Hello and thanks in advance for your support
On Tuesday 26-APR-2011 at 20:50 CST I received a pop-up notification from my then security application Microsoft Security Essentials that an item had been detected on a website I was on and that it was quarantined. The description of the item was EXPLOIT:Win32/Pdfjsc.oj.
I went merrily along my way thinking all was well. Of course it was not. MSE found ROOTKIT TDSS during a full scan and indicated that a re-boot would solve it. Doing this three or 4 times did not solve it. Malware Bytes does not find anything. TDSSKiller only gets to 80% then stops.
I removed MSE last night and installed the trial version of Avast then performed a full scan and a boot scan. Nothing was found, but the bad url message has appeared several times.
After reading this forum some I downloaded and ran aswMBR and the log shows these results. I did press the FIX MBR and rebooted, then ran aswMBR again and TDL4@MBR was found again
aswMBR version 0.9.5 Copyright(c) 2011 AVAST Software
Run date: 2011-04-28 17:35:33
17:35:33.093 OS Version: Windows 5.1.2600 Service Pack 3
17:35:33.093 Number of processors: 1 586 0x204
17:35:33.093 ComputerName: A(lastname) UserName:
17:35:33.781 Initialize success
17:35:38.093 Disk 0 (boot) \Device\Harddisk0\DR0 → \Device\Ide\IdeDeviceP0T0L0-3
17:35:38.093 Disk 0 Vendor: ST380021A 3.75 Size: 76319MB BusType: 3
17:35:38.093 Device \Driver\atapi → DriverStartIo 8a53933b
17:35:40.093 Disk 0 MBR read successfully
17:35:40.093 Disk 0 MBR scan
17:35:40.093 Disk 0 TDL4@MBR code has been found
17:35:40.093 Disk 0 MBR hidden
17:35:40.093 Disk 0 MBR [TDL4] ROOTKIT
17:35:40.093 Disk 0 trace - called modules:
17:35:40.093 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8a5394f0]<<
17:35:40.093 1 nt!IofCallDriver → \Device\Harddisk0\DR0[0x8a5c3ab8]
17:35:40.093 3 CLASSPNP.SYS[f7637fd7] → nt!IofCallDriver → [0x8a4d4190]
17:35:40.093 \Driver\atapi[0x8a5c1858] → IRP_MJ_CREATE → 0x8a5394f0
17:35:40.093 Scan finished successfully
17:40:08.968 Disk 0 fixing MBR
17:40:08.984 Infection fixed successfully - please reboot ASAP
17:40:15.671 Disk 0 MBR has been saved successfully to “C:\Documents and Settings\Ann (lastname)\Desktop\MBR.dat”
17:40:15.671 The log file has been saved successfully to “C:\Documents and Settings\Ann (lastname)\Desktop\aswMBR.txt”
The last time I rebooted it came up to the BSOD with an error message IRQL_NOT_LESS_OR_EQUAL. I rebooted and it is working.
What shall I do next?
Thanks,
EAGLEWI