aswMBR version 0.9.9.1297 Copyright© 2011 AVAST Software
Run date: 2012-01-18 14:24:06
-----------------------------
14:24:06.046 OS Version: Windows x64 6.1.7601 Service Pack 1
14:24:06.046 Number of processors: 4 586 0x2502
14:24:06.046 ComputerName: AMY-LAPTOP UserName: Amy
14:24:12.255 Initialize success
14:25:13.169 AVAST engine defs: 12011801
14:25:16.325 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
14:25:16.327 Disk 0 Vendor: SAMSUNG_HM500JI 2AC101C4 Size: 476940MB BusType: 11
14:25:16.349 Device \Driver\atapi -> MajorFunction fffffa8004f785c4
14:25:16.352 Disk 0 MBR read successfully
14:25:16.355 Disk 0 MBR scan
14:25:16.358 Disk 0 MBR:Pihar-C [Rtk]
14:25:16.361 Disk 0 TDL4@MBR code has been found
14:25:16.364 Disk 0 Windows 7 default MBR code found via API
14:25:16.367 Disk 0 MBR hidden
14:25:16.382 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 100 MB offset 2048
14:25:16.394 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 10000 MB offset 206848
14:25:16.421 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 60000 MB offset 20686848
14:25:16.426 Disk 0 Partition - 00 0F Extended LBA 406838 MB offset 143566848
14:25:16.459 Disk 0 Partition 4 00 07 HPFS/NTFS NTFS 406837 MB offset 143568896
14:25:16.476 Disk 0 MBR [TDL4] **ROOTKIT**
14:25:16.481 Disk 0 trace - called modules:
14:25:16.486 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0xfffffa8004f785c4]<<
14:25:16.491 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004b36060]
14:25:16.495 3 CLASSPNP.SYS[fffff8800165a43f] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa80048cc680]
14:25:16.500 \Driver\atapi[0xfffffa8004f06a70] -> IRP_MJ_CREATE -> 0xfffffa8004f785c4
14:25:18.699 AVAST engine scan C:\Windows
14:25:20.499 AVAST engine scan C:\Windows\system32
14:27:00.394 AVAST engine scan C:\Windows\system32\drivers
14:27:13.086 AVAST engine scan C:\Users\Amy
14:28:56.125 Disk 0 MBR has been saved successfully to "C:\Users\Amy\Desktop\MBR.dat"
14:28:56.125 The log file has been saved successfully to "C:\Users\Amy\Desktop\aswMBR.txt"
aswMBR version 0.9.9.1297 Copyright© 2011 AVAST Software
Run date: 2012-01-23 10:00:15
-----------------------------
10:00:15.262 OS Version: Windows x64 6.1.7601 Service Pack 1
10:00:15.262 Number of processors: 4 586 0x2502
10:00:15.262 ComputerName: AMY-LAPTOP UserName: Amy
10:00:15.699 Initialize success
10:00:59.757 AVAST engine defs: 12012300
10:01:29.038 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
10:01:29.038 Disk 0 Vendor: SAMSUNG_HM500JI 2AC101C4 Size: 476940MB BusType: 11
10:01:29.054 Disk 0 MBR read successfully
10:01:29.054 Disk 0 MBR scan
10:01:29.070 Disk 0 Windows 7 default MBR code
10:01:29.070 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 100 MB offset 2048
10:01:29.085 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 10000 MB offset 206848
10:01:29.101 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 60000 MB offset 20686848
10:01:29.116 Disk 0 Partition - 00 0F Extended LBA 406838 MB offset 143566848
10:01:29.148 Disk 0 Partition 4 00 07 HPFS/NTFS NTFS 406837 MB offset 143568896
10:01:29.148 Service scanning
10:01:30.458 Modules scanning
10:01:30.458 Disk 0 trace - called modules:
10:01:30.474 ntoskrnl.exe CLASSPNP.SYS disk.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
10:01:30.489 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004bad060]
10:01:30.489 3 CLASSPNP.SYS[fffff8800197843f] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa80048e8060]
10:01:31.254 AVAST engine scan C:\Windows
10:01:33.266 AVAST engine scan C:\Windows\system32
10:03:11.967 AVAST engine scan C:\Windows\system32\drivers
10:03:23.465 AVAST engine scan C:\Users\Amy
10:14:54.374 AVAST engine scan C:\ProgramData
10:17:02.887 Scan finished successfully
10:26:34.644 Disk 0 MBR has been saved successfully to "C:\Users\Amy\Desktop\MBR.dat"
10:26:34.644 The log file has been saved successfully to "C:\Users\Amy\Desktop\aswMBR.txt"