aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software Run date: 2013-04-18 10:44:02 ----------------------------- 10:44:02.904 OS Version: Windows 6.0.6002 Service Pack 2 10:44:02.904 Number of processors: 2 586 0xF0A 10:44:02.905 ComputerName: SALES-PC UserName: Sales 10:44:04.138 Initialize success 10:51:53.031 AVAST engine defs: 13041701 11:10:34.947 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 11:10:34.952 Disk 0 Vendor: KINGSTON E111 Size: 122103MB BusType: 3 11:10:34.988 Disk 0 MBR read successfully 11:10:34.991 Disk 0 MBR scan 11:10:35.014 Disk 0 unknown MBR code 11:10:35.018 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 7238 MB offset 2048 11:10:35.024 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 114864 MB offset 14825472 11:10:35.031 Disk 0 scanning sectors +250066944 11:10:35.073 Disk 0 scanning C:\Windows\system32\drivers 11:10:43.389 Service scanning 11:11:13.024 Modules scanning 11:11:17.265 Disk 0 trace - called modules: 11:11:17.275 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll iaStor.sys 11:11:17.607 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8608c5d0] 11:11:17.612 3 CLASSPNP.SYS[883d68b3] -> nt!IofCallDriver -> [0x853a5560] 11:11:17.617 5 acpi.sys[806936bc] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x84ddc028] 11:11:19.121 AVAST engine scan C:\Windows 11:11:19.714 File: C:\Windows\oem_uninst.exe **INFECTED** Win32:Trojan-gen 11:11:23.079 AVAST engine scan C:\Windows\system32 11:14:52.334 AVAST engine scan C:\Windows\system32\drivers 11:15:04.220 AVAST engine scan C:\Users\Sales 11:18:13.870 AVAST engine scan C:\ProgramData 11:19:49.533 Scan finished successfully 11:21:13.947 Disk 0 MBR has been saved successfully to "C:\Users\Sales\Desktop\MBR.dat" 11:21:13.962 The log file has been saved successfully to "C:\Users\Sales\Desktop\aswMBR.txt"