fabthiombiano
New member
Admin Edit, first topic: http://forums.spybot.info/showthread.php?70010-quot-DCOM-Server-Process-Launcher-Service-terminated
Hello, like recommended I have my DDS Log and aswMBR reports to post. However, i have few things to notice before. I did launch Erunt to backup my files and it went great. However it wouldnt let me run aswMBR so i launch it in safe mode. When i restarted, it appeared a message that the registry backed up with Erunt has a problem, so i tried to launch another one but it told me that it cant delete all the files from previous save so i canceled it. Another one is, i have already run combofix before hand but luckily it didnt finish the process because the computer turned off! Iam really desperate please help !
P.S= Internet explorer is not running anymore, and the ads running in background still there!
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16750 BrowserJavaVersion: 10.13.2
Run by user at 21:18:35 on 2014-01-10
Microsoft Windows 7 Professionnel 6.1.7601.1.1252.33.1036.18.4091.2052 [GMT -8:00]
.
AV: Kaspersky Internet Security *Disabled/Outdated* {2EAA32A5-1EE1-1B22-95DA-337730C6E984}
SP: Kaspersky Internet Security *Disabled/Updated* {95CBD341-38DB-14AC-AF6A-08054B41A339}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
FW: Kaspersky Internet Security *Disabled* {1691B380-548E-1A7A-BE85-9A42CE15AEFF}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\HitmanPro\hmpsched.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Users\user\AppData\Local\StormAlerts\StormAlerts.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\Macromed\Flash\FlashUtil64_11_9_900_170_ActiveX.exe
C:\Windows\system32\RunDll32.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
BHO: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Programme d'aide de l'Assistant de connexion Windows Live ID: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} -
mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe"
mRun: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
dRunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
StartupFolder: C:\Users\user\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk -
StartupFolder: C:\Users\user\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ERUNTA~1.LNK - C:\Program Files (x86)\ERUNT\AUTOBACK.EXE
StartupFolder: C:\Users\user\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\MAGICD~1.LNK -
StartupFolder: C:\Users\user\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\STORMA~2.LNK - C:\Users\user\AppData\Local\StormAlerts\StormAlerts.exe
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDriveTypeAutoRun = dword:60
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htm
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: E&xporter vers Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - {17A84966-F1E9-4645-AA9E-5E771EE1C859} - C:\Program Files (x86)\Nuclear Coffee\VideoGet\Plugins\VideoGet_IE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{B0A727C2-F9BD-49EE-9C21-A4966D502B5F} : DHCPNameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{B0A727C2-F9BD-49EE-9C21-A4966D502B5F}\16474777966696 : DHCPNameServer = 192.168.5.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Notify: SDWinLogon - SDWinLogon.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
x64-BHO: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\ievkbd.dll
x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll
x64-BHO: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\klwtbbho.dll
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\ievkbd.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-IE: {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - {17A84966-F1E9-4645-AA9E-5E771EE1C859} - C:\Program Files (x86)\Nuclear Coffee\VideoGet\Plugins\VideoGet_IE_x64.dll
x64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\klwtbbho.dll
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
x64-DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: klogon - C:\Windows\System32\klogon.dll
x64-SSODL: WebCheck - <orphaned>
x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
.
============= SERVICES / DRIVERS ===============
.
R1 kl2;kl2;C:\Windows\System32\drivers\kl2.sys [2011-3-4 11864]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\System32\drivers\klim6.sys [2011-3-10 29488]
R2 HitmanProScheduler;HitmanPro Scheduler;C:\Program Files\HitmanPro\hmpsched.exe [2014-1-10 109352]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2014-1-10 3921880]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2014-1-10 1042272]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2014-1-10 171416]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;C:\Windows\System32\drivers\k57nd60a.sys [2009-6-10 270848]
R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\System32\drivers\klmouflt.sys [2009-11-2 22544]
S2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe [2011-4-24 206448]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.EXE [2012-6-11 193616]
S3 BBUpdate;BBUpdate;C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.EXE [2012-6-11 240208]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2012-4-13 48488]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2012-3-8 1492840]
S3 StorSvc;Service de stockage;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2012-5-7 59392]
S3 WatAdminSvc;Service Windows Activation Technologies;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-1-18 1255736]
S4 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-10-2 3064000]
S4 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-9-5 171680]
S4 SpyHunter 4 Service;SpyHunter 4 Service;C:\PROGRA~2\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [2010-5-18 327064]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== File Associations ===============
.
ShellExec: dreamweaver.exe: Open="C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS5.5\dreamweaver.exe", "%1"
.
=============== Created Last 30 ================
.
2014-01-10 10:39:27 -------- d-----w- C:\AdwCleaner
2014-01-10 09:40:19 -------- d-----w- C:\Users\user\AppData\Local\Weather_Warnings_LLC
2014-01-10 09:38:59 -------- d-----w- C:\Users\user\AppData\Local\StormAlerts
2014-01-10 09:37:47 -------- d-----w- C:\Program Files\HitmanPro
2014-01-10 09:36:35 -------- d-----w- C:\ProgramData\HitmanPro
2014-01-10 09:22:59 343040 ----a-w- C:\Windows\System32\drivers\usbhub.sys.bak
2014-01-10 09:21:58 146432 ----a-w- C:\Windows\System32\drivers\rmcast.sys.bak
2014-01-10 09:20:57 148352 ----a-w- C:\Windows\System32\drivers\nvraid.sys.bak
2014-01-10 09:19:59 78848 ----a-w- C:\Windows\System32\drivers\IPMIDrv.sys.bak
2014-01-10 09:18:59 64512 ----a-w- C:\Windows\System32\drivers\amdk8.sys.bak
2014-01-10 09:15:40 -------- d-----w- C:\Program Files (x86)\BearShare Applications
2014-01-10 09:08:04 21040 ----a-w- C:\Windows\System32\sdnclean64.exe
2014-01-10 09:08:01 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2014-01-10 09:07:51 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-01-10 09:07:23 -------- d-----w- C:\Users\user\AppData\Local\Programs
2014-01-10 03:16:45 -------- d-----w- C:\$RECYCLE.BIN
2014-01-10 02:57:19 98816 ----a-w- C:\Windows\sed.exe
2014-01-10 02:57:19 256000 ----a-w- C:\Windows\PEV.exe
2014-01-10 02:57:19 208896 ----a-w- C:\Windows\MBR.exe
2014-01-10 02:57:09 -------- d-----w- C:\ComboFix
2014-01-09 11:24:48 -------- d-----w- C:\TDSSKiller_Quarantine
2014-01-09 11:18:17 -------- d-----w- C:\Users\user\.android
2014-01-09 11:18:10 -------- d-----w- C:\Users\user\AppData\Local\cache
2014-01-09 11:17:56 -------- d-----w- C:\Users\user\AppData\Roaming\newnext.me
2014-01-09 11:17:49 -------- d-----w- C:\Users\user\AppData\Local\genienext
2014-01-09 09:37:58 -------- d-----w- C:\Users\user\AppData\Local\{4AAB9E65-9CD0-481E-88FE-AEB81B77BAC7}
2014-01-08 19:32:51 -------- d-----w- C:\Users\user\AppData\Local\{FC914F1A-95F1-4AA3-821B-9AFFB710F9B8}
2014-01-08 03:47:48 -------- d--h--w- C:\ProgramData\{$1284-9213-2940-1289$}
2014-01-07 19:27:12 -------- d-----w- C:\Users\user\AppData\Local\{71FDF0EA-60DA-433D-A05E-AB7A1F70145D}
2014-01-06 18:26:22 -------- d-----w- C:\Users\user\AppData\Local\{4BC44031-D519-4A5F-B031-ED7426808515}
2014-01-05 21:40:03 -------- d-----w- C:\Users\user\AppData\Local\{1C63917D-BA19-4929-BA1F-EB7CCBD22E3C}
2014-01-05 09:39:34 -------- d-----w- C:\Users\user\AppData\Local\{0471E01D-9D55-446C-AF64-E40849AA0DBA}
2014-01-05 06:18:18 -------- d-----w- C:\Users\user\AppData\Local\CKFYW
2014-01-04 17:26:38 -------- d-----w- C:\Users\user\AppData\Local\{BEEB7765-344E-4675-BC66-EAE933658C13}
2014-01-04 04:29:06 -------- d-----w- C:\Users\user\AppData\Roaming\Pylaf
2014-01-04 04:29:06 -------- d-----w- C:\Users\user\AppData\Roaming\Nuruy
2014-01-04 04:29:06 -------- d-----w- C:\Users\user\AppData\Roaming\Ixixer
2014-01-04 03:58:57 -------- d-----w- C:\Users\user\AppData\Roaming\Yrfiwe
2014-01-04 03:58:57 -------- d-----w- C:\Users\user\AppData\Roaming\Ubucub
2014-01-04 03:58:57 -------- d-----w- C:\Users\user\AppData\Roaming\Odyh
2014-01-04 03:29:41 -------- d-----w- C:\Users\user\AppData\Local\{D42755F3-F5C4-4B98-833F-6639A4E70E98}
2014-01-04 03:08:25 10315576 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{52B9F076-B791-448F-B0EC-669DF92121AC}\mpengine.dll
2014-01-03 21:06:10 -------- d-----w- C:\Users\user\AppData\Roaming\Rymaic
2014-01-03 21:06:10 -------- d-----w- C:\Users\user\AppData\Roaming\Obytde
2014-01-03 21:06:10 -------- d-----w- C:\Users\user\AppData\Roaming\Deagep
2014-01-03 19:37:58 -------- d-sh--w- C:\ProgramData\bbtmp0
2014-01-03 10:48:14 -------- d-----w- C:\Users\user\AppData\Local\{4B737337-3319-4C99-8165-D5081BE65B17}
2014-01-03 10:37:21 -------- d-----w- C:\Users\user\AppData\Local\{BF014E26-F462-4710-891E-3D0AAFD582FA}
2014-01-03 10:36:32 -------- d--h--w- C:\ProgramData\REGVIEW
2014-01-02 02:44:45 -------- d-----w- C:\Users\user\AppData\Local\{B3254C0E-49F0-4558-AD87-F11F9EC05DEB}
2014-01-01 23:57:43 -------- d-----w- C:\Users\user\AppData\Local\{7CA44474-4985-47E2-9706-429A221F094C}
2013-12-31 16:44:15 -------- d-----w- C:\Users\user\AppData\Local\{9C6DE91A-18BF-559D-3CC8-B2A81C8B4231}
2013-12-30 02:08:06 -------- d-----w- C:\Users\user\AppData\Local\{324C473B-A68A-4C8C-A535-CBF903807446}
2013-12-28 10:35:25 -------- d-----w- C:\Users\user\AppData\Local\{084166BE-03D3-47A6-94C8-E9CB04248297}
2013-12-25 19:08:19 -------- d-----w- C:\Users\user\AppData\Local\{68F522E3-37F6-43D6-BDC3-7C92DF03A6C0}
2013-12-20 04:36:45 -------- d-----w- C:\Users\user\AppData\Local\{5A4069FE-B97A-402E-8491-DC0B7968BBE3}
2013-12-17 01:18:58 -------- d-----w- C:\Users\user\AppData\Local\{2FB25123-52FD-4ADF-8737-5587C1BF27B0}
2013-12-16 02:46:57 -------- d-----w- C:\Users\user\AppData\Local\{345905BB-78C9-458B-9B70-8F31C910BCE5}
2013-12-13 16:50:56 -------- d-----w- C:\Users\user\AppData\Local\{65AFBAE0-DC15-4B76-B123-EAE1C7F1126F}
2013-12-13 11:48:12 465920 ----a-w- C:\Windows\System32\WMPhoto.dll
2013-12-13 11:48:12 417792 ----a-w- C:\Windows\SysWow64\WMPhoto.dll
2013-12-13 11:48:02 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2013-12-13 11:48:02 2048 ----a-w- C:\Windows\System32\tzres.dll
2013-12-13 11:46:02 230400 ----a-w- C:\Windows\System32\drivers\portcls.sys
2013-12-13 11:46:02 116736 ----a-w- C:\Windows\System32\drivers\drmk.sys
2013-12-13 11:06:59 1084928 ----a-w- C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll
2013-12-13 11:06:51 1767936 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-12-13 11:06:48 2241536 ----a-w- C:\Windows\System32\wininet.dll
2013-12-12 21:21:15 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2013-12-12 21:21:15 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2013-12-12 21:21:13 202752 ----a-w- C:\Windows\System32\scrrun.dll
2013-12-12 21:21:13 168960 ----a-w- C:\Windows\System32\wscript.exe
2013-12-12 21:21:13 163840 ----a-w- C:\Windows\SysWow64\scrrun.dll
2013-12-12 21:21:13 156160 ----a-w- C:\Windows\System32\cscript.exe
2013-12-12 21:21:13 150016 ----a-w- C:\Windows\System32\wshom.ocx
2013-12-12 21:21:13 141824 ----a-w- C:\Windows\SysWow64\wscript.exe
2013-12-12 21:21:13 126976 ----a-w- C:\Windows\SysWow64\cscript.exe
2013-12-12 21:21:13 121856 ----a-w- C:\Windows\SysWow64\wshom.ocx
2013-12-12 21:21:09 3155968 ----a-w- C:\Windows\System32\win32k.sys
2013-12-12 16:45:21 -------- d-----w- C:\Users\user\AppData\Local\{43D97A3E-D4DB-494A-925B-6CDDB5F3D9E0}
2013-12-12 11:02:09 167424 ----a-w- C:\Program Files\Windows Media Player\wmplayer.exe
2013-12-12 11:02:09 164864 ----a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
2013-12-12 11:02:07 12625920 ----a-w- C:\Windows\System32\wmploc.DLL
2013-12-12 11:02:06 12625408 ----a-w- C:\Windows\SysWow64\wmploc.DLL
.
==================== Find3M ====================
.
2013-12-11 00:09:05 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-12-11 00:09:05 692616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-11-19 11:33:38 267936 ------w- C:\Windows\System32\MpSigStub.exe
2013-10-30 02:32:01 335360 ----a-w- C:\Windows\System32\msieftp.dll
2013-10-30 02:19:52 301568 ----a-w- C:\Windows\SysWow64\msieftp.dll
2013-10-25 06:17:57 3959808 ----a-w- C:\Windows\System32\jscript9.dll
2013-10-25 06:17:52 67072 ----a-w- C:\Windows\System32\iesetup.dll
2013-10-25 06:17:52 136704 ----a-w- C:\Windows\System32\iesysprep.dll
2013-10-25 04:43:42 2877952 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-10-25 04:43:38 61440 ----a-w- C:\Windows\SysWow64\iesetup.dll
2013-10-25 04:43:38 109056 ----a-w- C:\Windows\SysWow64\iesysprep.dll
2013-10-25 04:07:48 2706432 ----a-w- C:\Windows\System32\mshtml.tlb
2013-10-25 03:41:01 2706432 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2013-10-25 03:17:49 89600 ----a-w- C:\Windows\System32\RegisterIEPKEYs.exe
2013-10-25 02:49:34 71680 ----a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe
2011-06-09 19:03:40 3486088 ----a-w- C:\Program Files (x86)\Common Files\ApnToolbarInstaller.exe
2011-06-09 19:03:40 143240 ----a-w- C:\Program Files (x86)\Common Files\ApnStub.exe
2010-01-26 18:11:08 444283 ----a-w- C:\Program Files (x86)\Common Files\WinPcapNmap.exe
.
============= FINISH: 21:24:06,10 ===============
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2014-01-10 22:03:51
-----------------------------
22:03:51.341 OS Version: Windows x64 6.1.7601 Service Pack 1
22:03:51.341 Number of processors: 2 586 0x170A
22:03:51.341 ComputerName: PC-FABIEN UserName: user
22:04:07.877 Initialze error C0000061 - driver not loaded
22:18:31.978 AVAST engine defs: 14010701
22:20:21.490 The log file has been saved successfully to "C:\Users\user\Desktop\aswMBR.txt"
Hello, like recommended I have my DDS Log and aswMBR reports to post. However, i have few things to notice before. I did launch Erunt to backup my files and it went great. However it wouldnt let me run aswMBR so i launch it in safe mode. When i restarted, it appeared a message that the registry backed up with Erunt has a problem, so i tried to launch another one but it told me that it cant delete all the files from previous save so i canceled it. Another one is, i have already run combofix before hand but luckily it didnt finish the process because the computer turned off! Iam really desperate please help !

P.S= Internet explorer is not running anymore, and the ads running in background still there!
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16750 BrowserJavaVersion: 10.13.2
Run by user at 21:18:35 on 2014-01-10
Microsoft Windows 7 Professionnel 6.1.7601.1.1252.33.1036.18.4091.2052 [GMT -8:00]
.
AV: Kaspersky Internet Security *Disabled/Outdated* {2EAA32A5-1EE1-1B22-95DA-337730C6E984}
SP: Kaspersky Internet Security *Disabled/Updated* {95CBD341-38DB-14AC-AF6A-08054B41A339}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
FW: Kaspersky Internet Security *Disabled* {1691B380-548E-1A7A-BE85-9A42CE15AEFF}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\HitmanPro\hmpsched.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Users\user\AppData\Local\StormAlerts\StormAlerts.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\Macromed\Flash\FlashUtil64_11_9_900_170_ActiveX.exe
C:\Windows\system32\RunDll32.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
BHO: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Programme d'aide de l'Assistant de connexion Windows Live ID: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} -
mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe"
mRun: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
dRunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
StartupFolder: C:\Users\user\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk -
StartupFolder: C:\Users\user\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ERUNTA~1.LNK - C:\Program Files (x86)\ERUNT\AUTOBACK.EXE
StartupFolder: C:\Users\user\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\MAGICD~1.LNK -
StartupFolder: C:\Users\user\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\STORMA~2.LNK - C:\Users\user\AppData\Local\StormAlerts\StormAlerts.exe
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDriveTypeAutoRun = dword:60
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htm
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: E&xporter vers Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - {17A84966-F1E9-4645-AA9E-5E771EE1C859} - C:\Program Files (x86)\Nuclear Coffee\VideoGet\Plugins\VideoGet_IE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{B0A727C2-F9BD-49EE-9C21-A4966D502B5F} : DHCPNameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{B0A727C2-F9BD-49EE-9C21-A4966D502B5F}\16474777966696 : DHCPNameServer = 192.168.5.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Notify: SDWinLogon - SDWinLogon.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
x64-BHO: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\ievkbd.dll
x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll
x64-BHO: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\klwtbbho.dll
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\ievkbd.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-IE: {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - {17A84966-F1E9-4645-AA9E-5E771EE1C859} - C:\Program Files (x86)\Nuclear Coffee\VideoGet\Plugins\VideoGet_IE_x64.dll
x64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\klwtbbho.dll
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
x64-DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: klogon - C:\Windows\System32\klogon.dll
x64-SSODL: WebCheck - <orphaned>
x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
.
============= SERVICES / DRIVERS ===============
.
R1 kl2;kl2;C:\Windows\System32\drivers\kl2.sys [2011-3-4 11864]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\System32\drivers\klim6.sys [2011-3-10 29488]
R2 HitmanProScheduler;HitmanPro Scheduler;C:\Program Files\HitmanPro\hmpsched.exe [2014-1-10 109352]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2014-1-10 3921880]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2014-1-10 1042272]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2014-1-10 171416]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;C:\Windows\System32\drivers\k57nd60a.sys [2009-6-10 270848]
R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\System32\drivers\klmouflt.sys [2009-11-2 22544]
S2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe [2011-4-24 206448]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.EXE [2012-6-11 193616]
S3 BBUpdate;BBUpdate;C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.EXE [2012-6-11 240208]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2012-4-13 48488]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2012-3-8 1492840]
S3 StorSvc;Service de stockage;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2012-5-7 59392]
S3 WatAdminSvc;Service Windows Activation Technologies;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-1-18 1255736]
S4 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-10-2 3064000]
S4 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-9-5 171680]
S4 SpyHunter 4 Service;SpyHunter 4 Service;C:\PROGRA~2\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [2010-5-18 327064]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== File Associations ===============
.
ShellExec: dreamweaver.exe: Open="C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS5.5\dreamweaver.exe", "%1"
.
=============== Created Last 30 ================
.
2014-01-10 10:39:27 -------- d-----w- C:\AdwCleaner
2014-01-10 09:40:19 -------- d-----w- C:\Users\user\AppData\Local\Weather_Warnings_LLC
2014-01-10 09:38:59 -------- d-----w- C:\Users\user\AppData\Local\StormAlerts
2014-01-10 09:37:47 -------- d-----w- C:\Program Files\HitmanPro
2014-01-10 09:36:35 -------- d-----w- C:\ProgramData\HitmanPro
2014-01-10 09:22:59 343040 ----a-w- C:\Windows\System32\drivers\usbhub.sys.bak
2014-01-10 09:21:58 146432 ----a-w- C:\Windows\System32\drivers\rmcast.sys.bak
2014-01-10 09:20:57 148352 ----a-w- C:\Windows\System32\drivers\nvraid.sys.bak
2014-01-10 09:19:59 78848 ----a-w- C:\Windows\System32\drivers\IPMIDrv.sys.bak
2014-01-10 09:18:59 64512 ----a-w- C:\Windows\System32\drivers\amdk8.sys.bak
2014-01-10 09:15:40 -------- d-----w- C:\Program Files (x86)\BearShare Applications
2014-01-10 09:08:04 21040 ----a-w- C:\Windows\System32\sdnclean64.exe
2014-01-10 09:08:01 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2014-01-10 09:07:51 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-01-10 09:07:23 -------- d-----w- C:\Users\user\AppData\Local\Programs
2014-01-10 03:16:45 -------- d-----w- C:\$RECYCLE.BIN
2014-01-10 02:57:19 98816 ----a-w- C:\Windows\sed.exe
2014-01-10 02:57:19 256000 ----a-w- C:\Windows\PEV.exe
2014-01-10 02:57:19 208896 ----a-w- C:\Windows\MBR.exe
2014-01-10 02:57:09 -------- d-----w- C:\ComboFix
2014-01-09 11:24:48 -------- d-----w- C:\TDSSKiller_Quarantine
2014-01-09 11:18:17 -------- d-----w- C:\Users\user\.android
2014-01-09 11:18:10 -------- d-----w- C:\Users\user\AppData\Local\cache
2014-01-09 11:17:56 -------- d-----w- C:\Users\user\AppData\Roaming\newnext.me
2014-01-09 11:17:49 -------- d-----w- C:\Users\user\AppData\Local\genienext
2014-01-09 09:37:58 -------- d-----w- C:\Users\user\AppData\Local\{4AAB9E65-9CD0-481E-88FE-AEB81B77BAC7}
2014-01-08 19:32:51 -------- d-----w- C:\Users\user\AppData\Local\{FC914F1A-95F1-4AA3-821B-9AFFB710F9B8}
2014-01-08 03:47:48 -------- d--h--w- C:\ProgramData\{$1284-9213-2940-1289$}
2014-01-07 19:27:12 -------- d-----w- C:\Users\user\AppData\Local\{71FDF0EA-60DA-433D-A05E-AB7A1F70145D}
2014-01-06 18:26:22 -------- d-----w- C:\Users\user\AppData\Local\{4BC44031-D519-4A5F-B031-ED7426808515}
2014-01-05 21:40:03 -------- d-----w- C:\Users\user\AppData\Local\{1C63917D-BA19-4929-BA1F-EB7CCBD22E3C}
2014-01-05 09:39:34 -------- d-----w- C:\Users\user\AppData\Local\{0471E01D-9D55-446C-AF64-E40849AA0DBA}
2014-01-05 06:18:18 -------- d-----w- C:\Users\user\AppData\Local\CKFYW
2014-01-04 17:26:38 -------- d-----w- C:\Users\user\AppData\Local\{BEEB7765-344E-4675-BC66-EAE933658C13}
2014-01-04 04:29:06 -------- d-----w- C:\Users\user\AppData\Roaming\Pylaf
2014-01-04 04:29:06 -------- d-----w- C:\Users\user\AppData\Roaming\Nuruy
2014-01-04 04:29:06 -------- d-----w- C:\Users\user\AppData\Roaming\Ixixer
2014-01-04 03:58:57 -------- d-----w- C:\Users\user\AppData\Roaming\Yrfiwe
2014-01-04 03:58:57 -------- d-----w- C:\Users\user\AppData\Roaming\Ubucub
2014-01-04 03:58:57 -------- d-----w- C:\Users\user\AppData\Roaming\Odyh
2014-01-04 03:29:41 -------- d-----w- C:\Users\user\AppData\Local\{D42755F3-F5C4-4B98-833F-6639A4E70E98}
2014-01-04 03:08:25 10315576 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{52B9F076-B791-448F-B0EC-669DF92121AC}\mpengine.dll
2014-01-03 21:06:10 -------- d-----w- C:\Users\user\AppData\Roaming\Rymaic
2014-01-03 21:06:10 -------- d-----w- C:\Users\user\AppData\Roaming\Obytde
2014-01-03 21:06:10 -------- d-----w- C:\Users\user\AppData\Roaming\Deagep
2014-01-03 19:37:58 -------- d-sh--w- C:\ProgramData\bbtmp0
2014-01-03 10:48:14 -------- d-----w- C:\Users\user\AppData\Local\{4B737337-3319-4C99-8165-D5081BE65B17}
2014-01-03 10:37:21 -------- d-----w- C:\Users\user\AppData\Local\{BF014E26-F462-4710-891E-3D0AAFD582FA}
2014-01-03 10:36:32 -------- d--h--w- C:\ProgramData\REGVIEW
2014-01-02 02:44:45 -------- d-----w- C:\Users\user\AppData\Local\{B3254C0E-49F0-4558-AD87-F11F9EC05DEB}
2014-01-01 23:57:43 -------- d-----w- C:\Users\user\AppData\Local\{7CA44474-4985-47E2-9706-429A221F094C}
2013-12-31 16:44:15 -------- d-----w- C:\Users\user\AppData\Local\{9C6DE91A-18BF-559D-3CC8-B2A81C8B4231}
2013-12-30 02:08:06 -------- d-----w- C:\Users\user\AppData\Local\{324C473B-A68A-4C8C-A535-CBF903807446}
2013-12-28 10:35:25 -------- d-----w- C:\Users\user\AppData\Local\{084166BE-03D3-47A6-94C8-E9CB04248297}
2013-12-25 19:08:19 -------- d-----w- C:\Users\user\AppData\Local\{68F522E3-37F6-43D6-BDC3-7C92DF03A6C0}
2013-12-20 04:36:45 -------- d-----w- C:\Users\user\AppData\Local\{5A4069FE-B97A-402E-8491-DC0B7968BBE3}
2013-12-17 01:18:58 -------- d-----w- C:\Users\user\AppData\Local\{2FB25123-52FD-4ADF-8737-5587C1BF27B0}
2013-12-16 02:46:57 -------- d-----w- C:\Users\user\AppData\Local\{345905BB-78C9-458B-9B70-8F31C910BCE5}
2013-12-13 16:50:56 -------- d-----w- C:\Users\user\AppData\Local\{65AFBAE0-DC15-4B76-B123-EAE1C7F1126F}
2013-12-13 11:48:12 465920 ----a-w- C:\Windows\System32\WMPhoto.dll
2013-12-13 11:48:12 417792 ----a-w- C:\Windows\SysWow64\WMPhoto.dll
2013-12-13 11:48:02 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2013-12-13 11:48:02 2048 ----a-w- C:\Windows\System32\tzres.dll
2013-12-13 11:46:02 230400 ----a-w- C:\Windows\System32\drivers\portcls.sys
2013-12-13 11:46:02 116736 ----a-w- C:\Windows\System32\drivers\drmk.sys
2013-12-13 11:06:59 1084928 ----a-w- C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll
2013-12-13 11:06:51 1767936 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-12-13 11:06:48 2241536 ----a-w- C:\Windows\System32\wininet.dll
2013-12-12 21:21:15 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2013-12-12 21:21:15 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2013-12-12 21:21:13 202752 ----a-w- C:\Windows\System32\scrrun.dll
2013-12-12 21:21:13 168960 ----a-w- C:\Windows\System32\wscript.exe
2013-12-12 21:21:13 163840 ----a-w- C:\Windows\SysWow64\scrrun.dll
2013-12-12 21:21:13 156160 ----a-w- C:\Windows\System32\cscript.exe
2013-12-12 21:21:13 150016 ----a-w- C:\Windows\System32\wshom.ocx
2013-12-12 21:21:13 141824 ----a-w- C:\Windows\SysWow64\wscript.exe
2013-12-12 21:21:13 126976 ----a-w- C:\Windows\SysWow64\cscript.exe
2013-12-12 21:21:13 121856 ----a-w- C:\Windows\SysWow64\wshom.ocx
2013-12-12 21:21:09 3155968 ----a-w- C:\Windows\System32\win32k.sys
2013-12-12 16:45:21 -------- d-----w- C:\Users\user\AppData\Local\{43D97A3E-D4DB-494A-925B-6CDDB5F3D9E0}
2013-12-12 11:02:09 167424 ----a-w- C:\Program Files\Windows Media Player\wmplayer.exe
2013-12-12 11:02:09 164864 ----a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
2013-12-12 11:02:07 12625920 ----a-w- C:\Windows\System32\wmploc.DLL
2013-12-12 11:02:06 12625408 ----a-w- C:\Windows\SysWow64\wmploc.DLL
.
==================== Find3M ====================
.
2013-12-11 00:09:05 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-12-11 00:09:05 692616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-11-19 11:33:38 267936 ------w- C:\Windows\System32\MpSigStub.exe
2013-10-30 02:32:01 335360 ----a-w- C:\Windows\System32\msieftp.dll
2013-10-30 02:19:52 301568 ----a-w- C:\Windows\SysWow64\msieftp.dll
2013-10-25 06:17:57 3959808 ----a-w- C:\Windows\System32\jscript9.dll
2013-10-25 06:17:52 67072 ----a-w- C:\Windows\System32\iesetup.dll
2013-10-25 06:17:52 136704 ----a-w- C:\Windows\System32\iesysprep.dll
2013-10-25 04:43:42 2877952 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-10-25 04:43:38 61440 ----a-w- C:\Windows\SysWow64\iesetup.dll
2013-10-25 04:43:38 109056 ----a-w- C:\Windows\SysWow64\iesysprep.dll
2013-10-25 04:07:48 2706432 ----a-w- C:\Windows\System32\mshtml.tlb
2013-10-25 03:41:01 2706432 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2013-10-25 03:17:49 89600 ----a-w- C:\Windows\System32\RegisterIEPKEYs.exe
2013-10-25 02:49:34 71680 ----a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe
2011-06-09 19:03:40 3486088 ----a-w- C:\Program Files (x86)\Common Files\ApnToolbarInstaller.exe
2011-06-09 19:03:40 143240 ----a-w- C:\Program Files (x86)\Common Files\ApnStub.exe
2010-01-26 18:11:08 444283 ----a-w- C:\Program Files (x86)\Common Files\WinPcapNmap.exe
.
============= FINISH: 21:24:06,10 ===============
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2014-01-10 22:03:51
-----------------------------
22:03:51.341 OS Version: Windows x64 6.1.7601 Service Pack 1
22:03:51.341 Number of processors: 2 586 0x170A
22:03:51.341 ComputerName: PC-FABIEN UserName: user
22:04:07.877 Initialze error C0000061 - driver not loaded
22:18:31.978 AVAST engine defs: 14010701
22:20:21.490 The log file has been saved successfully to "C:\Users\user\Desktop\aswMBR.txt"
Attachments
Last edited by a moderator: