aswMBR version 0.9.5.256 Copyright(c) 2011 AVAST Software Run date: 2011-05-14 17:13:10 ----------------------------- 17:13:10.312 OS Version: Windows 5.1.2600 Service Pack 3 17:13:10.312 Number of processors: 1 586 0x207 17:13:10.312 ComputerName: ADAM UserName: 17:13:13.859 Initialize success 17:13:21.640 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 17:13:21.640 Disk 0 Vendor: ST380020A 3.39 Size: 76319MB BusType: 3 17:13:21.640 Device \Driver\atapi -> DriverStartIo 8a70f31b 17:13:21.640 Disk 0 MBR read successfully 17:13:21.640 Disk 0 MBR scan 17:13:21.640 Disk 0 TDL4@MBR code has been found 17:13:21.640 Disk 0 Windows XP default MBR code found via API 17:13:21.640 Disk 0 MBR hidden 17:13:21.640 Disk 0 MBR [TDL4] **ROOTKIT** 17:13:21.640 Disk 0 trace - called modules: 17:13:21.640 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8a70f4d0]<< 17:13:21.640 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a6e7ab8] 17:13:21.640 3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> \Device\0000005a[0x8a6edf18] 17:13:21.656 5 ACPI.sys[f75ae620] -> nt!IofCallDriver -> [0x8a723d98] 17:13:22.000 \Driver\atapi[0x8a7482b8] -> IRP_MJ_CREATE -> 0x8a70f4d0 17:13:22.000 Scan finished successfully 17:13:49.718 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Adam Gilbert\Desktop\MBR.dat" 17:13:49.734 The log file has been saved successfully to "C:\Documents and Settings\Adam Gilbert\Desktop\aswMBR.txt"