This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Funmoods redirect virus [Closed]

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Jeff, I tried to get rid of the ESET entry as described (dragging to ComboFix etc) but, after doing this, I noticed that the offending item was still on the desktop….. so I thought I'd better check to see if the trojan was still there by running the ESET scan again. It was and the scan picked it up. I decided to follow your instructions for a second time but, after checking with the ESET scan once more, it still hadn't been removed. The PC hasn't rebooted whilst Combofix was running either time (in contrast to my previous CF use) and, also, the first time Combofix started up, I was asked to agree to update the Combofix files - which'd never happened before. (Sorry, I don't know if this is of any relevance). The logs of the two CF scans are attached….they seem identical to me but maybe an expert can see subtle differences! The system is running a lot better. It wasn't really running at all before…..you probably wouldnt be surprised to learn! Internet connection is ok, no more redirects etc…..but there are still a few (comparatively small) problems: -Start up sequence is inconsistent. Before the PC was infected, there was a pause in the start up (at the black screen with system info on it) and you were asked to press F1 to continue, F12 to enter Set Up etc. Once infected, this request was skipped and the system proceeded to start up Windows automatically to the 'choose your user' option. Whilst I have been following your advice, there have been a couple of times where the start up sequence has reverted to what it was previously before infection but then gone back again the next time the system has been switched off and on. Not really a huge problem on the face of it but I thought it may be indicative of a more serious issue. - The are definitely issues with the audio. When it was heavily infected there was no sound at all, no media players would run, DVDs wouldn't play etc etc. Again, as I've been getting your help, the audio has suddenly come back but would only be there if 'SigmaTel Audio' was selected…rather than SB FX audio which is what we normally use (at first SB wasn't even one of the options available but it has reappeared now). Now SB works (but only some of the time) for internet streaming but nothing, not even Sigmatel, produces sound on any of the videos on the hard drive or when DVDs are played (i.e- the media players are mute). We were having a bit of a debate here if 'Sigmatel Audio' was on the PC before it got infected and, although no-one can really remember, I'm pretty sure it wasn't. No list of media options appears when a cd or DVD is inserted - with the cd being crackly and unlistenable and the DVD having no sound anyway. Tbh, every time I reboot, something different is happening with the audio….sometimes it's there, sometimes not, sometimes it'll only work on one audio device….and so on. Apologies for the long windedness of this post and thanks again for helping me get this far. Jen.
Hi Jeff, I tried to get rid of the ESET entry as described (dragging to ComboFix etc) but, after doing this, I noticed that the offending item was still on the desktop….. so I thought I'd better check to see if the trojan was still there by running the ESET scan again. It was and the scan picked it up. I decided to follow your instructions for a second time but, after checking with the ESET scan once more, it still hadn't been removed. The PC hasn't rebooted whilst Combofix was running either time (in contrast to my previous CF use) and, also, the first time Combofix started up, I was asked to agree to update the Combofix files - which'd never happened before. (Sorry, I don't know if this is of any relevance). The logs of the two CF scans are attached….they seem identical to me but maybe an expert can see subtle differences! The system is running a lot better. It wasn't really running at all before…..you probably wouldnt be surprised to learn! Internet connection is ok, no more redirects etc…..but there are still a few (comparatively small) problems: -Start up sequence is inconsistent. Before the PC was infected, there was a pause in the start up (at the black screen with system info on it) and you were asked to press F1 to continue, F12 to enter Set Up etc. Once infected, this request was skipped and the system proceeded to start up Windows automatically to the 'choose your user' option. Whilst I have been following your advice, there have been a couple of times where the start up sequence has reverted to what it was previously before infection but then gone back again the next time the system has been switched off and on. Not really a huge problem on the face of it but I thought it may be indicative of a more serious issue. - The are definitely issues with the audio. When it was heavily infected there was no sound at all, no media players would run, DVDs wouldn't play etc etc. Again, as I've been getting your help, the audio has suddenly come back but would only be there if 'SigmaTel Audio' was selected…rather than SB FX audio which is what we normally use (at first SB wasn't even one of the options available but it has reappeared now). Now SB works (but only some of the time) for internet streaming but nothing, not even Sigmatel, produces sound on any of the videos on the hard drive or when DVDs are played (i.e- the media players are mute). We were having a bit of a debate here if 'Sigmatel Audio' was on the PC before it got infected and, although no-one can really remember, I'm pretty sure it wasn't. No list of media options appears when a cd or DVD is inserted - with the cd being crackly and unlistenable and the DVD having no sound anyway. Tbh, every time I reboot, something different is happening with the audio….sometimes it's there, sometimes not, sometimes it'll only work on one audio device….and so on. Apologies for the long windedness of this post and thanks again for helping me get this far. Jen.
Hi, Thanks for letting me know how your system is running. I noticed in your OTL log that you have posted that you have on your system both AVG and McAfee antivirus programs. Which one are you using so that we can remove the other? Having two antivirus programs can lead to conflicts on your system and actually leave you less protected.
Hi, AVG is only downloaded, it wasn't installed. McAfee wouldn't scan properly or allow updates when system had become infected so I downloaded AVG Free but I couldn't get it to complete install. I think it's been on the system in the past though. McAfee Total Protection (ha!) is OK now. How should I remove AVG??….. Should I delete the whole AVG folder from Program Files?? Also, is attempting to put the Win32/Mebroot.FX trojan in quarantine on the Eset scanner an option?? Thanks again Jen.
Hi,

Download and run the tool here to remove AVG.
———-

Let's do this so I can have a better look at that file.

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :file
    C:\Documents and Settings\Dougie\Desktop\Dump_Hdd0_DR0.mbr
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
———-

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
Here's the SystemLook log…

SystemLook 30.07.11 by jpshortstuff
Log created at 13:04 on 18/07/2012 by Dougie
Administrator - Elevation successful

========== file ==========

C:\Documents and Settings\Dougie\Desktop\Dump_Hdd0_DR0.mbr - File found and opened.
MD5: 8972A1DC581298394D1E59F752B43262
Created at 03:39 on 11/07/2012
Modified at 15:45 on 11/07/2012
Size: 512 bytes
Attributes: –a—-
No version information available.

-= EOF =-





And here's the checkup.txt log….

Results of screen317's Security Check version 0.99.43
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Disabled!
McAfee Anti-Virus and Anti-Spyware
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Java™ 6 Update 17
Java™ 6 Update 3
Java™ 6 Update 5
Java™ 6 Update 7
Java 2 Runtime Environment, SE v1.4.2_03
Java version out of Date!
Adobe Flash Player 10 Flash Player out of Date!
Adobe Flash Player 11.3.300.265
Adobe Reader 7 Adobe Reader out of Date!
Mozilla Firefox (14.0.1)
Google Chrome 20.0.1132.47
Google Chrome 20.0.1132.57
````````Process Check: objlist.exe by Laurent````````
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 6%
````````````````````End of Log``````````````````````




Didn't know Windows Firewall had been turned off! Just turned it on again. Here's a second updated Checkup log:


Results of screen317's Security Check version 0.99.43
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
McAfee Anti-Virus and Anti-Spyware
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Java™ 6 Update 17
Java™ 6 Update 3
Java™ 6 Update 5
Java™ 6 Update 7
Java 2 Runtime Environment, SE v1.4.2_03
Java version out of Date!
Adobe Flash Player 10 Flash Player out of Date!
Adobe Flash Player 11.3.300.265
Adobe Reader 7 Adobe Reader out of Date!
Mozilla Firefox (14.0.1)
Google Chrome 20.0.1132.47
Google Chrome 20.0.1132.57
````````Process Check: objlist.exe by Laurent````````
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 6%
````````````````````End of Log``````````````````````




Thanks,

Jen
Hi,

Please download JavaRa to your desktop and unzip it to its own
folder
  • Run JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista), pick the language of your choice and click Select. Then
    click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista) again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest
    Java Runtime Environment (JRE) version for your computer.
———-

You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe Reader 7 first. Be sure to move any PDF documents to another folder first though.
———-

Your version of Adobe Flash Player is out of date. You can download the current version HERE.
Ok, I've done that. Here's the new SecurityCheck log….

Thanks

Jen.

Results of screen317's Security Check version 0.99.43
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
McAfee Anti-Virus and Anti-Spyware
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
JavaFX 2.1.1
Java™ 6 Update 17
Java™ 7 Update 5
Java™ 6 Update 3
Java™ 6 Update 5
Java™ 6 Update 7
Java 2 Runtime Environment, SE v1.4.2_03
Adobe Flash Player 11.3.300.265
Adobe Reader X (10.1.3)
Mozilla Firefox (14.0.1)
Google Chrome 20.0.1132.47
Google Chrome 20.0.1132.57
````````Process Check: objlist.exe by Laurent````````
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 6%
````````````````````End of Log``````````````````````
The system is running really well but still has the start up and audio problems mentioned upthread. I'm pretty sure the Sigmatel Audio issue is to do with the infection. I've kinda worked out that I'm actually only getting sound if the 'Sigmatel Audio' is selected as the default playback device. There's just a quiet crackly noise if something else is selected…as if it's been blocked and, like I've said, I'm really not sure if Sigmatel was on the PC beforehand. As well as the trojan threat that the Eset scanner is picking up, I ran a new aswMBR scan to see what it now looks like…. It seems to still be picking up one or two issues as well. Here's the log: aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-07-18 22:34:04 —————————– 22:34:04.265 OS Version: Windows 5.1.2600 Service Pack 3 22:34:04.265 Number of processors: 2 586 0x602 22:34:04.265 ComputerName: INNIT UserName: 22:34:05.328 Initialize success 22:34:22.187 AVAST engine defs: 12071800 22:34:45.765 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 22:34:45.765 Disk 0 Vendor: Intel___ 1.0. Size: 476832MB BusType: 3 22:34:45.796 Disk 0 MBR read successfully 22:34:45.796 Disk 0 MBR scan 22:34:45.843 Disk 0 unknown MBR code 22:34:45.843 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 47 MB offset 63 22:34:45.859 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 471925 MB offset 96390 22:34:45.890 Disk 0 Partition 3 00 DB CP/M / CTOS Dell 8.0 4855 MB offset 966598920 22:34:45.890 Disk 0 scanning sectors +976543155 22:34:45.906 Disk 0 malicious Win32:MBRoot code @ sector 976543158 ! 22:34:45.984 Disk 0 scanning C:\WINDOWS\system32\drivers 22:35:12.796 Service scanning 22:35:41.234 Modules scanning 22:35:48.234 Module: C:\WINDOWS\System32\DLA\DLADResN.SYS **SUSPICIOUS** 22:35:49.531 Disk 0 trace - called modules: 22:35:49.546 22:35:50.625 AVAST engine scan C:\WINDOWS 22:36:39.390 AVAST engine scan C:\WINDOWS\system32 22:42:54.281 AVAST engine scan C:\WINDOWS\system32\drivers 22:43:35.781 AVAST engine scan C:\Documents and Settings\Dougie 23:16:56.500 AVAST engine scan C:\Documents and Settings\All Users 23:20:10.125 Scan finished successfully 23:29:41.312 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Dougie\Desktop\MBR.dat" 23:29:41.359 The log file has been saved successfully to "C:\Documents and Settings\Dougie\Desktop\aswMBRnew.txt" Thanks Jen.
Hi,

Let's do some more digging…

Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.
———-

I need some information on some unidentified files. We will use Virustotal Please submit these files for analysis

To submit a file to virustotal, please click VirusTotal

Press Choose File and then browse to the following file: (one at a time if more than one file is listed)

C:\WINDOWS\System32\DLA\DLADResN.SYS

Once you locate the file select it and press Open now press Scan it!.

Now Copy/Paste the link to the results showing in the web browser bar to your next reply so that I can take a look at the results.

Please note that sometimes the scans take a few minutes. Please ensure that the scan has completed and the results are complete before submitting the next sample. Also please make sure each result is clearly identified as to which sample they belong to.
———-
Hi, the MBRCheck log is below. Here's the VirusTotal link

Thanks

Jen.



MBRCheck, version 1.2.3
© 2010, AD

Command-line:
Windows Version: Windows XP Professional
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x000001fd

Kernel Drivers (total 157):
0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
0x806E5000 \WINDOWS\system32\hal.dll
0xBA5A8000 \WINDOWS\system32\KDCOM.DLL
0xBA4B8000 \WINDOWS\system32\BOOTVID.dll
0xB9F79000 ACPI.sys
0xBA5AA000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xB9F68000 pci.sys
0xBA0A8000 isapnp.sys
0xBA670000 pciide.sys
0xBA328000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xBA0B8000 MountMgr.sys
0xB9F49000 ftdisk.sys
0xBA5AC000 dmload.sys
0xB9F23000 dmio.sys
0xBA330000 PartMgr.sys
0xBA0C8000 VolSnap.sys
0xB9F0B000 atapi.sys
0xB9E36000 iastor.sys
0xBA0D8000 disk.sys
0xBA0E8000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xB9E16000 fltmgr.sys
0xB9E04000 sr.sys
0xB9D95000 mfehidk.sys
0xB9D7F000 DRVMCDB.SYS
0xBA338000 PxHelp20.sys
0xB9D68000 KSecDD.sys
0xB9CDB000 Ntfs.sys
0xB9CAE000 NDIS.sys
0xB9C94000 Mup.sys
0xB9C80000 McPvDrv.sys
0xB970B000 \SystemRoot\system32\DRIVERS\intelppm.sys
0xB8F9C000 \SystemRoot\system32\DRIVERS\nv4_mini.sys
0xB8F88000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xB8F60000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0xB8F35000 \SystemRoot\system32\DRIVERS\e1e5132.sys
0xBA470000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0xB8F11000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xBA478000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xB8EEC000 \SystemRoot\system32\DRIVERS\hcwPP2.sys
0xB8EC9000 \SystemRoot\system32\DRIVERS\ks.sys
0xB8E5D000 \SystemRoot\system32\drivers\ctaud2k.sys
0xB8E39000 \SystemRoot\system32\drivers\portcls.sys
0xB96EB000 \SystemRoot\system32\drivers\drmk.sys
0xB8E07000 \SystemRoot\system32\drivers\ctoss2k.sys
0xB8DDC000 \SystemRoot\system32\drivers\mfeavfk.sys
0xB8D8A000 \SystemRoot\system32\drivers\mfefirek.sys
0xBA480000 \SystemRoot\system32\drivers\ctprxy2k.sys
0xB8D2E000 \SystemRoot\system32\DRIVERS\HSFHWBS2.sys
0xB8C2F000 \SystemRoot\system32\DRIVERS\HSF_DP.sys
0xB8B88000 \SystemRoot\system32\DRIVERS\HSF_CNXT.sys
0xBA488000 \SystemRoot\System32\Drivers\Modem.SYS
0xBA490000 \SystemRoot\system32\DRIVERS\fdc.sys
0xBA238000 \SystemRoot\system32\DRIVERS\imapi.sys
0xBA608000 \SystemRoot\System32\Drivers\DLACDBHM.SYS
0xBA248000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xBA258000 \SystemRoot\system32\DRIVERS\redbook.sys
0xBA498000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys
0xBA716000 \SystemRoot\system32\DRIVERS\audstub.sys
0xB8B75000 \SystemRoot\system32\DRIVERS\mfendisk.sys
0xBA268000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xB9C3B000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xB8B5E000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xBA278000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xBA288000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xBA4A0000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xB8B4D000 \SystemRoot\system32\DRIVERS\psched.sys
0xBA298000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xBA4A8000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xBA4B0000 \SystemRoot\system32\DRIVERS\raspti.sys
0xBA348000 \SystemRoot\system32\DRIVERS\wanatw4.sys
0xB8B1D000 \SystemRoot\system32\DRIVERS\rdpdr.sys
0xBA2A8000 \SystemRoot\system32\DRIVERS\termdd.sys
0xBA358000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xBA360000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xBA60A000 \SystemRoot\system32\DRIVERS\swenum.sys
0xB8ABF000 \SystemRoot\system32\DRIVERS\update.sys
0xB9C1F000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xB9C17000 \SystemRoot\system32\drivers\MODEMCSA.sys
0xA97E3000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xA67EA000 \SystemRoot\system32\drivers\sthda.sys
0xA94BD000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xA9BD9000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xA1C9A000 \SystemRoot\system32\drivers\ha20x2k.sys
0xA1C6D000 \SystemRoot\system32\drivers\emupia2k.sys
0xA1C46000 \SystemRoot\system32\drivers\ctsfm2k.sys
0xA1BAA000 \SystemRoot\system32\drivers\ctac32k.sys
0xA93F8000 \SystemRoot\system32\DRIVERS\flpydisk.sys
0xB5E62000 \SystemRoot\System32\Drivers\i2omgmt.SYS
0xA93B6000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xB275E000 \SystemRoot\System32\Drivers\Null.SYS
0xA93B4000 \SystemRoot\System32\Drivers\Beep.SYS
0xA93E8000 \SystemRoot\System32\Drivers\DLARTL_N.SYS
0xA93E0000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0xA93D8000 \SystemRoot\System32\drivers\vga.sys
0xA93B2000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xA93B0000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xA93D0000 \SystemRoot\System32\Drivers\Msfs.SYS
0xA93C8000 \SystemRoot\System32\Drivers\Npfs.SYS
0xB5E56000 \SystemRoot\system32\DRIVERS\rasacd.sys
0xA1B77000 \SystemRoot\system32\DRIVERS\ipsec.sys
0xA1B1E000 \SystemRoot\system32\DRIVERS\tcpip.sys
0xA1B09000 \SystemRoot\system32\drivers\mfetdi2k.sys
0xA1AE3000 \SystemRoot\system32\DRIVERS\ipnat.sys
0xA1ABC000 \SystemRoot\System32\Drivers\Mpfp.sys
0xA946D000 \SystemRoot\System32\DRIVERS\ipfltdrv.sys
0xA1A94000 \SystemRoot\system32\DRIVERS\netbt.sys
0xB440E000 \SystemRoot\System32\drivers\ws2ifsl.sys
0xA1A72000 \SystemRoot\System32\drivers\afd.sys
0xA945D000 \SystemRoot\system32\DRIVERS\netbios.sys
0xA1A47000 \SystemRoot\system32\DRIVERS\rdbss.sys
0xA19D7000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xA943D000 \SystemRoot\System32\Drivers\Fips.SYS
0xA8F12000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xA93AE000 \SystemRoot\System32\DRIVERS\ELmou.sys
0xA93AC000 \SystemRoot\System32\DRIVERS\ELmon.sys
0xA93AA000 \SystemRoot\System32\DRIVERS\ELkbd.sys
0xB2C74000 \SystemRoot\System32\DRIVERS\ELhid.sys
0xA8EA2000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xB2825000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0xA8E92000 \SystemRoot\system32\DRIVERS\IrBus.sys
0xB281D000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0xA1980000 \SystemRoot\system32\DRIVERS\PRISMA02.sys
0xB9307000 \SystemRoot\system32\DRIVERS\hidusb.sys
0xA8E82000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0xB2815000 \SystemRoot\system32\DRIVERS\hidir.sys
0xBA568000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0xBA56C000 \SystemRoot\system32\DRIVERS\mouhid.sys
0xA18AB000 \SystemRoot\System32\Drivers\dump_iastor.sys
0xBF800000 \SystemRoot\System32\win32k.sys
0xB8D72000 \SystemRoot\System32\drivers\Dxapi.sys
0xB2805000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xB231F000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF012000 \SystemRoot\System32\nv4_disp.dll
0xBF3CF000 \SystemRoot\System32\ATMFD.DLL
0xBA178000 \SystemRoot\System32\Drivers\DRVNDDM.SYS
0xA99C2000 \SystemRoot\System32\DLA\DLADResN.SYS
0xA1134000 \SystemRoot\System32\DLA\DLAIFS_M.SYS
0xA99D1000 \SystemRoot\System32\DLA\DLAOPIOM.SYS
0xBA61C000 \SystemRoot\System32\DLA\DLAPoolM.SYS
0xBA370000 \SystemRoot\System32\DLA\DLABOIOM.SYS
0xA111C000 \SystemRoot\System32\DLA\DLAUDFAM.SYS
0xA1106000 \SystemRoot\System32\DLA\DLAUDF_M.SYS
0xB9C0F000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xA0861000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0xA0780000 \SystemRoot\System32\Drivers\HTTP.sys
0xA0630000 \SystemRoot\system32\drivers\wdmaud.sys
0xB5B6C000 \SystemRoot\system32\drivers\sysaudio.sys
0xA0510000 \SystemRoot\system32\DRIVERS\srv.sys
0xA03E5000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys
0xAA2F7000 \SystemRoot\system32\drivers\MSPQM.sys
0x9D997000 \SystemRoot\system32\drivers\cfwids.sys
0x9C970000 \SystemRoot\system32\drivers\mfeapfk.sys
0x9B701000 \??\C:\DOCUME~1\Dougie\LOCALS~1\Temp\aswMBR.sys
0x99C22000 \SystemRoot\system32\drivers\kmixer.sys
0x99BDF000 \SystemRoot\System32\Drivers\Fastfat.SYS
0x7C900000 \WINDOWS\system32\ntdll.dll

Processes (total 85):
0 System Idle Process
4 System
944 C:\WINDOWS\system32\smss.exe
1376 csrss.exe
1400 C:\WINDOWS\system32\winlogon.exe
1444 C:\WINDOWS\system32\services.exe
1480 C:\WINDOWS\system32\lsass.exe
1700 C:\WINDOWS\system32\svchost.exe
1768 svchost.exe
1808 C:\WINDOWS\system32\svchost.exe
1900 svchost.exe
2028 svchost.exe
548 C:\WINDOWS\system32\spoolsv.exe
624 svchost.exe
708 C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
744 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
828 C:\Program Files\Bonjour\mDNSResponder.exe
848 C:\WINDOWS\system32\CTSVCCDA.EXE
892 C:\WINDOWS\ehome\ehrecvr.exe
908 C:\WINDOWS\ehome\ehSched.exe
960 C:\WINDOWS\system32\svchost.exe
1076 C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
1112 C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
1140 C:\Program Files\Kontiki\KService.exe
1276 C:\PROGRA~1\McAfee\SITEAD~1\McSACore.exe
1584 C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
2232 C:\WINDOWS\explorer.exe
2352 C:\WINDOWS\system32\rundll32.exe
2372 C:\WINDOWS\system32\mfevtps.exe
2400 C:\WINDOWS\system32\svchost.exe
2428 C:\WINDOWS\system32\nvsvc32.exe
2448 C:\WINDOWS\system32\svchost.exe
2736 svchost.exe
2996 C:\WINDOWS\system32\svchost.exe
3072 C:\Program Files\Common Files\Mcafee\SystemCore\mcshield.exe
3520 C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe
428 mcrdsvc.exe
1976 C:\WINDOWS\ehome\ehtray.exe
2444 C:\WINDOWS\CTHELPER.EXE
2572 C:\WINDOWS\system32\CTXFIHLP.EXE
2808 C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
3232 C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.exe
3356 C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
3480 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
3492 C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
3620 C:\WINDOWS\system32\DLA\DLACTRLW.EXE
1172 C:\WINDOWS\system32\CTXFISPI.EXE
3932 C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
3992 C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
292 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
1932 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
2668 C:\Program Files\iTunes\iTunesHelper.exe
2696 C:\Program Files\real\realplayer\Update\realsched.exe
3024 C:\Program Files\McAfee.com\Agent\mcagent.exe
3044 C:\Program Files\McAfee\MAT\McPvTray.exe
3180 C:\Program Files\Common Files\Java\Java Update\jusched.exe
3416 C:\Program Files\Dell Support\DSAgnt.exe
2464 C:\Program Files\Kontiki\KHost.exe
3692 C:\WINDOWS\system32\ctfmon.exe
1256 C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe
3844 C:\Program Files\Digital Line Detect\DLG.exe
3884 C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
4076 C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
248 C:\Program Files\BBC iPlayer Desktop\BBC iPlayer Desktop.exe
3176 C:\Program Files\OpenOffice.org 3\program\soffice.exe
2276 C:\Program Files\OpenOffice.org 3\program\soffice.bin
3248 wmiprvse.exe
5280 C:\WINDOWS\system32\dllhost.exe
5696 C:\WINDOWS\system32\dlcccoms.exe
5752 C:\Program Files\iPod\bin\iPodService.exe
6088 alg.exe
4972 C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
5344 C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
5200 C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
4228 C:\WINDOWS\ehome\ehmsas.exe
2492 C:\Program Files\Microsoft\BingBar\7.1.382.0\SeaPort.EXE
5548 C:\WINDOWS\system32\svchost.exe
1192 C:\Program Files\Mozilla Firefox\firefox.exe
1888 C:\Program Files\Mozilla Firefox\plugin-container.exe
4340 C:\Program Files\Mozilla Firefox\plugin-container.exe
5508 C:\Program Files\iTunes\iTunes.exe
4192 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
1164 C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe
5040 C:\WINDOWS\system32\wscntfy.exe
4948 C:\Documents and Settings\Dougie\Desktop\MBRCheck.exe

\\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`02f10c00 (NTFS)

PhysicalDrive0 Model Number: ‡$

Size Device Name MBR Status
——————————————–
465 GB \\.\PhysicalDrive0 Dell MBR code detected
SHA1: 57BDF501CE769EF2720C705B6C71C893DA31574E


Done!
…….Again, it's probably not relevant but VirusTotal said that there had been a previous scan of that file at an earlier date (also producing 0/42) and asked if I would I like to look at the results or reanalyse.


Out of curiousity, I scanned a couple of other files…

Here's the file picked up by Eset scanner.

And here's the file scan of Sigmatel Audio

(…I had to scan a shortcut link to the file as SigmaTel Audio only seems to exist in Control Panel)


Thanks

Jen.
Thanks for getting those to me. By the way….when did you first see the file on your Desktop appear? Since we started with our tools?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI