h8mal
2011-03-23, 22:44
Hi, I have click.giftload and Fraudload that redirect me to ads via Google links.
Hope I'm not getting ahead of myself, my aswmbr and gmer log are below and in the next post.
aswMBR version 0.9.4 Copyright(c) 2011 AVAST Software
Run date: 2011-03-23 16:43:36
-----------------------------
16:43:36.859 OS Version: Windows 5.1.2600 Service Pack 3
16:43:36.859 Number of processors: 2 586 0x209
16:43:36.859 ComputerName: OWNER-53AB28ACA UserName: Owner
16:43:38.796 Initialize success
16:43:41.718 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdePort0
16:43:41.734 Disk 0 Vendor: ST380215A 3.AAD Size: 76319MB BusType: 3
16:43:41.734 Device \Device\Ide\IdeDeviceP0T0L0-3 -> \??\IDE#DiskST380215A_______________________________3.AAD___#5&13a60baf&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} not found
16:43:41.734 Device \Driver\atapi -> DriverStartIo 8672027f
16:43:41.750 Disk 0 MBR read successfully
16:43:41.750 Disk 0 MBR scan
16:43:41.750 Disk 0 TDL4@MBR code has been found
16:43:41.750 Disk 0 MBR hidden
16:43:41.750 Disk 0 MBR [TDL4] **ROOTKIT**
16:43:41.750 Disk 0 trace - called modules:
16:43:41.750 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x86720439]<<
16:43:41.750 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86785ab8]
16:43:41.750 3 CLASSPNP.SYS[f788ffd7] -> nt!IofCallDriver -> \Device\00000059[0x86741f18]
16:43:41.750 5 ACPI.sys[f77e6620] -> nt!IofCallDriver -> [0x8678bd98]
16:43:41.765 \Driver\atapi[0x86761b10] -> IRP_MJ_CREATE -> 0x86720439
16:43:41.765 Scan finished successfully
Hope I'm not getting ahead of myself, my aswmbr and gmer log are below and in the next post.
aswMBR version 0.9.4 Copyright(c) 2011 AVAST Software
Run date: 2011-03-23 16:43:36
-----------------------------
16:43:36.859 OS Version: Windows 5.1.2600 Service Pack 3
16:43:36.859 Number of processors: 2 586 0x209
16:43:36.859 ComputerName: OWNER-53AB28ACA UserName: Owner
16:43:38.796 Initialize success
16:43:41.718 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdePort0
16:43:41.734 Disk 0 Vendor: ST380215A 3.AAD Size: 76319MB BusType: 3
16:43:41.734 Device \Device\Ide\IdeDeviceP0T0L0-3 -> \??\IDE#DiskST380215A_______________________________3.AAD___#5&13a60baf&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} not found
16:43:41.734 Device \Driver\atapi -> DriverStartIo 8672027f
16:43:41.750 Disk 0 MBR read successfully
16:43:41.750 Disk 0 MBR scan
16:43:41.750 Disk 0 TDL4@MBR code has been found
16:43:41.750 Disk 0 MBR hidden
16:43:41.750 Disk 0 MBR [TDL4] **ROOTKIT**
16:43:41.750 Disk 0 trace - called modules:
16:43:41.750 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x86720439]<<
16:43:41.750 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86785ab8]
16:43:41.750 3 CLASSPNP.SYS[f788ffd7] -> nt!IofCallDriver -> \Device\00000059[0x86741f18]
16:43:41.750 5 ACPI.sys[f77e6620] -> nt!IofCallDriver -> [0x8678bd98]
16:43:41.765 \Driver\atapi[0x86761b10] -> IRP_MJ_CREATE -> 0x86720439
16:43:41.765 Scan finished successfully