I use Eset smart security 4 and it informed me I had a Win32/Mebroot Trojan virus in memory and it could not clean the virus.
I tried several AV Programs to get rid of it and Microsoft security essentials did the trick.
Now I keep getting a Eset warning that an address "www.tombirdswithhair.com/banner2" 178.17.162.242 is being blocked and the PC freezes for minutes at a time.
I redirected www.tombirdswithhair.com to 127.0.0.1 using the hosts file and that stops the block warning but my system is still freezing up.
I ran the MBR Check and it said I have "Whistler / Black Internet" in the MBR of both hard drives.
Thanks in advance for your assistance.
Some logs attached due to size limits
##########################################################################
Step 1: Antivirus scanning
I ran eset, superantispywear and Microsoft security essentials and cleaned all problerms.
##########################################################################
Step 2: Temporary File Cleaner - I ran this.
##########################################################################
Step 3: Malwarebytes Anti-Malware
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4466
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
8/23/2010 7:16:41 PM
mbam-log-2010-08-23 (19-16-41).txt
Scan type: Quick scan
Objects scanned: 164883
Time elapsed: 38 minute(s), 20 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Documents and Settings\All Users\Application Data\sysReserve.ini (Malware.Trace) -> Quarantined and deleted successfully.
##########################################################################
Step 4: GMER Log
Attached
##########################################################################
Step 5: DDS - DDS.txt
Attached
##########################################################################
Step 5: DDS - Attach.txt
Attached
##########################################################################
Additional Step MRBCheck scan log
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows XP Professional
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x0000003d
Kernel Drivers (total 205):
0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
0x806E4000 \WINDOWS\system32\hal.dll
0xF7B12000 \WINDOWS\system32\KDCOM.DLL
0xF7A22000 \WINDOWS\system32\BOOTVID.dll
0xF7612000 ekmeqyw.sys
0xF74E3000 ACPI.sys
0xF7B14000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xF74D2000 pci.sys
0xF7622000 isapnp.sys
0xF7BDA000 pciide.sys
0xF7892000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xF7B16000 aliide.sys
0xF7B18000 cmdide.sys
0xF7B1A000 toside.sys
0xF7B1C000 viaide.sys
0xF7B1E000 intelide.sys
0xF7632000 MountMgr.sys
0xF74B3000 ftdisk.sys
0xF7B20000 dmload.sys
0xF748D000 dmio.sys
0xF789A000 PartMgr.sys
0xF7642000 VolSnap.sys
0xF7A26000 cpqarray.sys
0xF7475000 \WINDOWS\system32\DRIVERS\SCSIPORT.SYS
0xF73B7000 iaStor.sys
0xF739F000 atapi.sys
0xF7A2A000 aha154x.sys
0xF78A2000 sparrow.sys
0xF7A2E000 symc810.sys
0xF7652000 aic78xx.sys
0xF7A32000 dac960nt.sys
0xF7662000 ql10wnt.sys
0xF7A36000 amsint.sys
0xF78AA000 asc.sys
0xF7A3A000 asc3550.sys
0xF78B2000 mraid35x.sys
0xF78BA000 i2omp.sys
0xF7A3E000 ini910u.sys
0xF7672000 ql1240.sys
0xF7682000 aic78u2.sys
0xF78C2000 symc8xx.sys
0xF78CA000 sym_hi.sys
0xF78D2000 sym_u3.sys
0xF78DA000 ABP480N5.SYS
0xF78E2000 asc3350p.sys
0xF7B22000 cd20xrnt.sys
0xF7692000 ultra.sys
0xF7386000 adpu160m.sys
0xF78EA000 dpti2o.sys
0xF76A2000 ql1080.sys
0xF76B2000 ql1280.sys
0xF76C2000 ql12160.sys
0xF78F2000 perc2.sys
0xF7B24000 perc2hib.sys
0xF78FA000 hpn.sys
0xF7A42000 cbidf2k.sys
0xF735A000 dac2w2k.sys
0xF76D2000 disk.sys
0xF76E2000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xF733A000 fltmgr.sys
0xF7325000 drvmcdb.sys
0xF76F2000 PxHelp20.sys
0xF730E000 KSecDD.sys
0xF7281000 Ntfs.sys
0xF7254000 NDIS.sys
0xF7702000 sisagp.sys
0xF7712000 viaagp.sys
0xF7722000 ohci1394.sys
0xF7732000 \WINDOWS\system32\DRIVERS\1394BUS.SYS
0xF723A000 Mup.sys
0xF7742000 agp440.sys
0xF7752000 alim1541.sys
0xF7762000 amdagp.sys
0xF7772000 agpCPQ.sys
0xF7792000 \SystemRoot\system32\DRIVERS\nic1394.sys
0xF6C43000 \SystemRoot\system32\DRIVERS\intelppm.sys
0xF5C4B000 \SystemRoot\system32\DRIVERS\nv4_mini.sys
0xF5C37000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xF5C09000 \SystemRoot\system32\DRIVERS\b57xp32.sys
0xF79FA000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0xF5BE5000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xF7A02000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xF796A000 \SystemRoot\system32\DRIVERS\usbohci.sys
0xF5BBA000 \SystemRoot\system32\drivers\aticxcap.sys
0xF6C33000 \SystemRoot\system32\drivers\STREAM.SYS
0xF5B97000 \SystemRoot\system32\drivers\ks.sys
0xF5B1D000 \SystemRoot\system32\drivers\ctaud2k.sys
0xF5AF9000 \SystemRoot\system32\drivers\portcls.sys
0xF6C23000 \SystemRoot\system32\drivers\drmk.sys
0xF5AC6000 \SystemRoot\system32\drivers\ctoss2k.sys
0xF7A0A000 \SystemRoot\System32\drivers\ctprxy2k.sys
0xF7090000 \SystemRoot\system32\DRIVERS\gameenum.sys
0xF7A12000 \SystemRoot\system32\DRIVERS\fdc.sys
0xF5AB2000 \SystemRoot\system32\DRIVERS\parport.sys
0xF6C13000 \SystemRoot\system32\DRIVERS\serial.sys
0xF708C000 \SystemRoot\system32\DRIVERS\serenum.sys
0xF7A1A000 \SystemRoot\system32\drivers\Afc.sys
0xF7B66000 \SystemRoot\system32\drivers\sscdbhk5.sys
0xF6569000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xF7902000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys
0xF7CCB000 \SystemRoot\system32\DRIVERS\lmimirr.sys
0xF5A97000 \SystemRoot\system32\DRIVERS\dne2000.sys
0xF6559000 \SystemRoot\system32\DRIVERS\Epfwndis.sys
0xF7CCC000 \SystemRoot\system32\DRIVERS\audstub.sys
0xF6549000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xF7088000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xF5A80000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xF6539000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xF6529000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xF7912000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xF5A6F000 \SystemRoot\system32\DRIVERS\psched.sys
0xF6519000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xF791A000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xF7922000 \SystemRoot\system32\DRIVERS\raspti.sys
0xF5A3F000 \SystemRoot\system32\DRIVERS\rdpdr.sys
0xF77D2000 \SystemRoot\system32\DRIVERS\termdd.sys
0xF79C2000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xF79CA000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xF7BCE000 \SystemRoot\system32\DRIVERS\swenum.sys
0xF33CD000 \SystemRoot\system32\DRIVERS\update.sys
0xF70A8000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xF79D2000 \SystemRoot\system32\DRIVERS\omci.sys
0xF77E2000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xF7802000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xF7BD0000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xEE293000 \SystemRoot\system32\drivers\aticxtun.sys
0xEEF06000 \SystemRoot\system32\drivers\aticxxbr.sys
0xEC2E3000 \SystemRoot\System32\drivers\hap16v2k.sys
0xEC1DF000 \SystemRoot\System32\drivers\ha10kx2k.sys
0xEC1B2000 \SystemRoot\System32\drivers\emupia2k.sys
0xEC18B000 \SystemRoot\System32\drivers\ctsfm2k.sys
0xEC0EF000 \SystemRoot\System32\drivers\ctac32k.sys
0xEE28B000 \SystemRoot\system32\DRIVERS\flpydisk.sys
0xEE11D000 \SystemRoot\System32\Drivers\i2omgmt.SYS
0xEC0A4000 \SystemRoot\system32\DRIVERS\MpFilter.sys
0xEEBB5000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0xEEF22000 \SystemRoot\System32\Drivers\cdrbsvsd.SYS
0xF7BC6000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xEF9CB000 \SystemRoot\System32\Drivers\Null.SYS
0xF7BC8000 \SystemRoot\System32\Drivers\Beep.SYS
0xEEBA5000 \SystemRoot\system32\drivers\ssrtln.sys
0xF0EEF000 \SystemRoot\system32\DRIVERS\ehdrv.sys
0xEEB9D000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0xEEB95000 \SystemRoot\System32\drivers\vga.sys
0xF7BCA000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xF7BCC000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xEEB8D000 \SystemRoot\System32\Drivers\Msfs.SYS
0xEE2AB000 \SystemRoot\System32\Drivers\Npfs.SYS
0xEEF16000 \SystemRoot\system32\DRIVERS\rasacd.sys
0xF0E1C000 \SystemRoot\system32\DRIVERS\ipsec.sys
0xF0DC3000 \SystemRoot\system32\DRIVERS\tcpip.sys
0xF0DB0000 \SystemRoot\system32\DRIVERS\epfwtdi.sys
0xF0D88000 \SystemRoot\system32\DRIVERS\netbt.sys
0xEEF12000 \SystemRoot\System32\drivers\ws2ifsl.sys
0xF0D42000 \SystemRoot\System32\drivers\afd.sys
0xEFA53000 \SystemRoot\system32\DRIVERS\netbios.sys
0xF0D20000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
0xEE2A3000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
0xF0CF5000 \SystemRoot\system32\DRIVERS\rdbss.sys
0xF0C85000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xEFA23000 \SystemRoot\System32\Drivers\Fips.SYS
0xEFA13000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xEFA03000 \SystemRoot\system32\DRIVERS\arp1394.sys
0xEDD6A000 \SystemRoot\system32\DRIVERS\usbscan.sys
0xEDD66000 \SystemRoot\system32\DRIVERS\hidusb.sys
0xEF9E3000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0xEFF12000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0xEFF0E000 \SystemRoot\system32\DRIVERS\mouhid.sys
0xEF477000 \SystemRoot\system32\DRIVERS\usbprint.sys
0xEF3F1000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xEBFE6000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0xBF800000 \SystemRoot\System32\win32k.sys
0xEF7F2000 \SystemRoot\System32\drivers\Dxapi.sys
0xEF45F000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xF7C84000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF012000 \SystemRoot\System32\nv4_disp.dll
0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
0xB96E3000 \SystemRoot\system32\DRIVERS\eamon.sys
0xF6027000 \SystemRoot\system32\drivers\drvnddm.sys
0xF7D48000 \SystemRoot\system32\dla\tfsndres.sys
0xB96CD000 \SystemRoot\system32\dla\tfsnifs.sys
0xF7AEE000 \SystemRoot\system32\dla\tfsnopio.sys
0xF4E9B000 \SystemRoot\system32\dla\tfsnpool.sys
0xEEF37000 \SystemRoot\system32\dla\tfsnboio.sys
0xF6017000 \SystemRoot\system32\dla\tfsncofs.sys
0xF7C51000 \SystemRoot\system32\dla\tfsndrct.sys
0xB96B4000 \SystemRoot\system32\dla\tfsnudf.sys
0xB969B000 \SystemRoot\system32\dla\tfsnudfa.sys
0xB9678000 \SystemRoot\system32\DRIVERS\epfw.sys
0xB8E23000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0xF623D000 \SystemRoot\System32\drivers\BrPar.sys
0xEF7E2000 \SystemRoot\System32\Drivers\ASPI32.SYS
0xB8CD6000 \??\C:\WINDOWS\system32\Drivers\CVPNDRVA.sys
0xB8C6D000 \SystemRoot\System32\Drivers\HTTP.sys
0xF7B3C000 \??\C:\Program Files\LogMeIn\x86\RaInfo.sys
0xB8B6E000 \SystemRoot\system32\DRIVERS\srv.sys
0xB8A91000 \SystemRoot\system32\drivers\wdmaud.sys
0xF7872000 \SystemRoot\system32\drivers\sysaudio.sys
0xB884A000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys
0xB8807000 \??\C:\WINDOWS\system32\drivers\PfModNT.sys
0xF7B88000 \??\C:\WINDOWS\system32\Drivers\Vcs.sys
0xB770E000 \SystemRoot\System32\Drivers\Fastfat.SYS
0xB630B000 \SystemRoot\system32\drivers\kmixer.sys
0x7C900000 \WINDOWS\SYSTEM32\ntdll.dll
Processes (total 48):
0 System Idle Process
4 System
1268 C:\WINDOWS\SYSTEM32\smss.exe
1320 csrss.exe
1348 C:\WINDOWS\SYSTEM32\winlogon.exe
1392 C:\WINDOWS\SYSTEM32\services.exe
1404 C:\WINDOWS\SYSTEM32\lsass.exe
1596 C:\WINDOWS\SYSTEM32\svchost.exe
1716 svchost.exe
1868 C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
1904 C:\WINDOWS\SYSTEM32\svchost.exe
2032 svchost.exe
476 C:\WINDOWS\SYSTEM32\spoolsv.exe
632 C:\WINDOWS\SYSTEM32\svchost.exe
644 svchost.exe
684 C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
912 C:\WINDOWS\SYSTEM32\CTSVCCDA.EXE
944 C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
1048 C:\Program Files\ESET\ESET Smart Security\ekrn.exe
1064 C:\WINDOWS\SYSTEM32\svchost.exe
1140 C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
1204 C:\WINDOWS\SYSTEM32\imapi.exe
1236 C:\Program Files\LogMeIn\x86\ramaint.exe
1620 C:\Program Files\LogMeIn\x86\LogMeIn.exe
576 C:\Program Files\LogMeIn\x86\LMIGuardian.exe
588 C:\WINDOWS\explorer.exe
1552 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
2144 C:\WINDOWS\SYSTEM32\nvsvc32.exe
2448 C:\WINDOWS\SYSTEM32\svchost.exe
2728 C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
2844 C:\Program Files\Canon\CAL\CALMAIN.exe
3304 C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
3424 C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.exe
3600 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
3616 C:\Program Files\Dell\Media Experience\DMXLauncher.exe
3688 C:\PROGRA~1\MICROS~4\GAMECO~1\Common\SWTrayV4.EXE
3740 C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe
3760 C:\WINDOWS\CTHELPER.EXE
3872 C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe
3880 C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
3976 C:\Program Files\ESET\ESET Smart Security\egui.exe
4080 C:\Program Files\Microsoft Security Essentials\msseces.exe
2380 C:\Program Files\LogMeIn\x86\LMIGuardian.exe
3500 C:\WINDOWS\SYSTEM32\ctfmon.exe
3576 C:\Program Files\ATI Multimedia\main\atidtct.exe
3716 C:\WINDOWS\SYSTEM32\svchost.exe
340 C:\Program Files\Mozilla Firefox\firefox.exe
4064 C:\Temp\Virus\MBRCheck.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`03ec1000 (NTFS)
\\.\D: --> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (NTFS)
PhysicalDrive0 Model Number: WDCWD2500JD-75HBB0, Rev: 08.02D08
PhysicalDrive1 Model Number: WDCWD1001FALS-00J7B0, Rev: 05.00K05
Size Device Name MBR Status
--------------------------------------------
232 GB \\.\PhysicalDrive0 Known-bad MBR code detected (Whistler / Black Internet)!
SHA1: 610C151EA6600B4828D09565D95688B3829C12B2
931 GB \\.\PhysicalDrive1 Known-bad MBR code detected (Whistler / Black Internet)!
SHA1: 610C151EA6600B4828D09565D95688B3829C12B2
Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
I tried several AV Programs to get rid of it and Microsoft security essentials did the trick.
Now I keep getting a Eset warning that an address "www.tombirdswithhair.com/banner2" 178.17.162.242 is being blocked and the PC freezes for minutes at a time.
I redirected www.tombirdswithhair.com to 127.0.0.1 using the hosts file and that stops the block warning but my system is still freezing up.
I ran the MBR Check and it said I have "Whistler / Black Internet" in the MBR of both hard drives.
Thanks in advance for your assistance.
Some logs attached due to size limits
##########################################################################
Step 1: Antivirus scanning
I ran eset, superantispywear and Microsoft security essentials and cleaned all problerms.
##########################################################################
Step 2: Temporary File Cleaner - I ran this.
##########################################################################
Step 3: Malwarebytes Anti-Malware
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4466
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
8/23/2010 7:16:41 PM
mbam-log-2010-08-23 (19-16-41).txt
Scan type: Quick scan
Objects scanned: 164883
Time elapsed: 38 minute(s), 20 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Documents and Settings\All Users\Application Data\sysReserve.ini (Malware.Trace) -> Quarantined and deleted successfully.
##########################################################################
Step 4: GMER Log
Attached
##########################################################################
Step 5: DDS - DDS.txt
Attached
##########################################################################
Step 5: DDS - Attach.txt
Attached
##########################################################################
Additional Step MRBCheck scan log
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows XP Professional
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x0000003d
Kernel Drivers (total 205):
0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
0x806E4000 \WINDOWS\system32\hal.dll
0xF7B12000 \WINDOWS\system32\KDCOM.DLL
0xF7A22000 \WINDOWS\system32\BOOTVID.dll
0xF7612000 ekmeqyw.sys
0xF74E3000 ACPI.sys
0xF7B14000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xF74D2000 pci.sys
0xF7622000 isapnp.sys
0xF7BDA000 pciide.sys
0xF7892000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xF7B16000 aliide.sys
0xF7B18000 cmdide.sys
0xF7B1A000 toside.sys
0xF7B1C000 viaide.sys
0xF7B1E000 intelide.sys
0xF7632000 MountMgr.sys
0xF74B3000 ftdisk.sys
0xF7B20000 dmload.sys
0xF748D000 dmio.sys
0xF789A000 PartMgr.sys
0xF7642000 VolSnap.sys
0xF7A26000 cpqarray.sys
0xF7475000 \WINDOWS\system32\DRIVERS\SCSIPORT.SYS
0xF73B7000 iaStor.sys
0xF739F000 atapi.sys
0xF7A2A000 aha154x.sys
0xF78A2000 sparrow.sys
0xF7A2E000 symc810.sys
0xF7652000 aic78xx.sys
0xF7A32000 dac960nt.sys
0xF7662000 ql10wnt.sys
0xF7A36000 amsint.sys
0xF78AA000 asc.sys
0xF7A3A000 asc3550.sys
0xF78B2000 mraid35x.sys
0xF78BA000 i2omp.sys
0xF7A3E000 ini910u.sys
0xF7672000 ql1240.sys
0xF7682000 aic78u2.sys
0xF78C2000 symc8xx.sys
0xF78CA000 sym_hi.sys
0xF78D2000 sym_u3.sys
0xF78DA000 ABP480N5.SYS
0xF78E2000 asc3350p.sys
0xF7B22000 cd20xrnt.sys
0xF7692000 ultra.sys
0xF7386000 adpu160m.sys
0xF78EA000 dpti2o.sys
0xF76A2000 ql1080.sys
0xF76B2000 ql1280.sys
0xF76C2000 ql12160.sys
0xF78F2000 perc2.sys
0xF7B24000 perc2hib.sys
0xF78FA000 hpn.sys
0xF7A42000 cbidf2k.sys
0xF735A000 dac2w2k.sys
0xF76D2000 disk.sys
0xF76E2000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xF733A000 fltmgr.sys
0xF7325000 drvmcdb.sys
0xF76F2000 PxHelp20.sys
0xF730E000 KSecDD.sys
0xF7281000 Ntfs.sys
0xF7254000 NDIS.sys
0xF7702000 sisagp.sys
0xF7712000 viaagp.sys
0xF7722000 ohci1394.sys
0xF7732000 \WINDOWS\system32\DRIVERS\1394BUS.SYS
0xF723A000 Mup.sys
0xF7742000 agp440.sys
0xF7752000 alim1541.sys
0xF7762000 amdagp.sys
0xF7772000 agpCPQ.sys
0xF7792000 \SystemRoot\system32\DRIVERS\nic1394.sys
0xF6C43000 \SystemRoot\system32\DRIVERS\intelppm.sys
0xF5C4B000 \SystemRoot\system32\DRIVERS\nv4_mini.sys
0xF5C37000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xF5C09000 \SystemRoot\system32\DRIVERS\b57xp32.sys
0xF79FA000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0xF5BE5000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xF7A02000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xF796A000 \SystemRoot\system32\DRIVERS\usbohci.sys
0xF5BBA000 \SystemRoot\system32\drivers\aticxcap.sys
0xF6C33000 \SystemRoot\system32\drivers\STREAM.SYS
0xF5B97000 \SystemRoot\system32\drivers\ks.sys
0xF5B1D000 \SystemRoot\system32\drivers\ctaud2k.sys
0xF5AF9000 \SystemRoot\system32\drivers\portcls.sys
0xF6C23000 \SystemRoot\system32\drivers\drmk.sys
0xF5AC6000 \SystemRoot\system32\drivers\ctoss2k.sys
0xF7A0A000 \SystemRoot\System32\drivers\ctprxy2k.sys
0xF7090000 \SystemRoot\system32\DRIVERS\gameenum.sys
0xF7A12000 \SystemRoot\system32\DRIVERS\fdc.sys
0xF5AB2000 \SystemRoot\system32\DRIVERS\parport.sys
0xF6C13000 \SystemRoot\system32\DRIVERS\serial.sys
0xF708C000 \SystemRoot\system32\DRIVERS\serenum.sys
0xF7A1A000 \SystemRoot\system32\drivers\Afc.sys
0xF7B66000 \SystemRoot\system32\drivers\sscdbhk5.sys
0xF6569000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xF7902000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys
0xF7CCB000 \SystemRoot\system32\DRIVERS\lmimirr.sys
0xF5A97000 \SystemRoot\system32\DRIVERS\dne2000.sys
0xF6559000 \SystemRoot\system32\DRIVERS\Epfwndis.sys
0xF7CCC000 \SystemRoot\system32\DRIVERS\audstub.sys
0xF6549000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xF7088000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xF5A80000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xF6539000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xF6529000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xF7912000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xF5A6F000 \SystemRoot\system32\DRIVERS\psched.sys
0xF6519000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xF791A000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xF7922000 \SystemRoot\system32\DRIVERS\raspti.sys
0xF5A3F000 \SystemRoot\system32\DRIVERS\rdpdr.sys
0xF77D2000 \SystemRoot\system32\DRIVERS\termdd.sys
0xF79C2000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xF79CA000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xF7BCE000 \SystemRoot\system32\DRIVERS\swenum.sys
0xF33CD000 \SystemRoot\system32\DRIVERS\update.sys
0xF70A8000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xF79D2000 \SystemRoot\system32\DRIVERS\omci.sys
0xF77E2000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xF7802000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xF7BD0000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xEE293000 \SystemRoot\system32\drivers\aticxtun.sys
0xEEF06000 \SystemRoot\system32\drivers\aticxxbr.sys
0xEC2E3000 \SystemRoot\System32\drivers\hap16v2k.sys
0xEC1DF000 \SystemRoot\System32\drivers\ha10kx2k.sys
0xEC1B2000 \SystemRoot\System32\drivers\emupia2k.sys
0xEC18B000 \SystemRoot\System32\drivers\ctsfm2k.sys
0xEC0EF000 \SystemRoot\System32\drivers\ctac32k.sys
0xEE28B000 \SystemRoot\system32\DRIVERS\flpydisk.sys
0xEE11D000 \SystemRoot\System32\Drivers\i2omgmt.SYS
0xEC0A4000 \SystemRoot\system32\DRIVERS\MpFilter.sys
0xEEBB5000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0xEEF22000 \SystemRoot\System32\Drivers\cdrbsvsd.SYS
0xF7BC6000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xEF9CB000 \SystemRoot\System32\Drivers\Null.SYS
0xF7BC8000 \SystemRoot\System32\Drivers\Beep.SYS
0xEEBA5000 \SystemRoot\system32\drivers\ssrtln.sys
0xF0EEF000 \SystemRoot\system32\DRIVERS\ehdrv.sys
0xEEB9D000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0xEEB95000 \SystemRoot\System32\drivers\vga.sys
0xF7BCA000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xF7BCC000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xEEB8D000 \SystemRoot\System32\Drivers\Msfs.SYS
0xEE2AB000 \SystemRoot\System32\Drivers\Npfs.SYS
0xEEF16000 \SystemRoot\system32\DRIVERS\rasacd.sys
0xF0E1C000 \SystemRoot\system32\DRIVERS\ipsec.sys
0xF0DC3000 \SystemRoot\system32\DRIVERS\tcpip.sys
0xF0DB0000 \SystemRoot\system32\DRIVERS\epfwtdi.sys
0xF0D88000 \SystemRoot\system32\DRIVERS\netbt.sys
0xEEF12000 \SystemRoot\System32\drivers\ws2ifsl.sys
0xF0D42000 \SystemRoot\System32\drivers\afd.sys
0xEFA53000 \SystemRoot\system32\DRIVERS\netbios.sys
0xF0D20000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
0xEE2A3000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
0xF0CF5000 \SystemRoot\system32\DRIVERS\rdbss.sys
0xF0C85000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xEFA23000 \SystemRoot\System32\Drivers\Fips.SYS
0xEFA13000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xEFA03000 \SystemRoot\system32\DRIVERS\arp1394.sys
0xEDD6A000 \SystemRoot\system32\DRIVERS\usbscan.sys
0xEDD66000 \SystemRoot\system32\DRIVERS\hidusb.sys
0xEF9E3000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0xEFF12000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0xEFF0E000 \SystemRoot\system32\DRIVERS\mouhid.sys
0xEF477000 \SystemRoot\system32\DRIVERS\usbprint.sys
0xEF3F1000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xEBFE6000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0xBF800000 \SystemRoot\System32\win32k.sys
0xEF7F2000 \SystemRoot\System32\drivers\Dxapi.sys
0xEF45F000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xF7C84000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF012000 \SystemRoot\System32\nv4_disp.dll
0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
0xB96E3000 \SystemRoot\system32\DRIVERS\eamon.sys
0xF6027000 \SystemRoot\system32\drivers\drvnddm.sys
0xF7D48000 \SystemRoot\system32\dla\tfsndres.sys
0xB96CD000 \SystemRoot\system32\dla\tfsnifs.sys
0xF7AEE000 \SystemRoot\system32\dla\tfsnopio.sys
0xF4E9B000 \SystemRoot\system32\dla\tfsnpool.sys
0xEEF37000 \SystemRoot\system32\dla\tfsnboio.sys
0xF6017000 \SystemRoot\system32\dla\tfsncofs.sys
0xF7C51000 \SystemRoot\system32\dla\tfsndrct.sys
0xB96B4000 \SystemRoot\system32\dla\tfsnudf.sys
0xB969B000 \SystemRoot\system32\dla\tfsnudfa.sys
0xB9678000 \SystemRoot\system32\DRIVERS\epfw.sys
0xB8E23000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0xF623D000 \SystemRoot\System32\drivers\BrPar.sys
0xEF7E2000 \SystemRoot\System32\Drivers\ASPI32.SYS
0xB8CD6000 \??\C:\WINDOWS\system32\Drivers\CVPNDRVA.sys
0xB8C6D000 \SystemRoot\System32\Drivers\HTTP.sys
0xF7B3C000 \??\C:\Program Files\LogMeIn\x86\RaInfo.sys
0xB8B6E000 \SystemRoot\system32\DRIVERS\srv.sys
0xB8A91000 \SystemRoot\system32\drivers\wdmaud.sys
0xF7872000 \SystemRoot\system32\drivers\sysaudio.sys
0xB884A000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys
0xB8807000 \??\C:\WINDOWS\system32\drivers\PfModNT.sys
0xF7B88000 \??\C:\WINDOWS\system32\Drivers\Vcs.sys
0xB770E000 \SystemRoot\System32\Drivers\Fastfat.SYS
0xB630B000 \SystemRoot\system32\drivers\kmixer.sys
0x7C900000 \WINDOWS\SYSTEM32\ntdll.dll
Processes (total 48):
0 System Idle Process
4 System
1268 C:\WINDOWS\SYSTEM32\smss.exe
1320 csrss.exe
1348 C:\WINDOWS\SYSTEM32\winlogon.exe
1392 C:\WINDOWS\SYSTEM32\services.exe
1404 C:\WINDOWS\SYSTEM32\lsass.exe
1596 C:\WINDOWS\SYSTEM32\svchost.exe
1716 svchost.exe
1868 C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
1904 C:\WINDOWS\SYSTEM32\svchost.exe
2032 svchost.exe
476 C:\WINDOWS\SYSTEM32\spoolsv.exe
632 C:\WINDOWS\SYSTEM32\svchost.exe
644 svchost.exe
684 C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
912 C:\WINDOWS\SYSTEM32\CTSVCCDA.EXE
944 C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
1048 C:\Program Files\ESET\ESET Smart Security\ekrn.exe
1064 C:\WINDOWS\SYSTEM32\svchost.exe
1140 C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
1204 C:\WINDOWS\SYSTEM32\imapi.exe
1236 C:\Program Files\LogMeIn\x86\ramaint.exe
1620 C:\Program Files\LogMeIn\x86\LogMeIn.exe
576 C:\Program Files\LogMeIn\x86\LMIGuardian.exe
588 C:\WINDOWS\explorer.exe
1552 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
2144 C:\WINDOWS\SYSTEM32\nvsvc32.exe
2448 C:\WINDOWS\SYSTEM32\svchost.exe
2728 C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
2844 C:\Program Files\Canon\CAL\CALMAIN.exe
3304 C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
3424 C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.exe
3600 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
3616 C:\Program Files\Dell\Media Experience\DMXLauncher.exe
3688 C:\PROGRA~1\MICROS~4\GAMECO~1\Common\SWTrayV4.EXE
3740 C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe
3760 C:\WINDOWS\CTHELPER.EXE
3872 C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe
3880 C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
3976 C:\Program Files\ESET\ESET Smart Security\egui.exe
4080 C:\Program Files\Microsoft Security Essentials\msseces.exe
2380 C:\Program Files\LogMeIn\x86\LMIGuardian.exe
3500 C:\WINDOWS\SYSTEM32\ctfmon.exe
3576 C:\Program Files\ATI Multimedia\main\atidtct.exe
3716 C:\WINDOWS\SYSTEM32\svchost.exe
340 C:\Program Files\Mozilla Firefox\firefox.exe
4064 C:\Temp\Virus\MBRCheck.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`03ec1000 (NTFS)
\\.\D: --> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (NTFS)
PhysicalDrive0 Model Number: WDCWD2500JD-75HBB0, Rev: 08.02D08
PhysicalDrive1 Model Number: WDCWD1001FALS-00J7B0, Rev: 05.00K05
Size Device Name MBR Status
--------------------------------------------
232 GB \\.\PhysicalDrive0 Known-bad MBR code detected (Whistler / Black Internet)!
SHA1: 610C151EA6600B4828D09565D95688B3829C12B2
931 GB \\.\PhysicalDrive1 Known-bad MBR code detected (Whistler / Black Internet)!
SHA1: 610C151EA6600B4828D09565D95688B3829C12B2
Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit: