aswMBR version 0.9.5.247 Copyright(c) 2011 AVAST Software Run date: 2011-05-02 12:30:20 ----------------------------- 12:30:20.182 OS Version: Windows 5.1.2600 Service Pack 3 12:30:20.182 Number of processors: 1 586 0x905 12:30:20.182 ComputerName: JOHNNY UserName: ja3756 12:30:21.424 Initialize success 12:30:26.872 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdePort0 12:30:26.882 Disk 0 Vendor: IC25N030ATMR04-0 MOAOAD0A Size: 28615MB BusType: 3 12:30:26.892 Device \Device\Ide\IdeDeviceP0T0L0-3 -> \??\IDE#DiskIC25N030ATMR04-0________________________MOAOAD0A#5&2b81b351&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} not found 12:30:26.902 Device \Driver\atapi -> DriverStartIo 832b327f 12:30:28.915 Disk 0 MBR read successfully 12:30:28.915 Disk 0 MBR scan 12:30:28.925 Disk 0 TDL4@MBR code has been found 12:30:28.935 Disk 0 Windows XP default MBR code found via API 12:30:28.945 Disk 0 MBR hidden 12:30:28.955 Disk 0 MBR [TDL4] **ROOTKIT** 12:30:28.965 Disk 0 trace - called modules: 12:30:28.975 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x832b3439]<< 12:30:28.995 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x83385ab8] 12:30:29.005 3 CLASSPNP.SYS[f8876fd7] -> nt!IofCallDriver -> [0x8332c538] 12:30:29.025 \Driver\atapi[0x83271388] -> IRP_MJ_CREATE -> 0x832b3439 12:30:29.045 Scan finished successfully 12:30:55.273 Disk 0 MBR has been saved successfully to "E:\MBR.dat" 12:30:55.303 The log file has been saved successfully to "E:\aswMBR.txt"