Hi Broni,
I believe Webroot stops spyware, adware, etc. and Symantec Endpoint Protection is main AV program. Neither programs stopped this machine from getting infected.
The Firewall is managed by Symantec Endpoint Protection.
-- aswMBR log: --
----------------------
aswMBR version 0.9.9.1649 Copyright(c) 2011 AVAST Software
Run date: 2012-03-07 14:33:48
-----------------------------
14:33:48.085 OS Version: Windows x64 6.1.7601 Service Pack 1
14:33:48.085 Number of processors: 4 586 0x2505
14:33:48.085 ComputerName: CQUICK-W7 UserName: cquick
14:33:54.843 Initialize success
14:35:00.232 AVAST engine defs: 12030700
14:35:40.327 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
14:35:40.327 Disk 0 Vendor: ST916041 D005 Size: 152627MB BusType: 8
14:35:40.342 Disk 0 MBR read successfully
14:35:40.358 Disk 0 MBR scan
14:35:40.374 Disk 0 Windows XP default MBR code
14:35:40.374 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 290 MB offset 63
14:35:40.389 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 750 MB offset 595968
14:35:40.405 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 149524 MB offset 2131968
14:35:40.420 Disk 0 Partition - 00 0F Extended LBA 2062 MB offset 308357120
14:35:40.452 Disk 0 Partition 4 00 0B FAT32 MSDOS5.0 2061 MB offset 308359168
14:35:40.514 Disk 0 scanning C:\Windows\system32\drivers
14:35:59.305 Service scanning
14:36:31.377 Modules scanning
14:36:31.393 Disk 0 trace - called modules:
14:36:31.533 ntoskrnl.exe CLASSPNP.SYS disk.sys stdfltn.sys ACPI.sys iaStor.sys
14:36:31.549 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80066d9060]
14:36:31.565 3 CLASSPNP.SYS[fffff88001f9943f] -> nt!IofCallDriver -> [0xfffffa8006575b60]
14:36:31.565 5 stdfltn.sys[fffff88001ed8af2] -> nt!IofCallDriver -> [0xfffffa8003877be0]
14:36:31.565 7 ACPI.sys[fffff88000f917a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa80042ca050]
14:36:32.626 AVAST engine scan C:\Windows
14:36:34.780 AVAST engine scan C:\Windows\system32
14:40:22.241 AVAST engine scan C:\Windows\system32\drivers
14:40:41.947 AVAST engine scan C:\Users\cquick
14:43:39.952 AVAST engine scan C:\ProgramData
14:44:44.306 Scan finished successfully
14:48:02.750 Disk 0 MBR has been saved successfully to "C:\Users\cquick\Desktop\MBR.dat"
14:48:02.766 The log file has been saved successfully to "C:\Users\cquick\Desktop\aswMBR.txt"
aswMBR version 0.9.9.1649 Copyright(c) 2011 AVAST Software
Run date: 2012-03-07 14:33:48
-----------------------------
14:33:48.085 OS Version: Windows x64 6.1.7601 Service Pack 1
14:33:48.085 Number of processors: 4 586 0x2505
14:33:48.085 ComputerName: CQUICK-W7 UserName: cquick
14:33:54.843 Initialize success
14:35:00.232 AVAST engine defs: 12030700
14:35:40.327 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
14:35:40.327 Disk 0 Vendor: ST916041 D005 Size: 152627MB BusType: 8
14:35:40.342 Disk 0 MBR read successfully
14:35:40.358 Disk 0 MBR scan
14:35:40.374 Disk 0 Windows XP default MBR code
14:35:40.374 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 290 MB offset 63
14:35:40.389 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 750 MB offset 595968
14:35:40.405 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 149524 MB offset 2131968
14:35:40.420 Disk 0 Partition - 00 0F Extended LBA 2062 MB offset 308357120
14:35:40.452 Disk 0 Partition 4 00 0B FAT32 MSDOS5.0 2061 MB offset 308359168
14:35:40.514 Disk 0 scanning C:\Windows\system32\drivers
14:35:59.305 Service scanning
14:36:31.377 Modules scanning
14:36:31.393 Disk 0 trace - called modules:
14:36:31.533 ntoskrnl.exe CLASSPNP.SYS disk.sys stdfltn.sys ACPI.sys iaStor.sys
14:36:31.549 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80066d9060]
14:36:31.565 3 CLASSPNP.SYS[fffff88001f9943f] -> nt!IofCallDriver -> [0xfffffa8006575b60]
14:36:31.565 5 stdfltn.sys[fffff88001ed8af2] -> nt!IofCallDriver -> [0xfffffa8003877be0]
14:36:31.565 7 ACPI.sys[fffff88000f917a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa80042ca050]
14:36:32.626 AVAST engine scan C:\Windows
14:36:34.780 AVAST engine scan C:\Windows\system32
14:40:22.241 AVAST engine scan C:\Windows\system32\drivers
14:40:41.947 AVAST engine scan C:\Users\cquick
14:43:39.952 AVAST engine scan C:\ProgramData
14:44:44.306 Scan finished successfully
14:48:02.750 Disk 0 MBR has been saved successfully to "C:\Users\cquick\Desktop\MBR.dat"
14:48:02.766 The log file has been saved successfully to "C:\Users\cquick\Desktop\aswMBR.txt"
16:02:22.881 Disk 0 MBR has been saved successfully to "C:\Users\cquick\Desktop\MBR.dat"
16:02:22.897 The log file has been saved successfully to "C:\Users\cquick\Desktop\aswMBR.txt"
-- Bootkit Log --
--------------------
Bootkit Remover
(c) 2009 Esage Lab
www.esagelab.com
Program version: 1.2.0.1
OS Version: Microsoft Windows 7 Ultimate Edition Service Pack 1 (build 7601), 64
-bit
System volume is \\.\C:
\\.\C: -> \\.\PhysicalDrive0 at offset 0x00000000`41100000
Boot sector MD5 is: 6def5ffcbcdbdb4082f1015625e597bd
Size Device Name MBR Status
--------------------------------------------
149 GB \\.\PhysicalDrive0 OK (DOS/Win32 Boot code found)
Done;
Press any key to quit...