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\ebay log in.txt 33 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\FIA log in.txt 470 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\flightsim.com log in.txt 14 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\ga fed credit union.txt 44 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\ga fed quickpay xfer.txt 56 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\ge moneybank login.txt 36 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\gwinnett county water resources.txt 57 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\home depot log-in.txt 39 bytes
File C:\Users\Mitch\Documents\personal\Locked\misc 0 bytes
File C:\Users\Mitch\Documents\personal\Locked\misc\Jermaine logs cont.pdf 611856 bytes
File C:\Users\Mitch\Documents\personal\Locked\misc\Jermaine logs.docx 10796 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs 0 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2008 0 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2008\2008_Federal_Return Mitch.pdf 49865 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2008\2008_Federal_Return Terri.pdf 44376 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2008\2008_Georgia_Return Mitch.pdf 26591 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2008\2008_Georgia_Return Terri.pdf 26141 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2009 0 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2009\1099-R.pdf 165410 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2009\2009_Federal_Return.pdf 71442 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2009\2009_Georgia_Return.pdf 22145 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2010 0 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2010\2010_Federal_Form_W4_suggested.pdf 26651 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2010\2010_Federal_Return.pdf 47484 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2010\2010_Georgia_Return.pdf 19236 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2010 fed withholding suggestions.txt 617 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2011 0 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2011\2011_Federal_Form_1040.pdf 23232 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2011\2011_Federal_Form_4952.pdf 7639 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2011\2011_Federal_Schedule_A.pdf 10284 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2011\2011_Federal_Schedule_B.pdf 9366 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2011\2011_Federal_Schedule_D.pdf 17965 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2011\2011_Georgia_Return.pdf 20605 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2011\taxes fed state 04.pdf 46312 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\chris_april_ssn.txt 58 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\Federal and State Electronic Filing Instructions.doc 25600 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\suggested 2012 W4.pdf 123284 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\taxes fed 03.T03 48576 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\taxes fed state 04.pdf 387173 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\taxes fed state 05.PDF 359794 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\taxes fed state 06.pdf 309176 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\taxes fed state 07.pdf 295549 bytes
---- EOF - GMER 1.0.15 ----
*****************************************************************************************************************************************
ListParts by Farbar Version: 10-08-2012
Ran by Mitch (administrator) on 20-08-2012 at 09:41:00
Windows 7 (X86)
Running From: C:\Users\SG3 13\Desktop
Language: 0409
************************************************************
========================= Memory info ======================
Percentage of memory in use: 39%
Total physical RAM: 3571.9 MB
Available physical RAM: 2162.87 MB
Total Pagefile: 7142.08 MB
Available Pagefile: 5792.97 MB
Total Virtual: 2047.88 MB
Available Virtual: 1956.38 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:222.63 GB) (Free:102.18 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (RECOVERY) (Fixed) (Total:10 GB) (Free:3.37 GB) NTFS
3 Drive e: (COD2CD1) (CDROM) (Total:0.45 GB) (Free:0 GB) CDFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 232 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 258 MB 31 KB
Partition 2 Primary 10 GB 259 MB
Partition 3 Primary 222 GB 10 GB
======================================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
There is no volume associated with this partition.
======================================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 D RECOVERY NTFS Partition 10 GB Healthy
======================================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 222 GB Healthy System (partition with boot components)
======================================================================================================
Windows Boot Manager
--------------------
identifier {9dea862c-5cdd-4e70-acc1-f32b344d4795}
device partition=C:
description Windows Boot Manager
locale en-US
inherit {7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}
default {1311a3a9-3644-11df-a071-b1f2960e9c50}
resumeobject {1311a3a8-3644-11df-a071-b1f2960e9c50}
displayorder {1311a3a9-3644-11df-a071-b1f2960e9c50}
toolsdisplayorder {b2721d73-1db4-4c62-bf78-c548a880142d}
timeout 30
Windows Boot Loader
-------------------
identifier {1311a3a9-3644-11df-a071-b1f2960e9c50}
device partition=C:
path \Windows\system32\winload.exe
description Windows 7
locale en-US
inherit {6efb52bf-1766-41db-a6b3-0ee5eff72bd7}
recoverysequence {1311a3aa-3644-11df-a071-b1f2960e9c50}
recoveryenabled Yes
osdevice partition=C:
systemroot \Windows
resumeobject {1311a3a8-3644-11df-a071-b1f2960e9c50}
nx OptIn
Windows Boot Loader
-------------------
identifier {1311a3aa-3644-11df-a071-b1f2960e9c50}
device ramdisk=[C:]\Recovery\1311a3aa-3644-11df-a071-b1f2960e9c50\Winre.wim,{1311a3ab-3644-11df-a071-b1f2960e9c50}
path \windows\system32\winload.exe
description Windows Recovery Environment
inherit {6efb52bf-1766-41db-a6b3-0ee5eff72bd7}
osdevice ramdisk=[C:]\Recovery\1311a3aa-3644-11df-a071-b1f2960e9c50\Winre.wim,{1311a3ab-3644-11df-a071-b1f2960e9c50}
systemroot \windows
nx OptIn
winpe Yes
custom:46000010 Yes
Windows Boot Loader
-------------------
identifier {572bcd55-ffa7-11d9-aae0-0007e994107d}
device partition=D:
path \Windows\System32\boot\winload.exe
description Windows Recovery Environment
osdevice partition=D:
systemroot \Windows
nx OptIn
detecthal Yes
winpe Yes
Resume from Hibernate
---------------------
identifier {1311a3a8-3644-11df-a071-b1f2960e9c50}
device partition=C:
path \Windows\system32\winresume.exe
description Windows Resume Application
locale en-US
inherit {1afa9c49-16ab-4a5c-901b-212802da9460}
filedevice partition=C:
filepath \hiberfil.sys
pae Yes
debugoptionenabled No
Windows Memory Tester
---------------------
identifier {b2721d73-1db4-4c62-bf78-c548a880142d}
device partition=C:
path \boot\memtest.exe
description Windows Memory Diagnostic
locale en-US
inherit {7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}
badmemoryaccess Yes
Windows Legacy OS Loader
------------------------
identifier {466f5a88-0af2-4f76-9038-095b170dc21c}
device unknown
path \ntldr
description Earlier Version of Windows
custom:45000001 1
custom:47000005 301989892
6
EMS Settings
------------
identifier {0ce4991b-e6b3-4b16-b23c-5e0d9250e5d9}
bootems Yes
Debugger Settings
-----------------
identifier {4636856e-540f-4170-a130-a84776f4c654}
debugtype Serial
debugport 1
baudrate 115200
RAM Defects
-----------
identifier {5189b25c-5558-4bf2-bca4-289b11bd29e2}
Global Settings
---------------
identifier {7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}
inherit {4636856e-540f-4170-a130-a84776f4c654}
{0ce4991b-e6b3-4b16-b23c-5e0d9250e5d9}
{5189b25c-5558-4bf2-bca4-289b11bd29e2}
Boot Loader Settings
--------------------
identifier {6efb52bf-1766-41db-a6b3-0ee5eff72bd7}
inherit {7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}
{7ff607e0-4395-11db-b0de-0800200c9a66}
Hypervisor Settings
-------------------
identifier {7ff607e0-4395-11db-b0de-0800200c9a66}
hypervisordebugtype Serial
hypervisordebugport 1
hypervisorbaudrate 115200
Resume Loader Settings
----------------------
identifier {1afa9c49-16ab-4a5c-901b-212802da9460}
inherit {7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}
Device options
--------------
identifier {1311a3ab-3644-11df-a071-b1f2960e9c50}
description Ramdisk Options
ramdisksdidevice partition=C:
ramdisksdipath \Recovery\1311a3aa-3644-11df-a071-b1f2960e9c50\boot.sdi
****** End Of Log ******
Here is the GMER log and Listparts log:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-08-20 09:39:57
Windows 6.1.7600 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 rev.
Running: 7ex48rit.exe; Driver: C:\Users\Mitch\AppData\Local\Temp\kgloypog.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwNotifyChangeKey [0x9787A004]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwNotifyChangeMultipleKeys [0x9787A0D4]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0x97879D76]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateProcess [0x97879E1E]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0x97879EBA]
SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0x97879F56]
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKeyEx + 13BD 82E47589 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82E6C092 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!RtlSidHashLookup + 4A0 82E73AB0 8 Bytes [04, A0, 87, 97, D4, A0, 87, ...] {ADD AL, 0xa0; XCHG [EDI-0x68785f2c], EDX}
.text ntkrnlpa.exe!RtlSidHashLookup + 4E8 82E73AF8 4 Bytes [76, 9D, 87, 97]
.text ntkrnlpa.exe!RtlSidHashLookup + 7B8 82E73DC8 8 Bytes [1E, 9E, 87, 97, BA, 9E, 87, ...] {PUSH DS; SAHF ; XCHG [EDI-0x68786146], EDX}
.text ntkrnlpa.exe!RtlSidHashLookup + 82C 82E73E3C 4 Bytes [56, 9F, 87, 97]
---- User code sections - GMER 1.0.15 ----
? C:\Program Files\AVG\AVG2012\avgwdsvc.exe[384] C:\Windows\system32\IPHLPAPI.DLL time/date stamp mismatch; unknown module: dhcpcsvc.DLLunknown module: dhcpcsvc6.DLLunknown module: DNSAPI.dllunknown module: WINNSI.DLLunknown module: NSI.dll
? C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe[512] C:\Windows\system32\IPHLPAPI.DLL time/date stamp mismatch; unknown module: dhcpcsvc.DLLunknown module: dhcpcsvc6.DLLunknown module: DNSAPI.dllunknown module: WINNSI.DLLunknown module: NSI.dll
? C:\Windows\system32\lsass.exe[820] C:\Windows\system32\IPHLPAPI.DLL time/date stamp mismatch; unknown module: dhcpcsvc.DLLunknown module: dhcpcsvc6.DLLunknown module: DNSAPI.dllunknown module: WINNSI.DLLunknown module: NSI.dll
? C:\Windows\System32\svchost.exe[1096] c:\windows\system32\IPHLPAPI.DLL time/date stamp mismatch; unknown module: dhcpcsvc.DLLunknown module: dhcpcsvc6.DLLunknown module: DNSAPI.dllunknown module: WINNSI.DLLunknown module: NSI.dll
? C:\Windows\System32\svchost.exe[1128] c:\windows\system32\IPHLPAPI.DLL time/date stamp mismatch; unknown module: dhcpcsvc.DLLunknown module: dhcpcsvc6.DLLunknown module: DNSAPI.dllunknown module: WINNSI.DLLunknown module: NSI.dll
? C:\Windows\system32\svchost.exe[1172] c:\windows\system32\IPHLPAPI.DLL time/date stamp mismatch; unknown module: dhcpcsvc.DLLunknown module: dhcpcsvc6.DLLunknown module: DNSAPI.dllunknown module: WINNSI.DLLunknown module: NSI.dll
? C:\Windows\system32\svchost.exe[1276] c:\windows\system32\IPHLPAPI.DLL time/date stamp mismatch; unknown module: dhcpcsvc.DLLunknown module: dhcpcsvc6.DLLunknown module: DNSAPI.dllunknown module: WINNSI.DLLunknown module: NSI.dll
? C:\Windows\system32\svchost.exe[1448] C:\Windows\system32\iphlpapi.dll time/date stamp mismatch; unknown module: dhcpcsvc.DLLunknown module: dhcpcsvc6.DLLunknown module: DNSAPI.dllunknown module: WINNSI.DLLunknown module: NSI.dll
? C:\Windows\system32\winlogon.exe[1480] C:\Windows\system32\ADVAPI32.dll time/date stamp mismatch; unknown module: CRYPTSP.dllunknown module: WINTRUST.dllunknown module: SspiCli.dllunknown module: bcrypt.dllunknown module: pcwum.dllunknown module: KERNELBASE.dll
? C:\Windows\system32\winlogon.exe[1480] C:\Windows\system32\userenv.dll time/date stamp mismatch; unknown module: DNSAPI.dllunknown module: logoncli.dllunknown module: netutils.dllunknown module: SspiCli.dllunknown module: GPAPI.dllunknown module: GPSVC.dllunknown module: profapi.dllunknown module: KERNELBASE.dll
? C:\Windows\System32\spoolsv.exe[1892] C:\Windows\System32\IPHLPAPI.DLL time/date stamp mismatch; unknown module: dhcpcsvc.DLLunknown module: dhcpcsvc6.DLLunknown module: DNSAPI.dllunknown module: WINNSI.DLLunknown module: NSI.dll
? C:\Windows\system32\svchost.exe[1928] C:\Windows\system32\IPHLPAPI.DLL time/date stamp mismatch; unknown module: dhcpcsvc.DLLunknown module: dhcpcsvc6.DLLunknown module: DNSAPI.dllunknown module: WINNSI.DLLunknown module: NSI.dll
? C:\Windows\System32\svchost.exe[1952] C:\Windows\System32\IPHLPAPI.DLL time/date stamp mismatch; unknown module: dhcpcsvc.DLLunknown module: dhcpcsvc6.DLLunknown module: DNSAPI.dllunknown module: WINNSI.DLLunknown module: NSI.dll
? C:\Windows\Explorer.EXE[3464] C:\Windows\System32\IPHLPAPI.DLL time/date stamp mismatch; unknown module: dhcpcsvc.DLLunknown module: dhcpcsvc6.DLLunknown module: DNSAPI.dllunknown module: WINNSI.DLLunknown module: NSI.dll
? C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe[3732] C:\Windows\system32\iphlpapi.DLL time/date stamp mismatch; unknown module: dhcpcsvc.DLLunknown module: dhcpcsvc6.DLLunknown module: DNSAPI.dllunknown module: WINNSI.DLLunknown module: NSI.dll
? C:\Program Files\Google\Chrome\Application\chrome.exe[3888] C:\Windows\system32\IPHLPAPI.DLL time/date stamp mismatch; unknown module: dhcpcsvc.DLLunknown module: dhcpcsvc6.DLLunknown module: DNSAPI.dllunknown module: WINNSI.DLLunknown module: NSI.dll
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\system32\winlogon.exe[1480] @ C:\Windows\system32\winlogon.exe [KERNEL32.dll!LoadLibraryExA] [738C9B20] C:\Program Files\NetMotion Client\nmlogon.dll (NetMotion Logon DLL/NetMotion Wireless, Inc.)
IAT C:\Windows\system32\winlogon.exe[1480] @ C:\Windows\system32\winlogon.exe [KERNEL32.dll!LoadLibraryW] [738C9A80] C:\Program Files\NetMotion Client\nmlogon.dll (NetMotion Logon DLL/NetMotion Wireless, Inc.)
IAT C:\Windows\system32\winlogon.exe[1480] @ C:\Windows\system32\winlogon.exe [KERNEL32.dll!GetProcAddress] [738C9800] C:\Program Files\NetMotion Client\nmlogon.dll (NetMotion Logon DLL/NetMotion Wireless, Inc.)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Tcp nmdrv.sys
Device \Driver\ACPI_HAL \Device\00000057 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Udp nmdrv.sys
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp nmdrv.sys
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat avgidsfilterx.sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0007615150eb
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0007615150eb (not active ControlSet)
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sector 00: rootkit-like behavior
---- Files - GMER 1.0.15 ----
File C:\Users\Mitch\Documents\personal\Locked 0 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct 0 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\lowes login.txt 30 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\amazon log in.txt 77 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\att and uverse login.txt 109 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\avg license.txt 53 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\blackberry forums.txt 35 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\blue cross blue shield log in.txt 47 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\cigna dental log in.txt 40 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\citimortgage login.txt 53 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\COA benefits login.txt 49 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\directv login.txt 49 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\MXenergy.txt 33 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\online payment confirmation 0 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\online payment confirmation\simmons 6_11 online payment conf.txt 160 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\paypal login.txt 76 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\peachcare login.txt 88 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\retirement acct logins.txt 649 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\scottrade login.txt 67 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\simmons first login.txt 95 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\state farm.txt 38 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\target log in.txt 387 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\taxact login 09.txt 50 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\trev gosolar.txt 60 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\world golf tour.txt 38 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\ebay log in.txt 33 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\FIA log in.txt 470 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\flightsim.com log in.txt 14 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\ga fed credit union.txt 44 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\ga fed quickpay xfer.txt 56 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\ge moneybank login.txt 36 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\gwinnett county water resources.txt 57 bytes
File C:\Users\Mitch\Documents\personal\Locked\acct\home depot log-in.txt 39 bytes
File C:\Users\Mitch\Documents\personal\Locked\misc 0 bytes
File C:\Users\Mitch\Documents\personal\Locked\misc\Jermaine logs cont.pdf 611856 bytes
File C:\Users\Mitch\Documents\personal\Locked\misc\Jermaine logs.docx 10796 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs 0 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2008 0 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2008\2008_Federal_Return Mitch.pdf 49865 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2008\2008_Federal_Return Terri.pdf 44376 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2008\2008_Georgia_Return Mitch.pdf 26591 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2008\2008_Georgia_Return Terri.pdf 26141 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2009 0 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2009\1099-R.pdf 165410 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2009\2009_Federal_Return.pdf 71442 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2009\2009_Georgia_Return.pdf 22145 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2010 0 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2010\2010_Federal_Form_W4_suggested.pdf 26651 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2010\2010_Federal_Return.pdf 47484 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2010\2010_Georgia_Return.pdf 19236 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2010 fed withholding suggestions.txt 617 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2011 0 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2011\2011_Federal_Form_1040.pdf 23232 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2011\2011_Federal_Form_4952.pdf 7639 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2011\2011_Federal_Schedule_A.pdf 10284 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2011\2011_Federal_Schedule_B.pdf 9366 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2011\2011_Federal_Schedule_D.pdf 17965 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2011\2011_Georgia_Return.pdf 20605 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\2011\taxes fed state 04.pdf 46312 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\chris_april_ssn.txt 58 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\Federal and State Electronic Filing Instructions.doc 25600 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\suggested 2012 W4.pdf 123284 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\taxes fed 03.T03 48576 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\taxes fed state 04.pdf 387173 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\taxes fed state 05.PDF 359794 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\taxes fed state 06.pdf 309176 bytes
File C:\Users\Mitch\Documents\personal\Locked\tax docs\taxes fed state 07.pdf 295549 bytes
---- EOF - GMER 1.0.15 ----
*****************************************************************************************************************************************
ListParts by Farbar Version: 10-08-2012
Ran by Mitch (administrator) on 20-08-2012 at 09:41:00
Windows 7 (X86)
Running From: C:\Users\SG3 13\Desktop
Language: 0409
************************************************************
========================= Memory info ======================
Percentage of memory in use: 39%
Total physical RAM: 3571.9 MB
Available physical RAM: 2162.87 MB
Total Pagefile: 7142.08 MB
Available Pagefile: 5792.97 MB
Total Virtual: 2047.88 MB
Available Virtual: 1956.38 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:222.63 GB) (Free:102.18 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (RECOVERY) (Fixed) (Total:10 GB) (Free:3.37 GB) NTFS
3 Drive e: (COD2CD1) (CDROM) (Total:0.45 GB) (Free:0 GB) CDFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 232 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 258 MB 31 KB
Partition 2 Primary 10 GB 259 MB
Partition 3 Primary 222 GB 10 GB
======================================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
There is no volume associated with this partition.
======================================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 D RECOVERY NTFS Partition 10 GB Healthy
======================================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 222 GB Healthy System (partition with boot components)
======================================================================================================
Windows Boot Manager
--------------------
identifier {9dea862c-5cdd-4e70-acc1-f32b344d4795}
device partition=C:
description Windows Boot Manager
locale en-US
inherit {7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}
default {1311a3a9-3644-11df-a071-b1f2960e9c50}
resumeobject {1311a3a8-3644-11df-a071-b1f2960e9c50}
displayorder {1311a3a9-3644-11df-a071-b1f2960e9c50}
toolsdisplayorder {b2721d73-1db4-4c62-bf78-c548a880142d}
timeout 30
Windows Boot Loader
-------------------
identifier {1311a3a9-3644-11df-a071-b1f2960e9c50}
device partition=C:
path \Windows\system32\winload.exe
description Windows 7
locale en-US
inherit {6efb52bf-1766-41db-a6b3-0ee5eff72bd7}
recoverysequence {1311a3aa-3644-11df-a071-b1f2960e9c50}
recoveryenabled Yes
osdevice partition=C:
systemroot \Windows
resumeobject {1311a3a8-3644-11df-a071-b1f2960e9c50}
nx OptIn
Windows Boot Loader
-------------------
identifier {1311a3aa-3644-11df-a071-b1f2960e9c50}
device ramdisk=[C:]\Recovery\1311a3aa-3644-11df-a071-b1f2960e9c50\Winre.wim,{1311a3ab-3644-11df-a071-b1f2960e9c50}
path \windows\system32\winload.exe
description Windows Recovery Environment
inherit {6efb52bf-1766-41db-a6b3-0ee5eff72bd7}
osdevice ramdisk=[C:]\Recovery\1311a3aa-3644-11df-a071-b1f2960e9c50\Winre.wim,{1311a3ab-3644-11df-a071-b1f2960e9c50}
systemroot \windows
nx OptIn
winpe Yes
custom:46000010 Yes
Windows Boot Loader
-------------------
identifier {572bcd55-ffa7-11d9-aae0-0007e994107d}
device partition=D:
path \Windows\System32\boot\winload.exe
description Windows Recovery Environment
osdevice partition=D:
systemroot \Windows
nx OptIn
detecthal Yes
winpe Yes
Resume from Hibernate
---------------------
identifier {1311a3a8-3644-11df-a071-b1f2960e9c50}
device partition=C:
path \Windows\system32\winresume.exe
description Windows Resume Application
locale en-US
inherit {1afa9c49-16ab-4a5c-901b-212802da9460}
filedevice partition=C:
filepath \hiberfil.sys
pae Yes
debugoptionenabled No
Windows Memory Tester
---------------------
identifier {b2721d73-1db4-4c62-bf78-c548a880142d}
device partition=C:
path \boot\memtest.exe
description Windows Memory Diagnostic
locale en-US
inherit {7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}
badmemoryaccess Yes
Windows Legacy OS Loader
------------------------
identifier {466f5a88-0af2-4f76-9038-095b170dc21c}
device unknown
path \ntldr
description Earlier Version of Windows
custom:45000001 1
custom:47000005 301989892
6
EMS Settings
------------
identifier {0ce4991b-e6b3-4b16-b23c-5e0d9250e5d9}
bootems Yes
Debugger Settings
-----------------
identifier {4636856e-540f-4170-a130-a84776f4c654}
debugtype Serial
debugport 1
baudrate 115200
RAM Defects
-----------
identifier {5189b25c-5558-4bf2-bca4-289b11bd29e2}
Global Settings
---------------
identifier {7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}
inherit {4636856e-540f-4170-a130-a84776f4c654}
{0ce4991b-e6b3-4b16-b23c-5e0d9250e5d9}
{5189b25c-5558-4bf2-bca4-289b11bd29e2}
Boot Loader Settings
--------------------
identifier {6efb52bf-1766-41db-a6b3-0ee5eff72bd7}
inherit {7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}
{7ff607e0-4395-11db-b0de-0800200c9a66}
Hypervisor Settings
-------------------
identifier {7ff607e0-4395-11db-b0de-0800200c9a66}
hypervisordebugtype Serial
hypervisordebugport 1
hypervisorbaudrate 115200
Resume Loader Settings
----------------------
identifier {1afa9c49-16ab-4a5c-901b-212802da9460}
inherit {7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}
Device options
--------------
identifier {1311a3ab-3644-11df-a071-b1f2960e9c50}
description Ramdisk Options
ramdisksdidevice partition=C:
ramdisksdipath \Recovery\1311a3aa-3644-11df-a071-b1f2960e9c50\boot.sdi
****** End Of Log ******