Here is the log from aswMBR ... looks disconcerting (there was a lot of red)
aswMBR version 0.9.9.1297 Copyright(c) 2011 AVAST Software
Run date: 2012-01-12 15:21:24
-----------------------------
15:21:24.343 OS Version: Windows 6.0.6002 Service Pack 2
15:21:24.343 Number of processors: 2 586 0xF0B
15:21:24.345 ComputerName: STEPHEN-PC UserName:
15:21:33.567 Initialize success
15:23:25.501 AVAST engine defs: 12011200
15:23:41.477 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000032
15:23:41.480 Disk 0 Vendor: WDC_WD32 12.0 Size: 305245MB BusType: 6
15:23:41.482 Device \Device\00000041 -> \??\SCSI#Disk&Ven_WDC_WD32&Prod_00AAJS-00VWA#4&12a0b57c&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} not found
15:23:41.486 Disk 0 MBR read error 0
15:23:41.489 Disk 0 MBR scan
15:23:41.493 Disk 0 unknown MBR code
15:23:41.497 MBR BIOS signature not found 0
15:23:41.500 Disk 0 scanning sectors +625139712
15:23:41.535 Disk 0 scanning C:\Windows\system32\drivers
15:23:41.970 File: C:\Windows\system32\drivers\afd.sys **INFECTED** Win32:Aluroot-B [Rtk]
15:23:47.117 File: C:\Windows\system32\drivers\netbt.sys **INFECTED** Win32:Zeroot [Rtk]
15:23:53.279 File: C:\Windows\system32\drivers\Wdf01000.sys **INFECTED** Win32:RLoader-B
15:23:53.557 Disk 0 trace - called modules:
15:23:53.574 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x87f39ff0]<<
15:23:53.582 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8634c8e0]
15:23:53.591 3 CLASSPNP.SYS[8279f8b3] -> nt!IofCallDriver -> [0x87da32e8]
15:23:53.599 \Driver\00001060[0x87da9478] -> IRP_MJ_CREATE -> 0x87f39ff0
15:23:58.627 AVAST engine scan C:\Windows
15:24:01.441 AVAST engine scan C:\Windows\system32
15:35:01.341 AVAST engine scan C:\Windows\system32\drivers
15:35:02.345 File: C:\Windows\system32\drivers\afd.sys **INFECTED** Win32:Aluroot-B [Rtk]
15:35:12.982 File: C:\Windows\system32\drivers\netbt.sys **INFECTED** Win32:Zeroot [Rtk]
15:35:20.792 File: C:\Windows\system32\drivers\Wdf01000.sys **INFECTED** Win32:RLoader-B
15:35:24.407 AVAST engine scan C:\Users\Administrator
15:37:38.530 File: C:\Users\Administrator\AppData\Local\Temp\jar_cache2441297853792215642.tmp **INFECTED** Win32:Kryptik-DJD [Trj]
15:37:38.685 File: C:\Users\Administrator\AppData\Local\Temp\jar_cache2546951413663940763.tmp **INFECTED** Win32:MalOb-GF [Cryp]
15:37:38.736 File: C:\Users\Administrator\AppData\Local\Temp\jar_cache2740558627932482271.tmp **INFECTED** Win32:Kryptik-DJD [Trj]
15:37:38.935 File: C:\Users\Administrator\AppData\Local\Temp\jar_cache4416902755111729394.tmp **INFECTED** Win32:Kryptik-DKN [Trj]
15:37:39.177 File: C:\Users\Administrator\AppData\Local\Temp\jar_cache5554113741605944304.tmp **INFECTED** Win32:MalOb-GS [Cryp]
15:37:39.449 File: C:\Users\Administrator\AppData\Local\Temp\jar_cache6855520816091083099.tmp **INFECTED** Win32:MalOb-GS [Cryp]
15:37:39.552 File: C:\Users\Administrator\AppData\Local\Temp\jar_cache7262576682993569311.tmp **INFECTED** Win32:Kryptik-DJD [Trj]
15:37:39.661 File: C:\Users\Administrator\AppData\Local\Temp\jar_cache7309834498984758723.tmp **INFECTED** Win32:MalOb-GF [Cryp]
15:37:39.753 File: C:\Users\Administrator\AppData\Local\Temp\jar_cache7645806635774182343.tmp **INFECTED** Win32:Renosa-J [Wrm]
15:37:39.849 File: C:\Users\Administrator\AppData\Local\Temp\jar_cache8500703002762741723.tmp **INFECTED** Win32:Kryptik-DJD [Trj]
15:43:42.294 Disk 0 MBR has been saved successfully to "C:\Users\Administrator\Documents\MBR.dat"
15:43:42.376 The log file has been saved successfully to "C:\Users\Administrator\Documents\aswMBR.txt"
For Bootkit Remover, I recieved the following error ATA_PASS_THROUGH_DIRECT is not supported by your disc controller
SCSI_PASS_THROUGH_DIRECT will be use for disc I/O
This is the log that appeared.
Bootkit Remover
(c) 2009 Esage Lab
www.esagelab.com
Program version: 1.2.0.1
OS Version: Microsoft Windows Vista Home Premium Edition Service Pack 2 (build 6
002), 32-bit
System volume is \\.\C:
\\.\C: -> \\.\PhysicalDrive0 at offset 0x00000000`00100000
ATA_Read(): DeviceIoControl() ERROR 1
Boot sector MD5 is: 0ec6b2481fc707d1e901dc2a875f2826
Size Device Name MBR Status
--------------------------------------------
298 GB \\.\PhysicalDrive0 OK (DOS/Win32 Boot code found)
Done;
Press any key to quit...
and FixedParts displayed this
ListParts by Farbar
Ran by Administrator on 12-01-2012 at 15:56:18
Windows Vista (X86)
Running From: C:\Users\Administrator\Downloads
************************************************************
========================= Memory info ======================
Percentage of memory in use: 73%
Total physical RAM: 3070.45 MB
Available physical RAM: 822.81 MB
Total Pagefile: 6365.94 MB
Available Pagefile: 3737.42 MB
Total Virtual: 2047.88 MB
Available Virtual: 1965.83 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:298.09 GB) (Free:38.58 GB) NTFS ==>[Drive with boot components (obtanied from BCD)]
There are no fixed disks to show.
****** End Of Log ******
And yes AVG was uninstalled last night before using GMER and DDS.