As before, logs below:
Rkill 2.2.1 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2012 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 08/20/2012 03:27:02 AM in x64 mode.
Windows Version: Windows Vista
Checking for Windows services to stop.
* No malware services found to stop.
Checking for processes to terminate.
* No malware processes found to kill.
Checking Registry for malware related settings.
* Explorer Policy Removed: NoActiveDesktopChanges [HKLM]
Backup Registry file created at:
C:\Users\CrazyHorse\Desktop\rkill\rkill-08-20-2012-03-27-07.reg
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
* HKLM\Software\Classes\.exe\shell found and deleted!
Performing miscellaneous checks.
* No issues found.
Checking Windows Service Integrity:
* AppMgmt [Missing Service]
* CscService [Missing Service]
* Fax [Missing Service]
* UmRdpService [Missing Service]
* wbengine [Missing Service]
* gpsvc => %windir%\system32\svchost.exe -k GPSvcGroup [Incorrect ImagePath]
* atapi => \SystemRoot\system32\drivers\atapi.sys [Incorrect ImagePath]
* Processor => system32\DRIVERS\processr.sys [Incorrect ImagePath]
Searching for Missing Digital Signatures:
* No issues found.
Program finished at: 08/20/2012 03:27:13 AM
Execution time: 0 hours(s), 0 minute(s), and 10 seconds(s)
_____________________________________________________________________________________________________
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-08-20 03:30:31
-----------------------------
03:30:31.439 OS Version: Windows x64 6.0.6002 Service Pack 2
03:30:31.439 Number of processors: 4 586 0x203
03:30:31.439 ComputerName: CRAZYHORSE-PC UserName: CrazyHorse
03:30:34.291 Initialize success
03:33:19.057 AVAST engine defs: 12081900
03:33:43.047 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000054
03:33:43.050 Disk 0 Vendor: ST350041 HP22 Size: 476940MB BusType: 3
03:33:43.069 Disk 0 MBR read successfully
03:33:43.072 Disk 0 MBR scan
03:33:43.081 Disk 0 unknown MBR code
03:33:43.085 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 461515 MB offset 63
03:33:43.126 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 15421 MB offset 945184275
03:33:43.181 Disk 0 scanning C:\Windows\system32\drivers
03:33:58.273 Service scanning
03:34:22.885 Modules scanning
03:34:22.895 Disk 0 trace - called modules:
03:34:22.918 ntoskrnl.exe CLASSPNP.SYS disk.sys acpi.sys storport.sys hal.dll nvstor64.sys
03:34:22.923 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004f023e0]
03:34:22.930 3 CLASSPNP.SYS[fffffa6000969c33] -> nt!IofCallDriver -> [0xfffffa8003f79e40]
03:34:22.937 5 acpi.sys[fffffa6000814fde] -> nt!IofCallDriver -> \Device\00000054[0xfffffa8003f74060]
03:34:41.692 AVAST engine scan C:\Windows
03:34:44.328 AVAST engine scan C:\Windows\system32
03:39:37.114 AVAST engine scan C:\Windows\system32\drivers
03:40:03.224 AVAST engine scan C:\Users\CrazyHorse
03:53:32.887 AVAST engine scan C:\ProgramData
03:56:27.086 Scan finished successfully
03:57:40.260 Disk 0 MBR has been saved successfully to "C:\Users\CrazyHorse\Desktop\MBR.dat"
03:57:40.271 The log file has been saved successfully to "C:\Users\CrazyHorse\Desktop\aswMBR.log"