Avast Boot-time scan.
CmdLine - quick
aswBoot.exe /A:"C:" /A:"*" /A:"*" /L:"1033" /heur:80 /pup /archives /IA:0 /KBD:3 /dir:"C:\Program Files\Alwil Software\Avast5"
CmdLine end
SafeBoot: 0
CreateKbThread
new CKbBuffer
CKbBuffer::Init
CKbBuffer::Init end
NtCreateEvent(g_hStopEvent)
dep_osBeginThread - KbThread
CreateKbThread end
NtInitializeRegistry
ReadRegistry
KbThread start
DATA=C:\Documents and Settings\All Users\Application Data\Alwil Software\Avast5
PROG=C:\Program Files\Alwil Software\Avast5
BUILD=677
Microsoft Windows XP Service Pack 3, v.3311
SystemRoot=C:\WINDOWS
TEMP=C:\WINDOWS\TEMP
TMP=C:\WINDOWS\TEMP
ReadRegistry end
CreateTemp
CreateTemp end
aswcmnbDllMain
cmnbInit
aswEnginDllMain(DLL_PROCESS_ATTACH)
InitLog
InitLog end
CmdLine - full
aswBoot.exe /A:"C:" /A:"*" /A:"*" /L:"1033" /heur:80 /pup /archives /IA:0 /KBD:3 /dir:"C:\Program Files\Alwil Software\Avast5"
CmdLine end
Program folder: C:\Program Files\Alwil Software\Avast5
Engine folder: C:\Program Files\Alwil Software\Avast5\defs\10120500
TimeStamp: 4cf64fda
Unschedule
61,00,75,00,74,00,6F,00,63,00,68,00,65,00,63,00,
6B,00,20,00,61,00,75,00,74,00,6F,00,63,00,68,00,
6B,00,20,00,2A,00,00,00,32,00,00,00,2C,00,00,00,
61,00,75,00,74,00,6F,00,63,00,68,00,65,00,63,00,
6B,00,20,00,61,00,75,00,74,00,6F,00,63,00,68,00,
6B,00,20,00,2A,00,00,00,26,00,00,00,84,9A,19,00,
00,00,61,00,75,00,74,00,6F,00,63,00,68,00,65,00,
63,00,6B,00,20,00,73,00,6D,00,72,00,67,00,64,00,
66,00,20,00,43,00,3A,00,5C,00,44,00,6F,00,63,00,
75,00,6D,00,65,00,6E,00,74,00,73,00,20,00,61,00,
6E,00,64,00,20,00,53,00,65,00,74,00,74,00,69,00,
6E,00,67,00,73,00,5C,00,4E,00,65,00,72,00,67,00,
69,00,73,00,20,00,4D,00,61,00,6C,00,61,00,76,00,
65,00,5C,00,41,00,70,00,70,00,6C,00,69,00,63,00,
61,00,74,00,69,00,6F,00,6E,00,20,00,44,00,61,00,
74,00,61,00,5C,00,69,00,6F,00,6C,00,6F,00,5C,00,
00,00,61,00,73,00,77,00,42,00,6F,00,6F,00,74,00,
2E,00,65,00,78,00,65,00,20,00,2F,00,41,00,3A,00,
22,00,43,00,3A,00,22,00,20,00,2F,00,41,00,3A,00,
22,00,2A,00,22,00,20,00,2F,00,41,00,3A,00,22,00,
2A,00,22,00,20,00,2F,00,4C,00,3A,00,22,00,31,00,
30,00,33,00,33,00,22,00,20,00,2F,00,68,00,65,00,
75,00,72,00,3A,00,38,00,30,00,20,00,2F,00,70,00,
75,00,70,00,20,00,2F,00,61,00,72,00,63,00,68,00,
69,00,76,00,65,00,73,00,20,00,2F,00,49,00,41,00,
3A,00,30,00,20,00,2F,00,4B,00,42,00,44,00,3A,00,
33,00,20,00,2F,00,64,00,69,00,72,00,3A,00,22,00,
43,00,3A,00,5C,00,50,00,72,00,6F,00,67,00,72,00,
61,00,6D,00,20,00,46,00,69,00,6C,00,65,00,73,00,
5C,00,41,00,6C,00,77,00,69,00,6C,00,20,00,53,00,
6F,00,66,00,74,00,77,00,61,00,72,00,65,00,5C,00,
41,00,76,00,61,00,73,00,74,00,35,00,22,00,00,00,
00,00,
Unschedule end
LoadResources
LoadResources end
InitReport
InitReport end
Global exclusions:
NtSetEvent(g_hInitEvent) - 1
InitKeyboard
g_dwKbdNum: 3
\Device\KeyboardClass0 failed: 0xC0000034
CPU: Phys(2), Log(2), Aff(2), Feat(0000001f)
FreeMemory: 2838917120
avworkInitialize
FreeMemory: 2838028288
\Device\KeyboardClass0 failed: 0xC0000043
s_dwKbdClassCnt: 3
InitKeyboard end
NtSetEvent(g_hInitEvent) - 2
GetKey
CKbBuffer::Wait
CKbBuffer::Get
CKbBuffer::Get end
CKbBuffer::Wait end
ProcessArea
avfilesScanAdd *MBR0
avfilesScanAdd *BOOTC:
Loading raw access support
avfilesScanAdd *RAW:C:\ [Fs: 000500ff, NTFS; Dev: 07, 00000020]
avfilesScanRealMulti begin
1, 5, 0, 0, 0
GetKey end (4/34)
CKbBuffer::Put
CKbBuffer::Put end
GetKey
1, 5, 1, 0, 0
avfilesScanRealMulti finished
Runtime: 2841312ms
avworkClose
TerminateKbThread
GetKey end (?/00)
CloseKeyboard
CloseKeyboard end
KbThread stop
CKbBuffer::~CKbBuffer
CKbBuffer::~CKbBuffer end
aswEnginDllMain(DLL_PROCESS_DETACH)
cmnbFree
FreeResources
CloseReport
CloseLog