so yea, seems this is happening to a lot of people. Im getting popups telling me my browser is trying to connect to a blocked site and im getting redirected to sites during searches.
I also noticed that it will try to connect to these sites with both IE and firefox…
aswMBR version 0.9.8.978 Copyright(c) 2011 AVAST Software
Run date: 2011-08-18 13:44:58
13:44:58.921 OS Version: Windows 5.1.2600 Service Pack 3
13:44:58.921 Number of processors: 2 586 0xF06
13:44:58.921 ComputerName: MIKE-1821C9AEAF UserName: mike
13:45:00.062 Initialize success
13:45:00.750 AVAST engine defs: 11081800
13:45:08.515 Disk 0 (boot) \Device\Harddisk0\DR0 → \Device\Ide\IAAStorageDevice-1
13:45:08.515 Disk 0 Vendor: ST325082 3.AD Size: 238418MB BusType: 3
13:45:08.531 Disk 0 MBR read successfully
13:45:08.531 Disk 0 MBR scan
13:45:08.531 Disk 0 MBR:Alureon-I [Rtk]
13:45:08.531 Disk 0 TDL4@MBR code has been found
13:45:08.531 Disk 0 Windows XP default MBR code found via API
13:45:08.531 Disk 0 MBR hidden
13:45:08.531 Disk 0 MBR [TDL4] ROOTKIT
13:45:08.531 Disk 0 trace - called modules:
13:45:08.531 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8a338f16]<<
13:45:08.531 1 nt!IofCallDriver → \Device\Harddisk0\DR0[0x8ac78030]
13:45:08.531 3 CLASSPNP.SYS[b80f8fd7] → nt!IofCallDriver → \Device\Ide\IAAStorageDevice-1[0x8ac7a030]
13:45:08.546 \Driver\iastor[0x8ac38030] → IRP_MJ_INTERNAL_DEVICE_CONTROL → 0x8a338f16
13:45:09.140 AVAST engine scan C:\WINDOWS
13:45:18.187 AVAST engine scan C:\WINDOWS\system32
13:46:33.546 AVAST engine scan C:\WINDOWS\system32\drivers
13:46:48.671 AVAST engine scan C:\Documents and Settings\mike
14:03:52.625 AVAST engine scan C:\Documents and Settings\All Users
14:04:42.015 Scan finished successfully
14:07:30.015 Disk 0 MBR has been saved successfully to “C:\Documents and Settings\mike\Desktop\MBR.dat”
14:07:30.015 The log file has been saved successfully to “C:\Documents and Settings\mike\Desktop\aswMBR.txt”
aswMBR version 0.9.8.978 Copyright(c) 2011 AVAST Software
Run date: 2011-08-18 15:25:57
15:25:57.156 OS Version: Windows 5.1.2600 Service Pack 3
15:25:57.156 Number of processors: 2 586 0xF06
15:25:57.156 ComputerName: MIKE-1821C9AEAF UserName: mike
15:25:58.312 Initialize success
15:25:58.515 AVAST engine defs: 11081800
15:26:01.109 Disk 0 (boot) \Device\Harddisk0\DR0 → \Device\Ide\IAAStorageDevice-1
15:26:01.109 Disk 0 Vendor: ST325082 3.AD Size: 238418MB BusType: 3
15:26:01.125 Disk 0 MBR read successfully
15:26:01.125 Disk 0 MBR scan
15:26:01.125 Disk 0 MBR:Alureon-I [Rtk]
15:26:01.125 Disk 0 TDL4@MBR code has been found
15:26:01.125 Disk 0 Windows XP default MBR code found via API
15:26:01.125 Disk 0 MBR hidden
15:26:01.125 Disk 0 MBR [TDL4] ROOTKIT
15:26:01.125 Disk 0 trace - called modules:
15:26:01.125 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8a335f16]<<
15:26:01.125 1 nt!IofCallDriver → \Device\Harddisk0\DR0[0x8ac74030]
15:26:01.125 3 CLASSPNP.SYS[b80e8fd7] → nt!IofCallDriver → \Device\Ide\IAAStorageDevice-1[0x8ac8a030]
15:26:01.125 \Driver\iastor[0x8ac40630] → IRP_MJ_INTERNAL_DEVICE_CONTROL → 0x8a335f16
15:26:01.609 AVAST engine scan C:\WINDOWS
15:26:27.484 AVAST engine scan C:\WINDOWS\system32
15:27:41.765 AVAST engine scan C:\WINDOWS\system32\drivers
15:27:51.734 AVAST engine scan C:\Documents and Settings\mike
15:46:16.578 AVAST engine scan C:\Documents and Settings\All Users
15:47:08.156 Scan finished successfully
15:47:47.171 Disk 0 MBR has been saved successfully to “C:\Documents and Settings\mike\My Documents\kotor editor\MBR.dat”
15:47:47.171 The log file has been saved successfully to “C:\Documents and Settings\mike\My Documents\kotor editor\aswMBR.txt”