aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software Run date: 2014-03-31 04:30:23 ----------------------------- 04:30:23.143 OS Version: Windows x64 6.1.7601 Service Pack 1 04:30:23.143 Number of processors: 6 586 0xA00 04:30:23.144 ComputerName: DANA-PC UserName: Dana 04:30:28.729 Initialize success 04:30:32.201 AVAST engine defs: 14033100 04:30:38.419 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 04:30:38.421 Disk 0 Vendor: ST31000528AS CC44 Size: 953869MB BusType: 3 04:30:38.423 Device \Driver\atapi -> MajorFunction fffffa80082b70a8 04:30:38.447 Disk 0 MBR read successfully 04:30:38.450 Disk 0 MBR scan 04:30:38.453 Disk 0 MBR:Alureon-O [Rtk] 04:30:38.455 Disk 0 TDL4@MBR code has been found 04:30:38.458 Disk 0 MBR hidden 04:30:38.463 Disk 0 Partition 1 80 (A) 0B FAT32 NTFS 19024 MB offset 2048 04:30:38.480 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 934843 MB offset 38963200 04:30:38.483 Disk 0 MBR [TDL4] **ROOTKIT** 04:30:38.503 Disk 0 scanning C:\Windows\system32\drivers 04:30:51.828 Service scanning 04:31:02.166 Service MpKslb21f7fbe C:\Windows\Temp\MpKslb21f7fbe.sys **LOCKED** 32 04:31:14.062 Modules scanning 04:31:14.067 Disk 0 trace - called modules: 04:31:14.073 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys >>UNKNOWN [0xfffffa80082b70a8]<< 04:31:14.078 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80079fa060] 04:31:14.082 3 CLASSPNP.SYS[fffff8800184d43f] -> nt!IofCallDriver -> [0xfffffa80079229b0] 04:31:14.087 5 ACPI.sys[fffff88000f827a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa80079f6060] 04:31:14.092 \Driver\atapi[0xfffffa80082b3060] -> IRP_MJ_CREATE -> 0xfffffa80082b70a8 04:31:17.446 AVAST engine scan C:\Windows 04:31:19.944 AVAST engine scan C:\Windows\system32 04:36:01.310 AVAST engine scan C:\Windows\system32\drivers 04:36:18.817 AVAST engine scan C:\Users\Dana 05:34:09.795 AVAST engine scan C:\ProgramData 05:46:32.475 Scan finished successfully 18:37:06.071 Disk 0 MBR has been saved successfully to "C:\Users\Dana\Desktop\MBR.dat" 18:37:06.075 The log file has been saved successfully to "C:\Users\Dana\Desktop\aswMBR.txt"