aswMBR version 0.9.9.1532 Copyright(c) 2011 AVAST Software Run date: 2012-02-04 11:57:35 ----------------------------- 11:57:35.707 OS Version: Windows x64 6.1.7601 Service Pack 1 11:57:35.707 Number of processors: 6 586 0xA00 11:57:35.708 ComputerName: AEGIS UserName: DLee 11:57:36.938 Initialize success 11:57:46.596 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 11:57:46.599 Disk 0 Vendor: WDC_WD1002FAEX-00Z3A0 05.01D05 Size: 953869MB BusType: 3 11:57:46.603 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP0T1L0-2 11:57:46.607 Disk 1 Vendor: C300-CTFDDAC064MAG 0006 Size: 61057MB BusType: 3 11:57:46.611 Device \Driver\atapi -> MajorFunction fffffa800e6845c4 11:57:46.617 Disk 0 MBR read successfully 11:57:46.621 Disk 0 MBR scan 11:57:46.626 Disk 0 TDL4@MBR code has been found 11:57:46.632 Disk 0 Windows 7 default MBR code found via API 11:57:46.636 Disk 0 MBR hidden 11:57:46.638 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 476827 MB offset 2048 11:57:46.656 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 477039 MB offset 976543744 11:57:46.658 Disk 0 MBR [TDL4] **ROOTKIT** 11:57:46.661 Disk 0 trace - called modules: 11:57:46.665 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys >>UNKNOWN [0xfffffa800e6845c4]<< 11:57:46.668 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800cb91790] 11:57:46.671 3 CLASSPNP.SYS[fffff88001bc543f] -> nt!IofCallDriver -> [0xfffffa800d9a09b0] 11:57:46.676 5 ACPI.sys[fffff880011977a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa800da62680] 11:57:46.679 \Driver\atapi[0xfffffa800e633060] -> IRP_MJ_CREATE -> 0xfffffa800e6845c4 11:57:46.683 Scan finished successfully 11:57:55.371 Disk 0 MBR has been saved successfully to "C:\Users\DLee\Desktop\MBR.dat" 11:57:55.373 The log file has been saved successfully to "C:\Users\DLee\Desktop\aswMBR.txt"