WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionRedirect Trojan or Malware - Page 1 EmptyRe: Redirect Trojan or Malware

more_horiz
Download MBRCheck to your desktop.

  • Double click MBRCheck.exe to run (Vista and Windows 7 users, right click and select Run as Administrator).
  • It will show a black screen with some data on it.
  • A report called MBRcheckxxxx.txt will be on your desktop
  • Open this report and post its content in your next reply.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Redirect Trojan or Malware - Page 1 DXwU4
Redirect Trojan or Malware - Page 1 VvYDg

descriptionRedirect Trojan or Malware - Page 1 EmptyRe: Redirect Trojan or Malware

more_horiz
MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows 7 Home Premium Edition
Windows Information: (build 7600), 64-bit
Base Board Manufacturer: Quanta
BIOS Manufacturer: Hewlett-Packard
System Manufacturer: Hewlett-Packard
System Product Name: HP Pavilion dv6 Notebook PC
Logical Drives Mask: 0x0000001c

Kernel Drivers (total 235):
0x02C1D000 \SystemRoot\system32\ntoskrnl.exe
0x031F9000 \SystemRoot\system32\hal.dll
0x00B9F000 \SystemRoot\system32\kdcom.dll
0x00C8B000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x00CCF000 \SystemRoot\system32\PSHED.dll
0x00CE3000 \SystemRoot\system32\CLFS.SYS
0x00E2E000 \SystemRoot\system32\CI.dll
0x00EEE000 \SystemRoot\system32\drivers\Wdf01000.sys
0x00F92000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x00FA1000 \SystemRoot\system32\DRIVERS\ACPI.sys
0x00E00000 \SystemRoot\system32\DRIVERS\WMILIB.SYS
0x00E09000 \SystemRoot\system32\DRIVERS\msisadrv.sys
0x00D41000 \SystemRoot\system32\DRIVERS\pci.sys
0x00E13000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
0x00E20000 \SystemRoot\system32\DRIVERS\isapnp.sys
0x00D74000 \SystemRoot\system32\DRIVERS\mpio.sys
0x00D9E000 \SystemRoot\System32\drivers\partmgr.sys
0x00DB3000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x00DBC000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x00DC8000 \SystemRoot\system32\DRIVERS\volmgr.sys
0x00C00000 \SystemRoot\System32\drivers\volmgrx.sys
0x00FF8000 \SystemRoot\system32\DRIVERS\intelide.sys
0x00C5C000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
0x00C6C000 \SystemRoot\system32\DRIVERS\aliide.sys
0x00C73000 \SystemRoot\system32\DRIVERS\amdide.sys
0x00C7A000 \SystemRoot\system32\DRIVERS\cmdide.sys
0x00DDD000 \SystemRoot\System32\drivers\mountmgr.sys
0x01069000 \SystemRoot\system32\DRIVERS\msdsm.sys
0x0108F000 \SystemRoot\system32\DRIVERS\nvraid.sys
0x010B8000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x010E8000 \SystemRoot\system32\DRIVERS\pciide.sys
0x010EF000 \SystemRoot\system32\DRIVERS\viaide.sys
0x0128A000 \SystemRoot\system32\DRIVERS\iaStorV.sys
0x013A8000 \SystemRoot\system32\DRIVERS\atapi.sys
0x013B1000 \SystemRoot\system32\DRIVERS\ataport.SYS
0x013DB000 \SystemRoot\system32\DRIVERS\lsi_sas.sys
0x01200000 \SystemRoot\system32\DRIVERS\storport.sys
0x01262000 \SystemRoot\system32\DRIVERS\msahci.sys
0x0126D000 \SystemRoot\system32\DRIVERS\HpSAMD.sys
0x010F7000 \SystemRoot\system32\DRIVERS\adp94xx.sys
0x01172000 \SystemRoot\system32\DRIVERS\adpahci.sys
0x011C8000 \SystemRoot\system32\DRIVERS\adpu320.sys
0x01000000 \SystemRoot\system32\DRIVERS\amdsata.sys
0x0101E000 \SystemRoot\system32\DRIVERS\amdsbs.sys
0x01492000 \SystemRoot\system32\DRIVERS\amdxata.sys
0x0149D000 \SystemRoot\system32\DRIVERS\arc.sys
0x014B6000 \SystemRoot\system32\DRIVERS\arcsas.sys
0x014D1000 \SystemRoot\system32\DRIVERS\elxstor.sys
0x01558000 \SystemRoot\system32\DRIVERS\iirsp.sys
0x01569000 \SystemRoot\system32\DRIVERS\lsi_fc.sys
0x01588000 \SystemRoot\system32\DRIVERS\lsi_sas2.sys
0x0159B000 \SystemRoot\system32\DRIVERS\lsi_scsi.sys
0x015BA000 \SystemRoot\system32\DRIVERS\megasas.sys
0x016EB000 \SystemRoot\system32\DRIVERS\MegaSR.sys
0x0178F000 \SystemRoot\system32\DRIVERS\nfrd960.sys
0x0179F000 \SystemRoot\system32\DRIVERS\nvstor.sys
0x01831000 \SystemRoot\system32\DRIVERS\ql2300.sys
0x01600000 \SystemRoot\system32\DRIVERS\ql40xx.sys
0x019D5000 \SystemRoot\system32\DRIVERS\SiSRaid2.sys
0x019E3000 \SystemRoot\system32\DRIVERS\sisraid4.sys
0x01800000 \SystemRoot\system32\DRIVERS\stexstor.sys
0x0165F000 \SystemRoot\system32\DRIVERS\vsmraid.sys
0x01689000 \SystemRoot\system32\drivers\fltmgr.sys
0x0180A000 \SystemRoot\system32\drivers\fileinfo.sys
0x01A23000 \SystemRoot\System32\Drivers\Ntfs.sys
0x01400000 \SystemRoot\System32\Drivers\msrpc.sys
0x01BC6000 \SystemRoot\System32\Drivers\ksecdd.sys
0x01C28000 \SystemRoot\System32\Drivers\cng.sys
0x01C9B000 \SystemRoot\System32\drivers\pcw.sys
0x01CAC000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x01CB6000 \SystemRoot\system32\drivers\ndis.sys
0x01E68000 \SystemRoot\system32\drivers\NETIO.SYS
0x01EC8000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x02003000 \SystemRoot\System32\drivers\tcpip.sys
0x01EF3000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x01F3D000 \SystemRoot\system32\DRIVERS\wd.sys
0x01F45000 \SystemRoot\system32\DRIVERS\volsnap.sys
0x01F91000 \SystemRoot\System32\Drivers\spldr.sys
0x01F99000 \SystemRoot\system32\DRIVERS\sbp2port.sys
0x01FB6000 \SystemRoot\System32\drivers\rdyboost.sys
0x01E00000 \SystemRoot\System32\Drivers\mup.sys
0x01E12000 \SystemRoot\System32\drivers\hwpolicy.sys
0x01E1B000 \SystemRoot\system32\DRIVERS\hpdskflt.sys
0x01E25000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x01DA8000 \SystemRoot\system32\DRIVERS\disk.sys
0x017CA000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x01E5F000 \SystemRoot\System32\Drivers\Null.SYS
0x01DE8000 \SystemRoot\System32\Drivers\Beep.SYS
0x01DEF000 \SystemRoot\System32\drivers\vga.sys
0x01C00000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x01BE0000 \SystemRoot\System32\drivers\watchdog.sys
0x01BF0000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x01A00000 \SystemRoot\system32\drivers\rdpencdd.sys
0x01A09000 \SystemRoot\system32\drivers\rdprefmp.sys
0x01A12000 \SystemRoot\System32\Drivers\Msfs.SYS
0x0181E000 \SystemRoot\System32\Drivers\Npfs.SYS
0x0145E000 \SystemRoot\system32\DRIVERS\tdx.sys
0x016D5000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x034A8000 \SystemRoot\System32\Drivers\avgtdia.sys
0x034F9000 \SystemRoot\System32\DRIVERS\netbt.sys
0x0353E000 \SystemRoot\system32\drivers\afd.sys
0x035C8000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x035D1000 \SystemRoot\system32\DRIVERS\pacer.sys
0x03400000 \SystemRoot\system32\DRIVERS\vwififlt.sys
0x03416000 \SystemRoot\system32\DRIVERS\netbios.sys
0x03442000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x0345D000 \SystemRoot\system32\DRIVERS\termdd.sys
0x04235000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x04286000 \SystemRoot\system32\drivers\nsiproxy.sys
0x04292000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x0429D000 \SystemRoot\System32\drivers\discache.sys
0x042AC000 \SystemRoot\System32\Drivers\dfsc.sys
0x042CA000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x042DB000 \SystemRoot\System32\Drivers\avgmfx64.sys
0x042E3000 \SystemRoot\System32\Drivers\avgldx64.sys
0x0432A000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x04350000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x04366000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x044CA000 \SystemRoot\system32\DRIVERS\igdkmd64.sys
0x04CB5000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x04DA9000 \SystemRoot\System32\drivers\dxgmms1.sys
0x04DEF000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x04C00000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x04C56000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x04C67000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x050E1000 \SystemRoot\system32\DRIVERS\bcmwl664.sys
0x05389000 \SystemRoot\system32\DRIVERS\vwifibus.sys
0x053D3000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x053F1000 \SystemRoot\system32\DRIVERS\HpqKbFiltr.sys
0x05000000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x0500F000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x05058000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x0505A000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x05069000 \SystemRoot\system32\DRIVERS\enecir.sys
0x05086000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x05093000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x0509C000 \SystemRoot\system32\DRIVERS\Accelerometer.sys
0x050A8000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x050B8000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x04C8B000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x050CE000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x04BC9000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x04400000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x0441B000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x0443C000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x050DA000 \SystemRoot\system32\DRIVERS\swenum.sys
0x04456000 \SystemRoot\system32\DRIVERS\ks.sys
0x04499000 \SystemRoot\system32\DRIVERS\circlass.sys
0x044AB000 \SystemRoot\system32\DRIVERS\umbus.sys
0x0436B000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x043C5000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x06292000 \SystemRoot\system32\DRIVERS\stwrt64.sys
0x0630D000 \SystemRoot\system32\DRIVERS\portcls.sys
0x0634A000 \SystemRoot\system32\DRIVERS\drmk.sys
0x0636C000 \SystemRoot\system32\drivers\ksthunk.sys
0x06372000 \SystemRoot\system32\drivers\IntcHdmi.sys
0x06399000 \SystemRoot\system32\DRIVERS\hidir.sys
0x063AA000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x063C3000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x063CC000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x063DA000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x00060000 \SystemRoot\System32\win32k.sys
0x063E7000 \SystemRoot\System32\drivers\Dxapi.sys
0x06200000 \SystemRoot\System32\Drivers\crashdmp.sys
0x0620E000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x0621A000 \SystemRoot\System32\Drivers\dump_msahci.sys
0x06225000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x06238000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x06255000 \SystemRoot\System32\Drivers\usbvideo.sys
0x00590000 \SystemRoot\System32\TSDDD.dll
0x00850000 \SystemRoot\System32\ATMFD.DLL
0x05396000 \SystemRoot\system32\drivers\luafv.sys
0x043DA000 \SystemRoot\system32\drivers\WudfPf.sys
0x053B9000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x02E61000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x02EB4000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x02EC7000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x02EDF000 \SystemRoot\system32\DRIVERS\vwifimp.sys
0x02EE9000 \SystemRoot\system32\drivers\HTTP.sys
0x02FB1000 \SystemRoot\system32\DRIVERS\bowser.sys
0x02FCF000 \SystemRoot\System32\drivers\mpsdrv.sys
0x02E00000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x032F3000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x03341000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x03200000 \SystemRoot\system32\drivers\peauth.sys
0x032A6000 \SystemRoot\System32\Drivers\secdrv.SYS
0x032B1000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x032DE000 \SystemRoot\System32\drivers\tcpipreg.sys
0x03364000 \SystemRoot\System32\DRIVERS\srv2.sys
0x04E94000 \SystemRoot\System32\DRIVERS\srv.sys
0x04E00000 \SystemRoot\System32\Drivers\fastfat.SYS
0x00770000 \SystemRoot\System32\cdd.dll
0x04FB2000 \SystemRoot\system32\drivers\MSPQM.sys
0x04FB4000 \SystemRoot\system32\drivers\MSPCLOCK.sys
0x04F5B000 \SystemRoot\system32\DRIVERS\monitor.sys
0x77B30000 \Windows\System32\ntdll.dll
0x48460000 \Windows\System32\smss.exe
0xFFE50000 \Windows\System32\apisetschema.dll
0xFF230000 \Windows\System32\autochk.exe
0xFFDA0000 \Windows\System32\comdlg32.dll
0xFFD90000 \Windows\System32\nsi.dll
0xFFC60000 \Windows\System32\rpcrt4.dll
0xFFB80000 \Windows\System32\advapi32.dll
0xFF970000 \Windows\System32\ole32.dll
0xFF960000 \Windows\System32\lpk.dll
0xFF880000 \Windows\System32\oleaut32.dll
0xFEAF0000 \Windows\System32\shell32.dll
0xFE890000 \Windows\System32\iertutil.dll
0xFE7F0000 \Windows\System32\clbcatq.dll
0xFE610000 \Windows\System32\setupapi.dll
0xFE5E0000 \Windows\System32\imm32.dll
0xFE4D0000 \Windows\System32\msctf.dll
0xFE350000 \Windows\System32\urlmon.dll
0xFE280000 \Windows\System32\usp10.dll
0xFE230000 \Windows\System32\ws2_32.dll
0x77D00000 \Windows\System32\normaliz.dll
0xFE210000 \Windows\System32\imagehlp.dll
0xFE190000 \Windows\System32\shlwapi.dll
0xFE060000 \Windows\System32\wininet.dll
0x77CF0000 \Windows\System32\psapi.dll
0xFE010000 \Windows\System32\Wldap32.dll
0xFDF90000 \Windows\System32\difxapi.dll
0x77A30000 \Windows\System32\user32.dll
0xFDF20000 \Windows\System32\gdi32.dll
0xFDE80000 \Windows\System32\msvcrt.dll
0x77910000 \Windows\System32\kernel32.dll
0xFDE60000 \Windows\System32\sechost.dll
0xFDDC0000 \Windows\System32\comctl32.dll
0xFDD80000 \Windows\System32\cfgmgr32.dll
0xFDC10000 \Windows\System32\crypt32.dll
0xFDBF0000 \Windows\System32\devobj.dll
0xFDB80000 \Windows\System32\KernelBase.dll
0xFDB40000 \Windows\System32\wintrust.dll
0xFDB30000 \Windows\System32\msasn1.dll
0x77CE0000 \Windows\SysWOW64\normaliz.dll

Processes (total 86):
0 System Idle Process
4 System
272 C:\Windows\System32\smss.exe
384 csrss.exe
436 C:\Windows\System32\wininit.exe
448 csrss.exe
456 C:\Program Files (x86)\AVG\AVG9\avgchsva.exe
468 C:\Program Files (x86)\AVG\AVG9\avgrsa.exe
564 C:\Windows\System32\services.exe
580 C:\Windows\System32\lsass.exe
588 C:\Windows\System32\lsm.exe
624 C:\Windows\System32\winlogon.exe
660 C:\Program Files (x86)\AVG\AVG9\avgcsrva.exe
312 C:\Windows\System32\svchost.exe
556 C:\Windows\System32\svchost.exe
1028 C:\Windows\System32\svchost.exe
1096 C:\Windows\System32\svchost.exe
1136 C:\Windows\System32\svchost.exe
1168 C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\stacsv64.exe
1340 C:\Windows\System32\svchost.exe
1404 C:\Windows\System32\hpservice.exe
1512 C:\Windows\System32\svchost.exe
1624 C:\Windows\System32\wlanext.exe
1632 C:\Windows\System32\conhost.exe
1772 C:\Windows\System32\svchost.exe
1856 C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe
1900 C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
1924 C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
1952 C:\Program Files (x86)\Bonjour\mDNSResponder.exe
2004 C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
1496 C:\Windows\System32\svchost.exe
1116 C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe
2024 C:\Program Files (x86)\AVG\AVG9\avgnsa.exe
2228 C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
2292 C:\Windows\System32\svchost.exe
2356 C:\Program Files (x86)\AVG\AVG9\avgemc.exe
2468 C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
2592 unsecapp.exe
2736 WmiPrvSE.exe
2844 C:\Windows\System32\taskhost.exe
2916 C:\Windows\System32\dwm.exe
2980 C:\Windows\explorer.exe
2120 C:\Program Files (x86)\AVG\AVG9\avgcsrvx.exe
3328 C:\Windows\System32\igfxtray.exe
3380 C:\Windows\System32\hkcmd.exe
3388 C:\Windows\System32\igfxpers.exe
3404 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
3416 C:\Program Files\IDT\WDM\sttray64.exe
3432 C:\Program Files\Java\jre6\bin\jusched.exe
3440 C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
3492 C:\Windows\System32\igfxsrvc.exe
3704 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
3756 C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
3768 C:\Program Files (x86)\Common Files\Nikon\Monitor\NkMonitor.exe
3780 C:\Program Files (x86)\iTunes\iTunesHelper.exe
3788 C:\Program Files (x86)\AVG\AVG9\avgtray.exe
3280 C:\Program Files\iPod\bin\iPodService.exe
2776 C:\Windows\System32\SearchIndexer.exe
3480 C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
3648 WmiPrvSE.exe
1088 C:\Program Files\Windows Media Player\wmpnetwk.exe
4152 C:\Windows\System32\svchost.exe
4308 C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
2996 C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe
1220 C:\Program Files (x86)\Mozilla Firefox\firefox.exe
3208 C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
4664 C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
2608 C:\Windows\System32\svchost.exe
3560 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
4796 C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
5948 C:\Windows\System32\spoolsv.exe
4440 C:\Windows\System32\rundll32.exe
4104 C:\Windows\System32\spool\drivers\x64\3\E_IATIAEA.EXE
5360 C:\Windows\System32\taskhost.exe
7040 C:\Program Files (x86)\iTunes\iTunes.exe
6344 C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
6320 C:\Windows\System32\conhost.exe
6596 C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
6904 C:\Windows\System32\conhost.exe
6956 C:\Windows\SysWOW64\dllhost.exe
4348 C:\Windows\System32\SearchProtocolHost.exe
6176 C:\Windows\System32\SearchFilterHost.exe
6916 C:\Windows\System32\audiodg.exe
2628 C:\Users\Sigrid\Desktop\MBRCheck.exe
6400 C:\Windows\System32\conhost.exe
5072 C:\Windows\System32\dllhost.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`0c800000 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000071`3fe00000 (NTFS)

PhysicalDrive0 Model Number: FUJITSUMJA2500BHG2, Rev: 8919

Size Device Name MBR Status
--------------------------------------------
465 GB \\.\PhysicalDrive0 Unknown MBR code
SHA1: 263078AC856058B74BD330CBEEF0EB1B30D826B5


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:

descriptionRedirect Trojan or Malware - Page 1 EmptyRe: Redirect Trojan or Malware

more_horiz
Fix using MBRCheck.exe

Run MBRCheck.exe again by double-clicking on it.

  • Wait until you see the following line: Enter 'Y' and hit ENTER for more options, or 'N' to exit:
  • Enter 'Y' and then press Enter.
  • When asked: 'Enter your choice:', select option 2 (Restore the MBR of a physical disk with a standard boot code) and press the Enter key.
  • Now the program will ask: 'Enter the physical disk number to fix (0-99, -1 to cancel)'
  • Enter 0 and press the Enter key.
  • The program will show Available MBR codes followed by a list of operating systems as shown below:
    Available MBR codes:
    [ 0] Default (Windows XP)
    [ 1] Windows XP
    [ 2] Windows Server 2003
    [ 3] Windows Vista
    [ 4] Windows 2008
    [ 5] Windows 7
    [-1] Cancel
    Please select the MBR code to write to this drive:




  • Please select your version of Windows from the list and enter the corresponding number and then press Enter.
  • When prompted for confirmation: "Do you want to fix the MBR code?". Type the full word Yes (not Y or the fix will not work) and press Enter.
  • Left-click on the title bar (where program name and path is written).
  • From the menu chose Edit -> Select All.
  • Press the Enter key to copy selected text.
  • Open Notepad, paste that text into it and save to your desktop as MBRCheck.txt.
  • When complete, you should see Done! Press ENTER to exit.... Press Enter on the keyboard.
  • Reboot your computer to complete the fix and copy/paste MBRCheck.txt in your next reply.
  • If your computer does not restart on its own, please restart it manually.

Important Note: The Master Boot Record contains the Partition Table for the hard disk and a a little executable code for the boot start. While fixing the [URL="http://www.dewassoc.com/kbase/hard_drives/master_boot_record.htm"]Master Boot Record (MBR)[/URL] is generally safe, there is a small risk of damaging the MBR, which may cause the computer to not boot up or it may corrupt a partition.

The following are signs of a damaged MBR:

  • Invalid Partition Table
  • Missing Operating System
  • Error loading operating system


If it is the worst case scenario, and your computer cannot boot, please take note of the following:

Please have your Windows CD available, which will allow recovering the boot code via the Windows Recovery Console in case of any problems or install the [URL="http://www.bleepingcomputer.com/tutorials/tutorial117.html#what"]XP Recovery Console[/URL] before proceeding with the above fix. Then, if any problems occur, the links below explain how to use and repair the MBR:

  • [URL="http://support.microsoft.com/kb/307654"]How to use the Recovery Console[/URL]
  • [URL="http://helpdeskgeek.com/how-to/fix-mbr-xp-vista/"]How to fix MBR in Windows XP and Vista[/URL]


If you do not have a Windows CD available, please let me know. You will need access to a computer that can burn CDs.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Redirect Trojan or Malware - Page 1 DXwU4
Redirect Trojan or Malware - Page 1 VvYDg

descriptionRedirect Trojan or Malware - Page 1 EmptyRe: Redirect Trojan or Malware

more_horiz
I do not have Windows CDs, but I do have the recovery disks that came with the computer. (HP)

Also, my hard drive has a recovery partition on it - will fixing the MBR damage the recovery drive (D)?

descriptionRedirect Trojan or Malware - Page 1 EmptyRe: Redirect Trojan or Malware

more_horiz
Hello.
Did you run the MBRCheck fix? if so, please post the given log.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Redirect Trojan or Malware - Page 1 DXwU4
Redirect Trojan or Malware - Page 1 VvYDg

descriptionRedirect Trojan or Malware - Page 1 EmptyRe: Redirect Trojan or Malware

more_horiz
Not yet, as I do not have the Windows CDs and need to know if the Recovery Disks I have are adequate.

And because I need to know if running the fix will damage the partition on my hard drive as mentioned in my last post.

descriptionRedirect Trojan or Malware - Page 1 EmptyRe: Redirect Trojan or Malware

more_horiz
Hello.
Don't worry, the partition wont be damaged. The recovery disks may help if something goes wrong.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Redirect Trojan or Malware - Page 1 DXwU4
Redirect Trojan or Malware - Page 1 VvYDg

descriptionRedirect Trojan or Malware - Page 1 EmptyRe: Redirect Trojan or Malware

more_horiz
I did the fix and I have rebooted successfully:

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows 7 Home Premium Edition
Windows Information: (build 7600), 64-bit
Base Board Manufacturer: Quanta
BIOS Manufacturer: Hewlett-Packard
System Manufacturer: Hewlett-Packard
System Product Name: HP Pavilion dv6 Notebook PC
Logical Drives Mask: 0x0000001c

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`0c800000 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000071`3fe00000 (NTFS)

Size Device Name MBR Status
--------------------------------------------
465 GB \\.\PhysicalDrive0 Unknown MBR code
SHA1: 263078AC856058B74BD330CBEEF0EB1B30D826B5


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit: y

Options:
[1] Dump the MBR of a physical disk to file.
[2] Restore the MBR of a physical disk with a standard boot code.
[3] Exit.

Enter your choice: 2

Enter the physical disk number to fix (0-99, -1 to cancel): 0
Available MBR codes:
[ 0] Default (Windows 7)
[ 1] Windows XP
[ 2] Windows Server 2003
[ 3] Windows Vista
[ 4] Windows 2008
[ 5] Windows 7
[-1] Cancel

Please select the MBR code to write to this drive: 5
Do you want to fix the MBR code? Type 'YES' and hit ENTER to continue: yes
Successfully wrote new MBR code!
Please reboot your computer to complete the fix.


Done!
Press ENTER to exit...

descriptionRedirect Trojan or Malware - Page 1 EmptyRe: Redirect Trojan or Malware

more_horiz
Okay good, now run MBRCheck again, but normally this time, just double click and post the new log.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Redirect Trojan or Malware - Page 1 DXwU4
Redirect Trojan or Malware - Page 1 VvYDg

descriptionRedirect Trojan or Malware - Page 1 EmptyRe: Redirect Trojan or Malware

more_horiz
:sad:

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows 7 Home Premium Edition
Windows Information: (build 7600), 64-bit
Base Board Manufacturer: Quanta
BIOS Manufacturer: Hewlett-Packard
System Manufacturer: Hewlett-Packard
System Product Name: HP Pavilion dv6 Notebook PC
Logical Drives Mask: 0x0000001c

Kernel Drivers (total 234):
0x02C17000 \SystemRoot\system32\ntoskrnl.exe
0x031F3000 \SystemRoot\system32\hal.dll
0x00BCF000 \SystemRoot\system32\kdcom.dll
0x00CE1000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x00D25000 \SystemRoot\system32\PSHED.dll
0x00D39000 \SystemRoot\system32\CLFS.SYS
0x00C00000 \SystemRoot\system32\CI.dll
0x00EDC000 \SystemRoot\system32\drivers\Wdf01000.sys
0x00F80000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x00F8F000 \SystemRoot\system32\DRIVERS\ACPI.sys
0x00FE6000 \SystemRoot\system32\DRIVERS\WMILIB.SYS
0x00FEF000 \SystemRoot\system32\DRIVERS\msisadrv.sys
0x00E00000 \SystemRoot\system32\DRIVERS\pci.sys
0x00E33000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
0x00E40000 \SystemRoot\system32\DRIVERS\isapnp.sys
0x00E49000 \SystemRoot\system32\DRIVERS\mpio.sys
0x00E73000 \SystemRoot\System32\drivers\partmgr.sys
0x00E88000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x00E91000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x00E9D000 \SystemRoot\system32\DRIVERS\volmgr.sys
0x00D97000 \SystemRoot\System32\drivers\volmgrx.sys
0x00EB2000 \SystemRoot\system32\DRIVERS\intelide.sys
0x00EBA000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
0x00ECA000 \SystemRoot\system32\DRIVERS\aliide.sys
0x00ED1000 \SystemRoot\system32\DRIVERS\amdide.sys
0x00DF3000 \SystemRoot\system32\DRIVERS\cmdide.sys
0x00CC0000 \SystemRoot\System32\drivers\mountmgr.sys
0x010F3000 \SystemRoot\system32\DRIVERS\msdsm.sys
0x01119000 \SystemRoot\system32\DRIVERS\nvraid.sys
0x01142000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x01172000 \SystemRoot\system32\DRIVERS\pciide.sys
0x01179000 \SystemRoot\system32\DRIVERS\viaide.sys
0x012E2000 \SystemRoot\system32\DRIVERS\iaStorV.sys
0x01200000 \SystemRoot\system32\DRIVERS\atapi.sys
0x01209000 \SystemRoot\system32\DRIVERS\ataport.SYS
0x01233000 \SystemRoot\system32\DRIVERS\lsi_sas.sys
0x01250000 \SystemRoot\system32\DRIVERS\storport.sys
0x012B2000 \SystemRoot\system32\DRIVERS\msahci.sys
0x012BD000 \SystemRoot\system32\DRIVERS\HpSAMD.sys
0x01181000 \SystemRoot\system32\DRIVERS\adp94xx.sys
0x01000000 \SystemRoot\system32\DRIVERS\adpahci.sys
0x01056000 \SystemRoot\system32\DRIVERS\adpu320.sys
0x01085000 \SystemRoot\system32\DRIVERS\amdsata.sys
0x010A3000 \SystemRoot\system32\DRIVERS\amdsbs.sys
0x012D4000 \SystemRoot\system32\DRIVERS\amdxata.sys
0x01424000 \SystemRoot\system32\DRIVERS\arc.sys
0x0143D000 \SystemRoot\system32\DRIVERS\arcsas.sys
0x01458000 \SystemRoot\system32\DRIVERS\elxstor.sys
0x014DF000 \SystemRoot\system32\DRIVERS\iirsp.sys
0x014F0000 \SystemRoot\system32\DRIVERS\lsi_fc.sys
0x0150F000 \SystemRoot\system32\DRIVERS\lsi_sas2.sys
0x01522000 \SystemRoot\system32\DRIVERS\lsi_scsi.sys
0x01541000 \SystemRoot\system32\DRIVERS\megasas.sys
0x0154D000 \SystemRoot\system32\DRIVERS\MegaSR.sys
0x01400000 \SystemRoot\system32\DRIVERS\nfrd960.sys
0x016C9000 \SystemRoot\system32\DRIVERS\nvstor.sys
0x01810000 \SystemRoot\system32\DRIVERS\ql2300.sys
0x016F4000 \SystemRoot\system32\DRIVERS\ql40xx.sys
0x019B4000 \SystemRoot\system32\DRIVERS\SiSRaid2.sys
0x019C2000 \SystemRoot\system32\DRIVERS\sisraid4.sys
0x019DA000 \SystemRoot\system32\DRIVERS\stexstor.sys
0x01753000 \SystemRoot\system32\DRIVERS\vsmraid.sys
0x0177D000 \SystemRoot\system32\drivers\fltmgr.sys
0x019E4000 \SystemRoot\system32\drivers\fileinfo.sys
0x01A28000 \SystemRoot\System32\Drivers\Ntfs.sys
0x01600000 \SystemRoot\System32\Drivers\msrpc.sys
0x01BCB000 \SystemRoot\System32\Drivers\ksecdd.sys
0x01C6E000 \SystemRoot\System32\Drivers\cng.sys
0x01CE1000 \SystemRoot\System32\drivers\pcw.sys
0x01CF2000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x01CFC000 \SystemRoot\system32\drivers\ndis.sys
0x01C00000 \SystemRoot\system32\drivers\NETIO.SYS
0x0165E000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x01E00000 \SystemRoot\System32\drivers\tcpip.sys
0x020A2000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x020EC000 \SystemRoot\system32\DRIVERS\wd.sys
0x020F4000 \SystemRoot\system32\DRIVERS\volsnap.sys
0x02140000 \SystemRoot\System32\Drivers\spldr.sys
0x02148000 \SystemRoot\system32\DRIVERS\sbp2port.sys
0x02165000 \SystemRoot\System32\drivers\rdyboost.sys
0x0219F000 \SystemRoot\System32\Drivers\mup.sys
0x021B1000 \SystemRoot\System32\drivers\hwpolicy.sys
0x021BA000 \SystemRoot\system32\DRIVERS\hpdskflt.sys
0x021C4000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x02000000 \SystemRoot\system32\DRIVERS\disk.sys
0x0204E000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x02078000 \SystemRoot\System32\Drivers\Null.SYS
0x02081000 \SystemRoot\System32\Drivers\Beep.SYS
0x02088000 \SystemRoot\System32\drivers\vga.sys
0x01A00000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x01DEE000 \SystemRoot\System32\drivers\watchdog.sys
0x02096000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x01C60000 \SystemRoot\system32\drivers\rdpencdd.sys
0x01BE5000 \SystemRoot\system32\drivers\rdprefmp.sys
0x01BEE000 \SystemRoot\System32\Drivers\Msfs.SYS
0x01689000 \SystemRoot\System32\Drivers\Npfs.SYS
0x0169A000 \SystemRoot\system32\DRIVERS\tdx.sys
0x01800000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x03413000 \SystemRoot\System32\DRIVERS\netbt.sys
0x03458000 \SystemRoot\system32\drivers\afd.sys
0x034E2000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x034EB000 \SystemRoot\system32\DRIVERS\pacer.sys
0x03511000 \SystemRoot\system32\DRIVERS\vwififlt.sys
0x03527000 \SystemRoot\system32\DRIVERS\netbios.sys
0x03553000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x0356E000 \SystemRoot\system32\DRIVERS\termdd.sys
0x03582000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x035D3000 \SystemRoot\system32\drivers\nsiproxy.sys
0x035DF000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x035EA000 \SystemRoot\System32\drivers\discache.sys
0x017C9000 \SystemRoot\System32\Drivers\dfsc.sys
0x03400000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x042DA000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x04300000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x04316000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x04410000 \SystemRoot\system32\DRIVERS\igdkmd64.sys
0x04C73000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x04D67000 \SystemRoot\System32\drivers\dxgmms1.sys
0x04DAD000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x04C00000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x04C56000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x04DBA000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x05075000 \SystemRoot\system32\DRIVERS\bcmwl664.sys
0x0531D000 \SystemRoot\system32\DRIVERS\vwifibus.sys
0x05367000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x05385000 \SystemRoot\system32\DRIVERS\HpqKbFiltr.sys
0x05391000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x053A0000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x053E9000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x053EB000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x05000000 \SystemRoot\system32\DRIVERS\enecir.sys
0x0501D000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x0502A000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x05033000 \SystemRoot\system32\DRIVERS\Accelerometer.sys
0x0503F000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x0504F000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x04B0F000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x05065000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x04B33000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x04DDE000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x04B62000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x04B83000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x05071000 \SystemRoot\system32\DRIVERS\swenum.sys
0x04B9D000 \SystemRoot\system32\DRIVERS\ks.sys
0x04BE0000 \SystemRoot\system32\DRIVERS\circlass.sys
0x0431B000 \SystemRoot\system32\DRIVERS\umbus.sys
0x0432D000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x04387000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x04200000 \SystemRoot\system32\DRIVERS\stwrt64.sys
0x0427B000 \SystemRoot\system32\DRIVERS\portcls.sys
0x042B8000 \SystemRoot\system32\DRIVERS\drmk.sys
0x053FA000 \SystemRoot\system32\drivers\ksthunk.sys
0x0439C000 \SystemRoot\system32\drivers\IntcHdmi.sys
0x043C3000 \SystemRoot\system32\DRIVERS\hidir.sys
0x043D4000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x04C67000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x04BF2000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x04400000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x043ED000 \SystemRoot\System32\Drivers\crashdmp.sys
0x03536000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x03542000 \SystemRoot\System32\Drivers\dump_msahci.sys
0x02016000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x00020000 \SystemRoot\System32\win32k.sys
0x02029000 \SystemRoot\System32\drivers\Dxapi.sys
0x06237000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x06254000 \SystemRoot\System32\Drivers\usbvideo.sys
0x004C0000 \SystemRoot\System32\TSDDD.dll
0x00790000 \SystemRoot\System32\cdd.dll
0x00810000 \SystemRoot\System32\ATMFD.DLL
0x06290000 \SystemRoot\system32\drivers\luafv.sys
0x062B3000 \SystemRoot\system32\drivers\WudfPf.sys
0x062D4000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x062E9000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x0633C000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x0634F000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x02C77000 \SystemRoot\system32\drivers\HTTP.sys
0x02D3F000 \SystemRoot\system32\DRIVERS\bowser.sys
0x02D5D000 \SystemRoot\System32\drivers\mpsdrv.sys
0x02D75000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x02DA2000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x02DF0000 \SystemRoot\system32\DRIVERS\vwifimp.sys
0x02C00000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x03285000 \SystemRoot\system32\drivers\peauth.sys
0x0332B000 \SystemRoot\System32\Drivers\secdrv.SYS
0x03336000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x03363000 \SystemRoot\System32\drivers\tcpipreg.sys
0x03375000 \SystemRoot\System32\DRIVERS\srv2.sys
0x06367000 \SystemRoot\System32\DRIVERS\srv.sys
0x03271000 \SystemRoot\system32\DRIVERS\avgrkx64.sys
0x03200000 \SystemRoot\system32\DRIVERS\avgldx64.sys
0x0324F000 \SystemRoot\system32\DRIVERS\avgmfx64.sys
0x0884D000 \SystemRoot\system32\DRIVERS\avgtdia.sys
0x088AE000 \SystemRoot\system32\DRIVERS\AVGIDSFilter.Sys
0x088BA000 \SystemRoot\system32\DRIVERS\AVGIDSDriver.Sys
0x0892B000 \SystemRoot\system32\DRIVERS\monitor.sys
0x77B80000 \Windows\System32\ntdll.dll
0x47BC0000 \Windows\System32\smss.exe
0xFFEA0000 \Windows\System32\apisetschema.dll
0xFFD10000 \Windows\System32\autochk.exe
0x77D50000 \Windows\System32\normaliz.dll
0xFFE10000 \Windows\System32\shlwapi.dll
0xFFDE0000 \Windows\System32\imm32.dll
0x77D40000 \Windows\System32\psapi.dll
0xFFD00000 \Windows\System32\oleaut32.dll
0xFFC30000 \Windows\System32\usp10.dll
0xFFB90000 \Windows\System32\msvcrt.dll
0xFFA60000 \Windows\System32\wininet.dll
0xFFA50000 \Windows\System32\lpk.dll
0xFF8D0000 \Windows\System32\urlmon.dll
0xFEB40000 \Windows\System32\shell32.dll
0xFEB20000 \Windows\System32\imagehlp.dll
0xFEA10000 \Windows\System32\msctf.dll
0xFE930000 \Windows\System32\advapi32.dll
0xFE890000 \Windows\System32\comdlg32.dll
0xFE880000 \Windows\System32\nsi.dll
0xFE830000 \Windows\System32\ws2_32.dll
0xFE7C0000 \Windows\System32\gdi32.dll
0xFE770000 \Windows\System32\Wldap32.dll
0xFE640000 \Windows\System32\rpcrt4.dll
0x77A80000 \Windows\System32\user32.dll
0x77960000 \Windows\System32\kernel32.dll
0xFE5C0000 \Windows\System32\difxapi.dll
0xFE360000 \Windows\System32\iertutil.dll
0xFE2C0000 \Windows\System32\clbcatq.dll
0xFE0B0000 \Windows\System32\ole32.dll
0xFE090000 \Windows\System32\sechost.dll
0xFDEB0000 \Windows\System32\setupapi.dll
0xFDE90000 \Windows\System32\devobj.dll
0xFDE50000 \Windows\System32\cfgmgr32.dll
0xFDDE0000 \Windows\System32\KernelBase.dll
0xFDC70000 \Windows\System32\crypt32.dll
0xFDBD0000 \Windows\System32\comctl32.dll
0xFDB90000 \Windows\System32\wintrust.dll
0xFDB80000 \Windows\System32\msasn1.dll

Processes (total 84):
0 System Idle Process
4 System
264 C:\Windows\System32\smss.exe
372 csrss.exe
436 C:\Windows\System32\wininit.exe
456 csrss.exe
516 C:\Windows\System32\services.exe
524 C:\Windows\System32\lsass.exe
532 C:\Windows\System32\lsm.exe
544 C:\Windows\System32\winlogon.exe
656 C:\Windows\System32\svchost.exe
728 C:\Windows\System32\svchost.exe
836 C:\Windows\System32\svchost.exe
880 C:\Windows\System32\svchost.exe
908 C:\Windows\System32\svchost.exe
964 C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\stacsv64.exe
1040 C:\Windows\System32\svchost.exe
1088 C:\Windows\System32\hpservice.exe
1168 C:\Windows\System32\svchost.exe
1252 C:\Windows\System32\wlanext.exe
1260 C:\Windows\System32\conhost.exe
1344 C:\Windows\System32\spoolsv.exe
1372 C:\Windows\System32\svchost.exe
1492 C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe
1560 C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
1612 C:\Program Files (x86)\Bonjour\mDNSResponder.exe
1648 C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
1692 C:\Windows\System32\svchost.exe
1720 C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe
1828 C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
1880 C:\Windows\System32\svchost.exe
1976 unsecapp.exe
2072 WmiPrvSE.exe
2336 C:\Windows\System32\taskhost.exe
2388 C:\Windows\System32\taskeng.exe
2412 C:\Windows\System32\dwm.exe
2444 C:\Windows\explorer.exe
2784 C:\Windows\System32\igfxtray.exe
2796 C:\Windows\System32\hkcmd.exe
2808 C:\Windows\System32\igfxpers.exe
2816 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
2824 C:\Program Files\IDT\WDM\sttray64.exe
2832 C:\Program Files\Java\jre6\bin\jusched.exe
2840 C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
2912 C:\Windows\System32\igfxsrvc.exe
2988 C:\Windows\System32\spool\drivers\x64\3\E_IATIAEA.EXE
2212 C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
1456 C:\Program Files (x86)\Common Files\Nikon\Monitor\NkMonitor.exe
2056 C:\Program Files (x86)\iTunes\iTunesHelper.exe
2592 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
2568 C:\Program Files (x86)\Mozilla Firefox\firefox.exe
2752 C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
2852 WmiPrvSE.exe
980 C:\Program Files\iPod\bin\iPodService.exe
3108 C:\Windows\System32\SearchIndexer.exe
3120 C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
3236 C:\Program Files\Windows Media Player\wmpnetwk.exe
3620 C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
3772 C:\Windows\System32\svchost.exe
3860 C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
4036 C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
860 C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe
2780 C:\Windows\System32\svchost.exe
2768 C:\Windows\System32\taskhost.exe
4384 avgchsva.exe
4484 avgrsa.exe
4508 avgcsrva.exe
3968 C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
576 C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe
3268 C:\Program Files (x86)\AVG\AVG10\avgnsa.exe
3336 C:\Program Files (x86)\AVG\AVG10\avgemca.exe
4940 C:\Windows\System32\conhost.exe
4276 C:\Program Files\Windows Sidebar\sidebar.exe
692 C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
3508 C:\Program Files (x86)\AVG\AVG10\avgtray.exe
336 C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
4888 C:\Windows\System32\conhost.exe
3208 C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
6008 C:\Windows\System32\audiodg.exe
4856 C:\Windows\System32\SearchProtocolHost.exe
5984 C:\Windows\System32\SearchFilterHost.exe
3276 C:\Users\Sigrid\Desktop\MBRCheck.exe
3884 C:\Windows\System32\conhost.exe
5476 C:\Windows\System32\dllhost.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`0c800000 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000071`3fe00000 (NTFS)

PhysicalDrive0 Model Number: FUJITSUMJA2500BHG2, Rev: 8919

Size Device Name MBR Status
--------------------------------------------
465 GB \\.\PhysicalDrive0 Unknown MBR code
SHA1: 263078AC856058B74BD330CBEEF0EB1B30D826B5


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:

descriptionRedirect Trojan or Malware - Page 1 EmptyRe: Redirect Trojan or Malware

more_horiz
So, am I ok now even though I am getting the

"Found non-standard or infected MBR."4
??

descriptionRedirect Trojan or Malware - Page 1 EmptyRe: Redirect Trojan or Malware

more_horiz
Hello.
Do you have the repair discs for your OS?

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Redirect Trojan or Malware - Page 1 DXwU4
Redirect Trojan or Malware - Page 1 VvYDg

descriptionRedirect Trojan or Malware - Page 1 EmptyRe: Redirect Trojan or Malware

more_horiz
Yes, I have the recovery disks I made when I got the computer.

descriptionRedirect Trojan or Malware - Page 1 EmptyRe: Redirect Trojan or Malware

more_horiz
Bump

descriptionRedirect Trojan or Malware - Page 1 EmptyRe: Redirect Trojan or Malware

more_horiz
Hello.
Please reboot your computer, when it starts to boot, start tapping the F8 key to access the advanced boot menu. Is there an option for "Repair your computer"?

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Redirect Trojan or Malware - Page 1 DXwU4
Redirect Trojan or Malware - Page 1 VvYDg

descriptionRedirect Trojan or Malware - Page 1 EmptyRe: Redirect Trojan or Malware

more_horiz
yes.

descriptionRedirect Trojan or Malware - Page 1 EmptyRe: Redirect Trojan or Malware

more_horiz
Awesome.
Run that option, it will act like a command prompt.

Type in this command:

bootrec /fixmbr

If you are prompted with a yes/no option, type in yes or Y. Once it is done, type in exit and reboot the machine.

Next, run another MBRCheck and post the new log.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Redirect Trojan or Malware - Page 1 DXwU4
Redirect Trojan or Malware - Page 1 VvYDg

descriptionRedirect Trojan or Malware - Page 1 EmptyRe: Redirect Trojan or Malware

more_horiz
I'm not sure, but it appears a small "yay!" might be in order....

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows 7 Home Premium Edition
Windows Information: (build 7600), 64-bit
Base Board Manufacturer: Quanta
BIOS Manufacturer: Hewlett-Packard
System Manufacturer: Hewlett-Packard
System Product Name: HP Pavilion dv6 Notebook PC
Logical Drives Mask: 0x0000001c

Kernel Drivers (total 199):
0x02C0D000 \SystemRoot\system32\ntoskrnl.exe
0x031E9000 \SystemRoot\system32\hal.dll
0x00B9B000 \SystemRoot\system32\kdcom.dll
0x00CBF000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x00D03000 \SystemRoot\system32\PSHED.dll
0x00D17000 \SystemRoot\system32\CLFS.SYS
0x00EDF000 \SystemRoot\system32\CI.dll
0x00E00000 \SystemRoot\system32\drivers\Wdf01000.sys
0x00EA4000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x00F9F000 \SystemRoot\system32\DRIVERS\ACPI.sys
0x00FF6000 \SystemRoot\system32\DRIVERS\WMILIB.SYS
0x00EB3000 \SystemRoot\system32\DRIVERS\msisadrv.sys
0x00D75000 \SystemRoot\system32\DRIVERS\pci.sys
0x00EBD000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
0x00ECA000 \SystemRoot\system32\DRIVERS\isapnp.sys
0x00DA8000 \SystemRoot\system32\DRIVERS\mpio.sys
0x00DD2000 \SystemRoot\System32\drivers\partmgr.sys
0x00ED3000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x00DE7000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x00C00000 \SystemRoot\system32\DRIVERS\volmgr.sys
0x00C15000 \SystemRoot\System32\drivers\volmgrx.sys
0x00C71000 \SystemRoot\system32\DRIVERS\intelide.sys
0x00C79000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
0x00C89000 \SystemRoot\system32\DRIVERS\aliide.sys
0x00C90000 \SystemRoot\system32\DRIVERS\amdide.sys
0x00C97000 \SystemRoot\system32\DRIVERS\cmdide.sys
0x00C9F000 \SystemRoot\System32\drivers\mountmgr.sys
0x01090000 \SystemRoot\system32\DRIVERS\msdsm.sys
0x010B6000 \SystemRoot\system32\DRIVERS\nvraid.sys
0x010DF000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x0110F000 \SystemRoot\system32\DRIVERS\pciide.sys
0x01116000 \SystemRoot\system32\DRIVERS\viaide.sys
0x0127D000 \SystemRoot\system32\DRIVERS\iaStorV.sys
0x0139B000 \SystemRoot\system32\DRIVERS\atapi.sys
0x013A4000 \SystemRoot\system32\DRIVERS\ataport.SYS
0x013CE000 \SystemRoot\system32\DRIVERS\lsi_sas.sys
0x01200000 \SystemRoot\system32\DRIVERS\storport.sys
0x01262000 \SystemRoot\system32\DRIVERS\msahci.sys
0x0111E000 \SystemRoot\system32\DRIVERS\HpSAMD.sys
0x01135000 \SystemRoot\system32\DRIVERS\adp94xx.sys
0x01000000 \SystemRoot\system32\DRIVERS\adpahci.sys
0x01056000 \SystemRoot\system32\DRIVERS\adpu320.sys
0x011B0000 \SystemRoot\system32\DRIVERS\amdsata.sys
0x014B4000 \SystemRoot\system32\DRIVERS\amdsbs.sys
0x014FB000 \SystemRoot\system32\DRIVERS\amdxata.sys
0x01506000 \SystemRoot\system32\DRIVERS\arc.sys
0x0151F000 \SystemRoot\system32\DRIVERS\arcsas.sys
0x0153A000 \SystemRoot\system32\DRIVERS\elxstor.sys
0x015C1000 \SystemRoot\system32\DRIVERS\iirsp.sys
0x015D2000 \SystemRoot\system32\DRIVERS\lsi_fc.sys
0x01400000 \SystemRoot\system32\DRIVERS\lsi_sas2.sys
0x01413000 \SystemRoot\system32\DRIVERS\lsi_scsi.sys
0x01432000 \SystemRoot\system32\DRIVERS\megasas.sys
0x016E1000 \SystemRoot\system32\DRIVERS\MegaSR.sys
0x01785000 \SystemRoot\system32\DRIVERS\nfrd960.sys
0x01795000 \SystemRoot\system32\DRIVERS\nvstor.sys
0x0183A000 \SystemRoot\system32\DRIVERS\ql2300.sys
0x01600000 \SystemRoot\system32\DRIVERS\ql40xx.sys
0x019DE000 \SystemRoot\system32\DRIVERS\SiSRaid2.sys
0x01800000 \SystemRoot\system32\DRIVERS\sisraid4.sys
0x01818000 \SystemRoot\system32\DRIVERS\stexstor.sys
0x0165F000 \SystemRoot\system32\DRIVERS\vsmraid.sys
0x01689000 \SystemRoot\system32\drivers\fltmgr.sys
0x01822000 \SystemRoot\system32\drivers\fileinfo.sys
0x01A25000 \SystemRoot\System32\Drivers\Ntfs.sys
0x0143E000 \SystemRoot\System32\Drivers\msrpc.sys
0x01BC8000 \SystemRoot\System32\Drivers\ksecdd.sys
0x01C2C000 \SystemRoot\System32\Drivers\cng.sys
0x01C9F000 \SystemRoot\System32\drivers\pcw.sys
0x01CB0000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x01CBA000 \SystemRoot\system32\drivers\ndis.sys
0x01E55000 \SystemRoot\system32\drivers\NETIO.SYS
0x01EB5000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x02000000 \SystemRoot\System32\drivers\tcpip.sys
0x01EE0000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x01F2A000 \SystemRoot\system32\DRIVERS\wd.sys
0x01F32000 \SystemRoot\system32\DRIVERS\volsnap.sys
0x01F7E000 \SystemRoot\System32\Drivers\spldr.sys
0x01F86000 \SystemRoot\system32\DRIVERS\sbp2port.sys
0x01FA3000 \SystemRoot\System32\drivers\rdyboost.sys
0x01FDD000 \SystemRoot\System32\Drivers\mup.sys
0x01FEF000 \SystemRoot\System32\drivers\hwpolicy.sys
0x01E00000 \SystemRoot\system32\DRIVERS\hpdskflt.sys
0x01E0A000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x01DAC000 \SystemRoot\system32\DRIVERS\disk.sys
0x01E44000 \SystemRoot\system32\DRIVERS\avgrkx64.sys
0x01DC2000 \SystemRoot\system32\DRIVERS\AVGIDSEH.Sys
0x017C0000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x01C13000 \SystemRoot\system32\DRIVERS\avgmfx64.sys
0x01C22000 \SystemRoot\System32\Drivers\Null.SYS
0x01E4E000 \SystemRoot\System32\Drivers\Beep.SYS
0x01DF1000 \SystemRoot\System32\drivers\vga.sys
0x01A00000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x01BE2000 \SystemRoot\System32\drivers\watchdog.sys
0x01BF2000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x019EC000 \SystemRoot\system32\drivers\rdpencdd.sys
0x019F5000 \SystemRoot\system32\drivers\rdprefmp.sys
0x017EA000 \SystemRoot\System32\Drivers\Msfs.SYS
0x0149C000 \SystemRoot\System32\Drivers\Npfs.SYS
0x011CE000 \SystemRoot\system32\DRIVERS\tdx.sys
0x015F1000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x0346D000 \SystemRoot\system32\DRIVERS\avgtdia.sys
0x034CE000 \SystemRoot\System32\DRIVERS\netbt.sys
0x03513000 \SystemRoot\system32\drivers\afd.sys
0x0359D000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x035A6000 \SystemRoot\system32\DRIVERS\pacer.sys
0x035CC000 \SystemRoot\system32\DRIVERS\vwififlt.sys
0x035E2000 \SystemRoot\system32\DRIVERS\netbios.sys
0x0341D000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x03438000 \SystemRoot\system32\DRIVERS\termdd.sys
0x0421A000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x0426B000 \SystemRoot\system32\drivers\nsiproxy.sys
0x04277000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x04282000 \SystemRoot\System32\drivers\discache.sys
0x04291000 \SystemRoot\System32\Drivers\dfsc.sys
0x042AF000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x042C0000 \SystemRoot\system32\DRIVERS\avgldx64.sys
0x0430F000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x04335000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x0434B000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x0443B000 \SystemRoot\system32\DRIVERS\igdkmd64.sys
0x04CBF000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x04DB3000 \SystemRoot\System32\drivers\dxgmms1.sys
0x04C00000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x04C0D000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x04C63000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x04C74000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x05075000 \SystemRoot\system32\DRIVERS\bcmwl664.sys
0x0531D000 \SystemRoot\system32\DRIVERS\vwifibus.sys
0x05367000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x05385000 \SystemRoot\system32\DRIVERS\HpqKbFiltr.sys
0x05391000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x053A0000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x053E9000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x053EB000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x05000000 \SystemRoot\system32\DRIVERS\enecir.sys
0x0501D000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x0502A000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x05033000 \SystemRoot\system32\DRIVERS\Accelerometer.sys
0x0503F000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x0504F000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x04C98000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x05065000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x04B3A000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x04B69000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x04B84000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x04BA5000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x05071000 \SystemRoot\system32\DRIVERS\swenum.sys
0x04350000 \SystemRoot\system32\DRIVERS\ks.sys
0x04BBF000 \SystemRoot\system32\DRIVERS\circlass.sys
0x04BD1000 \SystemRoot\system32\DRIVERS\umbus.sys
0x04393000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x04BE3000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x06290000 \SystemRoot\system32\DRIVERS\stwrt64.sys
0x0630B000 \SystemRoot\system32\DRIVERS\portcls.sys
0x06348000 \SystemRoot\system32\DRIVERS\drmk.sys
0x0636A000 \SystemRoot\system32\drivers\ksthunk.sys
0x06370000 \SystemRoot\system32\drivers\IntcHdmi.sys
0x06397000 \SystemRoot\system32\DRIVERS\hidir.sys
0x063A8000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x063C1000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x063CA000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x063D8000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x06200000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x0621D000 \SystemRoot\System32\Drivers\usbvideo.sys
0x0624B000 \SystemRoot\System32\Drivers\crashdmp.sys
0x06259000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x06265000 \SystemRoot\System32\Drivers\dump_msahci.sys
0x06270000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x000F0000 \SystemRoot\System32\win32k.sys
0x06283000 \SystemRoot\System32\drivers\Dxapi.sys
0x063E5000 \SystemRoot\system32\DRIVERS\monitor.sys
0x00570000 \SystemRoot\System32\TSDDD.dll
0x00780000 \SystemRoot\System32\cdd.dll
0x00940000 \SystemRoot\System32\ATMFD.DLL
0x0532A000 \SystemRoot\system32\drivers\luafv.sys
0x04400000 \SystemRoot\system32\drivers\WudfPf.sys
0x0534D000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x02C9A000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x02CED000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x02D00000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x02D18000 \SystemRoot\system32\drivers\HTTP.sys
0x02DE0000 \SystemRoot\system32\DRIVERS\vwifimp.sys
0x02C00000 \SystemRoot\system32\DRIVERS\bowser.sys
0x02C1E000 \SystemRoot\System32\drivers\mpsdrv.sys
0x02C36000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x03041000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x0308F000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x030B2000 \SystemRoot\system32\DRIVERS\AVGIDSFilter.Sys
0x030BE000 \SystemRoot\system32\drivers\peauth.sys
0x03164000 \SystemRoot\System32\Drivers\secdrv.SYS
0x0316F000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x0319C000 \SystemRoot\System32\drivers\tcpipreg.sys
0x031AE000 \SystemRoot\system32\DRIVERS\AVGIDSDriver.Sys
0x040F5000 \SystemRoot\System32\DRIVERS\srv2.sys
0x0415C000 \SystemRoot\System32\DRIVERS\srv.sys
0x77180000 \Windows\System32\ntdll.dll
0x484A0000 \Windows\System32\smss.exe
0xFF4A0000 \Windows\System32\apisetschema.dll

Processes (total 79):
0 System Idle Process
4 System
272 C:\Windows\System32\smss.exe
348 C:\PROGRA~2\AVG\AVG10\avgchsva.exe
404 C:\PROGRA~2\AVG\AVG10\avgrsa.exe
548 csrss.exe
612 C:\Windows\System32\wininit.exe
632 csrss.exe
664 C:\Windows\System32\services.exe
704 C:\Windows\System32\lsass.exe
712 C:\Windows\System32\lsm.exe
728 C:\Windows\System32\winlogon.exe
844 C:\Windows\System32\svchost.exe
916 C:\Windows\System32\svchost.exe
332 C:\Windows\System32\svchost.exe
396 C:\Windows\System32\svchost.exe
556 C:\Windows\System32\svchost.exe
480 C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\stacsv64.exe
860 C:\Windows\System32\audiodg.exe
1152 C:\Windows\System32\svchost.exe
1196 C:\Windows\System32\hpservice.exe
1272 C:\Windows\System32\svchost.exe
1444 C:\Windows\System32\wlanext.exe
1452 C:\Windows\System32\conhost.exe
1544 C:\Windows\System32\spoolsv.exe
1596 C:\Windows\System32\svchost.exe
1684 C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe
1712 C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
1744 C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe
1780 C:\Program Files (x86)\Bonjour\mDNSResponder.exe
1856 C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
1896 C:\Windows\System32\svchost.exe
1924 C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe
2000 C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
788 C:\Windows\System32\svchost.exe
1460 C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
2080 unsecapp.exe
2172 WmiPrvSE.exe
2372 C:\Windows\System32\taskhost.exe
2456 C:\Windows\System32\dwm.exe
2480 C:\Windows\System32\taskeng.exe
2540 C:\Windows\explorer.exe
2672 C:\Program Files (x86)\AVG\AVG10\avgnsa.exe
2700 C:\Program Files (x86)\AVG\AVG10\avgemca.exe
2712 C:\Windows\System32\conhost.exe
2532 C:\Windows\System32\igfxtray.exe
3096 C:\Windows\System32\hkcmd.exe
3108 C:\Windows\System32\igfxpers.exe
3124 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
3136 C:\Program Files\IDT\WDM\sttray64.exe
3144 C:\Program Files\Java\jre6\bin\jusched.exe
3184 C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
3200 C:\Windows\System32\igfxsrvc.exe
3252 C:\Windows\System32\spool\drivers\x64\3\E_IATIAEA.EXE
3392 C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
3404 C:\Program Files (x86)\Common Files\Nikon\Monitor\NkMonitor.exe
3544 C:\Program Files (x86)\iTunes\iTunesHelper.exe
3564 C:\Program Files (x86)\AVG\AVG10\avgtray.exe
3640 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
4024 C:\Windows\System32\SearchIndexer.exe
3468 C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
3372 C:\Program Files\iPod\bin\iPodService.exe
3648 WmiPrvSE.exe
3828 C:\Program Files\Windows Media Player\wmpnetwk.exe
3972 C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
4028 C:\Windows\System32\conhost.exe
3852 C:\Windows\System32\SearchProtocolHost.exe
3388 C:\Windows\System32\SearchFilterHost.exe
3300 C:\Windows\System32\svchost.exe
4216 C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
4444 C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
4852 C:\Program Files (x86)\Mozilla Firefox\firefox.exe
5000 C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
4712 C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
4188 C:\Users\Sigrid\Desktop\MBRCheck.exe
3332 C:\Windows\System32\conhost.exe
4492 C:\Windows\System32\dllhost.exe
4956 C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe
1616 C:\Windows\System32\sppsvc.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`0c800000 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000071`3fe00000 (NTFS)

PhysicalDrive0 Model Number: FUJITSUMJA2500BHG2, Rev: 8919

Size Device Name MBR Status
--------------------------------------------
465 GB \\.\PhysicalDrive0 Windows 7 MBR code detected
SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79


Done!

descriptionRedirect Trojan or Malware - Page 1 EmptyRe: Redirect Trojan or Malware

more_horiz
Heh, that killed the bootkit infection.

Run ESET Online Scan
Please do an online scan with ESET Online Scanner. Please use Internet Explorer as it uses ActiveX.

  • Check (tick) this box: YES, I accept the Terms of Use.
  • Click on the Start button next to it.
  • When prompted to run ActiveX. click Yes.
  • You will be asked to install an ActiveX. Click Install.
  • Once installed, the scanner will be initialized.
  • After the scanner is initialized, click Start.
  • Check (tick) Remove found threats box.
  • Check (tick) Scan unwanted applications.
  • Click on Scan.
  • It will start scanning. Please be patient.
  • Once the scan is done, the log will be saved here: C:\Program Files\esetonlinescanner\log.txt.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Redirect Trojan or Malware - Page 1 DXwU4
Redirect Trojan or Malware - Page 1 VvYDg

descriptionRedirect Trojan or Malware - Page 1 EmptyRe: Redirect Trojan or Malware

more_horiz
Scan Results were No Threat Found


Contents of log

ESETSmartInstaller@High as CAB hook log:
OnlineScanner64.ocx - registred OK
OnlineScanner.ocx - registred OK

descriptionRedirect Trojan or Malware - Page 1 EmptyRe: Redirect Trojan or Malware

more_horiz
How is the machine running now?

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Redirect Trojan or Malware - Page 1 DXwU4
Redirect Trojan or Malware - Page 1 VvYDg

descriptionRedirect Trojan or Malware - Page 1 EmptyRe: Redirect Trojan or Malware

more_horiz
It seems to be fine - I haven't had a redirect since we fixed our router and I haven't noticed any other problems.

Thank you very much for your help!

descriptionRedirect Trojan or Malware - Page 1 EmptyRe: Redirect Trojan or Malware

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum