aswMBR version 0.9.5.256 Copyright(c) 2011 AVAST Software Run date: 2011-05-15 11:07:50 ----------------------------- 11:07:50.015 OS Version: Windows 5.1.2600 Service Pack 2 11:07:50.015 Number of processors: 2 586 0xF0A 11:07:50.015 ComputerName: D4BM8QD1 UserName: 11:08:08.281 Initialize success 11:08:11.203 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e 11:08:11.203 Disk 0 Vendor: TOSHIBA_MK6037GSX DL340D Size: 57231MB BusType: 3 11:08:11.203 Device \Driver\atapi -> DriverStartIo 8a61331b 11:08:13.234 Disk 0 MBR read successfully 11:08:13.234 Disk 0 MBR scan 11:08:13.234 Disk 0 TDL4@MBR code has been found 11:08:13.234 Disk 0 Windows XP default MBR code found via API 11:08:13.234 Disk 0 MBR hidden 11:08:13.234 Disk 0 MBR [TDL4] **ROOTKIT** 11:08:13.234 Disk 0 trace - called modules: 11:08:13.234 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8a6134d0]<< 11:08:13.234 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a6d3ab8] 11:08:13.234 3 CLASSPNP.SYS[ba0e905b] -> nt!IofCallDriver -> [0x8a685578] 11:08:13.234 \Driver\atapi[0x8a6ff9b8] -> IRP_MJ_CREATE -> 0x8a6134d0 11:08:13.234 Scan finished successfully 11:09:20.750 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Administrator\Desktop\MBR.dat" 11:09:20.765 The log file has been saved successfully to "C:\Documents and Settings\Administrator\Desktop\aswMBR.txt"