aswMBR version 1.0.1.2290 Copyright(c) 2014 AVAST Software Run date: 2018-07-07 11:16:13 ----------------------------- 11:16:13.961 OS Version: Windows 6.1.7601 Service Pack 1 11:16:13.961 Number of processors: 4 586 0x2A07 11:16:13.961 ComputerName: LENOVO-PC UserName: lenovo 11:16:16.332 Initialize success 11:16:16.394 VM: initialized successfully 11:16:16.394 VM: Intel CPU BiosDisabled 11:16:24.584 AVAST engine defs: 18070504 11:16:32.041 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 11:16:32.041 Disk 0 Vendor: WDC_WD50 03.0 Size: 476940MB BusType: 3 11:16:32.306 Disk 0 MBR read successfully 11:16:32.306 Disk 0 MBR scan 11:16:32.306 Disk 0 Windows 7 default MBR code 11:16:32.322 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048 11:16:32.322 Disk 0 Boot: NTFS code=1 11:16:32.384 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 79900 MB offset 206848 11:16:32.400 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 130000 MB offset 163842048 11:16:32.400 Disk 0 Partition - 00 0F Extended LBA 266938 MB offset 430082048 11:16:32.478 Disk 0 Partition 4 00 07 HPFS/NTFS NTFS 130000 MB offset 430084096 11:16:32.478 Disk 0 Partition - 00 05 Extended 136937 MB offset 696324096 11:16:32.587 Disk 0 Partition 5 00 07 HPFS/NTFS NTFS 136936 MB offset 696326144 11:16:32.618 Disk 0 scanning sectors +976771072 11:16:33.055 Disk 0 scanning C:\Windows\system32\drivers 11:17:07.017 Service scanning 11:18:01.897 Service sptd C:\Windows\System32\Drivers\sptd.sys **LOCKED** 32 11:18:23.145 Modules scanning 11:18:23.145 Disk 0 trace - called modules: 11:18:23.145 11:18:23.784 AVAST engine scan C:\ 11:18:29.759 File: C:\FRST\Quarantine\C\program files\microsoft\desktoplayer.exe.xBAD **INFECTED** Win32:GenMalicious-GOW [Trj] 11:36:11.840 File: C:\Program Files\Windscribe\libcurl.dll **INFECTED** Win32:RmnDrp 11:36:12.230 File: C:\Program Files\Windscribe\libeay32.dll **INFECTED** Win32:RmnDrp 11:36:13.697 File: C:\Program Files\Windscribe\Platforms\qwindows.dll **INFECTED** Win32:RmnDrp 17:13:46.626 File: C:\Users\lenovo\Downloads\Tally ERP 9 Release 5.3.1 with Crack-easy to Activate-2016\Crack **INFECTED** Win32:Malware-gen 18:25:49.939 Disk 0 statistics 13721625/0/0 @ 0.27 MB/s 18:25:49.971 Scan stopped 18:46:21.530 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 18:46:21.561 Disk 0 Vendor: WDC_WD50 03.0 Size: 476940MB BusType: 3 18:46:22.669 Disk 0 MBR read successfully 18:46:22.685 Disk 0 MBR scan 18:46:22.716 Disk 0 Windows 7 default MBR code 18:46:22.747 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048 18:46:22.825 Disk 0 Boot: NTFS code=1 18:46:22.919 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 79900 MB offset 206848 18:46:22.997 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 130000 MB offset 163842048 18:46:22.997 Disk 0 Partition - 00 0F Extended LBA 266938 MB offset 430082048 18:46:23.137 Disk 0 Partition 4 00 07 HPFS/NTFS NTFS 130000 MB offset 430084096 18:46:23.137 Disk 0 Partition - 00 05 Extended 136937 MB offset 696324096 18:46:23.293 Disk 0 Partition 5 00 07 HPFS/NTFS NTFS 136936 MB offset 696326144 18:46:23.324 Disk 0 scanning sectors +976771072 18:46:24.775 Disk 0 scanning C:\Windows\system32\drivers 18:48:33.834 Service scanning 18:49:25.720 Service sptd C:\Windows\System32\Drivers\sptd.sys **LOCKED** 32 18:49:37.045 Modules scanning 18:49:37.045 Disk 0 trace - called modules: 18:49:37.108 18:49:39.214 AVAST engine scan C:\ 18:50:22.192 File: C:\FRST\Quarantine\C\program files\microsoft\desktoplayer.exe.xBAD **INFECTED** Win32:GenMalicious-GOW [Trj] 21:20:28.259 File: C:\Program Files\Windscribe\libcurl.dll **INFECTED** Win32:RmnDrp 21:20:29.351 File: C:\Program Files\Windscribe\libeay32.dll **INFECTED** Win32:RmnDrp 21:20:34.000 File: C:\Program Files\Windscribe\Platforms\qwindows.dll **INFECTED** Win32:RmnDrp 12:17:02.877 File: C:\Users\lenovo\Downloads\Tally ERP 9 Release 5.3.1 with Crack-easy to Activate-2016\Crack **INFECTED** Win32:Malware-gen 06:47:31.533 Disk 0 statistics 45368632/0/0 @ 0.15 MB/s 06:47:31.533 Scan finished successfully 10:37:55.061 Disk 0 MBR has been saved successfully to "C:\Users\lenovo\Desktop\MBR.dat" 10:37:55.155 The log file has been saved successfully to "C:\Users\lenovo\Desktop\aswMBR.txt"