aswMBR version 0.9.9.1297 Copyright(c) 2011 AVAST Software Run date: 2012-01-11 18:04:38 ----------------------------- 18:04:38.629 OS Version: Windows 5.1.2600 Service Pack 3 18:04:38.629 Number of processors: 2 586 0xF06 18:04:38.629 ComputerName: DESIGNVACANT UserName: 18:04:40.160 Initialize success 18:07:20.863 AVAST engine defs: 12011101 18:08:14.082 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 18:08:14.082 Disk 0 Vendor: ST316081 3.AD Size: 152587MB BusType: 3 18:08:14.097 Disk 0 MBR read successfully 18:08:14.097 Disk 0 MBR scan 18:08:14.129 Disk 0 Windows XP default MBR code 18:08:14.129 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 54 MB offset 63 18:08:14.144 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 152531 MB offset 112455 18:08:14.160 Disk 0 scanning sectors +312496380 18:08:14.222 Disk 0 scanning C:\WINDOWS\system32\drivers 18:08:22.113 File: C:\WINDOWS\system32\drivers\mrxsmb.sys **SUSPICIOUS** 18:08:27.910 Disk 0 trace - called modules: 18:08:27.925 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0xac7b3ff0]<< 18:08:27.925 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x89e06ab8] 18:08:27.925 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> [0x89ca7db8] 18:08:27.941 \Driver\00001120[0x89d234f8] -> IRP_MJ_CREATE -> 0xac7b3ff0 18:08:28.738 AVAST engine scan C:\WINDOWS 18:08:39.191 AVAST engine scan C:\WINDOWS\system32 18:10:24.425 AVAST engine scan C:\WINDOWS\system32\drivers 18:10:33.066 File: C:\WINDOWS\system32\drivers\mrxsmb.sys **SUSPICIOUS** 18:10:40.988 AVAST engine scan C:\Documents and Settings\Administrator 18:10:56.910 AVAST engine scan C:\Documents and Settings\All Users 18:13:01.332 Scan finished successfully 18:13:13.004 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Administrator\Desktop\MBR.dat" 18:13:13.004 The log file has been saved successfully to "C:\Documents and Settings\Administrator\Desktop\aswMBR.txt"