Well below is the MBAM report.
First off the MBAM scan froze after 10 minutes at
c:\docs&settings\somerset.daisy\appdata\sun\java\deployment\systemcache\6.0\29\2d9f109d-7eafac72.idx
Now java updates have been nagging for a while, but haven’t succeeded because I normally run as limited user. However for this exercise I had temporarily upgraded to administrator.
After restart I updated java and re-ran MBAM, which went very quickly unlike Avast.
This time no problem, scanned all 3 drives.
Two false positives were listed
Keyfinder on the work drive
and
x.exe on the system drive in somerset.daisy (as the java problem), which it called trojan.avkill.
Now somerset.daisy is not an active user, just a copy of user data from an old computer.
However I removed x.exe and x.log, which seems to be associated with ‘my connection pc lite’
Since this program was an expired trial I also uninstalled it.
I also checked the registry, but there was nothing calling x.exe.
I also tried to call avastui from the run box, but it was no better.
With all this the problem with the Avast scan remains the same.
Malwarebytes’ Anti-Malware 1.46
www.malwarebytes.org
Database version: 4451
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
20/08/2010 10:41:43
mbam-log-2010-08-20 (10-41-43).txt
Scan type: Full scan (C:|D:|W:|)
Objects scanned: 212379
Time elapsed: 35 minute(s), 28 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
W:\Eric\kf151\keyfinder.exe (Application.FindKey) → No action taken.
C:\Documents and Settings\somerset.DAISY\x.exe (Trojan.KillAV) → No action taken.