aswMBR version 0.9.8.986 Copyright(c) 2011 AVAST Software Run date: 2011-09-05 16:52:35 ----------------------------- 16:52:35.250 OS Version: Windows 5.1.2600 Service Pack 2 16:52:35.265 Number of processors: 1 586 0x602 16:52:35.265 ComputerName: JOHN-8AA4DEDB42 UserName: User 16:52:47.578 Initialize success 16:53:01.953 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 16:53:01.953 Disk 0 Vendor: ST3802110A 3.AAE Size: 76319MB BusType: 3 16:53:04.031 Disk 0 MBR read successfully 16:53:04.031 Disk 0 MBR scan 16:53:04.031 Disk 0 TDL4@MBR code has been found 16:53:04.046 Disk 0 Windows XP default MBR code found via API 16:53:04.046 Disk 0 MBR hidden 16:53:04.046 Disk 0 MBR [TDL4] **ROOTKIT** 16:53:04.046 Disk 0 trace - called modules: 16:53:04.046 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x86b7ff16]<< 16:53:04.062 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86b8eab8] 16:53:04.062 3 CLASSPNP.SYS[f76d005b] -> nt!IofCallDriver -> \Device\00000058[0x86b90650] 16:53:04.062 5 ACPI.sys[f7646620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-4[0x86b94940] 16:53:04.062 \Driver\atapi[0x86b49918] -> IRP_MJ_INTERNAL_DEVICE_CONTROL -> 0x86b7ff16 16:53:04.078 Scan finished successfully 16:53:11.375 Disk 0 MBR read successfully 16:53:11.390 Disk 0 TDL4@MBR code has been found 16:53:11.421 Disk 0 fixing MBR ... 16:53:21.437 Disk 0 MBR restored successfully 16:53:21.437 Verifying disinfection 16:53:33.578 Infection fixed successfully - please reboot ASAP 16:54:10.437 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\User\Desktop\MBR.dat" 16:54:10.453 The log file has been saved successfully to "C:\Documents and Settings\User\Desktop\aswMBRfixed.txt"