aswMBR version 0.9.7.675 Copyright(c) 2011 AVAST Software Run date: 2011-06-22 20:13:25 ----------------------------- 20:13:25.453 OS Version: Windows 5.1.2600 Service Pack 3 20:13:25.453 Number of processors: 1 586 0x209 20:13:25.453 ComputerName: BOBNDEB-D81BC89 UserName: Deb 20:13:26.890 Initialize success 20:13:28.234 AVAST engine defs: 11062201 20:14:07.578 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 20:14:07.578 Disk 0 Vendor: WDC_WD400EB-75CPF0 06.04G06 Size: 38166MB BusType: 3 20:14:07.578 Device \Driver\atapi -> DriverStartIo 8233931b 20:14:09.578 Disk 0 MBR read successfully 20:14:09.578 Disk 0 MBR scan 20:14:09.593 Disk 0 MBR:Alureon-G [Rtk] 20:14:09.593 Disk 0 TDL4@MBR code has been found 20:14:09.593 Disk 0 Windows XP default MBR code found via API 20:14:09.593 Disk 0 MBR hidden 20:14:09.593 Disk 0 MBR [TDL4] **ROOTKIT** 20:14:09.593 Disk 0 trace - called modules: 20:14:09.593 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x823394d0]<< 20:14:09.593 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8239aab8] 20:14:09.593 3 CLASSPNP.SYS[f8578fd7] -> nt!IofCallDriver -> [0x823e1148] 20:14:09.593 \Driver\atapi[0x8238cb60] -> IRP_MJ_CREATE -> 0x823394d0 20:14:09.859 AVAST engine scan C:\WINDOWS 20:23:31.812 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Deb\Desktop\MBR.dat" 20:23:31.812 The log file has been saved successfully to "C:\Documents and Settings\Deb\Desktop\aswMBR.txt"