CmdLine - quick aswBoot.exe /A:"*" /L:"1033" /heur:80 /RA:ask /pup /archives /IA:0 /KBD:3 /wow /dir:"C:\Program Files\AVAST Software\Avast" CmdLine end SafeBoot: 0 CreateKbThread new CKbBuffer CKbBuffer::Init CKbBuffer::Init end NtCreateEvent(g_hStopEvent) dep_osBeginThread - KbThread CreateKbThread end NtInitializeRegistry KbThread start ReadRegistry DATA=C:\ProgramData\AVAST Software\Avast PROG=C:\Program Files\AVAST Software\Avast BUILD=1203 Windows 7 Home Premium Service Pack 1 SystemRoot=C:\Windows TEMP=C:\Windows\TEMP TMP=C:\Windows\TEMP ReadRegistry end CreateTemp CreateTemp end aswcmnbDllMain cmnbInit aswEnginDllMain(DLL_PROCESS_ATTACH) InitLog InitLog end CmdLine - full aswBoot.exe /A:"*" /L:"1033" /heur:80 /RA:ask /pup /archives /IA:0 /KBD:3 /wow /dir:"C:\Program Files\AVAST Software\Avast" CmdLine end Program folder: C:\Program Files\AVAST Software\Avast Engine folder: C:\Program Files\AVAST Software\Avast\defs\11080600 TimeStamp: 4e3c0f7b Unschedule 61,00,75,00,74,00,6F,00,63,00,68,00,65,00,63,00, 6B,00,20,00,61,00,75,00,74,00,6F,00,63,00,68,00, 6B,00,20,00,2A,00,00,00,61,00,73,00,77,00,42,00, 6F,00,6F,00,74,00,2E,00,65,00,78,00,65,00,20,00, 2F,00,41,00,3A,00,22,00,2A,00,22,00,20,00,2F,00, 4C,00,3A,00,22,00,31,00,30,00,33,00,33,00,22,00, 20,00,2F,00,68,00,65,00,75,00,72,00,3A,00,38,00, 30,00,20,00,2F,00,52,00,41,00,3A,00,61,00,73,00, 6B,00,20,00,2F,00,70,00,75,00,70,00,20,00,2F,00, 61,00,72,00,63,00,68,00,69,00,76,00,65,00,73,00, 20,00,2F,00,49,00,41,00,3A,00,30,00,20,00,2F,00, 4B,00,42,00,44,00,3A,00,33,00,20,00,2F,00,77,00, 6F,00,77,00,20,00,2F,00,64,00,69,00,72,00,3A,00, 22,00,43,00,3A,00,5C,00,50,00,72,00,6F,00,67,00, 72,00,61,00,6D,00,20,00,46,00,69,00,6C,00,65,00, 73,00,5C,00,41,00,56,00,41,00,53,00,54,00,20,00, 53,00,6F,00,66,00,74,00,77,00,61,00,72,00,65,00, 5C,00,41,00,76,00,61,00,73,00,74,00,22,00,00,00, 00,00, Unschedule end LoadResources LoadResources end InitReport InitReport end Global exclusions: NtSetEvent(g_hInitEvent) - 1 CPU: Phys(2), Log(4), Aff(4), Feat(000003ff) FreeMemory: 3634634752 avworkInitialize InitKeyboard g_dwKbdNum: 3 s_dwKbdClassCnt: 3 InitKeyboard end NtSetEvent(g_hInitEvent) - 2 GetKey FreeMemory: 3634597888 CKbBuffer::Wait CKbBuffer::Get CKbBuffer::Get end CKbBuffer::Wait end ProcessArea avfilesScanAdd *MBR0 avfilesScanAdd *BOOTC: Loading raw access support avfilesScanAdd *RAW:C:\ [Fs: 03e700ff, NTFS; Dev: 07, 00000020] avfilesScanAdd *BOOTVolume{f511b833-cafd-11df-9fcf-806e6f6e6963} avfilesScanAdd *RAW:Volume{f511b833-cafd-11df-9fcf-806e6f6e6963}\ [Fs: 03e700ff, NTFS; Dev: 07, 00000020] avfilesScanAdd *BOOTVolume{f511b834-cafd-11df-9fcf-806e6f6e6963} avfilesScanAdd *RAW:Volume{f511b834-cafd-11df-9fcf-806e6f6e6963}\ [Fs: 03e700ff, NTFS; Dev: 07, 00000020] avfilesScanRealMulti begin avfilesScanRealMulti finished Runtime: 8064621ms avworkClose TerminateKbThread GetKey end (?/00) CloseKeyboard CloseKeyboard end KbThread stop CKbBuffer::~CKbBuffer CKbBuffer::~CKbBuffer end aswEnginDllMain(DLL_PROCESS_DETACH) cmnbFree FreeResources CloseReport CloseLog