This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

aswMBR closed while running

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, it's hard for me to pin point my issue. A few things that have been happening.  When I shut down my computer these images and web pages show up about gardening or other advertisements, my screen pauses for a few moments and then goes back to the desktop. Just yesterday  while working it closed out my program on me without notice, and just a few minutes ago I ran aswMBR. It was performing the scan when a sign popped up saying it auto closed. Thanks for your help in advance.

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-11-20 11:18:03
—————————–
11:18:03.075    OS Version: Windows x64 6.1.7600 
11:18:03.075    Number of processors: 6 586 0x200
11:18:03.076    ComputerName: ROBERTOV-PC  UserName: Roberto V
11:18:05.735    Initialize success
11:18:05.738    VM: initialized successfully
11:18:05.753    VM: Amd CPU BiosDisabled 
11:18:42.209    AVAST engine defs: 15112000
11:20:30.792    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP3T0L0-3
11:20:30.794    Disk 0 Vendor: WDC_WD1002FAEX-00Z3A0 05.01D05 Size: 953869MB BusType: 3
11:20:31.177    Disk 0 MBR read successfully
11:20:31.179    Disk 0 MBR scan
11:20:31.183    Disk 0 Windows 7 default MBR code
11:20:31.197    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 2048
11:20:31.202    Disk 0 Boot: NTFS     code=1
11:20:31.238    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS       953767 MB offset 206848
11:20:31.587    Disk 0 scanning C:\Windows\system32\drivers
11:21:06.071    Service scanning
11:21:23.895    Modules scanning
11:21:24.226    Disk 0 trace - called modules:
11:21:24.244    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys 
11:21:24.247    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007792060]
11:21:24.251    3 CLASSPNP.SYS[fffff8800190043f] -> nt!IofCallDriver -> [0xfffffa80076bf9b0]
11:21:24.254    5 ACPI.sys[fffff88000e34781] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP3T0L0-3[0xfffffa800779a060]
11:21:26.832    AVAST engine scan C:\Windows
11:21:43.033    AVAST engine scan C:\Windows\system32
11:33:36.857    AVAST engine scan C:\Windows\system32\drivers
11:35:55.967    AVAST engine scan C:\Users\Roberto V
11:40:12.269    Disk 0 MBR has been saved successfully to "C:\Users\Roberto V\Desktop\MBR.dat"
11:40:12.278    The log file has been saved successfully to "C:\Users\Roberto V\Desktop\aswMBR.txt"
 
 
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-11-20 11:18:03
—————————–
11:18:03.075    OS Version: Windows x64 6.1.7600 
11:18:03.075    Number of processors: 6 586 0x200
11:18:03.076    ComputerName: ROBERTOV-PC  UserName: Roberto V
11:18:05.735    Initialize success
11:18:05.738    VM: initialized successfully
11:18:05.753    VM: Amd CPU BiosDisabled 
11:18:42.209    AVAST engine defs: 15112000
11:20:30.792    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP3T0L0-3
11:20:30.794    Disk 0 Vendor: WDC_WD1002FAEX-00Z3A0 05.01D05 Size: 953869MB BusType: 3
11:20:31.177    Disk 0 MBR read successfully
11:20:31.179    Disk 0 MBR scan
11:20:31.183    Disk 0 Windows 7 default MBR code
11:20:31.197    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 2048
11:20:31.202    Disk 0 Boot: NTFS     code=1
11:20:31.238    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS       953767 MB offset 206848
11:20:31.587    Disk 0 scanning C:\Windows\system32\drivers
11:21:06.071    Service scanning
11:21:23.895    Modules scanning
11:21:24.226    Disk 0 trace - called modules:
11:21:24.244    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys 
11:21:24.247    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007792060]
11:21:24.251    3 CLASSPNP.SYS[fffff8800190043f] -> nt!IofCallDriver -> [0xfffffa80076bf9b0]
11:21:24.254    5 ACPI.sys[fffff88000e34781] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP3T0L0-3[0xfffffa800779a060]
11:21:26.832    AVAST engine scan C:\Windows
11:21:43.033    AVAST engine scan C:\Windows\system32
11:33:36.857    AVAST engine scan C:\Windows\system32\drivers
11:35:55.967    AVAST engine scan C:\Users\Roberto V
11:40:12.269    Disk 0 MBR has been saved successfully to "C:\Users\Roberto V\Desktop\MBR.dat"
11:40:12.278    The log file has been saved successfully to "C:\Users\Roberto V\Desktop\aswMBR.txt"
11:56:05.998    Disk 0 MBR has been saved successfully to "C:\Users\Roberto V\Desktop\MBR.dat"
11:56:06.045    The log file has been saved successfully to "C:\Users\Roberto V\Desktop\aswMBR.txt"
 
 
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-11-20 11:18:03
—————————–
11:18:03.075    OS Version: Windows x64 6.1.7600 
11:18:03.075    Number of processors: 6 586 0x200
11:18:03.076    ComputerName: ROBERTOV-PC  UserName: Roberto V
11:18:05.735    Initialize success
11:18:05.738    VM: initialized successfully
11:18:05.753    VM: Amd CPU BiosDisabled 
11:18:42.209    AVAST engine defs: 15112000
11:20:30.792    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP3T0L0-3
11:20:30.794    Disk 0 Vendor: WDC_WD1002FAEX-00Z3A0 05.01D05 Size: 953869MB BusType: 3
11:20:31.177    Disk 0 MBR read successfully
11:20:31.179    Disk 0 MBR scan
11:20:31.183    Disk 0 Windows 7 default MBR code
11:20:31.197    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 2048
11:20:31.202    Disk 0 Boot: NTFS     code=1
11:20:31.238    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS       953767 MB offset 206848
11:20:31.587    Disk 0 scanning C:\Windows\system32\drivers
11:21:06.071    Service scanning
11:21:23.895    Modules scanning
11:21:24.226    Disk 0 trace - called modules:
11:21:24.244    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys 
11:21:24.247    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007792060]
11:21:24.251    3 CLASSPNP.SYS[fffff8800190043f] -> nt!IofCallDriver -> [0xfffffa80076bf9b0]
11:21:24.254    5 ACPI.sys[fffff88000e34781] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP3T0L0-3[0xfffffa800779a060]
11:21:26.832    AVAST engine scan C:\Windows
11:21:43.033    AVAST engine scan C:\Windows\system32
11:33:36.857    AVAST engine scan C:\Windows\system32\drivers
11:35:55.967    AVAST engine scan C:\Users\Roberto V
11:40:12.269    Disk 0 MBR has been saved successfully to "C:\Users\Roberto V\Desktop\MBR.dat"
11:40:12.278    The log file has been saved successfully to "C:\Users\Roberto V\Desktop\aswMBR.txt"
11:56:05.998    Disk 0 MBR has been saved successfully to "C:\Users\Roberto V\Desktop\MBR.dat"
11:56:06.045    The log file has been saved successfully to "C:\Users\Roberto V\Desktop\aswMBR.txt"
12:23:12.649    Disk 0 MBR has been saved successfully to "C:\Users\Roberto V\Desktop\MBR.dat"
12:23:12.661    The log file has been saved successfully to "C:\Users\Roberto V\Desktop\aswMBR.txt"
 
 
Please print out or make a copy in notepad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

Please download and run the following tool to help allow other programs to run. (courtesy of BleepingComputer.com)
There are 6 different versions. If one of them won't run then download and try to run the other one.
Vista and Win7 users need to right click and choose Run as Admin
You only need to get one of them to run, not all of them.
  • rkill.exe
  • rkill.com
  • rkill.scr
  • rkill.pif
  • WiNlOgOn.exe
  • uSeRiNiT.exe
~~~~~~~~~~~~~`

[external image: xlK5Hdb.png]Farbar Recovery Scan Tool (FRST) Scan
  • Please download Farbar Recovery Scan Tool (x32) or Farbar Recovery Scan Tool (x64) and save the file to your Desktop.
  • Note: Download and run the version compatible with your system (32 or 64-bit). Download both if you're unsure; only one will run.
  • Right-Click FRST.exe / FRST64.exe and select [external image: AVOiBNU.jpg]Run as administrator to run the programme.
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the programme run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy the contents of both logs and paste in your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI