Thanks for the input.
boot log:
CmdLine - quick
aswBoot.exe /A:“" /L:“English” /RA:chest /KBD:2
CmdLine end
SafeBoot: 0
CreateKbThread
new CKbBuffer
CKbBuffer::Init
CKbBuffer::Init end
NtCreateEvent(g_hStopEvent)
dep_osBeginThread - KbThread
CreateKbThread end
NtInitializeRegistry
KbThread start
ReadRegistry
DATA=C:\Program Files\Alwil Software\Avast4\DATA
PROG=C:\Program Files\Alwil Software\Avast4
BUILD=1296
Microsoft Windows XP Service Pack 3
SystemRoot=C:\WINDOWS
TEMP=C:\WINDOWS\TEMP
TMP=C:\WINDOWS\TEMP
ReadRegistry end
CreateTemp
CreateTemp end
cmnbInit
SetFolders
SetFolders end
aswEnginDllMain(DLL_PROCESS_ATTACH)
InitLog
InitLog end
CmdLine - full
aswBoot.exe /A:"” /L:“English” /RA:chest /KBD:2
CmdLine end
Unschedule
61,00,75,00,74,00,6F,00,63,00,68,00,65,00,63,00,
6B,00,20,00,61,00,75,00,74,00,6F,00,63,00,68,00,
6B,00,20,00,2A,00,00,00,50,00,61,00,72,00,74,00,
69,00,7A,00,61,00,6E,00,00,00,61,00,73,00,77,00,
42,00,6F,00,6F,00,74,00,2E,00,65,00,78,00,65,00,
20,00,2F,00,41,00,3A,00,22,00,2A,00,22,00,20,00,
2F,00,4C,00,3A,00,22,00,45,00,6E,00,67,00,6C,00,
69,00,73,00,68,00,22,00,20,00,2F,00,52,00,41,00,
3A,00,63,00,68,00,65,00,73,00,74,00,20,00,2F,00,
4B,00,42,00,44,00,3A,00,32,00,00,00,00,00,
Unschedule end
LoadResources
LoadResources end
InitReport
InitReport end
NtSetEvent(g_hInitEvent) - 1
InitKeyboard
g_dwKbdNum: 2
s_dwKbdClassCnt: 2
InitKeyboard end
NtSetEvent(g_hInitEvent) - 2
GetKey
FreeMemory: 1923964928
avworkInitialize
FreeMemory: 1864880128
CKbBuffer::Wait
CKbBuffer::Get
CKbBuffer::Get end
CKbBuffer::Wait end
ProcessArea
avfilesScanAdd *MBR0
avfilesScanAdd *RAW:C:\ [Fs: 000700ff, NTFS; Dev: 07, 00000020]
avfilesScanAdd *RAW:D:\ [Fs: 000700ff, NTFS; Dev: 07, 00000020]
avfilesScanRealMulti begin
CKbBuffer::Get
0, 2, 0, 0, 0
GetKey end
CKbBuffer::Put
CKbBuffer::Put end
GetKey
CKbBuffer::Get end
GetErrorText
0, 2, 1, 0, 0
CKbBuffer::Get
0, 2, 0, 0, 0
GetKey end
CKbBuffer::Put
CKbBuffer::Put end
GetKey
CKbBuffer::Get end
GetErrorText
0, 2, 1, 0, 0
avfilesScanRealMulti finished
avworkClose
Checking deleted files:
MarkFileRemoval
MarkFileRemoval end
Going to disable files:
*RAW:C:\WINDOWS\system32\drivers\qulytsft.sys
Preparing for restart
TerminateKbThread
GetKey end
CloseKeyboard
CloseKeyboard end
KbThread stop
CKbBuffer::~CKbBuffer
CKbBuffer::~CKbBuffer end
aswEnginDllMain(DLL_PROCESS_DETACH)
cmnbFree
FreeResources
CloseReport
CloseLog
Something seemed to have happened from running the scan. When the warnings popped up again on reboot, I was able to relocate them to the chest, I wasn’t getting the pop-up saying that they could not be moved.
I couldn’t find them in my sys 32 folder anymore, so hopefully they’re gone. thanks, Juno