Hi all,
Am at my wits end so really hoping someone can help…
Similar to a poster from back in July, Avast has detected a trojan that redirects all my google links to various sites including ebay and some dodgy anti-malware site and seems to be wayyy too clever for all the programs I’ve tried (tdss killer/hitman pro/avast bootscan/aswMBR/fixtdss). aswMBR finds it but only the FixMBR button is available after the scan - not the fix button. Avast seems to be constantly blocking malicious url’s too. I ran a full Avast scan plus boot-time scan but when complete it freezes so I can’t do anything with it. I also end up having to power off via the on/off button and reboot with a system restore as the mouse and keyboard are always locked at the windows login page. I’m using good old XP service pack 3 on a Dell Inspiron 9400 and the aswMBR log is below if that’s any help.
aswMBR version 0.9.8.986 Copyright(c) 2011 AVAST Software
Run date: 2011-11-15 01:08:11
01:08:11.480 OS Version: Windows 5.1.2600 Service Pack 3
01:08:11.480 Number of processors: 2 586 0xF06
01:08:11.480 ComputerName: STEVE UserName:
01:08:13.011 Initialize success
01:08:13.776 AVAST engine defs: 11111401
01:08:20.150 Disk 0 (boot) \Device\Harddisk0\DR0 → \Device\Ide\IdeDeviceP0T0L0-3
01:08:20.150 Disk 0 Vendor: Hitachi_HTS541612J9SA00 SBDOC74P Size: 114473MB BusType: 3
01:08:22.181 Disk 0 MBR read successfully
01:08:22.181 Disk 0 MBR scan
01:08:22.181 Disk 0 unknown MBR code
01:08:22.181 Disk 0 scanning sectors +234436545
01:08:22.275 Disk 0 scanning C:\WINDOWS\system32\drivers
01:08:27.836 File: C:\WINDOWS\system32\drivers\i8042prt.sys INFECTED Win32:Aluroot [Rtk]
01:08:36.022 Service scanning
01:08:38.600 Modules scanning
01:08:41.693 Module: C:\WINDOWS\system32\DRIVERS\i8042prt.sys SUSPICIOUS
01:08:50.629 Disk 0 trace - called modules:
01:08:50.660 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8ab5af10]<<
01:08:50.660 1 nt!IofCallDriver → \Device\Harddisk0\DR0[0x8ae83ab8]
01:08:50.660 3 CLASSPNP.SYS[ba0e8fd7] → nt!IofCallDriver → [0x8ac5a030]
01:08:50.660 \Driver\00001944[0x8aadc788] → IRP_MJ_CREATE → 0x8ab5af10
01:08:51.269 AVAST engine scan C:\WINDOWS
01:08:56.722 File: C:\WINDOWS\kb913800.exe INFECTED Win32:Malware-gen
01:09:00.846 AVAST engine scan C:\WINDOWS\system32
01:10:51.450 AVAST engine scan C:\WINDOWS\system32\drivers
01:10:58.527 File: C:\WINDOWS\system32\drivers\i8042prt.sys INFECTED Win32:Aluroot [Rtk]
01:11:10.962 AVAST engine scan C:\Documents and Settings\Steve Rix
01:47:06.732 AVAST engine scan C:\Documents and Settings\All Users
01:51:14.982 Scan finished successfully
01:51:50.467 Disk 0 MBR has been saved successfully to “C:\Documents and Settings\Steve\Desktop\MBR.dat”
01:51:50.482 The log file has been saved successfully to “C:\Documents and Settings\Steve\Desktop\aswMBR.txt”