Thanks for your prompt reply. Here we go:
TDSSKiller results:
20:51:00.0093 5120 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
20:51:00.0093 5120 perc2hib - ok
20:51:00.0171 5120 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
20:51:00.0171 5120 PptpMiniport - ok
20:51:00.0203 5120 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
20:51:00.0203 5120 PSched - ok
20:51:00.0218 5120 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
20:51:00.0218 5120 Ptilink - ok
20:51:00.0265 5120 PxHelp20 (7c81ae3c9b82ba2da437ed4d31bc56cf) C:\WINDOWS\system32\Drivers\PxHelp20.sys
20:51:00.0265 5120 PxHelp20 - ok
20:51:00.0281 5120 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
20:51:00.0296 5120 ql1080 - ok
20:51:00.0296 5120 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
20:51:00.0296 5120 Ql10wnt - ok
20:51:00.0359 5120 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
20:51:00.0359 5120 ql12160 - ok
20:51:00.0390 5120 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
20:51:00.0390 5120 ql1240 - ok
20:51:00.0406 5120 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
20:51:00.0406 5120 ql1280 - ok
20:51:00.0421 5120 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
20:51:00.0421 5120 RasAcd - ok
20:51:00.0468 5120 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
20:51:00.0484 5120 Rasl2tp - ok
20:51:00.0500 5120 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
20:51:00.0500 5120 RasPppoe - ok
20:51:00.0500 5120 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
20:51:00.0500 5120 Raspti - ok
20:51:00.0531 5120 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
20:51:00.0531 5120 Rdbss - ok
20:51:00.0562 5120 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
20:51:00.0562 5120 RDPCDD - ok
20:51:00.0609 5120 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
20:51:00.0609 5120 rdpdr - ok
20:51:00.0656 5120 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
20:51:00.0656 5120 RDPWD - ok
20:51:00.0671 5120 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
20:51:00.0671 5120 redbook - ok
20:51:00.0734 5120 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
20:51:00.0750 5120 Secdrv - ok
20:51:00.0796 5120 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
20:51:00.0796 5120 serenum - ok
20:51:00.0828 5120 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
20:51:00.0828 5120 Serial - ok
20:51:00.0859 5120 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
20:51:00.0859 5120 Sfloppy - ok
20:51:00.0875 5120 Simbad - ok
20:51:00.0921 5120 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys
20:51:00.0937 5120 sisagp - ok
20:51:00.0968 5120 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
20:51:00.0968 5120 SLIP - ok
20:51:01.0046 5120 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
20:51:01.0046 5120 Sparrow - ok
20:51:01.0062 5120 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
20:51:01.0062 5120 splitter - ok
20:51:01.0093 5120 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
20:51:01.0109 5120 sr - ok
20:51:01.0156 5120 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
20:51:01.0156 5120 Srv - ok
20:51:01.0250 5120 STHDA (797fcc1d859b203958e915bb82528da9) C:\WINDOWS\system32\drivers\sthda.sys
20:51:01.0281 5120 STHDA - ok
20:51:01.0328 5120 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
20:51:01.0328 5120 streamip - ok
20:51:01.0375 5120 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
20:51:01.0375 5120 swenum - ok
20:51:01.0390 5120 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
20:51:01.0390 5120 swmidi - ok
20:51:01.0437 5120 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
20:51:01.0437 5120 symc810 - ok
20:51:01.0453 5120 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
20:51:01.0453 5120 symc8xx - ok
20:51:01.0468 5120 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
20:51:01.0468 5120 sym_hi - ok
20:51:01.0484 5120 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
20:51:01.0484 5120 sym_u3 - ok
20:51:01.0546 5120 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
20:51:01.0546 5120 sysaudio - ok
20:51:01.0593 5120 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
20:51:01.0609 5120 Tcpip - ok
20:51:01.0625 5120 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
20:51:01.0625 5120 TDPIPE - ok
20:51:01.0656 5120 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
20:51:01.0671 5120 TDTCP - ok
20:51:01.0687 5120 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
20:51:01.0687 5120 TermDD - ok
20:51:01.0718 5120 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
20:51:01.0718 5120 TosIde - ok
20:51:01.0750 5120 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
20:51:01.0750 5120 Udfs - ok
20:51:01.0781 5120 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
20:51:01.0781 5120 ultra - ok
20:51:01.0843 5120 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
20:51:01.0843 5120 Update - ok
20:51:01.0906 5120 USBAAPL (83cafcb53201bbac04d822f32438e244) C:\WINDOWS\system32\Drivers\usbaapl.sys
20:51:01.0906 5120 USBAAPL - ok
20:51:01.0937 5120 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
20:51:01.0953 5120 usbaudio - ok
20:51:01.0953 5120 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
20:51:01.0968 5120 usbccgp - ok
20:51:02.0000 5120 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
20:51:02.0000 5120 usbehci - ok
20:51:02.0031 5120 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
20:51:02.0031 5120 usbhub - ok
20:51:02.0093 5120 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
20:51:02.0093 5120 usbprint - ok
20:51:02.0109 5120 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
20:51:02.0109 5120 usbscan - ok
20:51:02.0125 5120 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
20:51:02.0125 5120 USBSTOR - ok
20:51:02.0156 5120 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
20:51:02.0156 5120 usbuhci - ok
20:51:02.0171 5120 USB_RNDIS_XP (bee793d4a059caea55d6ac20e19b3a8f) C:\WINDOWS\system32\DRIVERS\usb8023.sys
20:51:02.0171 5120 USB_RNDIS_XP - ok
20:51:02.0187 5120 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
20:51:02.0187 5120 VgaSave - ok
20:51:02.0234 5120 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys
20:51:02.0234 5120 viaagp - ok
20:51:02.0281 5120 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
20:51:02.0281 5120 ViaIde - ok
20:51:02.0312 5120 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
20:51:02.0328 5120 VolSnap - ok
20:51:02.0406 5120 VX1000 (f4fab0b9d43a65f79fc838c94006f643) C:\WINDOWS\system32\DRIVERS\VX1000.sys
20:51:02.0468 5120 VX1000 - ok
20:51:02.0500 5120 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
20:51:02.0500 5120 Wanarp - ok
20:51:02.0546 5120 Wdf01000 (fd47474bd21794508af449d9d91af6e6) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
20:51:02.0578 5120 Wdf01000 - ok
20:51:02.0593 5120 WDICA - ok
20:51:02.0625 5120 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
20:51:02.0640 5120 wdmaud - ok
20:51:02.0718 5120 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
20:51:02.0734 5120 WpdUsb - ok
20:51:02.0765 5120 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
20:51:02.0765 5120 WSTCODEC - ok
20:51:02.0796 5120 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
20:51:02.0796 5120 WudfPf - ok
20:51:02.0828 5120 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
20:51:02.0828 5120 WudfRd - ok
20:51:02.0875 5120 MBR (0x1B8) (4bc21aabb8ea83c34000756722b7398b) \Device\Harddisk0\DR0
20:51:02.0906 5120 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - infected
20:51:02.0906 5120 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.b (0)
20:51:02.0937 5120 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
20:51:02.0937 5120 \Device\Harddisk0\DR0 - detected TDSS File System (1)
20:51:02.0968 5120 Boot (0x1200) (807fe6e9766c2484ac77edf8f054947b) \Device\Harddisk0\DR0\Partition0
20:51:02.0968 5120 \Device\Harddisk0\DR0\Partition0 - ok
20:51:02.0968 5120 ============================================================
20:51:02.0968 5120 Scan finished
20:51:02.0968 5120 ============================================================
20:51:02.0984 5112 Detected object count: 2
20:51:02.0984 5112 Actual detected object count: 2
GMER results:
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2012-02-21 21:29:23
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\iaStor0 ST316081 rev.3.AD
Running: jlf2uw5c.exe; Driver: C:\DOCUME~1\Aron\LOCALS~1\Temp\pxtdypog.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0x99346F3C]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateProcess [0x99346FE4]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0x99347080]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0x9934711C]
---- Kernel code sections - GMER 1.0.15 ----
? system32\drivers\58534017.sys The system cannot find the path specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\System32\svchost.exe[1352] kernel32.dll!WriteFile 7C810E27 5 Bytes JMP 0079000C
.text C:\WINDOWS\System32\svchost.exe[1352] USER32.dll!GetCursorPos 7E42974E 5 Bytes JMP 0087000A
.text C:\WINDOWS\System32\svchost.exe[1352] USER32.dll!WindowFromPoint 7E429766 5 Bytes JMP 0088000A
.text C:\WINDOWS\System32\svchost.exe[1352] USER32.dll!GetForegroundWindow 7E429823 5 Bytes JMP 0089000A
.text C:\WINDOWS\System32\svchost.exe[1352] ole32.dll!CoCreateInstance 774FF1BC 5 Bytes JMP 00FE000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[4480] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 01855B60 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[4836] USER32.dll!GetWindowInfo 7E42C49C 5 Bytes JMP 10450924 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[4836] USER32.dll!TrackPopupMenu 7E46531E 5 Bytes JMP 10450ECF C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \Driver\09031599 \Device\KLMD16012012_207010 58534017.sys
Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
Device 979E2D20
AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 TDL4@MBR code has been found <-- ROOTKIT !!!
Disk \Device\Harddisk0\DR0 sector 00: rootkit-like behavior
---- EOF - GMER 1.0.15 ----
aswMBR results:
9.1649 Copyright© 2011 AVAST Software
Run date: 2012-02-21 21:30:40
-----------------------------
21:30:40.281 OS Version: Windows 5.1.2600 Service Pack 3
21:30:40.281 Number of processors: 2 586 0xF02
21:30:40.296 ComputerName: MAIN UserName: Aron
21:30:44.593 Initialize success
21:35:14.875 AVAST engine defs: 12022101
21:35:58.140 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
21:35:58.140 Disk 0 Vendor: ST316081 3.AD Size: 152587MB BusType: 3
21:35:58.156 Disk 0 MBR read successfully
21:35:58.171 Disk 0 MBR scan
21:35:58.234 Disk 0 MBR:Pihar-C [Rtk]
21:35:58.234 Disk 0 TDL4@MBR code has been found
21:35:58.234 Disk 0 MBR hidden
21:35:58.250 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63
21:35:58.265 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 149464 MB offset 80325
21:35:58.296 Disk 0 Partition 3 00 DB CP/M / CTOS Dell 8.0 3074 MB offset 306198900
21:35:58.296 Disk 0 MBR [TDL4] **ROOTKIT**
21:35:58.312 Disk 0 trace - called modules:
21:35:58.312 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8646449f]<<
21:35:58.343 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x87161030]
21:35:58.343 3 CLASSPNP.SYS[f7530fd7] -> nt!IofCallDriver -> [0x85f76030]
21:35:58.343 \Driver\iaStor[0x86487428] -> IRP_MJ_CREATE -> 0x8646449f
21:35:59.375 AVAST engine scan C:\WINDOWS
21:36:23.640 AVAST engine scan C:\WINDOWS\system32
21:39:27.953 AVAST engine scan C:\WINDOWS\system32\drivers
21:39:40.421 AVAST engine scan C:\Documents and Settings\Aron
21:41:54.671 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Aron\Desktop\MBR.dat"
21:41:54.687 The log file has been saved successfully to "C:\Documents and Settings\Aron\Desktop\aswMBR.txt"