Several weeks ago, after launching a link on Facebook, I my laptop was taken over by Windows System Repair rootkit. I was able to reboot in safe mode and run Malwarebytes and get back control of my laptop but have been having continuous problems. Right after running malarebytes I started having Multiple Iexplore.exe processes running invisibly, causing audio clips of commercials, such as Slim Jim commercials and other random ads and a sports broadcast from 2010. Very wierd.
I think I had other infections, prior to this one, that I was unaware of. At some point last year my Task manager was all but disabled, showing on the processes window. I also lost the function of my optical disk drive. And the Shockwave Flash plug-in began to regularly crash spontaneously (I have discovered I can recreate that event by ending the plug-in container process in Taskmanager.) At that time I was running IObit and Avira and thought I was protected.
Since the Windows Vista Repair attack I have added Avast and run several completet scans, including boot scans. i have uncovered some infections but continue to have problems.
I have runn CCleaner and Super Anti-Spyware.
I run Mozilla Firefox 5.1 having recently upgraded from 3.6, thinking that might solve my problems.
My current problem is IE spontaneously opening a hidden window with the ultimate effect of shutting down my sound. Restarting Firefox re-enables the sound. Occasionaly, upon reboot, no sound drivers will load at all and the system will report "no device installed".
When IE starts malwarebytes reports an alarm that it is blocking a malicious URL with a IP address of 64.111.211.172. A WHOIS search revelas nothing much about that IP address.
It appears that a when a new internet session is initiated by a program IE starts up spontaeously in the background, w no visible window (and malwarebytes blocks the maicious URL) but I can see and kill the process in task manager.
The Chrome browser will no longer load webpages. Also, I am being plauged with a google redirect virus that I cannot get rid of. So I need some help.
Now, I've just re-started firefox and the bleepingcomputer site will not load unless I copy a new URL from a google search.
After doing a google search for solutions I came across this thread on bleepingcomputer.com
http://www.bleepingcomputer.com/forums/topic335239.html
I have run MBR Check and this is the log from the first run:
MBRCheck, version 1.2.3
© 2010, AD
Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: Service Pack 2 (build 6002), 32-bit
Logical Drives Mask: 0x0000000c
Kernel Drivers (total 166):
0x85814000 \SystemRoot\system32\ntkrnlpa.exe
0x85BCE000 \SystemRoot\system32\hal.dll
0x80605000 \SystemRoot\system32\kdcom.dll
0x8060C000 \SystemRoot\system32\PSHED.dll
0x8061D000 \SystemRoot\system32\BOOTVID.dll
0x80625000 \SystemRoot\system32\CLFS.SYS
0x80666000 \SystemRoot\system32\CI.dll
0x80746000 \SystemRoot\system32\drivers\Wdf01000.sys
0x807B7000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x85E0A000 \SystemRoot\system32\drivers\acpi.sys
0x85E50000 \SystemRoot\system32\drivers\WMILIB.SYS
0x85E59000 \SystemRoot\system32\drivers\msisadrv.sys
0x85E61000 \SystemRoot\system32\drivers\pci.sys
0x85E88000 \SystemRoot\System32\drivers\partmgr.sys
0x85E97000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x85E9A000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x85EA4000 \SystemRoot\system32\drivers\volmgr.sys
0x85EB3000 \SystemRoot\System32\drivers\volmgrx.sys
0x85EFD000 \SystemRoot\system32\drivers\pciide.sys
0x85F04000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x85F12000 \SystemRoot\System32\drivers\mountmgr.sys
0x85F22000 \SystemRoot\system32\drivers\atapi.sys
0x85F2A000 \SystemRoot\system32\drivers\ataport.SYS
0x85F48000 \SystemRoot\system32\drivers\fltmgr.sys
0x85F7A000 \SystemRoot\system32\drivers\fileinfo.sys
0x85F8A000 \SystemRoot\System32\Drivers\ksecdd.sys
0x8AC09000 \SystemRoot\system32\drivers\ndis.sys
0x8AD14000 \SystemRoot\system32\drivers\msrpc.sys
0x8AD3F000 \SystemRoot\system32\drivers\NETIO.SYS
0x8AE08000 \SystemRoot\System32\drivers\tcpip.sys
0x8AEF2000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8AF0D000 \SystemRoot\system32\DRIVERS\scmndisp.sys
0x8B008000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8B118000 \SystemRoot\system32\drivers\volsnap.sys
0x8B151000 \SystemRoot\System32\Drivers\spldr.sys
0x8B159000 \SystemRoot\system32\speedfan.sys
0x8B15B000 \SystemRoot\system32\DRIVERS\Soluto.sys
0x8B16A000 \SystemRoot\System32\Drivers\mup.sys
0x8B179000 \SystemRoot\system32\giveio.sys
0x8B17A000 \SystemRoot\System32\drivers\ecache.sys
0x8B1A1000 \SystemRoot\system32\drivers\disk.sys
0x8B1B2000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x8B1D3000 \SystemRoot\system32\drivers\crcdisk.sys
0x8AF16000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x8AF21000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x8AF2A000 \SystemRoot\system32\DRIVERS\amdk8.sys
0x8B1FC000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x8B000000 \SystemRoot\system32\DRIVERS\cpqbttn.sys
0x8AF3A000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x8AF4A000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x8AF51000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x8B003000 \SystemRoot\system32\DRIVERS\nvsmu.sys
0x8AF5A000 \SystemRoot\system32\DRIVERS\usbohci.sys
0x8AF64000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x8AFA2000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x8F205000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x8F292000 \SystemRoot\system32\DRIVERS\sdbus.sys
0x8F2AC000 \SystemRoot\system32\DRIVERS\rimmptsk.sys
0x8F2BD000 \SystemRoot\system32\DRIVERS\rimsptsk.sys
0x8F2D1000 \SystemRoot\system32\DRIVERS\rixdptsk.sys
0x8F402000 \SystemRoot\system32\DRIVERS\nvmfdx32.sys
0x8F603000 \SystemRoot\system32\DRIVERS\ts_athw.sys
0x8F800000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x8FF46000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x8FFE6000 \SystemRoot\System32\drivers\watchdog.sys
0x8F74D000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x8FFF2000 \SystemRoot\system32\DRIVERS\HpqKbFiltr.sys
0x8F760000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x8F76B000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x8FFF7000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x8F7A6000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x8F7B1000 \SystemRoot\System32\Drivers\tosrfcom.sys
0x8F7C1000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x8F503000 \SystemRoot\system32\DRIVERS\storport.sys
0x8F7F0000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8F544000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x8F55B000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x8F566000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x8F589000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x8F598000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x8F5AC000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x8F5C1000 \SystemRoot\system32\DRIVERS\termdd.sys
0x8FFF9000 \SystemRoot\system32\DRIVERS\swenum.sys
0x8F5D1000 \SystemRoot\system32\DRIVERS\ks.sys
0x8F323000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x8F32D000 \SystemRoot\system32\DRIVERS\umbus.sys
0x8F33A000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x8F343000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x8F378000 \SystemRoot\system32\DRIVERS\tosporte.sys
0x8F383000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x8F39D000 \SystemRoot\system32\drivers\CHDRT32.sys
0x8F3D0000 \SystemRoot\system32\drivers\portcls.sys
0x8AFB1000 \SystemRoot\system32\drivers\drmk.sys
0x8AD7A000 \SystemRoot\system32\DRIVERS\HSXHWAZL.sys
0x95A09000 \SystemRoot\system32\DRIVERS\HSX_DPV.sys
0x95B0C000 \SystemRoot\system32\DRIVERS\HSX_CNXT.sys
0x95BC1000 \SystemRoot\system32\drivers\modem.sys
0x95608000 \SystemRoot\System32\Drivers\aswSnx.SYS
0x95678000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x95681000 \SystemRoot\System32\Drivers\Null.SYS
0x95688000 \SystemRoot\System32\Drivers\Beep.SYS
0x9568F000 \SystemRoot\System32\drivers\vga.sys
0x9569B000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x956BC000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x956C4000 \SystemRoot\system32\drivers\rdpencdd.sys
0x956CC000 \SystemRoot\System32\Drivers\Msfs.SYS
0x956D7000 \SystemRoot\System32\Drivers\Npfs.SYS
0x956E5000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x956EE000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x956F7000 \SystemRoot\system32\DRIVERS\tdx.sys
0x9570D000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x95715000 \SystemRoot\System32\Drivers\aswTdi.SYS
0x9571E000 \SystemRoot\system32\DRIVERS\smb.sys
0x95732000 \SystemRoot\system32\drivers\afd.sys
0x9577A000 \SystemRoot\System32\Drivers\aswRdr.SYS
0x9577F000 \SystemRoot\System32\DRIVERS\netbt.sys
0x957B1000 \SystemRoot\system32\DRIVERS\pacer.sys
0x957C7000 \SystemRoot\system32\DRIVERS\jswpslwf.sys
0x957CC000 \SystemRoot\system32\DRIVERS\netbios.sys
0x957DA000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x8ADB8000 \SystemRoot\System32\drivers\truecrypt.sys
0x957ED000 \SystemRoot\system32\DRIVERS\ssmdrv.sys
0x95BCE000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
0x957F3000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
0x9620C000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x96248000 \SystemRoot\system32\drivers\nsiproxy.sys
0x96252000 \SystemRoot\System32\Drivers\dfsc.sys
0x96269000 \SystemRoot\system32\DRIVERS\avipbb.sys
0x96290000 \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys
0x96292000 \SystemRoot\System32\Drivers\aswSP.SYS
0x962DC000 \SystemRoot\System32\Drivers\crashdmp.sys
0x962E9000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x962F4000 \SystemRoot\System32\Drivers\dump_atapi.sys
0xA2400000 \SystemRoot\System32\win32k.sys
0x962FC000 \SystemRoot\System32\drivers\Dxapi.sys
0x96306000 \SystemRoot\system32\DRIVERS\monitor.sys
0xA2620000 \SystemRoot\System32\TSDDD.dll
0xA2640000 \SystemRoot\System32\cdd.dll
0x96315000 \SystemRoot\system32\drivers\luafv.sys
0x96330000 \??\C:\Windows\system32\drivers\aswMonFlt.sys
0x96368000 \SystemRoot\system32\DRIVERS\avgntflt.sys
0x9637F000 \SystemRoot\System32\Drivers\aswFsBlk.SYS
0x96382000 \??\C:\Program Files\IObit\Protected Folder\pffilter.sys
0x83607000 \SystemRoot\system32\drivers\spsys.sys
0x836B7000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x836C7000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x836F1000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x836FB000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x8370E000 \SystemRoot\system32\drivers\HTTP.sys
0x8377B000 \SystemRoot\system32\DRIVERS\bowser.sys
0x83794000 \SystemRoot\System32\drivers\mpsdrv.sys
0x837A9000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x963A7000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x837C8000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x837F8000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys
0xAA209000 \SystemRoot\system32\drivers\peauth.sys
0xAA2E7000 \SystemRoot\System32\Drivers\secdrv.SYS
0xAA2F1000 \SystemRoot\System32\DRIVERS\srvnet.sys
0xAA30E000 \SystemRoot\System32\drivers\tcpipreg.sys
0xAA31A000 \SystemRoot\system32\DRIVERS\xaudio.sys
0xAA322000 \SystemRoot\System32\DRIVERS\srv2.sys
0xAA34A000 \SystemRoot\System32\DRIVERS\srv.sys
0xAA399000 \??\C:\Program Files\IObit\IObit Malware Fighter\drivers\wlh_x86\regfilter.sys
0xAA3A3000 \??\C:\Program Files\IObit\IObit Malware Fighter\Drivers\wlh_x86\FileMonitor.sys
0xAA3E0000 \??\C:\Program Files\IObit\IObit Malware Fighter\drivers\wlh_x86\UrlFilter.sys
0x77710000 \WINDOWS\System32\ntdll.dll
Processes (total 74):
0 System Idle Process
4 System
508 C:\WINDOWS\System32\smss.exe
580 csrss.exe
632 C:\WINDOWS\System32\wininit.exe
640 csrss.exe
676 C:\WINDOWS\System32\services.exe
692 C:\WINDOWS\System32\lsass.exe
700 C:\WINDOWS\System32\lsm.exe
764 C:\WINDOWS\System32\winlogon.exe
904 C:\WINDOWS\System32\svchost.exe
980 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
1012 C:\WINDOWS\System32\svchost.exe
1068 C:\WINDOWS\System32\svchost.exe
1136 C:\WINDOWS\System32\svchost.exe
1180 C:\WINDOWS\System32\svchost.exe
1216 C:\WINDOWS\System32\svchost.exe
1300 C:\WINDOWS\System32\audiodg.exe
1332 C:\WINDOWS\System32\SLsvc.exe
1384 C:\WINDOWS\System32\svchost.exe
1512 C:\WINDOWS\System32\svchost.exe
1668 C:\Program Files\AVAST Software\Avast\AvastSvc.exe
2024 C:\WINDOWS\System32\spoolsv.exe
124 C:\Program Files\Avira\AntiVir Desktop\sched.exe
208 C:\WINDOWS\System32\svchost.exe
424 C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
1476 C:\Program Files\Soluto\Soluto.exe
1488 C:\WINDOWS\System32\dwm.exe
1732 C:\WINDOWS\explorer.exe
804 C:\WINDOWS\System32\taskeng.exe
2124 C:\WINDOWS\System32\taskeng.exe
2312 C:\Program Files\Windows Defender\MSASCui.exe
2356 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
2420 C:\WINDOWS\System32\rundll32.exe
2460 C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
2468 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
2520 C:\Program Files\Avira\AntiVir Desktop\avguard.exe
2536 C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
2592 C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
2608 C:\WINDOWS\System32\svchost.exe
2624 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
2640 C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe
2680 C:\WINDOWS\System32\svchost.exe
2816 C:\Program Files\Soluto\SolutoService.exe
2840 C:\Program Files\HP\HP Software Update\hpwuschd2.exe
3132 C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
3140 C:\Program Files\AVAST Software\Avast\AvastUI.exe
3164 C:\Users\jsampson\AppData\Local\Google\Update\GoogleUpdate.exe
3196 C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe
3232 C:\WINDOWS\System32\svchost.exe
3248 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
3284 C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
3380 C:\WINDOWS\System32\vds.exe
3416 C:\WINDOWS\System32\svchost.exe
3432 C:\Program Files\Windows Media Player\wmpnetwk.exe
3552 C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
1740 C:\Program Files\IObit\IObit Malware Fighter\IMF.exe
2668 WmiPrvSE.exe
4088 C:\WINDOWS\System32\taskeng.exe
1108 C:\WINDOWS\System32\wbem\unsecapp.exe
2232 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
4296 C:\WINDOWS\System32\svchost.exe
5116 C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
5188 C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
4040 C:\WINDOWS\System32\wuauclt.exe
5176 C:\WINDOWS\System32\taskmgr.exe
4944 C:\Program Files\IObit\Advanced SystemCare 4\ASC.exe
4064 C:\WINDOWS\System32\sdclt.exe
4476 C:\WINDOWS\System32\svchost.exe
2700 C:\Program Files\Mozilla Firefox\firefox.exe
4276 C:\Program Files\Mozilla Firefox\plugin-container.exe
5420 C:\Users\jsampson\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
5840 C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
1088 C:\Users\jsampson\Desktop\MBRCheck.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00100000 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000037`55393a00 (NTFS)
PhysicalDrive0 Model Number: HitachiHTS542525K9SA00, Rev: BBFOC32P
Size Device Name MBR Status
--------------------------------------------
232 GB \\.\PhysicalDrive0 Unknown MBR code
SHA1: D94F393960D1CD66C2071F2D7260A5196DF105AC
Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
Done!
Following the instruction in the thread I ran MBRCheck again, this time following the instructions to repair a Vista MBR. here is the log from that:
MBRCheck, version 1.2.3
© 2010, AD
Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: Service Pack 2 (build 6002), 32-bit
Logical Drives Mask: 0x0000000c
Kernel Drivers (total 166):
0x85814000 \SystemRoot\system32\ntkrnlpa.exe
0x85BCE000 \SystemRoot\system32\hal.dll
0x80605000 \SystemRoot\system32\kdcom.dll
0x8060C000 \SystemRoot\system32\PSHED.dll
0x8061D000 \SystemRoot\system32\BOOTVID.dll
0x80625000 \SystemRoot\system32\CLFS.SYS
0x80666000 \SystemRoot\system32\CI.dll
0x80746000 \SystemRoot\system32\drivers\Wdf01000.sys
0x807B7000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x85E0A000 \SystemRoot\system32\drivers\acpi.sys
0x85E50000 \SystemRoot\system32\drivers\WMILIB.SYS
0x85E59000 \SystemRoot\system32\drivers\msisadrv.sys
0x85E61000 \SystemRoot\system32\drivers\pci.sys
0x85E88000 \SystemRoot\System32\drivers\partmgr.sys
0x85E97000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x85E9A000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x85EA4000 \SystemRoot\system32\drivers\volmgr.sys
0x85EB3000 \SystemRoot\System32\drivers\volmgrx.sys
0x85EFD000 \SystemRoot\system32\drivers\pciide.sys
0x85F04000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x85F12000 \SystemRoot\System32\drivers\mountmgr.sys
0x85F22000 \SystemRoot\system32\drivers\atapi.sys
0x85F2A000 \SystemRoot\system32\drivers\ataport.SYS
0x85F48000 \SystemRoot\system32\drivers\fltmgr.sys
0x85F7A000 \SystemRoot\system32\drivers\fileinfo.sys
0x85F8A000 \SystemRoot\System32\Drivers\ksecdd.sys
0x8AC09000 \SystemRoot\system32\drivers\ndis.sys
0x8AD14000 \SystemRoot\system32\drivers\msrpc.sys
0x8AD3F000 \SystemRoot\system32\drivers\NETIO.SYS
0x8AE08000 \SystemRoot\System32\drivers\tcpip.sys
0x8AEF2000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8AF0D000 \SystemRoot\system32\DRIVERS\scmndisp.sys
0x8B008000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8B118000 \SystemRoot\system32\drivers\volsnap.sys
0x8B151000 \SystemRoot\System32\Drivers\spldr.sys
0x8B159000 \SystemRoot\system32\speedfan.sys
0x8B15B000 \SystemRoot\system32\DRIVERS\Soluto.sys
0x8B16A000 \SystemRoot\System32\Drivers\mup.sys
0x8B179000 \SystemRoot\system32\giveio.sys
0x8B17A000 \SystemRoot\System32\drivers\ecache.sys
0x8B1A1000 \SystemRoot\system32\drivers\disk.sys
0x8B1B2000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x8B1D3000 \SystemRoot\system32\drivers\crcdisk.sys
0x8AF16000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x8AF21000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x8AF2A000 \SystemRoot\system32\DRIVERS\amdk8.sys
0x8B1FC000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x8B000000 \SystemRoot\system32\DRIVERS\cpqbttn.sys
0x8AF3A000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x8AF4A000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x8AF51000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x8B003000 \SystemRoot\system32\DRIVERS\nvsmu.sys
0x8AF5A000 \SystemRoot\system32\DRIVERS\usbohci.sys
0x8AF64000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x8AFA2000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x8F205000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x8F292000 \SystemRoot\system32\DRIVERS\sdbus.sys
0x8F2AC000 \SystemRoot\system32\DRIVERS\rimmptsk.sys
0x8F2BD000 \SystemRoot\system32\DRIVERS\rimsptsk.sys
0x8F2D1000 \SystemRoot\system32\DRIVERS\rixdptsk.sys
0x8F402000 \SystemRoot\system32\DRIVERS\nvmfdx32.sys
0x8F603000 \SystemRoot\system32\DRIVERS\ts_athw.sys
0x8F800000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x8FF46000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x8FFE6000 \SystemRoot\System32\drivers\watchdog.sys
0x8F74D000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x8FFF2000 \SystemRoot\system32\DRIVERS\HpqKbFiltr.sys
0x8F760000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x8F76B000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x8FFF7000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x8F7A6000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x8F7B1000 \SystemRoot\System32\Drivers\tosrfcom.sys
0x8F7C1000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x8F503000 \SystemRoot\system32\DRIVERS\storport.sys
0x8F7F0000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8F544000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x8F55B000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x8F566000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x8F589000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x8F598000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x8F5AC000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x8F5C1000 \SystemRoot\system32\DRIVERS\termdd.sys
0x8FFF9000 \SystemRoot\system32\DRIVERS\swenum.sys
0x8F5D1000 \SystemRoot\system32\DRIVERS\ks.sys
0x8F323000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x8F32D000 \SystemRoot\system32\DRIVERS\umbus.sys
0x8F33A000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x8F343000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x8F378000 \SystemRoot\system32\DRIVERS\tosporte.sys
0x8F383000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x8F39D000 \SystemRoot\system32\drivers\CHDRT32.sys
0x8F3D0000 \SystemRoot\system32\drivers\portcls.sys
0x8AFB1000 \SystemRoot\system32\drivers\drmk.sys
0x8AD7A000 \SystemRoot\system32\DRIVERS\HSXHWAZL.sys
0x95A09000 \SystemRoot\system32\DRIVERS\HSX_DPV.sys
0x95B0C000 \SystemRoot\system32\DRIVERS\HSX_CNXT.sys
0x95BC1000 \SystemRoot\system32\drivers\modem.sys
0x95608000 \SystemRoot\System32\Drivers\aswSnx.SYS
0x95678000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x95681000 \SystemRoot\System32\Drivers\Null.SYS
0x95688000 \SystemRoot\System32\Drivers\Beep.SYS
0x9568F000 \SystemRoot\System32\drivers\vga.sys
0x9569B000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x956BC000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x956C4000 \SystemRoot\system32\drivers\rdpencdd.sys
0x956CC000 \SystemRoot\System32\Drivers\Msfs.SYS
0x956D7000 \SystemRoot\System32\Drivers\Npfs.SYS
0x956E5000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x956EE000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x956F7000 \SystemRoot\system32\DRIVERS\tdx.sys
0x9570D000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x95715000 \SystemRoot\System32\Drivers\aswTdi.SYS
0x9571E000 \SystemRoot\system32\DRIVERS\smb.sys
0x95732000 \SystemRoot\system32\drivers\afd.sys
0x9577A000 \SystemRoot\System32\Drivers\aswRdr.SYS
0x9577F000 \SystemRoot\System32\DRIVERS\netbt.sys
0x957B1000 \SystemRoot\system32\DRIVERS\pacer.sys
0x957C7000 \SystemRoot\system32\DRIVERS\jswpslwf.sys
0x957CC000 \SystemRoot\system32\DRIVERS\netbios.sys
0x957DA000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x8ADB8000 \SystemRoot\System32\drivers\truecrypt.sys
0x957ED000 \SystemRoot\system32\DRIVERS\ssmdrv.sys
0x95BCE000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
0x957F3000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
0x9620C000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x96248000 \SystemRoot\system32\drivers\nsiproxy.sys
0x96252000 \SystemRoot\System32\Drivers\dfsc.sys
0x96269000 \SystemRoot\system32\DRIVERS\avipbb.sys
0x96290000 \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys
0x96292000 \SystemRoot\System32\Drivers\aswSP.SYS
0x962DC000 \SystemRoot\System32\Drivers\crashdmp.sys
0x962E9000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x962F4000 \SystemRoot\System32\Drivers\dump_atapi.sys
0xA2400000 \SystemRoot\System32\win32k.sys
0x962FC000 \SystemRoot\System32\drivers\Dxapi.sys
0x96306000 \SystemRoot\system32\DRIVERS\monitor.sys
0xA2620000 \SystemRoot\System32\TSDDD.dll
0xA2640000 \SystemRoot\System32\cdd.dll
0x96315000 \SystemRoot\system32\drivers\luafv.sys
0x96330000 \??\C:\Windows\system32\drivers\aswMonFlt.sys
0x96368000 \SystemRoot\system32\DRIVERS\avgntflt.sys
0x9637F000 \SystemRoot\System32\Drivers\aswFsBlk.SYS
0x96382000 \??\C:\Program Files\IObit\Protected Folder\pffilter.sys
0x83607000 \SystemRoot\system32\drivers\spsys.sys
0x836B7000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x836C7000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x836F1000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x836FB000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x8370E000 \SystemRoot\system32\drivers\HTTP.sys
0x8377B000 \SystemRoot\system32\DRIVERS\bowser.sys
0x83794000 \SystemRoot\System32\drivers\mpsdrv.sys
0x837A9000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x963A7000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x837C8000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x837F8000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys
0xAA209000 \SystemRoot\system32\drivers\peauth.sys
0xAA2E7000 \SystemRoot\System32\Drivers\secdrv.SYS
0xAA2F1000 \SystemRoot\System32\DRIVERS\srvnet.sys
0xAA30E000 \SystemRoot\System32\drivers\tcpipreg.sys
0xAA31A000 \SystemRoot\system32\DRIVERS\xaudio.sys
0xAA322000 \SystemRoot\System32\DRIVERS\srv2.sys
0xAA34A000 \SystemRoot\System32\DRIVERS\srv.sys
0xAA399000 \??\C:\Program Files\IObit\IObit Malware Fighter\drivers\wlh_x86\regfilter.sys
0xAA3A3000 \??\C:\Program Files\IObit\IObit Malware Fighter\Drivers\wlh_x86\FileMonitor.sys
0xAA3E0000 \??\C:\Program Files\IObit\IObit Malware Fighter\drivers\wlh_x86\UrlFilter.sys
0x77710000 \WINDOWS\System32\ntdll.dll
Processes (total 74):
0 System Idle Process
4 System
508 C:\WINDOWS\System32\smss.exe
580 csrss.exe
632 C:\WINDOWS\System32\wininit.exe
640 csrss.exe
676 C:\WINDOWS\System32\services.exe
692 C:\WINDOWS\System32\lsass.exe
700 C:\WINDOWS\System32\lsm.exe
764 C:\WINDOWS\System32\winlogon.exe
904 C:\WINDOWS\System32\svchost.exe
980 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
1012 C:\WINDOWS\System32\svchost.exe
1068 C:\WINDOWS\System32\svchost.exe
1136 C:\WINDOWS\System32\svchost.exe
1180 C:\WINDOWS\System32\svchost.exe
1216 C:\WINDOWS\System32\svchost.exe
1300 C:\WINDOWS\System32\audiodg.exe
1332 C:\WINDOWS\System32\SLsvc.exe
1384 C:\WINDOWS\System32\svchost.exe
1512 C:\WINDOWS\System32\svchost.exe
1668 C:\Program Files\AVAST Software\Avast\AvastSvc.exe
2024 C:\WINDOWS\System32\spoolsv.exe
124 C:\Program Files\Avira\AntiVir Desktop\sched.exe
208 C:\WINDOWS\System32\svchost.exe
424 C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
1476 C:\Program Files\Soluto\Soluto.exe
1488 C:\WINDOWS\System32\dwm.exe
1732 C:\WINDOWS\explorer.exe
804 C:\WINDOWS\System32\taskeng.exe
2124 C:\WINDOWS\System32\taskeng.exe
2312 C:\Program Files\Windows Defender\MSASCui.exe
2356 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
2420 C:\WINDOWS\System32\rundll32.exe
2460 C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
2468 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
2520 C:\Program Files\Avira\AntiVir Desktop\avguard.exe
2536 C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
2592 C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
2608 C:\WINDOWS\System32\svchost.exe
2624 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
2640 C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe
2680 C:\WINDOWS\System32\svchost.exe
2816 C:\Program Files\Soluto\SolutoService.exe
2840 C:\Program Files\HP\HP Software Update\hpwuschd2.exe
3132 C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
3140 C:\Program Files\AVAST Software\Avast\AvastUI.exe
3196 C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe
3232 C:\WINDOWS\System32\svchost.exe
3248 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
3284 C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
3380 C:\WINDOWS\System32\vds.exe
3416 C:\WINDOWS\System32\svchost.exe
3432 C:\Program Files\Windows Media Player\wmpnetwk.exe
3552 C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
1740 C:\Program Files\IObit\IObit Malware Fighter\IMF.exe
2668 WmiPrvSE.exe
4088 C:\WINDOWS\System32\taskeng.exe
1108 C:\WINDOWS\System32\wbem\unsecapp.exe
2232 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
4296 C:\WINDOWS\System32\svchost.exe
5116 C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
5188 C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
4040 C:\WINDOWS\System32\wuauclt.exe
5176 C:\WINDOWS\System32\taskmgr.exe
4944 C:\Program Files\IObit\Advanced SystemCare 4\ASC.exe
4064 C:\WINDOWS\System32\sdclt.exe
4476 C:\WINDOWS\System32\svchost.exe
2700 C:\Program Files\Mozilla Firefox\firefox.exe
4276 C:\Program Files\Mozilla Firefox\plugin-container.exe
5420 C:\Users\jsampson\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
5840 C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
4772 C:\WINDOWS\System32\svchost.exe
6388 C:\Users\jsampson\Desktop\MBRCheck.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00100000 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000037`55393a00 (NTFS)
PhysicalDrive0 Model Number: HitachiHTS542525K9SA00, Rev: BBFOC32P
Size Device Name MBR Status
--------------------------------------------
232 GB \\.\PhysicalDrive0 Unknown MBR code
SHA1: D94F393960D1CD66C2071F2D7260A5196DF105AC
Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
Options:
[1] Dump the MBR of a physical disk to file.
[2] Restore the MBR of a physical disk with a standard boot code.
[3] Exit.
Enter your choice: Enter the physical disk number to fix (0-99, -1 to cancel): 0Available MBR codes:
[ 0] Default (Windows Vista)
[ 1] Windows XP
[ 2] Windows Server 2003
[ 3] Windows Vista
[ 4] Windows 2008
[ 5] Windows 7
[-1] Cancel
Please select the MBR code to write to this drive: 3
Do you want to fix the MBR code? Type 'YES' and hit ENTER to continue: yes
Successfully wrote new MBR code!
Please reboot your computer to complete the fix.
Done!
I've rebooted the laptop but am still experiencing all of the problems I've already described. So, before going on to Combofix I thought I better reach out to an expert before I go any further along with this solution.
I hope I've been able to supply enough detail for you to get a handle on my problem. Thanks.
Jack
Attached File(s)
-
MBRCheck_07.22.11_10.42.27.txt (13.28K)
Number of downloads: 0 -
MBRCheck_07.22.11_11.00.33.txt (13.84K)
Number of downloads: 0 -
MBRCheck_07.22.11_11.17.37.txt (13.2K)
Number of downloads: 1
This post has been edited by hamluis: 22 July 2011 - 12:05 PM
Reason for edit: Moved from Vista to Am I Infected.

Help
This topic is locked

Back to top













