multicabra
2012-11-11, 16:43
Hi, there...
I CAN NOT DOWNLOAD THE DSS FROM ANY OF THE 2 LINKS IN THE 2ND STICKY TREATH OF THIS FORUM
I bought a 2nd hand computer with windows7 ultimate.
found a lot of strange russian programms.
I downloaded Kaspersky Internet Security 2013, 30 dais trial and cannot run, nor unistall it.
cleaned with SUPERAntiSpyware and Search & Destroy.
stiil can not run or uninstall Kaspersky.
downloaded Norton Internet Security.
could not run Norton but uninstall it.
while writing this threat swetim.com opend automaticlally in a new browser.
thanks a lot
DDS (Ver_2012-11-07.01) - NTFS_x86
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 10.7.2
Run by daiketsu at 14:49:51 on 2012-11-11
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.34.3082.18.2047.1024 [GMT 0:00]
.
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\DllHost.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.es/
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
uSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - <orphaned>
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy 2\SDHelper.dll
BHO: Content Blocker Plugin: {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\contentblocker\ie_content_blocker_plugin.dll
BHO: Virtual Keyboard Plugin: {73455575-E40C-433C-9784-C78DC7761455} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\virtualkeyboard\ie_virtual_keyboard_plugin.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - <orphaned>
BHO: {8984B388-A5BB-4DF7-B274-77B879E179DB} - <orphaned>
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Safe Money Plugin: {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\onlinebanking\online_banking_bho.dll
BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - c:\program files\windows live\companion\companioncore.dll
BHO: IMinent WebBooster (BHO): {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} - c:\program files\iminent\Iminent.WebBooster.InternetExplorer.dll
BHO: DealPly: {A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} -
BHO: Help the General-Search Project: {CA4520F3-AE13-4FB1-A513-58E23991C86D} - c:\users\daiketsu\appdata\roaming\media finder\extensions\gencrawler_gc.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: URL Advisor Plugin: {E33CF602-D945-461A-83F0-819F76A199F8} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\urladvisor\klwtbbho.dll
uRun: [Google Update] "c:\users\daiketsu\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [Spybot-S&D Cleaning] "c:\program files\spybot - search & destroy 2\SDCleaner.exe" /autoclean
mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 2013\avp.exe"
mRun: [SDTray] "c:\program files\spybot - search & destroy 2\SDTray.exe"
StartupFolder: c:\users\daiketsu\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:0
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Download with &Media Finder - c:\program files\media finder\hook.html
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {0C4CC089-D306-440D-9772-464E226F6539} - {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\virtualkeyboard\ie_virtual_keyboard_plugin.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\urladvisor\klwtbbho.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy 2\SDHelper.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
TCP: NameServer = 80.58.61.250 80.58.61.254
TCP: Interfaces\{19A3CF75-16C2-4F2F-8C00-EC4804907086} : DHCPNameServer = 80.58.61.250 80.58.61.254
TCP: Interfaces\{241A6BB6-50DD-4220-AA3B-3C3ECB36F5AA} : DHCPNameServer = 80.58.61.250 80.58.61.254
TCP: Interfaces\{241A6BB6-50DD-4220-AA3B-3C3ECB36F5AA}\75C414E4F55493 : DHCPNameServer = 80.58.61.250 80.58.61.254
Handler: base64 - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - <orphaned>
Handler: chrome - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - <orphaned>
Handler: prox - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - <orphaned>
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: SDWinLogon - SDWinLogon.dll
SSODL: WebCheck - <orphaned>
SEH: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - c:\program files\superantispyware\SASSEH.DLL
Hosts: 127.0.0.1 www.spywareinfo.com (http://www.spywareinfo.com)
.
============= SERVICES / DRIVERS ===============
.
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\drivers\klim6.sys [2012-8-2 24408]
R1 kltdi;kltdi;c:\windows\system32\drivers\kltdi.sys [2012-6-8 43608]
R1 kneps;kneps;c:\windows\system32\drivers\kneps.sys [2012-8-13 144344]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664]
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2012-7-11 116608]
R2 AVP;Servicio Kaspersky Anti-Virus;c:\program files\kaspersky lab\kaspersky internet security 2013\avp.exe [2012-8-17 218880]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\spybot - search & destroy 2\SDFSSvc.exe [2012-11-10 1100320]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\spybot - search & destroy 2\SDUpdSvc.exe [2012-11-10 1367576]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\spybot - search & destroy 2\SDWSCSvc.exe [2012-11-10 168384]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2012-2-29 382272]
R3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\drivers\klkbdflt.sys [2012-10-25 25944]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2012-10-25 25944]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [2012-7-26 33792]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;c:\windows\system32\drivers\MijXfilt.sys [2012-4-7 97552]
S3 netr73;Controlador de tarjeta LAN inalámbrica USB RT73 para Vista;c:\windows\system32\drivers\netr73.sys [2009-6-10 545792]
.
=============== Created Last 30 ================
.
2012-11-10 22:02:38 -------- d-----w- c:\programdata\Norton
2012-11-10 22:02:28 -------- d-----w- c:\programdata\NortonInstaller
2012-11-10 20:46:09 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2012-11-10 20:45:59 15224 ----a-w- c:\windows\system32\sdnclean.exe
2012-11-10 20:45:54 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
2012-11-10 20:45:04 -------- d-----w- c:\users\daiketsu\appdata\local\Programs
2012-11-10 19:27:18 -------- d-----w- c:\windows\ELAMBKUP
2012-11-10 19:27:07 -------- d-----w- c:\programdata\Kaspersky Lab
2012-11-10 19:27:07 -------- d-----w- c:\program files\Kaspersky Lab
2012-11-10 19:26:54 75096 ----a-w- c:\windows\system32\drivers\klflt.sys
2012-11-07 23:36:44 -------- d-----w- c:\programdata\Corel Painter 12
2012-11-04 11:33:47 -------- d-----w- C:\HENNING
2012-11-02 20:22:08 -------- d-----w- C:\STOCK-STOCK
2012-11-02 02:33:45 -------- d-----w- c:\programdata\Protexis
2012-11-02 02:02:22 -------- d-----w- c:\program files\gs
2012-11-02 02:00:57 -------- d-----w- c:\program files\common files\Corel
2012-11-02 01:59:20 -------- d-----w- c:\program files\common files\Protexis
2012-11-02 00:52:52 -------- d-----w- c:\users\daiketsu\appdata\roaming\SUPERAntiSpyware.com
2012-11-02 00:52:45 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2012-11-02 00:52:45 -------- d-----w- c:\program files\SUPERAntiSpyware
2012-11-02 00:25:34 -------- d-----w- c:\users\daiketsu\appdata\roaming\LavasoftStatistics
2012-11-02 00:23:40 -------- d-----w- c:\users\daiketsu\appdata\roaming\Ad-Aware Antivirus
2012-11-01 22:54:39 -------- d-----w- c:\program files\common files\SWiSHzone.com
2012-11-01 22:54:37 -------- d-----w- c:\program files\SWiSH miniMax2
2012-11-01 22:19:09 -------- d-----w- c:\users\daiketsu\appdata\local\Microsoft Help
2012-11-01 22:15:40 -------- d-----w- c:\programdata\Corel
2012-11-01 22:07:50 -------- d-----w- c:\program files\Corel
2012-10-30 23:55:57 -------- d-----w- c:\windows\system32\appmgmt
2012-10-30 13:55:47 -------- d-----w- c:\users\daiketsu\appdata\local\{4324E2D9-A4C6-4EF4-BBD4-E1D2B6E89DDC}
2012-10-30 00:47:21 -------- d-----w- c:\users\daiketsu\appdata\local\{02DEE749-3CE8-4DBF-AC3A-22AF9F0D1CD6}
2012-10-29 12:46:52 -------- d-----w- c:\users\daiketsu\appdata\local\{5E27055F-6E1E-4399-B1E2-1F58530A8B8F}
2012-10-28 20:09:03 -------- d-----w- c:\users\daiketsu\appdata\local\{965E5641-DF1E-482D-99D8-D16D520F59A3}
2012-10-28 03:29:46 -------- d-----w- c:\users\daiketsu\appdata\local\{2589FACE-97A5-4A05-9C72-ED2C670E9BEA}
2012-10-27 15:28:54 -------- d-----w- c:\users\daiketsu\appdata\local\{E16F07E6-2AB5-4A56-86CD-7FCDB92120F1}
2012-10-27 00:48:28 -------- d-----w- c:\users\daiketsu\appdata\local\{E54AE089-8E4E-4B67-B69D-3F63F3BFC129}
2012-10-26 11:55:48 -------- d-----w- c:\users\daiketsu\appdata\local\{E2E8F234-88D4-4994-84AC-12BFFADA7101}
2012-10-25 13:53:52 25944 ----a-w- c:\windows\system32\drivers\klmouflt.sys
2012-10-25 13:53:52 25944 ----a-w- c:\windows\system32\drivers\klkbdflt.sys
2012-10-25 08:54:44 -------- d-----w- c:\users\daiketsu\appdata\local\{0B9E9030-CAF4-4927-8B5A-D08605562834}
2012-10-24 12:50:18 -------- d-----w- c:\users\daiketsu\appdata\local\{2087C463-A727-4CA6-97B8-A2DE6FE0C55F}
2012-10-23 11:44:42 -------- d-----w- c:\users\daiketsu\appdata\local\{DCBE1F8B-AB25-4E42-B2BC-25F295472C9F}
2012-10-22 02:05:44 -------- d-----w- c:\users\daiketsu\appdata\local\{83F51F54-E4B5-4385-B368-D7113C977BCB}
2012-10-21 14:05:11 -------- d-----w- c:\users\daiketsu\appdata\local\{3083C41D-C95E-4DEB-B016-6B8C4811A1B2}
2012-10-21 00:01:21 -------- d-----w- c:\users\daiketsu\appdata\local\{9694A2BB-848E-4FFD-9E98-A1A1FC50FA65}
2012-10-20 02:57:37 -------- d-----w- c:\users\daiketsu\appdata\local\{38F80DA2-92D2-46DC-AF36-B5CBA0EA5792}
2012-10-19 10:11:25 -------- d-----w- c:\users\daiketsu\appdata\local\{193D9D28-BF81-4389-AA44-464881497518}
2012-10-18 13:33:51 -------- d-----w- c:\users\daiketsu\appdata\local\{788BD4B1-A295-40F4-8D74-15BF155D782F}
2012-10-17 22:17:57 -------- d-----w- c:\users\daiketsu\appdata\local\{734C6964-45EA-4F07-B2E4-7C5E3303C122}
2012-10-16 12:20:56 -------- d-----w- c:\users\daiketsu\appdata\local\{5382C7AE-9FC9-44AC-A238-A49466D19C67}
2012-10-15 12:04:51 -------- d-----w- c:\users\daiketsu\appdata\local\{6A6A1F6A-1066-44C1-B03C-2B9BA1CC0F04}
2012-10-14 15:35:57 -------- d-----w- c:\users\daiketsu\appdata\local\{666CEF9E-4164-4E66-90E3-686DEFF260BD}
2012-10-13 16:19:46 -------- d-----w- c:\users\daiketsu\appdata\local\{CE7DFE72-9E40-454A-A59E-14A64936697B}
2012-10-13 03:40:37 -------- d-----w- c:\users\daiketsu\appdata\local\{E9771E5F-4F94-491B-AA40-4C97F8CA35E4}
.
==================== Find3M ====================
.
2012-10-11 17:51:07 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-10-11 17:50:27 821736 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-10-11 17:50:27 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-10-09 15:36:14 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-10-09 15:36:14 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-13 16:49:44 144344 ----a-w- c:\windows\system32\drivers\kneps.sys
.
============= FINISH: 14:50:34,46 ===============
aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
Run date: 2012-11-11 15:01:54
-----------------------------
15:01:54.083 OS Version: Windows 6.1.7600
15:01:54.083 Number of processors: 2 586 0xF0D
15:01:54.085 ComputerName: PERSONAL UserName: daiketsu
15:01:56.014 Initialize success
15:03:24.133 AVAST engine defs: 12111100
15:03:41.694 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-0
15:03:41.697 Disk 0 Vendor: SAMSUNG_HD204UI 1AQ10001 Size: 1907729MB BusType: 3
15:03:41.735 Disk 0 MBR read successfully
15:03:41.738 Disk 0 MBR scan
15:03:41.760 Disk 0 Windows 7 default MBR code
15:03:41.814 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 1907724 MB offset 2048
15:03:41.831 Disk 0 scanning sectors +3907020975
15:03:41.897 Disk 0 scanning C:\Windows\system32\drivers
15:03:52.776 Service scanning
15:04:14.429 Modules scanning
15:04:21.018 Disk 0 trace - called modules:
15:04:21.041 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
15:04:21.045 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86a7d7c0]
15:04:21.057 3 CLASSPNP.SYS[8ad9759e] -> nt!IofCallDriver -> [0x8697c918]
15:04:21.064 5 ACPI.sys[842173b2] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-0[0x85ca7908]
15:04:22.789 AVAST engine scan C:\Windows
15:04:27.161 AVAST engine scan C:\Windows\system32
15:07:35.430 AVAST engine scan C:\Windows\system32\drivers
15:07:50.819 AVAST engine scan C:\Users\daiketsu
15:10:16.424 Disk 0 MBR has been saved successfully to "C:\Users\daiketsu\Desktop\MBR.dat"
15:10:16.436 The log file has been saved successfully to "C:\Users\daiketsu\Desktop\aswMBR.txt"
I CAN NOT DOWNLOAD THE DSS FROM ANY OF THE 2 LINKS IN THE 2ND STICKY TREATH OF THIS FORUM
I bought a 2nd hand computer with windows7 ultimate.
found a lot of strange russian programms.
I downloaded Kaspersky Internet Security 2013, 30 dais trial and cannot run, nor unistall it.
cleaned with SUPERAntiSpyware and Search & Destroy.
stiil can not run or uninstall Kaspersky.
downloaded Norton Internet Security.
could not run Norton but uninstall it.
while writing this threat swetim.com opend automaticlally in a new browser.
thanks a lot
DDS (Ver_2012-11-07.01) - NTFS_x86
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 10.7.2
Run by daiketsu at 14:49:51 on 2012-11-11
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.34.3082.18.2047.1024 [GMT 0:00]
.
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\DllHost.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\daiketsu\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.es/
uSearch Bar = hxxp://www.google.com/ie
uSearch Page = hxxp://www.google.com
uSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - <orphaned>
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy 2\SDHelper.dll
BHO: Content Blocker Plugin: {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\contentblocker\ie_content_blocker_plugin.dll
BHO: Virtual Keyboard Plugin: {73455575-E40C-433C-9784-C78DC7761455} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\virtualkeyboard\ie_virtual_keyboard_plugin.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - <orphaned>
BHO: {8984B388-A5BB-4DF7-B274-77B879E179DB} - <orphaned>
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Safe Money Plugin: {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\onlinebanking\online_banking_bho.dll
BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - c:\program files\windows live\companion\companioncore.dll
BHO: IMinent WebBooster (BHO): {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} - c:\program files\iminent\Iminent.WebBooster.InternetExplorer.dll
BHO: DealPly: {A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} -
BHO: Help the General-Search Project: {CA4520F3-AE13-4FB1-A513-58E23991C86D} - c:\users\daiketsu\appdata\roaming\media finder\extensions\gencrawler_gc.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: URL Advisor Plugin: {E33CF602-D945-461A-83F0-819F76A199F8} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\urladvisor\klwtbbho.dll
uRun: [Google Update] "c:\users\daiketsu\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [Spybot-S&D Cleaning] "c:\program files\spybot - search & destroy 2\SDCleaner.exe" /autoclean
mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 2013\avp.exe"
mRun: [SDTray] "c:\program files\spybot - search & destroy 2\SDTray.exe"
StartupFolder: c:\users\daiketsu\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:0
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Download with &Media Finder - c:\program files\media finder\hook.html
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {0C4CC089-D306-440D-9772-464E226F6539} - {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\virtualkeyboard\ie_virtual_keyboard_plugin.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\urladvisor\klwtbbho.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy 2\SDHelper.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
TCP: NameServer = 80.58.61.250 80.58.61.254
TCP: Interfaces\{19A3CF75-16C2-4F2F-8C00-EC4804907086} : DHCPNameServer = 80.58.61.250 80.58.61.254
TCP: Interfaces\{241A6BB6-50DD-4220-AA3B-3C3ECB36F5AA} : DHCPNameServer = 80.58.61.250 80.58.61.254
TCP: Interfaces\{241A6BB6-50DD-4220-AA3B-3C3ECB36F5AA}\75C414E4F55493 : DHCPNameServer = 80.58.61.250 80.58.61.254
Handler: base64 - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - <orphaned>
Handler: chrome - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - <orphaned>
Handler: prox - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - <orphaned>
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: SDWinLogon - SDWinLogon.dll
SSODL: WebCheck - <orphaned>
SEH: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - c:\program files\superantispyware\SASSEH.DLL
Hosts: 127.0.0.1 www.spywareinfo.com (http://www.spywareinfo.com)
.
============= SERVICES / DRIVERS ===============
.
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\drivers\klim6.sys [2012-8-2 24408]
R1 kltdi;kltdi;c:\windows\system32\drivers\kltdi.sys [2012-6-8 43608]
R1 kneps;kneps;c:\windows\system32\drivers\kneps.sys [2012-8-13 144344]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664]
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2012-7-11 116608]
R2 AVP;Servicio Kaspersky Anti-Virus;c:\program files\kaspersky lab\kaspersky internet security 2013\avp.exe [2012-8-17 218880]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\spybot - search & destroy 2\SDFSSvc.exe [2012-11-10 1100320]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\spybot - search & destroy 2\SDUpdSvc.exe [2012-11-10 1367576]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\spybot - search & destroy 2\SDWSCSvc.exe [2012-11-10 168384]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2012-2-29 382272]
R3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\drivers\klkbdflt.sys [2012-10-25 25944]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2012-10-25 25944]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [2012-7-26 33792]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;c:\windows\system32\drivers\MijXfilt.sys [2012-4-7 97552]
S3 netr73;Controlador de tarjeta LAN inalámbrica USB RT73 para Vista;c:\windows\system32\drivers\netr73.sys [2009-6-10 545792]
.
=============== Created Last 30 ================
.
2012-11-10 22:02:38 -------- d-----w- c:\programdata\Norton
2012-11-10 22:02:28 -------- d-----w- c:\programdata\NortonInstaller
2012-11-10 20:46:09 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2012-11-10 20:45:59 15224 ----a-w- c:\windows\system32\sdnclean.exe
2012-11-10 20:45:54 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
2012-11-10 20:45:04 -------- d-----w- c:\users\daiketsu\appdata\local\Programs
2012-11-10 19:27:18 -------- d-----w- c:\windows\ELAMBKUP
2012-11-10 19:27:07 -------- d-----w- c:\programdata\Kaspersky Lab
2012-11-10 19:27:07 -------- d-----w- c:\program files\Kaspersky Lab
2012-11-10 19:26:54 75096 ----a-w- c:\windows\system32\drivers\klflt.sys
2012-11-07 23:36:44 -------- d-----w- c:\programdata\Corel Painter 12
2012-11-04 11:33:47 -------- d-----w- C:\HENNING
2012-11-02 20:22:08 -------- d-----w- C:\STOCK-STOCK
2012-11-02 02:33:45 -------- d-----w- c:\programdata\Protexis
2012-11-02 02:02:22 -------- d-----w- c:\program files\gs
2012-11-02 02:00:57 -------- d-----w- c:\program files\common files\Corel
2012-11-02 01:59:20 -------- d-----w- c:\program files\common files\Protexis
2012-11-02 00:52:52 -------- d-----w- c:\users\daiketsu\appdata\roaming\SUPERAntiSpyware.com
2012-11-02 00:52:45 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2012-11-02 00:52:45 -------- d-----w- c:\program files\SUPERAntiSpyware
2012-11-02 00:25:34 -------- d-----w- c:\users\daiketsu\appdata\roaming\LavasoftStatistics
2012-11-02 00:23:40 -------- d-----w- c:\users\daiketsu\appdata\roaming\Ad-Aware Antivirus
2012-11-01 22:54:39 -------- d-----w- c:\program files\common files\SWiSHzone.com
2012-11-01 22:54:37 -------- d-----w- c:\program files\SWiSH miniMax2
2012-11-01 22:19:09 -------- d-----w- c:\users\daiketsu\appdata\local\Microsoft Help
2012-11-01 22:15:40 -------- d-----w- c:\programdata\Corel
2012-11-01 22:07:50 -------- d-----w- c:\program files\Corel
2012-10-30 23:55:57 -------- d-----w- c:\windows\system32\appmgmt
2012-10-30 13:55:47 -------- d-----w- c:\users\daiketsu\appdata\local\{4324E2D9-A4C6-4EF4-BBD4-E1D2B6E89DDC}
2012-10-30 00:47:21 -------- d-----w- c:\users\daiketsu\appdata\local\{02DEE749-3CE8-4DBF-AC3A-22AF9F0D1CD6}
2012-10-29 12:46:52 -------- d-----w- c:\users\daiketsu\appdata\local\{5E27055F-6E1E-4399-B1E2-1F58530A8B8F}
2012-10-28 20:09:03 -------- d-----w- c:\users\daiketsu\appdata\local\{965E5641-DF1E-482D-99D8-D16D520F59A3}
2012-10-28 03:29:46 -------- d-----w- c:\users\daiketsu\appdata\local\{2589FACE-97A5-4A05-9C72-ED2C670E9BEA}
2012-10-27 15:28:54 -------- d-----w- c:\users\daiketsu\appdata\local\{E16F07E6-2AB5-4A56-86CD-7FCDB92120F1}
2012-10-27 00:48:28 -------- d-----w- c:\users\daiketsu\appdata\local\{E54AE089-8E4E-4B67-B69D-3F63F3BFC129}
2012-10-26 11:55:48 -------- d-----w- c:\users\daiketsu\appdata\local\{E2E8F234-88D4-4994-84AC-12BFFADA7101}
2012-10-25 13:53:52 25944 ----a-w- c:\windows\system32\drivers\klmouflt.sys
2012-10-25 13:53:52 25944 ----a-w- c:\windows\system32\drivers\klkbdflt.sys
2012-10-25 08:54:44 -------- d-----w- c:\users\daiketsu\appdata\local\{0B9E9030-CAF4-4927-8B5A-D08605562834}
2012-10-24 12:50:18 -------- d-----w- c:\users\daiketsu\appdata\local\{2087C463-A727-4CA6-97B8-A2DE6FE0C55F}
2012-10-23 11:44:42 -------- d-----w- c:\users\daiketsu\appdata\local\{DCBE1F8B-AB25-4E42-B2BC-25F295472C9F}
2012-10-22 02:05:44 -------- d-----w- c:\users\daiketsu\appdata\local\{83F51F54-E4B5-4385-B368-D7113C977BCB}
2012-10-21 14:05:11 -------- d-----w- c:\users\daiketsu\appdata\local\{3083C41D-C95E-4DEB-B016-6B8C4811A1B2}
2012-10-21 00:01:21 -------- d-----w- c:\users\daiketsu\appdata\local\{9694A2BB-848E-4FFD-9E98-A1A1FC50FA65}
2012-10-20 02:57:37 -------- d-----w- c:\users\daiketsu\appdata\local\{38F80DA2-92D2-46DC-AF36-B5CBA0EA5792}
2012-10-19 10:11:25 -------- d-----w- c:\users\daiketsu\appdata\local\{193D9D28-BF81-4389-AA44-464881497518}
2012-10-18 13:33:51 -------- d-----w- c:\users\daiketsu\appdata\local\{788BD4B1-A295-40F4-8D74-15BF155D782F}
2012-10-17 22:17:57 -------- d-----w- c:\users\daiketsu\appdata\local\{734C6964-45EA-4F07-B2E4-7C5E3303C122}
2012-10-16 12:20:56 -------- d-----w- c:\users\daiketsu\appdata\local\{5382C7AE-9FC9-44AC-A238-A49466D19C67}
2012-10-15 12:04:51 -------- d-----w- c:\users\daiketsu\appdata\local\{6A6A1F6A-1066-44C1-B03C-2B9BA1CC0F04}
2012-10-14 15:35:57 -------- d-----w- c:\users\daiketsu\appdata\local\{666CEF9E-4164-4E66-90E3-686DEFF260BD}
2012-10-13 16:19:46 -------- d-----w- c:\users\daiketsu\appdata\local\{CE7DFE72-9E40-454A-A59E-14A64936697B}
2012-10-13 03:40:37 -------- d-----w- c:\users\daiketsu\appdata\local\{E9771E5F-4F94-491B-AA40-4C97F8CA35E4}
.
==================== Find3M ====================
.
2012-10-11 17:51:07 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-10-11 17:50:27 821736 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-10-11 17:50:27 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-10-09 15:36:14 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-10-09 15:36:14 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-13 16:49:44 144344 ----a-w- c:\windows\system32\drivers\kneps.sys
.
============= FINISH: 14:50:34,46 ===============
aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
Run date: 2012-11-11 15:01:54
-----------------------------
15:01:54.083 OS Version: Windows 6.1.7600
15:01:54.083 Number of processors: 2 586 0xF0D
15:01:54.085 ComputerName: PERSONAL UserName: daiketsu
15:01:56.014 Initialize success
15:03:24.133 AVAST engine defs: 12111100
15:03:41.694 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-0
15:03:41.697 Disk 0 Vendor: SAMSUNG_HD204UI 1AQ10001 Size: 1907729MB BusType: 3
15:03:41.735 Disk 0 MBR read successfully
15:03:41.738 Disk 0 MBR scan
15:03:41.760 Disk 0 Windows 7 default MBR code
15:03:41.814 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 1907724 MB offset 2048
15:03:41.831 Disk 0 scanning sectors +3907020975
15:03:41.897 Disk 0 scanning C:\Windows\system32\drivers
15:03:52.776 Service scanning
15:04:14.429 Modules scanning
15:04:21.018 Disk 0 trace - called modules:
15:04:21.041 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
15:04:21.045 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86a7d7c0]
15:04:21.057 3 CLASSPNP.SYS[8ad9759e] -> nt!IofCallDriver -> [0x8697c918]
15:04:21.064 5 ACPI.sys[842173b2] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-0[0x85ca7908]
15:04:22.789 AVAST engine scan C:\Windows
15:04:27.161 AVAST engine scan C:\Windows\system32
15:07:35.430 AVAST engine scan C:\Windows\system32\drivers
15:07:50.819 AVAST engine scan C:\Users\daiketsu
15:10:16.424 Disk 0 MBR has been saved successfully to "C:\Users\daiketsu\Desktop\MBR.dat"
15:10:16.436 The log file has been saved successfully to "C:\Users\daiketsu\Desktop\aswMBR.txt"