Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: limited connectivity  (Read 22786 times)

0 Members and 1 Guest are viewing this topic.

SuperDave

  • Malware Removal Specialist
  • Moderator


  • Genius
  • Thanked: 1020
  • Certifications: List
  • Experience: Expert
  • OS: Windows 10
Re: limited connectivity
« Reply #30 on: February 13, 2012, 01:45:47 PM »
Quote
I just thought this might be why I cant find a VISTA OS disk and don't remember having one with this computer.  I usually save them and have them for all my other/past computers.
Yup, that's it. Very few people have the Vista disks.
This will restore your computer back to the day it was purchased. Can you boot into the Recovery Console? If you can, we should be able to repair the MBR.
This may work for you.


Reboot your machine and when the Boot Menu flashes up - select "Microsoft Windows Recovery Console"
(you need to be very fast with the arrow key as you only have a couple of seconds before it defaults to the windows bootup)





When you get to the above screen, take note of the number that references your operating system.

If it's '1' like the picture above, type 1 and press Enter



Next type FIXMBR

If it ask if you're sure you want to write a new MBR, answer 'Y'

Then type EXIT to reboot the machine.

With that done, please post back and let me know how things are now.
Windows 8 and Windows 10 dual boot with two SSD's

hansberry

    Topic Starter


    Rookie

    • Experience: Beginner
    • OS: Unknown
    Re: limited connectivity
    « Reply #31 on: February 13, 2012, 02:06:32 PM »
    ok, so you do NOT want me to use the emachines recovery management.  You just want me to turn my computer off and then back on.

    If I do that I dont see the recovery console option.  If I just turn it off I get safemode options.  If I tell it to shutdown I only get bios settings option and boot options but it doesnt give me the menu you showed.

    If you wanted me to do something other than just turn the computer on and off then I guess I'll need that spelled out, lol.

    SuperDave

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Re: limited connectivity
    « Reply #32 on: February 13, 2012, 04:31:02 PM »
    Just hold on a bit. I'm going to check something.
    Windows 8 and Windows 10 dual boot with two SSD's

    SuperDave

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Re: limited connectivity
    « Reply #33 on: February 13, 2012, 04:34:44 PM »
    Download BootKit Remover to your Desktop.

    •You then need to extract the remover.exe file from the RAR using a program capable of extracing RAR compressed files. If you don't have an extraction program, you can use 7-Zip

    •After extracing remover.exe to your Desktop, double-click on remover.exe to run the program (Vista/7 users,right click on remover.exe and click Run As Administrator.

    •It will show a Black screen with some data on it.

    •Right click on the screen and click Select All.

    •Press Enter

    •Open a Notepad and press CTRL V

    •Post the output back here.
    Windows 8 and Windows 10 dual boot with two SSD's

    hansberry

      Topic Starter


      Rookie

      • Experience: Beginner
      • OS: Unknown
      Re: limited connectivity
      « Reply #34 on: February 13, 2012, 05:25:51 PM »
      Bootkit Remover
      (c) 2009 Esage Lab
      www.esagelab.com

      Program version: 1.2.0.1
      OS Version: Microsoft Windows Vista Home Basic Edition Service Pack 2 (build 600
      2), 32-bit

      System volume is \\.\C:
      \\.\C: -> \\.\PhysicalDrive0 at offset 0x00000002`80100000
      ATA_Read(): DeviceIoControl() ERROR 1
      Boot sector MD5 is: c3f4814ee2c87f8f4fc3acd72454a04d

           Size  Device Name          MBR Status
       --------------------------------------------
         149 GB  \\.\PhysicalDrive0   Unknown boot code

      Unknown boot code has been found on some of your physical disks.
      To inspect the boot code manually, dump the master boot sector:
      remover.exe dump <device_name> [output_file]
      To disinfect the master boot sector, use the following command:
      remover.exe fix <device_name>


      Done;
      Press any key to quit...

      SuperDave

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Re: limited connectivity
      « Reply #35 on: February 14, 2012, 12:00:30 PM »
      Please download aswMBR.exe ( 511KB ) to your desktop.

      Double click the aswMBR.exe to run it



      Click the "Scan" button to start scan

      Note: Do not take action against any **Rootkit** entries until I have reviewed the log. Often there are false positives



      On completion of the scan click save log, save it to your desktop and post in your next reply
      *************************************************************************
      Please download and run ListParts by Farbar

      Click on Scan button.

      Scan result will open in Notepad.
      Post it in your next reply.
      Windows 8 and Windows 10 dual boot with two SSD's

      hansberry

        Topic Starter


        Rookie

        • Experience: Beginner
        • OS: Unknown
        Re: limited connectivity
        « Reply #36 on: February 14, 2012, 12:32:44 PM »
        aswMBR version 0.9.9.1532 Copyright(c) 2011 AVAST Software
        Run date: 2012-02-14 11:22:03
        -----------------------------
        11:22:03.866    OS Version: Windows 6.0.6002 Service Pack 2
        11:22:03.866    Number of processors: 1 586 0x5F03
        11:22:03.868    ComputerName: HANSBERRY-PC  UserName: Hansberry
        11:22:04.724    Initialize success
        11:22:11.097    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000061
        11:22:11.100    Disk 0 Vendor: ST316081 4.AA Size: 152627MB BusType: 6
        11:22:11.123    Disk 0 MBR read successfully
        11:22:11.125    Disk 0 MBR scan
        11:22:11.129    Disk 0 unknown MBR code
        11:22:11.135    Disk 0 Partition 1 00     27 Hidden NTFS WinRE NTFS        10240 MB offset 2048
        11:22:11.151    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS       142385 MB offset 20973568
        11:22:11.156    Disk 0 scanning sectors +312579760
        11:22:11.226    Disk 0 scanning C:\Windows\system32\drivers
        11:22:18.519    Service scanning
        11:22:19.946    Modules scanning
        11:22:26.241    Disk 0 trace - called modules:
        11:22:26.265    ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll storport.sys nvstor32.sys tcpip.sys NETIO.SYS SYMTDI.SYS
        11:22:26.269    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85b0b918]
        11:22:26.276    3 CLASSPNP.SYS[879a78b3] -> nt!IofCallDriver -> [0x841a26c0]
        11:22:26.281    5 acpi.sys[806096bc] -> nt!IofCallDriver -> \Device\00000061[0x841a2b88]
        11:22:26.286    Scan finished successfully
        11:23:43.367    Disk 0 MBR has been saved successfully to "E:\MBR.dat"
        11:23:43.386    The log file has been saved successfully to "E:\aswMBR.txt"


        ListParts by Farbar
        Ran by Hansberry on 14-02-2012 at 11:27:41
        Windows Vista (X86)
        Running From: C:\Users\Hansberry\Desktop
        Language: 0409
        ************************************************************

        ========================= Memory info ======================

        Percentage of memory in use: 47%
        Total physical RAM: 1917.76 MB
        Available physical RAM: 1001.97 MB
        Total Pagefile: 4083.5 MB
        Available Pagefile: 2758.07 MB
        Total Virtual: 2047.88 MB
        Available Virtual: 1966.55 MB

        =================ed.
        No Proxy Server is set.

        "Reset IE Proxy Settings": IE Proxy Settings were reset.
        ========================= Hosts content: =================================

        ::1             localhost

        127.0.0.1       localhost

        ========================= IP Configuration: ================================

        NETGEAR WG111v3 Wireless-G USB Adapter = Wireless Network Connection (Connected)
        NVIDIA nForce Networking Controller = Local Area Connection (Media disconnected)


        # ----------------------------------
        # IPv4 Configuration
        # ----------------------------------
        pushd interface ipv4

        reset
        set global icmpredirects=enabled


        popd
        # End of IPv4 configuration



        Windows IP Configuration

           Host Name . . . . . . . . . . . . : Hansberry-PC
           Primary Dns Suffix  . . . . . . . :
           Node Type . . . . . . . . . . . . : Hybrid
           IP Routing Enabled. . . . . . . . : No
           WINS Proxy Enabled. . . . . . . . : No

        Wireless LAN adapter Wireless Network Connection:

           Connection-specific DNS Suffix  . :
           Description . . . . . . . . . . . : NETGEAR WG111v3 Wireless-G USB Adapter
           Physical Address. . . . . . . . . : E0-91-F5-92-47-9E
           DHCP Enabled. . . . . . . . . . . : Yes
           Autoconfiguration Enabled . . . . : Yes
           Link-local IPv6 Address . . . . . : fe80::e9fe:4621:8bc9:c1aa%13(Preferred)
           Autoconfiguration IPv4 Address. . : 169.254.193.170(Preferred)
           Subnet Mask . . . . . . . . . . . : 255.255.0.0
           Default Gateway . . . . . . . . . :
           DHCPv6 IAID . . . . . . . . . . . : 283152885
           DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-11-2F-A1-08-00-21-97-D6-C7-4C
           DNS Servers . . . . . . . . . . . : fec0:0:0:ffff::1%1
                                               fec0:0:0:ffff::2%1
                                               fec0:0:0:ffff::3%1
           NetBIOS over Tcpip. . . . . . . . : Enabled

        Ethernet adapter Local Area Connection:

           Media State . . . . . . . . . . . : Media disconnected
           Connection-specific DNS Suffix  . :
           Description . . . . . . . . . . . : NVIDIA nForce 10/100 Mbps Ethernet
           Physical Address. . . . . . . . . : 00-21-97-D6-C7-4C
           DHCP Enabled. . . . . . . . . . . : Yes
           Autoconfiguration Enabled . . . . : Yes

        Tunnel adapter Local Area Connection* 6:

           Media State . . . . . . . . . . . : Media disconnected
           Connection-specific DNS Suffix  . :
           Description . . . . . . . . . . . : isatap.{A953D97E-D32D-46BB-9CCB-00FE62A44F8D}
           Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
           DHCP Enabled. . . . . . . . . . . : No
           Autoconfiguration Enabled . . . . : Yes

        Tunnel adapter Local Area Connection* 7:

           Media State . . . . . . . . . . . : Media disconnected
           Connection-specific DNS Suffix  . :
           Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
           Physical Address. . . . . . . . . : 02-00-54-55-4E-01
           DHCP Enabled. . . . . . . . . . . : No
           Autoconfiguration Enabled . . . . : Yes

        Tunnel adapter Local Area Connection* 11:

           Media State . . . . . . . . . . . : Media disconnected
           Connection-specific DNS Suffix  . :
           Description . . . . . . . . . . . : isatap.{3789212C-4E37-4DC7-8B34-88599A8C27F4}
           Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
           DHCP Enabled. . . . . . . . . . . : No
           Autoconfiguration Enabled . . . . : Yes
        Server:  UnKnown
        Address:  fec0:0:0:ffff::1

        Ping request could not find host google.com. Please check the name and try again.Server:  UnKnown
        Address:  fec0:0:0:ffff::1

        Ping request could not find host yahoo.com. Please check the name and try again.Server:  UnKnown
        Address:  fec0:0:0:ffff::1

        Ping request could not find host bleepingcomputer.com. Please check the name and try again.Pinging 127.0.0.1 with 32 bytes of data:General failure.General failure.Ping statistics for 127.0.0.1:    Packets: Sent = 2, Received = 0, Lost = 2 (100% loss),===========================================================================
        Interface List
         13 ...e0 91 f5 92 47 9e ...... NETGEAR WG111v3 Wireless-G USB Adapter
         10 ...00 21 97 d6 c7 4c ...... NVIDIA nForce 10/100 Mbps Ethernet
          1 ........................... Software Loopback Interface 1
         15 ...00 00 00 00 00 00 00 e0  isatap.{A953D97E-D32D-46BB-9CCB-00FE62A44F8D}
         11 ...02 00 54 55 4e 01 ...... Teredo Tunneling Pseudo-Interface
         14 ...00 00 00 00 00 00 00 e0  isatap.{3789212C-4E37-4DC7-8B34-88599A8C27F4}
        ===========================================================================

        IPv4 Route Table
        ===========================================================================
        Active Routes:
        Network Destination        Netmask          Gateway       Interface  Metric
                127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
                127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
          127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
              169.254.0.0      255.255.0.0         On-link   169.254.193.170    281
          169.254.193.170  255.255.255.255         On-link   169.254.193.170    281
          169.254.255.255  255.255.255.255         On-link   169.254.193.170    281
                224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
                224.0.0.0        240.0.0.0         On-link   169.254.193.170    281
          255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
          255.255.255.255  255.255.255.255         On-link   169.254.193.170    281
        ===========================================================================
        Persistent Routes:
          None

        IPv6 Route Table
        ===========================================================================
        Active Routes:
         If Metric Network Destination      Gateway
          1    306 ::1/128                  On-link
         13    281 fe80::/64                On-link
         13    281 fe80::e9fe:4621:8bc9:c1aa/128
                                            On-link
          1    306 ff00::/8                 On-link
         13    281 ff00::/8                 On-link
        ===========================================================================
        Persistent Routes:
          None

        ========================= Event log errors: ===============================

        Application errors:
        ==================
        Error: (02/09/2012 09:47:22 AM) (Source: Application Hang) (User: )
        Description: The program iTunes.exe version 10.5.2.11 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel.
        Process ID: 850
        Start Time: 01cce75275323a0d
        Termination Time: 16

        Error: (02/09/2012 09:38:12 AM) (Source: WinMgmt) (User: )
        Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

        Error: (02/09/2012 09:37:12 AM) (Source: SideBySide) (User: )
        Description: Activation context generation failed for "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
        Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
        Please use sxstrace.exe for detailed diagnosis.

        Error: (02/09/2012 09:37:12 AM) (Source: SideBySide) (User: )
        Description: Activation context generation failed for "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
        Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
        Please use sxstrace.exe for detailed diagnosis.

        Error: (02/09/2012 09:37:12 AM) (Source: SideBySide) (User: )
        Description: Activation context generation failed for "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
        Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
        Please use sxstrace.exe for detailed diagnosis.

        Error: (02/09/2012 09:37:12 AM) (Source: SideBySide) (User: )
        Description: Activation context generation failed for "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
        Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
        Please use sxstrace.exe for detailed diagnosis.

        Error: (02/09/2012 09:37:12 AM) (Source: SideBySide) (User: )
        Description: Activation context generation failed for "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
        Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
        Please use sxstrace.exe for detailed diagnosis.

        Error: (02/09/2012 09:37:12 AM) (Source: SideBySide) (User: )
        Description: Activation context generation failed for "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
        Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
        Please use sxstrace.exe for detailed diagnosis.

        Error: (02/09/2012 09:37:12 AM) (Source: SideBySide) (User: )
        Description: Activation context generation failed for "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
        Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
        Please use sxstrace.exe for detailed diagnosis.

        Error: (02/08/2012 11:29:58 PM) (Source: VSS) (User: )
        Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005.
        This is often caused by incorrect security settings in either the writer or requestor process.


        Operation:
           Gathering Writer Data

        Context:
           Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
           Writer Name: System Writer
           Writer Instance ID: {b1bb12d6-db89-4515-8e7a-97214babf3a0}


        System errors:
        =============
        Error: (02/09/2012 09:38:13 AM) (Source: Service Control Manager) (User: )
        Description: TICalc%%20

        Error: (02/09/2012 09:38:13 AM) (Source: Service Control Manager) (User: )
        Description: Windows Image Acquisition (WIA)Shell Hardware Detection%%1058

        Error: (02/09/2012 09:38:13 AM) (Source: Service Control Manager) (User: )
        Description: MCSTRM%%2

        Error: (02/08/2012 11:23:39 PM) (Source: Service Control Manager) (User: )
        Description: TICalc%%20

        Error: (02/08/2012 11:23:39 PM) (Source: Service Control Manager) (User: )
        Description: Windows Image Acquisition (WIA)Shell Hardware Detection%%1058

        Error: (02/08/2012 11:23:39 PM) (Source: Service Control Manager) (User: )
        Description: MCSTRM%%2

        Error: (02/08/2012 11:20:57 PM) (Source: Service Control Manager) (User: )
        Description: NVIDIA Display Driver Service32

        Error: (02/08/2012 11:20:57 PM) (Source: Service Control Manager) (User: )
        Description: Windows Installer%%1069

        Error: (02/08/2012 11:20:57 PM) (Source: Service Control Manager) (User: )
        Description: msiserverNT AUTHORITY\SYSTEM%%1352

        Error: (02/08/2012 11:20:57 PM) (Source: DCOM) (User: )
        Description: 1069MSIServer{000C101C-0000-0000-C000-000000000046}


        Microsoft Office Sessions:
        =========================
        Error: (11/08/2009 11:48:57 PM) (Source: Microsoft Office 12 Sessions)(User: )
        Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6211.1000, Microsoft Office Version: 12.0.6215.1000. This session lasted 8 seconds with 0 seconds of active time.  This session ended with a crash.


        ========================= Memory info: ===================================

        Percentage of memory in use: 44%
        Total physical RAM: 1917.76 MB
        Available physical RAM: 1067.47 MB
        Total Pagefile: 4085.54 MB
        Available Pagefile: 3057.95 MB
        Total Virtual: 2047.88 MB
        Available Virtual: 1946.32 MB

        ========================= Partitions: =====================================

        1 Drive c: (OS) (Fixed) (Total:139.05 GB) (Free:69.34 GB) NTFS
        3 Drive e: (CANON_SD) (Removable) (Total:3.69 GB) (Free:2.2 GB) FAT32
        7 Drive i: (FreeAgent Drive) (Fixed) (Total:298.09 GB) (Free:159.03 GB) NTFS
        8 Drive j: (GABRIEL'S) (Removable) (Total:1.87 GB) (Free:1.04 GB) FAT
        9 Drive k: (LEXAR MEDIA) (Removable) (Total:0.24 GB) (Free:0.24 GB) FAT
        10 Drive m: (CALEBCRUZER) (Removable) (Total:0.95 GB) (Free:0.76 GB) FAT

        ========================= Users: ========================================

        User accounts for \\HANSBERRY-PC

        Administrator            Guest                    Hansberry               


        **** End of log ****



        SuperDave

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Thanked: 1020
        • Certifications: List
        • Experience: Expert
        • OS: Windows 10
        Re: limited connectivity
        « Reply #37 on: February 15, 2012, 11:27:17 AM »
        If you have Vista/7 DVD...

        start with step 2

        If you don't have Vista/7 DVD...

        1. Create Vista/7 Recovery Disc.

        Option 1 :
        Vista: Vista Recovery disk. (Option Two)
        Windows 7: Win 7 Recovery disk.

        Option 2
        Download : Vista Recovery disk iso image
        Download : Windows 7 Recovery Disc iso image
        Burn it to CD, or DVD: Burning Image to disk.

        2. Boot from created disk.

        Vista users. At first screen click on Repair your computer:



        Windows 7 users. At first screen click on Install now:



        Select your language and click next:

        Click the button for "Use recovery tools":

        The following applies to both, Vista and Windows 7 users.

        This will bring you to a new screen where the repair process will look for all Windows Vista/7 installations on your computer. When done you will be presented with the System Recovery Options dialog box:

        After this, it will present you with a list of options including startup repair, system restore and command prompt:

        Select Command Prompt

        Type in:
        bootrec /FixMbr (<--- there is a "space" after "bootrec")
        and then press Enter

        Once completed then type Exit, press Enter and restart computer.

        Post fresh MBRCheck log.
        Windows 8 and Windows 10 dual boot with two SSD's

        hansberry

          Topic Starter


          Rookie

          • Experience: Beginner
          • OS: Unknown
          Re: limited connectivity
          « Reply #38 on: February 15, 2012, 01:48:05 PM »
          OK, well, all of that was very confusing.  I ended up accidentally doing option with the recdisc permissions etc just to discover that it was only for those with a vista installation disk, lol.

          Then when I went to option 2 you listed, it wanted me to pay $10 for the file.  So instead I looked around in the windows help file on my computer searching for system repair and managed to find out that the way I need to get to the last screenshot you just posted, is to hit F8 while the computer is restarting!  I don't think that was mentioned yet on this thread, so there ya go.

          Hopefully I didnt mess anythign up by doing the recdisc.exe replacement and permission stuff in Option 1.

          Anyway, here is the log for the check:

          MBRCheck, version 1.2.3
          (c) 2010, AD

          Command-line:         
          Windows Version:      Windows Vista Home Basic Edition
          Windows Information:      Service Pack 2 (build 6002), 32-bit
          Base Board Manufacturer:   eMachines
          BIOS Manufacturer:      Phoenix Technologies, LTD
          System Manufacturer:      eMachines
          System Product Name:      ET1161-05
          Logical Drives Mask:      0x000007fc

          Kernel Drivers (total 146):
            0x82019000 \SystemRoot\system32\ntkrnlpa.exe
            0x823D3000 \SystemRoot\system32\hal.dll
            0x8040D000 \SystemRoot\system32\kdcom.dll
            0x80414000 \SystemRoot\system32\PSHED.dll
            0x80425000 \SystemRoot\system32\BOOTVID.dll
            0x8042D000 \SystemRoot\system32\CLFS.SYS
            0x8046E000 \SystemRoot\system32\CI.dll
            0x8054E000 \SystemRoot\system32\drivers\Wdf01000.sys
            0x805BF000 \SystemRoot\system32\drivers\WDFLDR.SYS
            0x80602000 \SystemRoot\system32\drivers\acpi.sys
            0x80648000 \SystemRoot\system32\drivers\WMILIB.SYS
            0x80651000 \SystemRoot\system32\drivers\msisadrv.sys
            0x80659000 \SystemRoot\system32\drivers\pci.sys
            0x80680000 \SystemRoot\System32\drivers\partmgr.sys
            0x8068F000 \SystemRoot\system32\drivers\volmgr.sys
            0x8069E000 \SystemRoot\System32\drivers\volmgrx.sys
            0x806E8000 \SystemRoot\system32\drivers\pciide.sys
            0x806EF000 \SystemRoot\system32\drivers\PCIIDEX.SYS
            0x806FD000 \SystemRoot\System32\drivers\mountmgr.sys
            0x8070D000 \SystemRoot\system32\drivers\atapi.sys
            0x80715000 \SystemRoot\system32\drivers\ataport.SYS
            0x80733000 \SystemRoot\system32\DRIVERS\nvstor32.sys
            0x80757000 \SystemRoot\system32\DRIVERS\storport.sys
            0x80798000 \SystemRoot\system32\drivers\fltmgr.sys
            0x807CA000 \SystemRoot\system32\drivers\fileinfo.sys
            0x8260A000 \SystemRoot\System32\Drivers\ksecdd.sys
            0x8267B000 \SystemRoot\system32\drivers\ndis.sys
            0x82786000 \SystemRoot\system32\drivers\msrpc.sys
            0x827B1000 \SystemRoot\system32\drivers\NETIO.SYS
            0x87603000 \SystemRoot\System32\drivers\tcpip.sys
            0x876ED000 \SystemRoot\System32\drivers\fwpkclnt.sys
            0x87803000 \SystemRoot\System32\Drivers\Ntfs.sys
            0x87913000 \SystemRoot\system32\drivers\volsnap.sys
            0x8794C000 \SystemRoot\System32\Drivers\spldr.sys
            0x87954000 \SystemRoot\System32\Drivers\mup.sys
            0x87963000 \SystemRoot\System32\drivers\ecache.sys
            0x8798A000 \SystemRoot\system32\drivers\disk.sys
            0x8799B000 \SystemRoot\system32\drivers\CLASSPNP.SYS
            0x879BC000 \SystemRoot\system32\drivers\crcdisk.sys
            0x87708000 \SystemRoot\system32\DRIVERS\tunnel.sys
            0x87713000 \SystemRoot\system32\DRIVERS\tunmp.sys
            0x8771C000 \SystemRoot\system32\DRIVERS\amdk8.sys
            0x8772C000 \SystemRoot\system32\DRIVERS\i8042prt.sys
            0x8773F000 \SystemRoot\system32\DRIVERS\mouclass.sys
            0x8774A000 \SystemRoot\system32\DRIVERS\kbdclass.sys
            0x87755000 \SystemRoot\system32\DRIVERS\usbohci.sys
            0x8775F000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
            0x8779D000 \SystemRoot\system32\DRIVERS\usbehci.sys
            0x8AE0A000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
            0x8AE97000 \SystemRoot\system32\drivers\iviaspi.sys
            0x8AE9A000 \SystemRoot\system32\DRIVERS\cdrom.sys
            0x8AEB2000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys
            0x8B207000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
            0x8BB18000 \SystemRoot\system32\DRIVERS\nvBridge.kmd
            0x8BB1A000 \SystemRoot\System32\drivers\dxgkrnl.sys
            0x8BBBA000 \SystemRoot\System32\drivers\watchdog.sys
            0x8BBC6000 \SystemRoot\system32\DRIVERS\msiscsi.sys
            0x8BBF5000 \SystemRoot\system32\DRIVERS\TDI.SYS
            0x8AEB8000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
            0x8AECF000 \SystemRoot\system32\DRIVERS\ndistapi.sys
            0x8AEDA000 \SystemRoot\system32\DRIVERS\ndiswan.sys
            0x8AEFD000 \SystemRoot\system32\DRIVERS\raspppoe.sys
            0x8AF0C000 \SystemRoot\system32\DRIVERS\raspptp.sys
            0x8AF20000 \SystemRoot\system32\DRIVERS\rassstp.sys
            0x8AF35000 \SystemRoot\System32\Drivers\Pcouffin.sys
            0x8AF41000 \SystemRoot\system32\DRIVERS\termdd.sys
            0x8B200000 \SystemRoot\system32\DRIVERS\swenum.sys
            0x8AF51000 \SystemRoot\system32\DRIVERS\ks.sys
            0x8AF7B000 \SystemRoot\system32\DRIVERS\mssmbios.sys
            0x8AF85000 \SystemRoot\system32\DRIVERS\umbus.sys
            0x8AF92000 \SystemRoot\system32\DRIVERS\usbhub.sys
            0x8AFC7000 \SystemRoot\System32\Drivers\NDProxy.SYS
            0x8C008000 \SystemRoot\system32\drivers\RTKVHDA.sys
            0x8C215000 \SystemRoot\system32\drivers\portcls.sys
            0x8C242000 \SystemRoot\system32\drivers\drmk.sys
            0x8C267000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
            0x8C270000 \SystemRoot\System32\Drivers\Null.SYS
            0x8C277000 \SystemRoot\System32\Drivers\Beep.SYS
            0x8C27E000 \SystemRoot\System32\drivers\vga.sys
            0x8C28A000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
            0x8C2AB000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
            0x8C2B3000 \SystemRoot\system32\drivers\rdpencdd.sys
            0x8C2BB000 \SystemRoot\System32\Drivers\Msfs.SYS
            0x8C2C6000 \SystemRoot\System32\Drivers\Npfs.SYS
            0x8C2D4000 \SystemRoot\System32\DRIVERS\rasacd.sys
            0x8C2DD000 \SystemRoot\system32\DRIVERS\tdx.sys
            0x8C2F3000 \SystemRoot\System32\Drivers\SYMTDI.SYS
            0x8C31F000 \??\C:\Windows\system32\Drivers\SYMEVENT.SYS
            0x8C344000 \SystemRoot\system32\DRIVERS\smb.sys
            0x8C358000 \SystemRoot\system32\drivers\afd.sys
            0x8C3A0000 \SystemRoot\System32\DRIVERS\netbt.sys
            0x8C3D2000 \SystemRoot\system32\drivers\ws2ifsl.sys
            0x8C3DB000 \SystemRoot\system32\DRIVERS\pacer.sys
            0x8C3F1000 \SystemRoot\system32\DRIVERS\SymIMv.sys
            0x8AFD8000 \SystemRoot\system32\DRIVERS\rtlprot.sys
            0x8AFE2000 \SystemRoot\system32\DRIVERS\netbios.sys
            0x877AC000 \SystemRoot\system32\DRIVERS\wanarp.sys
            0x8AFF0000 \SystemRoot\System32\Drivers\SRTSPX.SYS
            0x8C80A000 \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
            0x8C87A000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
            0x8C89C000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
            0x8C8A2000 \SystemRoot\system32\DRIVERS\rdbss.sys
            0x8C8DE000 \SystemRoot\system32\drivers\nsiproxy.sys
            0x8C8E8000 \??\C:\PROGRA~2\Symantec\DEFINI~1\SymcData\ipsdefs\20090811.002\IDSvix86.sys
            0x8C92E000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
            0x8C98C000 \SystemRoot\System32\Drivers\dfsc.sys
            0x8D005000 \SystemRoot\system32\DRIVERS\wg111v3.sys
            0x8D063000 \SystemRoot\system32\DRIVERS\usbprint.sys
            0x8D06D000 \SystemRoot\system32\DRIVERS\USBD.SYS
            0x8D06F000 \SystemRoot\system32\DRIVERS\usbscan.sys
            0x8D07C000 \SystemRoot\System32\Drivers\crashdmp.sys
            0x8D089000 \SystemRoot\System32\Drivers\dump_diskdump.sys
            0x8D093000 \SystemRoot\System32\Drivers\dump_nvstor32.sys
            0x8D0B7000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
            0x93A20000 \SystemRoot\System32\win32k.sys
            0x8D0CC000 \SystemRoot\System32\drivers\Dxapi.sys
            0x8D0D6000 \SystemRoot\system32\DRIVERS\monitor.sys
            0x93C40000 \SystemRoot\System32\TSDDD.dll
            0x93C60000 \SystemRoot\System32\cdd.dll
            0x8D0E5000 \SystemRoot\system32\drivers\luafv.sys
            0x8D100000 \SystemRoot\system32\drivers\WudfPf.sys
            0x8D11A000 \SystemRoot\system32\DRIVERS\lltdio.sys
            0x8D12A000 \SystemRoot\system32\DRIVERS\nwifi.sys
            0x8D154000 \SystemRoot\system32\DRIVERS\ndisuio.sys
            0x8D15E000 \SystemRoot\system32\DRIVERS\rspndr.sys
            0x8D171000 \SystemRoot\system32\drivers\HTTP.sys
            0x8C9A3000 \SystemRoot\System32\Drivers\fastfat.SYS
            0x8D1DE000 \??\C:\Windows\system32\drivers\CO_Mon.sys
            0x8C9CB000 \SystemRoot\System32\DRIVERS\srvnet.sys
            0xA2A0D000 \SystemRoot\system32\drivers\spsys.sys
            0xA2ABD000 \SystemRoot\system32\DRIVERS\bowser.sys
            0xA2AD6000 \SystemRoot\System32\drivers\mpsdrv.sys
            0xA2AEB000 \SystemRoot\system32\drivers\mrxdav.sys
            0xA2B0C000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
            0xA2B2B000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
            0xA2B64000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
            0xA2B7C000 \SystemRoot\System32\DRIVERS\srv2.sys
            0xA2BA4000 \SystemRoot\System32\DRIVERS\srv.sys
            0xA2BF3000 \SystemRoot\System32\Drivers\SYMREDRV.SYS
            0xA2BF7000 \??\C:\Windows\system32\drivers\int15.sys
            0xA8004000 \SystemRoot\system32\drivers\peauth.sys
            0xA80E2000 \SystemRoot\System32\Drivers\secdrv.SYS
            0xA810A000 \SystemRoot\System32\drivers\tcpipreg.sys
            0xA8118000 \SystemRoot\system32\DRIVERS\WUDFRd.sys
            0xA8139000 \SystemRoot\system32\DRIVERS\cdfs.sys
            0x779E0000 \Windows\System32\ntdll.dll

          Processes (total 65):
                 0 System Idle Process
                 4 System
               432 C:\Windows\System32\smss.exe
               508 csrss.exe
               556 C:\Windows\System32\wininit.exe
               564 csrss.exe
               604 C:\Windows\System32\services.exe
               616 C:\Windows\System32\lsass.exe
               624 C:\Windows\System32\lsm.exe
               648 C:\Windows\System32\winlogon.exe
               816 C:\Windows\System32\svchost.exe
               864 C:\Windows\System32\nvvsvc.exe
               892 C:\Windows\System32\svchost.exe
               924 C:\Windows\System32\svchost.exe
               972 C:\Windows\System32\svchost.exe
              1080 C:\Windows\System32\svchost.exe
              1096 C:\Windows\System32\svchost.exe
              1168 C:\Windows\System32\audiodg.exe
              1192 C:\Windows\System32\svchost.exe
              1208 C:\Windows\System32\SLsvc.exe
              1244 C:\Windows\System32\svchost.exe
              1340 C:\Windows\System32\nvvsvc.exe
              1440 C:\Windows\System32\svchost.exe
              1672 C:\Windows\System32\spoolsv.exe
              1728 C:\Windows\System32\taskeng.exe
              1736 C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE
              1772 C:\Windows\System32\dwm.exe
              1868 C:\Windows\explorer.exe
              2008 C:\Windows\System32\svchost.exe
              1048 C:\Windows\RtHDVCpl.exe
              1304 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
              1588 C:\Program Files\Zune\ZuneLauncher.exe
              1540 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
              1720 C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
              2072 C:\Program Files\iTunes\iTunesHelper.exe
              2080 C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
              2088 C:\Program Files\Common Files\Java\Java Update\jusched.exe
              2124 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              2144 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
              2164 C:\Program Files\Windows Media Player\wmpnscfg.exe
              2184 C:\Program Files\Sandisk\Common\Bin\WinCinemaMgr.exe
              2200 C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
              2208 C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
              2216 C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
              2608 C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE
              3184 C:\Program Files\SUPERAntiSpyware\SASCore.exe
              3200 C:\Windows\System32\agrsmsvc.exe
              3228 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
              3244 C:\Program Files\Bonjour\mDNSResponder.exe
              3276 C:\Program Files\EMACHINES\eMachines Recovery Management\Service\ETService.exe
              3420 C:\Windows\System32\svchost.exe
              3456 C:\Program Files\CyberLink\Shared files\RichVideo.exe
              3568 C:\Windows\System32\svchost.exe
              3632 C:\Windows\System32\SearchIndexer.exe
              3768 WUDFHost.exe
              4024 C:\Program Files\Windows Media Player\wmpnetwk.exe
              4044 C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
              3172 C:\Program Files\iPod\bin\iPodService.exe
              2348 C:\Windows\System32\taskeng.exe
              3176 C:\Windows\System32\SearchProtocolHost.exe
              2828 C:\Windows\System32\SearchFilterHost.exe
              1052 dllhost.exe
               420 dllhost.exe
              3956 C:\Users\Hansberry\Desktop\MBRCheck.exe
               472 C:\Windows\System32\conime.exe

          \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000002`80100000  (NTFS)
          \\.\I: --> \\.\PhysicalDrive7 at offset 0x00000000`00007e00  (NTFS)

          PhysicalDrive0 Model Number: ST3160815AS, Rev: 4.AA
          PhysicalDrive7 Model Number: SeagateFreeAgentDesktop, Rev: 100D

                Size  Device Name          MBR Status
            --------------------------------------------
              149 GB  \\.\PhysicalDrive0   Windows 2008 MBR code detected
                      SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A797 9
              298 GB  \\.\PhysicalDrive7   RE: Unknown MBR code
                      SHA1: 639AC5CDF8A5CF3245975932C6A4215450A7B98 F


          Found non-standard or infected MBR.
          Enter 'Y' and hit ENTER for more options, or 'N' to exit:

          SuperDave

          • Malware Removal Specialist
          • Moderator


          • Genius
          • Thanked: 1020
          • Certifications: List
          • Experience: Expert
          • OS: Windows 10
          Re: limited connectivity
          « Reply #39 on: February 15, 2012, 04:22:14 PM »
          Quote
          hit F8 while the computer is restarting!  I don't think that was mentioned yet on this thread, so there ya go.
          Did you get a chance to do this?
          Quote
          Select Command Prompt

          Type in:
          bootrec /FixMbr (<--- there is a "space" after "bootrec")
          and then press Enter

          Once completed then type Exit, press Enter and restart computer.
          [/COLOR]
          Windows 8 and Windows 10 dual boot with two SSD's

          hansberry

            Topic Starter


            Rookie

            • Experience: Beginner
            • OS: Unknown
            Re: limited connectivity
            « Reply #40 on: February 15, 2012, 04:42:18 PM »
            Yep...I posted the log in my previous post.  The one drive that says unknown MBR is just an external drive we save things to if that matters.  The hard drive (C) for the computer says: Windows 2008 MBR code detected.

            hansberry

              Topic Starter


              Rookie

              • Experience: Beginner
              • OS: Unknown
              Re: limited connectivity
              « Reply #41 on: February 15, 2012, 04:49:11 PM »
              Here is a new log with the freeagent external drive unplugged.  We don't run stuff from that one it is just for backing up stuff we dont want to lose if the computer goes down.

              MBRCheck, version 1.2.3
              (c) 2010, AD

              Command-line:         
              Windows Version:      Windows Vista Home Basic Edition
              Windows Information:      Service Pack 2 (build 6002), 32-bit
              Base Board Manufacturer:   eMachines
              BIOS Manufacturer:      Phoenix Technologies, LTD
              System Manufacturer:      eMachines
              System Product Name:      ET1161-05
              Logical Drives Mask:      0x000006fc

              Kernel Drivers (total 147):
                0x82019000 \SystemRoot\system32\ntkrnlpa.exe
                0x823D3000 \SystemRoot\system32\hal.dll
                0x80400000 \SystemRoot\system32\kdcom.dll
                0x80407000 \SystemRoot\system32\PSHED.dll
                0x80418000 \SystemRoot\system32\BOOTVID.dll
                0x80420000 \SystemRoot\system32\CLFS.SYS
                0x80461000 \SystemRoot\system32\CI.dll
                0x80541000 \SystemRoot\system32\drivers\Wdf01000.sys
                0x805B2000 \SystemRoot\system32\drivers\WDFLDR.SYS
                0x8060D000 \SystemRoot\system32\drivers\acpi.sys
                0x80653000 \SystemRoot\system32\drivers\WMILIB.SYS
                0x8065C000 \SystemRoot\system32\drivers\msisadrv.sys
                0x80664000 \SystemRoot\system32\drivers\pci.sys
                0x8068B000 \SystemRoot\System32\drivers\partmgr.sys
                0x8069A000 \SystemRoot\system32\drivers\volmgr.sys
                0x806A9000 \SystemRoot\System32\drivers\volmgrx.sys
                0x806F3000 \SystemRoot\system32\drivers\pciide.sys
                0x806FA000 \SystemRoot\system32\drivers\PCIIDEX.SYS
                0x80708000 \SystemRoot\System32\drivers\mountmgr.sys
                0x80718000 \SystemRoot\system32\drivers\atapi.sys
                0x80720000 \SystemRoot\system32\drivers\ataport.SYS
                0x8073E000 \SystemRoot\system32\DRIVERS\nvstor32.sys
                0x80762000 \SystemRoot\system32\DRIVERS\storport.sys
                0x807A3000 \SystemRoot\system32\drivers\fltmgr.sys
                0x807D5000 \SystemRoot\system32\drivers\fileinfo.sys
                0x82605000 \SystemRoot\System32\Drivers\ksecdd.sys
                0x82676000 \SystemRoot\system32\drivers\ndis.sys
                0x82781000 \SystemRoot\system32\drivers\msrpc.sys
                0x827AC000 \SystemRoot\system32\drivers\NETIO.SYS
                0x8760B000 \SystemRoot\System32\drivers\tcpip.sys
                0x876F5000 \SystemRoot\System32\drivers\fwpkclnt.sys
                0x87805000 \SystemRoot\System32\Drivers\Ntfs.sys
                0x87915000 \SystemRoot\system32\drivers\volsnap.sys
                0x8794E000 \SystemRoot\System32\Drivers\spldr.sys
                0x87956000 \SystemRoot\System32\Drivers\mup.sys
                0x87965000 \SystemRoot\System32\drivers\ecache.sys
                0x8798C000 \SystemRoot\system32\drivers\disk.sys
                0x8799D000 \SystemRoot\system32\drivers\CLASSPNP.SYS
                0x879BE000 \SystemRoot\system32\drivers\crcdisk.sys
                0x879DE000 \SystemRoot\system32\DRIVERS\tunnel.sys
                0x879E9000 \SystemRoot\system32\DRIVERS\tunmp.sys
                0x87734000 \SystemRoot\system32\DRIVERS\amdk8.sys
                0x87744000 \SystemRoot\system32\DRIVERS\i8042prt.sys
                0x879F2000 \SystemRoot\system32\DRIVERS\mouclass.sys
                0x87757000 \SystemRoot\system32\DRIVERS\kbdclass.sys
                0x87762000 \SystemRoot\system32\DRIVERS\usbohci.sys
                0x8776C000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
                0x877AA000 \SystemRoot\system32\DRIVERS\usbehci.sys
                0x8AC0D000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
                0x8AC9A000 \SystemRoot\system32\drivers\iviaspi.sys
                0x8AC9D000 \SystemRoot\system32\DRIVERS\cdrom.sys
                0x8ACB5000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys
                0x8AE07000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
                0x8B718000 \SystemRoot\system32\DRIVERS\nvBridge.kmd
                0x8B71A000 \SystemRoot\System32\drivers\dxgkrnl.sys
                0x8B7BA000 \SystemRoot\System32\drivers\watchdog.sys
                0x8B7C6000 \SystemRoot\system32\DRIVERS\msiscsi.sys
                0x8B7F5000 \SystemRoot\system32\DRIVERS\TDI.SYS
                0x8ACBB000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
                0x8ACD2000 \SystemRoot\system32\DRIVERS\ndistapi.sys
                0x8ACDD000 \SystemRoot\system32\DRIVERS\ndiswan.sys
                0x8AD00000 \SystemRoot\system32\DRIVERS\raspppoe.sys
                0x8AD0F000 \SystemRoot\system32\DRIVERS\raspptp.sys
                0x8AD23000 \SystemRoot\system32\DRIVERS\rassstp.sys
                0x8AD38000 \SystemRoot\System32\Drivers\Pcouffin.sys
                0x8AD44000 \SystemRoot\system32\DRIVERS\termdd.sys
                0x8AE00000 \SystemRoot\system32\DRIVERS\swenum.sys
                0x8AD54000 \SystemRoot\system32\DRIVERS\ks.sys
                0x8AD7E000 \SystemRoot\system32\DRIVERS\mssmbios.sys
                0x8AD88000 \SystemRoot\system32\DRIVERS\umbus.sys
                0x8AD95000 \SystemRoot\system32\DRIVERS\usbhub.sys
                0x8ADCA000 \SystemRoot\System32\Drivers\NDProxy.SYS
                0x8BA0B000 \SystemRoot\system32\drivers\RTKVHDA.sys
                0x8BC18000 \SystemRoot\system32\drivers\portcls.sys
                0x8BC45000 \SystemRoot\system32\drivers\drmk.sys
                0x8BC6A000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
                0x8BC73000 \SystemRoot\System32\Drivers\Null.SYS
                0x8BC7A000 \SystemRoot\System32\Drivers\Beep.SYS
                0x8BC81000 \SystemRoot\System32\drivers\vga.sys
                0x8BC8D000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
                0x8BCAE000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
                0x8BCB6000 \SystemRoot\system32\drivers\rdpencdd.sys
                0x8BCBE000 \SystemRoot\System32\Drivers\Msfs.SYS
                0x8BCC9000 \SystemRoot\System32\Drivers\Npfs.SYS
                0x8BCD7000 \SystemRoot\System32\DRIVERS\rasacd.sys
                0x8BCE0000 \SystemRoot\system32\DRIVERS\tdx.sys
                0x8BCF6000 \SystemRoot\System32\Drivers\SYMTDI.SYS
                0x8BD22000 \??\C:\Windows\system32\Drivers\SYMEVENT.SYS
                0x8BD47000 \SystemRoot\system32\DRIVERS\smb.sys
                0x8BD5B000 \SystemRoot\system32\drivers\afd.sys
                0x8BDA3000 \SystemRoot\System32\DRIVERS\netbt.sys
                0x8BDD5000 \SystemRoot\system32\drivers\ws2ifsl.sys
                0x8BDDE000 \SystemRoot\system32\DRIVERS\pacer.sys
                0x8BDF4000 \SystemRoot\system32\DRIVERS\SymIMv.sys
                0x8BA00000 \SystemRoot\system32\DRIVERS\rtlprot.sys
                0x8ADDB000 \SystemRoot\system32\DRIVERS\netbios.sys
                0x8ADE9000 \SystemRoot\system32\DRIVERS\wanarp.sys
                0x8AC00000 \SystemRoot\System32\Drivers\SRTSPX.SYS
                0x8C40E000 \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
                0x8C47E000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
                0x8C4A0000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
                0x8C4A6000 \SystemRoot\system32\DRIVERS\rdbss.sys
                0x8C4E2000 \SystemRoot\system32\drivers\nsiproxy.sys
                0x8C4EC000 \??\C:\PROGRA~2\Symantec\DEFINI~1\SymcData\ipsdefs\20090811.002\IDSvix86.sys
                0x8C532000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
                0x8C590000 \SystemRoot\System32\Drivers\dfsc.sys
                0x8CC0F000 \SystemRoot\system32\DRIVERS\wg111v3.sys
                0x8CC6D000 \SystemRoot\system32\DRIVERS\usbprint.sys
                0x8CC77000 \SystemRoot\system32\DRIVERS\USBD.SYS
                0x8CC79000 \SystemRoot\System32\Drivers\crashdmp.sys
                0x8CC86000 \SystemRoot\System32\Drivers\dump_diskdump.sys
                0x8CC90000 \SystemRoot\System32\Drivers\dump_nvstor32.sys
                0x8CCB4000 \SystemRoot\system32\DRIVERS\usbscan.sys
                0x8CCC1000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
                0x938E0000 \SystemRoot\System32\win32k.sys
                0x8CCD6000 \SystemRoot\System32\drivers\Dxapi.sys
                0x8CCE0000 \SystemRoot\system32\DRIVERS\monitor.sys
                0x93B00000 \SystemRoot\System32\TSDDD.dll
                0x93B20000 \SystemRoot\System32\cdd.dll
                0x8CCEF000 \SystemRoot\system32\drivers\luafv.sys
                0x8CD0A000 \SystemRoot\system32\drivers\WudfPf.sys
                0x8CD24000 \SystemRoot\system32\DRIVERS\lltdio.sys
                0x8CD34000 \SystemRoot\system32\DRIVERS\nwifi.sys
                0x8CD5E000 \SystemRoot\system32\DRIVERS\ndisuio.sys
                0x8CD68000 \SystemRoot\system32\DRIVERS\rspndr.sys
                0x8CD7B000 \SystemRoot\system32\drivers\HTTP.sys
                0x8C5A7000 \SystemRoot\System32\Drivers\fastfat.SYS
                0x9D805000 \SystemRoot\system32\drivers\spsys.sys
                0x9D8B5000 \??\C:\Windows\system32\drivers\CO_Mon.sys
                0x9D8BD000 \SystemRoot\System32\DRIVERS\srvnet.sys
                0x9D8DA000 \SystemRoot\system32\DRIVERS\bowser.sys
                0x9D8F3000 \SystemRoot\System32\drivers\mpsdrv.sys
                0x9D908000 \SystemRoot\system32\drivers\mrxdav.sys
                0x9D929000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
                0x9D948000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
                0x9D981000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
                0x9D999000 \SystemRoot\System32\DRIVERS\srv2.sys
                0xA800B000 \SystemRoot\System32\DRIVERS\srv.sys
                0xA805A000 \SystemRoot\System32\Drivers\SYMREDRV.SYS
                0xA805E000 \??\C:\Windows\system32\drivers\int15.sys
                0xA8065000 \SystemRoot\system32\drivers\peauth.sys
                0xA8143000 \SystemRoot\System32\Drivers\secdrv.SYS
                0xA816B000 \SystemRoot\System32\drivers\tcpipreg.sys
                0xA8179000 \SystemRoot\system32\DRIVERS\WUDFRd.sys
                0xA819A000 \SystemRoot\system32\DRIVERS\cdfs.sys
                0xA81B0000 \??\C:\Windows\system32\drivers\mbam.sys
                0x773C0000 \Windows\System32\ntdll.dll

              Processes (total 68):
                     0 System Idle Process
                     4 System
                   432 C:\Windows\System32\smss.exe
                   508 csrss.exe
                   556 C:\Windows\System32\wininit.exe
                   564 csrss.exe
                   604 C:\Windows\System32\services.exe
                   616 C:\Windows\System32\lsass.exe
                   624 C:\Windows\System32\lsm.exe
                   648 C:\Windows\System32\winlogon.exe
                   816 C:\Windows\System32\svchost.exe
                   864 C:\Windows\System32\nvvsvc.exe
                   892 C:\Windows\System32\svchost.exe
                   924 C:\Windows\System32\svchost.exe
                  1028 C:\Windows\System32\svchost.exe
                  1080 C:\Windows\System32\svchost.exe
                  1092 C:\Windows\System32\svchost.exe
                  1168 C:\Windows\System32\audiodg.exe
                  1192 C:\Windows\System32\svchost.exe
                  1208 C:\Windows\System32\SLsvc.exe
                  1244 C:\Windows\System32\svchost.exe
                  1288 C:\Windows\System32\nvvsvc.exe
                  1456 C:\Windows\System32\svchost.exe
                  1732 C:\Windows\System32\spoolsv.exe
                  1748 C:\Windows\System32\dwm.exe
                  1796 C:\Windows\System32\taskeng.exe
                  1808 C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE
                  1836 C:\Windows\explorer.exe
                   300 C:\Windows\System32\svchost.exe
                  1088 C:\Windows\RtHDVCpl.exe
                   888 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
                  1444 C:\Program Files\Zune\ZuneLauncher.exe
                   972 C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
                  2072 C:\Program Files\iTunes\iTunesHelper.exe
                  2080 C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
                  2088 C:\Program Files\Common Files\Java\Java Update\jusched.exe
                  2096 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  2104 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                  2112 C:\Program Files\Windows Media Player\wmpnscfg.exe
                  2120 C:\Program Files\Sandisk\Common\Bin\WinCinemaMgr.exe
                  2136 C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
                  2164 C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
                  2172 C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                  2564 C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE
                  3152 C:\Program Files\SUPERAntiSpyware\SASCore.exe
                  3168 C:\Windows\System32\agrsmsvc.exe
                  3196 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
                  3212 C:\Program Files\Bonjour\mDNSResponder.exe
                  3244 C:\Program Files\EMACHINES\eMachines Recovery Management\Service\ETService.exe
                  3384 C:\Windows\System32\svchost.exe
                  3416 C:\Program Files\CyberLink\Shared files\RichVideo.exe
                  3540 C:\Windows\System32\svchost.exe
                  3600 C:\Windows\System32\SearchIndexer.exe
                  3872 WUDFHost.exe
                  4012 C:\Program Files\Windows Media Player\wmpnetwk.exe
                  4032 C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                  2148 C:\Program Files\iPod\bin\iPodService.exe
                  1904 C:\Windows\System32\conime.exe
                  2896 C:\Windows\System32\taskeng.exe
                  3080 C:\Windows\System32\SearchProtocolHost.exe
                  3664 C:\Windows\System32\svchost.exe
                  1304 C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
                  3864 C:\Windows\servicing\TrustedInstaller.exe
                  3620 WmiPrvSE.exe
                  3776 C:\Windows\System32\SearchFilterHost.exe
                  2556 dllhost.exe
                  1380 dllhost.exe
                  3024 C:\Users\Hansberry\Desktop\MBRCheck.exe

              \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000002`80100000  (NTFS)

              PhysicalDrive0 Model Number: ST3160815AS, Rev: 4.AA

                    Size  Device Name          MBR Status
                --------------------------------------------
                  149 GB  \\.\PhysicalDrive0   Windows 2008 MBR code detected
                          SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A797 9


              Done!

              SuperDave

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Thanked: 1020
              • Certifications: List
              • Experience: Expert
              • OS: Windows 10
              Re: limited connectivity
              « Reply #42 on: February 15, 2012, 05:29:05 PM »
              Quote
              We don't run stuff from that one it is just for backing up stuff we dont want to lose if the computer goes down.
              Good idea. How is the internet connection now? Can you run the ESET scan?
              Windows 8 and Windows 10 dual boot with two SSD's

              hansberry

                Topic Starter


                Rookie

                • Experience: Beginner
                • OS: Unknown
                Re: limited connectivity
                « Reply #43 on: February 15, 2012, 05:36:32 PM »
                No internet connection yet...still shows 'unidentified' network..sees the tab but wont really connect.  I have two other computers finding and connecting just fine.   I'm assuming the ESET scan you mean is the one I needed a connection for.

                SuperDave

                • Malware Removal Specialist
                • Moderator


                • Genius
                • Thanked: 1020
                • Certifications: List
                • Experience: Expert
                • OS: Windows 10
                Re: limited connectivity
                « Reply #44 on: February 15, 2012, 07:40:48 PM »
                Quote
                I'm assuming the ESET scan you mean is the one I needed a connection for.
                Yes. What browser are you using?

                Please download Farbar Service Scanner and run it on the computer with the issue.
                • Press "Scan".
                • It will create a log (FSS.txt) in the same directory the tool is run.
                • Please copy and paste the log to your reply.
                ******************************************************
                Download GMER Rootkit Scanner from here.

                •Double click the .exe file. If asked to allow gmer.sys driver to load, please consent
                •If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO
                •In the right panel, you will see several boxes that have been checked. Uncheck the following ...
                   *Sections
                   *IAT/EAT
                   *Drives/Partition other than Systemdrive (typically C:\)
                   *Show All (don't miss this one)
                •Then click the Scan button & wait for it to finish
                •Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file
                •Save it where you can easily find it, such as your desktop, and post it in reply
                **Caution**
                Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries

                Windows 8 and Windows 10 dual boot with two SSD's