I am working on a Windows 7 machine that has C:\Windows\System32\services.exe Win32:Patched-AKC and C:\Windows\assembly\GAC_32\Desktop.ini and \GAC_64\desktop.ini with WIN32:Sirefef-PL. I have a aswMBR log but I will get a log from OTL from what ive been reading on and post that.
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-08-26 19:55:07
19:55:07.822 OS Version: Windows x64 6.1.7600
19:55:07.822 Number of processors: 2 586 0x170A
19:55:07.822 ComputerName: ELITE UserName:
19:55:09.117 Initialize success
19:55:09.319 AVAST engine defs: 12082400
19:55:15.654 Disk 0 (boot) \Device\Harddisk0\DR0 → \Device\Ide\IAAStorageDevice-1
19:55:15.654 Disk 0 Vendor: WDC_WD32 01.0 Size: 305245MB BusType: 3
19:55:15.670 Disk 0 MBR read successfully
19:55:15.685 Disk 0 MBR scan
19:55:15.685 Disk 0 Windows 7 default MBR code
19:55:15.685 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 100 MB offset 2048
19:55:15.701 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 15000 MB offset 206848
19:55:15.716 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 290143 MB offset 30926848
19:55:15.748 Disk 0 scanning C:\Windows\system32\drivers
19:55:26.324 Service scanning
19:56:12.691 Modules scanning
19:56:12.691 Disk 0 trace - called modules:
19:56:12.722 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys
19:56:12.722 1 nt!IofCallDriver → \Device\Harddisk0\DR0[0xfffffa800301f5d0]
19:56:12.737 3 CLASSPNP.SYS[fffff880011cf43f] → nt!IofCallDriver → \Device\Ide\IAAStorageDevice-1[0xfffffa8002e2f050]
19:56:13.377 AVAST engine scan C:\Windows
19:56:15.671 AVAST engine scan C:\Windows\system32
19:57:28.857 File: C:\Windows\system32\services.exe INFECTED Win32:Patched-AKC [Trj]
19:57:57.426 File: C:\Windows\assembly\GAC_32\Desktop.ini INFECTED Win32:Sirefef-PL [Rtk]
19:57:59.812 File: C:\Windows\assembly\GAC_64\Desktop.ini INFECTED Win32:Sirefef-PL [Rtk]
19:58:59.662 AVAST engine scan C:\Windows\system32\drivers
19:59:12.329 AVAST engine scan C:\Users\Kristian
20:06:06.617 Disk 0 MBR has been saved successfully to “C:\Users\Kristian\Desktop\MBR.dat”
20:06:06.617 The log file has been saved successfully to “C:\Users\Kristian\Desktop\aswMBR.txt”
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-08-26 19:55:07
19:55:07.822 OS Version: Windows x64 6.1.7600
19:55:07.822 Number of processors: 2 586 0x170A
19:55:07.822 ComputerName: ELITE UserName:
19:55:09.117 Initialize success
19:55:09.319 AVAST engine defs: 12082400
19:55:15.654 Disk 0 (boot) \Device\Harddisk0\DR0 → \Device\Ide\IAAStorageDevice-1
19:55:15.654 Disk 0 Vendor: WDC_WD32 01.0 Size: 305245MB BusType: 3
19:55:15.670 Disk 0 MBR read successfully
19:55:15.685 Disk 0 MBR scan
19:55:15.685 Disk 0 Windows 7 default MBR code
19:55:15.685 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 100 MB offset 2048
19:55:15.701 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 15000 MB offset 206848
19:55:15.716 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 290143 MB offset 30926848
19:55:15.748 Disk 0 scanning C:\Windows\system32\drivers
19:55:26.324 Service scanning
19:56:12.691 Modules scanning
19:56:12.691 Disk 0 trace - called modules:
19:56:12.722 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys
19:56:12.722 1 nt!IofCallDriver → \Device\Harddisk0\DR0[0xfffffa800301f5d0]
19:56:12.737 3 CLASSPNP.SYS[fffff880011cf43f] → nt!IofCallDriver → \Device\Ide\IAAStorageDevice-1[0xfffffa8002e2f050]
19:56:13.377 AVAST engine scan C:\Windows
19:56:15.671 AVAST engine scan C:\Windows\system32
19:57:28.857 File: C:\Windows\system32\services.exe INFECTED Win32:Patched-AKC [Trj]
19:57:57.426 File: C:\Windows\assembly\GAC_32\Desktop.ini INFECTED Win32:Sirefef-PL [Rtk]
19:57:59.812 File: C:\Windows\assembly\GAC_64\Desktop.ini INFECTED Win32:Sirefef-PL [Rtk]
19:58:59.662 AVAST engine scan C:\Windows\system32\drivers
19:59:12.329 AVAST engine scan C:\Users\Kristian
20:06:06.617 Disk 0 MBR has been saved successfully to “C:\Users\Kristian\Desktop\MBR.dat”
20:06:06.617 The log file has been saved successfully to “C:\Users\Kristian\Desktop\aswMBR.txt”
20:10:07.655 AVAST engine scan C:\ProgramData
20:12:59.800 Scan finished successfully
20:15:25.233 Disk 0 MBR has been saved successfully to “C:\Users\Kristian\Desktop\MBR.dat”
20:15:25.248 The log file has been saved successfully to “C:\Users\Kristian\Desktop\aswMBR.txt”