-
Sorry for the delay.
I have run the MBR check as instructed. My computer has been off for the past several days and I ran the scan on start up today. It once again said that something was incorrect or infected, and would I like to fix. I did not fix anything this time.
logs-
BRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: (build 6000), 32-bit
Base Board Manufacturer: Quanta
BIOS Manufacturer: Hewlett-Packard
System Manufacturer: Hewlett-Packard
System Product Name: HP Pavilion dx6500 Notebook PC
Logical Drives Mask: 0x000001fc
Kernel Drivers (total 156):
0x81C00000 \SystemRoot\system32\ntkrnlpa.exe
0x81FA1000 \SystemRoot\system32\hal.dll
0x802C6000 \SystemRoot\system32\kdcom.dll
0x80266000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x8025D000 \SystemRoot\system32\PSHED.dll
0x80255000 \SystemRoot\system32\BOOTVID.dll
0x8021A000 \SystemRoot\system32\CLFS.SYS
0x8051F000 \SystemRoot\system32\CI.dll
0x804A4000 \SystemRoot\system32\drivers\Wdf01000.sys
0x8020D000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x80461000 \SystemRoot\system32\drivers\acpi.sys
0x80204000 \SystemRoot\system32\drivers\WMILIB.SYS
0x80459000 \SystemRoot\system32\drivers\msisadrv.sys
0x80434000 \SystemRoot\system32\drivers\pci.sys
0x80425000 \SystemRoot\system32\drivers\volmgr.sys
0x80201000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x8041B000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x8040B000 \SystemRoot\System32\drivers\mountmgr.sys
0x80404000 \SystemRoot\system32\DRIVERS\pciide.sys
0x807F2000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
0x807A8000 \SystemRoot\System32\drivers\volmgrx.sys
0x806EA000 \SystemRoot\system32\DRIVERS\iaStor.sys
0x806E2000 \SystemRoot\system32\drivers\atapi.sys
0x806C4000 \SystemRoot\system32\drivers\ataport.SYS
0x80693000 \SystemRoot\system32\drivers\fltmgr.sys
0x80683000 \SystemRoot\system32\drivers\fileinfo.sys
0x8067A000 \SystemRoot\System32\Drivers\PxHelp20.sys
0x876FC000 \SystemRoot\system32\drivers\ndis.sys
0x8064F000 \SystemRoot\system32\drivers\msrpc.sys
0x80616000 \SystemRoot\system32\drivers\NETIO.SYS
0x878F8000 \SystemRoot\System32\Drivers\Ntfs.sys
0x87692000 \SystemRoot\System32\Drivers\ksecdd.sys
0x8765C000 \SystemRoot\system32\drivers\volsnap.sys
0x8060E000 \SystemRoot\System32\Drivers\spldr.sys
0x8764D000 \SystemRoot\System32\drivers\partmgr.sys
0x8763E000 \SystemRoot\System32\Drivers\mup.sys
0x87619000 \SystemRoot\System32\drivers\ecache.sys
0x87608000 \SystemRoot\system32\drivers\disk.sys
0x878D7000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x80605000 \SystemRoot\system32\drivers\crcdisk.sys
0x8820F000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x87842000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x88690000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x8B0A0000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x8860F000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x8B21A000 \SystemRoot\system32\DRIVERS\igdkmd32.sys
0x8B003000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x88602000 \SystemRoot\System32\drivers\watchdog.sys
0x88635000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x8A805000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x8864A000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x8B11E000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x8B9D9000 \SystemRoot\system32\DRIVERS\NETw4v32.sys
0x8B107000 \SystemRoot\system32\DRIVERS\Rtlh86.sys
0x88700000 \SystemRoot\system32\DRIVERS\ohci1394.sys
0x8B0F9000 \SystemRoot\system32\DRIVERS\1394BUS.SYS
0x8B0E1000 \SystemRoot\system32\DRIVERS\sdbus.sys
0x87833000 \SystemRoot\system32\DRIVERS\rimmptsk.sys
0x8B206000 \SystemRoot\system32\DRIVERS\rimsptsk.sys
0x8B898000 \SystemRoot\system32\DRIVERS\rixdptsk.sys
0x8A866000 \SystemRoot\system32\DRIVERS\cpqbttn.sys
0x88720000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x8B14C000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x8B885000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x8B87A000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x8B84F000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x88670000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x8B844000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x8B82C000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x8B1BE000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x8B801000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x8BDC0000 \SystemRoot\system32\DRIVERS\storport.sys
0x8BDB5000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8BD9E000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x8BD93000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x8BD70000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x8B8E9000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x8BD5D000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x8B8F8000 \SystemRoot\system32\DRIVERS\termdd.sys
0x8BD33000 \SystemRoot\system32\DRIVERS\mcdbus.sys
0x8BD0D000 \SystemRoot\system32\DRIVERS\SCSIPORT.SYS
0x88664000 \SystemRoot\system32\DRIVERS\swenum.sys
0x8BCE3000 \SystemRoot\system32\DRIVERS\ks.sys
0x8BCD9000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x8BD50000 \SystemRoot\system32\DRIVERS\umbus.sys
0x8BC95000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x8B0BB000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x88780000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x8C256000 \SystemRoot\system32\drivers\RTKVHDA.sys
0x8BC1B000 \SystemRoot\system32\drivers\portcls.sys
0x8C231000 \SystemRoot\system32\drivers\drmk.sys
0x8B0CD000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x8B168000 \SystemRoot\System32\Drivers\Null.SYS
0x8B16F000 \SystemRoot\System32\Drivers\Beep.SYS
0x8C225000 \SystemRoot\System32\drivers\vga.sys
0x8C204000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x8A9F8000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x88658000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8BC00000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8C7D2000 \SystemRoot\System32\Drivers\Npfs.SYS
0x8B0D6000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x8C66D000 \SystemRoot\System32\drivers\tcpip.sys
0x8C654000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8C9EB000 \SystemRoot\system32\DRIVERS\tdx.sys
0x8C600000 \SystemRoot\system32\DRIVERS\smb.sys
0x8C9A4000 \SystemRoot\system32\drivers\afd.sys
0x8C972000 \SystemRoot\System32\DRIVERS\netbt.sys
0x8C95C000 \SystemRoot\system32\DRIVERS\pacer.sys
0x8C94E000 \SystemRoot\system32\DRIVERS\netbios.sys
0x8866C000 \SystemRoot\system32\DRIVERS\eabfiltr.sys
0x8C93B000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x8C92A000 \SystemRoot\System32\Drivers\SRTSPX.SYS
0x8C8EF000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x8C8E5000 \SystemRoot\system32\drivers\nsiproxy.sys
0x8C883000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
0x8C86C000 \SystemRoot\System32\Drivers\dfsc.sys
0x8C805000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x8A90F000 \SystemRoot\System32\Drivers\usbvideo.sys
0x8A8D4000 \SystemRoot\system32\DRIVERS\udfs.sys
0x8A8BE000 \SystemRoot\system32\DRIVERS\cdfs.sys
0x8BC48000 \SystemRoot\System32\Drivers\crashdmp.sys
0x8E142000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0x8C76F000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x8A990000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x94600000 \SystemRoot\System32\win32k.sys
0x8A876000 \SystemRoot\System32\drivers\Dxapi.sys
0x8B916000 \SystemRoot\system32\DRIVERS\monitor.sys
0xA5E00000 \SystemRoot\System32\TSDDD.dll
0xA5E10000 \SystemRoot\System32\cdd.dll
0xA5E20000 \SystemRoot\System32\ATMFD.DLL
0x95285000 \SystemRoot\system32\drivers\luafv.sys
0xA9372000 \SystemRoot\system32\drivers\spsys.sys
0x95200000 \SystemRoot\system32\DRIVERS\lltdio.sys
0xA9347000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x8A8A4000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xA9334000 \SystemRoot\system32\DRIVERS\rspndr.sys
0xAAC07000 \SystemRoot\system32\drivers\HTTP.sys
0xAAE45000 \SystemRoot\System32\DRIVERS\srvnet.sys
0xAC5C7000 \SystemRoot\system32\DRIVERS\bowser.sys
0xAC5B3000 \SystemRoot\System32\drivers\mpsdrv.sys
0xAC593000 \SystemRoot\system32\drivers\mrxdav.sys
0xAC575000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xABFC7000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0xAA5E0000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0xABFA3000 \SystemRoot\System32\DRIVERS\srv2.sys
0xABF52000 \SystemRoot\System32\DRIVERS\srv.sys
0xAD922000 \SystemRoot\system32\drivers\peauth.sys
0xAAD60000 \SystemRoot\System32\Drivers\secdrv.SYS
0xAACBB000 \SystemRoot\System32\drivers\tcpipreg.sys
0xADD36000 \SystemRoot\System32\Drivers\SRTSP.SYS
0xADC67000 \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20070430.018\NAVEX15.SYS
0xAA4E3000 \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20070430.018\NAVENG.SYS
0x8ACDC000 \SystemRoot\System32\Drivers\fastfat.SYS
0x8C78A000 \SystemRoot\system32\DRIVERS\asyncmac.sys
0xCAA36000 \SystemRoot\System32\Drivers\usbaapl.sys
0x77100000 \Windows\System32\ntdll.dll
Processes (total 82):
0 System Idle Process
4 System
456 C:\Windows\System32\smss.exe
588 csrss.exe
628 C:\Windows\System32\wininit.exe
640 csrss.exe
672 C:\Windows\System32\services.exe
684 C:\Windows\System32\lsass.exe
692 C:\Windows\System32\lsm.exe
796 C:\Windows\System32\winlogon.exe
888 C:\Windows\System32\svchost.exe
944 C:\Windows\System32\svchost.exe
980 C:\Windows\System32\svchost.exe
1072 C:\Windows\System32\svchost.exe
1100 C:\Windows\System32\svchost.exe
1144 C:\Windows\System32\svchost.exe
1252 C:\Windows\System32\audiodg.exe
1284 C:\Windows\System32\SLsvc.exe
1344 C:\Windows\System32\svchost.exe
1520 C:\Windows\System32\svchost.exe
1700 C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
1768 C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
1940 C:\Windows\System32\dwm.exe
1960 C:\Windows\explorer.exe
2008 C:\Windows\System32\spoolsv.exe
2024 C:\Windows\System32\taskeng.exe
2044 C:\Windows\System32\svchost.exe
1044 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
884 C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
504 C:\Program Files\Bonjour\mDNSResponder.exe
2052 C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
2108 C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
2144 C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
2164 C:\Program Files\Common Files\LightScribe\LSSrvc.exe
2228 C:\Windows\System32\svchost.exe
2292 C:\Windows\System32\svchost.exe
2468 C:\Windows\System32\svchost.exe
2648 C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
3532 C:\Windows\System32\taskeng.exe
3908 C:\Program Files\Windows Defender\MSASCui.exe
3928 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
3944 WmiPrvSE.exe
3996 C:\Windows\System32\igfxtray.exe
4008 C:\Windows\System32\hkcmd.exe
4016 C:\Windows\System32\igfxpers.exe
4064 C:\Windows\RtHDVCpl.exe
4080 C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
2080 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
1892 C:\Program Files\HP\QuickPlay\QPService.exe
2128 C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
2668 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
2856 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
1136 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
2948 C:\Program Files\Java\jre6\bin\jusched.exe
3000 C:\Program Files\Winamp\winampa.exe
2636 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
3028 C:\Program Files\DivX\DivX Update\DivXUpdate.exe
1032 C:\Program Files\iTunes\iTunesHelper.exe
2852 WmiPrvSE.exe
3116 C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
3184 C:\Program Files\Windows Sidebar\sidebar.exe
3260 C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
3056 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
3092 C:\Program Files\uTorrent\uTorrent.exe
3152 C:\Program Files\Windows Media Player\wmpnscfg.exe
3660 C:\Windows\System32\wbem\unsecapp.exe
2640 C:\Program Files\Windows Media Player\wmpnetwk.exe
3124 C:\Windows\System32\igfxsrvc.exe
4188 C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
4268 C:\Program Files\iPod\bin\iPodService.exe
4504 C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
4656 C:\Windows\System32\conime.exe
4712 C:\Program Files\Hewlett-Packard\HP Advisor\SSDK04.exe
3136 C:\Program Files\Java\jre6\bin\jucheck.exe
5624 C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
5600 C:\Windows\servicing\TrustedInstaller.exe
4488 C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
4552 C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
5952 C:\Windows\System32\SearchIndexer.exe
5716 C:\Windows\System32\wuauclt.exe
4104 C:\Program Files\Mozilla Firefox\firefox.exe
1684 C:\Users\sneha\Desktop\MBRCheck.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\D: --> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (NTFS)
\\.\E: --> \\.\PhysicalDrive0 at offset 0x00000019`e1709400 (NTFS)
PhysicalDrive0 Model Number: FUJITSUMHY2120BH, Rev: 890B
PhysicalDrive1 Model Number: WDCWD800BEVS-60RST0, Rev: 04.01G04
Size Device Name MBR Status
--------------------------------------------
111 GB \\.\PhysicalDrive0 Unknown MBR code
SHA1: D94F393960D1CD66C2071F2D7260A5196DF105AC
74 GB \\.\PhysicalDrive1 Windows XP MBR code detected
SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
Options:
[1] Dump the MBR of a physical disk to file.
[2] Restore the MBR of a physical disk with a standard boot code.
[3] Exit.
Enter your choice: Enter the physical disk number to fix (0-99, -1 to cancel): 0Available MBR codes:
[ 0] Default (Windows Vista)
[ 1] Windows XP
[ 2] Windows Server 2003
[ 3] Windows Vista
[ 4] Windows 2008
[ 5] Windows 7
[-1] Cancel
Please select the MBR code to write to this drive: 3
Do you want to fix the MBR code? Type 'YES' and hit ENTER to continue: yes
Successfully wrote new MBR code!
Please reboot your computer to complete the fix.
Done!
-
Here is today's log:
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: (build 6000), 32-bit
Base Board Manufacturer: Quanta
BIOS Manufacturer: Hewlett-Packard
System Manufacturer: Hewlett-Packard
System Product Name: HP Pavilion dx6500 Notebook PC
Logical Drives Mask: 0x000001fc
Kernel Drivers (total 153):
0x81C00000 \SystemRoot\system32\ntkrnlpa.exe
0x81FA1000 \SystemRoot\system32\hal.dll
0x802C6000 \SystemRoot\system32\kdcom.dll
0x80266000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x8025D000 \SystemRoot\system32\PSHED.dll
0x80255000 \SystemRoot\system32\BOOTVID.dll
0x8021A000 \SystemRoot\system32\CLFS.SYS
0x8051F000 \SystemRoot\system32\CI.dll
0x804A4000 \SystemRoot\system32\drivers\Wdf01000.sys
0x8020D000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x80461000 \SystemRoot\system32\drivers\acpi.sys
0x80204000 \SystemRoot\system32\drivers\WMILIB.SYS
0x80459000 \SystemRoot\system32\drivers\msisadrv.sys
0x80434000 \SystemRoot\system32\drivers\pci.sys
0x80425000 \SystemRoot\system32\drivers\volmgr.sys
0x80201000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x8041B000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x8040B000 \SystemRoot\System32\drivers\mountmgr.sys
0x80404000 \SystemRoot\system32\DRIVERS\pciide.sys
0x807F2000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
0x807A8000 \SystemRoot\System32\drivers\volmgrx.sys
0x806EA000 \SystemRoot\system32\DRIVERS\iaStor.sys
0x806E2000 \SystemRoot\system32\drivers\atapi.sys
0x806C4000 \SystemRoot\system32\drivers\ataport.SYS
0x80693000 \SystemRoot\system32\drivers\fltmgr.sys
0x80683000 \SystemRoot\system32\drivers\fileinfo.sys
0x8067A000 \SystemRoot\System32\Drivers\PxHelp20.sys
0x876FC000 \SystemRoot\system32\drivers\ndis.sys
0x8064F000 \SystemRoot\system32\drivers\msrpc.sys
0x80616000 \SystemRoot\system32\drivers\NETIO.SYS
0x878F8000 \SystemRoot\System32\Drivers\Ntfs.sys
0x87692000 \SystemRoot\System32\Drivers\ksecdd.sys
0x8765C000 \SystemRoot\system32\drivers\volsnap.sys
0x8060E000 \SystemRoot\System32\Drivers\spldr.sys
0x8764D000 \SystemRoot\System32\drivers\partmgr.sys
0x8763E000 \SystemRoot\System32\Drivers\mup.sys
0x87619000 \SystemRoot\System32\drivers\ecache.sys
0x87608000 \SystemRoot\system32\drivers\disk.sys
0x878D7000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x80605000 \SystemRoot\system32\drivers\crcdisk.sys
0x88A6A000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x88B2C000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x88A33000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x88B35000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x88A7E000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x8B21A000 \SystemRoot\system32\DRIVERS\igdkmd32.sys
0x8AE15000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x88A97000 \SystemRoot\System32\drivers\watchdog.sys
0x8AE0A000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x8B9C3000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x8B20C000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x8B961000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x8BDD9000 \SystemRoot\system32\DRIVERS\NETw4v32.sys
0x8B94A000 \SystemRoot\system32\DRIVERS\Rtlh86.sys
0x88770000 \SystemRoot\system32\DRIVERS\ohci1394.sys
0x8B8CC000 \SystemRoot\system32\DRIVERS\1394BUS.SYS
0x8B8B4000 \SystemRoot\system32\DRIVERS\sdbus.sys
0x88610000 \SystemRoot\system32\DRIVERS\rimmptsk.sys
0x8B8A0000 \SystemRoot\system32\DRIVERS\rimsptsk.sys
0x8B84F000 \SystemRoot\system32\DRIVERS\rixdptsk.sys
0x8AF18000 \SystemRoot\system32\DRIVERS\cpqbttn.sys
0x88780000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x8B8E1000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x8B83C000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x8B201000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x8B811000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x88BE4000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x8B806000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x8B9AB000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x8AED0000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x8BDAE000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x8BD6E000 \SystemRoot\system32\DRIVERS\storport.sys
0x8B9A0000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8BD57000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x8BD4C000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x8BD29000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x8861F000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x8BD16000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x8862E000 \SystemRoot\system32\DRIVERS\termdd.sys
0x8BCEC000 \SystemRoot\system32\DRIVERS\mcdbus.sys
0x8BCC6000 \SystemRoot\system32\DRIVERS\SCSIPORT.SYS
0x88BE0000 \SystemRoot\system32\DRIVERS\swenum.sys
0x8BC9C000 \SystemRoot\system32\DRIVERS\ks.sys
0x8AE00000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x8BD09000 \SystemRoot\system32\DRIVERS\umbus.sys
0x8BC68000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x88B62000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x887D0000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x8C056000 \SystemRoot\system32\drivers\RTKVHDA.sys
0x8C029000 \SystemRoot\system32\drivers\portcls.sys
0x8C004000 \SystemRoot\system32\drivers\drmk.sys
0x88B6B000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x8B920000 \SystemRoot\System32\Drivers\Null.SYS
0x8B927000 \SystemRoot\System32\Drivers\Beep.SYS
0x8C5E4000 \SystemRoot\System32\drivers\vga.sys
0x8C5C3000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x88B0C000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x88B14000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8C598000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8BC0A000 \SystemRoot\System32\Drivers\Npfs.SYS
0x88B74000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x8C4C3000 \SystemRoot\System32\drivers\tcpip.sys
0x8C4AA000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8C495000 \SystemRoot\system32\DRIVERS\tdx.sys
0x8C481000 \SystemRoot\system32\DRIVERS\smb.sys
0x8C43A000 \SystemRoot\system32\drivers\afd.sys
0x8C408000 \SystemRoot\System32\DRIVERS\netbt.sys
0x8C7EA000 \SystemRoot\system32\DRIVERS\pacer.sys
0x8C7DC000 \SystemRoot\system32\DRIVERS\netbios.sys
0x88BD6000 \SystemRoot\system32\DRIVERS\eabfiltr.sys
0x8C7C9000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x8C7B8000 \SystemRoot\System32\Drivers\SRTSPX.SYS
0x8C77D000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x8B996000 \SystemRoot\system32\drivers\nsiproxy.sys
0x8C63B000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
0x8C624000 \SystemRoot\System32\Drivers\dfsc.sys
0x88B59000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x88AB4000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x8D9E9000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x8D9C8000 \SystemRoot\System32\Drivers\usbvideo.sys
0x8AFC5000 \SystemRoot\system32\DRIVERS\udfs.sys
0x8AFAF000 \SystemRoot\system32\DRIVERS\cdfs.sys
0x88A0A000 \SystemRoot\System32\Drivers\crashdmp.sys
0x8D83A000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0x94800000 \SystemRoot\System32\win32k.sys
0x8C69D000 \SystemRoot\System32\drivers\Dxapi.sys
0x8865B000 \SystemRoot\system32\DRIVERS\monitor.sys
0xA5800000 \SystemRoot\System32\TSDDD.dll
0xA5810000 \SystemRoot\System32\cdd.dll
0xA5820000 \SystemRoot\System32\ATMFD.DLL
0xA64E5000 \SystemRoot\system32\drivers\luafv.sys
0xA7F72000 \SystemRoot\system32\drivers\spsys.sys
0x887B0000 \SystemRoot\system32\DRIVERS\lltdio.sys
0xA7E35000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x8C6C5000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xA705D000 \SystemRoot\system32\DRIVERS\rspndr.sys
0xAB353000 \SystemRoot\system32\drivers\HTTP.sys
0xAA401000 \SystemRoot\System32\DRIVERS\srvnet.sys
0xAA523000 \SystemRoot\system32\DRIVERS\bowser.sys
0xAA50F000 \SystemRoot\System32\drivers\mpsdrv.sys
0xAB2F3000 \SystemRoot\system32\drivers\mrxdav.sys
0xAB2D5000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xAB29C000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0xAB28A000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0xAB266000 \SystemRoot\System32\DRIVERS\srv2.sys
0xABBAF000 \SystemRoot\System32\DRIVERS\srv.sys
0xAD122000 \SystemRoot\system32\drivers\peauth.sys
0x8C71F000 \SystemRoot\System32\Drivers\secdrv.SYS
0xA7ECE000 \SystemRoot\System32\drivers\tcpipreg.sys
0xAE0F6000 \SystemRoot\System32\Drivers\SRTSP.SYS
0xAE027000 \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20070430.018\NAVEX15.SYS
0xABA09000 \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20070430.018\NAVENG.SYS
0x777E0000 \Windows\System32\ntdll.dll
Processes (total 82):
0 System Idle Process
4 System
456 C:\Windows\System32\smss.exe
544 csrss.exe
584 C:\Windows\System32\wininit.exe
596 csrss.exe
628 C:\Windows\System32\services.exe
640 C:\Windows\System32\lsass.exe
648 C:\Windows\System32\lsm.exe
724 C:\Windows\System32\winlogon.exe
840 C:\Windows\System32\svchost.exe
900 C:\Windows\System32\svchost.exe
936 C:\Windows\System32\svchost.exe
1024 C:\Windows\System32\svchost.exe
1048 C:\Windows\System32\svchost.exe
1068 C:\Windows\System32\svchost.exe
1132 C:\Windows\System32\audiodg.exe
1176 C:\Windows\System32\SLsvc.exe
1212 C:\Windows\System32\svchost.exe
1348 C:\Windows\System32\svchost.exe
1624 C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
1732 C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
1852 C:\Windows\System32\dwm.exe
1876 C:\Windows\explorer.exe
1940 C:\Windows\System32\spoolsv.exe
1948 C:\Windows\System32\taskeng.exe
1972 C:\Windows\System32\svchost.exe
1536 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
1820 C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
1552 C:\Program Files\Bonjour\mDNSResponder.exe
1432 C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
1764 C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
2060 C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
2084 C:\Program Files\Common Files\LightScribe\LSSrvc.exe
2212 C:\Windows\System32\svchost.exe
2288 C:\Windows\System32\svchost.exe
2364 C:\Windows\System32\svchost.exe
2400 C:\Windows\System32\SearchIndexer.exe
2540 C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
2792 WmiPrvSE.exe
2876 C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
3040 C:\Windows\System32\taskeng.exe
3312 C:\Program Files\Windows Defender\MSASCui.exe
3320 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
3356 C:\Windows\System32\igfxtray.exe
3396 C:\Windows\System32\hkcmd.exe
3452 C:\Windows\System32\igfxsrvc.exe
3468 C:\Windows\System32\igfxpers.exe
3532 C:\Windows\RtHDVCpl.exe
3544 C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
3552 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
3584 C:\Program Files\HP\QuickPlay\QPService.exe
3592 C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
3620 C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
3632 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
3652 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
3660 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
3676 C:\Program Files\Java\jre6\bin\jusched.exe
3684 C:\Program Files\Winamp\winampa.exe
3692 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
3716 C:\Program Files\DivX\DivX Update\DivXUpdate.exe
3728 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
3748 C:\Program Files\iTunes\iTunesHelper.exe
3960 WmiPrvSE.exe
4036 C:\Program Files\Windows Sidebar\sidebar.exe
1824 C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
2236 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
1704 C:\Program Files\uTorrent\uTorrent.exe
1860 C:\Program Files\Windows Media Player\wmpnscfg.exe
3516 C:\Windows\System32\wbem\unsecapp.exe
3244 C:\Program Files\Windows Media Player\wmpnetwk.exe
4220 C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
4228 C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
4340 C:\Program Files\iPod\bin\iPodService.exe
4532 C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
4972 C:\Program Files\Hewlett-Packard\HP Advisor\SSDK04.exe
5088 C:\Windows\System32\SearchProtocolHost.exe
5328 C:\Windows\System32\SearchFilterHost.exe
5928 dllhost.exe
5964 dllhost.exe
5992 C:\Users\sneha\Desktop\MBRCheck.exe
6004 C:\Windows\System32\conime.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\D: --> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (NTFS)
\\.\E: --> \\.\PhysicalDrive0 at offset 0x00000019`e1709400 (NTFS)
PhysicalDrive0 Model Number: FUJITSUMHY2120BH, Rev: 890B
PhysicalDrive1 Model Number: WDCWD800BEVS-60RST0, Rev: 04.01G04
Size Device Name MBR Status
--------------------------------------------
111 GB \\.\PhysicalDrive0 Unknown MBR code
SHA1: D94F393960D1CD66C2071F2D7260A5196DF105AC
74 GB \\.\PhysicalDrive1 Windows XP MBR code detected
SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
Options:
[1] Dump the MBR of a physical disk to file.
[2] Restore the MBR of a physical disk with a standard boot code.
[3] Exit.
Enter your choice:
-
Your last post was September 9th, so with this pace, it'll take a while to fix your computer and on a top of it, if you keep using it in its current state, we'll be going circles.
Please download NTBR by noahdfear and save it to your Desktop.
File size: 2.44 MB (2,565,432 bytes)
- Place a blank CD in your CD drive.
- Double click on NTBR_CD.exe file and a folder of the same name will appear.
- Open the folder and double click on BurnItCD.cmd file. If your CD drive will open, simply close it back.
- Follow the prompts to burn the CD.
- Now you will need to set the CD-Rom as first boot device if it isn't already (if you don't know how to do it, see HERE)
- If you have any questions about this step, ask before you proceed. If you enter the BIOS and are unsure if you have carried out the step correctly, there should be an option to exit without keeping changes, so you won't do any harm.
- Insert the newly created CD into your infected PC and reboot your computer.
- Once you have rebooted please press Enter when prompted to continue booting from CD - you have a whole 15 seconds to do this!
- Read the warning and then continue as prompted.
- You first need to select your keyboard layout - press Enter for English.
- Next you want to select the appropriate tool. Enter 1 to choose 1. MBRWORK
- On the following screen enter 5 to select Install Standard MBR code.
- Enter 1 to overwrite the infected MBR Code with the Standard MBR code.
- When asked to confirm please do so.
- Afterwards, please enter E to leave MBRWORK, then 6 to leave the bootable CD.
- Eject the disc and then press ctrl+alt+del to reboot the PC.
Once rebooted, run MBRCheck again and post its log.