aswMBR version 0.9.5.256 Copyright(c) 2011 AVAST Software Run date: 2011-06-04 17:54:28 ----------------------------- 17:54:28.119 OS Version: Windows 6.0.6002 Service Pack 2 17:54:28.119 Number of processors: 2 586 0xF0B 17:54:28.119 ComputerName: HEGEMON-PC UserName: Hegemon 17:54:30.340 Initialize success 17:54:46.349 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 17:54:46.351 Disk 0 Vendor: Hitachi_HDT725040VLA360 V5COA7BA Size: 381554MB BusType: 3 17:54:48.353 Disk 0 MBR read successfully 17:54:48.355 Disk 0 MBR scan 17:54:48.357 Disk 0 TDL4@MBR code has been found 17:54:48.360 Disk 0 MBR hidden 17:54:48.362 Disk 0 MBR [TDL4] **ROOTKIT** 17:54:48.365 Disk 0 trace - called modules: 17:54:48.368 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x855d24d0]<< 17:54:48.371 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8552b4b0] 17:54:48.375 3 CLASSPNP.SYS[82fa28b3] -> nt!IofCallDriver -> [0x85406898] 17:54:48.379 5 acpi.sys[806976bc] -> nt!IofCallDriver -> [0x8540bb98] 17:54:48.394 \Driver\atapi[0x855b4b20] -> IRP_MJ_CREATE -> 0x855d24d0 17:54:48.409 Scan finished successfully 17:56:17.503 Disk 0 fixing MBR ... 17:56:27.508 Disk 0 MBR restored successfully 17:56:27.513 Verifying disinfection 17:56:41.557 Infection fixed successfully - please reboot ASAP 17:56:54.913 Disk 0 MBR has been saved successfully to "C:\Users\Hegemon\Desktop\MBR.dat" 17:56:54.918 The log file has been saved successfully to "C:\Users\Hegemon\Desktop\viruslog.txt"