Eric Witzling
Posts: 120 +2
TDSSKiller seems to find the same thing that aswMBR does ( \Device\Harddisk0\DR0 ( TDSS File System ) ) but does not give me a "Cure" option, so I'm forced to skip. The rest all seem like regular old unsigned drivers, not anything malware-associated that I can recognize. The full log is attached.
Ran a new aswMBR scan while I was in there as well:
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-07-23 00:43:50
-----------------------------
00:43:50.359 OS Version: Windows 5.1.2600 Service Pack 3
00:43:50.359 Number of processors: 2 586 0xF0D
00:43:50.359 ComputerName: HL111008 UserName: Kristine
00:43:50.640 Initialize success
00:45:31.671 AVAST engine defs: 12072201
00:46:01.781 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4
00:46:01.796 Disk 0 Vendor: ST3160815AS 4.CCC Size: 152627MB BusType: 3
00:46:01.828 Disk 0 MBR read successfully
00:46:01.828 Disk 0 MBR scan
00:46:01.875 Disk 0 Windows XP default MBR code
00:46:01.890 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 149069 MB offset 2048
00:46:01.937 Disk 0 Partition 2 00 12 Compaq diag MSDOS5.0 3556 MB offset 305295360
00:46:01.953 Disk 0 Partition 3 00 17 Hidd HPFS/NTFS NTFS 1 MB offset 312578048
00:46:01.968 Disk 0 Partition 3 **INFECTED** MBR:SST [Rtk]
00:46:02.015 Disk 0 scanning sectors +312581792
00:46:03.484 Disk 0 scanning C:\WINDOWS\system32\drivers
00:46:13.218 Service scanning
00:46:32.640 Modules scanning
00:46:38.359 Disk 0 trace - called modules:
00:46:38.437 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
00:46:38.468 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x87375ab8]
00:46:38.515 3 CLASSPNP.SYS[f774cfd7] -> nt!IofCallDriver -> \Device\00000063[0x873ca9e8]
00:46:38.546 5 ACPI.sys[f76c3620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-4[0x87378d98]
00:46:38.921 AVAST engine scan C:\WINDOWS
00:47:03.859 AVAST engine scan C:\WINDOWS\system32
00:49:16.906 AVAST engine scan C:\WINDOWS\system32\drivers
00:49:37.046 AVAST engine scan C:\Documents and Settings\kristine
00:51:51.234 File: C:\Documents and Settings\kristine\Local Settings\Temp\34acf1a4-5753.tmp **INFECTED** Win32:Rootkit-gen [Rtk]
00:51:51.359 File: C:\Documents and Settings\kristine\Local Settings\Temp\35ad8ae8-5753.tmp **INFECTED** Win32:Rootkit-gen [Rtk]
00:51:51.531 File: C:\Documents and Settings\kristine\Local Settings\Temp\7ea807b2-5753.tmp **INFECTED** Win32:Rootkit-gen [Rtk]
00:52:29.156 AVAST engine scan C:\Documents and Settings\All Users
00:53:11.328 Scan finished successfully
00:53:19.890 Disk 0 MBR has been saved successfully to "C:\download\MBR.dat"
00:53:19.937 The log file has been saved successfully to "C:\download\aswMBR.txt"
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-07-25 18:19:57
-----------------------------
18:19:57.781 OS Version: Windows 5.1.2600 Service Pack 3
18:19:57.781 Number of processors: 2 586 0xF0D
18:19:57.781 ComputerName: HL111008 UserName: Kristine
18:19:58.359 Initialize success
18:21:56.500 AVAST engine defs: 12072500
18:22:17.109 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4
18:22:17.125 Disk 0 Vendor: ST3160815AS 4.CCC Size: 152627MB BusType: 3
18:22:17.140 Disk 0 MBR read successfully
18:22:17.156 Disk 0 MBR scan
18:22:17.203 Disk 0 Windows XP default MBR code
18:22:17.234 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 149069 MB offset 2048
18:22:17.250 Disk 0 Partition 2 00 12 Compaq diag MSDOS5.0 3556 MB offset 305295360
18:22:17.296 Disk 0 Partition 3 00 17 Hidd HPFS/NTFS NTFS 1 MB offset 312578048
18:22:17.312 Disk 0 Partition 3 **INFECTED** MBR:SST [Rtk]
18:22:17.343 Disk 0 scanning sectors +312581792
18:22:18.781 Disk 0 scanning C:\WINDOWS\system32\drivers
18:22:29.578 Service scanning
18:22:51.093 Modules scanning
18:22:53.859 Disk 0 trace - called modules:
18:22:53.937 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
18:22:53.968 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8734d908]
18:22:54.015 3 CLASSPNP.SYS[f774cfd7] -> nt!IofCallDriver -> \Device\00000065[0x873d3338]
18:22:54.046 5 ACPI.sys[f76c3620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-4[0x87350d98]
18:22:54.500 AVAST engine scan C:\WINDOWS
18:23:20.500 AVAST engine scan C:\WINDOWS\system32
18:25:40.468 AVAST engine scan C:\WINDOWS\system32\drivers
18:26:03.000 AVAST engine scan C:\Documents and Settings\kristine
18:28:19.109 File: C:\Documents and Settings\kristine\Local Settings\Temp\34acf1a4-5753.tmp **INFECTED** Win32:Rootkit-gen [Rtk]
18:28:19.234 File: C:\Documents and Settings\kristine\Local Settings\Temp\35ad8ae8-5753.tmp **INFECTED** Win32:Rootkit-gen [Rtk]
18:28:19.406 File: C:\Documents and Settings\kristine\Local Settings\Temp\7ea807b2-5753.tmp **INFECTED** Win32:Rootkit-gen [Rtk]
18:28:39.687 AVAST engine scan C:\Documents and Settings\All Users
18:29:24.468 Scan finished successfully
18:41:27.640 Disk 0 MBR has been saved successfully to "C:\download\MBR.dat"
18:41:27.687 The log file has been saved successfully to "C:\download\aswMBR.txt"
Ran a new aswMBR scan while I was in there as well:
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-07-23 00:43:50
-----------------------------
00:43:50.359 OS Version: Windows 5.1.2600 Service Pack 3
00:43:50.359 Number of processors: 2 586 0xF0D
00:43:50.359 ComputerName: HL111008 UserName: Kristine
00:43:50.640 Initialize success
00:45:31.671 AVAST engine defs: 12072201
00:46:01.781 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4
00:46:01.796 Disk 0 Vendor: ST3160815AS 4.CCC Size: 152627MB BusType: 3
00:46:01.828 Disk 0 MBR read successfully
00:46:01.828 Disk 0 MBR scan
00:46:01.875 Disk 0 Windows XP default MBR code
00:46:01.890 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 149069 MB offset 2048
00:46:01.937 Disk 0 Partition 2 00 12 Compaq diag MSDOS5.0 3556 MB offset 305295360
00:46:01.953 Disk 0 Partition 3 00 17 Hidd HPFS/NTFS NTFS 1 MB offset 312578048
00:46:01.968 Disk 0 Partition 3 **INFECTED** MBR:SST [Rtk]
00:46:02.015 Disk 0 scanning sectors +312581792
00:46:03.484 Disk 0 scanning C:\WINDOWS\system32\drivers
00:46:13.218 Service scanning
00:46:32.640 Modules scanning
00:46:38.359 Disk 0 trace - called modules:
00:46:38.437 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
00:46:38.468 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x87375ab8]
00:46:38.515 3 CLASSPNP.SYS[f774cfd7] -> nt!IofCallDriver -> \Device\00000063[0x873ca9e8]
00:46:38.546 5 ACPI.sys[f76c3620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-4[0x87378d98]
00:46:38.921 AVAST engine scan C:\WINDOWS
00:47:03.859 AVAST engine scan C:\WINDOWS\system32
00:49:16.906 AVAST engine scan C:\WINDOWS\system32\drivers
00:49:37.046 AVAST engine scan C:\Documents and Settings\kristine
00:51:51.234 File: C:\Documents and Settings\kristine\Local Settings\Temp\34acf1a4-5753.tmp **INFECTED** Win32:Rootkit-gen [Rtk]
00:51:51.359 File: C:\Documents and Settings\kristine\Local Settings\Temp\35ad8ae8-5753.tmp **INFECTED** Win32:Rootkit-gen [Rtk]
00:51:51.531 File: C:\Documents and Settings\kristine\Local Settings\Temp\7ea807b2-5753.tmp **INFECTED** Win32:Rootkit-gen [Rtk]
00:52:29.156 AVAST engine scan C:\Documents and Settings\All Users
00:53:11.328 Scan finished successfully
00:53:19.890 Disk 0 MBR has been saved successfully to "C:\download\MBR.dat"
00:53:19.937 The log file has been saved successfully to "C:\download\aswMBR.txt"
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-07-25 18:19:57
-----------------------------
18:19:57.781 OS Version: Windows 5.1.2600 Service Pack 3
18:19:57.781 Number of processors: 2 586 0xF0D
18:19:57.781 ComputerName: HL111008 UserName: Kristine
18:19:58.359 Initialize success
18:21:56.500 AVAST engine defs: 12072500
18:22:17.109 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4
18:22:17.125 Disk 0 Vendor: ST3160815AS 4.CCC Size: 152627MB BusType: 3
18:22:17.140 Disk 0 MBR read successfully
18:22:17.156 Disk 0 MBR scan
18:22:17.203 Disk 0 Windows XP default MBR code
18:22:17.234 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 149069 MB offset 2048
18:22:17.250 Disk 0 Partition 2 00 12 Compaq diag MSDOS5.0 3556 MB offset 305295360
18:22:17.296 Disk 0 Partition 3 00 17 Hidd HPFS/NTFS NTFS 1 MB offset 312578048
18:22:17.312 Disk 0 Partition 3 **INFECTED** MBR:SST [Rtk]
18:22:17.343 Disk 0 scanning sectors +312581792
18:22:18.781 Disk 0 scanning C:\WINDOWS\system32\drivers
18:22:29.578 Service scanning
18:22:51.093 Modules scanning
18:22:53.859 Disk 0 trace - called modules:
18:22:53.937 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
18:22:53.968 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8734d908]
18:22:54.015 3 CLASSPNP.SYS[f774cfd7] -> nt!IofCallDriver -> \Device\00000065[0x873d3338]
18:22:54.046 5 ACPI.sys[f76c3620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-4[0x87350d98]
18:22:54.500 AVAST engine scan C:\WINDOWS
18:23:20.500 AVAST engine scan C:\WINDOWS\system32
18:25:40.468 AVAST engine scan C:\WINDOWS\system32\drivers
18:26:03.000 AVAST engine scan C:\Documents and Settings\kristine
18:28:19.109 File: C:\Documents and Settings\kristine\Local Settings\Temp\34acf1a4-5753.tmp **INFECTED** Win32:Rootkit-gen [Rtk]
18:28:19.234 File: C:\Documents and Settings\kristine\Local Settings\Temp\35ad8ae8-5753.tmp **INFECTED** Win32:Rootkit-gen [Rtk]
18:28:19.406 File: C:\Documents and Settings\kristine\Local Settings\Temp\7ea807b2-5753.tmp **INFECTED** Win32:Rootkit-gen [Rtk]
18:28:39.687 AVAST engine scan C:\Documents and Settings\All Users
18:29:24.468 Scan finished successfully
18:41:27.640 Disk 0 MBR has been saved successfully to "C:\download\MBR.dat"
18:41:27.687 The log file has been saved successfully to "C:\download\aswMBR.txt"