Hello,
New tool from Avast (by Gmer): http://public.avast.com/~gmerek/aswMBR.htm
It seems to work (tested on TDL4 0.03),
first time after reboot TDL is always present
second time, after reboot TDL is dead
New tool from Avast (by Gmer): http://public.avast.com/~gmerek/aswMBR.htm
It seems to work (tested on TDL4 0.03),
first time after reboot TDL is always present
second time, after reboot TDL is dead
aswMBR version 0.9.3 Copyright(c) 2011 avast! Software
Run date: 2011-02-16 19:16:56
-----------------------------
20:16:56.921 OS Version: Windows 5.1.2600 Service Pack 3
20:16:56.921 Number of processors: 1 586 0x80A
20:16:56.921 ComputerName: EEE-7DAE6D62252 UserName: XXXXX
20:16:57.203 Initialize success
20:16:58.468 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdePort0
20:16:58.484 Disk 0 Vendor: ST320414A 3.25 Size: 19092MB BusType: 3
20:16:58.500 Disk 1 \Device\Harddisk1\DR2 -> \Device\00000053
20:16:58.500 Disk 1 Vendor: PNY_____ 8.02 Size: 15283MB BusType: 7
20:16:58.500 Device \Device\Ide\IdeDeviceP0T0L0-3 -> \??\IDE#DiskST320414A_______________________________3.25____#453331434a33325a202020202020202020202020#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} not found
20:16:58.500 Device \Driver\atapi -> DriverStartIo 81abf422
20:17:00.500 Disk 0 MBR read successfully
20:17:00.500 Disk 0 MBR scan
20:17:00.500 Disk 0 TDL4@MBR code has been found
20:17:00.500 Disk 0 MBR hidden
20:17:00.500 Disk 0 MBR [TDL4] **ROOTKIT**
20:17:00.500 Disk 0 trace - called modules:
20:17:00.500 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x81abf5dc]<<
20:17:00.500 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x81b8cab8]
20:17:01.031 3 CLASSPNP.SYS[f8511fd7] -> nt!IofCallDriver -> \Device\0000004f[0x81afbef8]
20:17:01.031 5 ACPI.sys[f8487620] -> nt!IofCallDriver -> [0x81b134e0]
20:17:01.046 \Driver\atapi[0x81b258f8] -> IRP_MJ_CREATE -> 0x81abf5dc
20:17:01.062 Scan finished successfully
20:17:14.796 Disk 0 Windows 501 MBR fixed successfully
20:17:18.359 Disk 0 fixing MBR
20:17:28.375 Disk 0 MBR restored successfully
20:17:28.375 Infection fixed successfully - please reboot ASAP