aswMBR version 0.9.8.986 Copyright(c) 2011 AVAST Software Run date: 2011-12-12 14:42:00 ----------------------------- 14:42:00.986 OS Version: Windows x64 6.1.7600 14:42:00.986 Number of processors: 8 586 0x1E05 14:42:00.987 ComputerName: HEINTJE-PC UserName: Heintje 14:42:02.691 Initialize success 14:45:30.509 AVAST engine defs: 11121201 14:45:58.922 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 14:45:58.925 Disk 0 Vendor: ST3500418AS CC45 Size: 476940MB BusType: 3 14:45:58.936 Disk 0 MBR read successfully 14:45:58.939 Disk 0 MBR scan 14:45:58.955 Disk 0 TDL4@MBR code has been found 14:45:58.956 Disk 0 MBR hidden 14:45:58.959 Disk 0 MBR [TDL4] **ROOTKIT** 14:45:58.961 Disk 0 trace - called modules: 14:45:58.972 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys >>UNKNOWN [0xfffffa8007c7f254]<< 14:45:58.974 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007c5a520] 14:45:58.977 3 CLASSPNP.SYS[fffff8800165a43f] -> nt!IofCallDriver -> [0xfffffa8007afd520] 14:45:58.980 5 ACPI.sys[fffff88000efc781] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8007afe060] 14:45:58.982 \Driver\atapi[0xfffffa8007ae8900] -> IRP_MJ_INTERNAL_DEVICE_CONTROL -> 0xfffffa8007c7f254 14:46:03.557 AVAST engine scan C:\Windows 14:46:06.927 AVAST engine scan C:\Windows\system32 14:47:37.199 AVAST engine scan C:\Windows\system32\drivers 14:47:45.814 AVAST engine scan C:\Users\Heintje 14:49:24.133 AVAST engine scan C:\ProgramData 14:51:08.625 Scan finished successfully 14:56:56.106 Disk 0 MBR read successfully 14:56:56.114 Disk 0 TDL4@MBR code has been found 14:56:56.118 Disk 0 fixing MBR ... 14:57:06.127 Disk 0 MBR restored successfully 14:57:06.145 Verifying disinfection 14:57:16.174 Infection fixed successfully - please reboot ASAP 14:57:38.468 Disk 0 MBR has been saved successfully to "C:\Users\Heintje\Desktop\MBR.dat" 14:57:38.528 The log file has been saved successfully to "C:\Users\Heintje\Desktop\aswMBR12dec.txt"