This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack, redirects and registry edits

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I appreciate any help you can provide…

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:37:15 AM, on 8/27/2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\msconfig.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Robert\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…94ww85a4942y245
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…94ww85a4942y245
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACG…94ww85a4942y245
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [Acer ePower Management] C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-1055561323-912349929-2034843510-501\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Guest')
O4 - HKUS\S-1-5-21-1055561323-912349929-2034843510-501\..\RunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\FlashUtil10g_ActiveX.exe -update activex (User 'Guest')
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files\Launch Manager\dsiwmis.exe
O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\Gateway Games\Gateway Game Console\GameConsoleService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
O23 - Service: Updater Service - Acer - C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe

–
End of file - 8613 bytes
Hi

Please do the following:



Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.



NEXT



Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.



NEXT


Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Thanks for your help. Here is the report you requested. MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows 7 Starter Edition Windows Information: (build 7600), 32-bit Base Board Manufacturer: Acer BIOS Manufacturer: Acer System Manufacturer: Gateway System Product Name: LT21 Logical Drives Mask: 0x00000014 Kernel Drivers (total 196): 0x81C3A000 \SystemRoot\system32\ntoskrnl.exe 0x81C03000 \SystemRoot\system32\halmacpi.dll 0x81944000 \SystemRoot\system32\kdcom.dll 0x86C18000 \SystemRoot\system32\mcupdate_GenuineIntel.dll 0x86C90000 \SystemRoot\system32\PSHED.dll 0x86CA1000 \SystemRoot\system32\BOOTVID.dll 0x86CA9000 \SystemRoot\system32\CLFS.SYS 0x86CEB000 \SystemRoot\system32\CI.dll 0x86D96000 \SystemRoot\system32\drivers\Wdf01000.sys 0x86E07000 \SystemRoot\system32\drivers\WDFLDR.SYS 0x86E15000 \SystemRoot\system32\DRIVERS\ACPI.sys 0x86E5D000 \SystemRoot\system32\DRIVERS\WMILIB.SYS 0x86E66000 \SystemRoot\system32\DRIVERS\msisadrv.sys 0x86E6E000 \SystemRoot\system32\DRIVERS\pci.sys 0x86E98000 \SystemRoot\system32\DRIVERS\vdrvroot.sys 0x86EA3000 \SystemRoot\System32\drivers\partmgr.sys 0x86EB4000 \SystemRoot\system32\DRIVERS\compbatt.sys 0x86EBC000 \SystemRoot\system32\DRIVERS\BATTC.SYS 0x86EC7000 \SystemRoot\system32\DRIVERS\volmgr.sys 0x86ED7000 \SystemRoot\System32\drivers\volmgrx.sys 0x86F22000 \SystemRoot\System32\drivers\mountmgr.sys 0x8701A000 \SystemRoot\system32\DRIVERS\iaStor.sys 0x870F4000 \SystemRoot\system32\DRIVERS\atapi.sys 0x870FD000 \SystemRoot\system32\DRIVERS\ataport.SYS 0x87120000 \SystemRoot\system32\DRIVERS\amdxata.sys 0x87129000 \SystemRoot\system32\drivers\fltmgr.sys 0x8715D000 \SystemRoot\system32\drivers\fileinfo.sys 0x8716E000 \SystemRoot\System32\Drivers\Ntfs.sys 0x8729D000 \SystemRoot\System32\Drivers\msrpc.sys 0x872C8000 \SystemRoot\System32\Drivers\ksecdd.sys 0x872DB000 \SystemRoot\System32\Drivers\cng.sys 0x87338000 \SystemRoot\System32\drivers\pcw.sys 0x87346000 \SystemRoot\System32\Drivers\Fs_Rec.sys 0x86F38000 \SystemRoot\system32\drivers\ndis.sys 0x8734F000 \SystemRoot\system32\drivers\NETIO.SYS 0x8738D000 \SystemRoot\System32\Drivers\ksecpkg.sys 0x87410000 \SystemRoot\System32\drivers\tcpip.sys 0x87559000 \SystemRoot\System32\drivers\fwpkclnt.sys 0x8758A000 \SystemRoot\system32\DRIVERS\wd.sys 0x87592000 \SystemRoot\system32\DRIVERS\volsnap.sys 0x875D1000 \SystemRoot\System32\Drivers\spldr.sys 0x875D9000 \SystemRoot\System32\drivers\rdyboost.sys 0x87606000 \SystemRoot\System32\Drivers\mup.sys 0x87616000 \SystemRoot\System32\drivers\hwpolicy.sys 0x8761E000 \SystemRoot\System32\DRIVERS\fvevol.sys 0x87650000 \SystemRoot\system32\DRIVERS\disk.sys 0x87661000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS 0x8779D000 \SystemRoot\System32\Drivers\SRTSP.SYS 0x8BC25000 \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20100826.023\NAVEX15.SYS 0x8BD71000 \??\C:\Windows\system32\Drivers\SYMEVENT.SYS 0x8BD96000 \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20100826.023\NAVENG.SYS 0x8BDAA000 \SystemRoot\System32\Drivers\SRTSPX.SYS 0x8BDB4000 \SystemRoot\System32\Drivers\Null.SYS 0x8BDBB000 \SystemRoot\System32\Drivers\Beep.SYS 0x8BDC2000 \SystemRoot\System32\drivers\vga.sys 0x8BDCE000 \SystemRoot\System32\drivers\VIDEOPRT.SYS 0x8BDEF000 \SystemRoot\System32\drivers\watchdog.sys 0x8BDFC000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0x8BE04000 \SystemRoot\system32\drivers\rdpencdd.sys 0x8BE0C000 \SystemRoot\system32\drivers\rdprefmp.sys 0x8BE14000 \SystemRoot\System32\Drivers\Msfs.SYS 0x8BE1F000 \SystemRoot\System32\Drivers\Npfs.SYS 0x8BE2D000 \SystemRoot\system32\DRIVERS\tdx.sys 0x8BE44000 \SystemRoot\system32\DRIVERS\TDI.SYS 0x8BE4F000 \??\C:\Windows\system32\drivers\wpsdrvnt.sys 0x8BE5D000 \SystemRoot\System32\Drivers\SYMTDI.SYS 0x8BE8A000 \SystemRoot\System32\DRIVERS\netbt.sys 0x8BEBC000 \SystemRoot\system32\drivers\afd.sys 0x8BF16000 \SystemRoot\system32\DRIVERS\wfplwf.sys 0x8BF1D000 \SystemRoot\system32\DRIVERS\pacer.sys 0x8BF3C000 \SystemRoot\system32\DRIVERS\vwififlt.sys 0x8BF4D000 \SystemRoot\system32\DRIVERS\netbios.sys 0x8BF5B000 \SystemRoot\system32\DRIVERS\wanarp.sys 0x8BF6E000 \SystemRoot\system32\DRIVERS\termdd.sys 0x8BF7E000 \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys 0x873B2000 \SystemRoot\system32\DRIVERS\rdbss.sys 0x8BFE8000 \SystemRoot\system32\drivers\nsiproxy.sys 0x8BFF2000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0x90014000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 0x90072000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 0x9008F000 \SystemRoot\System32\drivers\discache.sys 0x9009B000 \SystemRoot\System32\Drivers\dfsc.sys 0x900B3000 \SystemRoot\system32\DRIVERS\blbdrive.sys 0x900C1000 \SystemRoot\system32\DRIVERS\tunnel.sys 0x900E2000 \SystemRoot\system32\DRIVERS\intelppm.sys 0x90437000 \SystemRoot\system32\DRIVERS\igdkmd32.sys 0x90940000 \SystemRoot\System32\drivers\dxgkrnl.sys 0x909F7000 \SystemRoot\System32\drivers\dxgmms1.sys 0x90A30000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0x90A4F000 \SystemRoot\system32\DRIVERS\L1C62x86.sys 0x90A60000 \SystemRoot\system32\DRIVERS\athr.sys 0x90B8D000 \SystemRoot\system32\DRIVERS\vwifibus.sys 0x90B97000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0x90BA2000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0x90BED000 \SystemRoot\system32\DRIVERS\usbehci.sys 0x90BFC000 \SystemRoot\system32\DRIVERS\CmBatt.sys 0x90400000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0x90418000 \SystemRoot\system32\DRIVERS\DKbFltr.sys 0x90422000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0x900F4000 \SystemRoot\system32\DRIVERS\Apfiltr.sys 0x9012C000 \SystemRoot\system32\DRIVERS\mouclass.sys 0x90139000 \SystemRoot\system32\DRIVERS\wmiacpi.sys 0x90142000 \SystemRoot\system32\DRIVERS\CompositeBus.sys 0x9014F000 \SystemRoot\system32\DRIVERS\AgileVpn.sys 0x90161000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0x90179000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0x90184000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0x901A6000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0x901BE000 \SystemRoot\system32\DRIVERS\raspptp.sys 0x901D5000 \SystemRoot\system32\DRIVERS\rassstp.sys 0x901EC000 \SystemRoot\system32\DRIVERS\mcdbus.sys 0x90209000 \SystemRoot\system32\DRIVERS\SCSIPORT.SYS 0x9022F000 \SystemRoot\system32\DRIVERS\teefer2.sys 0x9042F000 \SystemRoot\system32\DRIVERS\swenum.sys 0x9024D000 \SystemRoot\system32\DRIVERS\ks.sys 0x90281000 \SystemRoot\system32\DRIVERS\umbus.sys 0x9028F000 \SystemRoot\system32\DRIVERS\usbhub.sys 0x902D3000 \SystemRoot\System32\Drivers\NDProxy.SYS 0x902E4000 \SystemRoot\system32\DRIVERS\cdrom.sys 0x81439000 \SystemRoot\system32\drivers\RTKVHDA.sys 0x816D7000 \SystemRoot\system32\drivers\portcls.sys 0x81706000 \SystemRoot\system32\drivers\drmk.sys 0x930D0000 \SystemRoot\System32\win32k.sys 0x8171F000 \SystemRoot\System32\drivers\Dxapi.sys 0x81729000 \SystemRoot\System32\Drivers\crashdmp.sys 0x90303000 \SystemRoot\System32\Drivers\dump_iaStor.sys 0x81736000 \SystemRoot\System32\Drivers\dump_dumpfve.sys 0x81747000 \SystemRoot\system32\DRIVERS\usbccgp.sys 0x8175E000 \SystemRoot\system32\DRIVERS\USBD.SYS 0x81760000 \SystemRoot\System32\Drivers\usbvideo.sys 0x81784000 \SystemRoot\system32\DRIVERS\monitor.sys 0x93330000 \SystemRoot\System32\TSDDD.dll 0x93360000 \SystemRoot\System32\cdd.dll 0x93380000 \SystemRoot\System32\ATMFD.DLL 0x8178F000 \SystemRoot\system32\drivers\luafv.sys 0x817AA000 \SystemRoot\system32\drivers\WudfPf.sys 0x817C4000 \SystemRoot\system32\DRIVERS\lltdio.sys 0x87686000 \SystemRoot\system32\DRIVERS\nwifi.sys 0x817D4000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0x817E4000 \SystemRoot\system32\DRIVERS\rspndr.sys 0x817F7000 \SystemRoot\system32\DRIVERS\vwifimp.sys 0x876CC000 \SystemRoot\system32\drivers\HTTP.sys 0x81400000 \SystemRoot\system32\DRIVERS\bowser.sys 0x81419000 \SystemRoot\System32\drivers\mpsdrv.sys 0x903DD000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0x87751000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys 0x8BC00000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys 0xABC25000 \SystemRoot\system32\drivers\peauth.sys 0xABCBC000 \SystemRoot\System32\Drivers\secdrv.SYS 0xABCC6000 \SystemRoot\System32\DRIVERS\srvnet.sys 0xABCE7000 \SystemRoot\System32\drivers\tcpipreg.sys 0xABCF4000 \SystemRoot\System32\DRIVERS\srv2.sys 0xABD43000 \SystemRoot\System32\DRIVERS\srv.sys 0xABD94000 \??\C:\Windows\system32\drivers\WpsHelper.sys 0xABDBB000 \SystemRoot\System32\Drivers\SYMREDRV.SYS 0xABDC0000 \SystemRoot\system32\DRIVERS\WSDPrint.sys 0xABDCA000 \SystemRoot\system32\drivers\spsys.sys 0x76FF0000 \Windows\System32\ntdll.dll 0x47D50000 \Windows\System32\smss.exe 0x77230000 \Windows\System32\apisetschema.dll 0x00420000 \Windows\System32\autochk.exe 0x77150000 \Windows\System32\msctf.dll 0x76EF0000 \Windows\System32\wininet.dll 0x76E10000 \Windows\System32\kernel32.dll 0x77130000 \Windows\System32\sechost.dll 0x76E00000 \Windows\System32\normaliz.dll 0x76D60000 \Windows\System32\usp10.dll 0x76CB0000 \Windows\System32\msvcrt.dll 0x76CA0000 \Windows\System32\nsi.dll 0x76B60000 \Windows\System32\urlmon.dll 0x76AE0000 \Windows\System32\comdlg32.dll 0x76AC0000 \Windows\System32\imm32.dll 0x76A70000 \Windows\System32\gdi32.dll 0x769D0000 \Windows\System32\advapi32.dll 0x769A0000 \Windows\System32\imagehlp.dll 0x76990000 \Windows\System32\lpk.dll 0x768C0000 \Windows\System32\user32.dll 0x75C70000 \Windows\System32\shell32.dll 0x75C60000 \Windows\System32\psapi.dll 0x75C10000 \Windows\System32\Wldap32.dll 0x75BB0000 \Windows\System32\shlwapi.dll 0x75A10000 \Windows\System32\setupapi.dll 0x75980000 \Windows\System32\oleaut32.dll 0x75780000 \Windows\System32\iertutil.dll 0x75740000 \Windows\System32\ws2_32.dll 0x75690000 \Windows\System32\rpcrt4.dll 0x75600000 \Windows\System32\clbcatq.dll 0x754A0000 \Windows\System32\ole32.dll 0x75440000 \Windows\System32\difxapi.dll 0x75410000 \Windows\System32\wintrust.dll 0x75380000 \Windows\System32\comctl32.dll 0x75350000 \Windows\System32\cfgmgr32.dll 0x75230000 \Windows\System32\crypt32.dll 0x751E0000 \Windows\System32\KernelBase.dll 0x751C0000 \Windows\System32\devobj.dll 0x751B0000 \Windows\System32\msasn1.dll Processes (total 64): 0 System Idle Process 4 System 296 C:\Windows\System32\smss.exe 452 csrss.exe 508 csrss.exe 516 C:\Windows\System32\wininit.exe 548 C:\Windows\System32\winlogon.exe 612 C:\Windows\System32\services.exe 620 C:\Windows\System32\lsass.exe 628 C:\Windows\System32\lsm.exe 724 C:\Windows\System32\svchost.exe 800 C:\Windows\System32\svchost.exe 884 C:\Windows\System32\svchost.exe 936 C:\Windows\System32\svchost.exe 964 C:\Windows\System32\svchost.exe 1128 C:\Windows\System32\svchost.exe 1264 C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe 1332 C:\Windows\System32\svchost.exe 1404 C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe 1592 C:\Windows\System32\spoolsv.exe 1636 C:\Windows\System32\svchost.exe 1804 C:\Program Files\Launch Manager\dsiwmis.exe 1836 C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe 1864 C:\Windows\System32\svchost.exe 1912 C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe 1996 C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe 388 C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe 2124 C:\Windows\System32\svchost.exe 2580 C:\Windows\System32\taskhost.exe 2636 C:\Windows\System32\dwm.exe 2660 C:\Windows\explorer.exe 2708 C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe 2808 C:\Windows\System32\igfxtray.exe 2816 C:\Windows\System32\hkcmd.exe 2824 C:\Windows\System32\igfxpers.exe 2836 C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe 2844 C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe 2852 C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe 2948 C:\Windows\System32\igfxsrvc.exe 3204 C:\Windows\System32\igfxext.exe 3432 C:\Program Files\Launch Manager\LManager.exe 3448 C:\Program Files\Apoint2K\Apoint.exe 3456 C:\Program Files\Common Files\Symantec Shared\ccApp.exe 3584 C:\Windows\System32\SearchIndexer.exe 3644 C:\Windows\System32\wbem\unsecapp.exe 3780 C:\Program Files\Apoint2K\ApMsgFwd.exe 3840 WmiPrvSE.exe 3864 C:\Program Files\Apoint2K\ApntEx.exe 3928 C:\Windows\System32\conhost.exe 4020 C:\Program Files\Gateway\Gateway Power Management\ePowerEvent.exe 4056 C:\Program Files\Windows Media Player\wmpnetwk.exe 1052 C:\Windows\System32\SearchProtocolHost.exe 3404 C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe 3172 C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe 3192 C:\Windows\System32\sppsvc.exe 2792 C:\Windows\servicing\TrustedInstaller.exe 2060 taskhost.exe 1928 C:\Windows\System32\taskeng.exe 3256 C:\Windows\System32\SearchFilterHost.exe 3988 C:\Windows\System32\audiodg.exe 1036 dllhost.exe 3056 dllhost.exe 3116 C:\Users\Robert\Downloads\MBRCheck.exe 3200 C:\Windows\System32\conhost.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000003`069e5800 (NTFS) PhysicalDrive0 Model Number: ST9250315AS, Rev: 0001SDM1 Size Device Name MBR Status ——————————————– 232 GB \\.\PhysicalDrive0 Windows 7 MBR code detected SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79 Done!
sorry, posted without fully reading. Redid the first w/ antivirus off as well.

MBRCheck, version 1.2.3
© 2010, AD

Command-line:
Windows Version: Windows 7 Starter Edition
Windows Information: (build 7600), 32-bit
Base Board Manufacturer: Acer
BIOS Manufacturer: Acer
System Manufacturer: Gateway
System Product Name: LT21
Logical Drives Mask: 0x00000014

Kernel Drivers (total 194):
0x81C3A000 \SystemRoot\system32\ntoskrnl.exe
0x81C03000 \SystemRoot\system32\halmacpi.dll
0x81944000 \SystemRoot\system32\kdcom.dll
0x86C18000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x86C90000 \SystemRoot\system32\PSHED.dll
0x86CA1000 \SystemRoot\system32\BOOTVID.dll
0x86CA9000 \SystemRoot\system32\CLFS.SYS
0x86CEB000 \SystemRoot\system32\CI.dll
0x86D96000 \SystemRoot\system32\drivers\Wdf01000.sys
0x86E07000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x86E15000 \SystemRoot\system32\DRIVERS\ACPI.sys
0x86E5D000 \SystemRoot\system32\DRIVERS\WMILIB.SYS
0x86E66000 \SystemRoot\system32\DRIVERS\msisadrv.sys
0x86E6E000 \SystemRoot\system32\DRIVERS\pci.sys
0x86E98000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
0x86EA3000 \SystemRoot\System32\drivers\partmgr.sys
0x86EB4000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x86EBC000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x86EC7000 \SystemRoot\system32\DRIVERS\volmgr.sys
0x86ED7000 \SystemRoot\System32\drivers\volmgrx.sys
0x86F22000 \SystemRoot\System32\drivers\mountmgr.sys
0x8701A000 \SystemRoot\system32\DRIVERS\iaStor.sys
0x870F4000 \SystemRoot\system32\DRIVERS\atapi.sys
0x870FD000 \SystemRoot\system32\DRIVERS\ataport.SYS
0x87120000 \SystemRoot\system32\DRIVERS\amdxata.sys
0x87129000 \SystemRoot\system32\drivers\fltmgr.sys
0x8715D000 \SystemRoot\system32\drivers\fileinfo.sys
0x8716E000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8729D000 \SystemRoot\System32\Drivers\msrpc.sys
0x872C8000 \SystemRoot\System32\Drivers\ksecdd.sys
0x872DB000 \SystemRoot\System32\Drivers\cng.sys
0x87338000 \SystemRoot\System32\drivers\pcw.sys
0x87346000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x86F38000 \SystemRoot\system32\drivers\ndis.sys
0x8734F000 \SystemRoot\system32\drivers\NETIO.SYS
0x8738D000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x87410000 \SystemRoot\System32\drivers\tcpip.sys
0x87559000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8758A000 \SystemRoot\system32\DRIVERS\wd.sys
0x87592000 \SystemRoot\system32\DRIVERS\volsnap.sys
0x875D1000 \SystemRoot\System32\Drivers\spldr.sys
0x875D9000 \SystemRoot\System32\drivers\rdyboost.sys
0x87606000 \SystemRoot\System32\Drivers\mup.sys
0x87616000 \SystemRoot\System32\drivers\hwpolicy.sys
0x8761E000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x87650000 \SystemRoot\system32\DRIVERS\disk.sys
0x87661000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x8779D000 \SystemRoot\System32\Drivers\SRTSP.SYS
0x8BD71000 \??\C:\Windows\system32\Drivers\SYMEVENT.SYS
0x8BDAA000 \SystemRoot\System32\Drivers\SRTSPX.SYS
0x8BDB4000 \SystemRoot\System32\Drivers\Null.SYS
0x8BDBB000 \SystemRoot\System32\Drivers\Beep.SYS
0x8BDC2000 \SystemRoot\System32\drivers\vga.sys
0x8BDCE000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x8BDEF000 \SystemRoot\System32\drivers\watchdog.sys
0x8BDFC000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x8BE04000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8BE0C000 \SystemRoot\system32\drivers\rdprefmp.sys
0x8BE14000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8BE1F000 \SystemRoot\System32\Drivers\Npfs.SYS
0x8BE2D000 \SystemRoot\system32\DRIVERS\tdx.sys
0x8BE44000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8BE4F000 \??\C:\Windows\system32\drivers\wpsdrvnt.sys
0x8BE5D000 \SystemRoot\System32\Drivers\SYMTDI.SYS
0x8BE8A000 \SystemRoot\System32\DRIVERS\netbt.sys
0x8BEBC000 \SystemRoot\system32\drivers\afd.sys
0x8BF16000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x8BF1D000 \SystemRoot\system32\DRIVERS\pacer.sys
0x8BF3C000 \SystemRoot\system32\DRIVERS\vwififlt.sys
0x8BF4D000 \SystemRoot\system32\DRIVERS\netbios.sys
0x8BF5B000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x8BF6E000 \SystemRoot\system32\DRIVERS\termdd.sys
0x8BF7E000 \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
0x873B2000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x8BFE8000 \SystemRoot\system32\drivers\nsiproxy.sys
0x8BFF2000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x90014000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
0x90072000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
0x9008F000 \SystemRoot\System32\drivers\discache.sys
0x9009B000 \SystemRoot\System32\Drivers\dfsc.sys
0x900B3000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x900C1000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x900E2000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x90437000 \SystemRoot\system32\DRIVERS\igdkmd32.sys
0x90940000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x909F7000 \SystemRoot\System32\drivers\dxgmms1.sys
0x90A30000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x90A4F000 \SystemRoot\system32\DRIVERS\L1C62x86.sys
0x90A60000 \SystemRoot\system32\DRIVERS\athr.sys
0x90B8D000 \SystemRoot\system32\DRIVERS\vwifibus.sys
0x90B97000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x90BA2000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x90BED000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x90BFC000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x90400000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x90418000 \SystemRoot\system32\DRIVERS\DKbFltr.sys
0x90422000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x900F4000 \SystemRoot\system32\DRIVERS\Apfiltr.sys
0x9012C000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x90139000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x90142000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x9014F000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x90161000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x90179000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x90184000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x901A6000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x901BE000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x901D5000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x901EC000 \SystemRoot\system32\DRIVERS\mcdbus.sys
0x90209000 \SystemRoot\system32\DRIVERS\SCSIPORT.SYS
0x9022F000 \SystemRoot\system32\DRIVERS\teefer2.sys
0x9042F000 \SystemRoot\system32\DRIVERS\swenum.sys
0x9024D000 \SystemRoot\system32\DRIVERS\ks.sys
0x90281000 \SystemRoot\system32\DRIVERS\umbus.sys
0x9028F000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x902D3000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x902E4000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x81439000 \SystemRoot\system32\drivers\RTKVHDA.sys
0x816D7000 \SystemRoot\system32\drivers\portcls.sys
0x81706000 \SystemRoot\system32\drivers\drmk.sys
0x930D0000 \SystemRoot\System32\win32k.sys
0x8171F000 \SystemRoot\System32\drivers\Dxapi.sys
0x81729000 \SystemRoot\System32\Drivers\crashdmp.sys
0x90303000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0x81736000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x81747000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x8175E000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x81760000 \SystemRoot\System32\Drivers\usbvideo.sys
0x81784000 \SystemRoot\system32\DRIVERS\monitor.sys
0x93330000 \SystemRoot\System32\TSDDD.dll
0x93360000 \SystemRoot\System32\cdd.dll
0x93380000 \SystemRoot\System32\ATMFD.DLL
0x8178F000 \SystemRoot\system32\drivers\luafv.sys
0x817AA000 \SystemRoot\system32\drivers\WudfPf.sys
0x817C4000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x87686000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x817D4000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x817E4000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x817F7000 \SystemRoot\system32\DRIVERS\vwifimp.sys
0x876CC000 \SystemRoot\system32\drivers\HTTP.sys
0x81400000 \SystemRoot\system32\DRIVERS\bowser.sys
0x81419000 \SystemRoot\System32\drivers\mpsdrv.sys
0x903DD000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x87751000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x8BC00000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0xABC25000 \SystemRoot\system32\drivers\peauth.sys
0xABCBC000 \SystemRoot\System32\Drivers\secdrv.SYS
0xABCC6000 \SystemRoot\System32\DRIVERS\srvnet.sys
0xABCE7000 \SystemRoot\System32\drivers\tcpipreg.sys
0xABCF4000 \SystemRoot\System32\DRIVERS\srv2.sys
0xABD43000 \SystemRoot\System32\DRIVERS\srv.sys
0xABDBB000 \SystemRoot\System32\Drivers\SYMREDRV.SYS
0xABDC0000 \SystemRoot\system32\DRIVERS\WSDPrint.sys
0xABE5B000 \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20100827.051\NAVEX15.SYS
0xABFA7000 \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20100827.051\NAVENG.SYS
0x76FF0000 \Windows\System32\ntdll.dll
0x47D50000 \Windows\System32\smss.exe
0x77230000 \Windows\System32\apisetschema.dll
0x00420000 \Windows\System32\autochk.exe
0x77150000 \Windows\System32\msctf.dll
0x76EF0000 \Windows\System32\wininet.dll
0x76E10000 \Windows\System32\kernel32.dll
0x77130000 \Windows\System32\sechost.dll
0x76E00000 \Windows\System32\normaliz.dll
0x76D60000 \Windows\System32\usp10.dll
0x76CB0000 \Windows\System32\msvcrt.dll
0x76CA0000 \Windows\System32\nsi.dll
0x76B60000 \Windows\System32\urlmon.dll
0x76AE0000 \Windows\System32\comdlg32.dll
0x76AC0000 \Windows\System32\imm32.dll
0x76A70000 \Windows\System32\gdi32.dll
0x769D0000 \Windows\System32\advapi32.dll
0x769A0000 \Windows\System32\imagehlp.dll
0x76990000 \Windows\System32\lpk.dll
0x768C0000 \Windows\System32\user32.dll
0x75C70000 \Windows\System32\shell32.dll
0x75C60000 \Windows\System32\psapi.dll
0x75C10000 \Windows\System32\Wldap32.dll
0x75BB0000 \Windows\System32\shlwapi.dll
0x75A10000 \Windows\System32\setupapi.dll
0x75980000 \Windows\System32\oleaut32.dll
0x75780000 \Windows\System32\iertutil.dll
0x75740000 \Windows\System32\ws2_32.dll
0x75690000 \Windows\System32\rpcrt4.dll
0x75600000 \Windows\System32\clbcatq.dll
0x754A0000 \Windows\System32\ole32.dll
0x75440000 \Windows\System32\difxapi.dll
0x75410000 \Windows\System32\wintrust.dll
0x75380000 \Windows\System32\comctl32.dll
0x75350000 \Windows\System32\cfgmgr32.dll
0x75230000 \Windows\System32\crypt32.dll
0x751E0000 \Windows\System32\KernelBase.dll
0x751C0000 \Windows\System32\devobj.dll
0x751B0000 \Windows\System32\msasn1.dll

Processes (total 59):
0 System Idle Process
4 System
296 C:\Windows\System32\smss.exe
452 csrss.exe
508 csrss.exe
516 C:\Windows\System32\wininit.exe
548 C:\Windows\System32\winlogon.exe
612 C:\Windows\System32\services.exe
620 C:\Windows\System32\lsass.exe
628 C:\Windows\System32\lsm.exe
724 C:\Windows\System32\svchost.exe
800 C:\Windows\System32\svchost.exe
884 C:\Windows\System32\svchost.exe
936 C:\Windows\System32\svchost.exe
964 C:\Windows\System32\svchost.exe
1128 C:\Windows\System32\svchost.exe
1264 C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
1332 C:\Windows\System32\svchost.exe
1404 C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
1592 C:\Windows\System32\spoolsv.exe
1636 C:\Windows\System32\svchost.exe
1804 C:\Program Files\Launch Manager\dsiwmis.exe
1836 C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe
1864 C:\Windows\System32\svchost.exe
1912 C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
1996 C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe
388 C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
2124 C:\Windows\System32\svchost.exe
2580 C:\Windows\System32\taskhost.exe
2636 C:\Windows\System32\dwm.exe
2660 C:\Windows\explorer.exe
2708 C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
2808 C:\Windows\System32\igfxtray.exe
2816 C:\Windows\System32\hkcmd.exe
2824 C:\Windows\System32\igfxpers.exe
2836 C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
2844 C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
2852 C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe
2948 C:\Windows\System32\igfxsrvc.exe
3204 C:\Windows\System32\igfxext.exe
3432 C:\Program Files\Launch Manager\LManager.exe
3448 C:\Program Files\Apoint2K\Apoint.exe
3456 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
3584 C:\Windows\System32\SearchIndexer.exe
3644 C:\Windows\System32\wbem\unsecapp.exe
3780 C:\Program Files\Apoint2K\ApMsgFwd.exe
3840 WmiPrvSE.exe
3864 C:\Program Files\Apoint2K\ApntEx.exe
3928 C:\Windows\System32\conhost.exe
4020 C:\Program Files\Gateway\Gateway Power Management\ePowerEvent.exe
4056 C:\Program Files\Windows Media Player\wmpnetwk.exe
3404 C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe
3172 C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe
2792 C:\Windows\servicing\TrustedInstaller.exe
2052 C:\Windows\System32\audiodg.exe
3196 dllhost.exe
3200 dllhost.exe
1204 C:\Users\Robert\Desktop\MBRCheck.exe
3244 C:\Windows\System32\conhost.exe

\\.\C: –> \\.\PhysicalDrive0 at offset 0x00000003`069e5800 (NTFS)

PhysicalDrive0 Model Number: ST9250315AS, Rev: 0001SDM1

Size Device Name MBR Status
——————————————–
232 GB \\.\PhysicalDrive0 Windows 7 MBR code detected
SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79


Done!



DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 13:59:55.99 on Sat 08/28/2010
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Starter 6.1.7600.0.1252.1.1033.18.1013.205 [GMT -4:00]


============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Launch Manager\dsiwmis.exe
C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe
C:\Windows\Explorer.EXE
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\igfxext.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Gateway\Gateway Power Management\ePowerEvent.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Robert\Desktop\srgp6je9.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Robert\Desktop\dds.com
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uDefault_Page_URL = hxxp://homepage.gateway.com/rdr.aspx?b=ACGW&l=0409&m=lt21&r=27b506102735l0394ww85a4942y245
mDefault_Page_URL = hxxp://homepage.gateway.com/rdr.aspx?b=ACGW&l=0409&m=lt21&r=27b506102735l0394ww85a4942y245
mStart Page = hxxp://homepage.gateway.com/rdr.aspx?b=ACGW&l=0409&m=lt21&r=27b506102735l0394ww85a4942y245
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [Acer ePower Management] c:\program files\gateway\gateway power management\ePowerTray.exe
mRun: [LManager] c:\program files\launch manager\LManager.exe
mRun: [Apoint] c:\program files\apoint2k\Apoint.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: []
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: EnableLinkedConnections = 1 (0x1)
IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll

============= SERVICES / DRIVERS ===============

R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-7-8 102448]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\drivers\L1C62x86.sys [2009-11-11 54784]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 EUCR;EUCR;c:\windows\system32\drivers\EUCR6SK.sys [2009-11-11 102784]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-13 14336]

=============== Created Last 30 ================

2010-08-28 14:55:50 255504148 —-a-w- c:\windows\MEMORY.DMP
2010-08-27 07:54:36 0 d—–w- c:\program files\Trend Micro
2010-08-25 02:27:04 571904 —-a-w- c:\windows\system32\oleaut32.dll
2010-08-11 00:00:12 1286016 —-a-w- c:\windows\system32\drivers\tcpip.sys
2010-08-08 07:00:53 0 d—–w- c:\program files\MSXML 4.0
2010-08-07 17:18:49 0 d—–w- c:\programdata\Nero
2010-08-07 17:17:45 0 d—–w- c:\program files\Nero
2010-08-07 17:14:02 1974616 —-a-w- c:\windows\system32\D3DCompiler_42.dll
2010-08-07 17:13:31 1892184 —-a-w- c:\windows\system32\D3DX9_42.dll
2010-08-07 17:13:02 4379984 —-a-w- c:\windows\system32\D3DX9_40.dll
2010-08-07 17:12:31 3727720 —-a-w- c:\windows\system32\d3dx9_35.dll
2010-08-07 17:12:00 3497832 —-a-w- c:\windows\system32\d3dx9_34.dll
2010-07-30 05:22:46 0 d—–w- c:\users\robert\appdata\roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2010-07-30 04:53:24 45392 —-a-r- c:\windows\system32\AdobePDF.dll
2010-07-30 04:53:24 22872 —-a-r- c:\windows\system32\AdobePDFUI.dll

==================== Find3M ====================

2010-07-29 06:30:49 197632 —-a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30:34 82944 —-a-w- c:\windows\system32\iccvid.dll
2010-07-09 00:26:35 806 —-a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-07-09 00:26:35 7456 —-a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-07-09 00:26:35 124976 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-06-30 06:25:31 978432 —-a-w- c:\windows\system32\wininet.dll
2010-06-19 06:33:29 3955080 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-06-19 06:33:29 3899784 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-06-19 06:23:50 37376 —-a-w- c:\windows\system32\rtutils.dll
2010-06-19 04:07:18 2326016 —-a-w- c:\windows\system32\win32k.sys
2010-06-16 05:48:35 224256 —-a-w- c:\windows\system32\schannel.dll
2010-06-15 02:46:24 56 —ha-w- c:\programdata\ezsidmv.dat
2010-06-08 06:02:06 1233920 —-a-w- c:\windows\system32\msxml3.dll
2009-07-14 04:56:42 31548 —-a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 04:56:42 31548 —-a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 04:56:42 291294 —-a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 04:56:42 291294 —-a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:41:57 174 –sha-w- c:\program files\desktop.ini
2009-07-14 00:34:40 291294 —-a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 00:34:40 291294 —-a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 00:34:38 31548 —-a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 00:34:38 31548 —-a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 21:26:35 9633792 –sha-r- c:\windows\fonts\StaticCache.dat
2009-07-14 01:14:45 396800 –sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

============= FINISH: 14:00:59.70 ===============


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-28 13:59:25
Windows 6.1.7600
Running: srgp6je9.exe; Driver: C:\Users\Robert\AppData\Local\Temp\pwryapog.sys


—- System - GMER 1.0.15 —-

SSDT 85221A10 ZwAlertResumeThread
SSDT 852285E8 ZwAlertThread
SSDT 8521F008 ZwAllocateVirtualMemory
SSDT 85107F08 ZwConnectPort
SSDT 852217C0 ZwCreateMutant
SSDT 85221FB0 ZwCreateThread
SSDT 85213470 ZwFreeVirtualMemory
SSDT 85221890 ZwImpersonateAnonymousToken
SSDT 85221950 ZwImpersonateThread
SSDT 85213390 ZwMapViewOfSection
SSDT 85221700 ZwOpenEvent
SSDT 85220320 ZwOpenProcessToken
SSDT 85228B58 ZwOpenThreadToken
SSDT \??\C:\Windows\system32\drivers\wpsdrvnt.sys ZwProtectVirtualMemory [0x8B68B880]
SSDT 851FE630 ZwResumeThread
SSDT 85229C78 ZwSetContextThread
SSDT 85229D38 ZwSetInformationProcess
SSDT 85228A00 ZwSetInformationThread
SSDT 852293B8 ZwSuspendProcess
SSDT 852286F0 ZwSuspendThread
SSDT 852208B8 ZwTerminateProcess
SSDT 852287B0 ZwTerminateThread
SSDT 85229E08 ZwUnmapViewOfSection
SSDT 8521F078 ZwWriteVirtualMemory

INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8202AAF8
INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8202A104
INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8202A3F4
INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82012634
INT 0xD2 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82012898
INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8202A1DC
INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8202A958
INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8202A6F8
INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8202AF2C
INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8202B1A8

—- Kernel code sections - GMER 1.0.15 —-

.text ntoskrnl.exe!ZwSaveKeyEx + 13B1 81C458E9 1 Byte [06]
.text ntoskrnl.exe!KiDispatchInterrupt + 5A2 81C653D2 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, …] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntoskrnl.exe!KeRemoveQueueEx + 139B 81C6C668 8 Bytes [10, 1A, 22, 85, E8, 85, 22, …] {ADC [EDX], BL; AND AL, [EBP-0x7add7a18]}
.text ntoskrnl.exe!KeRemoveQueueEx + 13B3 81C6C680 4 Bytes [08, F0, 21, 85]
.text ntoskrnl.exe!KeRemoveQueueEx + 1453 81C6C720 4 Bytes JMP 107F0881
.text ntoskrnl.exe!KeRemoveQueueEx + 148F 81C6C75C 4 Bytes [C0, 17, 22, 85]
.text ntoskrnl.exe!KeRemoveQueueEx + 14C3 81C6C790 4 Bytes [B0, 1F, 22, 85]
.text …
.text peauth.sys ACC3EC9D 28 Bytes [CF, 3A, CA, 9D, 7A, F6, 49, …]
.text peauth.sys ACC3ECC1 28 Bytes [CF, 3A, CA, 9D, 7A, F6, 49, …]

—- User code sections - GMER 1.0.15 —-

.text C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe[2844] ntdll.dll!NtCreateFile + 6 77904A36 4 Bytes [28, 00, 06, 00]
.text C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe[2844] ntdll.dll!NtCreateFile + B 77904A3B 1 Byte [E2]
.text C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe[2844] ntdll.dll!NtOpenFile + 6 77905146 4 Bytes [68, 00, 06, 00]
.text C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe[2844] ntdll.dll!NtOpenFile + B 7790514B 1 Byte [E2]
.text C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe[2844] ntdll.dll!NtOpenProcess + 6 779051F6 4 Bytes [A8, 01, 06, 00]
.text C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe[2844] ntdll.dll!NtOpenProcess + B 779051FB 1 Byte [E2]
.text C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe[2844] ntdll.dll!NtOpenProcessToken + 6 77905206 4 Bytes CALL 7690580C C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe[2844] ntdll.dll!NtOpenProcessToken + B 7790520B 1 Byte [E2]
.text C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe[2844] ntdll.dll!NtOpenProcessTokenEx + 6 77905216 4 Bytes [A8, 02, 06, 00]
.text C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe[2844] ntdll.dll!NtOpenProcessTokenEx + B 7790521B 1 Byte [E2]
.text C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe[2844] ntdll.dll!NtOpenThread + 6 77905276 4 Bytes [68, 01, 06, 00]
.text C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe[2844] ntdll.dll!NtOpenThread + B 7790527B 1 Byte [E2]
.text C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe[2844] ntdll.dll!NtOpenThreadToken + 6 77905286 4 Bytes [68, 02, 06, 00]
.text C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe[2844] ntdll.dll!NtOpenThreadToken + B 7790528B 1 Byte [E2]
.text C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe[2844] ntdll.dll!NtOpenThreadTokenEx + 6 77905296 4 Bytes CALL 7690589D C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe[2844] ntdll.dll!NtOpenThreadTokenEx + B 7790529B 1 Byte [E2]
.text C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe[2844] ntdll.dll!NtQueryAttributesFile + 6 779053A6 4 Bytes [A8, 00, 06, 00]
.text C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe[2844] ntdll.dll!NtQueryAttributesFile + B 779053AB 1 Byte [E2]
.text C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe[2844] ntdll.dll!NtQueryFullAttributesFile + 6 77905456 4 Bytes CALL 76905A5B C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe[2844] ntdll.dll!NtQueryFullAttributesFile + B 7790545B 1 Byte [E2]
.text C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe[2844] ntdll.dll!NtSetInformationFile + 6 77905AA6 4 Bytes [28, 01, 06, 00]
.text C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe[2844] ntdll.dll!NtSetInformationFile + B 77905AAB 1 Byte [E2]
.text C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe[2844] ntdll.dll!NtSetInformationThread + 6 77905B06 4 Bytes [28, 02, 06, 00]
.text C:\Users\Robert\AppData\Local\Google\Chrome\Application\chrome.exe[2844] ntdll.dll!NtSetInformationThread + B 77905B0B 1 Byte [E2]

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\tdx \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\ACPI_HAL \Device\00000056 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)

AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

—- EOF - GMER 1.0.15 —-

Attachments:

Hi,

Please do the following:

Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI