aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software Run date: 2012-03-28 11:50:16 ----------------------------- 11:50:16.072 OS Version: Windows x64 6.1.7601 Service Pack 1 11:50:16.072 Number of processors: 8 586 0x1E05 11:50:16.072 ComputerName: ALIENWARE UserName: 11:50:16.634 Initialize success 11:51:00.938 AVAST engine defs: 12032801 11:51:05.571 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 11:51:05.571 Disk 0 Vendor: SAMSUNG_ VBM2 Size: 244198MB BusType: 3 11:51:05.571 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IAAStorageDevice-2 11:51:05.571 Disk 1 Vendor: SAMSUNG_ VBM2 Size: 244198MB BusType: 3 11:51:05.571 Disk 0 MBR read successfully 11:51:05.587 Disk 0 MBR scan 11:51:05.587 Disk 0 Windows 7 default MBR code 11:51:05.587 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 101 MB offset 63 11:51:05.587 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 9118 MB offset 208896 11:51:05.602 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 234977 MB offset 18882560 11:51:05.602 Disk 0 scanning C:\Windows\system32\drivers 11:51:11.983 Service scanning 11:51:20.251 Service sfilter C:\Windows\system32\MobilePreInstallerService.dll **INFECTED** Win64:ZAccess-E [Rtk] 11:51:22.591 Modules scanning 11:51:22.591 Disk 0 trace - called modules: 11:51:22.591 ntoskrnl.exe CLASSPNP.SYS disk.sys stdflt.sys iaStor.sys hal.dll 11:51:22.606 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007cb5790] 11:51:22.606 3 CLASSPNP.SYS[fffff8800185143f] -> nt!IofCallDriver -> [0xfffffa8007bbace0] 11:51:22.606 5 stdflt.sys[fffff88001b65a4a] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8007a40050] 11:51:31.530 AVAST engine scan C:\Windows 11:51:32.762 AVAST engine scan C:\Windows\system32 11:51:36.178 File: C:\Windows\system32\consrv.dll **INFECTED** Win32:Sirefef-HO [Rtk] 11:51:36.241 File: C:\Windows\system32\crauto.dll **INFECTED** Win64:ZAccess-E [Rtk] 11:51:44.525 File: C:\Windows\system32\lxrjd31s.dll **INFECTED** Win64:ZAccess-E [Rtk] 11:51:45.461 File: C:\Windows\system32\MobilePreInstallerService.dll **INFECTED** Win64:ZAccess-E [Rtk] 11:52:04.867 File: C:\Windows\assembly\GAC_32\Desktop.ini **INFECTED** Win32:Sirefef-FQ [Drp] 11:52:05.351 File: C:\Windows\assembly\GAC_64\Desktop.ini **INFECTED** Win32:Sirefef-HO [Rtk] 11:52:28.579 AVAST engine scan C:\Windows\system32\drivers 11:52:31.933 AVAST engine scan C:\Users\rockroland 11:52:34.928 File: C:\Users\rockroland\AppData\Local\Google\Update\1.3.21.111\GoogleCrashHandler.exe **INFECTED** Win32:Malware-gen 11:52:34.959 File: C:\Users\rockroland\AppData\Local\Google\Update\1.3.21.111\GoogleUpdate.exe **INFECTED** Win32:Trojan-gen 11:52:35.365 File: C:\Users\rockroland\AppData\Local\Google\Update\GoogleUpdate.exe **INFECTED** Win32:Trojan-gen 11:52:55.520 AVAST engine scan C:\ProgramData 11:53:04.709 Scan finished successfully 11:53:23.881 Disk 0 MBR has been saved successfully to "C:\Installs\VirusTools\MBR.dat" 11:53:23.897 The log file has been saved successfully to "C:\Installs\VirusTools\aswMBR.txt" aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software Run date: 2012-03-28 18:42:38 ----------------------------- 18:42:38.377 OS Version: Windows x64 6.1.7601 Service Pack 1 18:42:38.377 Number of processors: 8 586 0x1E05 18:42:38.377 ComputerName: ALIENWARE UserName: 18:42:39.048 Initialize success 18:43:20.139 AVAST engine defs: 12032802 18:43:27.127 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 18:43:27.143 Disk 0 Vendor: SAMSUNG_ VBM2 Size: 244198MB BusType: 3 18:43:27.143 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IAAStorageDevice-2 18:43:27.143 Disk 1 Vendor: SAMSUNG_ VBM2 Size: 244198MB BusType: 3 18:43:27.143 Disk 0 MBR read successfully 18:43:27.143 Disk 0 MBR scan 18:43:27.159 Disk 0 Windows 7 default MBR code 18:43:27.159 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 101 MB offset 63 18:43:27.159 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 9118 MB offset 208896 18:43:27.159 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 234977 MB offset 18882560 18:43:27.174 Disk 0 scanning C:\Windows\system32\drivers 18:43:32.104 Service scanning 18:43:42.478 Modules scanning 18:43:42.478 Disk 0 trace - called modules: 18:43:42.478 ntoskrnl.exe CLASSPNP.SYS disk.sys stdflt.sys iaStor.sys hal.dll 18:43:42.493 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007cab790] 18:43:42.493 3 CLASSPNP.SYS[fffff88001bbe43f] -> nt!IofCallDriver -> [0xfffffa8007bb6ce0] 18:43:42.493 5 stdflt.sys[fffff88001b09a4a] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8007a14050] 18:43:45.239 AVAST engine scan C:\Windows 18:43:46.487 AVAST engine scan C:\Windows\system32 18:43:49.966 File: C:\Windows\system32\crauto.dll **INFECTED** Win64:ZAccess-E [Rtk] 18:43:58.421 File: C:\Windows\system32\lxrjd31s.dll **INFECTED** Win64:ZAccess-E [Rtk] 18:43:59.357 File: C:\Windows\system32\MobilePreInstallerService.dll **INFECTED** Win64:ZAccess-E [Rtk] 18:44:43.411 AVAST engine scan C:\Windows\system32\drivers 18:44:46.656 AVAST engine scan C:\Users\rockroland 18:45:11.554 AVAST engine scan C:\ProgramData 18:45:21.023 Scan finished successfully 18:59:08.121 Disk 0 MBR has been saved successfully to "C:\Installs\VirusTools\MBR.dat" 18:59:08.137 The log file has been saved successfully to "C:\Installs\VirusTools\aswMBR.txt"