systemmistress
Posts: 73 +0
Hi,
I thought I was totally lost, but due to the teasting requirements you recommend, I think my whole problem is because Avast 4 is locked in Self-Protect mode and also is locking me out of my Recovery Drive partition. Maybe this is why the odd test results? I did one weeks worth of investigating, reading, studying and clean-up of my machine and now it all makes sense.
I have a :Summary HP, Compaq Presario, SR1920NX.
Operating System
MS Windows XP Home 32-bit SP3
CPU
AMD Athlon 64 3500+ 43 °C
Venice 90nm Technology
RAM
512MB Dual-Channel DDR @ 200MHz (3-3-3-8)
Motherboard
ASUSTek Computer INC. NAGAMI2L (Socket 939)
Graphics
COMPAQ FS7600 @ 1024x768
nVidia video (HP)
Hard Drives
195GB SAMSUNG SP2004C (IDE) 41 °C
Optical Drives
PHILIPS DVD8851
Audio
Realtek High Definition Audio
Operating System
MS Windows XP Home 32-bit SP3
Installation Date: 30 March 2009, 07:14
CPU
AMD Athlon 64 3500+Core Memory slots
Total memory slots 4
Used memory slots 2
Free memory slots 2
Memory
Type DDR
Size 512 MBytes
Channels # Dual
DRAM Frequency 200.4 MHz
CAS# Latency (CL) 3 clocks
RAS# to CAS# Delay (tRCD) 3 clocks
RAS# Precharge (tRP) 3 clocks
Cycle Time (tRAS) 8 clocks
Bank Cycle Time (tR?) 11 clocks
Command Rate (CR) 2T
SPD
Number Of SPD Modules 2
Slot #1
Type DDR
Size 256 MBytes
Manufacturer Hyundai Electronics
Max Bandwidth PC3200 (200 MHz)
Here are the Results:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4490
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
8/27/2010 3:46:14 PM
mbam-log-2010-08-27 (15-46-14).txt
Scan type: Full scan (C:\|)
Objects scanned: 182135
Time elapsed: 20 minute(s), 44 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-08-27 15:55:39
Windows 5.1.2600 Service Pack 3
Running: k3h5kxm2[1].exe; Driver: C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\uwlcraoc.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- EOF - GMER 1.0.15 ----
I even tried to delete the above with Revo Uninstaller, CCleaner, Add/Rem Programs, by hand, and withFile Assassin..nothing worked. And I tried more than once.
Alwil Software, Avast4 resides in my Local Drive of all places..I would have thought it would have been in C:\\.
Here is the other result:
[I will give my opinion of the results, based on a popup I got from my computer, which told me I could no longer access my partition "for safety reasons" from Avast]. when you see the testing results]
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows XP Home Edition
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x000001fd
Kernel Drivers (total 125):
0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
0x806D0000 \WINDOWS\system32\hal.dll
0xF79DC000 \WINDOWS\system32\KDCOM.DLL
0xF78EC000 \WINDOWS\system32\BOOTVID.dll
0xF73AD000 ACPI.sys
0xF79DE000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xF739C000 pci.sys
0xF74DC000 isapnp.sys
0xF7AA4000 pciide.sys
0xF775C000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xF79E0000 viaide.sys
0xF79E2000 intelide.sys
0xF74EC000 MountMgr.sys
0xF737D000 ftdisk.sys
0xF7764000 PartMgr.sys
0xF74FC000 VolSnap.sys
0xF72A8000 iaStor.sys
0xF7290000 atapi.sys
0xF750C000 disk.sys
0xF751C000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xF7270000 fltmgr.sys
0xF725E000 sr.sys
0xF752C000 PxHelp20.sys
0xF7247000 KSecDD.sys
0xF71BA000 Ntfs.sys
0xF718D000 NDIS.sys
0xF716E000 xpacket.sys
0xF7154000 Mup.sys
0xF770C000 \SystemRoot\system32\DRIVERS\AmdK8.sys
0xF6BC9000 \SystemRoot\system32\DRIVERS\nv4_mini.sys
0xF6BB5000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xF7834000 \SystemRoot\system32\DRIVERS\usbohci.sys
0xF6B91000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xF783C000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xF771C000 \SystemRoot\system32\DRIVERS\imapi.sys
0xF772C000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xF773C000 \SystemRoot\system32\DRIVERS\redbook.sys
0xF6B6E000 \SystemRoot\system32\DRIVERS\ks.sys
0xF6A51000 \SystemRoot\system32\DRIVERS\AGRSM.sys
0xF7A04000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xF784C000 \SystemRoot\System32\Drivers\Modem.SYS
0xF6A29000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0xF79C8000 \SystemRoot\system32\DRIVERS\nvnetbus.sys
0xF69DE000 \SystemRoot\system32\DRIVERS\NVNRM.SYS
0xF69A7000 \SystemRoot\system32\DRIVERS\NVSNPU.SYS
0xF774C000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0xF7854000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xF7A08000 \SystemRoot\System32\Drivers\RootMdm.sys
0xF7BE9000 \SystemRoot\system32\DRIVERS\audstub.sys
0xF755C000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xF79CC000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xF6990000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xF756C000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xF757C000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xF785C000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xF697F000 \SystemRoot\system32\DRIVERS\psched.sys
0xF758C000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xF7864000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xF786C000 \SystemRoot\system32\DRIVERS\raspti.sys
0xF6943000 \SystemRoot\system32\DRIVERS\parport.sys
0xF759C000 \SystemRoot\system32\DRIVERS\termdd.sys
0xF7874000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xF7A0C000 \SystemRoot\system32\DRIVERS\swenum.sys
0xF68E5000 \SystemRoot\system32\DRIVERS\update.sys
0xF6F4D000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xF75AC000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xF75BC000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xF75CC000 \SystemRoot\system32\DRIVERS\NVENETFD.sys
0xF30DA000 \SystemRoot\system32\drivers\RtkHDAud.sys
0xF30B6000 \SystemRoot\system32\drivers\portcls.sys
0xF75DC000 \SystemRoot\system32\drivers\drmk.sys
0xF7A10000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xF7B81000 \SystemRoot\System32\Drivers\Null.SYS
0xF7A12000 \SystemRoot\System32\Drivers\Beep.SYS
0xF78B4000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0xF78BC000 \SystemRoot\System32\drivers\vga.sys
0xF7A14000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xF7A16000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xF78C4000 \SystemRoot\System32\Drivers\Msfs.SYS
0xF78CC000 \SystemRoot\System32\Drivers\Npfs.SYS
0xF7990000 \SystemRoot\system32\DRIVERS\rasacd.sys
0xF3033000 \SystemRoot\system32\DRIVERS\ipsec.sys
0xF2FDA000 \SystemRoot\system32\DRIVERS\tcpip.sys
0xF2FB2000 \SystemRoot\system32\DRIVERS\netbt.sys
0xF75FC000 \SystemRoot\System32\Drivers\aswTdi.SYS
0xF2F90000 \SystemRoot\System32\drivers\afd.sys
0xF760C000 \SystemRoot\system32\DRIVERS\netbios.sys
0xF2F6E000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
0xF78D4000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
0xF2F43000 \SystemRoot\system32\DRIVERS\rdbss.sys
0xF2ED3000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xF762C000 \SystemRoot\System32\Drivers\Fips.SYS
0xF2EAD000 \SystemRoot\system32\DRIVERS\ipnat.sys
0xF763C000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xF78DC000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0xF696F000 \SystemRoot\system32\DRIVERS\hidusb.sys
0xF764C000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0xF2E64000 \SystemRoot\System32\Drivers\aswSP.SYS
0xF78E4000 \SystemRoot\System32\Drivers\Aavmker4.SYS
0xF77A4000 \SystemRoot\system32\DRIVERS\usbprint.sys
0xF696B000 \SystemRoot\system32\DRIVERS\sfloppy.sys
0xF6967000 \SystemRoot\system32\DRIVERS\mouhid.sys
0xF695F000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0xF2E40000 \SystemRoot\System32\Drivers\Fastfat.SYS
0xF2E28000 \SystemRoot\System32\Drivers\dump_atapi.sys
0xF7A24000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0xF308E000 \SystemRoot\System32\drivers\Dxapi.sys
0xF77BC000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xF7B15000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF012000 \SystemRoot\System32\nv4_disp.dll
0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
0xF7894000 \SystemRoot\system32\DRIVERS\aswFsBlk.sys
0xBA51C000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xBA391000 \SystemRoot\System32\Drivers\aswMon2.SYS
0xB9A59000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xB97BC000 \SystemRoot\system32\drivers\wdmaud.sys
0xB99A1000 \SystemRoot\system32\drivers\sysaudio.sys
0xB9587000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0xB93F0000 \SystemRoot\system32\DRIVERS\srv.sys
0xB9107000 \SystemRoot\System32\Drivers\HTTP.sys
0xB7BBC000 \??\C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\uwlcraoc.sys
0xB7ACF000 \SystemRoot\system32\drivers\kmixer.sys
0x7C900000 \WINDOWS\system32\ntdll.dll
Processes (total 33):
0 System Idle Process
4 System
592 C:\WINDOWS\system32\smss.exe
656 csrss.exe
680 C:\WINDOWS\system32\winlogon.exe
724 C:\WINDOWS\system32\services.exe
736 C:\WINDOWS\system32\lsass.exe
900 C:\WINDOWS\system32\svchost.exe
948 svchost.exe
1044 C:\WINDOWS\system32\svchost.exe
1092 svchost.exe
1184 svchost.exe
1568 C:\WINDOWS\explorer.exe
1780 C:\WINDOWS\RTHDCPL.EXE
1832 C:\Program Files\PeoplePC\ISP7000\Browser\BartShel.exe
1828 C:\Program Files\Common Files\Java\Java Update\jusched.exe
1848 C:\Program Files\Filseclab\xfilter\xfilter.exe
1864 C:\WINDOWS\system32\ctfmon.exe
660 C:\WINDOWS\system32\spoolsv.exe
152 C:\WINDOWS\system\hpsysdrv.exe
1448 svchost.exe
444 C:\Program Files\LSI SoftModem\agrsmsvc.exe
456 aspnet_state.exe
1920 PresentationFontCache.exe
564 C:\Program Files\Java\jre6\bin\jqs.exe
584 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
1000 C:\WINDOWS\system32\nvsvc32.exe
2448 alg.exe
2812 C:\PROGRA~1\PeoplePC\ISP7000\Browser\PPShared.exe
2956 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
4092 C:\Program Files\Internet Explorer\iexplore.exe
1932 C:\Program Files\Internet Explorer\iexplore.exe
2820 C:\Documents and Settings\Compaq_Owner\Desktop\MBRCheck.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x0000002c`c0050e00 (FAT32)
PhysicalDrive0 Model Number: SAMSUNGSP2004C, Rev: VM100-54
Size Device Name MBR Status
--------------------------------------------
186 GB \\.\PhysicalDrive0 Unknown MBR code
SHA1: 3FA1BAC1D7FD18071BE2B53E6001CD7DFE278CEB
Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
Options:
[1] Dump the MBR of a physical disk to file.
[2] Restore the MBR of a physical disk with a standard boot code.
[3] Exit.
Enter your choice: 3
Done!
My thoughts on this odd results is that Avast has locked me out of my partition [D Drive] and it cannot be read..I am probably wrong.
My symptoms are hangs, freezes to the point when I have to hit the 'kill' button because nothing works. I just blamed all this on Firefox's Plug-in Container...I had better apologize..I do not think this is trhe problem, as I uninstalled FF 3.6.8, and am using 3.5.11. I also read that lots of my symptoms are the same as those on the forums at Mozilla as well. I wonder now.
All of the online scans for malware and viruses came up clean for me except the big one in MBam..I guess I should attach that huge file as well. You did not seem to want it from the other person you helped with a locked Avast..I do have it if needed.
Thanx very much, I am sorry to be so windy, but I want you to know that I tried myself. This is sort of a last resort for me, as I do not give up easily.
Thank you very much.
Systemmistress
I thought I was totally lost, but due to the teasting requirements you recommend, I think my whole problem is because Avast 4 is locked in Self-Protect mode and also is locking me out of my Recovery Drive partition. Maybe this is why the odd test results? I did one weeks worth of investigating, reading, studying and clean-up of my machine and now it all makes sense.
I have a :Summary HP, Compaq Presario, SR1920NX.
Operating System
MS Windows XP Home 32-bit SP3
CPU
AMD Athlon 64 3500+ 43 °C
Venice 90nm Technology
RAM
512MB Dual-Channel DDR @ 200MHz (3-3-3-8)
Motherboard
ASUSTek Computer INC. NAGAMI2L (Socket 939)
Graphics
COMPAQ FS7600 @ 1024x768
nVidia video (HP)
Hard Drives
195GB SAMSUNG SP2004C (IDE) 41 °C
Optical Drives
PHILIPS DVD8851
Audio
Realtek High Definition Audio
Operating System
MS Windows XP Home 32-bit SP3
Installation Date: 30 March 2009, 07:14
CPU
AMD Athlon 64 3500+Core Memory slots
Total memory slots 4
Used memory slots 2
Free memory slots 2
Memory
Type DDR
Size 512 MBytes
Channels # Dual
DRAM Frequency 200.4 MHz
CAS# Latency (CL) 3 clocks
RAS# to CAS# Delay (tRCD) 3 clocks
RAS# Precharge (tRP) 3 clocks
Cycle Time (tRAS) 8 clocks
Bank Cycle Time (tR?) 11 clocks
Command Rate (CR) 2T
SPD
Number Of SPD Modules 2
Slot #1
Type DDR
Size 256 MBytes
Manufacturer Hyundai Electronics
Max Bandwidth PC3200 (200 MHz)
Here are the Results:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4490
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
8/27/2010 3:46:14 PM
mbam-log-2010-08-27 (15-46-14).txt
Scan type: Full scan (C:\|)
Objects scanned: 182135
Time elapsed: 20 minute(s), 44 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-08-27 15:55:39
Windows 5.1.2600 Service Pack 3
Running: k3h5kxm2[1].exe; Driver: C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\uwlcraoc.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- EOF - GMER 1.0.15 ----
I even tried to delete the above with Revo Uninstaller, CCleaner, Add/Rem Programs, by hand, and withFile Assassin..nothing worked. And I tried more than once.
Alwil Software, Avast4 resides in my Local Drive of all places..I would have thought it would have been in C:\\.
Here is the other result:
[I will give my opinion of the results, based on a popup I got from my computer, which told me I could no longer access my partition "for safety reasons" from Avast]. when you see the testing results]
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows XP Home Edition
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x000001fd
Kernel Drivers (total 125):
0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
0x806D0000 \WINDOWS\system32\hal.dll
0xF79DC000 \WINDOWS\system32\KDCOM.DLL
0xF78EC000 \WINDOWS\system32\BOOTVID.dll
0xF73AD000 ACPI.sys
0xF79DE000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xF739C000 pci.sys
0xF74DC000 isapnp.sys
0xF7AA4000 pciide.sys
0xF775C000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xF79E0000 viaide.sys
0xF79E2000 intelide.sys
0xF74EC000 MountMgr.sys
0xF737D000 ftdisk.sys
0xF7764000 PartMgr.sys
0xF74FC000 VolSnap.sys
0xF72A8000 iaStor.sys
0xF7290000 atapi.sys
0xF750C000 disk.sys
0xF751C000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xF7270000 fltmgr.sys
0xF725E000 sr.sys
0xF752C000 PxHelp20.sys
0xF7247000 KSecDD.sys
0xF71BA000 Ntfs.sys
0xF718D000 NDIS.sys
0xF716E000 xpacket.sys
0xF7154000 Mup.sys
0xF770C000 \SystemRoot\system32\DRIVERS\AmdK8.sys
0xF6BC9000 \SystemRoot\system32\DRIVERS\nv4_mini.sys
0xF6BB5000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xF7834000 \SystemRoot\system32\DRIVERS\usbohci.sys
0xF6B91000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xF783C000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xF771C000 \SystemRoot\system32\DRIVERS\imapi.sys
0xF772C000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xF773C000 \SystemRoot\system32\DRIVERS\redbook.sys
0xF6B6E000 \SystemRoot\system32\DRIVERS\ks.sys
0xF6A51000 \SystemRoot\system32\DRIVERS\AGRSM.sys
0xF7A04000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xF784C000 \SystemRoot\System32\Drivers\Modem.SYS
0xF6A29000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0xF79C8000 \SystemRoot\system32\DRIVERS\nvnetbus.sys
0xF69DE000 \SystemRoot\system32\DRIVERS\NVNRM.SYS
0xF69A7000 \SystemRoot\system32\DRIVERS\NVSNPU.SYS
0xF774C000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0xF7854000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xF7A08000 \SystemRoot\System32\Drivers\RootMdm.sys
0xF7BE9000 \SystemRoot\system32\DRIVERS\audstub.sys
0xF755C000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xF79CC000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xF6990000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xF756C000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xF757C000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xF785C000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xF697F000 \SystemRoot\system32\DRIVERS\psched.sys
0xF758C000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xF7864000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xF786C000 \SystemRoot\system32\DRIVERS\raspti.sys
0xF6943000 \SystemRoot\system32\DRIVERS\parport.sys
0xF759C000 \SystemRoot\system32\DRIVERS\termdd.sys
0xF7874000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xF7A0C000 \SystemRoot\system32\DRIVERS\swenum.sys
0xF68E5000 \SystemRoot\system32\DRIVERS\update.sys
0xF6F4D000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xF75AC000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xF75BC000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xF75CC000 \SystemRoot\system32\DRIVERS\NVENETFD.sys
0xF30DA000 \SystemRoot\system32\drivers\RtkHDAud.sys
0xF30B6000 \SystemRoot\system32\drivers\portcls.sys
0xF75DC000 \SystemRoot\system32\drivers\drmk.sys
0xF7A10000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xF7B81000 \SystemRoot\System32\Drivers\Null.SYS
0xF7A12000 \SystemRoot\System32\Drivers\Beep.SYS
0xF78B4000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0xF78BC000 \SystemRoot\System32\drivers\vga.sys
0xF7A14000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xF7A16000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xF78C4000 \SystemRoot\System32\Drivers\Msfs.SYS
0xF78CC000 \SystemRoot\System32\Drivers\Npfs.SYS
0xF7990000 \SystemRoot\system32\DRIVERS\rasacd.sys
0xF3033000 \SystemRoot\system32\DRIVERS\ipsec.sys
0xF2FDA000 \SystemRoot\system32\DRIVERS\tcpip.sys
0xF2FB2000 \SystemRoot\system32\DRIVERS\netbt.sys
0xF75FC000 \SystemRoot\System32\Drivers\aswTdi.SYS
0xF2F90000 \SystemRoot\System32\drivers\afd.sys
0xF760C000 \SystemRoot\system32\DRIVERS\netbios.sys
0xF2F6E000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
0xF78D4000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
0xF2F43000 \SystemRoot\system32\DRIVERS\rdbss.sys
0xF2ED3000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xF762C000 \SystemRoot\System32\Drivers\Fips.SYS
0xF2EAD000 \SystemRoot\system32\DRIVERS\ipnat.sys
0xF763C000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xF78DC000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0xF696F000 \SystemRoot\system32\DRIVERS\hidusb.sys
0xF764C000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0xF2E64000 \SystemRoot\System32\Drivers\aswSP.SYS
0xF78E4000 \SystemRoot\System32\Drivers\Aavmker4.SYS
0xF77A4000 \SystemRoot\system32\DRIVERS\usbprint.sys
0xF696B000 \SystemRoot\system32\DRIVERS\sfloppy.sys
0xF6967000 \SystemRoot\system32\DRIVERS\mouhid.sys
0xF695F000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0xF2E40000 \SystemRoot\System32\Drivers\Fastfat.SYS
0xF2E28000 \SystemRoot\System32\Drivers\dump_atapi.sys
0xF7A24000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0xF308E000 \SystemRoot\System32\drivers\Dxapi.sys
0xF77BC000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xF7B15000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF012000 \SystemRoot\System32\nv4_disp.dll
0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
0xF7894000 \SystemRoot\system32\DRIVERS\aswFsBlk.sys
0xBA51C000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xBA391000 \SystemRoot\System32\Drivers\aswMon2.SYS
0xB9A59000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xB97BC000 \SystemRoot\system32\drivers\wdmaud.sys
0xB99A1000 \SystemRoot\system32\drivers\sysaudio.sys
0xB9587000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0xB93F0000 \SystemRoot\system32\DRIVERS\srv.sys
0xB9107000 \SystemRoot\System32\Drivers\HTTP.sys
0xB7BBC000 \??\C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\uwlcraoc.sys
0xB7ACF000 \SystemRoot\system32\drivers\kmixer.sys
0x7C900000 \WINDOWS\system32\ntdll.dll
Processes (total 33):
0 System Idle Process
4 System
592 C:\WINDOWS\system32\smss.exe
656 csrss.exe
680 C:\WINDOWS\system32\winlogon.exe
724 C:\WINDOWS\system32\services.exe
736 C:\WINDOWS\system32\lsass.exe
900 C:\WINDOWS\system32\svchost.exe
948 svchost.exe
1044 C:\WINDOWS\system32\svchost.exe
1092 svchost.exe
1184 svchost.exe
1568 C:\WINDOWS\explorer.exe
1780 C:\WINDOWS\RTHDCPL.EXE
1832 C:\Program Files\PeoplePC\ISP7000\Browser\BartShel.exe
1828 C:\Program Files\Common Files\Java\Java Update\jusched.exe
1848 C:\Program Files\Filseclab\xfilter\xfilter.exe
1864 C:\WINDOWS\system32\ctfmon.exe
660 C:\WINDOWS\system32\spoolsv.exe
152 C:\WINDOWS\system\hpsysdrv.exe
1448 svchost.exe
444 C:\Program Files\LSI SoftModem\agrsmsvc.exe
456 aspnet_state.exe
1920 PresentationFontCache.exe
564 C:\Program Files\Java\jre6\bin\jqs.exe
584 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
1000 C:\WINDOWS\system32\nvsvc32.exe
2448 alg.exe
2812 C:\PROGRA~1\PeoplePC\ISP7000\Browser\PPShared.exe
2956 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
4092 C:\Program Files\Internet Explorer\iexplore.exe
1932 C:\Program Files\Internet Explorer\iexplore.exe
2820 C:\Documents and Settings\Compaq_Owner\Desktop\MBRCheck.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x0000002c`c0050e00 (FAT32)
PhysicalDrive0 Model Number: SAMSUNGSP2004C, Rev: VM100-54
Size Device Name MBR Status
--------------------------------------------
186 GB \\.\PhysicalDrive0 Unknown MBR code
SHA1: 3FA1BAC1D7FD18071BE2B53E6001CD7DFE278CEB
Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
Options:
[1] Dump the MBR of a physical disk to file.
[2] Restore the MBR of a physical disk with a standard boot code.
[3] Exit.
Enter your choice: 3
Done!
My thoughts on this odd results is that Avast has locked me out of my partition [D Drive] and it cannot be read..I am probably wrong.
My symptoms are hangs, freezes to the point when I have to hit the 'kill' button because nothing works. I just blamed all this on Firefox's Plug-in Container...I had better apologize..I do not think this is trhe problem, as I uninstalled FF 3.6.8, and am using 3.5.11. I also read that lots of my symptoms are the same as those on the forums at Mozilla as well. I wonder now.
All of the online scans for malware and viruses came up clean for me except the big one in MBam..I guess I should attach that huge file as well. You did not seem to want it from the other person you helped with a locked Avast..I do have it if needed.
Thanx very much, I am sorry to be so windy, but I want you to know that I tried myself. This is sort of a last resort for me, as I do not give up easily.
Thank you very much.
Systemmistress