aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software Run date: 2012-07-27 18:32:45 ----------------------------- 18:32:45.112 OS Version: Windows x64 6.1.7601 Service Pack 1 18:32:45.112 Number of processors: 2 586 0x100 18:32:45.112 ComputerName: TEE-PC UserName: Tee 18:32:47.783 Initialize success 18:32:48.371 AVAST engine defs: 12072602 18:33:51.102 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 18:33:51.117 Disk 0 Vendor: TOSHIBA_MK3259GSXP GN003J Size: 305245MB BusType: 11 18:33:51.211 Disk 0 MBR read successfully 18:33:51.227 Disk 0 MBR scan 18:33:51.242 Disk 0 Windows 7 default MBR code 18:33:51.242 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 14336 MB offset 2048 18:33:51.273 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 29362176 18:33:51.305 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 290808 MB offset 29566976 18:33:51.336 Disk 0 scanning C:\Windows\system32\drivers 18:34:07.638 Service scanning 18:34:50.103 Modules scanning 18:34:50.119 Disk 0 trace - called modules: 18:34:50.150 ntoskrnl.exe CLASSPNP.SYS disk.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys 18:34:50.181 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8002d55740] 18:34:50.197 3 CLASSPNP.SYS[fffff8800160143f] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8002bff680] 18:34:51.195 AVAST engine scan C:\Windows 18:34:54.440 AVAST engine scan C:\Windows\system32 18:36:02.385 File: C:\Windows\system32\services.exe **INFECTED** Win32:Sirefef-ZT [Trj] 18:36:28.626 File: C:\Windows\assembly\GAC_32\Desktop.ini **INFECTED** Win32:Sirefef-PL [Rtk] 18:36:30.826 File: C:\Windows\assembly\GAC_64\Desktop.ini **INFECTED** Win32:Sirefef-PL [Rtk] 18:38:13.283 AVAST engine scan C:\Windows\system32\drivers 18:38:27.887 AVAST engine scan C:\Users\Tee 18:44:20.447 AVAST engine scan C:\ProgramData 18:45:56.108 Scan finished successfully 18:47:58.780 Disk 0 MBR has been saved successfully to "C:\Users\Tee\Desktop\Eric-Logs\MBR.dat" 18:47:58.795 The log file has been saved successfully to "C:\Users\Tee\Desktop\Eric-Logs\aswMBR.txt"