aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software Run date: 2012-04-07 16:19:18 ----------------------------- 16:19:18.656 OS Version: Windows 5.1.2600 Service Pack 3 16:19:18.656 Number of processors: 2 586 0x170A 16:19:18.656 ComputerName: SERVER UserName: Amir 16:19:22.593 Initialize success 16:19:43.656 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-18 16:19:43.656 Disk 0 Vendor: ST3808110AS 3.ADH Size: 76293MB BusType: 3 16:19:43.656 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T1L0-20 16:19:43.656 Disk 1 Vendor: WDC_WD10EARS-22Y5B1 80.00A80 Size: 953869MB BusType: 3 16:19:43.734 Disk 0 MBR read successfully 16:19:43.734 Disk 0 MBR scan 16:19:43.734 Disk 0 Windows XP default MBR code 16:19:43.750 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 76293 MB offset 63 16:19:43.765 Disk 0 scanning sectors +156248190 16:19:43.859 Disk 0 scanning C:\WINDOWS\system32\drivers 16:20:05.578 Service scanning 16:20:31.203 Modules scanning 16:20:54.171 Module: C:\WINDOWS\System32\DLA\DLADResN.SYS **SUSPICIOUS** 16:20:58.078 Disk 0 trace - called modules: 16:20:58.125 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys 16:20:58.125 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85f1aab8] 16:20:58.125 3 CLASSPNP.SYS[f7537fd7] -> nt!IofCallDriver -> \Device\0000006e[0x85f7c9e8] 16:20:58.125 5 ACPI.sys[f73ce620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-18[0x85f7b940] 16:20:58.125 Scan finished successfully 16:22:08.406 Disk 0 MBR has been saved successfully to "C:\MBR.dat" 16:22:08.406 The log file has been saved successfully to "C:\aswMBR.txt"