This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

unwanted programs

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:43:31 PM, on 21/08/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18943)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\SGPSA\ie3sh.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Windows\WindowsMobile\wmdSync.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\wuauclt.exe
C:\WINDOWS\Tasks\y.exe
C:\WINDOWS\Tasks\y.exe
C:\WINDOWS\Tasks\y.exe
C:\WINDOWS\Tasks\y.exe
C:\WINDOWS\Tasks\y.exe
C:\WINDOWS\Tasks\y.exe
C:\WINDOWS\Tasks\y.exe
C:\WINDOWS\Tasks\y.exe
C:\WINDOWS\Tasks\y.exe
C:\Windows\helppane.exe
C:\WINDOWS\Tasks\y.exe
C:\Users\jassi\Downloads\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: PlaySushi - {21608B66-026F-4DCB-9244-0DACA328DCED} - C:\Program Files\PlaySushi\PSText.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
O2 - BHO: UrlHelper Class - {474597C5-AB09-49d6-A4D5-2E8D7341384E} - C:\Program Files\iMesh Applications\MediaBar\DataMngr\IEBHO.dll (file missing)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\tbDVDV.dll
O2 - BHO: BrowserHelper Class - {8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6} - C:\Program Files\SGPSA\SearchAssistant.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: PriceGong - {D2A2595C-4FE4-4315-AA9B-19DBD6271B71} - C:\Program Files\PriceGong\1.5.0\PriceGongIE.dll (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVD1.dll
O2 - BHO: Bandoo IE Plugin - {EB5CEE80-030A-4ED8-8E20-454E9C68380F} - C:\Program Files\Bandoo\Plugins\IE\ieplugin.dll
O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:\Program Files\SGPSA\BHO.dll
O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll (file missing)
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Fast Browser Search Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll (file missing)
O3 - Toolbar: DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVD1.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\tbDVDV.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [FBSSA] C:\Program Files\SGPSA\ie3sh.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Microsoft Updat] C:\WINDOWS\Tasks\sqlservr.exe
O4 - Startup: Microsoft.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: Go to PlaySushi web site - {EBD24BD3-E272-4FA3-A8BA-C5D709757CAB} - C:\Program Files\PlaySushi\PSText.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppD…ap/PhtPkMSN.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - AppInit_DLLs: c:\progra~1\bandoo\bndhook.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bandoo Coordinator - Discordia Limited - C:\PROGRA~1\Bandoo\Bandoo.exe
O23 - Service: Google Update Service (gupdate1ca711fd19c5e79) (gupdate1ca711fd19c5e79) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Registry Helper Service - SafeApp Software, LLC - C:\Program Files\Registry Helper\RegistryHelperService.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 11676 bytes
:(
Hi trender, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Open hijackthis, do a system scan only and checkmark these lines, if present

O4 - HKCU\..\Run: [Microsoft Updat] C:\WINDOWS\Tasks\sqlservr.exe
O4 - Startup: Microsoft.exe


Close ALL other windows/browsers and click Fix Checked. Answer Yes if prompted. Close HJT.



Important Reboot your computer.

Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.


Next

Go HERE to get a randomly named copy of GMER. Scroll down to the Download section and click Download EXE. Save it to your desktop.

Before scanning with GMER, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

  • Right click on the file you downloaded and selct "Run as Administrator". If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER will not run in normal windows, please run it in Safe Mode



Next

Download OTL to your desktop.
  • Right click on OTL.exe and select "Run as Administrator" to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Please post back with
  • MBRCheck log
  • Gmer log
  • both OTL logs
Are you still hearing the audio?

Thanks
Heyya thanks alot Oldman960. I did as you said but when i came to 'Gmer' it kinda didnt work because as soon as the scan was over it said something like Gmer can not find any system modifications.:o,still i saved it then when i checked it on notepad the page was blank.so i really need help at this step.I clicked scan twice for this program but both the times it said that.I thought that i should get an advice before i carry on to the next step so if u can please help! I just noticed that the guy that speaks without any running a certain program on my computer ,talks for some www.hacksforsale.com..whenever i turn on the speakers after like 30 seconds this guy turns on and since this is happening i cannot turn up the volume from the speaker icon too:( It just stays at '0' even if i click to the highest like 100 it still drops down to 0 everytime.HELP! :pullhair: The MBR scan went well so I am going to post the MBRcheck log. MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows Vista Home Basic Edition Windows Information: Service Pack 2 (build 6002), 32-bit Base Board Manufacturer: eMachines BIOS Manufacturer: Phoenix Technologies, LTD System Manufacturer: eMachines System Product Name: EL1200-06h Logical Drives Mask: 0x0000007c Kernel Drivers (total 127): 0x81C0D000 \SystemRoot\system32\ntkrnlpa.exe 0x81FC6000 \SystemRoot\system32\hal.dll 0x80403000 \SystemRoot\system32\kdcom.dll 0x8040A000 \SystemRoot\system32\PSHED.dll 0x8041B000 \SystemRoot\system32\BOOTVID.dll 0x80423000 \SystemRoot\system32\CLFS.SYS 0x80464000 \SystemRoot\system32\CI.dll 0x80544000 \SystemRoot\system32\drivers\Wdf01000.sys 0x805C0000 \SystemRoot\system32\drivers\WDFLDR.SYS 0x8060E000 \SystemRoot\system32\drivers\acpi.sys 0x80654000 \SystemRoot\system32\drivers\WMILIB.SYS 0x8065D000 \SystemRoot\system32\drivers\msisadrv.sys 0x80665000 \SystemRoot\system32\drivers\pci.sys 0x8068C000 \SystemRoot\System32\drivers\partmgr.sys 0x8069B000 \SystemRoot\system32\drivers\volmgr.sys 0x806AA000 \SystemRoot\System32\drivers\volmgrx.sys 0x806F4000 \SystemRoot\system32\drivers\pciide.sys 0x806FB000 \SystemRoot\system32\drivers\PCIIDEX.SYS 0x80709000 \SystemRoot\System32\drivers\mountmgr.sys 0x80719000 \SystemRoot\system32\drivers\atapi.sys 0x80721000 \SystemRoot\system32\drivers\ataport.SYS 0x8073F000 \SystemRoot\system32\drivers\nvstor.sys 0x8074C000 \SystemRoot\system32\drivers\storport.sys 0x8078D000 \SystemRoot\system32\drivers\fltmgr.sys 0x807BF000 \SystemRoot\system32\drivers\fileinfo.sys 0x82208000 \SystemRoot\System32\Drivers\ksecdd.sys 0x82279000 \SystemRoot\system32\drivers\ndis.sys 0x82384000 \SystemRoot\system32\drivers\msrpc.sys 0x823AF000 \SystemRoot\system32\drivers\NETIO.SYS 0x86E0C000 \SystemRoot\System32\Drivers\Ntfs.sys 0x86F1C000 \SystemRoot\system32\drivers\volsnap.sys 0x86F55000 \SystemRoot\System32\Drivers\spldr.sys 0x86F5D000 \SystemRoot\System32\Drivers\mup.sys 0x86F6C000 \SystemRoot\System32\drivers\ecache.sys 0x86F93000 \SystemRoot\system32\drivers\disk.sys 0x86FA4000 \SystemRoot\system32\drivers\CLASSPNP.SYS 0x86FC5000 \SystemRoot\system32\drivers\crcdisk.sys 0x86FF2000 \SystemRoot\system32\DRIVERS\tunnel.sys 0x86E00000 \SystemRoot\system32\DRIVERS\tunmp.sys 0x823EA000 \SystemRoot\system32\DRIVERS\amdk8.sys 0x807CF000 \SystemRoot\system32\DRIVERS\wmiacpi.sys 0x807D8000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0x807EB000 \SystemRoot\system32\DRIVERS\mouclass.sys 0x80600000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0x807F6000 \SystemRoot\system32\DRIVERS\usbohci.sys 0x8A40F000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0x8A44D000 \SystemRoot\system32\DRIVERS\usbehci.sys 0x8A45C000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0x8A4E9000 \SystemRoot\system32\DRIVERS\nvm60x32.sys 0x8A5AB000 \SystemRoot\system32\DRIVERS\cdrom.sys 0x8A5C3000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys 0x8A802000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys 0x8B263000 \SystemRoot\system32\DRIVERS\nvBridge.kmd 0x8B265000 \SystemRoot\System32\drivers\dxgkrnl.sys 0x8B306000 \SystemRoot\System32\drivers\watchdog.sys 0x8B312000 \SystemRoot\system32\DRIVERS\msiscsi.sys 0x8B341000 \SystemRoot\system32\DRIVERS\TDI.SYS 0x8B34C000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0x8B363000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0x8B36E000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0x8B391000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0x8B3A0000 \SystemRoot\system32\DRIVERS\raspptp.sys 0x8B3B4000 \SystemRoot\system32\DRIVERS\rassstp.sys 0x8B3C9000 \SystemRoot\system32\DRIVERS\termdd.sys 0x8B3D9000 \SystemRoot\system32\DRIVERS\swenum.sys 0x8A5C9000 \SystemRoot\system32\DRIVERS\ks.sys 0x8B3DB000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0x8B3E5000 \SystemRoot\system32\DRIVERS\umbus.sys 0x8B400000 \SystemRoot\system32\DRIVERS\usbhub.sys 0x8B435000 \SystemRoot\System32\Drivers\NDProxy.SYS 0x8B446000 \SystemRoot\system32\drivers\HdAudio.sys 0x8B485000 \SystemRoot\system32\drivers\portcls.sys 0x8B4B2000 \SystemRoot\system32\drivers\drmk.sys 0x8B4D7000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0x8B4E0000 \SystemRoot\System32\Drivers\Null.SYS 0x8B4E7000 \SystemRoot\System32\Drivers\Beep.SYS 0x8B4EE000 \SystemRoot\System32\drivers\vga.sys 0x8B4FA000 \SystemRoot\System32\drivers\VIDEOPRT.SYS 0x8B51B000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0x8B523000 \SystemRoot\system32\drivers\rdpencdd.sys 0x8B52B000 \SystemRoot\System32\Drivers\Msfs.SYS 0x8B536000 \SystemRoot\System32\Drivers\Npfs.SYS 0x8B544000 \SystemRoot\System32\DRIVERS\rasacd.sys 0x8B807000 \SystemRoot\System32\drivers\tcpip.sys 0x8B8F1000 \SystemRoot\System32\drivers\fwpkclnt.sys 0x8B90C000 \SystemRoot\system32\DRIVERS\tdx.sys 0x8B922000 \SystemRoot\system32\DRIVERS\smb.sys 0x8B936000 \SystemRoot\system32\drivers\afd.sys 0x8B97E000 \SystemRoot\System32\DRIVERS\netbt.sys 0x8B9B0000 \SystemRoot\system32\DRIVERS\pacer.sys 0x8B9C6000 \SystemRoot\system32\DRIVERS\netbios.sys 0x8B9D4000 \SystemRoot\system32\DRIVERS\wanarp.sys 0x8B54D000 \SystemRoot\system32\DRIVERS\rdbss.sys 0x8B9E7000 \SystemRoot\system32\drivers\nsiproxy.sys 0x8B589000 \SystemRoot\System32\Drivers\dfsc.sys 0x8B5A0000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS 0x8B9F1000 \SystemRoot\system32\DRIVERS\USBD.SYS 0x8B9F3000 \SystemRoot\System32\Drivers\crashdmp.sys 0x8B5B5000 \SystemRoot\System32\Drivers\dump_diskdump.sys 0x8B5BF000 \SystemRoot\System32\Drivers\dump_nvstor.sys 0x93400000 \SystemRoot\System32\win32k.sys 0x8B5CC000 \SystemRoot\System32\drivers\Dxapi.sys 0x8B5D6000 \SystemRoot\system32\DRIVERS\monitor.sys 0x93620000 \SystemRoot\System32\TSDDD.dll 0x93640000 \SystemRoot\System32\cdd.dll 0x8B5E5000 \SystemRoot\system32\drivers\luafv.sys 0x86FCE000 \SystemRoot\system32\DRIVERS\lltdio.sys 0x86FDE000 \SystemRoot\system32\DRIVERS\rspndr.sys 0x98A0E000 \SystemRoot\system32\drivers\HTTP.sys 0x98A7B000 \SystemRoot\System32\DRIVERS\srvnet.sys 0x98A98000 \SystemRoot\system32\DRIVERS\bowser.sys 0x98AB1000 \SystemRoot\System32\drivers\mpsdrv.sys 0x98AC6000 \SystemRoot\system32\drivers\mrxdav.sys 0x98AE7000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0x98B06000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys 0x98B3F000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys 0x98B57000 \SystemRoot\System32\DRIVERS\srv2.sys 0x98B7E000 \SystemRoot\System32\DRIVERS\srv.sys 0x98E02000 \SystemRoot\system32\drivers\spsys.sys 0x98EB2000 \SystemRoot\system32\DRIVERS\asyncmac.sys 0x98EBB000 \SystemRoot\system32\drivers\peauth.sys 0x98F99000 \SystemRoot\System32\Drivers\secdrv.SYS 0x98FA3000 \SystemRoot\System32\drivers\tcpipreg.sys 0x98FAF000 \SystemRoot\system32\DRIVERS\WUDFRd.sys 0x98FC4000 \SystemRoot\system32\DRIVERS\WUDFPf.sys 0x98FD6000 \SystemRoot\system32\DRIVERS\cdfs.sys 0x77AA0000 \Windows\System32\ntdll.dll Processes (total 70): 0 System Idle Process 4 System 372 C:\Windows\System32\smss.exe 440 csrss.exe 488 C:\Windows\System32\wininit.exe 496 csrss.exe 540 C:\Windows\System32\services.exe 568 C:\Windows\System32\lsass.exe 576 C:\Windows\System32\lsm.exe 588 C:\Windows\System32\winlogon.exe 768 C:\Windows\System32\svchost.exe 820 C:\Windows\System32\nvvsvc.exe 852 C:\Windows\System32\svchost.exe 888 C:\Windows\System32\svchost.exe 940 C:\Windows\System32\svchost.exe 1048 C:\Windows\System32\svchost.exe 1092 C:\Windows\System32\svchost.exe 1152 C:\Windows\System32\audiodg.exe 1176 C:\Windows\System32\svchost.exe 1200 C:\Windows\System32\SLsvc.exe 1236 C:\Windows\System32\svchost.exe 1348 C:\Windows\System32\nvvsvc.exe 1388 C:\Windows\System32\svchost.exe 1560 C:\Windows\System32\spoolsv.exe 1600 C:\Windows\System32\svchost.exe 1904 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 256 C:\Windows\System32\svchost.exe 396 C:\PROGRA~1\McAfee\SITEAD~1\McSACore.exe 444 C:\Windows\System32\svchost.exe 996 C:\Windows\System32\svchost.exe 1368 C:\Windows\System32\rundll32.exe 1700 C:\Windows\System32\svchost.exe 1752 C:\Program Files\Registry Helper\RegistryHelperService.exe 1072 C:\Windows\System32\taskeng.exe 1668 C:\Windows\System32\dwm.exe 2108 C:\Windows\explorer.exe 2172 C:\Windows\System32\svchost.exe 2216 C:\Windows\System32\svchost.exe 2240 C:\Program Files\Windows Defender\MSASCui.exe 2248 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe 2256 C:\Program Files\SGPSA\ie3sh.exe 2264 C:\Program Files\Common Files\Real\Update_OB\realsched.exe 2280 C:\Windows\WindowsMobile\wmdSync.exe 2304 C:\Program Files\iTunes\iTunesHelper.exe 2320 C:\Program Files\Common Files\Java\Java Update\jusched.exe 2332 C:\Program Files\Windows Sidebar\sidebar.exe 2348 C:\Program Files\Windows Live\Messenger\msnmsgr.exe 2396 C:\Program Files\Windows Media Player\wmpnscfg.exe 2412 C:\Windows\System32\SearchIndexer.exe 2424 C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe 2444 C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe 2552 C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe 2624 C:\PROGRA~1\Bandoo\Bandoo.exe 2632 WUDFHost.exe 2716 C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE 3448 C:\Windows\System32\taskeng.exe 2832 C:\Windows\System32\svchost.exe 3700 C:\Program Files\Windows Media Player\wmpnetwk.exe 3332 C:\Program Files\iPod\bin\iPodService.exe 1520 C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe 3328 C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe 1808 C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe 708 C:\Windows\servicing\TrustedInstaller.exe 2232 C:\Windows\System32\wuauclt.exe 2896 C:\Program Files\Mozilla Firefox\firefox.exe 408 C:\Program Files\Mozilla Firefox\plugin-container.exe 1920 C:\Windows\System32\conime.exe 3932 C:\Windows\System32\SearchProtocolHost.exe 2468 C:\Windows\System32\SearchFilterHost.exe 2456 C:\Users\jassi\Downloads\MBRCheck.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000004`a0600000 (NTFS) \\.\D: –> \\.\PhysicalDrive0 at offset 0x00000014`f1e00000 (NTFS) PhysicalDrive0 Model Number: HitachiHDP725016GLA, Rev: GMBO Size Device Name MBR Status ——————————————– 149 GB \\.\PhysicalDrive0 Windows 2008 MBR code detected SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A7979 Done! Once again Thanks alot .It'll be grateful to seek more help from you!(just like the one at the top)HELP :smack:
Hi Trender, Yes please do the OTL scan and post the logs. GMER seems to be ok, it was just reporting it didn't find anything. Thanks.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI