aswMBR shows an unknown MBR code. The machine is NOT a Dell or HP (or any other system with a recovery partition). I am not running any boot managers or any other utility that should change the MBR. I installed the drives and have imaged/restored them with ghost many times. I’m running Windows XP. No hidden partitions that I can find.
Neither aswMBR or TDSSKiller show active infections although TDSSKiller does locate \Device\Harddisk0\DR0 ( TDSS File System ), assuming from a past infection although I don’t know when or what software removed the infection.
Is the “unknown MBR code” anything to worry about?
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-03-26 10:32:36
10:32:36.125 OS Version: Windows 5.1.2600 Service Pack 3
10:32:36.125 Number of processors: 2 586 0x209
10:32:36.125 ComputerName: SAM UserName: gandolph
10:32:36.437 Initialize success
10:51:36.781 AVAST engine defs: 12032601
11:13:28.781 Disk 0 (boot) \Device\Harddisk0\DR0 → \Device\Ide\IdeDeviceP2T0L0-e
11:13:28.781 Disk 0 Vendor: WDC_WD20EADS-00S2B0 01.00A01 Size: 1907729MB BusType: 3
11:13:28.781 Disk 1 \Device\Harddisk1\DR1 → \Device\Ide\IdeDeviceP3T0L0-19
11:13:28.781 Disk 1 Vendor: ST3160023AS 3.05 Size: 152627MB BusType: 3
11:13:28.796 Disk 0 MBR read successfully
11:13:28.796 Disk 0 MBR scan
11:13:28.843 Disk 0 unknown MBR code
11:13:28.843 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 29996 MB offset 63
11:13:28.843 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 122628 MB offset 61432560
11:13:28.875 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 99998 MB offset 312576705
11:13:28.875 Disk 0 Partition - 00 0F Extended LBA 1655102 MB offset 517373325
11:13:28.875 Disk 0 Partition 4 00 07 HPFS/NTFS NTFS 255102 MB offset 517373388
11:13:28.890 Disk 0 Partition - 00 05 Extended 499999 MB offset 1039823190
11:13:28.890 Disk 0 Partition 5 00 07 HPFS/NTFS NTFS 499999 MB offset 1039823253
11:13:28.906 Disk 0 scanning sectors +3907024065
11:13:28.968 Disk 0 scanning C:\WINDOWS\system32\drivers
11:13:38.296 Service scanning
11:13:49.203 Modules scanning
11:13:52.265 Disk 0 trace - called modules:
11:13:52.281 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
11:13:52.281 1 nt!IofCallDriver → \Device\Harddisk0\DR0[0x8a67dab8]
11:13:52.281 3 CLASSPNP.SYS[f7657fd7] → nt!IofCallDriver → \Device\0000006f[0x8a67e9e8]
11:13:52.281 5 ACPI.sys[f75ae620] → nt!IofCallDriver → \Device\Ide\IdeDeviceP2T0L0-e[0x8a667d98]
11:13:52.625 AVAST engine scan C:\WINDOWS
11:13:59.218 AVAST engine scan C:\WINDOWS\system32
11:16:48.375 AVAST engine scan C:\WINDOWS\system32\drivers
11:17:01.750 AVAST engine scan C:\Documents and Settings\gandolph
11:17:17.500 Disk 0 MBR has been saved successfully to “C:\Documents and Settings\gandolph\Desktop\MBR.dat”
11:17:17.515 The log file has been saved successfully to “C:\Documents and Settings\gandolph\Desktop\aswMBR.txt”
12:13:30.0531 3824 TDSS rootkit removing tool 2.7.23.0 Mar 26 2012 13:40:18
12:13:31.0062 3824 ============================================================
12:13:31.0062 3824 Current date / time: 2012/03/27 12:13:31.0062
12:13:31.0062 3824 SystemInfo:
12:13:31.0062 3824
12:13:31.0062 3824 OS Version: 5.1.2600 ServicePack: 3.0
12:13:31.0062 3824 Product type: Workstation
12:13:31.0062 3824 ComputerName: SAM
12:13:31.0062 3824 UserName: gandolph
12:13:31.0062 3824 Windows directory: C:\WINDOWS
12:13:31.0062 3824 System windows directory: C:\WINDOWS
12:13:31.0062 3824 Processor architecture: Intel x86
12:13:31.0062 3824 Number of processors: 2
12:13:31.0062 3824 Page size: 0x1000
12:13:31.0062 3824 Boot type: Normal boot
12:13:31.0062 3824 ============================================================
12:13:33.0171 3824 Drive \Device\Harddisk0\DR0 - Size: 0x1D1C1116000 (1863.02 Gb), SectorSize: 0x200, Cylinders: 0x3B601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type ‘K0’, Flags 0x00000054
12:13:33.0187 3824 Drive \Device\Harddisk1\DR1 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type ‘K0’, Flags 0x00000054
12:13:33.0203 3824 \Device\Harddisk0\DR0:
12:13:33.0203 3824 MBR used
12:13:33.0203 3824 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x3A962B1
12:13:33.0203 3824 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3A962F0, BlocksNum 0xEF827D1
12:13:33.0203 3824 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x12A18AC1, BlocksNum 0xC34F2CC
12:13:33.0218 3824 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x1ED67DCC, BlocksNum 0x1F23F38A
12:13:33.0234 3824 \Device\Harddisk0\DR0\Partition4: MBR, Type 0x7, StartLBA 0x3DFA7195, BlocksNum 0x3D08FC7E
12:13:33.0234 3824 \Device\Harddisk1\DR1:
12:13:33.0234 3824 MBR used
12:13:33.0234 3824 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x12A18A82
12:13:33.0531 3824 Initialize success
scan a bunch of files - everthing is OK
12:13:48.0515 3888 ============================================================
12:13:48.0515 3888 Scan finished
12:13:48.0515 3888 ============================================================
12:13:48.0531 3880 Detected object count: 0
12:13:48.0531 3880 Actual detected object count: 0
12:13:59.0296 3928 ============================================================
12:13:33.0531 3824 ============================================================
12:13:59.0296 3928 Scan started
12:13:59.0296 3928 Mode: Manual; TDLFS;
12:13:59.0296 3928 ============================================================
12:14:07.0875 3928 MBR (0x1B8) (671b81004fdd1588fa9ed1331c9ceca9) \Device\Harddisk0\DR0
12:14:08.0062 3928 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
12:14:08.0062 3928 \Device\Harddisk0\DR0 - detected TDSS File System (1)
12:14:08.0078 3928 MBR (0x1B8) (671b81004fdd1588fa9ed1331c9ceca9) \Device\Harddisk1\DR1
12:14:08.0140 3928 \Device\Harddisk1\DR1 - ok
12:14:08.0140 3928 Boot (0x1200) (a45abe50bcd6cd7377d0eff06ce75429) \Device\Harddisk0\DR0\Partition0
12:14:08.0140 3928 \Device\Harddisk0\DR0\Partition0 - ok
12:14:08.0187 3928 Boot (0x1200) (4ee9c2d7df7c34039c36db13a414bd1d) \Device\Harddisk0\DR0\Partition1
12:14:08.0187 3928 \Device\Harddisk0\DR0\Partition1 - ok
12:14:08.0203 3928 Boot (0x1200) (938e0e53cae7382e02cd96e10c5dd0dc) \Device\Harddisk0\DR0\Partition2
12:14:08.0203 3928 \Device\Harddisk0\DR0\Partition2 - ok
12:14:08.0218 3928 Boot (0x1200) (7e4e853ca9726e35959723a10e561236) \Device\Harddisk0\DR0\Partition3
12:14:08.0218 3928 \Device\Harddisk0\DR0\Partition3 - ok
12:14:08.0234 3928 Boot (0x1200) (deda2e871b32dbdfc831e497686119a6) \Device\Harddisk0\DR0\Partition4
12:14:08.0234 3928 \Device\Harddisk0\DR0\Partition4 - ok
12:14:08.0234 3928 Boot (0x1200) (29ef3976cd62e3e90a2ab2e5f1bf33ca) \Device\Harddisk1\DR1\Partition0
12:14:08.0234 3928 \Device\Harddisk1\DR1\Partition0 - ok
scan a bunch of files everything is OK
12:14:08.0234 3928 ============================================================
12:14:08.0234 3928 Scan finished
12:14:08.0234 3928 ============================================================
12:14:08.0250 3920 Detected object count: 1
12:14:08.0250 3920 Actual detected object count: 1
12:14:37.0718 3920 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
12:14:37.0718 3920 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip
12:14:39.0687 3816 Deinitialize success