aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software Run date: 2013-08-18 21:06:05 ----------------------------- 21:06:05.578 OS Version: Windows 5.1.2600 Service Pack 3 21:06:05.593 Number of processors: 2 586 0xE08 21:06:05.593 ComputerName: XP-798BF17A12A1 UserName: ingo 21:06:06.593 Initialize success 21:12:02.234 AVAST engine defs: 13081801 21:14:27.437 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 21:14:27.437 Disk 0 Vendor: SAMSUNG_HM250HI 2AC101C4 Size: 238475MB BusType: 3 21:14:27.843 Disk 0 MBR read successfully 21:14:27.843 Disk 0 MBR scan 21:14:27.890 Disk 0 unknown MBR code 21:14:27.921 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 127132 MB offset 63 21:14:27.953 Disk 0 Partition 2 00 0C FAT32 LBA RECOVERY 3935 MB offset 260366463 21:14:27.968 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 107405 MB offset 268425360 21:14:27.968 Disk 0 scanning sectors +488391120 21:14:28.187 Disk 0 scanning C:\WINDOWS\system32\drivers 21:14:45.078 Service scanning 21:15:04.781 Modules scanning 21:15:15.203 Module: C:\WINDOWS\System32\DLA\DLADResN.SYS **SUSPICIOUS** 21:15:16.625 Disk 0 trace - called modules: 21:15:16.656 ntkrnlpa.exe CLASSPNP.SYS disk.sys hpdskflt.sys hal.dll ACPI.sys atapi.sys intelide.sys PCIIDEX.SYS 21:15:16.656 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a91dab8] 21:15:16.656 3 CLASSPNP.SYS[f74e7fd7] -> nt!IofCallDriver -> [0x8a98b548] 21:15:16.656 5 hpdskflt.sys[f7518ffd] -> nt!IofCallDriver -> \Device\0000009b[0x8a8af9e8] 21:15:16.656 7 ACPI.sys[f735d620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8a942940] 21:15:17.671 AVAST engine scan C:\WINDOWS 21:15:41.250 AVAST engine scan C:\WINDOWS\system32 21:19:51.609 AVAST engine scan C:\WINDOWS\system32\drivers 21:20:20.734 AVAST engine scan C:\Dokumente und Einstellungen\ingo 23:58:54.859 AVAST engine scan C:\Dokumente und Einstellungen\All Users 00:00:33.437 Scan finished successfully 00:02:08.687 Disk 0 MBR has been saved successfully to "C:\MBR.dat" 00:02:08.687 The log file has been saved successfully to "C:\aswMBR20130819.txt"