aswMBR version 1.0.1.2252 Copyright(c) 2014 AVAST Software Run date: 2014-12-07 15:50:23 ----------------------------- 15:50:23.153 OS Version: Windows x64 6.2.9200 15:50:23.153 Number of processors: 2 586 0x200 15:50:23.153 ComputerName: KEVONS-PC UserName: Kevon 15:50:24.670 Initialize success 15:50:24.670 VM: initialized successfully 15:50:24.685 VM: Amd CPU supported virtualizedSuspended 15:50:29.496 AVAST engine defs: 14120702 15:50:45.820 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000028 15:50:45.836 Disk 0 Vendor: ST320LT012-9WS14C 0001YAM1 Size: 305245MB BusType: 11 15:50:46.008 Disk 0 MBR read successfully 15:50:46.008 Disk 0 MBR scan 15:50:46.023 Disk 0 unknown MBR code 15:50:46.039 Disk 0 Partition 1 00 EE GPT 2097151 MB offset 1 15:50:46.086 Disk 0 scanning C:\WINDOWS\system32\drivers 15:51:02.796 Service scanning 15:51:08.332 Service BHDrvx64 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\BASHDefs\20140214.001\BHDrvx64.sys **LOCKED** 5 15:51:09.504 Service ccSet_NIS C:\WINDOWS\system32\drivers\NISx64\1405000.01C\ccSetx64.sys **LOCKED** 5 15:51:12.630 Service eeCtrl C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys **LOCKED** 5 15:51:13.053 Service EraserUtilRebootDrv C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys **LOCKED** 5 15:51:17.054 Service IDSVia64 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\IPSDefs\20140221.001\IDSvia64.sys **LOCKED** 5 15:51:21.872 Service NAVENG C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\VirusDefs\20140222.007\ENG64.SYS **LOCKED** 5 15:51:22.059 Service NAVEX15 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\VirusDefs\20140222.007\EX64.SYS **LOCKED** 5 15:51:29.627 Service SRTSPX C:\WINDOWS\system32\drivers\NISx64\1405000.01C\SRTSPX64.SYS **LOCKED** 5 15:51:30.596 Service SymDS C:\WINDOWS\system32\drivers\NISx64\1405000.01C\SYMDS64.SYS **LOCKED** 5 15:51:30.736 Service SymELAM C:\WINDOWS\system32\drivers\NISx64\1405000.01C\SymELAM.sys **LOCKED** 5 15:51:30.830 Service SymEvent C:\Windows\system32\Drivers\SYMEVENT64x86.SYS **LOCKED** 5 15:51:30.908 Service SymIRON C:\WINDOWS\system32\drivers\NISx64\1405000.01C\Ironx64.SYS **LOCKED** 5 15:51:31.002 Service SymNetS C:\WINDOWS\System32\Drivers\NISx64\1405000.01C\SYMNETS.SYS **LOCKED** 5 15:51:39.609 Modules scanning 15:51:39.624 Disk 0 trace - called modules: 15:51:39.703 ntoskrnl.exe CLASSPNP.SYS disk.sys amdxata.sys storport.sys hal.dll amdsata.sys 15:51:39.718 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffe001ea7c6770] 15:51:39.734 3 CLASSPNP.SYS[fffff8012876127b] -> nt!IofCallDriver -> [0xffffe001ea719830] 15:51:39.749 5 amdxata.sys[fffff801283e56b4] -> nt!IofCallDriver -> \Device\00000028[0xffffe001ea71b7f0] 15:51:40.718 AVAST engine scan C:\WINDOWS 15:51:43.611 AVAST engine scan C:\WINDOWS\system32 15:56:06.980 AVAST engine scan C:\WINDOWS\system32\drivers 15:56:33.678 AVAST engine scan C:\Users\Kevon 16:01:10.783 File: C:\Users\Kevon\Downloads\Setup (1).exe **INFECTED** Win32:Evo-gen [Susp] 16:01:27.334 AVAST engine scan C:\ProgramData 16:11:47.248 Disk 0 statistics 3346339/0/0 @ 1.92 MB/s 16:11:47.294 Scan finished successfully 16:13:22.478 Disk 0 MBR has been saved successfully to "C:\Users\Kevon\Desktop\MBR.dat" 16:13:22.494 The log file has been saved successfully to "C:\Users\Kevon\Desktop\aswMBR.txt"