aswMBR version 0.9.9.1532 Copyright(c) 2011 AVAST Software Run date: 2012-02-04 17:24:16 ----------------------------- 17:24:16.160 OS Version: Windows x64 6.1.7601 Service Pack 1 17:24:16.160 Number of processors: 6 586 0xA00 17:24:16.160 ComputerName: AEGIS UserName: DLee 17:24:17.359 Initialize success 17:24:29.156 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 17:24:29.157 Disk 0 Vendor: WDC_WD1002FAEX-00Z3A0 05.01D05 Size: 953869MB BusType: 3 17:24:29.158 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP0T1L0-2 17:24:29.159 Disk 1 Vendor: C300-CTFDDAC064MAG 0006 Size: 61057MB BusType: 3 17:24:29.161 Device \Driver\atapi -> MajorFunction fffffa800e5ac5c4 17:24:29.183 Disk 0 MBR read successfully 17:24:29.185 Disk 0 MBR scan 17:24:29.186 Disk 0 TDL4@MBR code has been found 17:24:29.188 Disk 0 Windows 7 default MBR code found via API 17:24:29.189 Disk 0 MBR hidden 17:24:29.198 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 476827 MB offset 2048 17:24:29.219 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 477039 MB offset 976543744 17:24:29.221 Disk 0 MBR [TDL4] **ROOTKIT** 17:24:29.224 Disk 0 trace - called modules: 17:24:29.227 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys >>UNKNOWN [0xfffffa800e5ac5c4]<< 17:24:29.230 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800cb91790] 17:24:29.233 3 CLASSPNP.SYS[fffff8800185143f] -> nt!IofCallDriver -> [0xfffffa800d9cc960] 17:24:29.236 5 ACPI.sys[fffff8800103a7a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa800da8f680] 17:24:29.239 \Driver\atapi[0xfffffa800e5aa550] -> IRP_MJ_CREATE -> 0xfffffa800e5ac5c4 17:24:29.243 Scan finished successfully 17:24:30.391 Disk 0 MBR read successfully 17:24:30.394 Disk 0 TDL4@MBR code has been found 17:24:30.406 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 476827 MB offset 2048 17:24:30.428 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 477039 MB offset 976543744 17:24:30.431 Disk 0 fixing MBR ... 17:24:30.445 Disk 0 MBR restored successfully 17:24:30.510 Verifying disinfection 17:24:40.578 Infection fixed successfully - please reboot ASAP 17:25:02.814 Disk 0 MBR has been saved successfully to "C:\Users\DLee\Desktop\MBR.dat" 17:25:02.816 The log file has been saved successfully to "C:\Users\DLee\Desktop\aswMBR2.txt"