aswMBR version 0.9.4 Copyright(c) 2011 AVAST Software Run date: 2011-04-09 16:47:42 ----------------------------- 16:47:42.328 OS Version: Windows 5.1.2600 Service Pack 2 16:47:42.328 Number of processors: 4 586 0xF0B 16:47:42.328 ComputerName: JEFFDESK UserName: Jeff 16:47:47.718 Initialize success 16:48:01.437 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-6 16:48:01.437 Disk 0 Vendor: WDC_WD1600AAJB-00PVA0 00.07H00 Size: 152627MB BusType: 3 16:48:01.437 Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdePort2 16:48:01.437 Disk 1 Vendor: WDC_WD1600JS-00NCB1 10.02E02 Size: 152627MB BusType: 3 16:48:01.437 Disk 2 \Device\Harddisk2\DR2 -> \Device\Ide\IdeDeviceP4T0L0-26 16:48:01.437 Disk 2 Vendor: ST3250823AS 3.06 Size: 238475MB BusType: 3 16:48:01.437 Device \Device\Ide\IdeDeviceP2T0L0-19 -> \??\IDE#DiskWDC_WD1600JS-00NCB1_____________________10.02E02#5&18fda9ce&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} not found 16:48:01.437 Device \Driver\atapi -> DriverStartIo 8a41caea 16:48:03.437 Disk 1 MBR read successfully 16:48:03.453 Disk 1 MBR scan 16:48:05.453 Disk 1 scanning sectors +312576705 16:48:05.468 Disk 1 scanning C:\WINDOWS\system32\drivers 16:48:09.968 File C:\WINDOWS\system32\drivers\sshrmd.sys TDL3 **ROOTKIT** 16:48:09.968 Disk 1 trace - called modules: 16:48:09.984 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x886c5ad8]<< 16:48:09.984 1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0x8a411ab8] 16:48:09.984 Scan finished successfully