aswMBR version 0.9.8.978 Copyright(c) 2011 AVAST Software Run date: 2011-08-11 17:14:23 ----------------------------- 17:14:23.046 OS Version: Windows 5.1.2600 Service Pack 3 17:14:23.046 Number of processors: 2 586 0x1C02 17:14:23.046 ComputerName: D74KH5K1 UserName: Bren 17:14:25.125 Initialize success 17:14:26.640 AVAST engine defs: 11081101 17:14:28.750 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdePort0 17:14:28.750 Disk 0 Vendor: TOSHIBA_MK1655GSX FG010D Size: 152627MB BusType: 3 17:14:28.765 Device \Device\Ide\IdeDeviceP0T0L0-3 -> \??\IDE#DiskTOSHIBA_MK1655GSX_______________________FG010D__#5&33dc7a75&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} not found 17:14:28.765 Device \Driver\atapi -> DriverStartIo 86ca3aea 17:14:30.828 Disk 0 MBR read successfully 17:14:30.843 Disk 0 MBR scan 17:14:30.953 Disk 0 Windows VISTA default MBR code 17:14:30.984 Disk 0 scanning sectors +312579760 17:14:31.093 Disk 0 scanning C:\WINDOWS\system32\drivers 17:14:38.703 File: C:\WINDOWS\system32\drivers\ftdisk.sys **INFECTED** Win32:Alureon-FZ 17:14:47.390 Service scanning 17:14:48.328 Service vsdatant C:\WINDOWS\System32\vsdatant.sys **LOCKED** 32 17:14:48.875 Modules scanning 17:14:56.250 Disk 0 trace - called modules: 17:14:56.296 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x86ca3ec5]<< 17:14:56.312 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86dd0ab8] 17:14:56.328 3 CLASSPNP.SYS[f75fdfd7] -> nt!IofCallDriver -> \Device\00000070[0x86d639e8] 17:14:56.328 5 ACPI.sys[f7494620] -> nt!IofCallDriver -> [0x86d63d98] 17:14:56.343 [0x86d72278] -> IRP_MJ_CREATE -> 0x86ca3ec5 17:14:57.515 AVAST engine scan C:\WINDOWS 17:15:01.453 AVAST engine scan C:\WINDOWS\system32 17:16:24.406 AVAST engine scan C:\WINDOWS\system32\drivers 17:16:30.437 File: C:\WINDOWS\system32\drivers\ftdisk.sys **INFECTED** Win32:Alureon-FZ 17:16:37.046 AVAST engine scan C:\Documents and Settings\Bren 17:17:29.375 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Bren\Desktop\MBR.dat" 17:17:29.406 The log file has been saved successfully to "C:\Documents and Settings\Bren\Desktop\aswMBR.txt"